This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Virus

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help!!I am assuming I have the Google Redirect Virus because that's what's happening. Here are my logs
I ran Malware two different days here is the first log

Malwarebytes' Anti-Malware 1.44
Database version: 3675
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/1/2010 10:28:57 PM
mbam-log-2010-02-01 (22-28-57).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 247011
Time elapsed: 2 hour(s), 6 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

The second one

Malwarebytes' Anti-Malware 1.44
Database version: 3681
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/2/2010 6:24:42 PM
mbam-log-2010-02-02 (18-24-42).txt

Scan type: Quick Scan
Objects scanned: 125707
Time elapsed: 12 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\{F9197A7E-CE10-458e-85F8-5B0CE6DF2BBE} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


The GMER log

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-02 20:56:56
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\test\LOCALS~1\Temp\kgpyapod.sys


—- System - GMER 1.0.15 —-

SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FCE] ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD8] ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FC9] ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FDD] ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE2] ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FF1] ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FEC] ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE7] ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwSetValueKey [0x804D7FD3]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD3] ZwSetValueKey [0x804D7FD3]

INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D7FF6

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEB54F78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEB54F738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEB54F74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEB54F7CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEB54F917]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEB54F710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEB54F724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEB54F79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEB54F8B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEB54F858]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEB54F93F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEB54F92B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEB54F776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEB54F762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEB54F7F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEB54F901]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEB54F7E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEB54F7B4]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)

AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \Driver\Disk \GLOBAL??\C2CAD972#4079#4fd3#A68D#AD34CC121074 F7881BDE

—- Threads - GMER 1.0.15 —-

Thread System [4:144] F788293A
—- Processes - GMER 1.0.15 —-

Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Google\Gmail Notifier\gnotify.exe [316] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [440] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [512] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Windows Media Player\WMPNetwk.exe [556] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [880] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\msdtc.exe [1204] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [1404] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1620] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1664] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1816] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1844] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\mqsvc.exe [2044] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2072] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [2084] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\eHome\ehSched.exe [2212] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\hasplms.exe [2688] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2836] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2980] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\McAfee\MPF\MPFSrv.exe [3280] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\IEXPLORE.EXE [3712] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [3756] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [3992] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\ehome\mcrdsvc.exe [4020] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [5720] 0x35670000
Library \\74.117.114.86\max++.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [5736] 0x35670000

—- EOF - GMER 1.0.15 —-

And the DSS logs

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:04:53.27 on Tue 02/02/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.395 [GMT -6:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\hasplms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\RUBotted\TMRUBottedLite.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\test\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://groups.yahoo.com/group/DFWpaddlers/
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=pavilion&pf=laptop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] nwiz.exe /installquiet /nodetect
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe"
StartupFolder: c:\docume~1\test\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244681197328
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-1-28 64288]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 214664]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-3 93320]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-3 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-3 144704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-4 24652]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-1 38224]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-3 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-3 35272]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2010-1-26 206608]
S2 gupdate1ca204bad189b6c;Google Update Service (gupdate1ca204bad189b6c);c:\program files\google\update\GoogleUpdate.exe [2009-8-18 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-12-2 1181328]
S2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2010-1-26 582992]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-3 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-3 40552]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 rootrepeal2;rootrepeal2;\??\c:\windows\system32\drivers\rootrepeal2.sys –> c:\windows\system32\drivers\rootrepeal2.sys [?]
S3 rootrepeal3;rootrepeal3;\??\c:\windows\system32\drivers\rootrepeal3.sys –> c:\windows\system32\drivers\rootrepeal3.sys [?]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2010-1-26 206608]
S3 VsmRWDriver;VSM Reader/Writer Type A USB Driver service;c:\windows\system32\drivers\VsmRWDriver.sys [2009-11-7 7808]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-3 606736]

=============== Created Last 30 ================

2010-02-01 20:18 –d—– c:\docume~1\test\applic~1\Malwarebytes
2010-02-01 20:18 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 20:18 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-01 20:18 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-01 20:18 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-31 18:58 0 a——- c:\documents and settings\test\settings.dat
2010-01-29 20:01 –d—– c:\documents and settings\test\log
2010-01-29 01:23 15,880 a——- c:\windows\system32\lsdelete.exe
2010-01-28 22:52 64,288 a——- c:\windows\system32\drivers\Lbd.sys
2010-01-28 22:51 -cd-h— c:\docume~1\alluse~1\applic~1\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-28 22:50 –d—– c:\program files\Lavasoft
2010-01-28 20:03 –d—– c:\documents and settings\test\Calibre Library
2010-01-28 20:03 –d—– c:\docume~1\test\applic~1\calibre
2010-01-28 20:00 –d—– c:\program files\Calibre2
2010-01-28 19:02 –d—– c:\program files\Spybot - Search & Destroy
2010-01-28 19:02 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-26 22:34 –d—– c:\program files\TrendMicro
2010-01-26 22:32 206,608 a——- c:\windows\system32\drivers\TMPassthru.sys
2010-01-26 22:32 –d—– c:\program files\Trend Micro
2010-01-12 19:07 471,552 ——– c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2009-12-31 09:33 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 09:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 07:05 634,648 ——– c:\windows\system32\dllcache\iexplore.exe
2009-12-18 07:04 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-11-24 20:24 56,412 a—h— c:\windows\system32\mlfcache.dat
2009-11-21 09:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-06-10 19:32 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009061020090611\index.dat

============= FINISH: 21:05:23.63 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/31/2009 2:58:31 PM
System Uptime: 2/2/2010 5:33:00 PM (4 hours ago)

