I picked up the Live Security Platinum trojan today. I ran fixexec and then Malware Bytes to remove it. But then my Microsoft Security Essentials wouldn't run. I reinstalled Microsoft Security Essentials. But on restarting I could not use Fireforx or IE and windows keeps crashing with an automatic restart.
I ran Farbar and it flags system32/services.exe in the MD5 section. Here is the farbar log (below).
HELP! I have been at this all day.
==========================================
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 05-08-2012 01
Ran by SYSTEM at 07-08-2012 14:43:22
Running from F:\Install
Windows Vista Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13539872 2008-09-26] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [92704 2008-09-26] (NVIDIA Corporation)
HKLM\...\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\...\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM\...\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" [210216 2008-06-13] (CyberLink Corp.)
HKLM\...\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2008-09-11] (CyberLink Corp.)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" [148888 2009-06-07] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [185896 2006-09-28] (Nuance Communications, Inc.)
HKLM\...\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [75304 2006-10-11] (ScanSoft, Inc.)
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [63048 2008-07-24] (LogMeIn, Inc.)
HKLM\...\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe [1325936 2009-10-16] (Seagate)
HKLM\...\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe [904840 2009-10-16] (Acronis)
HKLM\...\Run: [Seagate Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [136544 2009-10-16] (Seagate)
HKLM\...\Run: [DVDAgent] "c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [1148200 2009-09-09] (CyberLink Corp.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-09-08] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421160 2010-11-17] (Apple Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Run: [vrdms] rundll32.exe "C:\Users\Craig and Susan\AppData\Roaming\vrdms.dll",OpenDatabase [119808 2012-08-07] (Crytek inc.)
HKLM\...\Run: [agrer] "C:\Windows\System32\rundll32.exe" "C:\Users\Craig and Susan\AppData\Roaming\agrer.dll",Values [359424 2012-08-07] (Andrew Zhezherun)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Craig and Susan\...\Run: [googletalk] C:\Users\Craig and Susan\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google)
HKU\Craig and Susan\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Craig and Susan\...\Run: [SlickRun] "C:\Program Files\SlickRun\sr.exe" [1161568 2009-06-02] (Bayden Systems)
HKU\Craig and Susan\...\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" [247144 2009-11-13] (TomTom)
HKU\Craig and Susan\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY [1644088 2009-08-05] (Hewlett-Packard)
HKU\Craig and Susan\...\Run: [Google Update] "C:\Users\Craig and Susan\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2010-04-13] (Google Inc.)
HKU\Default\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\Default User\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\LogMeInRemoteUser\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
HKU\LogMeInRemoteUser.CraigSusan-PC\...\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN [1644088 2009-08-05] (Hewlett-Packard)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Craig and Susan\Start Menu\Programs\Startup\goSoft (3.1.2.0 F).lnk
ShortcutTarget: goSoft (3.1.2.0 F).lnk -> C:\Program Files\goFluent\goSoft(3.1.2.0 F)\goStart.exe (No File)
================================ Services (Whitelisted) ==================
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation)
2 LMIGuardianSvc; "C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe" [374184 2012-07-12] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files\LogMeIn\x86\RaMaint.exe" [136616 2012-07-12] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files\LogMeIn\x86\LogMeIn.exe" [390528 2010-12-08] (LogMeIn, Inc.)
2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2009-11-12] ()
2 SgtSch2Svc; "C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe" [431456 2009-10-16] (Seagate)
2 Skype C2C Service; "C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe" [3048136 2012-07-05] (Skype Technologies S.A.)
2 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [160944 2012-07-03] (Skype Technologies)
2 TeamViewer5; "C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe" -service [173352 2010-07-06] (TeamViewer GmbH)
2 XAudioService; C:\Windows\System32\DRIVERS\xaudio.exe work [403968 2008-09-04] (Conexant Systems, Inc.)
2 HP Health Check Service; "c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe" [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
2 Norton Internet Security; "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 [x]
========================== Drivers (Whitelisted) =============
3 CamDrL; C:\Windows\System32\DRIVERS\Camdrl.sys [1075360 2007-02-03] (Logitech Inc.)
2 LMIInfo; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [12856 2008-07-24] (LogMeIn, Inc.)
3 lmimirr; C:\Windows\System32\DRIVERS\lmimirr.sys [10144 2008-07-24] (LogMeIn, Inc.)
2 LMIRfsDriver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [47640 2008-07-24] (LogMeIn, Inc.)
3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28944 2008-02-29] (Logitech, Inc.)
