I have apparently picked up this nasty thing too. I tried virus removals at first and they did not stop the problem. I've read through some of the other posts and it looks like I could do the first step and save a little time so I'm attaching the FRST.txt contents and the Search.txt contents. The machine is running Windows Vista 64 bit. Strangely, I thought I had SP2 though below it says SP1. If I could turn it on for more than a minute, I could check again. I hope you can help and Thank YOU in advance. I will await your reply before doing anything else.
Lynndie
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012
Ran by SYSTEM at 07-08-2012 23:58:07
Running from D:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM-x32\...\Run: [] [x]
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\LogMeInRemoteUser\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\owner\...\Run: [AdobeBridge] [x]
HKLM-x32\...\Runonce: [removeSearchqudatamngr] cmd.exe /c RD /S /Q "C:\Program Files (x86)\Searchqu Toolbar" [x]
HKLM-x32\...\Runonce: [removeSearchqutoolbar] cmd.exe /c RD /S /Q "C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar" [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 24.217.0.5 24.217.201.67
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\LogMeInRemoteUser\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 nosGetPlusHelper; C:\Program Files (x86)\NOS\bin\getPlus_Helper_3004.dll [66112 2010-09-01] (NOS Microsystems Ltd.)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [211968 2008-01-20] (Microsoft Corporation)
4 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74384 2008-03-24] (MicroVision Development, Inc.)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [428544 2008-01-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 CAXHWBS2; C:\Windows\System32\Drivers\CAXHWBS2.sys [411136 2008-07-01] (Conexant Systems, Inc.)
3 EyeOneDisplay; C:\Windows\System32\Drivers\i1display_x64.sys [7808 2005-12-13] (GretagMacbeth LLC)
3 LVPr2M64; C:\Windows\System32\Drivers\LVPr2M64.sys [30304 2010-05-07] ()
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
3 MusCAudio; C:\Windows\System32\Drivers\MusCAudio.sys [33336 2009-10-30] (Windows (R) Codename Longhorn DDK provider)
3 SeqCal; C:\Windows\System32\Drivers\SeqCal.sys [7808 2006-05-18] (GretagMacbeth LLC)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
2 PDIHWCTL; \??\C:\Windows\system32\drivers\pdihwctl.sys [x]
2 regi; \??\C:\Windows\system32\drivers\regi.sys [x]
3 WacomVKHid; C:\Windows\System32\DRIVERS\WacomVKHid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-07 23:58 - 2012-08-07 23:58 - 00000000 ____D C:\FRST
2012-08-07 20:02 - 2012-08-07 20:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nyuzseir.sys
2012-08-06 10:44 - 2012-08-06 10:44 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-06 09:12 - 2012-08-06 09:12 - 00000000 ____D C:\$WINDOWS.~BT
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-05 15:31 - 2012-08-06 15:37 - 00003403 ____A C:\Windows\setupact.log
2012-08-05 15:31 - 2012-08-06 09:11 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 13:06 - 2012-08-07 17:38 - 00004566 ____A C:\Windows\WindowsUpdate.log
2012-08-05 13:06 - 2012-08-05 13:06 - 00721626 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-05 13:06 - 2012-08-05 13:06 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-05 13:06 - 2012-08-05 13:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-05 11:39 - 2012-08-05 13:06 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 11:37 - 2012-08-05 11:37 - 12621696 ____A (Microsoft Corporation) C:\Users\owner\Downloads\mseinstall.exe
2012-08-04 17:22 - 2012-08-07 20:49 - 00039012 ____A C:\Windows\PFRO.log
2012-07-31 18:25 - 2012-07-31 18:36 - 00000732 ____A C:\Users\owner\AppData\Local\d3d9caps64.dat
2012-07-31 18:23 - 2012-08-02 13:54 - 00000000 ____D C:\Windows\Minidump
2012-07-31 13:35 - 2012-07-31 13:35 - 00000000 ____D C:\Users\owner\Doctor Web
2012-07-31 13:19 - 2012-07-31 13:19 - 00000000 ____D C:\Program Files\Common Files\Doctor Web
2012-07-31 13:18 - 2012-07-31 13:19 - 00000000 ____D C:\Users\All Users\Doctor Web
2012-07-30 17:05 - 2012-07-30 17:05 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\owner\Downloads\mbam-setup.exe
2012-07-30 16:56 - 2012-07-30 16:56 - 00883616 ____A (Bleeping Computer, LLC) C:\Program Files (x86)\FixExec.scr
2012-07-30 16:39 - 2012-07-30 17:02 - 00001246 ____A C:\Users\owner\Desktop\FixExec.txt
2012-07-30 15:56 - 2012-07-30 15:56 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(2).exe
2012-07-30 15:55 - 2012-07-30 15:55 - 00001205 ____A C:\Users\owner\Downloads\registryfix(1).reg
2012-07-30 15:27 - 2012-07-30 15:27 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(1).exe
