Ally
Topic Starter
Hi,I have had to re-post as I did not follow the correct procedure before
Anyway…..I thought I was malware free up until I decided to do a free online Virus scan with Bitdefender.After the scan completed it found two trojans calledTrojan.Wimad.Gen.1 which it disinfected and one Trojan called Gen:Trojan.Heur.iq8@YcK6Ffe which it failed to delete.I then clicked on the send report for analysis.I then ran an E-SET online san and it did not detect anything.I ran Avast stand-alone removal tool and this also did not pick up any detections. I still have a copy of the Bitdefender log file which I will post last.First I will post Mbytes,G-mer and DDS logs >>> Malwarebytes' Anti-Malware 1.44
Database version: 3632
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
25/01/2010 05:39:05
mbam-log-2010-01-25 (05-39-05).txt
Scan type: Quick Scan
Objects scanned: 114220
Time elapsed: 3 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-25 06:03:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Alistair\LOCALS~1\Temp\kfqiqaog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xABDC458C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xABDC4E0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xABDC5922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xABDC5E94]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateFile [0xAB5B9772]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xABDC3436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xABDC5D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xABDC4192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xABDC5C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xABDC434E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xABDC5FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xABDC7C08]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateThread [0xAB5B8FAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xABDC5CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xABDC75FA]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteKey [0xAB5B9594]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteValueKey [0xAB5B9466]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xABDC5576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xABDC85CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xABDC3ECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xABDC3F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xABDC5382]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwLoadDriver [0xAB5B8DE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xABDC3412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xABDC3424]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwMapViewOfSection [0xAB5B8B84]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xABDC40C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xABDC5F36]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenFile [0xAB5B99C2]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenKey [0xAB5B9760]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xABDC5E04]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenProcess [0xAB5B90CE]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenSection [0xAB5B9234]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xABDC6068]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenThread [0xAB5B917E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xABDC401E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xABDC3C46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xABDC7FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xABDC3896]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwQueueApcThread [0xAB5B905C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xABDC3B0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xABDC32B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xABDC63F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xABDC62B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xABDC739A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xABDCAE2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xABDC84AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xABDC3248]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSecureConnectPort [0xAB5B9AF0]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetContextThread [0xAB5B8B16]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xABDC6C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xABDC7786]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetSystemInformation [0xAB5B8F3E]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetValueKey [0xAB5B9660]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xABDC81F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xABDC8320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xABDC7526]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwTerminateProcess [0xAB5B934C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xABDC4860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xABDC7E8A]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwWriteVirtualMemory [0xAB5B8A48]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:04:34.79 on 25/01/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2858 [GMT 0:00]
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Alistair\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
uRun: [EPSON SX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifce.exe /fu "c:\windows\temp\E_SC.tmp" /EF "HKCU"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SkyTel] SkyTel.EXE
mRun: [AntiLogger] "c:\program files\antilogger\AntiLogger.exe" /minimized
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110}
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\kloehk.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: GrcorticOcm.Grcortic: {79b34a1f-d8fd-474f-84f3-8622d06faf40} - c:\windows\system32\grcortic.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\alistair\applic~1\mozilla\firefox\profiles\pbbl1whh.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://m.uk.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-7 28552]