3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41504 2007-02-03] (Logitech Inc.)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
4 nvsmu; C:\Windows\system32\drivers\nvsmu.sys [15360 2008-05-22] (NVIDIA Corporation)
3 pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [47360 2009-10-22] (VSO Software)
3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] ()
0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2010-01-30] (Acronis)
2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2010-01-30] (Acronis)
0 timounter; C:\Windows\System32\DRIVERS\timntr.sys [441760 2010-01-30] (Acronis)
3 USB_RNDIS; C:\Windows\System32\DRIVERS\usb8023.sys [15872 2009-04-10] (Microsoft Corporation)
3 catchme; \??\C:\ComboFix\catchme.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
4 LMIRfsClientNP; [x]
3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081022.006\NAVENG.SYS [x]
3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20081022.006\NAVEX15.SYS [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
3 PCD5SRVC{BD6912E3-AC9D80E8-05040000}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms [x]
1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [x]
1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-07 14:43 - 2012-08-07 14:43 - 00000000 ____D C:\FRST
2012-08-07 13:24 - 2012-08-07 13:24 - 00139784 ____A C:\Windows\Minidump\Mini080712-01.dmp
2012-08-07 11:50 - 2012-08-07 11:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-07 11:47 - 2012-08-07 11:49 - 10288512 ____A (Microsoft Corporation) C:\Users\Craig and Susan\Downloads\mseinstall.exe
2012-08-07 09:56 - 2012-08-07 09:56 - 00000872 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-07 09:56 - 2012-08-07 09:56 - 00000872 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-07 09:43 - 2012-08-07 09:57 - 00001246 ____A C:\Users\Craig and Susan\Desktop\FixExec.txt
2012-08-07 09:43 - 2012-08-07 09:40 - 00883616 ____A (Bleeping Computer, LLC) C:\FixExec.exe
2012-08-07 08:41 - 2012-08-07 08:41 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-07 08:36 - 2012-08-07 08:38 - 00000000 ____D C:\Users\All Users\Application Data\036E19320357F9631A6804E82F3B707C
2012-08-07 08:36 - 2012-08-07 08:38 - 00000000 ____D C:\Users\All Users\036E19320357F9631A6804E82F3B707C
2012-08-07 08:36 - 2012-08-07 08:36 - 00359424 ____A (Andrew Zhezherun) C:\Users\Craig and Susan\Application Data\agrer.dll
2012-08-07 08:36 - 2012-08-07 08:36 - 00359424 ____A (Andrew Zhezherun) C:\Users\Craig and Susan\AppData\Roaming\agrer.dll
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Windows\scoped_dir_9056_23239
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Windows\scoped_dir_9056_12794
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\Local Settings\Application Data\{E94AF4AB-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\Local Settings\Application Data\{E94AB980-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\Local Settings\{E94AF4AB-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\Local Settings\{E94AB980-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\AppData\Local\{E94AF4AB-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:36 - 2012-08-07 08:36 - 00000000 ____D C:\Users\Craig and Susan\AppData\Local\{E94AB980-E0AD-11E1-8270-B8AC6F996F26}
2012-08-07 08:35 - 2012-08-07 08:35 - 00119808 __ASH (Crytek inc.) C:\Users\Craig and Susan\Application Data\vrdms.dll
2012-08-07 08:35 - 2012-08-07 08:35 - 00119808 __ASH (Crytek inc.) C:\Users\Craig and Susan\AppData\Roaming\vrdms.dll
2012-08-07 08:35 - 2012-08-07 08:35 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\mobsEXEC.dll
2012-08-05 14:16 - 2012-08-05 14:16 - 00000332 ____A C:\Users\Craig and Susan\Desktop\Subscription Purchase.website
2012-07-30 15:28 - 2012-07-30 15:28 - 00011320 ____A C:\Users\Craig and Susan\.recently-used.xbel
2012-07-23 07:04 - 2012-07-23 07:04 - 00018032 ____A C:\Users\Craig and Susan\Downloads\TodoList.jsp.html
2012-07-23 07:04 - 2012-07-23 07:04 - 00000000 ____D C:\Users\Craig and Susan\Downloads\TodoList.jsp_files
2012-07-16 16:27 - 2012-07-29 15:59 - 00000000 ____D C:\Users\Craig and Susan\My Documents\Things to paint
2012-07-16 16:27 - 2012-07-29 15:59 - 00000000 ____D C:\Users\Craig and Susan\Documents\Things to paint
2012-07-16 16:26 - 2012-07-16 16:26 - 00000000 ____D C:\Users\Craig and Susan\New Folder (1)
2012-07-12 11:33 - 2012-08-07 13:24 - 209673277 ____A C:\Windows\MEMORY.DMP
2012-07-12 11:33 - 2012-07-12 11:33 - 00139784 ____A C:\Windows\Minidump\Mini071212-01.dmp
2012-07-11 02:08 - 2012-06-13 05:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 02:03 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 02:03 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 02:03 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 02:03 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 02:03 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 02:03 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 02:03 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 02:03 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 02:03 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 02:03 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 02:03 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 02:03 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 02:03 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 02:03 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 19:49 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 19:39 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 19:39 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 19:39 - 2012-06-04 07:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 19:39 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 19:39 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