Motherboard: Quanta | | 30B9
Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | Socket S1 | 1607/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 81 GiB total, 47.649 GiB free.
D: is FIXED (FAT32) - 11 GiB total, 1.093 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP141: 11/3/2009 7:55:43 PM - System Checkpoint
RP142: 11/4/2009 11:00:19 PM - Software Distribution Service 3.0
RP143: 11/6/2009 7:41:46 PM - System Checkpoint
RP144: 11/7/2009 6:26:25 PM - Installed 4D Embroidery Extra 8.1.
RP145: 11/7/2009 6:46:23 PM - Installed 4D Embroidery System 8.1 Update.
RP146: 11/7/2009 6:51:49 PM - Removed 32-bit VSM Device Drivers.
RP147: 11/7/2009 7:56:13 PM - Installed 32-bit VSM Device Drivers.
RP148: 11/7/2009 8:01:29 PM - Unsigned driver install
RP149: 11/8/2009 8:22:32 PM - Unsigned driver install
RP150: 11/10/2009 9:38:48 AM - System Checkpoint
RP151: 11/10/2009 10:00:18 PM - Software Distribution Service 3.0
RP152: 11/11/2009 1:29:56 PM - Software Distribution Service 3.0
RP153: 11/13/2009 8:45:48 PM - System Checkpoint
RP154: 11/14/2009 9:23:38 PM - System Checkpoint
RP155: 11/15/2009 9:31:13 PM - System Checkpoint
RP156: 11/17/2009 8:31:54 PM - System Checkpoint
RP157: 11/18/2009 9:31:51 PM - System Checkpoint
RP158: 11/20/2009 12:55:35 PM - System Checkpoint
RP159: 11/22/2009 8:21:05 PM - System Checkpoint
RP160: 11/24/2009 10:00:28 PM - Software Distribution Service 3.0
RP161: 11/25/2009 10:56:58 PM - System Checkpoint
RP162: 11/27/2009 12:56:27 PM - System Checkpoint
RP163: 11/29/2009 10:40:40 AM - System Checkpoint
RP164: 11/30/2009 5:57:27 PM - System Checkpoint
RP165: 12/1/2009 6:01:05 PM - System Checkpoint
RP166: 12/4/2009 12:14:21 PM - System Checkpoint
RP167: 12/5/2009 10:28:40 PM - System Checkpoint
RP168: 12/8/2009 8:52:17 PM - System Checkpoint
RP169: 12/8/2009 10:00:36 PM - Software Distribution Service 3.0
RP170: 12/10/2009 10:19:28 PM - System Checkpoint
RP171: 12/11/2009 11:10:15 PM - System Checkpoint
RP172: 12/13/2009 11:36:04 AM - System Checkpoint
RP173: 12/14/2009 9:39:47 PM - System Checkpoint
RP174: 12/15/2009 7:46:14 PM - Removed eBook Library by Sony.
RP175: 12/15/2009 7:46:33 PM - Installed Reader Library by Sony.
RP176: 12/16/2009 8:42:14 PM - System Checkpoint
RP177: 12/18/2009 8:49:46 PM - System Checkpoint
RP178: 12/18/2009 10:00:30 PM - Software Distribution Service 3.0
RP179: 12/20/2009 11:24:33 AM - System Checkpoint
RP180: 12/21/2009 8:06:18 PM - System Checkpoint
RP181: 12/23/2009 2:00:31 PM - System Checkpoint
RP182: 12/24/2009 3:06:06 PM - System Checkpoint
RP183: 12/25/2009 6:27:11 PM - System Checkpoint
RP184: 12/28/2009 11:40:21 PM - System Checkpoint
RP185: 12/30/2009 9:19:05 PM - System Checkpoint
RP186: 12/31/2009 10:31:28 PM - System Checkpoint
RP187: 1/1/2010 10:39:02 PM - System Checkpoint
RP188: 1/5/2010 3:37:22 PM - System Checkpoint
RP189: 1/6/2010 5:59:38 PM - System Checkpoint
RP190: 1/8/2010 3:29:32 PM - System Checkpoint
RP191: 1/9/2010 7:21:19 PM - System Checkpoint
RP192: 1/10/2010 7:31:57 PM - System Checkpoint
RP193: 1/12/2010 9:58:57 PM - System Checkpoint
RP194: 1/12/2010 10:00:29 PM - Software Distribution Service 3.0
RP195: 1/14/2010 8:50:03 PM - System Checkpoint
RP196: 1/15/2010 10:23:27 PM - System Checkpoint
RP197: 1/17/2010 11:34:12 AM - System Checkpoint
RP198: 1/19/2010 9:11:20 PM - System Checkpoint
RP199: 1/19/2010 9:46:00 PM - Software Distribution Service 3.0
RP200: 1/21/2010 6:56:02 PM - System Checkpoint
RP201: 1/21/2010 10:00:15 PM - Software Distribution Service 3.0
RP202: 1/22/2010 11:03:06 PM - System Checkpoint
RP203: 1/24/2010 1:47:01 PM - System Checkpoint
RP204: 1/25/2010 10:34:45 PM - Removed Reader Library by Sony.
RP205: 1/25/2010 10:45:45 PM - Installed Reader Library by Sony.
RP206: 1/25/2010 11:21:15 PM - Removed Reader Library by Sony.
RP207: 1/25/2010 11:30:43 PM - Installed Reader Library by Sony.
RP208: 1/25/2010 11:53:30 PM - Removed Reader Library by Sony.
RP209: 1/26/2010 12:03:21 AM - Installed Reader Library by Sony.
RP210: 1/26/2010 12:17:33 AM - Removed Reader Library by Sony.
RP211: 1/26/2010 12:25:26 AM - Installed Reader Library by Sony.
RP212: 1/26/2010 12:48:39 AM - Removed Reader Library by Sony.
RP213: 1/26/2010 12:54:27 AM - Installed Reader Library by Sony.
RP214: 1/26/2010 7:13:14 PM - Removed Reader Library by Sony.
RP215: 1/26/2010 7:14:24 PM - Removed Reader Library by Sony.
RP216: 1/26/2010 7:15:43 PM - Removed Quicken 2006
RP217: 1/26/2010 7:43:42 PM - Installed Reader Library by Sony.
RP218: 1/26/2010 10:21:28 PM - Removed PRS-500 USB driver.
RP219: 1/26/2010 10:32:41 PM - Installed Trend Micro RUBotted
RP220: 1/26/2010 10:34:08 PM - Installed HiJackThis
RP221: 1/28/2010 8:00:27 PM - Installed calibre
RP222: 1/28/2010 8:17:19 PM - Removed Reader Library by Sony.
RP223: 1/30/2010 1:31:37 AM - System Checkpoint
RP224: 1/31/2010 6:25:42 PM - System Checkpoint
RP225: 2/2/2010 6:59:14 PM - System Checkpoint
RP226: 2/2/2010 7:30:50 PM - Automatic Restore Point
RP227: 2/2/2010 7:31:15 PM - Automatic Restore Point

==== Installed Programs ======================


32-bit VSM Device Drivers
32-bit VSM Device Drivers 8.2
4D Embroidery Extra 8.1
4D Embroidery System 8.1 Update
7-Zip 9.07 beta
Acrobat.com
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AutoUpdate
Bonjour
BufferChm
calibre
Conexant HD Audio
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Customer Experience Enhancement
Destinations
DeviceManagementQFolder
DivX
Embroidery Machine Communication Software
EPSON Scan
EPSON WorkForce 500 Series Printer Uninstall
ERUNT 1.1j
FullDPAppQFolder
Garmin POI Loader
Garmin USB Drivers
Google Chrome
Google Earth
Google Gmail Notifier
Google Update Helper
Google Updater
HiJackThis
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Update
HP User Guides 0032
HP Wireless Assistant 2.00 G2
HpSdpAppCoreApp
ieSpell
InstantShareDevices
iTunes
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 7
LightScribe 1.4.97.1
Macromedia Flash Player 8
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Works
MobileMe Control Panel
Move Media Player
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 5.0
NetWaiting
NVIDIA Drivers
Office 2003 Trial Assistant
OpenOffice.org 3.0
OptionalContentQFolder
Otto
PhotoGallery
QuickTime
RandMap
Safari
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SkinsHP1
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
SonicAC3Encoder
SonicMPEGEncoder
Spybot - Search & Destroy
Synaptics Pointing Device Driver
TourSetup
Trend Micro RUBotted
Unload
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Vongo
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Wireless Home Network Setup

==== Event Viewer Messages From Past Week ========

2/1/2010 10:33:55 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AliIde IntelIde Pcmcia ViaIde
1/29/2010 8:35:40 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ System Application service to connect.
1/29/2010 8:35:40 PM, error: Service Control Manager [7000] - The COM+ System Application service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/29/2010 8:35:40 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service COMSysApp with arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
1/29/2010 8:29:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Print Spooler service to connect.
1/29/2010 8:29:38 PM, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/29/2010 8:28:27 PM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
1/29/2010 4:45:16 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'GEARAspiWDM.sys' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/28/2010 9:36:25 PM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/28/2010 10:01:34 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Trend Micro RUBotted Service service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Message Queuing service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The HASP License Manager service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 10:01:33 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/28/2010 10:01:33 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
1/28/2010 10:01:33 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
1/28/2010 10:01:33 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/28/2010 10:01:33 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/27/2010 9:59:09 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
1/27/2010 9:59:09 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL. Reference error message: The operation completed successfully. .
1/27/2010 9:59:09 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.
1/26/2010 7:05:13 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee SystemGuards service to connect.
1/26/2010 7:05:13 PM, error: Service Control Manager [7000] - The McAfee SystemGuards service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

==== End Of File ===========================

Thanks
Hi,

Please do the following:




Please download and execute this file, and post the log produced. The log is also saved at C:\maxhandle.txt

http://noahdfear.net/downloads/maxhandle.exe

If the infection I suspect is not found…Nothing found! is echoed to the screen - no log is produced.

Also…

Please download mbr.exe from here to your desktop.

Open NOTEPAD and copy/paste the text in the quotebox below into it:

@echo off
mbr.exe -t
start mbr.log
del %0

Save this as fix.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Place fix.bat next to mbr.exe & then double click to run it. A log file should open.

