Jump to content

Help with FBI Virus


dravp
 Share

Recommended Posts

Hi,

My laptop recently got the FBI Virus, and now, I cannot go on to my home screen. Tried the safe mode, but the same thing happens.

I have read the posts by the mods / experts on this subject in this forum, but it was mentioned that some of the removal tools / scripts would be user specific.

 

I have a Sony Vaio, running Win7 64bit. I had read about the first step of Farbar Recovery tool scan and have done it already.

This is the msg:

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-09-2013
Ran by SYSTEM on MININT-6RG4O28 on 01-09-2013 00:44:11
Running from H:\
Windows 7 Professional (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-05-31] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-05-31] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-05-31] (Alps Electric Co., Ltd.)
HKLM\...\Run: [intelWirelessWiMAX] - C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1441792 2010-06-08] (Intel® Corporation)
HKLM\...\Run: [intelWireless] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1931024 2010-07-19] (Intel® Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Trend Micro Titanium] - C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1374328 2013-05-29] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] - C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [209712 2013-02-04] (Trend Micro Inc.)
HKLM\...\RunOnce: [DCERegBootClean64] - C:\Windows\RegBootClean64.exe [234544 2013-08-25] ()
HKLM-x32\...\Run: [iAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [iSBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [650080 2011-03-15] (Sony Corporation)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-05-22] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [b2C_AGENT] - C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM-x32\...\Run: [ConnectionCenter] - C:\Users\Ashish\AppData\Local\Citrix\ICA Client\concentr.exe [309184 2012-03-28] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [bingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-27] (Microsoft Corp.)
HKLM-x32\...\Run: [] -  [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [815512 2012-01-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [TkBellExe] - c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-06-20] (RealNetworks, Inc.)
HKU\Ashish\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-05-09] (Google Inc.)
HKU\Ashish\...\Run: [Akamai NetSession Interface] - C:\Users\Ashish\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-04] (Akamai Technologies, Inc.)
HKU\Ashish\...\Run: [C:\Program Files (x86)\NetMeter\NetMeter.exe] - C:\Program Files (x86)\NetMeter\NetMeter.exe [293888 2009-08-09] ()
HKU\Ashish\...\Run: [Messenger (Yahoo!)] - C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\Ashish\...\Run: [CAtxuyCkm.exe] - C:\Users\Ashish\AppData\Local\6OJUXBFT\CAtxuyCkm.exe [113664 2013-08-25] (Mzkzc Bxxvsb)
HKU\Ashish\...\Winlogon: [shell] cmd.exe [345088 2010-11-20] (Microsoft Corporation) <==== ATTENTION
HKU\Ashish\...\Command Processor: "C:\Users\Ashish\AppData\Local\6OJUXBFT\CAtxuyCkm.exe" <===== ATTENTION!
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-11] (Akamai Technologies, Inc.)
S2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-27] (Microsoft Corp.)
S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [427432 2013-02-22] ()
S2 GoogleInputService; C:\Program Files (x86)\Google\Google Input Tools\GoogleInputService.exe [164888 2012-11-05] (Google Inc)
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe [237328 2012-03-30] (McAfee, Inc.)
S2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [116632 2012-07-13] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-07-19] ()
S2 PCloudd; C:\Program Files (x86)\Iomega Storage Manager\pCloudd.exe [213504 2012-09-08] (Iomega Corp)
S2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [258048 2013-03-04] (Sony Corporation)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [427432 2013-02-22] ()
S2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)
S3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1286784 2012-10-26] (Sony Corporation)
S2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad [x]

