Praankster
Posts: 23 +0
OS: Windows 7 Ultimate 32
Hello and thanks in advance for any help!
I have the same problem as many others - I appear to have the Zeroaccess virus, variants of Win32/Sirefef and following the reinstall of MSE a system that reboots every couple of minutes even in safe mode (although it takes a little longer). I tried a few tools before a friend recommended this forum - then I ran farbar in System Recovery Option (files below).
The full story if it is useful...
It all started after getting redirects using Chrome web browser, and then couldnt access sites such as Microsoft and Sophos. MSE detected a virus but disappeared before I could read what it was. On next boot I could not get MSE service to start, and the firewall was down both giving error messages.
I tried Rogue Killer which identified Zeroaccess in desktop.ini and in services.exe that it could not fix. MBAM also found Zeroaccess. I also lost my network connection - Rogue Killer reported a problem with DNS.
The Microsoft website recommended using their Safety Scanner and MSE. Safety scanner detected Win32/Sirefef.R in services.exe.
I reinstalled MSE. Sirefef.R was detected as above and 'disinfected', Win32/Sirefef.AH was 'removed'. On reboot Win32/Sirefef.AB was detected and since then get a 'Windows has encountered a critical error' after a couple of minutes and the system reboots.
I managed to run TDSSKiller, which found and quarantined 5 objects (log file attached). This did not appear to make any difference to the situation. I then tried Kaspersky Rescue Disk 10 which found no problems. At that point I was contemplating a reinstall, until a friend recommended this site.
I've run farbar (files below) in Systems Recovery Options using Windows Installation Disc.
When I clicked 'Repair your computer' there was an automatic scan for problems, which suggested a repair and reported the following:
--------------------------
Repair details:
The following startup option will be repaired:
Name: Windows Boot Manager
Identifier: {9DEA862C-5CDD-4E70-ACC1-F32B344D4795}
Name: Windows Recovery Environment (recovered)
Path: Recovery\375044d2-f9d9-11df-945b-a8cfbde69105\Winre.wim
Windows Device: Partition=C: (1907627 MB)
A copy of the current boot configuration data will be saved as: C:\Boot\BCD.Backup.0001
--------------------------
I did not repair and reboot, but instead cancelled (fearing more damage) and then ran the farbar scan and a search generating the logs - frst.txt and search.txt ...
FRST.TXT
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 08-08-2012 00:06:23
Running from F:\
Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet003
========================== Registry (Whitelisted) =============
HKLM\...\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" [17408 2010-07-04] ()
HKLM\...\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r [1733120 2010-01-17] (VIA)
HKLM\...\Run: [VIAAUD] C:\Program Files\VIA\VIAudioi\VDeck\VIAAUD.exe [x]
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [1043968 2010-11-16] (Check Point Software Technologies LTD)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\praAnkster\...\Run: [Google Update] "C:\Users\praAnkster\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-11-26] (Google Inc.)
HKU\praAnkster\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [354304 2009-07-13] (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 ERDAS-Net License Server; C:\Program Files\ERDAS\Shared\licensing\bin\ntx86\lmgrd.exe [1423440 2009-11-11] (Macrovision Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 vsmon; C:\Windows\System32\ZoneLabs\vsmon.exe -service [2435592 2010-11-16] (Check Point Software Technologies LTD)
3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 AEILAB; C:\Windows\System32\DRIVERS\AEILAB.SYS [24299 2000-09-05] (USB2LAN Provider)
3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.)
1 archlp; C:\Windows\System32\drivers\archlp.sys [96384 2008-08-12] ()
3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-13] (Microsoft Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 Nsynas32; C:\Windows\System32\Drivers\Nsynas32.sys [17784 2001-04-09] (Syncrosoft Hard- und Software GmbH)
1 RapportCerberus_34302; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [228208 2011-12-15] ()
3 RapportIaso; \??\c:\programdata\trusteer\rapport\store\exts\rapportms\39624\rapportiaso.sys [21520 2012-05-28] (Trusteer Ltd.)
0 RapportKELL; C:\Windows\System32\Drivers\RapportKELL.sys [65752 2012-07-07] (Trusteer Ltd.)
3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1119232 2010-01-11] (VIA Technologies, Inc.)
1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [461400 2010-05-15] (Check Point Software Technologies LTD)
3 FXDrv32; \??\D:\FXDrv32.sys [x]
1 RapportEI; \??\C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [x]
1 RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 19:36 - 2012-08-06 19:50 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-08-06 16:16 - 2012-08-06 16:16 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-06 06:58 - 2012-08-06 06:58 - 00000186 ____A C:\Users\praAnkster\Desktop\New shortcut.lnk
2012-08-06 06:54 - 2012-08-06 06:54 - 00023288 ____A C:\Users\praAnkster\Desktop\FRST.txt
2012-08-03 06:17 - 2012-08-06 06:53 - 00002843 ____A C:\Users\praAnkster\Desktop\FRST_.txt
2012-08-02 14:17 - 2012-08-06 06:54 - 00000000 ____D C:\FRST
2012-08-02 14:17 - 2012-08-02 14:17 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\oyzqmrff.sys
2012-08-02 12:20 - 2012-08-02 12:20 - 00892822 ____A (Farbar) C:\Users\praAnkster\Desktop\FRST.exe
2012-08-02 09:10 - 2012-08-02 09:10 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\orniwxlf.sys
2012-08-02 07:49 - 2012-08-02 07:49 - 00002057 ____A C:\Users\praAnkster\Desktop\RKreport[20].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002052 ____A C:\Users\praAnkster\Desktop\RKreport[19].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002019 ____A C:\Users\praAnkster\Desktop\RKreport[18].txt
2012-08-02 06:52 - 2012-08-02 06:52 - 00002176 ____A C:\Users\praAnkster\Desktop\RKreport[17].txt
2012-08-02 06:51 - 2012-08-02 06:51 - 00002143 ____A C:\Users\praAnkster\Desktop\RKreport[16].txt
2012-08-02 06:26 - 2012-08-02 06:26 - 00000000 ____D C:\Windows\System32\MpEngineStore
2012-08-02 05:02 - 2012-08-02 05:02 - 00002136 ____A C:\Users\praAnkster\Desktop\RKreport[15].txt
2012-08-02 05:01 - 2012-08-02 05:01 - 00002103 ____A C:\Users\praAnkster\Desktop\RKreport[14].txt
2012-08-02 04:57 - 2012-08-02 04:57 - 00001936 ____A C:\Users\praAnkster\Desktop\RKreport[13].txt
2012-08-02 04:56 - 2012-08-02 04:56 - 00001903 ____A C:\Users\praAnkster\Desktop\RKreport[12].txt