R1 AntiLog32;AntiLog32;c:\program files\antilogger\AntiLog32.sys [2010-1-12 116072]
R1 EIO_XP;EIO_XP;c:\windows\system32\drivers\EIO_XP.sys [2010-1-21 12288]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-12-15 315408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-12-15 1858144]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-1-6 12672]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2010-1-5 14976]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2010-1-20 93184]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2009-12-16 532992]
S2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\c0.tmp –> c:\windows\system32\C0.tmp [?]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2009-12-17 14424]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-1-11 16456]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-1-11 11088]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 Video3D;ASUS Video3D Service;c:\windows\system32\drivers\video3d32.sys –> c:\windows\system32\drivers\Video3D32.sys [?]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-12-15 90352]
=============== Created Last 30 ================
2010-01-24 11:21 –d—– c:\program files\MAME
2010-01-23 06:17 –d—– c:\docume~1\alistair\applic~1\QuickScan
2010-01-21 13:10 –d—– c:\program files\ATI Technologies
2010-01-21 13:10 –d—– c:\program files\ATI
2010-01-21 13:09 –d—– C:\ATI
2010-01-21 12:11 12,288 a—-r– c:\windows\system32\drivers\EIO_XP.sys
2010-01-21 12:09 53,760 ac—— c:\windows\system32\dllcache\vfwwdm32.dll
2010-01-21 12:09 53,760 a——- c:\windows\system32\vfwwdm32.dll
2010-01-21 12:08 –d—– c:\program files\ASUS
2010-01-21 10:05 –d—– c:\program files\Essentials Codec Pack
2010-01-21 08:09 –d—– c:\docume~1\alistair\applic~1\PowerUp Software
2010-01-21 08:08 –d—– c:\docume~1\alluse~1\applic~1\PowerUp Software
2010-01-21 06:38 –d—– c:\program files\ESET
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1ins.dll
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1.dll
2010-01-20 09:32 53,632 a—-r– c:\windows\system32\drivers\NVENETFD.sys
2010-01-20 09:32 4,805 a——- c:\windows\system32\nvnrm.nvu
2010-01-20 09:31 888,064 a—-r– c:\windows\system32\drivers\nvnrm.sys
2010-01-20 09:31 37,376 a—-r– c:\windows\system32\nvconrm.dll
2010-01-20 09:31 22,016 a—-r– c:\windows\system32\drivers\nvnetbus.sys
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1ins.dll
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1.dll
2010-01-20 09:19 –d—– c:\program files\common files\ATI Technologies
2010-01-20 09:07 10 a——- c:\windows\WININIT.INI
2010-01-20 09:06 0 a——- c:\windows\ativpsrm.bin
2010-01-20 09:06 19,017 a——- c:\windows\atiogl.xml
2010-01-20 09:05 93,184 a—-r– c:\windows\system32\drivers\AtiHdmi.sys
2010-01-20 08:58 –d—– c:\program files\My Company Name
2010-01-20 06:46 –d—– c:\program files\SpeedFan
2010-01-20 06:46 45 a——- c:\windows\system32\initdebug.nfo
2010-01-18 06:49 –d—– c:\docume~1\alistair\applic~1\KALiNKOsoft
2010-01-13 01:58 –d—– c:\program files\FairUse Wizard 2
2010-01-13 01:06 –d—– c:\docume~1\alistair\applic~1\AnvSoft
2010-01-13 01:06 –d—– c:\program files\AnvSoft
2010-01-12 22:32 –d—– c:\program files\common files\DivX Shared
2010-01-12 19:31 -cd-h— c:\docume~1\alluse~1\applic~1\{ADBE1C37-5B60-41F1-8C26-C3F880D609C1}
2010-01-12 08:48 8,576 a——- c:\windows\system32\drivers\apgiywudryke.sys
2010-01-12 08:44 8,576 a——- c:\windows\system32\drivers\admqnrgkhnlw.sys
2010-01-12 08:43 8,576 a——- c:\windows\system32\drivers\yeoqjaedbosu.sys
2010-01-12 08:42 8,576 a——- c:\windows\system32\drivers\ywghcedstlcr.sys
2010-01-12 08:41 8,576 a——- c:\windows\system32\drivers\ynltosggncjp.sys
2010-01-12 08:40 8,576 a——- c:\windows\system32\drivers\ydugtctlvwoo.sys
2010-01-12 08:37 8,576 a——- c:\windows\system32\drivers\yhikanbisygi.sys
2010-01-12 08:34 –d—– c:\documents and settings\alistair\Pavark
2010-01-12 08:19 161,296 a——- c:\windows\system32\drivers\tmcomm.sys
2010-01-12 07:21 –d—– c:\program files\JockerSoft
2010-01-12 01:06 27,612 a——- c:\windows\syscall.dat
2010-01-12 01:06 –d—– c:\program files\AntiLogger
2010-01-11 23:09 461,368 a——- c:\windows\system32\pwNative.exe
2010-01-11 23:09 16,456 a——- c:\windows\system32\pwdrvio.sys
2010-01-11 23:09 11,088 a——- c:\windows\system32\pwdspio.sys
2010-01-11 23:09 –d—– c:\program files\Partition Wizard Home Edition 4.2.2
2010-01-10 22:13 –d—– c:\documents and settings\alistair\.thumbnails
2010-01-10 22:08 –d—– c:\documents and settings\alistair\.gimp-2.6
2010-01-10 21:13 –d—– c:\docume~1\alluse~1\applic~1\Simply Super Software
2010-01-10 15:09 –d—– c:\documents and settings\alistair\DoctorWeb
2010-01-10 14:23 –d—– c:\windows\Performance
2010-01-10 05:10 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions
2010-01-10 05:10 –d—– c:\program files\Innovative Solutions
2010-01-09 12:00 –d—– c:\windows\$regcmp$
2010-01-09 11:56 –d—– c:\program files\Intel Corporation
2010-01-09 11:52 –d—– c:\program files\SystemRequirementsLab
2010-01-08 12:21 –d—– c:\docume~1\alluse~1\applic~1\DriverScanner
2010-01-08 12:21 –d—– c:\docume~1\alistair\applic~1\Uniblue
2010-01-08 11:37 –d—– c:\windows\system32\%PersonalRootCertificateFolder%
2010-01-07 01:46 28,552 a——- c:\windows\system32\drivers\pavboot.sys
2010-01-07 01:45 –d—– c:\program files\Panda Security
2010-01-06 15:15 –d-h— C:\VJVod_Cache
2010-01-06 02:17 12,672 a——- c:\windows\system32\drivers\cpuz132_x32.sys
2010-01-06 02:17 –d—– c:\program files\CPUID
2010-01-06 02:12 –d—– c:\program files\Wise Registry Cleaner
2010-01-06 02:09 3,840 a——- c:\windows\system32\drivers\BANTExt.sys
2010-01-06 02:09 –d—– c:\program files\Belarc
2010-01-06 01:34 –d—– c:\program files\VS Revo Group
2010-01-06 01:09 –d—– c:\program files\Registry Clean Expert
2010-01-05 20:51 –d—– c:\program files\AviSynth 2.5
2010-01-05 20:25 –d—– c:\program files\DVD Shrink
2010-01-05 20:22 –d—– c:\program files\DVD Decrypter