==================== Drivers (Whitelisted) ====================

S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2010-12-07] (LG Electronics Inc.)
S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2010-12-07] (LG Electronics Inc.)
S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2010-12-07] (LG Electronics Inc.)
S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2010-12-07] (LG Electronics Inc.)
S3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138872 2011-07-28] (SlySoft, Inc.)
S2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2012-11-06] ()
S1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [108584 2012-12-21] (Trend Micro Inc.)
S0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [174016 2012-12-21] (Trend Micro Inc.)
S0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [46392 2012-08-24] (Trend Micro Inc.)
S3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [94520 2012-12-07] (Trend Micro Inc.)
S1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [77184 2012-12-21] (Trend Micro Inc.)
S3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [210232 2012-07-05] (Trend Micro Inc.)
S1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105744 2012-05-02] (Trend Micro Inc.)
S3 vNICdrv; C:\Windows\System32\DRIVERS\vNICdrv.sys [20048 2012-09-08] (Iomega Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 motusbdevice; system32\DRIVERS\motusbdevice.sys [x]
S2 MSSQL$DDNI;
S2 TMAgent;

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\bu7IllhSkV6
2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\Users\Ashish\AppData\Local\C44LM2K0Ut
2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\ProgramData\y5DiWe8JO
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\WGKUARGMM
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\Users\Ashish\AppData\Local\UE2Z8AKhRwb
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\ProgramData\ZmyAhAn5wG
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\vA2cBKmw
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\Users\Ashish\AppData\Local\cqxqs8h1
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\ProgramData\Tvpsphdo
2013-08-31 09:38 - 2013-08-31 13:41 - 00000380 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Ashish.job
2013-08-31 09:38 - 2013-08-31 13:25 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Ashish.job
2013-08-31 09:38 - 2013-08-31 13:25 - 00000370 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Ashish.job
2013-08-31 09:38 - 2013-08-31 09:38 - 00003622 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002972 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002968 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002676 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Ashish
2013-08-25 16:14 - 2013-08-25 16:14 - 00001147 _____ C:\Users\Public\Desktop\AoA Audio Extractor Platinum.lnk
2013-08-25 16:14 - 2007-05-13 09:24 - 00086683 _____ (Open Source Software community project) C:\Windows\SysWOW64\pthreadGC2.dll
2013-08-25 16:12 - 2013-08-25 16:22 - 00009866 _____ C:\Windows\RegBootClean64.CFG
2013-08-25 16:06 - 2013-08-25 16:14 - 00000000 ____D C:\Program Files (x86)\AoA Audio Extractor Platinum
2013-08-25 16:00 - 2013-08-25 16:00 - 00000000 ____D C:\Users\Ashish\Documents\eRightSoft
2013-08-25 15:59 - 2013-08-29 19:58 - 00000000 ____D C:\Program Files (x86)\eRightSoft
2013-08-25 15:59 - 2004-07-02 14:33 - 00327749 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\drvc.dll
2013-08-25 15:06 - 2013-08-25 16:37 - 00000000 ____D C:\Users\Ashish\Desktop\Karaoke mp3 2
2013-08-25 14:43 - 2013-08-25 15:01 - 00000000 ____D C:\Users\Ashish\Desktop\Karaoke MP3
2013-08-25 14:40 - 2013-08-25 14:40 - 00000000 ____D C:\Users\Ashish\AppData\Local\Xenocode
2013-08-25 14:39 - 2013-08-25 14:39 - 00001150 _____ C:\Users\Ashish\Desktop\Flv Audio Video Extractor.lnk
2013-08-25 14:39 - 2013-08-25 14:39 - 00000000 ____D C:\Program Files (x86)\Flv Audio Video Extractor
2013-08-25 14:39 - 2011-12-09 05:56 - 00587768 _____ (Codejock Software) C:\Windows\SysWOW64\Codejock.SkinFramework.Unicode.v15.2.1.ocx
2013-08-25 11:49 - 2013-08-25 16:12 - 00003370 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-25 11:49 - 2013-08-25 16:12 - 00003238 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-25 10:45 - 2013-08-31 13:26 - 00000000 ____D C:\Users\Ashish\AppData\Local\6OJUXBFT
2013-08-25 10:44 - 2013-08-26 04:15 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Kishore [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 10:43 - 2013-08-25 10:50 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Lata [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 10:40 - 2013-08-25 22:01 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Mohd. Rafi [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 09:58 - 2013-08-27 20:38 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke_Special_15-CDs
2013-08-23 20:02 - 2013-08-23 20:08 - 00000000 ____D C:\Users\Ashish\Desktop\Poetry
2013-08-23 19:23 - 2013-08-31 13:41 - 00003348 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-23 19:23 - 2013-08-31 13:41 - 00003216 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-14 18:27 - 2013-08-14 18:27 - 00000000 _____ C:\Windows\SysWOW64\shoA190.tmp
