I'm a new member, and I came upon your site after reading a couple recent threads dealing with the Sirefef virus. I've tried running Microsoft Security Essentials, but my laptop keeps restarting before it has the chance to remove it.
I have the same exact problem as in these two threads:
http://www.bleepingcomputer.com/forums/topic463661.html
http://www.bleepingcomputer.com/forums/topic462717.html
I've tried following them, and have successfully completed the step involving System Recovery Options and frst.exe I'm no technical expert, though, so I don't know what to put in the fixlist.
I'll attach the FRST.txt and Search.txt I've generated from my computer, and hopefully you can get back to me. I really appreciate it!
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 08-08-2012
Ran by SYSTEM at 08-08-2012 06:33:39
Running from E:\
Windows Vista Business (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM\...\Run: [iSkysoft Helper Compact.exe] C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [x]
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Anastassia\...\Run: [] [x]
HKU\Anastassia\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\Anastassia\...\Run: [Akamai NetSession Interface] "C:\Users\Anastassia\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\Anastassia\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\Anastassia\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Anastassia\Start Menu\Programs\Startup\MagicDisc.lnk
ShortcutTarget: MagicDisc.lnk -> C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
================================ Services (Whitelisted) ==================
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation)
2 MacDrive8Service; "C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe" [192512 2009-09-03] (Mediafour Corporation)
2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe" [335872 2006-10-26] (Microsoft Corporation)
2 Akamai; c:\program files\common files\akamai/netsession_win_4f7fccd.dll [x]
2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x]
3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x]
========================== Drivers (Whitelisted) =============
3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2009-01-20] (Broadcom Corporation)
3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2012-08-08] (Malwarebytes Corporation)
0 MDFSYSNT; C:\Windows\System32\Drivers\MDFSYSNT.sys [259176 2009-09-03] (Mediafour Corporation)
0 MDPMGRNT; C:\Windows\System32\Drivers\MDPMGRNT.sys [27488 2009-07-31] (Mediafour Corporation)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 WsAudio_DeviceS(1); C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys [25704 2011-12-09] (Wondershare)
3 WsAudio_DeviceS(2); C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys [25704 2011-12-09] (Wondershare)
3 WsAudio_DeviceS(3); C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys [25704 2011-12-09] (Wondershare)
3 WsAudio_DeviceS(4); C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys [25704 2011-12-09] (Wondershare)
3 WsAudio_DeviceS(5); C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys [25704 2011-12-09] (Wondershare)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 06:33 - 2012-08-08 06:33 - 00000000 ____D C:\FRST
2012-08-08 02:59 - 2012-08-08 02:59 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 02:08 - 2012-08-08 02:08 - 00000000 ____D C:\Users\Anastassia\AppData\Roaming\Malwarebytes
2012-08-08 02:07 - 2012-08-08 02:07 - 00000906 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 02:07 - 2012-08-08 02:07 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-08-08 02:07 - 2012-08-08 02:07 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-08-08 02:07 - 2012-07-03 10:46 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-08 01:59 - 2012-08-08 01:55 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\Anastassia\Desktop\mbam-setup.exe
2012-08-08 01:41 - 2012-08-08 01:42 - 00000000 ____D C:\Qoobox
2012-08-08 01:31 - 2012-08-08 01:42 - 00000000 ____D C:\Windows\erdnt
2012-08-08 01:30 - 2012-08-08 02:56 - 00000000 ___SD C:\32788R22FWJFW
2012-08-08 01:27 - 2012-08-08 01:19 - 04729922 ____R (Swearware) C:\Users\Anastassia\Desktop\ComboFix.exe
2012-08-06 23:42 - 2012-08-06 23:42 - 00001826 ____A C:\Users\Anastassia\Desktop\Microsoft Security Essentials.lnk
2012-08-06 22:32 - 2012-08-06 22:19 - 16373192 ____A (Microsoft Corporation) C:\Users\Anastassia\Desktop\Windows-KB890830-V4.10.exe
2012-08-06 21:04 - 2012-08-06 21:05 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-06 20:57 - 2012-08-06 20:57 - 10288512 ____A (Microsoft Corporation) C:\Users\Anastassia\Desktop\mseinstall.exe