2012-08-02 03:08 - 2012-08-02 03:08 - 00001898 ____A C:\Users\praAnkster\Desktop\RKreport[11].txt
2012-08-02 03:07 - 2012-08-02 03:07 - 00001863 ____A C:\Users\praAnkster\Desktop\RKreport[10].txt
2012-08-01 14:49 - 2012-08-01 14:49 - 00001857 ____A C:\Users\praAnkster\Desktop\RKreport[9].txt
2012-08-01 14:48 - 2012-08-01 14:48 - 00001825 ____A C:\Users\praAnkster\Desktop\RKreport[8].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00001807 ____A C:\Users\praAnkster\Desktop\RKreport[7].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00000615 ____A C:\Users\praAnkster\Desktop\RKreport[6].txt
2012-08-01 11:44 - 2012-08-01 11:44 - 00001769 ____A C:\Users\praAnkster\Desktop\RKreport[5].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00001751 ____A C:\Users\praAnkster\Desktop\RKreport[4].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00000855 ____A C:\Users\praAnkster\Desktop\RKreport[3].txt
2012-08-01 11:08 - 2012-08-01 11:08 - 00001999 ____A C:\Users\praAnkster\Desktop\RKreport[2].txt
2012-08-01 11:05 - 2012-08-01 11:05 - 00139856 ____A C:\Windows\Minidump\080112-23150-01.dmp
2012-08-01 11:03 - 2012-08-01 11:03 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1].txt
2012-08-01 10:58 - 2012-08-01 10:59 - 00144072 ____A C:\Windows\Minidump\080112-23821-01.dmp
2012-08-01 07:44 - 2012-08-01 07:44 - 00002567 ____A C:\Users\praAnkster\Desktop\RKreport[10]_2.txt
2012-08-01 03:57 - 2012-08-01 03:57 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[7]_2.txt
2012-08-01 03:56 - 2012-08-01 03:56 - 00001952 ____A C:\Users\praAnkster\Desktop\RKreport[6]_2.txt
2012-07-31 16:37 - 2012-07-31 16:37 - 00002106 ____A C:\Users\praAnkster\Desktop\RKreport[4]_2.txt
2012-07-31 16:36 - 2012-07-31 16:36 - 00002038 ____A C:\Users\praAnkster\Desktop\RKreport[3]_2.txt
2012-07-31 14:59 - 2012-07-31 14:59 - 00002070 ____A C:\Users\praAnkster\Desktop\RKreport[2]_2.txt
2012-07-31 14:58 - 2012-07-31 14:58 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1]_2.txt
2012-07-31 14:54 - 2012-07-31 14:54 - 00000053 ____A C:\Users\praAnkster\AppData\Roaming\mbam.context.scan
2012-07-31 14:49 - 2012-07-31 14:49 - 00420800 ___AH C:\Windows\System32\Drivers\vsconfig.xml
2012-07-31 14:49 - 2012-07-31 14:49 - 00000000 ____D C:\Windows\System32\ZoneLabs
2012-07-31 14:49 - 2010-11-16 08:45 - 01238528 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zpeng25.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00302592 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vspubapi.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00112128 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsdata.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00110080 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsxml.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00108032 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsmonapi.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00104448 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zlcommdb.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00069120 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zlcomm.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00058368 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsregexp.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00043008 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vswmi.dll
2012-07-31 14:49 - 2010-05-15 07:30 - 00461400 ____A (Check Point Software Technologies LTD) C:\Windows\System32\Drivers\vsdatant.sys
2012-07-31 14:48 - 2012-07-31 14:48 - 00000000 ____D C:\Program Files\Zone Labs
2012-07-31 14:48 - 2010-11-16 08:45 - 00715264 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsutil.dll
2012-07-31 14:48 - 2010-11-16 08:45 - 00228864 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsinit.dll
2012-07-31 11:54 - 2012-08-01 08:31 - 00000000 ____D C:\Users\praAnkster\Desktop\RK reports
2012-07-31 07:30 - 2012-07-31 07:30 - 00144072 ____A C:\Windows\Minidump\073112-25630-01.dmp
2012-07-31 07:26 - 2012-07-31 07:26 - 00000000 ____D C:\Users\All Users\ZA_PreservedFiles
2012-07-30 13:49 - 2012-07-30 13:50 - 00144072 ____A C:\Windows\Minidump\073012-23946-01.dmp
2012-07-30 12:57 - 2012-08-02 07:49 - 00000000 ____D C:\Users\praAnkster\Desktop\RK_Quarantine
2012-07-30 12:56 - 2012-07-30 12:56 - 01552384 ____A C:\Users\praAnkster\Desktop\RogueKiller.exe
2012-07-30 11:37 - 2012-07-30 11:37 - 00000000 ____D C:\Users\All Users\CheckPoint
2012-07-30 11:03 - 2012-07-30 11:03 - 00144072 ____A C:\Windows\Minidump\073012-33852-01.dmp
2012-07-30 09:10 - 2012-07-30 09:11 - 00144072 ____A C:\Windows\Minidump\073012-24632-01.dmp
2012-07-30 08:49 - 2012-07-30 08:49 - 00000000 ____D C:\Users\praAnkster\AppData\Roaming\Malwarebytes
2012-07-30 08:48 - 2012-07-30 11:08 - 00001176 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 08:48 - 2012-07-30 08:59 - 00000000 ____D C:\Program Files\DESTROY Malwarebytes' Anti-Malware
2012-07-30 08:48 - 2012-07-30 08:48 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-30 08:48 - 2012-07-03 04:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-30 08:36 - 2012-07-30 08:36 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 08:29 - 2012-07-30 08:29 - 00144072 ____A C:\Windows\Minidump\073012-36629-01.dmp
2012-07-30 08:23 - 2012-07-30 08:23 - 00000000 ____D C:\Users\praAnkster\AppData\Local\{E3DE8E83-DA62-11E1-8270-B8AC6F996F26}
2012-07-30 08:22 - 2012-07-30 08:22 - 00000012 ____A C:\Windows\srun.log
2012-07-30 08:01 - 2012-08-01 10:56 - 00738286 ____A C:\Users\praAnkster\AppData\Local\hfwiudnu.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00135507 ____A C:\Users\praAnkster\AppData\Local\tardhnsx.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00003247 ____A C:\Users\praAnkster\AppData\Local\xoksmwpv.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00002865 ____A C:\Users\praAnkster\AppData\Local\rhbguoor.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00004048 ____A C:\Users\praAnkster\AppData\Local\kxuagrty.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\hwlonyvp.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\brdepvjb.log
2012-07-30 07:58 - 2012-08-01 14:43 - 00000000 ____D C:\Users\praAnkster\AppData\Local\vfvwxwct
2012-07-30 07:58 - 2012-08-01 10:57 - 00000024 ____A C:\Users\praAnkster\AppData\Local\foafbyde.log
2012-07-30 07:58 - 2012-07-30 08:00 - 00440304 ____A C:\Users\praAnkster\AppData\Local\gfhpwvke.log
2012-07-30 07:58 - 2012-07-30 07:58 - 00000064 ____A C:\Users\All Users\spiaynhf.log
2012-07-27 07:27 - 2012-07-27 07:27 - 03028656 ____A (TeamViewer) C:\Users\praAnkster\Downloads\TeamViewerQS_en.exe