2013-08-14 18:12 - 2013-07-25 21:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-08-14 18:12 - 2013-07-25 21:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-08-14 18:12 - 2013-07-25 21:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-08-14 18:12 - 2013-07-25 21:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-08-14 18:12 - 2013-07-25 21:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-08-14 18:12 - 2013-07-25 19:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-08-14 18:12 - 2013-07-25 19:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 18:12 - 2013-07-25 19:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 18:12 - 2013-07-25 19:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 18:12 - 2013-07-25 19:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 18:12 - 2013-07-25 19:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 18:12 - 2013-07-25 18:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 18:12 - 2013-07-25 18:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-08-14 18:12 - 2013-07-25 17:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 17:58 - 2013-07-25 01:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-08-14 17:58 - 2013-07-25 00:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 17:58 - 2013-07-18 17:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-08-14 17:58 - 2013-07-18 17:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 17:58 - 2013-07-08 22:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-08-14 17:58 - 2013-07-08 21:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-08-14 17:58 - 2013-07-08 21:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-08-14 17:58 - 2013-07-08 21:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2013-08-14 17:58 - 2013-07-08 21:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2013-08-14 17:58 - 2013-07-08 21:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-08-14 17:58 - 2013-07-08 21:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-08-14 17:58 - 2013-07-08 21:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-08-14 17:58 - 2013-07-08 21:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 17:58 - 2013-07-08 21:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 17:58 - 2013-07-08 20:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 17:58 - 2013-07-08 20:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 17:58 - 2013-07-08 20:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 17:58 - 2013-07-08 20:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 17:58 - 2013-07-08 20:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 17:58 - 2013-07-08 20:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 17:58 - 2013-07-08 20:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 17:58 - 2013-07-08 18:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 17:58 - 2013-07-08 18:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 17:58 - 2013-07-08 18:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 17:58 - 2013-07-08 18:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 17:58 - 2013-06-14 20:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys
2013-08-14 17:56 - 2013-07-05 22:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-08-10 13:41 - 2013-08-10 13:43 - 33984417 ____R C:\Users\Ashish\Downloads\Temple Run 2 v1.0.1.apk
2013-08-09 19:51 - 2013-08-09 19:52 - 02913412 ____R C:\Users\Ashish\Downloads\0028641418Poetry.epub
2013-08-08 21:22 - 2013-08-08 21:23 - 00000000 ____D C:\Users\Ashish\Downloads\Nautanki Saala (2013) 720p BRRip x264 AAC [HINDI] [955MB]--[CooL GuY] {{a2zRG}}
2013-08-08 20:30 - 2013-08-08 21:01 - 00000000 ____D C:\Users\Ashish\Downloads\Zindagi 50-50 (2013) DVDRip -Xvid - [1CD] - [ExclusivE]_
2013-08-08 20:30 - 2013-08-08 20:33 - 00000000 ____D C:\Users\Ashish\Downloads\Saare Jahaan Se Mehnga 2013 Hindi DTHRip 400MB x264 AAC NimitMak SilverRG
2013-08-08 20:26 - 2013-08-10 17:31 - 1553543204 ____R C:\Users\Ashish\Downloads\Zilla Ghaziabad (2013) 1-3 HD-WebRip -Xvid-AC3 5.1 - Team IcTv Exclusive (1).avi
2013-08-08 20:25 - 2013-08-08 20:25 - 00000000 ____D C:\Users\Ashish\Downloads\Bajatey Raho (2013) Hindi DvDScr XviD xRG
2013-08-08 19:26 - 2013-08-08 19:56 - 00000000 ____D C:\Users\Ashish\Downloads\Consumer Reports - Top Tablets Phones Cameras Laptops and More For Your Budget (August 2013)
2013-08-08 19:15 - 2013-08-08 19:15 - 00000875 _____ C:\Users\Ashish\Desktop\BitTorrent.lnk
2013-08-08 19:13 - 2013-08-08 19:13 - 00000000 ____D C:\Users\Ashish\Downloads\Consumer Reports - Grow Your Savings- Make More Money With Your 401(k) (September 2013)
2013-08-06 21:13 - 2013-08-06 21:13 - 00000000 ____D C:\Users\Ashish\Desktop\San.Andreas.Alistair.MacLean
2013-08-05 18:11 - 2013-08-05 18:11 - 00000000 ____D C:\Users\Ashish\Downloads\Alistair MacLean
2013-08-03 13:00 - 2013-08-03 13:10 - 00000000 ____D C:\Users\Ashish\Desktop\Pics 2
2013-08-02 18:09 - 2013-08-02 18:13 - 00000000 ____D C:\Users\Ashish\Desktop\pics