2012-08-05 02:55 - 2012-08-05 02:55 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-12 08:37 - 2012-06-13 05:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 08:21 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 08:21 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 08:21 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 08:21 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 08:21 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 08:21 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 08:21 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 08:21 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 08:21 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 08:21 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 08:21 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 08:21 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 08:21 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 08:21 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 14:02 - 2012-07-11 14:02 - 00001726 ____A C:\Users\Public\Desktop\CDBurnerXP.lnk
2012-07-11 14:02 - 2012-07-11 14:02 - 00000000 ____D C:\Users\Anastassia\AppData\Roaming\Canneverbe Limited
2012-07-11 14:02 - 2012-07-11 14:02 - 00000000 ____D C:\Users\All Users\Canneverbe Limited
2012-07-11 14:02 - 2012-07-11 14:02 - 00000000 ____D C:\Program Files\CDBurnerXP
2012-07-11 13:38 - 2012-06-21 00:31 - 1997193216 ____A C:\Users\Anastassia\Downloads\Citizen Kane.avi
2012-07-11 12:41 - 2012-07-11 12:41 - 00001647 ____A C:\Users\Public\Desktop\mkvmerge GUI.lnk
2012-07-11 12:41 - 2012-07-11 12:41 - 00000000 ____D C:\Users\Anastassia\AppData\Roaming\mkvtoolnix
2012-07-11 12:41 - 2012-01-10 09:16 - 00002953 ____A C:\Users\Anastassia\Desktop\MKVExtractGUI2_readme.txt
2012-07-11 12:40 - 2012-07-11 12:44 - 00000000 ____D C:\Program Files\MKVToolNix
2012-07-11 12:39 - 2012-07-11 12:40 - 00719218 ____A C:\Users\Anastassia\Desktop\MKVExtractGUI-2.2.2.9.zip
2012-07-11 12:22 - 2012-07-11 12:22 - 00000859 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-11 10:46 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 10:46 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 10:46 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 10:45 - 2012-06-04 07:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 10:45 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 10:45 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
============ 3 Months Modified Files ========================
2012-08-08 03:25 - 2006-11-02 04:47 - 00003712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-08 03:25 - 2006-11-02 04:47 - 00003712 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-08 03:24 - 2011-06-06 08:47 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cc24697ddf3580.job
2012-08-08 03:24 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-08 03:00 - 2010-10-05 00:28 - 00279552 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-08 02:59 - 2012-08-08 02:59 - 00040776 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2012-08-08 02:19 - 2012-04-08 04:52 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 02:07 - 2012-08-08 02:07 - 00000906 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-08 01:55 - 2012-08-08 01:59 - 10651816 ____A (Malwarebytes Corporation ) C:\Users\Anastassia\Desktop\mbam-setup.exe
2012-08-08 01:19 - 2012-08-08 01:27 - 04729922 ____R (Swearware) C:\Users\Anastassia\Desktop\ComboFix.exe
2012-08-08 01:00 - 2010-10-13 19:12 - 00001356 ____A C:\Users\Anastassia\AppData\Local\d3d9caps.dat
2012-08-08 00:11 - 2012-08-08 00:10 - 00000012 ____A C:\Users\Anastassia\Desktop\fix.bat
2012-08-06 23:42 - 2012-08-06 23:42 - 00001826 ____A C:\Users\Anastassia\Desktop\Microsoft Security Essentials.lnk
2012-08-06 22:19 - 2012-08-06 22:32 - 16373192 ____A (Microsoft Corporation) C:\Users\Anastassia\Desktop\Windows-KB890830-V4.10.exe
2012-08-06 21:06 - 2008-01-20 17:39 - 01248145 ____A C:\Windows\WindowsUpdate.log
2012-08-06 21:05 - 2011-02-04 08:14 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-06 20:57 - 2012-08-06 20:57 - 10288512 ____A (Microsoft Corporation) C:\Users\Anastassia\Desktop\mseinstall.exe
2012-08-06 20:46 - 2006-11-02 05:01 - 00032606 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-06 20:41 - 2010-10-24 03:32 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-03 15:26 - 2012-04-08 04:52 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 15:26 - 2011-05-17 13:03 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-02 10:46 - 2010-10-24 03:34 - 00001971 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-26 00:05 - 2010-10-14 00:18 - 00159744 ____A C:\Users\Anastassia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-14 19:30 - 2006-11-02 04:47 - 01714536 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 08:36 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-11 14:02 - 2012-07-11 14:02 - 00001726 ____A C:\Users\Public\Desktop\CDBurnerXP.lnk
2012-07-11 12:41 - 2012-07-11 12:41 - 00001647 ____A C:\Users\Public\Desktop\mkvmerge GUI.lnk
2012-07-11 12:40 - 2012-07-11 12:39 - 00719218 ____A C:\Users\Anastassia\Desktop\MKVExtractGUI-2.2.2.9.zip
2012-07-11 12:22 - 2012-07-11 12:22 - 00000859 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-11 10:49 - 2012-04-07 19:32 - 00000752 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-07-03 10:46 - 2012-08-08 02:07 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-03 00:13 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-06-13 05:40 - 2012-07-12 08:37 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 18:08 - 2012-06-12 18:08 - 00001664 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-12 14:41 - 2012-06-12 14:41 - 00000804 ____A C:\Users\Anastassia\Desktop\Audacity.lnk