2012-07-30 15:14 - 2012-07-30 15:57 - 00001004 ____A C:\Users\owner\Desktop\Rkill.txt
2012-07-30 15:14 - 2012-07-30 15:14 - 00000000 ____D C:\Users\owner\Desktop\rkill-backup
2012-07-30 15:12 - 2012-07-30 15:12 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore.exe
2012-07-30 15:11 - 2012-07-30 15:11 - 00001205 ____A C:\Users\owner\Downloads\registryfix.reg
2012-07-30 14:30 - 2012-07-30 14:30 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-30 14:25 - 2012-07-30 20:17 - 00000000 ____D C:\Users\All Users\7531CC9600714A53199543F32F3B707C
2012-07-12 13:56 - 2012-07-12 13:56 - 03875048 ____A (AVG Technologies) C:\Users\owner\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320(1).exe
2012-07-12 13:39 - 2012-07-12 13:39 - 00002071 ____A C:\Users\Public\Desktop\HP Photosmart Essential.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00001894 ____A C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00000000 ____D C:\Users\All Users\HPSSUPPLY
2012-07-12 00:01 - 2012-06-13 05:58 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 02:14 - 2012-06-08 09:59 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 02:14 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 02:14 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 02:14 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 02:14 - 2012-06-05 08:22 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 02:14 - 2012-06-05 08:22 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 02:14 - 2012-06-04 07:29 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 02:14 - 2012-06-01 16:22 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 02:14 - 2012-06-01 16:22 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 02:14 - 2012-06-01 16:05 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 02:14 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 02:14 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
============ 3 Months Modified Files ========================
2012-08-07 20:53 - 2006-11-02 07:42 - 00032568 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-07 20:53 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 20:52 - 2011-11-26 05:30 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-07 20:49 - 2012-08-04 17:22 - 00039012 ____A C:\Windows\PFRO.log
2012-08-07 20:02 - 2012-08-07 20:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nyuzseir.sys
2012-08-07 17:38 - 2012-08-05 13:06 - 00004566 ____A C:\Windows\WindowsUpdate.log
2012-08-07 17:34 - 2011-11-26 05:30 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-07 17:33 - 2012-03-27 17:23 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2274459378-4032421509-301073050-1000UA.job
2012-08-06 15:37 - 2012-08-05 15:31 - 00003403 ____A C:\Windows\setupact.log
2012-08-06 15:36 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 15:36 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 10:44 - 2012-08-06 10:44 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-06 09:11 - 2012-08-05 15:31 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 13:06 - 2012-08-05 13:06 - 00721626 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-05 13:06 - 2012-08-05 11:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 12:17 - 2006-11-02 04:46 - 00703342 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-05 11:46 - 2006-11-02 07:21 - 05154120 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-05 11:37 - 2012-08-05 11:37 - 12621696 ____A (Microsoft Corporation) C:\Users\owner\Downloads\mseinstall.exe
2012-08-04 14:33 - 2012-03-27 17:23 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2274459378-4032421509-301073050-1000Core.job
2012-07-31 18:36 - 2012-07-31 18:25 - 00000732 ____A C:\Users\owner\AppData\Local\d3d9caps64.dat
2012-07-30 17:05 - 2012-07-30 17:05 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\owner\Downloads\mbam-setup.exe
2012-07-30 17:02 - 2012-07-30 16:39 - 00001246 ____A C:\Users\owner\Desktop\FixExec.txt
2012-07-30 16:56 - 2012-07-30 16:56 - 00883616 ____A (Bleeping Computer, LLC) C:\Program Files (x86)\FixExec.scr
2012-07-30 15:57 - 2012-07-30 15:14 - 00001004 ____A C:\Users\owner\Desktop\Rkill.txt
2012-07-30 15:56 - 2012-07-30 15:56 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(2).exe
2012-07-30 15:55 - 2012-07-30 15:55 - 00001205 ____A C:\Users\owner\Downloads\registryfix(1).reg
2012-07-30 15:27 - 2012-07-30 15:27 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(1).exe
2012-07-30 15:12 - 2012-07-30 15:12 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore.exe
2012-07-30 15:11 - 2012-07-30 15:11 - 00001205 ____A C:\Users\owner\Downloads\registryfix.reg
2012-07-30 14:27 - 2009-08-07 12:29 - 00009746 ____A C:\Users\owner\AppData\Roaming\wklnhst.dat