==================== One Month Modified Files and Folders =======

2013-09-01 00:43 - 2013-09-01 00:43 - 00000000 ____D C:\FRST
2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\bu7IllhSkV6
2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\Users\Ashish\AppData\Local\C44LM2K0Ut
2013-08-31 13:41 - 2013-08-31 13:41 - 00182272 _____ C:\ProgramData\y5DiWe8JO
2013-08-31 13:41 - 2013-08-31 09:38 - 00000380 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Ashish.job
2013-08-31 13:41 - 2013-08-23 19:23 - 00003348 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-31 13:41 - 2013-08-23 19:23 - 00003216 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-31 13:41 - 2013-04-12 18:46 - 00009130 _____ C:\Windows\setupact.log
2013-08-31 13:41 - 2011-05-09 19:15 - 00000050 _____ C:\Windows\System32\SupplicantTest.log
2013-08-31 13:41 - 2011-05-09 19:13 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-31 13:41 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\WGKUARGMM
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\Users\Ashish\AppData\Local\UE2Z8AKhRwb
2013-08-31 13:39 - 2013-08-31 13:39 - 00182272 _____ C:\ProgramData\ZmyAhAn5wG
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\Users\Ashish\AppData\Roaming\vA2cBKmw
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\Users\Ashish\AppData\Local\cqxqs8h1
2013-08-31 13:26 - 2013-08-31 13:26 - 00182272 _____ C:\ProgramData\Tvpsphdo
2013-08-31 13:26 - 2013-08-25 10:45 - 00000000 ____D C:\Users\Ashish\AppData\Local\6OJUXBFT
2013-08-31 13:25 - 2013-08-31 09:38 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Ashish.job
2013-08-31 13:25 - 2013-08-31 09:38 - 00000370 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Ashish.job
2013-08-31 10:48 - 2011-05-09 18:56 - 01449161 _____ C:\Windows\WindowsUpdate.log
2013-08-31 10:40 - 2011-05-09 19:13 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-31 10:18 - 2012-04-29 19:42 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-31 10:09 - 2011-05-15 17:05 - 00000000 ____D C:\Users\Ashish\AppData\Roaming\vlc
2013-08-31 09:38 - 2013-08-31 09:38 - 00003622 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002972 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002968 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Ashish
2013-08-31 09:38 - 2013-08-31 09:38 - 00002676 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Ashish
2013-08-29 23:00 - 2011-05-10 19:30 - 00000000 ____D C:\Users\Ashish\AppData\Local\Adobe
2013-08-29 19:58 - 2013-08-25 15:59 - 00000000 ____D C:\Program Files (x86)\eRightSoft
2013-08-28 07:17 - 2011-12-25 17:13 - 00028672 _____ C:\Users\Ashish\Desktop\Password.xlsx