2012-06-09 23:11 - 2012-06-09 23:11 - 00001892 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-06-08 11:41 - 2010-11-06 13:42 - 00000934 ____A C:\Users\Anastassia\Desktop\Dropbox.lnk
2012-06-08 09:47 - 2012-07-11 10:46 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-05 08:47 - 2012-07-11 10:46 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 08:47 - 2012-07-11 10:46 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-04 07:26 - 2012-07-11 10:45 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 14:19 - 2012-06-19 03:25 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 03:25 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 03:25 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 03:25 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 03:25 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:12 - 2012-06-19 03:25 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:12 - 2012-06-19 03:25 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-19 03:24 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:12 - 2012-06-19 03:24 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 01:07 - 2012-07-12 08:21 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 00:43 - 2012-07-12 08:21 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 00:33 - 2012-07-12 08:21 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 00:26 - 2012-07-12 08:21 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 00:25 - 2012-07-12 08:21 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 08:21 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 00:23 - 2012-07-12 08:21 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 00:21 - 2012-07-12 08:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 08:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 08:21 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 00:19 - 2012-07-12 08:21 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 00:17 - 2012-07-12 08:21 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 08:21 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 08:21 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-01 16:04 - 2012-07-11 10:45 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 16:03 - 2012-07-11 10:45 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-05-29 23:10 - 2012-04-07 19:30 - 00880496 ____A (BitTorrent, Inc.) C:\Users\Anastassia\Desktop\uTorrent.exe
2012-05-29 21:09 - 2012-04-08 04:40 - 00001186 ____A C:\Windows\PFRO.log
2012-05-29 20:42 - 2011-02-01 14:43 - 00001854 ____A C:\Users\Public\Desktop\Safari.lnk
ZeroAccess:
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\@
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\L
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\n
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\00000001.@
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\80000000.@
C:\Windows\Installer\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\800000cb.@
ZeroAccess:
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\@
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\L
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\n
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\00000001.@
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\80000000.@
C:\Users\Anastassia\AppData\Local\{228cf61f-1375-4ad7-7874-df1cdfdbe27b}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 19%
Total physical RAM: 1917.44 MB
Available physical RAM: 1543.48 MB
Total Pagefile: 1737.76 MB
Available Pagefile: 1601.7 MB
Total Virtual: 2047.88 MB
Available Virtual: 1984.97 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:74.44 GB) (Free:1.48 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (2007.11.03_2329) (CDROM) (Total:0.12 GB) (Free:0 GB) UDF
3 Drive e: (MY TASKS) (Fixed) (Total:37.3 GB) (Free:3.25 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 75 GB 1528 KB
Disk 1 Online 37 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 86 MB 32 KB
Partition 2 Primary 74 GB 86 MB
==================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 FAT Partition 86 MB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 74 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 37 GB 32 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E MY TASKS FAT32 Partition 37 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 02:20
======================= End Of Log ==========================
Farbar Recovery Scan Tool Version: 08-08-2012
Ran by SYSTEM at 2012-08-08 06:35:33
Running from E:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2010-10-05 00:28] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2008-01-20 18:25] - [2008-01-20 18:25] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C
C:\Windows\System32\services.exe
[2010-10-05 00:28] - [2012-08-08 03:00] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843
=== End Of Search ===


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