2010-01-05 20:19 –d—– c:\docume~1\alistair\applic~1\RipIt4Me
2010-01-05 00:51 14,976 a——- c:\windows\system32\drivers\SBKUPNT.SYS
2010-01-05 00:51 13,312 a——- c:\windows\system32\DEVLOAD.EXE
2010-01-05 00:50 2,799 a——- c:\windows\SKLANG.INI
2010-01-05 00:50 306,688 a——- c:\windows\IsUninst.exe
2010-01-04 21:39 –d—– c:\windows\system32\NtmsData
2010-01-04 19:46 –d—– c:\program files\LSoft Technologies
2010-01-04 00:27 11,254 a——- c:\windows\system32\locate.com
2010-01-03 21:51 –d—– c:\docume~1\alistair\applic~1\Mp3tag
2010-01-03 21:51 –d—– c:\program files\Mp3tag
2010-01-03 21:41 –d—– c:\docume~1\alluse~1\applic~1\F-Secure
2010-01-03 19:14 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX
2010-01-03 19:14 118,784 a——- c:\windows\system32\MSSTDFMT.DLL
2010-01-03 19:14 –d—– c:\program files\SpywareBlaster
2010-01-03 17:43 –d—– c:\windows\system32\Adobe
2010-01-03 16:58 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2010-01-03 16:58 2,414,360 a——- c:\windows\system32\d3dx9_31.dll
2010-01-03 16:58 –d—– c:\windows\Logs
2010-01-02 20:29 1,184,984 a——- c:\windows\system32\wvc1dmod.dll
2010-01-02 20:29 626,688 a——- c:\windows\system32\vp7vfw.dll
2010-01-02 20:29 217,127 a——- c:\windows\system32\drv43260.dll
2010-01-02 20:29 208,935 a——- c:\windows\system32\drv33260.dll
2010-01-02 20:29 176,165 a——- c:\windows\system32\drv23260.dll
2010-01-02 20:29 102,439 a——- c:\windows\system32\sipr3260.dll
2010-01-02 20:29 65,602 a——- c:\windows\system32\cook3260.dll
2010-01-02 20:26 87,608 a——- c:\docume~1\alistair\applic~1\inst.exe
2010-01-02 20:06 –d—– c:\windows\system32\QuickTime
2010-01-02 20:01 –d—– c:\docume~1\alistair\applic~1\PhotoFiltre
2010-01-02 20:01 –d—– c:\program files\PhotoFiltre
2010-01-02 19:55 –d—– c:\docume~1\alistair\applic~1\CBS Interactive
2010-01-02 17:29 –d—– c:\program files\Readon Technology
2010-01-02 16:49 –d—– c:\docume~1\alistair\applic~1\MozillaControl
2010-01-02 16:49 –d—– c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-02 15:53 –d—– c:\windows\system32\nagasoft
2010-01-02 13:27 32 a——- c:\windows\system32\msvcsv60.dll
2009-12-29 22:17 –d—– c:\docume~1\alistair\applic~1\TuneUp Software
2009-12-29 22:17 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software
2009-12-29 22:17 –dsh— c:\docume~1\alluse~1\applic~1\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-29 15:24 –d—– c:\program files\IrfanView
2009-12-28 07:16 a-dshr– C:\cmdcons
2009-12-27 07:28 –d—– c:\program files\CCleaner
==================== Find3M ====================
2010-01-21 08:08 119,296 a——- c:\windows\system32\zlib.dll
2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-02 20:29 47,360 a——- c:\windows\system32\drivers\pcouffin.sys
2010-01-02 20:29 47,360 a——- c:\docume~1\alistair\applic~1\pcouffin.sys
2009-12-25 06:57 218,624 a——- c:\windows\system32\uxtheme.dll
2009-12-24 06:13 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-12-21 19:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-15 07:46 411,368 a——- c:\windows\system32\deploytk.dll
2009-12-15 06:00 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-12-15 05:02 315,392 a——- c:\windows\HideWin.exe
2009-12-15 04:57 108,059 a——- c:\windows\system32\drivers\klin.dat
2009-12-15 04:57 95,259 a——- c:\windows\system32\drivers\klick.dat
2009-12-15 04:20 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-12-14 14:20 131,072 a–shr– c:\windows\system32\grcortic.dll
2009-12-03 05:38 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-11-25 03:27 446,464 a——- c:\windows\system32\ATIDEMGX.dll
2009-11-25 03:26 300,032 a——- c:\windows\system32\ati2dvag.dll
2009-11-25 03:11 208,896 a——- c:\windows\system32\atipdlxx.dll
2009-11-25 03:11 155,648 a——- c:\windows\system32\Oemdspif.dll
2009-11-25 03:10 26,112 a——- c:\windows\system32\Ati2mdxx.exe
2009-11-25 03:10 43,520 a——- c:\windows\system32\ati2edxx.dll
2009-11-25 03:10 155,648 a——- c:\windows\system32\ati2evxx.dll
2009-11-25 03:09 602,112 a——- c:\windows\system32\ati2evxx.exe
2009-11-25 03:07 53,248 a——- c:\windows\system32\ATIDDC.DLL
2009-11-25 02:59 311,296 a——- c:\windows\system32\atiiiexx.dll
2009-11-25 02:59 3,538,496 a——- c:\windows\system32\ati3duag.dll
2009-11-25 02:44 13,533,184 a——- c:\windows\system32\atioglxx.dll
2009-11-25 02:43 2,142,848 a——- c:\windows\system32\ativvaxx.dll
2009-11-25 02:42 887,724 a——- c:\windows\system32\ativva6x.dat
2009-11-25 02:26 65,024 a——- c:\windows\system32\atimpc32.dll
2009-11-25 02:26 65,024 a——- c:\windows\system32\amdpcom32.dll
2009-11-25 02:21 565,248 a——- c:\windows\system32\atikvmag.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalrt.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalcl.dll
2009-11-25 02:19 176,128 a——- c:\windows\system32\atiadlxx.dll
2009-11-25 02:18 17,408 a——- c:\windows\system32\atitvo32.dll
2009-11-25 02:18 3,612,672 a——- c:\windows\system32\aticaldd.dll
2009-11-25 02:17 397,312 a——- c:\windows\system32\atiok3x2.dll
2009-11-25 02:12 638,976 a——- c:\windows\system32\ati2cqag.dll
2009-11-21 15:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-21 02:34 592,488 a——- c:\windows\system32\nvudisp.exe
2009-11-19 21:42 592,488 a——- c:\windows\system32\NVUNINST.EXE
2009-11-14 00:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-10-29 04:48 499,712 a——- c:\windows\system32\msvcp71.dll
2009-10-29 04:48 348,160 a——- c:\windows\system32\msvcr71.dll
============= FINISH: 6:04:48.84 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 15/12/2009 04:23:46
System Uptime: 25/01/2010 05:26:31 (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5N-MX
Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 233 GiB total, 182.772 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {5458011F-08D4-4605-93A2-F03E61BEDBA3}
Description: Enhanced Display Driver Helper Service
Device ID: ROOT\ASUSOTHERDEVICES\0000
Manufacturer: ASUSTeK
Name: Enhanced Display Driver Helper Service
PNP Device ID: ROOT\ASUSOTHERDEVICES\0000
Service: asuskbnt
==== System Restore Points ===================
RP1: 25/01/2010 05:31:36 - System Checkpoint