============ 3 Months Modified Files ========================
2012-08-07 13:27 - 2009-09-18 11:57 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-07 13:27 - 2006-11-02 04:47 - 00003744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-07 13:27 - 2006-11-02 04:47 - 00003744 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-07 13:25 - 2012-01-30 19:28 - 00000900 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-07 13:25 - 2009-02-17 13:10 - 01291980 ____A C:\Windows\WindowsUpdate.log
2012-08-07 13:24 - 2012-08-07 13:24 - 00139784 ____A C:\Windows\Minidump\Mini080712-01.dmp
2012-08-07 13:24 - 2012-07-12 11:33 - 209673277 ____A C:\Windows\MEMORY.DMP
2012-08-07 13:24 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-07 12:16 - 2012-01-30 19:28 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-07 11:52 - 2012-05-02 10:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-07 11:52 - 2010-04-13 18:29 - 00000948 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1015957308-2917552244-2219005616-1000UA.job
2012-08-07 11:51 - 2010-12-20 20:24 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-07 11:50 - 2006-11-02 02:33 - 00721122 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-07 11:49 - 2012-08-07 11:47 - 10288512 ____A (Microsoft Corporation) C:\Users\Craig and Susan\Downloads\mseinstall.exe
2012-08-07 11:44 - 2009-04-16 19:18 - 00000258 _RASH C:\Users\All Users\ntuser.pol
2012-08-07 11:44 - 2009-04-16 19:18 - 00000258 _RASH C:\Users\All Users\Application Data\ntuser.pol
2012-08-07 10:58 - 2012-02-06 07:49 - 00011018 ____A C:\Windows\PFRO.log
2012-08-07 09:57 - 2012-08-07 09:43 - 00001246 ____A C:\Users\Craig and Susan\Desktop\FixExec.txt
2012-08-07 09:56 - 2012-08-07 09:56 - 00000872 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-07 09:56 - 2012-08-07 09:56 - 00000872 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-07 09:40 - 2012-08-07 09:43 - 00883616 ____A (Bleeping Computer, LLC) C:\FixExec.exe
2012-08-07 08:36 - 2012-08-07 08:36 - 00359424 ____A (Andrew Zhezherun) C:\Users\Craig and Susan\Application Data\agrer.dll
2012-08-07 08:36 - 2012-08-07 08:36 - 00359424 ____A (Andrew Zhezherun) C:\Users\Craig and Susan\AppData\Roaming\agrer.dll
2012-08-07 08:35 - 2012-08-07 08:35 - 00119808 __ASH (Crytek inc.) C:\Users\Craig and Susan\Application Data\vrdms.dll
2012-08-07 08:35 - 2012-08-07 08:35 - 00119808 __ASH (Crytek inc.) C:\Users\Craig and Susan\AppData\Roaming\vrdms.dll
2012-08-07 08:35 - 2012-08-07 08:35 - 00057344 ___AH (AhnLab, Inc.) C:\Windows\System32\mobsEXEC.dll
2012-08-07 07:40 - 2012-05-30 16:13 - 00002573 ____A C:\Users\Craig and Susan\Desktop\Microsoft Word 2010.lnk
2012-08-06 15:52 - 2010-04-13 18:29 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1015957308-2917552244-2219005616-1000Core.job
2012-08-05 14:16 - 2012-08-05 14:16 - 00000332 ____A C:\Users\Craig and Susan\Desktop\Subscription Purchase.website
2012-08-03 08:54 - 2012-05-02 10:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 08:54 - 2011-06-16 05:02 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-03 07:57 - 2009-04-06 16:29 - 00000052 ____A C:\Windows\System32\DOErrors.log
2012-07-30 15:28 - 2012-07-30 15:28 - 00011320 ____A C:\Users\Craig and Susan\.recently-used.xbel
2012-07-27 15:08 - 2012-02-29 20:33 - 00002337 ____A C:\Users\Public\Desktop\Skype.lnk
2012-07-27 15:08 - 2012-02-29 20:33 - 00002337 ____A C:\Users\All Users\Desktop\Skype.lnk
2012-07-23 12:51 - 2012-02-08 20:08 - 00022092 ____A C:\Windows\setupact.log
2012-07-23 07:04 - 2012-07-23 07:04 - 00018032 ____A C:\Users\Craig and Susan\Downloads\TodoList.jsp.html
2012-07-12 11:37 - 2009-04-29 19:02 - 00087456 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll
2012-07-12 11:37 - 2009-04-29 19:02 - 00083392 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll
2012-07-12 11:37 - 2009-04-29 19:02 - 00030624 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll
2012-07-12 11:33 - 2012-07-12 11:33 - 00139784 ____A C:\Windows\Minidump\Mini071212-01.dmp
2012-07-11 02:29 - 2006-11-02 04:47 - 00516952 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 02:27 - 2006-11-02 05:01 - 00032522 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-11 02:05 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-07-08 20:32 - 2009-04-04 15:18 - 00000456 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job
2012-07-03 12:46 - 2011-02-18 00:18 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-13 05:40 - 2012-07-11 02:08 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 18:06 - 2012-06-09 18:06 - 00023552 ___AH C:\Users\Craig and Susan\My Documents\~WRL0005.tmp
2012-06-09 18:06 - 2012-06-09 18:06 - 00023552 ___AH C:\Users\Craig and Susan\Documents\~WRL0005.tmp