2012-07-27 07:15 - 2012-07-27 08:00 - 00000000 ____D C:\Users\praAnkster\AppData\Roaming\TeamViewer
2012-07-27 07:13 - 2012-07-27 07:13 - 03610576 ____A (TeamViewer GmbH) C:\Users\praAnkster\Downloads\TeamViewer_Setup_en.exe
2012-07-23 09:22 - 2012-07-23 09:23 - 00000000 ____D C:\CV
2012-07-21 10:08 - 2012-07-21 10:08 - 00000000 ____D C:\New folder
2012-07-19 14:56 - 2012-07-19 14:56 - 00001028 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-19 14:53 - 2012-07-19 14:53 - 04411280 ____A C:\Users\praAnkster\Downloads\fallen.ogg
2012-07-19 12:29 - 2012-07-24 03:28 - 00000000 ____D C:\TV and Radio
2012-07-17 04:11 - 2012-07-17 04:11 - 00132428 ____A C:\Users\praAnkster\Desktop\important.jpg-large
2012-07-14 09:12 - 2012-07-14 09:12 - 02456064 ____A C:\Users\praAnkster\Documents\Radiance MET Office - Matricardi_TC_2012.ppt
2012-07-13 14:04 - 2012-07-23 07:25 - 00000000 ____D C:\Users\praAnkster\Documents\Olympic cycling road race and sailing
2012-07-12 12:45 - 2012-07-22 06:23 - 00000000 ____D C:\Users\praAnkster\Documents\Invoices
============ 3 Months Modified Files ========================
2012-08-07 09:31 - 2012-08-07 09:31 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\znwtofdo.sys
2012-08-07 09:31 - 2010-11-28 07:59 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-07 09:30 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 09:29 - 2009-07-13 20:39 - 00378509 ____A C:\Windows\setupact.log
2012-08-06 06:58 - 2012-08-06 06:58 - 00000186 ____A C:\Users\praAnkster\Desktop\New shortcut.lnk
2012-08-06 06:54 - 2012-08-06 06:54 - 00023288 ____A C:\Users\praAnkster\Desktop\FRST.txt
2012-08-06 06:53 - 2012-08-03 06:17 - 00002843 ____A C:\Users\praAnkster\Desktop\FRST_.txt
2012-08-06 06:48 - 2010-11-28 07:59 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-03 06:38 - 2010-11-26 12:00 - 00733518 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 14:17 - 2012-08-02 14:17 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\oyzqmrff.sys
2012-08-02 12:20 - 2012-08-02 12:20 - 00892822 ____A (Farbar) C:\Users\praAnkster\Desktop\FRST.exe
2012-08-02 09:10 - 2012-08-02 09:10 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\orniwxlf.sys
2012-08-02 07:49 - 2012-08-02 07:49 - 00002057 ____A C:\Users\praAnkster\Desktop\RKreport[20].txt
2012-08-02 07:37 - 2012-04-10 07:11 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-02 07:37 - 2010-11-26 12:49 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3402657652-3708558674-1240141188-1000UA.job
2012-08-02 07:26 - 2011-02-06 05:50 - 00020386 ____A C:\Windows\PFRO.log
2012-08-02 07:24 - 2012-08-02 07:24 - 00002052 ____A C:\Users\praAnkster\Desktop\RKreport[19].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002019 ____A C:\Users\praAnkster\Desktop\RKreport[18].txt
2012-08-02 06:56 - 2011-04-05 03:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-02 06:52 - 2012-08-02 06:52 - 00002176 ____A C:\Users\praAnkster\Desktop\RKreport[17].txt
2012-08-02 06:51 - 2012-08-02 06:51 - 00002143 ____A C:\Users\praAnkster\Desktop\RKreport[16].txt
2012-08-02 06:36 - 2009-07-13 20:34 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-02 06:36 - 2009-07-13 20:34 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-02 05:02 - 2012-08-02 05:02 - 00002136 ____A C:\Users\praAnkster\Desktop\RKreport[15].txt
2012-08-02 05:01 - 2012-08-02 05:01 - 00002103 ____A C:\Users\praAnkster\Desktop\RKreport[14].txt
2012-08-02 04:57 - 2012-08-02 04:57 - 00001936 ____A C:\Users\praAnkster\Desktop\RKreport[13].txt
2012-08-02 04:56 - 2012-08-02 04:56 - 00001903 ____A C:\Users\praAnkster\Desktop\RKreport[12].txt
2012-08-02 03:08 - 2012-08-02 03:08 - 00001898 ____A C:\Users\praAnkster\Desktop\RKreport[11].txt
2012-08-02 03:07 - 2012-08-02 03:07 - 00001863 ____A C:\Users\praAnkster\Desktop\RKreport[10].txt
2012-08-01 14:49 - 2012-08-01 14:49 - 00001857 ____A C:\Users\praAnkster\Desktop\RKreport[9].txt
2012-08-01 14:48 - 2012-08-01 14:48 - 00001825 ____A C:\Users\praAnkster\Desktop\RKreport[8].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00001807 ____A C:\Users\praAnkster\Desktop\RKreport[7].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00000615 ____A C:\Users\praAnkster\Desktop\RKreport[6].txt
2012-08-01 11:44 - 2012-08-01 11:44 - 00001769 ____A C:\Users\praAnkster\Desktop\RKreport[5].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00001751 ____A C:\Users\praAnkster\Desktop\RKreport[4].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00000855 ____A C:\Users\praAnkster\Desktop\RKreport[3].txt
2012-08-01 11:08 - 2012-08-01 11:08 - 00001999 ____A C:\Users\praAnkster\Desktop\RKreport[2].txt
2012-08-01 11:05 - 2012-08-01 11:05 - 00139856 ____A C:\Windows\Minidump\080112-23150-01.dmp
2012-08-01 11:05 - 2011-04-25 11:37 - 232493646 ____A C:\Windows\MEMORY.DMP
2012-08-01 11:03 - 2012-08-01 11:03 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1].txt
2012-08-01 10:59 - 2012-08-01 10:58 - 00144072 ____A C:\Windows\Minidump\080112-23821-01.dmp
2012-08-01 10:57 - 2012-07-30 07:58 - 00000024 ____A C:\Users\praAnkster\AppData\Local\foafbyde.log
2012-08-01 10:56 - 2012-07-30 08:01 - 00738286 ____A C:\Users\praAnkster\AppData\Local\hfwiudnu.log
2012-08-01 07:44 - 2012-08-01 07:44 - 00002567 ____A C:\Users\praAnkster\Desktop\RKreport[10]_2.txt
2012-08-01 03:57 - 2012-08-01 03:57 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[7]_2.txt
2012-08-01 03:56 - 2012-08-01 03:56 - 00001952 ____A C:\Users\praAnkster\Desktop\RKreport[6]_2.txt
2012-07-31 16:37 - 2012-07-31 16:37 - 00002106 ____A C:\Users\praAnkster\Desktop\RKreport[4]_2.txt
2012-07-31 16:36 - 2012-07-31 16:36 - 00002038 ____A C:\Users\praAnkster\Desktop\RKreport[3]_2.txt
2012-07-31 14:59 - 2012-07-31 14:59 - 00002070 ____A C:\Users\praAnkster\Desktop\RKreport[2]_2.txt
2012-07-31 14:58 - 2012-07-31 14:58 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1]_2.txt
2012-07-31 14:54 - 2012-07-31 14:54 - 00000053 ____A C:\Users\praAnkster\AppData\Roaming\mbam.context.scan
2012-07-31 14:49 - 2012-07-31 14:49 - 00420800 ___AH C:\Windows\System32\Drivers\vsconfig.xml
2012-07-31 14:49 - 2010-11-26 11:52 - 01166814 ____A C:\Windows\WindowsUpdate.log
2012-07-31 07:30 - 2012-07-31 07:30 - 00144072 ____A C:\Windows\Minidump\073112-25630-01.dmp
2012-07-30 13:50 - 2012-07-30 13:49 - 00144072 ____A C:\Windows\Minidump\073012-23946-01.dmp
2012-07-30 12:56 - 2012-07-30 12:56 - 01552384 ____A C:\Users\praAnkster\Desktop\RogueKiller.exe
2012-07-30 11:08 - 2012-07-30 08:48 - 00001176 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 11:03 - 2012-07-30 11:03 - 00144072 ____A C:\Windows\Minidump\073012-33852-01.dmp
2012-07-30 09:11 - 2012-07-30 09:10 - 00144072 ____A C:\Windows\Minidump\073012-24632-01.dmp