Post the contents in your next reply
Nothing found on the maxhandle

Here is log for mbr

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvata.sys
kernel: MBR read successfully
Hi,

Please run the following:

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Hi,

Can you please run the following command:

Go to Start > Run and type in cmd

a command window will open

copy/paste the following into the command window:

handle -a >%systemdrive%\handle.txt

you will find a log file called handle.txt in your C:\ drive
it will be very large, please zip it up and attach the zipped file in your next reply.
Here are the OTL logs
OTL logfile created on: 2/3/2010 9:47:50 PM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\test\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.00 Mb Total Physical Memory | 318.00 Mb Available Physical Memory | 33.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.66 Gb Total Space | 47.52 Gb Free Space | 58.91% Space Free | Partition Type: NTFS
Drive D: | 11.46 Gb Total Space | 1.09 Gb Free Space | 9.53% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-0CDC4F5844
Current User Name: test
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\test\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Trend Micro\RUBotted\TMRUBottedLite.exe ()
PRC - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\WINDOWS\system32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\test\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (gupdate1ca204bad189b6c) Google Update Service (gupdate1ca204bad189b6c) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (RUBotted) – C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe (Trend Micro Inc.)
SRV - (MSMQTriggers) – C:\WINDOWS\system32\mqtgsvc.exe (Microsoft Corporation)
SRV - (MSMQ) – C:\WINDOWS\system32\mqsvc.exe (Microsoft Corporation)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (Aladdin Knowledge Systems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (hpqwmiex) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://groups.yahoo.com/group/DFWpaddlers/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/01/20 19:46:05 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/01/28 19:43:26 | 000,377,755 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13022 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TMRUBottedTray] C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\test\Start Menu\Programs\StartUp\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 64 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 63 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1244681197328 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Wave.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Wave.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 14:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{0fca55a6-a194-11de-ba1f-0016369ed127}\Shell\AutoRun\command - "" = F:\Seagate\Installer\InstallSeagateManager.exe – File not found
O33 - MountPoints2\{0fca55a6-a194-11de-ba1f-0016369ed127}\Shell\Install\command - "" = F:\Seagate\Installer\InstallSeagateManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2006/09/19 22:40:03 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)

========== Files/Folders - Created Within 14 Days ==========

[2010/02/03 21:42:27 | 000,548,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\test\Desktop\OTL.exe
[2010/02/03 21:02:00 | 000,417,136 | —- | C] (Sysinternals) – C:\WINDOWS\handle.exe
[2010/02/02 19:35:23 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/02 19:34:44 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/02 19:33:51 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\test\Desktop\erunt_setup.exe
[2010/02/02 19:30:11 | 000,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\test\Desktop\SysRestorePoint.exe
[2010/02/01 20:18:43 | 000,000,000 | —D | C] – C:\Documents and Settings\test\Application Data\Malwarebytes
[2010/02/01 20:18:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/01 20:18:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/01 20:18:28 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/01 20:18:27 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/29 20:01:17 | 000,000,000 | —D | C] – C:\Documents and Settings\test\log
[2010/01/28 22:52:36 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/01/28 22:51:11 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010/01/28 22:50:36 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/01/28 22:50:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/01/28 20:03:13 | 000,000,000 | —D | C] – C:\Documents and Settings\test\Calibre Library
[2010/01/28 20:03:08 | 000,000,000 | —D | C] – C:\Documents and Settings\test\Application Data\calibre
[2010/01/28 20:00:41 | 000,000,000 | —D | C] – C:\Program Files\Calibre2
[2010/01/28 19:02:38 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/01/28 19:02:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/01/26 22:34:08 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/01/26 22:32:43 | 000,206,608 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TMPassthru.sys
[2010/01/26 22:32:41 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/01/25 23:43:46 | 000,000,000 | —D | C] – C:\Documents and Settings\test\Local Settings\Application Data\ICS
[2009/09/15 18:17:16 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2009/09/11 19:16:27 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\SACore
[2009/08/19 10:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/08/18 15:34:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/08/11 19:42:20 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/08/11 19:42:17 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/07/09 18:50:53 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\StumbleUpon
[2009/07/09 18:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2009/07/03 11:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/04/03 22:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2006/09/19 23:44:52 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/09/19 23:44:51 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/09/24 09:49:16 | 000,012,288 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/02/03 21:42:37 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\test\Desktop\OTL.exe
[2010/02/03 21:08:20 | 000,077,312 | —- | M] () – C:\Documents and Settings\test\Desktop\mbr.exe
[2010/02/03 21:01:46 | 000,802,800 | —- | M] () – C:\Documents and Settings\test\Desktop\maxhandle.exe
[2010/02/03 20:53:29 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 20:49:45 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/02/03 20:49:42 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/02/03 20:45:09 | 000,022,585 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/02/03 20:45:08 | 000,001,405 | —- | M] () – C:\hpqp.ini
[2010/02/03 20:43:04 | 000,000,039 | —- | M] () – C:\XP_TV.ini
[2010/02/03 20:42:57 | 000,051,048 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/02/03 20:42:32 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/03 20:42:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/03 20:42:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/03 20:42:07 | 1005,170,688 | -HS- | M] () – C:\hiberfil.sys
[2010/02/02 22:38:58 | 007,864,320 | -H– | M] () – C:\Documents and Settings\test\NTUSER.DAT
[2010/02/02 22:38:58 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\test\ntuser.ini
[2010/02/02 21:53:04 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/02 21:01:44 | 000,359,929 | —- | M] () – C:\Documents and Settings\test\Desktop\dds.scr
[2010/02/02 19:37:54 | 000,284,915 | —- | M] () – C:\Documents and Settings\test\Desktop\gmer.zip
[2010/02/02 19:34:46 | 000,000,611 | —- | M] () – C:\Documents and Settings\test\Desktop\NTREGOPT.lnk
[2010/02/02 19:34:46 | 000,000,592 | —- | M] () – C:\Documents and Settings\test\Desktop\ERUNT.lnk
[2010/02/02 19:33:56 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\test\Desktop\erunt_setup.exe
[2010/02/02 19:30:27 | 000,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\test\Desktop\SysRestorePoint.exe
[2010/02/02 18:40:07 | 000,483,720 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/02/02 18:40:07 | 000,412,352 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/02/02 18:40:07 | 000,065,704 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/02/01 20:18:37 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/01 01:40:16 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2010/02/01 01:39:30 | 000,001,460 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Media Center.lnk
[2010/01/31 18:58:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\test\settings.dat
[2010/01/31 13:22:26 | 000,002,439 | —- | M] () – C:\Documents and Settings\test\Desktop\HiJackThis.lnk
[2010/01/29 18:19:18 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/01/28 22:52:14 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/01/28 22:51:09 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/01/28 21:46:49 | 000,274,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/28 20:02:26 | 000,000,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2010/01/28 19:43:26 | 000,377,755 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/28 19:02:44 | 000,000,933 | —- | M] () – C:\Documents and Settings\test\Desktop\Spybot - Search & Destroy.lnk
[2010/01/27 21:00:29 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/01/26 22:54:02 | 000,000,036 | —- | M] () – C:\Documents and Settings\test\Local Settings\Application Data\housecall.guid.cache
[2010/01/26 19:15:47 | 000,000,031 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2010/01/25 22:57:08 | 000,000,210 | RHS- | M] () – C:\boot.ini
[2010/01/25 21:44:41 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/03 21:07:58 | 000,077,312 | —- | C] () – C:\Documents and Settings\test\Desktop\mbr.exe
[2010/02/03 21:01:35 | 000,802,800 | —- | C] () – C:\Documents and Settings\test\Desktop\maxhandle.exe
[2010/02/02 21:01:43 | 000,359,929 | —- | C] () – C:\Documents and Settings\test\Desktop\dds.scr
[2010/02/02 19:37:40 | 000,284,915 | —- | C] () – C:\Documents and Settings\test\Desktop\gmer.zip
[2010/02/02 19:34:46 | 000,000,611 | —- | C] () – C:\Documents and Settings\test\Desktop\NTREGOPT.lnk
[2010/02/02 19:34:46 | 000,000,592 | —- | C] () – C:\Documents and Settings\test\Desktop\ERUNT.lnk
[2010/02/01 20:18:37 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/31 18:58:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\test\settings.dat
[2010/01/29 01:23:46 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/01/28 22:59:54 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/01/28 22:59:54 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/01/28 22:59:54 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/01/28 22:59:54 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/01/28 22:59:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/01/28 22:51:09 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/01/28 20:02:26 | 000,000,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\calibre - E-book management.lnk
[2010/01/28 19:02:44 | 000,000,933 | —- | C] () – C:\Documents and Settings\test\Desktop\Spybot - Search & Destroy.lnk
[2010/01/26 22:54:02 | 000,000,036 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\housecall.guid.cache
[2010/01/26 22:34:11 | 000,002,439 | —- | C] () – C:\Documents and Settings\test\Desktop\HiJackThis.lnk
[2010/01/01 14:20:51 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/11/15 11:50:34 | 000,001,274 | —- | C] () – C:\WINDOWS\4DQuickFontWizard.INI
[2009/09/26 16:31:41 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2009/08/18 11:19:41 | 000,000,141 | —- | C] () – C:\WINDOWS\asym.ini
[2009/04/03 21:12:13 | 000,005,632 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/31 18:31:23 | 000,000,000 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\FnF4.txt
[2009/03/31 13:59:45 | 000,000,127 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\fusioncache.dat
[2009/03/31 13:59:45 | 000,000,000 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\DSwitch.txt
[2009/03/31 13:59:45 | 000,000,000 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\AtStart.txt
[2009/03/31 13:59:44 | 000,000,000 | —- | C] () – C:\Documents and Settings\test\Local Settings\Application Data\QSwitch.txt
[2008/01/14 16:47:06 | 000,099,712 | —- | C] () – C:\WINDOWS\HPBroker.dll
[2006/09/20 00:31:07 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/20 00:27:17 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/09/20 00:14:30 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/20 00:04:20 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/18 02:00:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/18 02:00:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/08/18 02:00:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/18 02:00:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/08/18 02:00:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/06/29 13:18:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 12:49:18 | 000,000,368 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/06/29 12:46:56 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 12:43:40 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/03/04 01:07:34 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/02 12:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/05/05 20:06:32 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2004/09/16 14:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/01/01 14:20:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/08/19 19:20:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kinoma
[2009/08/19 19:22:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Marlin
[2009/11/09 22:31:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pulse
[2009/06/21 08:46:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/04 00:02:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/09/09 20:43:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/14 21:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/01/28 22:51:19 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010/01/28 20:03:45 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\calibre
[2009/12/25 18:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\GARMIN
[2009/06/23 21:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\ieSpell
[2009/04/03 21:23:00 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\Leadertech
[2009/05/04 21:36:50 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\OpenOffice.org
[2010/01/26 20:56:08 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\StumbleUpon
[2009/05/26 19:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\test\Application Data\Viewpoint
[2010/02/03 20:49:42 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010/02/03 20:49:44 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010/02/03 20:49:45 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/04/03 23:00:32 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/02/01 01:40:16 | 000,000,330 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/11/07 12:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe


< MD5 for: AGP440.SYS >
[2006/03/15 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\I386\sp2.cab:AGP440.sys
[2006/03/15 22:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/06/10 19:11:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/06/10 19:11:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 12:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 12:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 08:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2006/03/15 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\I386\sp2.cab:atapi.sys
[2006/03/15 22:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/06/10 19:11:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/06/10 19:11:37 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 12:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 07:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 18:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 18:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2006/03/15 22:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2005/10/13 03:07:12 | 000,874,240 | —- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B – C:\SWSetup\HDD\iastor.sys
[2005/10/13 03:07:12 | 000,874,240 | —- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B – C:\WINDOWS\system32\drivers\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 18:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 18:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2006/03/15 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\IDE\Win2K\sata_ide\nvata.sys
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\IDE\WinXP\sata_ide\nvata.sys
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\nvata.sys
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\WINDOWS\system32\drivers\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\IDE\Win2K\sataraid\nvatabus.sys
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\IDE\WinXP\sataraid\nvatabus.sys
[2006/01/26 18:04:16 | 000,099,584 | —- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 – C:\SWSetup\Chipset\nvatabus.sys

< MD5 for: SCECLI.DLL >
[2006/03/15 22:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 18:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 18:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/02/02 17:33:07 | 016,777,216 | -HS- | M] () – C:\WINDOWS\system32\config\axkmhvaj.sav
[2006/06/29 04:59:22 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/06/29 04:59:22 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
< End of report >

OTL Extras logfile created on: 2/3/2010 9:47:50 PM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\test\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.00 Mb Total Physical Memory | 318.00 Mb Available Physical Memory | 33.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.66 Gb Total Space | 47.52 Gb Free Space | 58.91% Space Free | Partition Type: NTFS
Drive D: | 11.46 Gb Total Space | 1.09 Gb Free Space | 9.53% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-0CDC4F5844
Current User Name: test
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1947:TCP" = 1947:TCP:*:Enabled:HASP SRM
"1947:UDP" = 1947:UDP:*:Enabled:HASP SRM

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mqsvc.exe" = C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mqsvc.exe" = C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing – (Microsoft Corporation)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{09B09E5C-5CFA-4DA2-B8DB-9D3D64E052DD}" = 4D Embroidery Extra 8.1
"{09BA972C-5F3C-4A2D-95A0-832985E183F1}" = 4D Embroidery System 8.1 Update
"{09D8492A-C8E2-421E-927D-46800FB327A3}" = Wireless Home Network Setup
"{12650598-D7B9-4FB5-91B2-2CAA641AC589}" = Trend Micro RUBotted
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B3A1F17-2A1A-4C08-8722-39CE8C1FAC28}" = 32-bit VSM Device Drivers 8.2
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{328019A7-0012-401D-96A2-4CDDD02675A8}" = Garmin POI Loader
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A2
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 G2
"{4361496D-B956-4C83-A7A5-2BFDFC73FAC7}" = Embroidery Machine Communication Software
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.3
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{5058EC99-4AB7-4306-98FD-E42FE97FDB2D}" = calibre
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{52FBAE98-D389-4281-8C14-21B4046CCB4E}" = SonicAC3Encoder
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A28AB0B-22B1-494C-AF61-B386EA1736C0}" = LightScribe 1.4.97.1
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}" =
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = TourSetup
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B16AF568-A644-483C-A6DA-5028CD019C8C}" = SonicMPEGEncoder
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{B607C354-CD79-4D22-86D1-92DC94153F42}" = Apple Application Support
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{C084BC61-E537-11DE-8616-005056806466}" = Google Earth
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DB7E00C9-6DEF-489A-8112-D8F81614F45A}" = Vongo
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E276E05A-FFE8-485B-A005-42E76EA72AC4}" = HP User Guides 0032
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{E89C3076-E0FC-4CE1-916A-8942250D7E31}" = 32-bit VSM Device Drivers
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB09F05F-85C6-4205-B28D-5BF071D276C3}" = muvee autoProducer 5.0
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"7-Zip" = 7-Zip 9.07 beta
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m" = Soft Data Fax Modem with SmartCP
"EPSON Scanner" = EPSON Scan
"EPSON WorkForce 500 Series" = EPSON WorkForce 500 Series Printer Uninstall
"ERUNT_is1" = ERUNT 1.1j
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ieSpell" = ieSpell
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/1/2010 12:53:35 AM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 1:53:24 AM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 2:53:15 AM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 3:53:24 AM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 4:53:24 AM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 7:53:30 PM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 8:53:21 PM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/1/2010 9:53:45 PM | Computer Name = YOUR-0CDC4F5844 | Source = Google Update | ID = 20
Description =

Error - 2/2/2010 7:38:44 PM | Computer Name = YOUR-0CDC4F5844 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 2/3/2010 11:45:44 PM | Computer Name = YOUR-0CDC4F5844 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.1.27.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7031
Description = The McAfee Network Agent service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7031
Description = The McAfee Personal Firewall Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
5000 milliseconds: Run the configured recovery program.