2012-07-25 19:12 - 2012-01-03 08:07 - 00024576 ____A C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-22 19:28 - 2010-07-27 13:28 - 00001848 ____A C:\Users\owner\Desktop\mpixpro ROES.lnk
2012-07-12 13:56 - 2012-07-12 13:56 - 03875048 ____A (AVG Technologies) C:\Users\owner\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-12 13:54 - 2011-04-13 16:56 - 00000858 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320(1).exe
2012-07-12 13:41 - 2010-11-19 09:34 - 00148401 ____A C:\Windows\hpoins19.dat
2012-07-12 13:41 - 2010-11-19 08:35 - 00012239 ____A C:\Users\All Users\hpzinstall.log
2012-07-12 13:39 - 2012-07-12 13:39 - 00002071 ____A C:\Users\Public\Desktop\HP Photosmart Essential.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00001894 ____A C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2012-07-12 00:04 - 2006-11-02 04:35 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-18 15:20 - 2012-06-18 15:20 - 00841568 ____A (WinRecovery Software ) C:\Users\owner\Downloads\cardrecovery_setup(1).exe
2012-06-18 15:17 - 2012-06-18 15:17 - 00841568 ____A (WinRecovery Software ) C:\Users\owner\Downloads\cardrecovery_setup.exe
2012-06-18 15:12 - 2012-06-18 15:12 - 03917522 ____A ( ) C:\Users\owner\Downloads\zar91setup.exe
2012-06-18 14:41 - 2012-06-18 14:41 - 04149019 ____A (InstallShield Software Corporation) C:\Users\owner\Downloads\pci_us_smartrecovery.exe.part
2012-06-14 09:13 - 2012-06-14 09:13 - 00001872 ____A C:\Users\owner\Desktop\Diversified Digital Link.lnk
2012-06-13 05:58 - 2012-07-12 00:01 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:59 - 2012-07-11 02:14 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-11 02:14 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 08:47 - 2012-07-11 02:14 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-11 02:14 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-11 02:14 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-11 02:14 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-11 02:14 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-20 18:29 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 18:29 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 18:29 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-20 18:29 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-18 16:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-20 18:29 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 12:19 - 2012-06-18 16:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:19 - 2012-06-18 16:29 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 12:15 - 2012-06-18 16:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 12:12 - 2012-06-18 16:29 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-01 16:22 - 2012-07-11 02:14 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-11 02:14 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-11 02:14 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-11 02:14 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-11 02:14 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-14 22:35 - 2012-06-13 20:04 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 06007808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-14 22:32 - 2012-06-13 20:04 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-14 22:32 - 2012-06-13 20:04 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-14 22:32 - 2012-06-13 20:04 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-14 21:01 - 2012-06-13 20:04 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-14 19:26 - 2012-06-13 20:04 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-14 19:25 - 2012-06-13 20:04 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-14 19:24 - 2012-06-13 20:04 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-14 19:23 - 2012-06-13 20:04 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-14 18:19 - 2012-06-13 20:04 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-14 18:19 - 2012-06-13 20:04 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 18:19 - 2012-06-13 20:04 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-14 18:18 - 2012-06-13 20:04 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-14 18:16 - 2012-06-13 20:04 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-14 18:14 - 2012-06-13 20:04 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-14 17:21 - 2012-06-13 20:04 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-14 16:40 - 2012-06-13 20:04 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-14 16:40 - 2012-06-13 20:04 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-14 16:39 - 2012-06-13 20:04 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-14 16:39 - 2012-06-13 20:04 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