2013-08-27 20:50 - 2011-05-10 18:51 - 00000000 ____D C:\Users\Ashish\AppData\Roaming\BitTorrent
2013-08-27 20:38 - 2013-08-25 09:58 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke_Special_15-CDs
2013-08-26 04:15 - 2013-08-25 10:44 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Kishore [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 22:01 - 2013-08-25 10:40 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Mohd. Rafi [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 16:37 - 2013-08-25 15:06 - 00000000 ____D C:\Users\Ashish\Desktop\Karaoke mp3 2
2013-08-25 16:22 - 2013-08-25 16:12 - 00009866 _____ C:\Windows\RegBootClean64.CFG
2013-08-25 16:22 - 2012-03-20 19:29 - 00234544 _____ C:\Windows\RegBootClean64.exe
2013-08-25 16:14 - 2013-08-25 16:14 - 00001147 _____ C:\Users\Public\Desktop\AoA Audio Extractor Platinum.lnk
2013-08-25 16:14 - 2013-08-25 16:06 - 00000000 ____D C:\Program Files (x86)\AoA Audio Extractor Platinum
2013-08-25 16:12 - 2013-08-25 11:49 - 00003370 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-25 16:12 - 2013-08-25 11:49 - 00003238 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2591141585-2933172239-3159010534-1002
2013-08-25 16:12 - 2011-05-10 08:31 - 00000000 ____D C:\ProgramData\Trend Micro
2013-08-25 16:00 - 2013-08-25 16:00 - 00000000 ____D C:\Users\Ashish\Documents\eRightSoft
2013-08-25 15:01 - 2013-08-25 14:43 - 00000000 ____D C:\Users\Ashish\Desktop\Karaoke MP3
2013-08-25 14:40 - 2013-08-25 14:40 - 00000000 ____D C:\Users\Ashish\AppData\Local\Xenocode
2013-08-25 14:39 - 2013-08-25 14:39 - 00001150 _____ C:\Users\Ashish\Desktop\Flv Audio Video Extractor.lnk
2013-08-25 14:39 - 2013-08-25 14:39 - 00000000 ____D C:\Program Files (x86)\Flv Audio Video Extractor
2013-08-25 10:50 - 2013-08-25 10:43 - 00000000 ____D C:\Users\Ashish\Downloads\Karaoke Classic Lata [2008-MP3-VBR-320Kbps] - xDR
2013-08-25 10:08 - 2009-07-13 20:45 - 00014160 _____ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-25 10:08 - 2009-07-13 20:45 - 00014160 _____ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-23 20:08 - 2013-08-23 20:02 - 00000000 ____D C:\Users\Ashish\Desktop\Poetry
2013-08-23 19:27 - 2009-07-13 21:13 - 00796068 _____ C:\Windows\System32\PerfStringBackup.INI
2013-08-20 20:18 - 2012-04-29 19:42 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-20 20:18 - 2012-04-29 19:42 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-20 20:18 - 2011-05-17 08:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-18 17:46 - 2009-07-13 21:08 - 00032634 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-17 13:31 - 2012-07-11 19:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-08-17 13:31 - 2012-07-11 19:45 - 00000000 ____D C:\ProgramData\Skype