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Trend Micro RUBotted Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7031
Description = The Media Center Extender Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
5000 milliseconds: Restart the service.

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Message Queuing service terminated unexpectedly. It has done
this 1 time(s).

Error - 2/2/2010 1:00:31 AM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7034
Description = The Application Layer Gateway Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 2/2/2010 7:33:58 PM | Computer Name = YOUR-0CDC4F5844 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000243'
while processing the file 'GEARAspiWDM.sys' on the volume 'HarddiskVolume1'. It
has stopped monitoring the volume.

Error - 2/2/2010 7:34:53 PM | Computer Name = YOUR-0CDC4F5844 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 2/3/2010 10:44:57 PM | Computer Name = YOUR-0CDC4F5844 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cdrom Imapi redbook


< End of report >
Hi


You have a fairly new rootkit infection, - max++ version2 - so I will be asking for a few diagnostic logs, I appreciate your co-operation very much.

This will help us to be able to fix this properly.

Please do the following:
Go to > Start > Run > type in
sigverif - the file Signature verification window will open

click the Advanced button

check the "Look for other files that are not digitally signed"

in the "scan this file type" box - from the drop down menu - change the file types to *.sys

In the "Look in this folder" window > browse to and select c:\windows\system32\drivers
click OK
click start
generally a window will open when done with the unsigned files it finds - close it, then click Advanced again

click the Logging tab then View log - post the contents of the log in your next reply.
******************************** Microsoft Signature Verification Log file generated on 2/4/2010 at 9:38 PM OS Platform: Windows 2000 (x86), Version: 5.1, Build: 2600, CSDVersion: Service Pack 3 Scan Results: Total Files: 346, Signed: 340, Unsigned: 6, Not Scanned: 0 User-specified search path: *.sys User-specified search pattern: C:\WINDOWS\system32\drivers File Modified Version Status Catalog Signed By —————— ———— ———– ———— ———– ——————- [c:\windows\system32\drivers] 1394bus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher 5u870cap.sys 6/6/2006 2:5.1 Signed oem11.CAT Microsoft Windows Hardware Compatibility Publisher abp480n5.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher acpi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher acpiec.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher adpu160m.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher afd.sys 8/14/2008 2:5.1 Signed KB956803.cat Microsoft Windows Component Publisher agp440.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher agpcpq.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher aha154x.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher aic78u2.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aic78xx.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aksclass.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem52.CAT Microsoft Windows Hardware Compatibility Publisher aksfridge.sys 3/12/2007 2:5.00,2:5.1,2:5.2,2Signed oem50.CAT Microsoft Windows Hardware Compatibility Publisher akshasp.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem51.CAT Microsoft Windows Hardware Compatibility Publisher akshhl.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem50.CAT Microsoft Windows Hardware Compatibility Publisher aksusb.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem52.CAT Microsoft Windows Hardware Compatibility Publisher aliide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher alim1541.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk6.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk7.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk8.sys 6/19/2006 2:5.1,2:5.2 Signed oem0.CAT Microsoft Windows Component Publisher amsint.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher arp1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher asc.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher asc3350p.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher asc3550.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher asyncmac.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1btxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1mdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1pdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1raxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1rvxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1snxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1ttxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1tuxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1xbxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1xsxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati2mtaa.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati2mtag.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinbtxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinmdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinpdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinraxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinrvxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinsnxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinttxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atintuxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinxbxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinxsxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmarpc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmepvc.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher atmlane.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmuni.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher audstub.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher battc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bcmwl5.sys 4/28/2006 2:5.00,2:5.1,2:5.2 Signed oem10.CAT Microsoft Windows Hardware Compatibility Publisher beep.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher bridge.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthmodem.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthpan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthport.sys 6/13/2008 2:5.1 Signed KB951376-v2.cat Microsoft Windows Component Publisher bthprint.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthusb.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher btwusb.sys 5/12/2006 4.0.1.3500 Not Signed N/A cbidf2k.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ccdecode.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cd20xrnt.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher cdaudio.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher cdfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cdrom.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher chdaud.sys 6/1/2006 2:5.00,2:5.1 Signed oem14.CAT Microsoft Windows Hardware Compatibility Publisher cinemst2.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher classpnp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cmbatt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cmdide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher compbatt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cpqarray.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher cpqbttn.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher cpqdap01.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher crusoe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dac2w2k.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dac960nt.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher disk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher diskdump.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmboot.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmload.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dmusic.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dpti2o.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher drmk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher drmkaud.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dxapi.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dxg.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dxgthk.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher eabfiltr.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher eabusb.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher enum1394.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher fastfat.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fdc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fips.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher flpydisk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fltmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fsvga.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher fs_rec.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ftdisk.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher gagp30kx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hardlock.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem51.CAT Microsoft Windows Hardware Compatibility Publisher hdaudbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hdaudio.sys 1/7/2005 2:5.1 Signed KB888111WXPSP2.cat Microsoft Windows XP Publisher hidbth.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidir.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidparse.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidusb.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hpn.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher hsfbs2s2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfcxts2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfdpsp2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfhwazl.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher hsf_cnxt.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher hsf_dpv.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher http.sys 10/20/2009 2:5.1 Signed KB970430.cat Microsoft Windows Component Publisher i2omgmt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher i2omp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher i8042prt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher iastor.sys 10/13/2005 5.5.0.1035 Not Signed N/A imapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ini910u.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher intelide.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher intelppm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ip6fw.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipfltdrv.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ipinip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipnat.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipsec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher irbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher irenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher isapnp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kbdclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kbdhid.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kmixer.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ks.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ksecdd.sys 6/24/2009 2:5.1 Signed KB968389.cat Microsoft Windows Component Publisher lbd.sys 12/2/2009 None Signed N/A Lavasoft AB mbam.sys 1/7/2010 None Signed N/A Malwarebytes Corporation mbamswissarmy.sys 1/7/2010 None Signed N/A Malwarebytes Corporation mcd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mdmxsdk.sys 2/13/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher mf.