ZeroAccess:
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\@
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\U
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L\00000004.@
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L\201d3dde
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe B8844F93D2C5F1DCDB179AAA9AF134B7 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 8189.27 MB
Available physical RAM: 7566.78 MB
Total Pagefile: 7938.67 MB
Available Pagefile: 7550.45 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:916.82 GB) (Free:719.78 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:0.24 GB) (Free:0.05 GB) FAT32
8 Drive x: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:7.88 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 932 GB 0 B
Disk 1 Online 245 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 32 KB
Partition 2 Primary 15 GB 40 MB
Partition 3 Primary 917 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 917 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 245 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D FAT32 Removable 245 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-05 12:17
======================= End Of Log ==========================
Lynndie
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012
Ran by SYSTEM at 07-08-2012 23:58:07
Running from D:\
Windows Vista (TM) Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM-x32\...\Run: [] [x]
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\LogMeInRemoteUser\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\owner\...\Run: [AdobeBridge] [x]
HKLM-x32\...\Runonce: [removeSearchqudatamngr] cmd.exe /c RD /S /Q "C:\Program Files (x86)\Searchqu Toolbar" [x]
HKLM-x32\...\Runonce: [removeSearchqutoolbar] cmd.exe /c RD /S /Q "C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar" [x]
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 24.217.0.5 24.217.201.67
Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\LogMeInRemoteUser\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 nosGetPlusHelper; C:\Program Files (x86)\NOS\bin\getPlus_Helper_3004.dll [66112 2010-09-01] (NOS Microsystems Ltd.)
2 RapiMgr; C:\Windows\WindowsMobile\rapimgr.dll [211968 2008-01-20] (Microsoft Corporation)
4 stllssvr; "C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe" [74384 2008-03-24] (MicroVision Development, Inc.)
2 WcesComm; C:\Windows\WindowsMobile\wcescomm.dll [428544 2008-01-20] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 CAXHWBS2; C:\Windows\System32\Drivers\CAXHWBS2.sys [411136 2008-07-01] (Conexant Systems, Inc.)
3 EyeOneDisplay; C:\Windows\System32\Drivers\i1display_x64.sys [7808 2005-12-13] (GretagMacbeth LLC)
3 LVPr2M64; C:\Windows\System32\Drivers\LVPr2M64.sys [30304 2010-05-07] ()
3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
3 MusCAudio; C:\Windows\System32\Drivers\MusCAudio.sys [33336 2009-10-30] (Windows (R) Codename Longhorn DDK provider)
3 SeqCal; C:\Windows\System32\Drivers\SeqCal.sys [7808 2006-05-18] (GretagMacbeth LLC)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
2 PDIHWCTL; \??\C:\Windows\system32\drivers\pdihwctl.sys [x]
2 regi; \??\C:\Windows\system32\drivers\regi.sys [x]
3 WacomVKHid; C:\Windows\System32\DRIVERS\WacomVKHid.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-07 23:58 - 2012-08-07 23:58 - 00000000 ____D C:\FRST
2012-08-07 20:02 - 2012-08-07 20:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nyuzseir.sys
2012-08-06 10:44 - 2012-08-06 10:44 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-06 09:12 - 2012-08-06 09:12 - 00000000 ____D C:\$WINDOWS.~BT
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-05 15:31 - 2012-08-06 15:37 - 00003403 ____A C:\Windows\setupact.log
2012-08-05 15:31 - 2012-08-06 09:11 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 13:06 - 2012-08-07 17:38 - 00004566 ____A C:\Windows\WindowsUpdate.log
2012-08-05 13:06 - 2012-08-05 13:06 - 00721626 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-05 13:06 - 2012-08-05 13:06 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-05 13:06 - 2012-08-05 13:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-05 11:39 - 2012-08-05 13:06 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 11:37 - 2012-08-05 11:37 - 12621696 ____A (Microsoft Corporation) C:\Users\owner\Downloads\mseinstall.exe
2012-08-04 17:22 - 2012-08-07 20:49 - 00039012 ____A C:\Windows\PFRO.log
2012-07-31 18:25 - 2012-07-31 18:36 - 00000732 ____A C:\Users\owner\AppData\Local\d3d9caps64.dat
2012-07-31 18:23 - 2012-08-02 13:54 - 00000000 ____D C:\Windows\Minidump
2012-07-31 13:35 - 2012-07-31 13:35 - 00000000 ____D C:\Users\owner\Doctor Web