2012-07-30 08:29 - 2012-07-30 08:29 - 00144072 ____A C:\Windows\Minidump\073012-36629-01.dmp
2012-07-30 08:22 - 2012-07-30 08:22 - 00000012 ____A C:\Windows\srun.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00135507 ____A C:\Users\praAnkster\AppData\Local\tardhnsx.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00003247 ____A C:\Users\praAnkster\AppData\Local\xoksmwpv.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00002865 ____A C:\Users\praAnkster\AppData\Local\rhbguoor.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00004048 ____A C:\Users\praAnkster\AppData\Local\kxuagrty.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\hwlonyvp.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\brdepvjb.log
2012-07-30 08:00 - 2012-07-30 07:58 - 00440304 ____A C:\Users\praAnkster\AppData\Local\gfhpwvke.log
2012-07-30 07:58 - 2012-07-30 07:58 - 00000064 ____A C:\Users\All Users\spiaynhf.log
2012-07-29 14:24 - 2010-11-26 12:49 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3402657652-3708558674-1240141188-1000Core.job
2012-07-27 07:27 - 2012-07-27 07:27 - 03028656 ____A (TeamViewer) C:\Users\praAnkster\Downloads\TeamViewerQS_en.exe
2012-07-27 07:13 - 2012-07-27 07:13 - 03610576 ____A (TeamViewer GmbH) C:\Users\praAnkster\Downloads\TeamViewer_Setup_en.exe
2012-07-27 01:34 - 2012-04-10 07:11 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 01:34 - 2011-06-17 12:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-25 05:02 - 2011-01-10 04:39 - 00001524 ____A C:\Users\praAnkster\Desktop\stuff.txt
2012-07-19 14:56 - 2012-07-19 14:56 - 00001028 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-19 14:53 - 2012-07-19 14:53 - 04411280 ____A C:\Users\praAnkster\Downloads\fallen.ogg
2012-07-17 04:11 - 2012-07-17 04:11 - 00132428 ____A C:\Users\praAnkster\Desktop\important.jpg-large
2012-07-16 02:25 - 2011-02-27 10:41 - 00000000 ____A C:\Windows\System32\synsopos.soj
2012-07-14 09:59 - 2010-12-18 16:27 - 00007602 ____A C:\Users\praAnkster\AppData\Local\Resmon.ResmonCfg
2012-07-14 09:12 - 2012-07-14 09:12 - 02456064 ____A C:\Users\praAnkster\Documents\Radiance MET Office - Matricardi_TC_2012.ppt
2012-07-07 22:19 - 2012-07-07 22:19 - 00065752 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKELL.sys
2012-07-07 05:59 - 2012-07-07 05:37 - 1796533693 ____A C:\Users\praAnkster\Downloads\Wimbledon_2012_30_06_2012_b01ks80t_1341108740.wmv
2012-07-07 04:34 - 2012-07-07 04:34 - 00000228 ____A C:\Users\praAnkster\.swfinfo
2012-07-06 16:25 - 2012-07-06 16:25 - 08288706 ____A C:\Users\praAnkster\Downloads\ipdl.exe
2012-07-06 16:11 - 2012-07-06 16:11 - 06761918 ____A C:\Users\praAnkster\Downloads\get_iplayer_setup_latest.exe
2012-07-03 09:21 - 2012-07-03 09:21 - 00004096 ___AH C:\Users\praAnkster\AppData\Local\keyfile3.drm
2012-07-03 04:46 - 2012-07-30 08:48 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 18:13 - 2010-11-26 13:00 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-07 08:08 - 2012-06-07 08:08 - 01383424 ____A C:\Users\praAnkster\Downloads\eggsurvey2007.xls
2012-06-02 14:19 - 2012-06-21 04:31 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 04:31 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 04:31 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 04:30 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 04:30 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 04:31 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 04:30 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-21 04:30 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-21 04:30 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-30 07:36 - 2012-05-30 07:36 - 04886564 ____A C:\Users\praAnkster\Downloads\Pictures from St. Kitts.zip
2012-05-28 12:15 - 2012-05-28 12:15 - 00972893 ____A C:\Users\praAnkster\Downloads\spoty honda (3).zip
2012-05-28 12:14 - 2012-05-28 12:14 - 00000000 ____A C:\Users\praAnkster\Downloads\spoty honda (2).zip.crdownload
2012-05-28 12:14 - 2012-05-28 12:14 - 00000000 ____A C:\Users\praAnkster\Downloads\spoty honda (1).zip.crdownload
2012-05-28 12:13 - 2012-05-28 12:13 - 00972893 ____A C:\Users\praAnkster\Downloads\spoty honda.zip
2012-05-26 13:15 - 2009-07-13 20:53 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-21 11:15 - 2012-05-21 11:15 - 00615072 ____A C:\Users\praAnkster\Downloads\car.zip
2012-05-20 15:34 - 2012-05-20 15:34 - 00012922 ____A C:\Users\praAnkster\Downloads\Final_HDTV_X264-SuperS-((www.Demonoid.me)).torrent
2012-05-14 14:03 - 2012-05-14 14:03 - 00001563 ____A C:\Windows\System32\Frequency-of-precipitation-and-temperature-extremes-over-France-in-an-anthropogenic-scenario-Model-results-and-statistical-correction-according-to-observed-values_2007_Global-and-Planetary-Change.lnk
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3839.18 MB
Available physical RAM: 3297.98 MB
Total Pagefile: 3837.46 MB
Available Pagefile: 3308.11 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.21 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:1862.92 GB) (Free:1737.11 GB) NTFS
2 Drive e: () (Removable) (Total:14.92 GB) (Free:12.42 GB) NTFS
3 Drive f: () (Removable) (Total:0.98 GB) (Free:0.07 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1863 GB 0 B
Disk 1 Online 14 GB 0 B
Disk 2 Online 1003 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 1862 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 1862 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 22 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Removable 14 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1002 MB 16 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT Removable 1002 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 05:19
======================= End Of Log ==========================
SEARCH.TXT
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-08 00:08:24
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
THANKS IN ADVANCE FOR ANY HELP!!! Matt
Hello and thanks in advance for any help!
I have the same problem as many others - I appear to have the Zeroaccess virus, variants of Win32/Sirefef and following the reinstall of MSE a system that reboots every couple of minutes even in safe mode (although it takes a little longer). I tried a few tools before a friend recommended this forum - then I ran farbar in System Recovery Option (files below).
The full story if it is useful...
It all started after getting redirects using Chrome web browser, and then couldnt access sites such as Microsoft and Sophos. MSE detected a virus but disappeared before I could read what it was. On next boot I could not get MSE service to start, and the firewall was down both giving error messages.