2013-08-16 01:33 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-08-15 18:29 - 2012-10-14 10:59 - 00000000 ___RD C:\Users\Ashish\Dropbox
2013-08-15 18:29 - 2012-10-14 10:57 - 00000000 ____D C:\Users\Ashish\AppData\Roaming\Dropbox
2013-08-14 18:27 - 2013-08-14 18:27 - 00000000 _____ C:\Windows\SysWOW64\shoA190.tmp
2013-08-14 18:12 - 2011-07-04 11:24 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 18:06 - 2013-07-16 18:50 - 00000000 ____D C:\Windows\System32\MRT
2013-08-14 18:01 - 2011-05-12 18:11 - 78161360 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-08-10 17:31 - 2013-08-08 20:26 - 1553543204 ____R C:\Users\Ashish\Downloads\Zilla Ghaziabad (2013) 1-3 HD-WebRip -Xvid-AC3 5.1 - Team IcTv Exclusive (1).avi
2013-08-10 13:43 - 2013-08-10 13:41 - 33984417 ____R C:\Users\Ashish\Downloads\Temple Run 2 v1.0.1.apk
2013-08-09 20:25 - 2013-06-16 12:22 - 00000000 ____D C:\Users\Ashish\Desktop\15230616
2013-08-09 20:19 - 2013-04-14 00:24 - 00029650 _____ C:\Windows\PFRO.log
2013-08-09 19:52 - 2013-08-09 19:51 - 02913412 ____R C:\Users\Ashish\Downloads\0028641418Poetry.epub
2013-08-08 21:23 - 2013-08-08 21:22 - 00000000 ____D C:\Users\Ashish\Downloads\Nautanki Saala (2013) 720p BRRip x264 AAC [HINDI] [955MB]--[CooL GuY] {{a2zRG}}
2013-08-08 21:01 - 2013-08-08 20:30 - 00000000 ____D C:\Users\Ashish\Downloads\Zindagi 50-50 (2013) DVDRip -Xvid - [1CD] - [ExclusivE]_
2013-08-08 20:33 - 2013-08-08 20:30 - 00000000 ____D C:\Users\Ashish\Downloads\Saare Jahaan Se Mehnga 2013 Hindi DTHRip 400MB x264 AAC NimitMak SilverRG
2013-08-08 20:26 - 2013-07-15 18:41 - 00000000 ____D C:\Users\Ashish\Downloads\008
2013-08-08 20:25 - 2013-08-08 20:25 - 00000000 ____D C:\Users\Ashish\Downloads\Bajatey Raho (2013) Hindi DvDScr XviD xRG
2013-08-08 19:56 - 2013-08-08 19:26 - 00000000 ____D C:\Users\Ashish\Downloads\Consumer Reports - Top Tablets Phones Cameras Laptops and More For Your Budget (August 2013)
2013-08-08 19:15 - 2013-08-08 19:15 - 00000875 _____ C:\Users\Ashish\Desktop\BitTorrent.lnk
2013-08-08 19:13 - 2013-08-08 19:13 - 00000000 ____D C:\Users\Ashish\Downloads\Consumer Reports - Grow Your Savings- Make More Money With Your 401(k) (September 2013)
2013-08-06 21:18 - 2011-05-18 19:16 - 00000000 ____D C:\Users\Ashish\Calibre Library
2013-08-06 21:13 - 2013-08-06 21:13 - 00000000 ____D C:\Users\Ashish\Desktop\San.Andreas.Alistair.MacLean
2013-08-05 18:11 - 2013-08-05 18:11 - 00000000 ____D C:\Users\Ashish\Downloads\Alistair MacLean
2013-08-03 13:10 - 2013-08-03 13:00 - 00000000 ____D C:\Users\Ashish\Desktop\Pics 2
2013-08-03 13:06 - 2011-05-09 18:32 - 00000000 ____D C:\users\Ashish
2013-08-02 18:13 - 2013-08-02 18:09 - 00000000 ____D C:\Users\Ashish\Desktop\pics