2012-06-08 09:47 - 2012-07-10 19:49 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 14:55 - 2012-06-05 14:55 - 00000450 ____A C:\Users\Craig and Susan\Desktop\L26 Nikon Camera.lnk
2012-06-05 08:47 - 2012-07-10 19:39 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-10 19:39 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 07:26 - 2012-07-10 19:39 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 21:01 - 2009-04-03 19:20 - 00163720 ____A C:\Users\Craig and Susan\Local Settings\GDIPFONTCACHEV1.DAT
2012-06-02 21:01 - 2009-04-03 19:20 - 00163720 ____A C:\Users\Craig and Susan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2012-06-02 21:01 - 2009-04-03 19:20 - 00163720 ____A C:\Users\Craig and Susan\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-02 20:57 - 2012-06-02 20:57 - 00001955 ____A C:\Users\Public\Desktop\Serif PagePlus X5.lnk
2012-06-02 20:57 - 2012-06-02 20:57 - 00001955 ____A C:\Users\All Users\Desktop\Serif PagePlus X5.lnk
2012-06-02 14:19 - 2012-06-18 21:46 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-18 21:46 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-18 21:46 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-18 21:45 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-18 21:45 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-18 21:45 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-18 21:46 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-18 21:45 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:12 - 2012-06-18 21:45 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-11 02:03 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-11 02:03 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-11 02:03 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-11 02:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-11 02:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 02:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-11 02:03 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-11 02:03 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 02:03 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 02:03 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-11 02:03 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-11 02:03 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 02:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 02:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-10 19:39 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-10 19:39 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-31 02:47 - 2012-05-31 02:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2012-05-31 02:47 - 2012-05-31 02:47 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_07_00.Wdf
2012-05-30 15:49 - 2009-04-04 17:59 - 00000011 ____A C:\Windows\exchng.ini
2012-05-30 15:49 - 2006-11-02 02:23 - 00000171 ____A C:\Windows\win.ini
2012-05-30 01:32 - 2012-05-30 01:32 - 02466465 ____A C:\Users\Craig and Susan\My Documents\Contact sheet from Italy.eml
2012-05-30 01:32 - 2012-05-30 01:32 - 02466465 ____A C:\Users\Craig and Susan\Documents\Contact sheet from Italy.eml
2012-05-18 18:04 - 2009-04-29 19:02 - 00083360 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll.000.bak
ZeroAccess:
C:\Windows\Installer\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}
C:\Windows\Installer\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\@
C:\Windows\Installer\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\L
C:\Windows\Installer\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\U
C:\Windows\Installer\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\U\00000001.@
ZeroAccess:
C:\Users\Craig and Susan\AppData\Local\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}
C:\Users\Craig and Susan\AppData\Local\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\@
C:\Users\Craig and Susan\AppData\Local\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\L
C:\Users\Craig and Susan\AppData\Local\{bce63da1-5ed8-b0ec-38c5-863b6df10fa5}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 19%
Total physical RAM: 2941.76 MB
Available physical RAM: 2382.32 MB
Total Pagefile: 2624.93 MB
Available Pagefile: 2450.83 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.11 MB
======================= Partitions =========================
1 Drive c: (COMPAQ) (Fixed) (Total:221.63 GB) (Free:129.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (FACTORY_IMAGE) (Fixed) (Total:11.25 GB) (Free:1.54 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive f: (KINGSTON) (Removable) (Total:3.72 GB) (Free:2.56 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 233 GB 0 B
Disk 1 Online 3818 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 222 GB 32 KB
Partition 2 Primary 11 GB 222 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C COMPAQ NTFS Partition 222 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D FACTORY_IMA NTFS Partition 11 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3817 MB 4096 B
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3817 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-07 11:29
======================= End Of Log ==========================


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top