2012-07-31 13:19 - 2012-07-31 13:19 - 00000000 ____D C:\Program Files\Common Files\Doctor Web
2012-07-31 13:18 - 2012-07-31 13:19 - 00000000 ____D C:\Users\All Users\Doctor Web
2012-07-30 17:05 - 2012-07-30 17:05 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\owner\Downloads\mbam-setup.exe
2012-07-30 16:56 - 2012-07-30 16:56 - 00883616 ____A (Bleeping Computer, LLC) C:\Program Files (x86)\FixExec.scr
2012-07-30 16:39 - 2012-07-30 17:02 - 00001246 ____A C:\Users\owner\Desktop\FixExec.txt
2012-07-30 15:56 - 2012-07-30 15:56 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(2).exe
2012-07-30 15:55 - 2012-07-30 15:55 - 00001205 ____A C:\Users\owner\Downloads\registryfix(1).reg
2012-07-30 15:27 - 2012-07-30 15:27 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(1).exe
2012-07-30 15:14 - 2012-07-30 15:57 - 00001004 ____A C:\Users\owner\Desktop\Rkill.txt
2012-07-30 15:14 - 2012-07-30 15:14 - 00000000 ____D C:\Users\owner\Desktop\rkill-backup
2012-07-30 15:12 - 2012-07-30 15:12 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore.exe
2012-07-30 15:11 - 2012-07-30 15:11 - 00001205 ____A C:\Users\owner\Downloads\registryfix.reg
2012-07-30 14:30 - 2012-07-30 14:30 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-30 14:25 - 2012-07-30 20:17 - 00000000 ____D C:\Users\All Users\7531CC9600714A53199543F32F3B707C
2012-07-12 13:56 - 2012-07-12 13:56 - 03875048 ____A (AVG Technologies) C:\Users\owner\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320(1).exe
2012-07-12 13:39 - 2012-07-12 13:39 - 00002071 ____A C:\Users\Public\Desktop\HP Photosmart Essential.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00001894 ____A C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00000000 ____D C:\Users\All Users\HPSSUPPLY
2012-07-12 00:01 - 2012-06-13 05:58 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 02:14 - 2012-06-08 09:59 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 02:14 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 02:14 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 02:14 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 02:14 - 2012-06-05 08:22 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 02:14 - 2012-06-05 08:22 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 02:14 - 2012-06-04 07:29 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 02:14 - 2012-06-01 16:22 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 02:14 - 2012-06-01 16:22 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 02:14 - 2012-06-01 16:05 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 02:14 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 02:14 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
============ 3 Months Modified Files ========================
2012-08-07 20:53 - 2006-11-02 07:42 - 00032568 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-07 20:53 - 2006-11-02 07:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 20:52 - 2011-11-26 05:30 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-07 20:49 - 2012-08-04 17:22 - 00039012 ____A C:\Windows\PFRO.log
2012-08-07 20:02 - 2012-08-07 20:02 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\nyuzseir.sys
2012-08-07 17:38 - 2012-08-05 13:06 - 00004566 ____A C:\Windows\WindowsUpdate.log
2012-08-07 17:34 - 2011-11-26 05:30 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-07 17:33 - 2012-03-27 17:23 - 00000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2274459378-4032421509-301073050-1000UA.job
2012-08-06 15:37 - 2012-08-05 15:31 - 00003403 ____A C:\Windows\setupact.log
2012-08-06 15:36 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-06 15:36 - 2006-11-02 07:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-06 10:44 - 2012-08-06 10:44 - 524288000 ____A C:\REMOVE_THIS_FILE.livecd.swap
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagwrn.xml
2012-08-06 09:11 - 2012-08-06 09:11 - 00001887 ____A C:\Windows\diagerr.xml
2012-08-06 09:11 - 2012-08-05 15:31 - 00000000 ____A C:\Windows\setuperr.log
2012-08-05 13:06 - 2012-08-05 13:06 - 00721626 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-05 13:06 - 2012-08-05 11:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-05 12:17 - 2006-11-02 04:46 - 00703342 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-05 11:46 - 2006-11-02 07:21 - 05154120 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-05 11:37 - 2012-08-05 11:37 - 12621696 ____A (Microsoft Corporation) C:\Users\owner\Downloads\mseinstall.exe
2012-08-04 14:33 - 2012-03-27 17:23 - 00000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2274459378-4032421509-301073050-1000Core.job
2012-07-31 18:36 - 2012-07-31 18:25 - 00000732 ____A C:\Users\owner\AppData\Local\d3d9caps64.dat