RP2: 25/01/2010 05:31:48 - Automatic Restore Point
==== Installed Programs ======================
7-Zip 4.65
a-squared Free 4.5
AAC Decoder
ABBYY FineReader 6.0 Sprint
Active@ KillDisk FREE Suite
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player 11.5
Advanced SystemCare 3
Allok Video Joiner 4.4.1117
AmpliTube Metal
AmpliTube2
AntiLogger
Any Video Converter 3.0.1
ASIO4ALL
ASUS Utilities
ASUS VGA Driver
ATI Catalyst Install Manager
ATI Display Driver
µTorrent
AutoUpdate
AviSynth 2.5
Belarc Advisor 8.1
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CodecInstaller 2.10.2
ConvertHelper 2.2
ConvertXtoDVD 4.0.9.322
CPUID CPU-Z 1.53
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DriverMax 5
DVD Decrypter (Remove Only)
DVD Shrink 3.2
Epson Easy Photo Print 2
EPSON Scan
Epson Stylus SX210_SX410_TX210_TX410 Manual
EPSON SX410 Series Printer Uninstall
EPSON Web-To-Page
ERUNT 1.1j
ESET Online Scanner v3
FairUse Wizard 2
Foxit Reader
Free Download Manager 3.0
Free Registry Defrag
Full Tilt Poker
GrcorticOcm
H.264 Decoder
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
IconTweaker
ImgBurn
Intel® Processor ID Utility
IrfanView (remove only)
Java™ 6 Update 17
Kaspersky Internet Security 2010
Line 6 Uninstaller
Little Registry Cleaner
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Motorola Driver Installation
Mozilla Firefox (3.5.7)
Mp3tag v2.45a
NVIDIA Drivers
P2PFilter 3.0.5
Panda ActiveScan 2.0
Partition Wizard Home Edition 4.2.2
PC Pitstop Optimize3 3.0
PeerBlock 1.0.0 (r181)
PhotoFiltre
PicSizer
PokerStars
QuickTime
Readon TV Movie Radio Player [removed]
Realtek High Definition Audio Driver
Revo Uninstaller 1.85
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
Skins
Smart Defrag
Sophos Anti-Rootkit 1.5.0
SpeedFan (remove only)
SpywareBlaster 4.2
Styler
SUPERAntiSpyware Free Edition
Switch Sound File Converter
System Requirements Lab
Tweak UI
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.3
WebFldrs XP
Winamp
Windows Essentials Media Codec Pack 2.3d
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
Wise Registry Cleaner 4 Free 4.92
==== Event Viewer Messages From Past Week ========
21/01/2010 12:44:43, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
21/01/2010 12:27:37, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
21/01/2010 12:04:10, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\drivers\ati2mtag.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
21/01/2010 11:53:14, error: Service Control Manager [7000] - The SBKUPNT service failed to start due to the following error: Access is denied.
21/01/2010 11:13:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
21/01/2010 11:13:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
21/01/2010 11:13:02, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BANTExt Fips intelppm kl1 KLIF pavboot SASDIFSV SASKUTIL
21/01/2010 11:12:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
21/01/2010 10:29:27, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
21/01/2010 08:08:48, error: Service Control Manager [7034] - The PinnacleUpdate Service service terminated unexpectedly. It has done this 1 time(s).
20/01/2010 09:32:11, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativvaxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.208.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativtmxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativmvxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativdaxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3duag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.630.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3d1ag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.4071.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvaa.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.13.10.5019.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2cqag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.404.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\ati2mtag.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ativvaxx.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati3duag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2dvag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2cqag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\nv4_disp.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\nv4_mini.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_mini.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_disp.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.
==== End Of File ===========================
And here is the Bitdefender log > BitDefender Online Scanner
Scan report generated at: Fri, Jan 22, 2010 - 17:05:11
Scan path: C:\;D:\;F:\;G:\;H:\;I:\;J:\;
Statistics
Time
00:29:00
Files
162901
Folders
5827
Boot Sectors
0
Archives
1873
Packed Files
7751
Results
Identified Viruses
2
Infected Files
3
Suspect Files
0
Warnings
0
Disinfected
2
Deleted Files
0
Engines Info
Virus Definitions
4895792
Engine build
AVCORE v2.1 Windows/i386 11.0.0.33 (Nov 24 2009)
Scan plugins
17
Archive plugins
44
Unpack plugins
8
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)
Infected with: Trojan.Wimad.Gen.1
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)
Disinfected
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq
Update failed
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)
Infected with: Trojan.Wimad.Gen.1
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)
Disinfected
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq
Update failed
C:\WINDOWS\system32\grcortic.dll
Infected with: Gen:Trojan.Heur.iq8@YcK6Ffe
C:\WINDOWS\system32\grcortic.dll
Disinfection failed
C:\WINDOWS\system32\grcortic.dll
Delete failed
I am concerned as I don't how dangerous this Trojan is and was wondering if I should change all my online banking details/passwords,etc,etc.?I really hope I don't have to re-format
as I not long ago done a fresh install! Any help with this issue is greatly appreciated,thanks.