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mfeavfk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem47.CAT Microsoft Windows Hardware Compatibility Publisher mfebopk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem48.CAT Microsoft Windows Hardware Compatibility Publisher mfehidk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem46.CAT Microsoft Windows Hardware Compatibility Publisher mferkdk.sys 9/16/2009 None Signed N/A McAfee, Inc. mfesmfk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem49.CAT Microsoft Windows Hardware Compatibility Publisher mhndrv.sys 8/10/2004 5.1.2600.2180 Not Signed N/A mnmdd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher modem.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mouclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mouhid.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mountmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mpfp.sys 7/16/2009 2:5.1 Signed McAfee Personal FireMicrosoft Windows Hardware Compatibility Publisher mqac.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mraid35x.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mrxdav.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mrxsmb.sys 10/24/2008 2:5.1 Signed KB957097.cat Microsoft Windows Component Publisher msfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher msgpc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mskssrv.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mspclock.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mspqm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mssmbios.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mstee.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtlmnt5.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtlstrm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtxparhm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mup.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mutohpen.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nabtsfec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndis.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndisip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndistapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndisuio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndiswan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndproxy.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher netbios.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher netbt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nic1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nikedrv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher nmnt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher npfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ntfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ntmtlfax.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher null.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nv4_mini.sys 8/18/2006 2:5.00,2:5.1 Signed oem1.CAT Microsoft Windows Hardware Compatibility Publisher nvata.sys 1/26/2006 2:5.00,2:5.1 Signed oem3.CAT Microsoft Windows Hardware Compatibility Publisher nvenetfd.sys 3/2/2006 2:5.00,2:5.1 Signed oem5.CAT Microsoft Windows Hardware Compatibility Publisher nvnetbus.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvnrm.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvsmu.sys 3/5/2006 2:5.00,2:5.1 Signed oem6.CAT Microsoft Windows Hardware Compatibility Publisher nvsnpu.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvtcp.sys 3/2/2006 1.0.0.5024 Not Signed N/A nwlnkflt.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkfwd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkipx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nwlnknb.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkspx.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwrdr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ohci1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher oprghdlr.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher p3.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher parport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher partmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher parvdm.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher pciide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pciidex.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher pcmcia.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher perc2.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher perc2hib.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher portcls.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher processr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher psched.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ptilink.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pxhelp20.sys 6/20/2005 2.3.32.0 Not Signed N/A ql1080.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql10wnt.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql12160.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql1240.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql1280.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rasacd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rasl2tp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspppoe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspptp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspti.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rawwan.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rdbss.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rdpcdd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rdpdr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rdpwd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher recagent.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher redbook.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rfcomm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rimmptsk.sys 11/15/2005 2:5.00,2:5.1 Signed oem8.CAT Microsoft Windows Hardware Compatibility Publisher rimsptsk.sys 10/31/2005 2:5.00,2:5.1 Signed oem7.CAT Microsoft Windows Hardware Compatibility Publisher rio8drv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher riodrv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher rixdptsk.sys 10/31/2005 2:5.00,2:5.1 Signed oem9.CAT Microsoft Windows Hardware Compatibility Publisher rmcast.sys 5/8/2008 2:5.1 Signed KB950762.cat Microsoft Windows Component Publisher rndismp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rndismpx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rootmdm.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rtl8139.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher s3gnbm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher scsiport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sdbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher secdrv.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher serenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher serial.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffdisk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffp_mmc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffp_sd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sfloppy.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sisagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slnt7554.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slntamr.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slnthal.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slwdmsup.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher smbali.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher smclib.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sonydcam.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sparrow.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher splitter.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher srv.sys 12/11/2008 2:5.1 Signed KB958687.cat Microsoft Windows Component Publisher stream.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher streamip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher swenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher swmidi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher symc810.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher symc8xx.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sym_hi.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sym_u3.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher syntp.sys 3/31/2006 2:5.00,2:5.1 Signed oem21.CAT Microsoft Windows Hardware Compatibility Publisher sysaudio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tape.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tcpip.sys 6/20/2008 2:5.1 Signed KB951748.cat Microsoft Windows Component Publisher tcpip6.sys 6/20/2008 2:5.1 Signed KB951748.cat Microsoft Windows Component Publisher tdi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tdpipe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tdtcp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher termdd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tmpassthru.sys 3/2/2008 2:5.00,2:5.1,2:5.2,2Signed oem38.CAT Microsoft Windows Hardware Compatibility Publisher tosdvd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher toside.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher tsbvcap.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher tunmp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher uagp35.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher udfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ultra.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher update.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usb8023.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usb8023x.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbaapl.sys 8/28/2009 2:5.1,2:6.0,2:6.1 Signed oem39.CAT Microsoft Windows Hardware Compatibility Publisher usbcamd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbcamd2.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher usbehci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbhub.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbintel.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbohci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbscan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbstor.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbuhci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbvideo.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher vdmindvd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher vga.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher viaagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher viaide.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher videoprt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher volsnap.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher vsmrwdriver.sys 1/8/2007 1.0.1.3 Not Signed N/A wacompen.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv07nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv08nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv09nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv11nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wanarp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher watv06nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher watv10nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wdf01000.sys 11/2/2006 2:5.0,2:5.1,2:5.2 Signed Wdf01005.cat Microsoft Windows Component Publisher wdfldr.sys 11/2/2006 2:5.0,2:5.1,2:5.2 Signed Wdf01005.cat Microsoft Windows Component Publisher wdmaud.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wmiacpi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wmilib.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher wpdusb.sys 10/18/2006 2:5.1 Signed WMFDist11.cat Microsoft Windows Component Publisher ws2ifsl.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher wstcodec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wudfpf.sys 9/28/2006 2:5.1,2:5.2 Signed Wudf01000.cat Microsoft Windows wudfrd.sys 9/28/2006 2:5.1,2:5.2 Signed Wudf01000.cat Microsoft Windows
Thank-you for the log.