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2591141585-2933172239-3159010534-1002\$59df36f9706368e2c1236e1617d1aaa5

Files to move or delete:
====================
C:\Users\Ashish\AppData\Local\6OJUXBFT\CAtxuyCkm.exe
C:\Users\Ashish\AppData\Local\Temp\01366592978573.exe
C:\Users\Ashish\AppData\Local\Temp\01366592979156.exe
C:\Users\Ashish\AppData\Local\Temp\6po9eoq9.dll
C:\Users\Ashish\AppData\Local\Temp\aae.exe
C:\Users\Ashish\AppData\Local\Temp\GLF1C7A.EXE
C:\Users\Ashish\AppData\Local\Temp\GLF2B98.EXE
C:\Users\Ashish\AppData\Local\Temp\GLF34BC.EXE
C:\Users\Ashish\AppData\Local\Temp\GLF3CF7.EXE
C:\Users\Ashish\AppData\Local\Temp\GLFE257.EXE
C:\Users\Ashish\AppData\Local\Temp\GLFEB5D.EXE
C:\Users\Ashish\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Ashish\AppData\Local\Temp\lowproc.exe
C:\Users\Ashish\AppData\Local\Temp\mtfrvyhftxersafybkk.bfg
C:\Users\Ashish\AppData\Local\Temp\mtfrvyhftxersafybkk.dll
C:\Users\Ashish\AppData\Local\Temp\SCC.dll
C:\Users\Ashish\AppData\Local\Temp\stubhelper.dll
C:\Users\Ashish\AppData\Local\Temp\uttAB2F.tmp.exe
C:\Users\Ashish\AppData\Local\Temp\VCPerfService32.exe
C:\Users\Ashish\AppData\Local\Temp\vlc-2.0.6-win32.exe
C:\Users\Ashish\AppData\Local\Temp\vlc-2.0.7-win32.exe
C:\Users\Ashish\AppData\Local\Temp\~rnsetup\GEMSETUP\msvcr100.dll
C:\Users\Ashish\AppData\Local\Temp\~rnsetup\GEMSETUP\pnrs3260.dll
C:\Users\Ashish\AppData\Local\Temp\VSDA71.tmp\setup.exe
C:\Users\Ashish\AppData\Local\Temp\VSD5C19.tmp\setup.exe
C:\Users\Ashish\AppData\Local\Temp\Rar$EX60.952\aaep.exe
C:\Users\Ashish\AppData\Local\Temp\nsi762C.tmp\DropboxNSISTools.dll
C:\Users\Ashish\AppData\Local\Temp\GLF7D6A\Troubleshooter Installer - RC1.exe
C:\Users\Ashish\AppData\Local\Temp\GLF586B\setup32.exe
C:\Users\Ashish\AppData\Local\Temp\GLF586B\setup64.exe
C:\Users\Ashish\AppData\Local\Temp\g2m2A56.tmp\G2MCoreInstExtractor.exe
C:\Users\Ashish\AppData\Local\Temp\esrv\64\esrv.exe
C:\Users\Ashish\AppData\Local\Temp\esrv\64\esrv_svc.exe
C:\Users\Ashish\AppData\Local\Temp\esrv\64\intel_modeler.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\64\sony_acpi_battery_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\64\sony_foreground_window_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\64\sony_sema_thermal_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\64\sony_wifi_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\32\esrv.exe
C:\Users\Ashish\AppData\Local\Temp\esrv\32\esrv_svc.exe
C:\Users\Ashish\AppData\Local\Temp\esrv\32\intel_modeler.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\32\sony_acpi_battery_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\32\sony_foreground_window_input.dll
C:\Users\Ashish\AppData\Local\Temp\esrv\32\sony_wifi_input.dll

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-08-24 11:41:38
Restore point made on: 2013-08-26 00:00:50
Restore point made on: 2013-08-29 00:02:16
Restore point made on: 2013-08-30 00:00:32
Restore point made on: 2013-08-31 10:48:19

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 3758.1 MB
Available physical RAM: 3115.05 MB
Total Pagefile: 3756.25 MB
Available Pagefile: 3107.12 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:204.05 GB) (Free:21.17 GB) NTFS
Drive d: (Data) (Fixed) (Total:250 GB) (Free:70.83 GB) NTFS
Drive f: (Recovery) (Fixed) (Total:11.61 GB) (Free:0.76 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive h: (PublicZone) (Removable) (Total:0.71 GB) (Free:0.22 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 74F027F7)
Partition 1: (Not Active) - (Size=12 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=204 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=250 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 728 MB) (Disk ID: BCCFD9C2)
Partition 1: (Active) - (Size=727 MB) - (Type=06)

LastRegBack: 2013-08-23 19:20

==================== End Of Log ============================

 

 

 

How do I proceed from here..?

Thanks.

 

 

Link to post
Share on other sites

OK, here you go......this should get you going:

Please download the attached fixlist.txt and copy it to your flashdrive.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options. (as you did before)

Run FRST64 or FRST (which ever one you're using) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

See if the computer boots normally now and if so..........run MBAR

If not...rescan with FRST and post the new log

Download Malwarebytes Anti-Rootkit from HERE

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log.txt and system-log.txt
To attach a log if needed:

Bottom right corner of this page.

more-reply-options.jpg

New window that comes up.

choose-files1.jpg

~~~~~~~~~~~~~~~~~~~~~~~

Note:

If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

Internet access

Windows Update

Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot. It's located in the Plugins folder which is in the MBAR folder.

Just run fixdamage.exe.

Verify that they are now functioning normally.

MrC

Link to post
Share on other sites

Well Done, lets run ComboFix to clear up any leftovers.

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

---------->NOTE<----------

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC

Link to post
Share on other sites

Looks Good......

Lets clean out any adware while you're here:

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
If you agree with everything listed to be removed in the folders section...........

Double click on AdwCleaner.exe to run the tool again.

  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • This time click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Good......

Finally lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
Link to post
Share on other sites

This is the result from Security Check.

 

 Results of screen317's Security Check version 0.99.73 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 10 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Trend Micro Titanium Maximum Security  
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware version 1.75.0.1300 
 Java 6 Update 20 
 Java version out of Date!
 Adobe Flash Player 11.8.800.94 
 Adobe Reader 9 Adobe Reader out of Date!
 Google Chrome 28.0.1500.95 
 Google Chrome 29.0.1547.62 
````````Process Check: objlist.exe by Laurent```````` 
 windows defender MpCmdRun.exe  
 Trend Micro AMSP coreServiceShell.exe 
 Trend Micro UniClient UiFrmWrk uiWatchDog.exe
 Trend Micro AMSP coreFrameworkHost.exe 
 Trend Micro AMSP AMSP_LogServer.exe 
 Trend Micro UniClient UiFrmWrk uiSeAgnt.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
 

Link to post
Share on other sites

Out dated programs on the system are vulnerable to malware.
Please update or uninstall them:


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Java™ 6 Update 20 <-----please uninstall from your add/remove programs and any other Java listed

Java version out of Date! <-------Download and install the latest version (Java™ 7 Update 25) from Here. Uncheck the box to install the Ask toolbar!!! and any other free "stuff".

----------------------------------------------

Adobe Reader 9 Adobe Reader out of Date! <---please check for an update if available or uninstall and download and install Foxit Reader which is less vulnerable to malware and much better than Adobe. Don't install any toolbars that may come with it (ASK Toolbar).

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

A little clean up to do....

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

cf2.jpg

Then hit enter.
This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)

---------------------------------

If you used FRST:
Download the fixlist.txt to the same folder as FRST.
Run FRST and click Fix only once and wait
That will delete the quarantine folder created by FRST.

-----------------------------

Please download OTC to your desktop.
http://oldtimer.geekstogo.com/OTC.exe

Double-click OTC to run it. (Vista and up users, please right click on OTC and select "Run as an Administrator")
Click on the CleanUp! button and follow the prompts.
(If you get a warning from your firewall or other security programs regarding OTC attempting to contact the Internet, please allow the connection.)
You will be asked to reboot the machine to finish the Cleanup process, choose Yes.
After the reboot all the tools we used should be gone.
Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.

Any other programs or logs you can manually delete.
IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST, MBAR, etc....AdwCleaner > just run the program and click uninstall.

-------------------------------

Any questions...please post back.

If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Link to post
Share on other sites

Thanks a lot MrCharlie.

I have uninstalled Java6, and updated it to Java7; ran combofix /uninstall, and then the frst process. finally the OTC.

 

As you are helping me on this issue, can I ask you about another error msg on my laptop..? (it was there even before the FBI virus)

It is the "Netmeter.exe" error msg

 

Any ideas what should I do? I had seen many sites stating to use so and so removal tool, but was a bit skeptical in downloading anything new.  Any suggestions in what tool to use?

 

Thanks.

post-144942-0-31298000-1378140920_thumb.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.