I tried Rogue Killer which identified Zeroaccess in desktop.ini and in services.exe that it could not fix. MBAM also found Zeroaccess. I also lost my network connection - Rogue Killer reported a problem with DNS.
The Microsoft website recommended using their Safety Scanner and MSE. Safety scanner detected Win32/Sirefef.R in services.exe.
I reinstalled MSE. Sirefef.R was detected as above and 'disinfected', Win32/Sirefef.AH was 'removed'. On reboot Win32/Sirefef.AB was detected and since then get a 'Windows has encountered a critical error' after a couple of minutes and the system reboots.
I managed to run TDSSKiller, which found and quarantined 5 objects (log file attached). This did not appear to make any difference to the situation. I then tried Kaspersky Rescue Disk 10 which found no problems. At that point I was contemplating a reinstall, until a friend recommended this site.
I've run farbar (files below) in Systems Recovery Options using Windows Installation Disc.
When I clicked 'Repair your computer' there was an automatic scan for problems, which suggested a repair and reported the following:
--------------------------
Repair details:
The following startup option will be repaired:
Name: Windows Boot Manager
Identifier: {9DEA862C-5CDD-4E70-ACC1-F32B344D4795}
Name: Windows Recovery Environment (recovered)
Path: Recovery\375044d2-f9d9-11df-945b-a8cfbde69105\Winre.wim
Windows Device: Partition=C: (1907627 MB)
A copy of the current boot configuration data will be saved as: C:\Boot\BCD.Backup.0001
--------------------------
I did not repair and reboot, but instead cancelled (fearing more damage) and then ran the farbar scan and a search generating the logs - frst.txt and search.txt ...
FRST.TXT
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 08-08-2012 00:06:23
Running from F:\
Windows 7 Ultimate Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet003
========================== Registry (Whitelisted) =============
HKLM\...\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" [17408 2010-07-04] ()
HKLM\...\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r [1733120 2010-01-17] (VIA)
HKLM\...\Run: [VIAAUD] C:\Program Files\VIA\VIAudioi\VDeck\VIAAUD.exe [x]
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [1043968 2010-11-16] (Check Point Software Technologies LTD)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\praAnkster\...\Run: [Google Update] "C:\Users\praAnkster\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-11-26] (Google Inc.)
HKU\praAnkster\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [354304 2009-07-13] (Microsoft Corporation)
================================ Services (Whitelisted) ==================
2 ERDAS-Net License Server; C:\Program Files\ERDAS\Shared\licensing\bin\ntx86\lmgrd.exe [1423440 2009-11-11] (Macrovision Corporation)
2 eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 2009-07-13] (Microsoft Corporation)
2 vsmon; C:\Windows\System32\ZoneLabs\vsmon.exe -service [2435592 2010-11-16] (Check Point Software Technologies LTD)
3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 AEILAB; C:\Windows\System32\DRIVERS\AEILAB.SYS [24299 2000-09-05] (USB2LAN Provider)
3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.)
1 archlp; C:\Windows\System32\drivers\archlp.sys [96384 2008-08-12] ()
3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-13] (Microsoft Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
2 Nsynas32; C:\Windows\System32\Drivers\Nsynas32.sys [17784 2001-04-09] (Syncrosoft Hard- und Software GmbH)
1 RapportCerberus_34302; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys [228208 2011-12-15] ()
3 RapportIaso; \??\c:\programdata\trusteer\rapport\store\exts\rapportms\39624\rapportiaso.sys [21520 2012-05-28] (Trusteer Ltd.)
0 RapportKELL; C:\Windows\System32\Drivers\RapportKELL.sys [65752 2012-07-07] (Trusteer Ltd.)
3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1119232 2010-01-11] (VIA Technologies, Inc.)
1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [461400 2010-05-15] (Check Point Software Technologies LTD)
3 FXDrv32; \??\D:\FXDrv32.sys [x]
1 RapportEI; \??\C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [x]
1 RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [x]
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-06 19:36 - 2012-08-06 19:50 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-08-06 16:16 - 2012-08-06 16:16 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-08-06 06:58 - 2012-08-06 06:58 - 00000186 ____A C:\Users\praAnkster\Desktop\New shortcut.lnk
2012-08-06 06:54 - 2012-08-06 06:54 - 00023288 ____A C:\Users\praAnkster\Desktop\FRST.txt
2012-08-03 06:17 - 2012-08-06 06:53 - 00002843 ____A C:\Users\praAnkster\Desktop\FRST_.txt
2012-08-02 14:17 - 2012-08-06 06:54 - 00000000 ____D C:\FRST
2012-08-02 14:17 - 2012-08-02 14:17 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\oyzqmrff.sys
2012-08-02 12:20 - 2012-08-02 12:20 - 00892822 ____A (Farbar) C:\Users\praAnkster\Desktop\FRST.exe
2012-08-02 09:10 - 2012-08-02 09:10 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\orniwxlf.sys
2012-08-02 07:49 - 2012-08-02 07:49 - 00002057 ____A C:\Users\praAnkster\Desktop\RKreport[20].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002052 ____A C:\Users\praAnkster\Desktop\RKreport[19].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002019 ____A C:\Users\praAnkster\Desktop\RKreport[18].txt
2012-08-02 06:52 - 2012-08-02 06:52 - 00002176 ____A C:\Users\praAnkster\Desktop\RKreport[17].txt
2012-08-02 06:51 - 2012-08-02 06:51 - 00002143 ____A C:\Users\praAnkster\Desktop\RKreport[16].txt
2012-08-02 06:26 - 2012-08-02 06:26 - 00000000 ____D C:\Windows\System32\MpEngineStore
2012-08-02 05:02 - 2012-08-02 05:02 - 00002136 ____A C:\Users\praAnkster\Desktop\RKreport[15].txt
2012-08-02 05:01 - 2012-08-02 05:01 - 00002103 ____A C:\Users\praAnkster\Desktop\RKreport[14].txt
2012-08-02 04:57 - 2012-08-02 04:57 - 00001936 ____A C:\Users\praAnkster\Desktop\RKreport[13].txt
2012-08-02 04:56 - 2012-08-02 04:56 - 00001903 ____A C:\Users\praAnkster\Desktop\RKreport[12].txt
2012-08-02 03:08 - 2012-08-02 03:08 - 00001898 ____A C:\Users\praAnkster\Desktop\RKreport[11].txt
2012-08-02 03:07 - 2012-08-02 03:07 - 00001863 ____A C:\Users\praAnkster\Desktop\RKreport[10].txt
2012-08-01 14:49 - 2012-08-01 14:49 - 00001857 ____A C:\Users\praAnkster\Desktop\RKreport[9].txt