Database version: 3632
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
25/01/2010 05:39:05
mbam-log-2010-01-25 (05-39-05).txt
Scan type: Quick Scan
Objects scanned: 114220
Time elapsed: 3 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-25 06:03:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Alistair\LOCALS~1\Temp\kfqiqaog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xABDC458C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xABDC4E0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xABDC5922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xABDC5E94]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateFile [0xAB5B9772]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xABDC3436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xABDC5D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xABDC4192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xABDC5C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xABDC434E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xABDC5FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xABDC7C08]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwCreateThread [0xAB5B8FAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xABDC5CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xABDC75FA]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteKey [0xAB5B9594]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwDeleteValueKey [0xAB5B9466]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xABDC5576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xABDC85CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xABDC3ECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xABDC3F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xABDC5382]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwLoadDriver [0xAB5B8DE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xABDC3412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xABDC3424]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwMapViewOfSection [0xAB5B8B84]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xABDC40C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xABDC5F36]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenFile [0xAB5B99C2]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenKey [0xAB5B9760]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xABDC5E04]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenProcess [0xAB5B90CE]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenSection [0xAB5B9234]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xABDC6068]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwOpenThread [0xAB5B917E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xABDC401E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xABDC3C46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xABDC7FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xABDC3896]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwQueueApcThread [0xAB5B905C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xABDC3B0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xABDC32B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xABDC63F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xABDC62B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xABDC739A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xABDCAE2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xABDC84AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xABDC3248]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSecureConnectPort [0xAB5B9AF0]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetContextThread [0xAB5B8B16]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xABDC6C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xABDC7786]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetSystemInformation [0xAB5B8F3E]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwSetValueKey [0xAB5B9660]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xABDC81F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xABDC8320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xABDC7526]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwTerminateProcess [0xAB5B934C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xABDC4860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xABDC7E8A]
SSDT \??\C:\Program Files\AntiLogger\AntiLog32.sys (Zemana AntiLogger Driver (stand-alone)/Zemana Ltd.) ZwWriteVirtualMemory [0xAB5B8A48]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:04:34.79 on 25/01/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2858 [GMT 0:00]
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Alistair\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
uRun: [EPSON SX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifce.exe /fu "c:\windows\temp\E_SC.tmp" /EF "HKCU"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SkyTel] SkyTel.EXE
mRun: [AntiLogger] "c:\program files\antilogger\AntiLogger.exe" /minimized
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {4248FE82-7FCB-46AC-B270-339F08212110}
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\kloehk.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: GrcorticOcm.Grcortic: {79b34a1f-d8fd-474f-84f3-8622d06faf40} - c:\windows\system32\grcortic.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\alistair\applic~1\mozilla\firefox\profiles\pbbl1whh.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://m.uk.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-1-7 28552]
R1 AntiLog32;AntiLog32;c:\program files\antilogger\AntiLog32.sys [2010-1-12 116072]
R1 EIO_XP;EIO_XP;c:\windows\system32\drivers\EIO_XP.sys [2010-1-21 12288]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-12-15 315408]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-12-15 1858144]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-1-6 12672]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2010-1-5 14976]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2010-1-20 93184]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2009-12-16 532992]
S2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\c0.tmp –> c:\windows\system32\C0.tmp [?]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2009-12-17 14424]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-1-11 16456]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-1-11 11088]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 Video3D;ASUS Video3D Service;c:\windows\system32\drivers\video3d32.sys –> c:\windows\system32\drivers\Video3D32.sys [?]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-12-15 90352]
=============== Created Last 30 ================
2010-01-24 11:21 –d—– c:\program files\MAME
2010-01-23 06:17 –d—– c:\docume~1\alistair\applic~1\QuickScan
2010-01-21 13:10 –d—– c:\program files\ATI Technologies
2010-01-21 13:10 –d—– c:\program files\ATI
2010-01-21 13:09 –d—– C:\ATI
2010-01-21 12:11 12,288 a—-r– c:\windows\system32\drivers\EIO_XP.sys
2010-01-21 12:09 53,760 ac—— c:\windows\system32\dllcache\vfwwdm32.dll
2010-01-21 12:09 53,760 a——- c:\windows\system32\vfwwdm32.dll
2010-01-21 12:08 –d—– c:\program files\ASUS
2010-01-21 10:05 –d—– c:\program files\Essentials Codec Pack
2010-01-21 08:09 –d—– c:\docume~1\alistair\applic~1\PowerUp Software
2010-01-21 08:08 –d—– c:\docume~1\alluse~1\applic~1\PowerUp Software
2010-01-21 06:38 –d—– c:\program files\ESET
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1ins.dll
2010-01-20 09:32 195,072 a—-r– c:\windows\system32\fdco1.dll
2010-01-20 09:32 53,632 a—-r– c:\windows\system32\drivers\NVENETFD.sys
2010-01-20 09:32 4,805 a——- c:\windows\system32\nvnrm.nvu
2010-01-20 09:31 888,064 a—-r– c:\windows\system32\drivers\nvnrm.sys
2010-01-20 09:31 37,376 a—-r– c:\windows\system32\nvconrm.dll
2010-01-20 09:31 22,016 a—-r– c:\windows\system32\drivers\nvnetbus.sys
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1ins.dll
2010-01-20 09:31 9,216 a—-r– c:\windows\system32\bdco1.dll
2010-01-20 09:19 –d—– c:\program files\common files\ATI Technologies
2010-01-20 09:07 10 a——- c:\windows\WININIT.INI
2010-01-20 09:06 0 a——- c:\windows\ativpsrm.bin
2010-01-20 09:06 19,017 a——- c:\windows\atiogl.xml
2010-01-20 09:05 93,184 a—-r– c:\windows\system32\drivers\AtiHdmi.sys
2010-01-20 08:58 –d—– c:\program files\My Company Name
2010-01-20 06:46 –d—– c:\program files\SpeedFan
2010-01-20 06:46 45 a——- c:\windows\system32\initdebug.nfo
2010-01-18 06:49 –d—– c:\docume~1\alistair\applic~1\KALiNKOsoft
2010-01-13 01:58 –d—– c:\program files\FairUse Wizard 2
2010-01-13 01:06 –d—– c:\docume~1\alistair\applic~1\AnvSoft
2010-01-13 01:06 –d—– c:\program files\AnvSoft
2010-01-12 22:32 –d—– c:\program files\common files\DivX Shared
2010-01-12 19:31 -cd-h— c:\docume~1\alluse~1\applic~1\{ADBE1C37-5B60-41F1-8C26-C3F880D609C1}
2010-01-12 08:48 8,576 a——- c:\windows\system32\drivers\apgiywudryke.sys
2010-01-12 08:44 8,576 a——- c:\windows\system32\drivers\admqnrgkhnlw.sys
2010-01-12 08:43 8,576 a——- c:\windows\system32\drivers\yeoqjaedbosu.sys
2010-01-12 08:42 8,576 a——- c:\windows\system32\drivers\ywghcedstlcr.sys
2010-01-12 08:41 8,576 a——- c:\windows\system32\drivers\ynltosggncjp.sys
2010-01-12 08:40 8,576 a——- c:\windows\system32\drivers\ydugtctlvwoo.sys
2010-01-12 08:37 8,576 a——- c:\windows\system32\drivers\yhikanbisygi.sys
2010-01-12 08:34 –d—– c:\documents and settings\alistair\Pavark
2010-01-12 08:19 161,296 a——- c:\windows\system32\drivers\tmcomm.sys
2010-01-12 07:21 –d—– c:\program files\JockerSoft
2010-01-12 01:06 27,612 a——- c:\windows\syscall.dat
2010-01-12 01:06 –d—– c:\program files\AntiLogger
2010-01-11 23:09 461,368 a——- c:\windows\system32\pwNative.exe
2010-01-11 23:09 16,456 a——- c:\windows\system32\pwdrvio.sys
2010-01-11 23:09 11,088 a——- c:\windows\system32\pwdspio.sys
2010-01-11 23:09 –d—– c:\program files\Partition Wizard Home Edition 4.2.2
2010-01-10 22:13 –d—– c:\documents and settings\alistair\.thumbnails
2010-01-10 22:08 –d—– c:\documents and settings\alistair\.gimp-2.6
2010-01-10 21:13 –d—– c:\docume~1\alluse~1\applic~1\Simply Super Software
2010-01-10 15:09 –d—– c:\documents and settings\alistair\DoctorWeb
2010-01-10 14:23 –d—– c:\windows\Performance
2010-01-10 05:10 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions
2010-01-10 05:10 –d—– c:\program files\Innovative Solutions
2010-01-09 12:00 –d—– c:\windows\$regcmp$
2010-01-09 11:56 –d—– c:\program files\Intel Corporation
2010-01-09 11:52 –d—– c:\program files\SystemRequirementsLab
2010-01-08 12:21 –d—– c:\docume~1\alluse~1\applic~1\DriverScanner
2010-01-08 12:21 –d—– c:\docume~1\alistair\applic~1\Uniblue
2010-01-08 11:37 –d—– c:\windows\system32\%PersonalRootCertificateFolder%
2010-01-07 01:46 28,552 a——- c:\windows\system32\drivers\pavboot.sys
2010-01-07 01:45 –d—– c:\program files\Panda Security
2010-01-06 15:15 –d-h— C:\VJVod_Cache
2010-01-06 02:17 12,672 a——- c:\windows\system32\drivers\cpuz132_x32.sys
2010-01-06 02:17 –d—– c:\program files\CPUID
2010-01-06 02:12 –d—– c:\program files\Wise Registry Cleaner
2010-01-06 02:09 3,840 a——- c:\windows\system32\drivers\BANTExt.sys
2010-01-06 02:09 –d—– c:\program files\Belarc
2010-01-06 01:34 –d—– c:\program files\VS Revo Group
2010-01-06 01:09 –d—– c:\program files\Registry Clean Expert
2010-01-05 20:51 –d—– c:\program files\AviSynth 2.5
2010-01-05 20:25 –d—– c:\program files\DVD Shrink
2010-01-05 20:22 –d—– c:\program files\DVD Decrypter
2010-01-05 20:19 –d—– c:\docume~1\alistair\applic~1\RipIt4Me
2010-01-05 00:51 14,976 a——- c:\windows\system32\drivers\SBKUPNT.SYS
2010-01-05 00:51 13,312 a——- c:\windows\system32\DEVLOAD.EXE
2010-01-05 00:50 2,799 a——- c:\windows\SKLANG.INI
2010-01-05 00:50 306,688 a——- c:\windows\IsUninst.exe
2010-01-04 21:39 –d—– c:\windows\system32\NtmsData
2010-01-04 19:46 –d—– c:\program files\LSoft Technologies
2010-01-04 00:27 11,254 a——- c:\windows\system32\locate.com
2010-01-03 21:51 –d—– c:\docume~1\alistair\applic~1\Mp3tag
2010-01-03 21:51 –d—– c:\program files\Mp3tag
2010-01-03 21:41 –d—– c:\docume~1\alluse~1\applic~1\F-Secure
2010-01-03 19:14 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX
2010-01-03 19:14 118,784 a——- c:\windows\system32\MSSTDFMT.DLL
2010-01-03 19:14 –d—– c:\program files\SpywareBlaster
2010-01-03 17:43 –d—– c:\windows\system32\Adobe
2010-01-03 16:58 3,426,072 a——- c:\windows\system32\d3dx9_32.dll
2010-01-03 16:58 2,414,360 a——- c:\windows\system32\d3dx9_31.dll
2010-01-03 16:58 –d—– c:\windows\Logs
2010-01-02 20:29 1,184,984 a——- c:\windows\system32\wvc1dmod.dll
2010-01-02 20:29 626,688 a——- c:\windows\system32\vp7vfw.dll
2010-01-02 20:29 217,127 a——- c:\windows\system32\drv43260.dll
2010-01-02 20:29 208,935 a——- c:\windows\system32\drv33260.dll
2010-01-02 20:29 176,165 a——- c:\windows\system32\drv23260.dll
2010-01-02 20:29 102,439 a——- c:\windows\system32\sipr3260.dll
2010-01-02 20:29 65,602 a——- c:\windows\system32\cook3260.dll
2010-01-02 20:26 87,608 a——- c:\docume~1\alistair\applic~1\inst.exe
2010-01-02 20:06 –d—– c:\windows\system32\QuickTime
2010-01-02 20:01 –d—– c:\docume~1\alistair\applic~1\PhotoFiltre
2010-01-02 20:01 –d—– c:\program files\PhotoFiltre
2010-01-02 19:55 –d—– c:\docume~1\alistair\applic~1\CBS Interactive
2010-01-02 17:29 –d—– c:\program files\Readon Technology
2010-01-02 16:49 –d—– c:\docume~1\alistair\applic~1\MozillaControl
2010-01-02 16:49 –d—– c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-02 15:53 –d—– c:\windows\system32\nagasoft
2010-01-02 13:27 32 a——- c:\windows\system32\msvcsv60.dll
2009-12-29 22:17 –d—– c:\docume~1\alistair\applic~1\TuneUp Software
2009-12-29 22:17 –d—– c:\docume~1\alluse~1\applic~1\TuneUp Software
2009-12-29 22:17 –dsh— c:\docume~1\alluse~1\applic~1\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-29 15:24 –d—– c:\program files\IrfanView
2009-12-28 07:16 a-dshr– C:\cmdcons
2009-12-27 07:28 –d—– c:\program files\CCleaner
==================== Find3M ====================
2010-01-21 08:08 119,296 a——- c:\windows\system32\zlib.dll
2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-02 20:29 47,360 a——- c:\windows\system32\drivers\pcouffin.sys
2010-01-02 20:29 47,360 a——- c:\docume~1\alistair\applic~1\pcouffin.sys
2009-12-25 06:57 218,624 a——- c:\windows\system32\uxtheme.dll
2009-12-24 06:13 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-12-21 19:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-15 07:46 411,368 a——- c:\windows\system32\deploytk.dll
2009-12-15 06:00 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-12-15 05:02 315,392 a——- c:\windows\HideWin.exe
2009-12-15 04:57 108,059 a——- c:\windows\system32\drivers\klin.dat
2009-12-15 04:57 95,259 a——- c:\windows\system32\drivers\klick.dat
2009-12-15 04:20 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-12-14 14:20 131,072 a–shr– c:\windows\system32\grcortic.dll
2009-12-03 05:38 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-11-25 03:27 446,464 a——- c:\windows\system32\ATIDEMGX.dll
2009-11-25 03:26 300,032 a——- c:\windows\system32\ati2dvag.dll
2009-11-25 03:11 208,896 a——- c:\windows\system32\atipdlxx.dll
2009-11-25 03:11 155,648 a——- c:\windows\system32\Oemdspif.dll
2009-11-25 03:10 26,112 a——- c:\windows\system32\Ati2mdxx.exe
2009-11-25 03:10 43,520 a——- c:\windows\system32\ati2edxx.dll
2009-11-25 03:10 155,648 a——- c:\windows\system32\ati2evxx.dll
2009-11-25 03:09 602,112 a——- c:\windows\system32\ati2evxx.exe
2009-11-25 03:07 53,248 a——- c:\windows\system32\ATIDDC.DLL
2009-11-25 02:59 311,296 a——- c:\windows\system32\atiiiexx.dll
2009-11-25 02:59 3,538,496 a——- c:\windows\system32\ati3duag.dll
2009-11-25 02:44 13,533,184 a——- c:\windows\system32\atioglxx.dll
2009-11-25 02:43 2,142,848 a——- c:\windows\system32\ativvaxx.dll
2009-11-25 02:42 887,724 a——- c:\windows\system32\ativva6x.dat
2009-11-25 02:26 65,024 a——- c:\windows\system32\atimpc32.dll
2009-11-25 02:26 65,024 a——- c:\windows\system32\amdpcom32.dll
2009-11-25 02:21 565,248 a——- c:\windows\system32\atikvmag.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalrt.dll
2009-11-25 02:20 45,056 a——- c:\windows\system32\aticalcl.dll
2009-11-25 02:19 176,128 a——- c:\windows\system32\atiadlxx.dll
2009-11-25 02:18 17,408 a——- c:\windows\system32\atitvo32.dll
2009-11-25 02:18 3,612,672 a——- c:\windows\system32\aticaldd.dll
2009-11-25 02:17 397,312 a——- c:\windows\system32\atiok3x2.dll
2009-11-25 02:12 638,976 a——- c:\windows\system32\ati2cqag.dll
2009-11-21 15:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-21 02:34 592,488 a——- c:\windows\system32\nvudisp.exe
2009-11-19 21:42 592,488 a——- c:\windows\system32\NVUNINST.EXE
2009-11-14 00:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-10-29 04:48 499,712 a——- c:\windows\system32\msvcp71.dll
2009-10-29 04:48 348,160 a——- c:\windows\system32\msvcr71.dll
============= FINISH: 6:04:48.84 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 15/12/2009 04:23:46
System Uptime: 25/01/2010 05:26:31 (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5N-MX
Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 2000/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 233 GiB total, 182.772 GiB free.
D: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID: {5458011F-08D4-4605-93A2-F03E61BEDBA3}
Description: Enhanced Display Driver Helper Service
Device ID: ROOT\ASUSOTHERDEVICES\0000
Manufacturer: ASUSTeK
Name: Enhanced Display Driver Helper Service
PNP Device ID: ROOT\ASUSOTHERDEVICES\0000
Service: asuskbnt
==== System Restore Points ===================
RP1: 25/01/2010 05:31:36 - System Checkpoint
RP2: 25/01/2010 05:31:48 - Automatic Restore Point
==== Installed Programs ======================
7-Zip 4.65
a-squared Free 4.5
AAC Decoder
ABBYY FineReader 6.0 Sprint
Active@ KillDisk FREE Suite
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player 11.5
Advanced SystemCare 3
Allok Video Joiner 4.4.1117
AmpliTube Metal
AmpliTube2
AntiLogger
Any Video Converter 3.0.1
ASIO4ALL
ASUS Utilities
ASUS VGA Driver
ATI Catalyst Install Manager
ATI Display Driver
µTorrent
AutoUpdate
AviSynth 2.5
Belarc Advisor 8.1
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
CCleaner
CodecInstaller 2.10.2
ConvertHelper 2.2
ConvertXtoDVD 4.0.9.322
CPUID CPU-Z 1.53
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DriverMax 5
DVD Decrypter (Remove Only)
DVD Shrink 3.2
Epson Easy Photo Print 2
EPSON Scan
Epson Stylus SX210_SX410_TX210_TX410 Manual
EPSON SX410 Series Printer Uninstall
EPSON Web-To-Page
ERUNT 1.1j
ESET Online Scanner v3
FairUse Wizard 2
Foxit Reader
Free Download Manager 3.0
Free Registry Defrag
Full Tilt Poker
GrcorticOcm
H.264 Decoder
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976098-v2)
IconTweaker
ImgBurn
Intel® Processor ID Utility
IrfanView (remove only)
Java™ 6 Update 17
Kaspersky Internet Security 2010
Line 6 Uninstaller
Little Registry Cleaner
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Motorola Driver Installation
Mozilla Firefox (3.5.7)
Mp3tag v2.45a
NVIDIA Drivers
P2PFilter 3.0.5
Panda ActiveScan 2.0
Partition Wizard Home Edition 4.2.2
PC Pitstop Optimize3 3.0
PeerBlock 1.0.0 (r181)
PhotoFiltre
PicSizer
PokerStars
QuickTime
Readon TV Movie Radio Player [removed]
Realtek High Definition Audio Driver
Revo Uninstaller 1.85
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
Skins
Smart Defrag
Sophos Anti-Rootkit 1.5.0
SpeedFan (remove only)
SpywareBlaster 4.2
Styler
SUPERAntiSpyware Free Edition
Switch Sound File Converter
System Requirements Lab
Tweak UI
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.3
WebFldrs XP
Winamp
Windows Essentials Media Codec Pack 2.3d
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
Wise Registry Cleaner 4 Free 4.92
==== Event Viewer Messages From Past Week ========
21/01/2010 12:44:43, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
21/01/2010 12:27:37, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
21/01/2010 12:04:10, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\drivers\ati2mtag.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
21/01/2010 11:53:14, error: Service Control Manager [7000] - The SBKUPNT service failed to start due to the following error: Access is denied.
21/01/2010 11:13:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
21/01/2010 11:13:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
21/01/2010 11:13:02, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BANTExt Fips intelppm kl1 KLIF pavboot SASDIFSV SASKUTIL
21/01/2010 11:12:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
21/01/2010 10:29:27, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
21/01/2010 08:08:48, error: Service Control Manager [7034] - The PinnacleUpdate Service service terminated unexpectedly. It has done this 1 time(s).
20/01/2010 09:32:11, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativvaxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.208.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativtmxx.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:54, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativmvxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ativdaxx.ax. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6238.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3duag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.630.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati3d1ag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.4071.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.6891.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2dvaa.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.13.10.5019.
20/01/2010 09:14:53, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ati2cqag.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.404.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\ati2mtag.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ativvaxx.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati3duag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2dvag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 09:07:23, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\ati2cqag.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\nv4_disp.dll could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:44, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\nv4_mini.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_mini.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.
20/01/2010 08:29:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nv4_disp.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.14.10.5673.
==== End Of File ===========================
And here is the Bitdefender log > BitDefender Online Scanner
Scan report generated at: Fri, Jan 22, 2010 - 17:05:11
Scan path: C:\;D:\;F:\;G:\;H:\;I:\;J:\;
Statistics
Time
00:29:00
Files
162901
Folders
5827
Boot Sectors
0
Archives
1873
Packed Files
7751
Results
Identified Viruses
2
Infected Files
3
Suspect Files
0
Warnings
0
Disinfected
2
Deleted Files
0
Engines Info
Virus Definitions
4895792
Engine build
AVCORE v2.1 Windows/i386 11.0.0.33 (Nov 24 2009)
Scan plugins
17
Archive plugins
44
Unpack plugins
8
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)
Infected with: Trojan.Wimad.Gen.1
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq=>(Quarantine-6)
Disinfected
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\8ef2afba273dcb82.klq
Update failed
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)
Infected with: Trojan.Wimad.Gen.1
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq=>(Quarantine-6)
Disinfected
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\QB\9e257a94c0a0b283.klq
Update failed
C:\WINDOWS\system32\grcortic.dll
Infected with: Gen:Trojan.Heur.iq8@YcK6Ffe
C:\WINDOWS\system32\grcortic.dll
Disinfection failed
C:\WINDOWS\system32\grcortic.dll
Delete failed
I am concerned as I don't how dangerous this Trojan is and was wondering if I should change all my online banking details/passwords,etc,etc.?I really hope I don't have to re-format