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
I may have messed up, I had turned off the wireless and it had not come back on before it tried to install the recovery console. It ran the scan here is the log ******************************** Microsoft Signature Verification Log file generated on 2/4/2010 at 9:38 PM OS Platform: Windows 2000 (x86), Version: 5.1, Build: 2600, CSDVersion: Service Pack 3 Scan Results: Total Files: 346, Signed: 340, Unsigned: 6, Not Scanned: 0 User-specified search path: *.sys User-specified search pattern: C:\WINDOWS\system32\drivers File Modified Version Status Catalog Signed By —————— ———— ———– ———— ———– ——————- [c:\windows\system32\drivers] 1394bus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher 5u870cap.sys 6/6/2006 2:5.1 Signed oem11.CAT Microsoft Windows Hardware Compatibility Publisher abp480n5.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher acpi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher acpiec.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher adpu160m.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher afd.sys 8/14/2008 2:5.1 Signed KB956803.cat Microsoft Windows Component Publisher agp440.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher agpcpq.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher aha154x.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher aic78u2.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aic78xx.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher aksclass.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem52.CAT Microsoft Windows Hardware Compatibility Publisher aksfridge.sys 3/12/2007 2:5.00,2:5.1,2:5.2,2Signed oem50.CAT Microsoft Windows Hardware Compatibility Publisher akshasp.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem51.CAT Microsoft Windows Hardware Compatibility Publisher akshhl.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem50.CAT Microsoft Windows Hardware Compatibility Publisher aksusb.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem52.CAT Microsoft Windows Hardware Compatibility Publisher aliide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher alim1541.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk6.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk7.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher amdk8.sys 6/19/2006 2:5.1,2:5.2 Signed oem0.CAT Microsoft Windows Component Publisher amsint.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher arp1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher asc.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher asc3350p.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher asc3550.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher asyncmac.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1btxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1mdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1pdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1raxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1rvxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1snxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1ttxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1tuxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1xbxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati1xsxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati2mtaa.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ati2mtag.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinbtxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinmdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinpdxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinraxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinrvxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinsnxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinttxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atintuxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinxbxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atinxsxx.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmarpc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmepvc.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher atmlane.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher atmuni.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher audstub.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher battc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bcmwl5.sys 4/28/2006 2:5.00,2:5.1,2:5.2 Signed oem10.CAT Microsoft Windows Hardware Compatibility Publisher beep.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher bridge.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthmodem.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthpan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthport.sys 6/13/2008 2:5.1 Signed KB951376-v2.cat Microsoft Windows Component Publisher bthprint.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher bthusb.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher btwusb.sys 5/12/2006 4.0.1.3500 Not Signed N/A cbidf2k.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ccdecode.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cd20xrnt.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher cdaudio.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher cdfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cdrom.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher chdaud.sys 6/1/2006 2:5.00,2:5.1 Signed oem14.CAT Microsoft Windows Hardware Compatibility Publisher cinemst2.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher classpnp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cmbatt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cmdide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher compbatt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher cpqarray.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher cpqbttn.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher cpqdap01.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher crusoe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dac2w2k.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dac960nt.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher disk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher diskdump.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmboot.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dmload.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dmusic.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dpti2o.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher drmk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher drmkaud.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dxapi.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher dxg.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher dxgthk.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher eabfiltr.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher eabusb.sys 9/19/2005 2:5.00,2:5.1 Signed oem23.CAT Microsoft Windows Hardware Compatibility Publisher enum1394.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher fastfat.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fdc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fips.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher flpydisk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fltmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher fsvga.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher fs_rec.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ftdisk.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher gagp30kx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hardlock.sys 3/6/2007 2:5.00,2:5.1,2:5.2,2Signed oem51.CAT Microsoft Windows Hardware Compatibility Publisher hdaudbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hdaudio.sys 1/7/2005 2:5.1 Signed KB888111WXPSP2.cat Microsoft Windows XP Publisher hidbth.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidir.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidparse.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hidusb.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hpn.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher hsfbs2s2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfcxts2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfdpsp2.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher hsfhwazl.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher hsf_cnxt.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher hsf_dpv.sys 4/19/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher http.sys 10/20/2009 2:5.1 Signed KB970430.cat Microsoft Windows Component Publisher i2omgmt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher i2omp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher i8042prt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher iastor.sys 10/13/2005 5.5.0.1035 Not Signed N/A imapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ini910u.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher intelide.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher intelppm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ip6fw.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipfltdrv.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ipinip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipnat.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ipsec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher irbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher irenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher isapnp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kbdclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kbdhid.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher kmixer.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ks.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ksecdd.sys 6/24/2009 2:5.1 Signed KB968389.cat Microsoft Windows Component Publisher lbd.sys 12/2/2009 None Signed N/A Lavasoft AB mbam.sys 1/7/2010 None Signed N/A Malwarebytes Corporation mbamswissarmy.sys 1/7/2010 None Signed N/A Malwarebytes Corporation mcd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mdmxsdk.sys 2/13/2006 2:5.00,2:5.1 Signed oem15.CAT Microsoft Windows Hardware Compatibility Publisher mf.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mfeavfk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem47.CAT Microsoft Windows Hardware Compatibility Publisher mfebopk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem48.CAT Microsoft Windows Hardware Compatibility Publisher mfehidk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem46.CAT Microsoft Windows Hardware Compatibility Publisher mferkdk.sys 9/16/2009 None Signed N/A McAfee, Inc. mfesmfk.sys 9/16/2009 2:5.00,2:5.1,2:5.2,2Signed oem49.CAT Microsoft Windows Hardware Compatibility Publisher mhndrv.sys 8/10/2004 5.1.2600.2180 Not Signed N/A mnmdd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher modem.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mouclass.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mouhid.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mountmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mpfp.sys 7/16/2009 2:5.1 Signed McAfee Personal FireMicrosoft Windows Hardware Compatibility Publisher mqac.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mraid35x.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher mrxdav.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mrxsmb.sys 10/24/2008 2:5.1 Signed KB957097.cat Microsoft Windows Component Publisher msfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher msgpc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mskssrv.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mspclock.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mspqm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mssmbios.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mstee.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtlmnt5.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtlstrm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mtxparhm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mup.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher mutohpen.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nabtsfec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndis.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndisip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndistapi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndisuio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndiswan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ndproxy.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher netbios.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher netbt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nic1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nikedrv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher nmnt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher npfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ntfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ntmtlfax.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher null.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nv4_mini.sys 8/18/2006 2:5.00,2:5.1 Signed oem1.CAT Microsoft Windows Hardware Compatibility Publisher nvata.sys 1/26/2006 2:5.00,2:5.1 Signed oem3.CAT Microsoft Windows Hardware Compatibility Publisher nvenetfd.sys 3/2/2006 2:5.00,2:5.1 Signed oem5.CAT Microsoft Windows Hardware Compatibility Publisher nvnetbus.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvnrm.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvsmu.sys 3/5/2006 2:5.00,2:5.1 Signed oem6.CAT Microsoft Windows Hardware Compatibility Publisher nvsnpu.sys 3/2/2006 2:5.00,2:5.1 Signed oem4.CAT Microsoft Windows Hardware Compatibility Publisher nvtcp.sys 3/2/2006 1.0.0.5024 Not Signed N/A nwlnkflt.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkfwd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkipx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher nwlnknb.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwlnkspx.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher nwrdr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ohci1394.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher oprghdlr.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher p3.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher parport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher partmgr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher parvdm.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher pciide.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pciidex.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher pcmcia.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher perc2.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher perc2hib.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher portcls.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher processr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher psched.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ptilink.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher pxhelp20.sys 6/20/2005 2.3.32.0 Not Signed N/A ql1080.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql10wnt.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql12160.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql1240.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher ql1280.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rasacd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rasl2tp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspppoe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspptp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher raspti.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rawwan.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rdbss.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rdpcdd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rdpdr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rdpwd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher recagent.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher redbook.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rfcomm.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rimmptsk.sys 11/15/2005 2:5.00,2:5.1 Signed oem8.CAT Microsoft Windows Hardware Compatibility Publisher rimsptsk.sys 10/31/2005 2:5.00,2:5.1 Signed oem7.CAT Microsoft Windows Hardware Compatibility Publisher rio8drv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher riodrv.sys 3/15/2006 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher rixdptsk.sys 10/31/2005 2:5.00,2:5.1 Signed oem9.CAT Microsoft Windows Hardware Compatibility Publisher rmcast.sys 5/8/2008 2:5.1 Signed KB950762.cat Microsoft Windows Component Publisher rndismp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rndismpx.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher rootmdm.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher rtl8139.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher s3gnbm.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher scsiport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sdbus.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher secdrv.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher serenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher serial.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffdisk.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffp_mmc.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sffp_sd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sfloppy.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sisagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slnt7554.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slntamr.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slnthal.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher slwdmsup.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher smbali.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher smclib.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sonydcam.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sparrow.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher splitter.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher sr.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher srv.sys 12/11/2008 2:5.1 Signed KB958687.cat Microsoft Windows Component Publisher stream.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher streamip.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher swenum.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher swmidi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher symc810.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher symc8xx.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sym_hi.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher sym_u3.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher syntp.sys 3/31/2006 2:5.00,2:5.1 Signed oem21.CAT Microsoft Windows Hardware Compatibility Publisher sysaudio.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tape.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tcpip.sys 6/20/2008 2:5.1 Signed KB951748.cat Microsoft Windows Component Publisher tcpip6.sys 6/20/2008 2:5.1 Signed KB951748.cat Microsoft Windows Component Publisher tdi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tdpipe.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tdtcp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher termdd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher tmpassthru.sys 3/2/2008 2:5.00,2:5.1,2:5.2,2Signed oem38.CAT Microsoft Windows Hardware Compatibility Publisher tosdvd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher toside.sys 8/17/2001 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher tsbvcap.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher tunmp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher uagp35.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher udfs.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher ultra.sys 8/17/2001 2:5.1 Signed nt5inf.cat Microsoft Windows Component Publisher update.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usb8023.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usb8023x.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbaapl.sys 8/28/2009 2:5.1,2:6.0,2:6.1 Signed oem39.CAT Microsoft Windows Hardware Compatibility Publisher usbcamd.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbcamd2.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher usbehci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbhub.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbintel.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbohci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbport.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbscan.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbstor.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbuhci.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher usbvideo.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher vdmindvd.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher vga.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher viaagp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher viaide.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher videoprt.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher volsnap.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher vsmrwdriver.sys 1/8/2007 1.0.1.3 Not Signed N/A wacompen.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv07nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv08nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv09nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wadv11nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wanarp.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher watv06nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher watv10nt.sys 8/4/2004 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wdf01000.sys 11/2/2006 2:5.0,2:5.1,2:5.2 Signed Wdf01005.cat Microsoft Windows Component Publisher wdfldr.sys 11/2/2006 2:5.0,2:5.1,2:5.2 Signed Wdf01005.cat Microsoft Windows Component Publisher wdmaud.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wmiacpi.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wmilib.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher wpdusb.sys 10/18/2006 2:5.1 Signed WMFDist11.cat Microsoft Windows Component Publisher ws2ifsl.sys 3/15/2006 2:5.1 Signed nt5.cat Microsoft Windows Component Publisher wstcodec.sys 4/13/2008 2:5.1 Signed sp3.cat Microsoft Windows Component Publisher wudfpf.sys 9/28/2006 2:5.1,2:5.2 Signed Wudf01000.cat Microsoft Windows wudfrd.sys 9/28/2006 2:5.1,2:5.2 Signed Wudf01000.cat Microsoft Windows
My apologies, I thought that I had posted (and saved) the combo fix log. And now I can't find it. Do you want me to rerun or do something else?