2012-08-01 14:48 - 2012-08-01 14:48 - 00001825 ____A C:\Users\praAnkster\Desktop\RKreport[8].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00001807 ____A C:\Users\praAnkster\Desktop\RKreport[7].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00000615 ____A C:\Users\praAnkster\Desktop\RKreport[6].txt
2012-08-01 11:44 - 2012-08-01 11:44 - 00001769 ____A C:\Users\praAnkster\Desktop\RKreport[5].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00001751 ____A C:\Users\praAnkster\Desktop\RKreport[4].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00000855 ____A C:\Users\praAnkster\Desktop\RKreport[3].txt
2012-08-01 11:08 - 2012-08-01 11:08 - 00001999 ____A C:\Users\praAnkster\Desktop\RKreport[2].txt
2012-08-01 11:05 - 2012-08-01 11:05 - 00139856 ____A C:\Windows\Minidump\080112-23150-01.dmp
2012-08-01 11:03 - 2012-08-01 11:03 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1].txt
2012-08-01 10:58 - 2012-08-01 10:59 - 00144072 ____A C:\Windows\Minidump\080112-23821-01.dmp
2012-08-01 07:44 - 2012-08-01 07:44 - 00002567 ____A C:\Users\praAnkster\Desktop\RKreport[10]_2.txt
2012-08-01 03:57 - 2012-08-01 03:57 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[7]_2.txt
2012-08-01 03:56 - 2012-08-01 03:56 - 00001952 ____A C:\Users\praAnkster\Desktop\RKreport[6]_2.txt
2012-07-31 16:37 - 2012-07-31 16:37 - 00002106 ____A C:\Users\praAnkster\Desktop\RKreport[4]_2.txt
2012-07-31 16:36 - 2012-07-31 16:36 - 00002038 ____A C:\Users\praAnkster\Desktop\RKreport[3]_2.txt
2012-07-31 14:59 - 2012-07-31 14:59 - 00002070 ____A C:\Users\praAnkster\Desktop\RKreport[2]_2.txt
2012-07-31 14:58 - 2012-07-31 14:58 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1]_2.txt
2012-07-31 14:54 - 2012-07-31 14:54 - 00000053 ____A C:\Users\praAnkster\AppData\Roaming\mbam.context.scan
2012-07-31 14:49 - 2012-07-31 14:49 - 00420800 ___AH C:\Windows\System32\Drivers\vsconfig.xml
2012-07-31 14:49 - 2012-07-31 14:49 - 00000000 ____D C:\Windows\System32\ZoneLabs
2012-07-31 14:49 - 2010-11-16 08:45 - 01238528 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zpeng25.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00302592 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vspubapi.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00112128 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsdata.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00110080 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsxml.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00108032 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsmonapi.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00104448 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zlcommdb.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00069120 ____A (Check Point Software Technologies LTD) C:\Windows\System32\zlcomm.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00058368 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsregexp.dll
2012-07-31 14:49 - 2010-11-16 08:45 - 00043008 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vswmi.dll
2012-07-31 14:49 - 2010-05-15 07:30 - 00461400 ____A (Check Point Software Technologies LTD) C:\Windows\System32\Drivers\vsdatant.sys
2012-07-31 14:48 - 2012-07-31 14:48 - 00000000 ____D C:\Program Files\Zone Labs
2012-07-31 14:48 - 2010-11-16 08:45 - 00715264 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsutil.dll
2012-07-31 14:48 - 2010-11-16 08:45 - 00228864 ____A (Check Point Software Technologies LTD) C:\Windows\System32\vsinit.dll
2012-07-31 11:54 - 2012-08-01 08:31 - 00000000 ____D C:\Users\praAnkster\Desktop\RK reports
2012-07-31 07:30 - 2012-07-31 07:30 - 00144072 ____A C:\Windows\Minidump\073112-25630-01.dmp
2012-07-31 07:26 - 2012-07-31 07:26 - 00000000 ____D C:\Users\All Users\ZA_PreservedFiles
2012-07-30 13:49 - 2012-07-30 13:50 - 00144072 ____A C:\Windows\Minidump\073012-23946-01.dmp
2012-07-30 12:57 - 2012-08-02 07:49 - 00000000 ____D C:\Users\praAnkster\Desktop\RK_Quarantine
2012-07-30 12:56 - 2012-07-30 12:56 - 01552384 ____A C:\Users\praAnkster\Desktop\RogueKiller.exe
2012-07-30 11:37 - 2012-07-30 11:37 - 00000000 ____D C:\Users\All Users\CheckPoint
2012-07-30 11:03 - 2012-07-30 11:03 - 00144072 ____A C:\Windows\Minidump\073012-33852-01.dmp
2012-07-30 09:10 - 2012-07-30 09:11 - 00144072 ____A C:\Windows\Minidump\073012-24632-01.dmp
2012-07-30 08:49 - 2012-07-30 08:49 - 00000000 ____D C:\Users\praAnkster\AppData\Roaming\Malwarebytes
2012-07-30 08:48 - 2012-07-30 11:08 - 00001176 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 08:48 - 2012-07-30 08:59 - 00000000 ____D C:\Program Files\DESTROY Malwarebytes' Anti-Malware
2012-07-30 08:48 - 2012-07-30 08:48 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-30 08:48 - 2012-07-03 04:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-30 08:36 - 2012-07-30 08:36 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-30 08:29 - 2012-07-30 08:29 - 00144072 ____A C:\Windows\Minidump\073012-36629-01.dmp
2012-07-30 08:23 - 2012-07-30 08:23 - 00000000 ____D C:\Users\praAnkster\AppData\Local\{E3DE8E83-DA62-11E1-8270-B8AC6F996F26}
2012-07-30 08:22 - 2012-07-30 08:22 - 00000012 ____A C:\Windows\srun.log
2012-07-30 08:01 - 2012-08-01 10:56 - 00738286 ____A C:\Users\praAnkster\AppData\Local\hfwiudnu.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00135507 ____A C:\Users\praAnkster\AppData\Local\tardhnsx.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00003247 ____A C:\Users\praAnkster\AppData\Local\xoksmwpv.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00002865 ____A C:\Users\praAnkster\AppData\Local\rhbguoor.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00004048 ____A C:\Users\praAnkster\AppData\Local\kxuagrty.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\hwlonyvp.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\brdepvjb.log
2012-07-30 07:58 - 2012-08-01 14:43 - 00000000 ____D C:\Users\praAnkster\AppData\Local\vfvwxwct
2012-07-30 07:58 - 2012-08-01 10:57 - 00000024 ____A C:\Users\praAnkster\AppData\Local\foafbyde.log
2012-07-30 07:58 - 2012-07-30 08:00 - 00440304 ____A C:\Users\praAnkster\AppData\Local\gfhpwvke.log
2012-07-30 07:58 - 2012-07-30 07:58 - 00000064 ____A C:\Users\All Users\spiaynhf.log
2012-07-27 07:27 - 2012-07-27 07:27 - 03028656 ____A (TeamViewer) C:\Users\praAnkster\Downloads\TeamViewerQS_en.exe
2012-07-27 07:15 - 2012-07-27 08:00 - 00000000 ____D C:\Users\praAnkster\AppData\Roaming\TeamViewer