2012-07-30 17:05 - 2012-07-30 17:05 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\owner\Downloads\mbam-setup.exe
2012-07-30 17:02 - 2012-07-30 16:39 - 00001246 ____A C:\Users\owner\Desktop\FixExec.txt
2012-07-30 16:56 - 2012-07-30 16:56 - 00883616 ____A (Bleeping Computer, LLC) C:\Program Files (x86)\FixExec.scr
2012-07-30 15:57 - 2012-07-30 15:14 - 00001004 ____A C:\Users\owner\Desktop\Rkill.txt
2012-07-30 15:56 - 2012-07-30 15:56 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(2).exe
2012-07-30 15:55 - 2012-07-30 15:55 - 00001205 ____A C:\Users\owner\Downloads\registryfix(1).reg
2012-07-30 15:27 - 2012-07-30 15:27 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore(1).exe
2012-07-30 15:12 - 2012-07-30 15:12 - 01050016 ____A (Bleeping Computer, LLC) C:\Users\owner\Downloads\iExplore.exe
2012-07-30 15:11 - 2012-07-30 15:11 - 00001205 ____A C:\Users\owner\Downloads\registryfix.reg
2012-07-30 14:27 - 2009-08-07 12:29 - 00009746 ____A C:\Users\owner\AppData\Roaming\wklnhst.dat
2012-07-25 19:12 - 2012-01-03 08:07 - 00024576 ____A C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-22 19:28 - 2010-07-27 13:28 - 00001848 ____A C:\Users\owner\Desktop\mpixpro ROES.lnk
2012-07-12 13:56 - 2012-07-12 13:56 - 03875048 ____A (AVG Technologies) C:\Users\owner\Downloads\avg_free_stb_all_2012_2195_cnet.exe
2012-07-12 13:54 - 2011-04-13 16:56 - 00000858 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320.exe
2012-07-12 13:53 - 2012-07-12 13:53 - 03889704 ____A (Piriform Ltd) C:\Users\owner\Downloads\ccsetup320(1).exe
2012-07-12 13:41 - 2010-11-19 09:34 - 00148401 ____A C:\Windows\hpoins19.dat
2012-07-12 13:41 - 2010-11-19 08:35 - 00012239 ____A C:\Users\All Users\hpzinstall.log
2012-07-12 13:39 - 2012-07-12 13:39 - 00002071 ____A C:\Users\Public\Desktop\HP Photosmart Essential.lnk
2012-07-12 13:39 - 2012-07-12 13:39 - 00001894 ____A C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2012-07-12 00:04 - 2006-11-02 04:35 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-18 15:20 - 2012-06-18 15:20 - 00841568 ____A (WinRecovery Software ) C:\Users\owner\Downloads\cardrecovery_setup(1).exe
2012-06-18 15:17 - 2012-06-18 15:17 - 00841568 ____A (WinRecovery Software ) C:\Users\owner\Downloads\cardrecovery_setup.exe
2012-06-18 15:12 - 2012-06-18 15:12 - 03917522 ____A ( ) C:\Users\owner\Downloads\zar91setup.exe
2012-06-18 14:41 - 2012-06-18 14:41 - 04149019 ____A (InstallShield Software Corporation) C:\Users\owner\Downloads\pci_us_smartrecovery.exe.part
2012-06-14 09:13 - 2012-06-14 09:13 - 00001872 ____A C:\Users\owner\Desktop\Diversified Digital Link.lnk
2012-06-13 05:58 - 2012-07-12 00:01 - 02769408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 09:59 - 2012-07-11 02:14 - 12899840 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 09:47 - 2012-07-11 02:14 - 11586048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 08:47 - 2012-07-11 02:14 - 01401856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 08:47 - 2012-07-11 02:14 - 01248768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 08:22 - 2012-07-11 02:14 - 01869824 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 08:22 - 2012-07-11 02:14 - 01797120 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-04 07:29 - 2012-07-11 02:14 - 00516480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-20 18:29 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 18:29 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 18:29 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00577048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:19 - 2012-06-18 16:29 - 00035864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2012-06-02 14:15 - 2012-06-20 18:29 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-18 16:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-20 18:29 - 00088576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2012-06-02 12:19 - 2012-06-18 16:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:19 - 2012-06-18 16:29 - 00171904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2012-06-02 12:15 - 2012-06-18 16:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 12:12 - 2012-06-18 16:29 - 00033792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2012-06-01 16:22 - 2012-07-11 02:14 - 00347136 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:22 - 2012-07-11 02:14 - 00254464 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 16:05 - 2012-07-11 02:14 - 00077312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 16:04 - 2012-07-11 02:14 - 00278528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 16:03 - 2012-07-11 02:14 - 00204288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 01212416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 00916992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-14 22:37 - 2012-06-13 20:04 - 00105984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-14 22:35 - 2012-06-13 20:04 - 00206848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 06007808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00629760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00611840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstime.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00067072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-14 22:33 - 2012-06-13 20:04 - 00055296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-14 22:32 - 2012-06-13 20:04 - 01469440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-14 22:32 - 2012-06-13 20:04 - 00043520 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-14 22:32 - 2012-06-13 20:04 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 11111424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 02000384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00387584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00184320 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00164352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-14 22:31 - 2012-06-13 20:04 - 00055808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-14 21:01 - 2012-06-13 20:04 - 00385024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-14 19:26 - 2012-06-13 20:04 - 00133632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-14 19:25 - 2012-06-13 20:04 - 00174080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-14 19:24 - 2012-06-13 20:04 - 00013312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-14 19:23 - 2012-06-13 20:04 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-14 18:19 - 2012-06-13 20:04 - 01488384 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-14 18:19 - 2012-06-13 20:04 - 01147392 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 18:19 - 2012-06-13 20:04 - 00108032 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-14 18:18 - 2012-06-13 20:04 - 00243712 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-14 18:16 - 2012-06-13 20:04 - 01062912 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 09328640 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00742912 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00056832 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-14 18:15 - 2012-06-13 20:04 - 00031744 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 12508672 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 02350592 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 01538560 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-14 18:14 - 2012-06-13 20:04 - 00459776 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00252416 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00132096 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-14 18:14 - 2012-06-13 20:04 - 00072192 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-14 17:21 - 2012-06-13 20:04 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-14 16:40 - 2012-06-13 20:04 - 00162816 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-14 16:40 - 2012-06-13 20:04 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-14 16:39 - 2012-06-13 20:04 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-14 16:39 - 2012-06-13 20:04 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
ZeroAccess:
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\@
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\U
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L\00000004.@
C:\Windows\Installer\{5cbbb43c-55e9-d992-a3af-aff90a8bd5c8}\L\201d3dde
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe B8844F93D2C5F1DCDB179AAA9AF134B7 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 8189.27 MB
Available physical RAM: 7566.78 MB
Total Pagefile: 7938.67 MB
Available Pagefile: 7550.45 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:916.82 GB) (Free:719.78 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Removable) (Total:0.24 GB) (Free:0.05 GB) FAT32
8 Drive x: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:7.88 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 932 GB 0 B
Disk 1 Online 245 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 32 KB
Partition 2 Primary 15 GB 40 MB
Partition 3 Primary 917 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 FAT Partition 39 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 917 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 245 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D FAT32 Removable 245 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-05 12:17
======================= End Of Log ==========================