Is this it? (I do feel like an idiot)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: error reading MBR
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf74ebf28
\Driver\ACPI -> ACPI.sys @ 0xf735ecb8
\Driver\atapi -> atapi.sys @ 0xf72d2852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xf71c5bb0
PacketIndicateHandler -> NDIS.sys @ 0xf71b4a0d
SendHandler -> NDIS.sys @ 0xf71c8b40
omboFix 10-02-04.06 - test 02/04/2010 22:26:09.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.525 [GMT -6:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\install.exe c:\windows\jestertb.dll c:\windows\kb913800.exe D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 ))))))))))))))))))))))))))))))) . 2010-02-05 04:00 . 2010-02-05 04:00 ——– d—–w- c:\windows\LastGood 2010-02-04 04:20 . 2010-02-04 04:20 101154 —-a-w- C:\handle.zip 2010-02-04 03:02 . 2008-11-18 19:15 417136 —-a-w- c:\windows\handle.exe 2010-02-03 01:34 . 2010-02-03 01:34 ——– d—–w- c:\program files\ERUNT 2010-02-02 02:18 . 2010-02-02 02:18 ——– d—–w- c:\documents and settings\test\Application Data\Malwarebytes 2010-02-02 02:18 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-02 02:18 . 2010-02-02 02:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-02 02:18 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-02 02:18 . 2010-02-02 02:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-01 00:58 . 2010-02-01 00:58 0 —-a-w- c:\documents and settings\test\settings.dat 2010-01-30 02:01 . 2010-01-30 02:01 ——– d—–w- c:\documents and settings\test\log 2010-01-29 07:23 . 2010-01-29 04:52 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-01-29 04:51 . 2010-01-29 04:51 816784 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2010-01-29 04:51 . 2010-01-29 04:51 823928 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2010-01-29 04:51 . 2010-01-29 04:51 1643272 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2010-01-29 04:51 . 2010-01-29 04:51 788880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2010-01-29 04:51 . 2010-01-29 04:51 1181328 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2010-01-29 04:51 . 2010-01-29 04:51 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9} 2010-01-29 04:51 . 2009-12-07 14:10 2953352 -c–a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe 2010-01-29 04:50 . 2010-01-29 04:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft 2010-01-29 04:50 . 2010-01-29 04:50 ——– d—–w- c:\program files\Lavasoft 2010-01-29 02:03 . 2010-01-29 02:07 ——– d—–w- c:\documents and settings\test\Calibre Library 2010-01-29 02:03 . 2010-01-29 02:03 ——– d—–w- c:\documents and settings\test\Application Data\calibre 2010-01-29 02:00 . 2010-01-29 02:02 ——– d—–w- c:\program files\Calibre2 2010-01-29 01:02 . 2010-01-29 01:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-01-29 01:02 . 2010-01-29 01:07 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-01-27 04:34 . 2010-01-27 04:34 388096 —-a-r- c:\documents and settings\test\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe 2010-01-27 04:34 . 2010-01-27 04:34 ——– d—–w- c:\program files\TrendMicro 2010-01-27 04:32 . 2008-03-02 09:28 206608 —-a-w- c:\windows\system32\drivers\TMPassthru.sys 2010-01-27 04:32 . 2010-01-27 04:32 ——– d—–w- c:\program files\Trend Micro 2010-01-26 05:43 . 2010-01-26 05:43 ——– d—–w- c:\documents and settings\test\Local Settings\Application Data\ICS 2010-01-13 01:07 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-05 03:23 . 2006-09-20 05:46 70680 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-02-04 04:08 . 2010-02-04 04:08 ——– d—–w- c:\program files\MSBuild 2010-02-04 04:08 . 2010-02-04 04:08 ——– d—–w- c:\program files\Reference Assemblies 2010-01-27 04:32 . 2006-09-20 04:39 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-01-27 04:21 . 2009-08-20 01:19 ——– d—–w- c:\program files\Sony 2010-01-27 02:56 . 2009-06-12 01:59 ——– d—–w- c:\documents and settings\test\Application Data\StumbleUpon 2010-01-27 01:52 . 2009-05-05 03:37 1 —-a-w- c:\documents and settings\test\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-01-27 01:15 . 2006-09-20 06:31 ——– d—–w- c:\program files\Quicken 2010-01-21 01:40 . 2009-09-27 00:17 ——– d—–w- c:\program files\Microsoft Silverlight 2010-01-15 02:36 . 2009-08-24 00:49 ——– d—–w- c:\program files\Common Files\Adobe 2010-01-05 10:00 . 2006-03-16 04:00 832512 —-a-w- c:\windows\system32\wininet.dll 2010-01-05 10:00 . 2006-03-16 04:00 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-01-05 10:00 . 2006-03-16 04:00 17408 —-a-w- c:\windows\system32\corpol.dll 2010-01-02 01:47 . 2010-01-02 01:47 ——– d—–w- c:\program files\Garmin 2010-01-01 20:20 . 2010-01-01 20:20 ——– d—–w- c:\documents and settings\test\Application Data\InstallShield 2010-01-01 20:20 . 2010-01-01 20:19 ——– d—–w- c:\documents and settings\All Users\Application Data\EPSON 2010-01-01 20:18 . 2010-01-01 20:18 ——– d—–w- c:\program files\epson 2009-12-26 00:09 . 2009-12-26 00:09 ——– d—–w- c:\documents and settings\test\Application Data\GARMIN 2009-12-24 01:56 . 2009-04-04 05:54 ——– d—–w- c:\program files\Google 2009-12-19 05:36 . 2009-04-04 05:00 ——– d—–w- c:\program files\McAfee 2009-12-02 13:19 . 2010-01-29 04:52 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2009-11-25 02:24 . 2009-08-18 18:05 56412 —ha-w- c:\windows\system32\mlfcache.dat 2009-11-21 15:51 . 2006-03-16 04:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll 2009-11-09 03:32 . 2009-11-09 03:32 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-18 39408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512] "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016] "nwiz"="nwiz.exe" [2006-08-18 1617920] "MsmqIntCert"="mqrt.dll" [2008-04-14 177152] "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840] "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960] "RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840] "Reminder"="c:\windows\CREATOR\Remind_XP.exe" [2006-02-09 643072] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088] c:\documents and settings\test\Start Menu\Programs\Startup\ OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1947:TCP"= 1947:TCP:HASP SRM "1947:UDP"= 1947:UDP:HASP SRM R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/28/2010 10:52 PM 64288] R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/3/2009 11:02 PM 93320] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/4/2009 12:31 AM 24652] R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [1/26/2010 10:32 PM 206608] S2 gupdate1ca204bad189b6c;Google Update Service (gupdate1ca204bad189b6c);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2009 3:34 PM 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/2/2009 7:19 AM 1181328] S2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [1/26/2010 10:32 PM 582992] S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 2:39 PM 61952] S3 rootrepeal2;rootrepeal2;\??\c:\windows\system32\drivers\rootrepeal2.sys –> c:\windows\system32\drivers\rootrepeal2.sys [?] S3 rootrepeal3;rootrepeal3;\??\c:\windows\system32\drivers\rootrepeal3.sys –> c:\windows\system32\drivers\rootrepeal3.sys [?] S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [1/26/2010 10:32 PM 206608] S3 VsmRWDriver;VSM Reader/Writer Type A USB Driver service;c:\windows\system32\drivers\VsmRWDriver.sys [11/7/2009 7:01 PM 7808] . Contents of the 'Scheduled Tasks' folder 2010-02-05 c:\windows\Tasks\Ad-Aware Update (Daily 1).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 04:51] 2010-02-05 c:\windows\Tasks\Ad-Aware Update (Daily 2).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 04:51] 2010-02-05 c:\windows\Tasks\Ad-Aware Update (Daily 3).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 04:51] 2010-02-05 c:\windows\Tasks\Ad-Aware Update (Daily 4).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 04:51] 2010-02-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 04:51] 2009-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34] 2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-18 21:34] 2010-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-18 21:34] 2009-04-04 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-04 17:22] 2010-02-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-04 17:22] . . ——- Supplementary Scan ——- . uStart Page = hxxp://groups.yahoo.com/group/DFWpaddlers/ uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI