StylusTrouble
Topic Starter
I started getting messages from my Norton Security that it was blocking a trojan.zbot's attempts to connect to the internet. Occassionaly i would have one about a trojan 3gen.
At first it seemed to make very little difference to my computer perhaps making it a little slower. As i started to perform the checks neessary to obtain the logs you need the downloads were very slow and then my computer froze. It has taken several attempts to to turn on the computer as it wasn't responding and now seems to have turned off my virus protection.
Any help with this will be great
here are the logs
Malwarebytes' Anti-Malware 1.44
Database version: 3539
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
11/01/2010 13:32:16
mbam-log-2010-01-11 (13-32-12).txt
Scan type: Quick Scan
Objects scanned: 99102
Time elapsed: 6 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 3
Registry Data Items Infected: 4
Folders Infected: 1
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\LREC75DND7 (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\E8WECRKKMV (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lrec75dnd7 (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> No action taken.
Folders Infected:
C:\Windows\System32\lowsec (Stolen.data) -> No action taken.
Files Infected:
C:\Windows\Temp\fbqd.tmp\svchost.exe (Spyware.Passwords) -> No action taken.
C:\Users\david\downloads\ZwinkySetup2.3.50.57.ZJfox000.exe (Adware.MyWebSearch) -> No action taken.
C:\Windows\System32\lowsec\local.ds (Stolen.data) -> No action taken.
C:\Windows\System32\lowsec\user.ds (Stolen.data) -> No action taken.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> No action taken.
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\Windows\System32\sshnas.dll (Trojan.Agent) -> No action taken.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-11 13:55:47
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\david\AppData\Local\Temp\awtdikod.sys
—- System - GMER 1.0.15 —-
SSDT 875F3C60 ZwAlertResumeThread
SSDT 8761B150 ZwAlertThread
SSDT 87622A48 ZwAllocateVirtualMemory
SSDT 85B72FB0 ZwAlpcConnectPort
SSDT 8765C808 ZwAssignProcessToJobObject
SSDT 876574F0 ZwCreateMutant
SSDT 8765D5F8 ZwCreateSymbolicLinkObject
SSDT 8764B668 ZwCreateThread
SSDT 87656048 ZwDebugActiveProcess
SSDT 87622C60 ZwDuplicateObject
SSDT 87622428 ZwFreeVirtualMemory
SSDT 876493A8 ZwImpersonateAnonymousToken
SSDT 876504E0 ZwImpersonateThread
SSDT 8723A430 ZwLoadDriver
SSDT 876222C8 ZwMapViewOfSection
SSDT 8761F048 ZwOpenEvent
SSDT 87623008 ZwOpenProcess
SSDT 87580068 ZwOpenProcessToken
SSDT 87624048 ZwOpenSection
SSDT 87622DB0 ZwOpenThread
SSDT 8765C2B8 ZwProtectVirtualMemory
SSDT 87574B98 ZwResumeThread
SSDT 875CBAF0 ZwSetContextThread
SSDT 876220F0 ZwSetInformationProcess
SSDT 87625048 ZwSetSystemInformation
SSDT 87623050 ZwSuspendProcess
SSDT 875FA048 ZwSuspendThread
SSDT 875666B8 ZwTerminateProcess
SSDT 875D0B98 ZwTerminateThread
SSDT 875B7C50 ZwUnmapViewOfSection
SSDT 87622738 ZwWriteVirtualMemory
SSDT 8765DA68 ZwCreateThreadEx
INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x91 ? 86BAFBF8
INT 0xA2 ? 86BAFBF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 851661F8
Device \FileSystem\fastfat \FatCdrom 878F41F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 851621F8
Device \Driver\usbohci \Device\USBPDO-0 86BD11F8
Device \Driver\usbohci \Device\USBPDO-1 86BD11F8
Device \Driver\usbehci \Device\USBPDO-2 86BD31F8
Device \Driver\usbohci \Device\USBPDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{17EEA341-584A-4D54-A539-5E24325FCE5D} 874ED1F8
Device \Driver\usbehci \Device\USBPDO-4 86BD31F8
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\volmgr \Device\HarddiskVolume1 851621F8
Device \Driver\volmgr \Device\HarddiskVolume2 851621F8
Device \Driver\cdrom \Device\CdRom0 86BB21F8
Device \Driver\volmgr \Device\HarddiskVolume3 851621F8
Device \Driver\netbt \Device\NetBt_Wins_Export 874ED1F8
Device \Driver\Smb \Device\NetbiosSmb 874F91F8
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\iScsiPrt \Device\RaidPort1 86BEF1F8
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbohci \Device\USBFDO-0 86BD11F8
Device \Driver\usbohci \Device\USBFDO-1 86BD11F8
Device \Driver\usbehci \Device\USBFDO-2 86BD31F8
Device \Driver\usbohci \Device\USBFDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{AAF7D1EC-25F8-482E-B66D-42E0FF000732} 874ED1F8
Device \Driver\usbehci \Device\USBFDO-4 86BD31F8
Device \FileSystem\fastfat \Fat 878F41F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 88EEB1F8
Device -> \Driver\ahcix86s \Device\Harddisk0\DR0 85289841
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
—- Files - GMER 1.0.15 —-
File C:\Windows\system32\drivers\ahcix86s.sys suspicious modification
—- EOF - GMER 1.0.15 —-
Nero DriveSpeed
Nero Express Help
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Norton 360
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
PhotoNow!
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
Samsung PC Studio 3 USB Driver Installer
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Sid Meier's Civilization III: Complete
Skype™ 4.0
SoulSeek 157 NS 13c
SoundTrax
Steam
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.762
Virtual DJ - Atomix Productions
VLC media player 1.0.2
WinAVIVideoConverter
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
WinRAR archiver
WinZip 12.0
Wireless Manager
==== Event Viewer Messages From Past Week ========
11/01/2010 14:25:50, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
11/01/2010 14:25:15, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume Acer.
11/01/2010 14:16:24, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IDSVix86 SRTSP
11/01/2010 14:16:24, Error: Service Control Manager [7023] - The WinDefend service terminated with the following error: The specified module could not be found.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The NTIPPKernel service failed to start due to the following error: The file or directory is corrupted and unreadable.
11/01/2010 14:15:55, Error: SRTSP [5] - Error loading Symantec real time Anti-Virus driver.
11/01/2010 14:15:55, Error: SRTSP [4] - Error loading virus definitions.
11/01/2010 14:08:05, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the N360 service.
10/01/2010 19:17:19, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Ati External Event Utility service.
08/01/2010 19:27:04, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
08/01/2010 19:27:04, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
08/01/2010 19:27:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
05/01/2010 10:31:42, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
05/01/2010 08:08:29, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
05/01/2010 08:08:29, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
05/01/2010 08:06:05, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.
==== End Of File ===========================
irefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2009-11-26 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2009-11-26 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2009-11-26 482432]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-8-20 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-8-20 81504]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-20 24576]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2009-11-26 117640]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2009-11-26 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-11-18 22072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
=============== Created Last 30 ================
2010-01-11 14:21 –dsh— c:\windows\system32\lowsec
2010-01-11 13:23 –d—– c:\users\david\appdata\roaming\Malwarebytes
2010-01-11 13:23 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 13:22 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-11 13:22 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-11 12:11 195,456 ——– c:\windows\system32\MpSigStub.exe
2010-01-10 14:10 –d–r– c:\program files\Norton Support
2010-01-04 22:31 –d—– c:\program files\Musicnotes
==================== Find3M ====================
2009-11-27 14:35 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-26 11:59 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-26 11:59 86,016 a——- c:\windows\inf\infstor.dat
2009-11-26 11:59 51,200 a——- c:\windows\inf\infpub.dat
2009-11-26 11:59 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:59 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:58 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 25,648 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2009-11-21 06:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 06:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-21 04:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-19 03:19 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 09:17 2,048 a——- c:\windows\system32\tzres.dll
2009-04-30 15:58 87,608 a——- c:\users\david\appdata\roaming\inst.exe
2009-04-30 15:58 47,360 a——- c:\users\david\appdata\roaming\pcouffin.sys
2008-01-21 02:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 14:26:17.48 ===============
At first it seemed to make very little difference to my computer perhaps making it a little slower. As i started to perform the checks neessary to obtain the logs you need the downloads were very slow and then my computer froze. It has taken several attempts to to turn on the computer as it wasn't responding and now seems to have turned off my virus protection.
Any help with this will be great
here are the logs
Malwarebytes' Anti-Malware 1.44
Database version: 3539
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
11/01/2010 13:32:16
mbam-log-2010-01-11 (13-32-12).txt
Scan type: Quick Scan
Objects scanned: 99102
Time elapsed: 6 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 3
Registry Data Items Infected: 4
Folders Infected: 1
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\LREC75DND7 (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\E8WECRKKMV (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lrec75dnd7 (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> No action taken.
Folders Infected:
C:\Windows\System32\lowsec (Stolen.data) -> No action taken.
Files Infected:
C:\Windows\Temp\fbqd.tmp\svchost.exe (Spyware.Passwords) -> No action taken.
C:\Users\david\downloads\ZwinkySetup2.3.50.57.ZJfox000.exe (Adware.MyWebSearch) -> No action taken.
C:\Windows\System32\lowsec\local.ds (Stolen.data) -> No action taken.
C:\Windows\System32\lowsec\user.ds (Stolen.data) -> No action taken.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> No action taken.
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\Windows\System32\sshnas.dll (Trojan.Agent) -> No action taken.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-11 13:55:47
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\david\AppData\Local\Temp\awtdikod.sys
—- System - GMER 1.0.15 —-
SSDT 875F3C60 ZwAlertResumeThread
SSDT 8761B150 ZwAlertThread
SSDT 87622A48 ZwAllocateVirtualMemory
SSDT 85B72FB0 ZwAlpcConnectPort
SSDT 8765C808 ZwAssignProcessToJobObject
SSDT 876574F0 ZwCreateMutant
SSDT 8765D5F8 ZwCreateSymbolicLinkObject
SSDT 8764B668 ZwCreateThread
SSDT 87656048 ZwDebugActiveProcess
SSDT 87622C60 ZwDuplicateObject
SSDT 87622428 ZwFreeVirtualMemory
SSDT 876493A8 ZwImpersonateAnonymousToken
SSDT 876504E0 ZwImpersonateThread
SSDT 8723A430 ZwLoadDriver
SSDT 876222C8 ZwMapViewOfSection
SSDT 8761F048 ZwOpenEvent
SSDT 87623008 ZwOpenProcess
SSDT 87580068 ZwOpenProcessToken
SSDT 87624048 ZwOpenSection
SSDT 87622DB0 ZwOpenThread
SSDT 8765C2B8 ZwProtectVirtualMemory
SSDT 87574B98 ZwResumeThread
SSDT 875CBAF0 ZwSetContextThread
SSDT 876220F0 ZwSetInformationProcess
SSDT 87625048 ZwSetSystemInformation
SSDT 87623050 ZwSuspendProcess
SSDT 875FA048 ZwSuspendThread
SSDT 875666B8 ZwTerminateProcess
SSDT 875D0B98 ZwTerminateThread
SSDT 875B7C50 ZwUnmapViewOfSection
SSDT 87622738 ZwWriteVirtualMemory
SSDT 8765DA68 ZwCreateThreadEx
INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x82 ? 86BAFBF8
INT 0x91 ? 86BAFBF8
INT 0xA2 ? 86BAFBF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 851661F8
Device \FileSystem\fastfat \FatCdrom 878F41F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 851621F8
Device \Driver\usbohci \Device\USBPDO-0 86BD11F8
Device \Driver\usbohci \Device\USBPDO-1 86BD11F8
Device \Driver\usbehci \Device\USBPDO-2 86BD31F8
Device \Driver\usbohci \Device\USBPDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{17EEA341-584A-4D54-A539-5E24325FCE5D} 874ED1F8
Device \Driver\usbehci \Device\USBPDO-4 86BD31F8
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\volmgr \Device\HarddiskVolume1 851621F8
Device \Driver\volmgr \Device\HarddiskVolume2 851621F8
Device \Driver\cdrom \Device\CdRom0 86BB21F8
Device \Driver\volmgr \Device\HarddiskVolume3 851621F8
Device \Driver\netbt \Device\NetBt_Wins_Export 874ED1F8
Device \Driver\Smb \Device\NetbiosSmb 874F91F8
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\iScsiPrt \Device\RaidPort1 86BEF1F8
AttachedDevice \Driver\tdx \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbohci \Device\USBFDO-0 86BD11F8
Device \Driver\usbohci \Device\USBFDO-1 86BD11F8
Device \Driver\usbehci \Device\USBFDO-2 86BD31F8
Device \Driver\usbohci \Device\USBFDO-3 86BD11F8
Device \Driver\netbt \Device\NetBT_Tcpip_{AAF7D1EC-25F8-482E-B66D-42E0FF000732} 874ED1F8
Device \Driver\usbehci \Device\USBFDO-4 86BD31F8
Device \FileSystem\fastfat \Fat 878F41F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 88EEB1F8
Device -> \Driver\ahcix86s \Device\Harddisk0\DR0 85289841
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x95 0x5E 0xAE 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xE8 0x02 0x1A 0x51 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF6 0x2C 0x68 0x4A …
—- Files - GMER 1.0.15 —-
File C:\Windows\system32\drivers\ahcix86s.sys suspicious modification
—- EOF - GMER 1.0.15 —-
Nero DriveSpeed
Nero Express Help
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Norton 360
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
PhotoNow!
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
Samsung PC Studio 3 USB Driver Installer
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Sid Meier's Civilization III: Complete
Skype™ 4.0
SoulSeek 157 NS 13c
SoundTrax
Steam
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.762
Virtual DJ - Atomix Productions
VLC media player 1.0.2
WinAVIVideoConverter
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
WinRAR archiver
WinZip 12.0
Wireless Manager
==== Event Viewer Messages From Past Week ========
11/01/2010 14:25:50, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
11/01/2010 14:25:15, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume Acer.
11/01/2010 14:16:24, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IDSVix86 SRTSP
11/01/2010 14:16:24, Error: Service Control Manager [7023] - The WinDefend service terminated with the following error: The specified module could not be found.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
11/01/2010 14:16:24, Error: Service Control Manager [7000] - The NTIPPKernel service failed to start due to the following error: The file or directory is corrupted and unreadable.
11/01/2010 14:15:55, Error: SRTSP [5] - Error loading Symantec real time Anti-Virus driver.
11/01/2010 14:15:55, Error: SRTSP [4] - Error loading virus definitions.
11/01/2010 14:08:05, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the N360 service.
10/01/2010 19:17:19, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Ati External Event Utility service.
08/01/2010 19:27:04, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
08/01/2010 19:27:04, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
08/01/2010 19:27:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
05/01/2010 10:31:42, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
05/01/2010 08:08:29, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
05/01/2010 08:08:29, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
05/01/2010 08:06:05, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.
==== End Of File ===========================
irefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0305020.00b\SymEFA.sys [2009-11-26 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0305020.00b\BHDrvx86.sys [2009-11-26 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0305020.00b\cchpx86.sys [2009-11-26 482432]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-8-20 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2008-8-20 81504]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-8-20 24576]
R2 N360;Norton 360;c:\program files\norton 360\engine\3.5.2.11\ccSvcHst.exe [2009-11-26 117640]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0305020.00b\symndisv.sys [2009-11-26 48688]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-11-18 22072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
=============== Created Last 30 ================
2010-01-11 14:21 –dsh— c:\windows\system32\lowsec
2010-01-11 13:23 –d—– c:\users\david\appdata\roaming\Malwarebytes
2010-01-11 13:23 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 13:22 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-11 13:22 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-11 12:11 195,456 ——– c:\windows\system32\MpSigStub.exe
2010-01-10 14:10 –d–r– c:\program files\Norton Support
2010-01-04 22:31 –d—– c:\program files\Musicnotes
==================== Find3M ====================
2009-11-27 14:35 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-26 11:59 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-26 11:59 86,016 a——- c:\windows\inf\infstor.dat
2009-11-26 11:59 51,200 a——- c:\windows\inf\infpub.dat
2009-11-26 11:59 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-26 11:59 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-26 11:59 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-11-26 11:58 26,600 a—-r– c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 11:58 25,648 a—-r– c:\windows\system32\drivers\SymIMV.sys
2009-11-26 11:58 107,368 a—-r– c:\windows\system32\GEARAspi.dll
2009-11-21 06:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 06:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-21 04:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-19 03:20 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-19 03:19 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 09:17 2,048 a——- c:\windows\system32\tzres.dll
2009-04-30 15:58 87,608 a——- c:\users\david\appdata\roaming\inst.exe
2009-04-30 15:58 47,360 a——- c:\users\david\appdata\roaming\pcouffin.sys
2008-01-21 02:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 14:26:17.48 ===============