2012-07-27 07:13 - 2012-07-27 07:13 - 03610576 ____A (TeamViewer GmbH) C:\Users\praAnkster\Downloads\TeamViewer_Setup_en.exe
2012-07-23 09:22 - 2012-07-23 09:23 - 00000000 ____D C:\CV
2012-07-21 10:08 - 2012-07-21 10:08 - 00000000 ____D C:\New folder
2012-07-19 14:56 - 2012-07-19 14:56 - 00001028 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-19 14:53 - 2012-07-19 14:53 - 04411280 ____A C:\Users\praAnkster\Downloads\fallen.ogg
2012-07-19 12:29 - 2012-07-24 03:28 - 00000000 ____D C:\TV and Radio
2012-07-17 04:11 - 2012-07-17 04:11 - 00132428 ____A C:\Users\praAnkster\Desktop\important.jpg-large
2012-07-14 09:12 - 2012-07-14 09:12 - 02456064 ____A C:\Users\praAnkster\Documents\Radiance MET Office - Matricardi_TC_2012.ppt
2012-07-13 14:04 - 2012-07-23 07:25 - 00000000 ____D C:\Users\praAnkster\Documents\Olympic cycling road race and sailing
2012-07-12 12:45 - 2012-07-22 06:23 - 00000000 ____D C:\Users\praAnkster\Documents\Invoices
============ 3 Months Modified Files ========================
2012-08-07 09:31 - 2012-08-07 09:31 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\znwtofdo.sys
2012-08-07 09:31 - 2010-11-28 07:59 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-07 09:30 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 09:29 - 2009-07-13 20:39 - 00378509 ____A C:\Windows\setupact.log
2012-08-06 06:58 - 2012-08-06 06:58 - 00000186 ____A C:\Users\praAnkster\Desktop\New shortcut.lnk
2012-08-06 06:54 - 2012-08-06 06:54 - 00023288 ____A C:\Users\praAnkster\Desktop\FRST.txt
2012-08-06 06:53 - 2012-08-03 06:17 - 00002843 ____A C:\Users\praAnkster\Desktop\FRST_.txt
2012-08-06 06:48 - 2010-11-28 07:59 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-03 06:38 - 2010-11-26 12:00 - 00733518 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-02 14:17 - 2012-08-02 14:17 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\oyzqmrff.sys
2012-08-02 12:20 - 2012-08-02 12:20 - 00892822 ____A (Farbar) C:\Users\praAnkster\Desktop\FRST.exe
2012-08-02 09:10 - 2012-08-02 09:10 - 00043480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\orniwxlf.sys
2012-08-02 07:49 - 2012-08-02 07:49 - 00002057 ____A C:\Users\praAnkster\Desktop\RKreport[20].txt
2012-08-02 07:37 - 2012-04-10 07:11 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-02 07:37 - 2010-11-26 12:49 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3402657652-3708558674-1240141188-1000UA.job
2012-08-02 07:26 - 2011-02-06 05:50 - 00020386 ____A C:\Windows\PFRO.log
2012-08-02 07:24 - 2012-08-02 07:24 - 00002052 ____A C:\Users\praAnkster\Desktop\RKreport[19].txt
2012-08-02 07:24 - 2012-08-02 07:24 - 00002019 ____A C:\Users\praAnkster\Desktop\RKreport[18].txt
2012-08-02 06:56 - 2011-04-05 03:52 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-02 06:52 - 2012-08-02 06:52 - 00002176 ____A C:\Users\praAnkster\Desktop\RKreport[17].txt
2012-08-02 06:51 - 2012-08-02 06:51 - 00002143 ____A C:\Users\praAnkster\Desktop\RKreport[16].txt
2012-08-02 06:36 - 2009-07-13 20:34 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-02 06:36 - 2009-07-13 20:34 - 00014192 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-02 05:02 - 2012-08-02 05:02 - 00002136 ____A C:\Users\praAnkster\Desktop\RKreport[15].txt
2012-08-02 05:01 - 2012-08-02 05:01 - 00002103 ____A C:\Users\praAnkster\Desktop\RKreport[14].txt
2012-08-02 04:57 - 2012-08-02 04:57 - 00001936 ____A C:\Users\praAnkster\Desktop\RKreport[13].txt
2012-08-02 04:56 - 2012-08-02 04:56 - 00001903 ____A C:\Users\praAnkster\Desktop\RKreport[12].txt
2012-08-02 03:08 - 2012-08-02 03:08 - 00001898 ____A C:\Users\praAnkster\Desktop\RKreport[11].txt
2012-08-02 03:07 - 2012-08-02 03:07 - 00001863 ____A C:\Users\praAnkster\Desktop\RKreport[10].txt
2012-08-01 14:49 - 2012-08-01 14:49 - 00001857 ____A C:\Users\praAnkster\Desktop\RKreport[9].txt
2012-08-01 14:48 - 2012-08-01 14:48 - 00001825 ____A C:\Users\praAnkster\Desktop\RKreport[8].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00001807 ____A C:\Users\praAnkster\Desktop\RKreport[7].txt
2012-08-01 11:45 - 2012-08-01 11:45 - 00000615 ____A C:\Users\praAnkster\Desktop\RKreport[6].txt
2012-08-01 11:44 - 2012-08-01 11:44 - 00001769 ____A C:\Users\praAnkster\Desktop\RKreport[5].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00001751 ____A C:\Users\praAnkster\Desktop\RKreport[4].txt
2012-08-01 11:09 - 2012-08-01 11:09 - 00000855 ____A C:\Users\praAnkster\Desktop\RKreport[3].txt
2012-08-01 11:08 - 2012-08-01 11:08 - 00001999 ____A C:\Users\praAnkster\Desktop\RKreport[2].txt
2012-08-01 11:05 - 2012-08-01 11:05 - 00139856 ____A C:\Windows\Minidump\080112-23150-01.dmp
2012-08-01 11:05 - 2011-04-25 11:37 - 232493646 ____A C:\Windows\MEMORY.DMP
2012-08-01 11:03 - 2012-08-01 11:03 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1].txt
2012-08-01 10:59 - 2012-08-01 10:58 - 00144072 ____A C:\Windows\Minidump\080112-23821-01.dmp
2012-08-01 10:57 - 2012-07-30 07:58 - 00000024 ____A C:\Users\praAnkster\AppData\Local\foafbyde.log
2012-08-01 10:56 - 2012-07-30 08:01 - 00738286 ____A C:\Users\praAnkster\AppData\Local\hfwiudnu.log
2012-08-01 07:44 - 2012-08-01 07:44 - 00002567 ____A C:\Users\praAnkster\Desktop\RKreport[10]_2.txt
2012-08-01 03:57 - 2012-08-01 03:57 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[7]_2.txt
2012-08-01 03:56 - 2012-08-01 03:56 - 00001952 ____A C:\Users\praAnkster\Desktop\RKreport[6]_2.txt
2012-07-31 16:37 - 2012-07-31 16:37 - 00002106 ____A C:\Users\praAnkster\Desktop\RKreport[4]_2.txt
2012-07-31 16:36 - 2012-07-31 16:36 - 00002038 ____A C:\Users\praAnkster\Desktop\RKreport[3]_2.txt
2012-07-31 14:59 - 2012-07-31 14:59 - 00002070 ____A C:\Users\praAnkster\Desktop\RKreport[2]_2.txt
2012-07-31 14:58 - 2012-07-31 14:58 - 00002002 ____A C:\Users\praAnkster\Desktop\RKreport[1]_2.txt
2012-07-31 14:54 - 2012-07-31 14:54 - 00000053 ____A C:\Users\praAnkster\AppData\Roaming\mbam.context.scan
2012-07-31 14:49 - 2012-07-31 14:49 - 00420800 ___AH C:\Windows\System32\Drivers\vsconfig.xml
2012-07-31 14:49 - 2010-11-26 11:52 - 01166814 ____A C:\Windows\WindowsUpdate.log
2012-07-31 07:30 - 2012-07-31 07:30 - 00144072 ____A C:\Windows\Minidump\073112-25630-01.dmp
2012-07-30 13:50 - 2012-07-30 13:49 - 00144072 ____A C:\Windows\Minidump\073012-23946-01.dmp
2012-07-30 12:56 - 2012-07-30 12:56 - 01552384 ____A C:\Users\praAnkster\Desktop\RogueKiller.exe
2012-07-30 11:08 - 2012-07-30 08:48 - 00001176 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-30 11:03 - 2012-07-30 11:03 - 00144072 ____A C:\Windows\Minidump\073012-33852-01.dmp
2012-07-30 09:11 - 2012-07-30 09:10 - 00144072 ____A C:\Windows\Minidump\073012-24632-01.dmp
2012-07-30 08:29 - 2012-07-30 08:29 - 00144072 ____A C:\Windows\Minidump\073012-36629-01.dmp
2012-07-30 08:22 - 2012-07-30 08:22 - 00000012 ____A C:\Windows\srun.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00135507 ____A C:\Users\praAnkster\AppData\Local\tardhnsx.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00003247 ____A C:\Users\praAnkster\AppData\Local\xoksmwpv.log
2012-07-30 08:01 - 2012-07-30 08:01 - 00002865 ____A C:\Users\praAnkster\AppData\Local\rhbguoor.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00004048 ____A C:\Users\praAnkster\AppData\Local\kxuagrty.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\hwlonyvp.log
2012-07-30 08:00 - 2012-07-30 08:00 - 00000000 ____A C:\Users\praAnkster\AppData\Local\brdepvjb.log
2012-07-30 08:00 - 2012-07-30 07:58 - 00440304 ____A C:\Users\praAnkster\AppData\Local\gfhpwvke.log
2012-07-30 07:58 - 2012-07-30 07:58 - 00000064 ____A C:\Users\All Users\spiaynhf.log
2012-07-29 14:24 - 2010-11-26 12:49 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3402657652-3708558674-1240141188-1000Core.job
2012-07-27 07:27 - 2012-07-27 07:27 - 03028656 ____A (TeamViewer) C:\Users\praAnkster\Downloads\TeamViewerQS_en.exe
2012-07-27 07:13 - 2012-07-27 07:13 - 03610576 ____A (TeamViewer GmbH) C:\Users\praAnkster\Downloads\TeamViewer_Setup_en.exe
2012-07-27 01:34 - 2012-04-10 07:11 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-07-27 01:34 - 2011-06-17 12:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-07-25 05:02 - 2011-01-10 04:39 - 00001524 ____A C:\Users\praAnkster\Desktop\stuff.txt
2012-07-19 14:56 - 2012-07-19 14:56 - 00001028 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-19 14:53 - 2012-07-19 14:53 - 04411280 ____A C:\Users\praAnkster\Downloads\fallen.ogg
2012-07-17 04:11 - 2012-07-17 04:11 - 00132428 ____A C:\Users\praAnkster\Desktop\important.jpg-large
2012-07-16 02:25 - 2011-02-27 10:41 - 00000000 ____A C:\Windows\System32\synsopos.soj
2012-07-14 09:59 - 2010-12-18 16:27 - 00007602 ____A C:\Users\praAnkster\AppData\Local\Resmon.ResmonCfg
2012-07-14 09:12 - 2012-07-14 09:12 - 02456064 ____A C:\Users\praAnkster\Documents\Radiance MET Office - Matricardi_TC_2012.ppt
2012-07-07 22:19 - 2012-07-07 22:19 - 00065752 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKELL.sys
2012-07-07 05:59 - 2012-07-07 05:37 - 1796533693 ____A C:\Users\praAnkster\Downloads\Wimbledon_2012_30_06_2012_b01ks80t_1341108740.wmv
2012-07-07 04:34 - 2012-07-07 04:34 - 00000228 ____A C:\Users\praAnkster\.swfinfo
2012-07-06 16:25 - 2012-07-06 16:25 - 08288706 ____A C:\Users\praAnkster\Downloads\ipdl.exe
2012-07-06 16:11 - 2012-07-06 16:11 - 06761918 ____A C:\Users\praAnkster\Downloads\get_iplayer_setup_latest.exe
2012-07-03 09:21 - 2012-07-03 09:21 - 00004096 ___AH C:\Users\praAnkster\AppData\Local\keyfile3.drm
2012-07-03 04:46 - 2012-07-30 08:48 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-02 18:13 - 2010-11-26 13:00 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-07 08:08 - 2012-06-07 08:08 - 01383424 ____A C:\Users\praAnkster\Downloads\eggsurvey2007.xls
2012-06-02 14:19 - 2012-06-21 04:31 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 04:31 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 04:31 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 04:30 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 04:30 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-21 04:31 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-21 04:30 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-21 04:30 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:12 - 2012-06-21 04:30 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-30 07:36 - 2012-05-30 07:36 - 04886564 ____A C:\Users\praAnkster\Downloads\Pictures from St. Kitts.zip
2012-05-28 12:15 - 2012-05-28 12:15 - 00972893 ____A C:\Users\praAnkster\Downloads\spoty honda (3).zip
2012-05-28 12:14 - 2012-05-28 12:14 - 00000000 ____A C:\Users\praAnkster\Downloads\spoty honda (2).zip.crdownload
2012-05-28 12:14 - 2012-05-28 12:14 - 00000000 ____A C:\Users\praAnkster\Downloads\spoty honda (1).zip.crdownload
2012-05-28 12:13 - 2012-05-28 12:13 - 00972893 ____A C:\Users\praAnkster\Downloads\spoty honda.zip
2012-05-26 13:15 - 2009-07-13 20:53 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-21 11:15 - 2012-05-21 11:15 - 00615072 ____A C:\Users\praAnkster\Downloads\car.zip
2012-05-20 15:34 - 2012-05-20 15:34 - 00012922 ____A C:\Users\praAnkster\Downloads\Final_HDTV_X264-SuperS-((www.Demonoid.me)).torrent
2012-05-14 14:03 - 2012-05-14 14:03 - 00001563 ____A C:\Windows\System32\Frequency-of-precipitation-and-temperature-extremes-over-France-in-an-anthropogenic-scenario-Model-results-and-statistical-correction-according-to-observed-values_2007_Global-and-Planetary-Change.lnk
ZeroAccess:
C:\Windows\assembly\GAC\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe A302BBFF2A7278C0E239EE5D471D86A9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 14%
Total physical RAM: 3839.18 MB
Available physical RAM: 3297.98 MB
Total Pagefile: 3837.46 MB
Available Pagefile: 3308.11 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.21 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:1862.92 GB) (Free:1737.11 GB) NTFS
2 Drive e: () (Removable) (Total:14.92 GB) (Free:12.42 GB) NTFS
3 Drive f: () (Removable) (Total:0.98 GB) (Free:0.07 GB) FAT
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 1863 GB 0 B
Disk 1 Online 14 GB 0 B
Disk 2 Online 1003 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 1862 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 1862 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 14 GB 22 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Removable 14 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1002 MB 16 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT Removable 1002 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 05:19
======================= End Of Log ==========================
SEARCH.TXT
Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 2012-08-08 00:08:24
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) A302BBFF2A7278C0E239EE5D471D86A9
=== End Of Search ===
THANKS IN ADVANCE FOR ANY HELP!!! Matt