This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus?csrss.exe,no restore points and other issues

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here's the TDSSkiller log: 08:46:52:281 4116 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48 08:46:52:281 4116 ================================================================================ 08:46:52:281 4116 SystemInfo: 08:46:52:281 4116 OS Version: 5.1.2600 ServicePack: 3.0 08:46:52:281 4116 Product type: Workstation 08:46:52:281 4116 ComputerName: TANJA 08:46:52:281 4116 UserName: mine 08:46:52:281 4116 Windows directory: C:\WINDOWS 08:46:52:281 4116 Processor architecture: Intel x86 08:46:52:281 4116 Number of processors: 2 08:46:52:281 4116 Page size: 0x1000 08:46:52:281 4116 Boot type: Normal boot 08:46:52:281 4116 ================================================================================ 08:46:52:281 4116 Initialize success 08:46:52:281 4116 08:46:52:281 4116 Scanning Services … 08:46:52:281 4116 Raw services enum returned 393 services 08:46:52:281 4116 08:46:52:281 4116 Scanning Drivers … 08:46:52:281 4116 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 08:46:52:281 4116 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 08:46:52:281 4116 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 08:46:52:281 4116 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 08:46:52:281 4116 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 08:46:52:281 4116 AegisP (91f3df93f40a74d222cd166fe95db633) C:\WINDOWS\system32\DRIVERS\AegisP.sys 08:46:52:281 4116 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 08:46:52:281 4116 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 08:46:52:281 4116 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 08:46:52:281 4116 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 08:46:52:281 4116 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 08:46:52:281 4116 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 08:46:52:281 4116 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 08:46:52:281 4116 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 08:46:52:281 4116 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 08:46:52:281 4116 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 08:46:52:281 4116 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 08:46:52:281 4116 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 08:46:52:281 4116 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 08:46:52:281 4116 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 08:46:52:281 4116 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 08:46:52:281 4116 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 08:46:52:281 4116 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 08:46:52:281 4116 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 08:46:52:281 4116 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 08:46:52:281 4116 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 08:46:52:281 4116 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 08:46:52:281 4116 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 08:46:52:281 4116 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 08:46:52:281 4116 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 08:46:52:281 4116 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 08:46:52:281 4116 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 08:46:52:281 4116 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 08:46:52:281 4116 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 08:46:52:281 4116 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 08:46:52:281 4116 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 08:46:52:281 4116 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 08:46:52:281 4116 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 08:46:52:281 4116 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 08:46:52:281 4116 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 08:46:52:281 4116 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 08:46:52:281 4116 DCamUSBUVT (f24360ae209c8e75da51ec3becbe05df) C:\WINDOWS\system32\Drivers\usbuvt.sys 08:46:52:281 4116 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 08:46:52:281 4116 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 08:46:52:281 4116 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 08:46:52:281 4116 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 08:46:52:281 4116 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 08:46:52:281 4116 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 08:46:52:281 4116 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 08:46:52:281 4116 drvmcdb (96bc8f872f0270c10edc3931f1c03776) C:\WINDOWS\system32\drivers\drvmcdb.sys 08:46:52:281 4116 drvnddm (5afbec7a6ac61b211633dfdb1d9e0c89) C:\WINDOWS\system32\drivers\drvnddm.sys 08:46:52:281 4116 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 08:46:52:281 4116 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 08:46:52:281 4116 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 08:46:52:281 4116 F-Secure Filter (d4980588ed87f8bb16be43ddd0fbd5fe) C:\Program Files\Shaw Secure\Anti-Virus\Win2K\FSfilter.sys 08:46:52:281 4116 F-Secure Gatekeeper (1dbeb37e602d9aaf60be2f49d5247dc9) C:\Program Files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys 08:46:52:281 4116 F-Secure HIPS (f5aca65237c7511d5803cdc5e7003d75) C:\Program Files\Shaw Secure\HIPS\drivers\fshs.sys 08:46:52:281 4116 F-Secure Recognizer (6ce1195511533c9359f91a9e63792f5e) C:\Program Files\Shaw Secure\Anti-Virus\Win2K\FSrec.sys 08:46:52:281 4116 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 08:46:52:281 4116 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 08:46:52:281 4116 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 08:46:52:281 4116 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 08:46:52:281 4116 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 08:46:52:281 4116 fsbts (de7cba8a38ae0c404eb2acd08d18aa3e) C:\WINDOWS\system32\Drivers\fsbts.sys 08:46:52:281 4116 FSFW (d93e91a800af12ccb14f3ee7cd3a22a2) C:\WINDOWS\system32\drivers\fsdfw.sys 08:46:52:281 4116 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 08:46:52:281 4116 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 08:46:52:281 4116 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 08:46:52:281 4116 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 08:46:52:281 4116 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 08:46:52:281 4116 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 08:46:52:281 4116 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 08:46:52:281 4116 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 08:46:52:281 4116 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 08:46:52:281 4116 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 08:46:52:281 4116 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 08:46:52:281 4116 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 08:46:52:281 4116 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 08:46:52:281 4116 ialm (93aa9660aacb82f73d854180afd9817e) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 08:46:52:281 4116 ICAM5USB (0a8a464d0dfd3257b72792248b44fc93) C:\WINDOWS\system32\Drivers\Icam5USB.sys 08:46:52:281 4116 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 08:46:52:281 4116 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 08:46:52:281 4116 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 08:46:52:281 4116 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 08:46:52:281 4116 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 08:46:52:281 4116 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 08:46:52:281 4116 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 08:46:52:281 4116 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 08:46:52:281 4116 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 08:46:52:281 4116 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 08:46:52:281 4116 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 08:46:52:281 4116 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 08:46:52:281 4116 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys 08:46:52:281 4116 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 08:46:52:281 4116 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 08:46:52:281 4116 ManyCam (c6d085c7045200143528136a43a65fde) C:\WINDOWS\system32\DRIVERS\ManyCam.sys 08:46:52:281 4116 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 08:46:52:281 4116 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 08:46:52:281 4116 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 08:46:52:281 4116 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 08:46:52:281 4116 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 08:46:52:281 4116 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 08:46:52:281 4116 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 08:46:52:281 4116 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 08:46:52:281 4116 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 08:46:52:281 4116 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 08:46:52:281 4116 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 08:46:52:281 4116 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 08:46:52:281 4116 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 08:46:52:281 4116 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 08:46:52:281 4116 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 08:46:52:281 4116 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 08:46:52:281 4116 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 08:46:52:281 4116 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 08:46:52:281 4116 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 08:46:52:281 4116 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 08:46:52:281 4116 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 08:46:52:281 4116 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 08:46:52:281 4116 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 08:46:52:281 4116 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 08:46:52:281 4116 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 08:46:52:281 4116 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 08:46:52:281 4116 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 08:46:52:281 4116 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 08:46:52:281 4116 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 08:46:52:281 4116 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 08:46:52:281 4116 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 08:46:52:281 4116 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 08:46:52:281 4116 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 08:46:52:281 4116 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys 08:46:52:281 4116 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 08:46:52:281 4116 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 08:46:52:281 4116 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 08:46:52:281 4116 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 08:46:52:281 4116 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 08:46:52:281 4116 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 08:46:52:281 4116 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 08:46:52:281 4116 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 08:46:52:281 4116 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 08:46:52:281 4116 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 08:46:52:281 4116 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 08:46:52:281 4116 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 08:46:52:281 4116 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys 08:46:52:281 4116 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 08:46:52:281 4116 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 08:46:52:281 4116 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 08:46:52:281 4116 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 08:46:52:281 4116 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 08:46:52:281 4116 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 08:46:52:281 4116 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 08:46:52:281 4116 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 08:46:52:281 4116 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 08:46:52:281 4116 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 08:46:52:281 4116 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 08:46:52:281 4116 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 08:46:52:281 4116 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 08:46:52:281 4116 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 08:46:52:281 4116 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 08:46:52:281 4116 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 08:46:52:281 4116 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 08:46:52:281 4116 s24trans (2c0e9e777ab1849b43494626c1f308b5) C:\WINDOWS\system32\DRIVERS\s24trans.sys 08:46:52:281 4116 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 08:46:52:281 4116 SDDMI2 (8edd7b9e4a4b4c16e2dab9188caa861b) C:\WINDOWS\system32\DDMI2.sys 08:46:52:281 4116 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 08:46:52:281 4116 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 08:46:52:281 4116 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 08:46:52:281 4116 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys 08:46:52:281 4116 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys 08:46:52:281 4116 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 08:46:52:281 4116 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 08:46:52:281 4116 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 08:46:52:281 4116 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 08:46:52:281 4116 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 08:46:52:281 4116 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 08:46:52:281 4116 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys 08:46:52:281 4116 sscdbhk5 (98625722ad52b40305e74aaa83c93086) C:\WINDOWS\system32\drivers\sscdbhk5.sys 08:46:52:281 4116 ssrtln (d79412e3942c8a257253487536d5a994) C:\WINDOWS\system32\drivers\ssrtln.sys 08:46:52:281 4116 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys 08:46:52:281 4116 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 08:46:52:281 4116 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 08:46:52:281 4116 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 08:46:52:281 4116 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 08:46:52:281 4116 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 08:46:52:281 4116 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 08:46:52:281 4116 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 08:46:52:281 4116 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys 08:46:52:281 4116 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 08:46:52:281 4116 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\WINDOWS\system32\DRIVERS\taphss.sys 08:46:52:281 4116 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 08:46:52:281 4116 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 08:46:52:281 4116 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 08:46:52:281 4116 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 08:46:52:281 4116 tfsnboio (d0177776e11b0b3f272eebd262a69661) C:\WINDOWS\system32\dla\tfsnboio.sys 08:46:52:281 4116 tfsncofs (599804bc938b8305a5422319774da871) C:\WINDOWS\system32\dla\tfsncofs.sys 08:46:52:281 4116 tfsndrct (a1902c00adc11c4d83f8e3ed947a6a32) C:\WINDOWS\system32\dla\tfsndrct.sys 08:46:52:281 4116 tfsndres (d8ddb3f2b1bef15cff6728d89c042c61) C:\WINDOWS\system32\dla\tfsndres.sys 08:46:52:281 4116 tfsnifs (c4f2dea75300971cdaee311007de138d) C:\WINDOWS\system32\dla\tfsnifs.sys 08:46:52:281 4116 tfsnopio (272925be0ea919f08286d2ee6f102b0f) C:\WINDOWS\system32\dla\tfsnopio.sys 08:46:52:281 4116 tfsnpool (7b7d955e5cebc2fb88b03ef875d52a2f) C:\WINDOWS\system32\dla\tfsnpool.sys 08:46:52:281 4116 tfsnudf (e3d01263109d800c1967c12c10a0b018) C:\WINDOWS\system32\dla\tfsnudf.sys 08:46:52:281 4116 tfsnudfa (b9e9c377906e3a65bc74598fff7f7458) C:\WINDOWS\system32\dla\tfsnudfa.sys 08:46:52:281 4116 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 08:46:52:281 4116 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 08:46:52:281 4116 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 08:46:52:281 4116 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 08:46:52:281 4116 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 08:46:52:281 4116 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 08:46:52:281 4116 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 08:46:52:281 4116 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 08:46:52:281 4116 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 08:46:52:281 4116 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 08:46:52:281 4116 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 08:46:52:281 4116 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 08:46:52:281 4116 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 08:46:52:281 4116 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 08:46:52:281 4116 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 08:46:52:281 4116 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 08:46:52:281 4116 w39n51 (95c7421f8bafc85ba09d33364058937d) C:\WINDOWS\system32\DRIVERS\w39n51.sys 08:46:52:281 4116 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 08:46:52:281 4116 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 08:46:52:281 4116 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 08:46:52:281 4116 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 08:46:52:281 4116 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 08:46:52:281 4116 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 08:46:52:281 4116 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 08:46:52:281 4116 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 08:46:52:281 4116 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 08:46:52:281 4116 08:46:52:281 4116 Completed 08:46:52:281 4116 08:46:52:281 4116 Results: 08:46:52:281 4116 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 08:46:52:281 4116 File objects infected / cured / cured on reboot: 0 / 0 / 0 08:46:52:281 4116 08:46:52:281 4116 KLMD(ARK) unloaded successfully
I found the log for the TDSS killer:

TDSSKiller log:

08:46:52:281 4116 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
08:46:52:281 4116 ================================================================================
08:46:52:281 4116 SystemInfo:

08:46:52:281 4116 OS Version: 5.1.2600 ServicePack: 3.0
08:46:52:281 4116 Product type: Workstation
08:46:52:281 4116 ComputerName: TANJA
08:46:52:281 4116 UserName: mine
08:46:52:281 4116 Windows directory: C:\WINDOWS
08:46:52:281 4116 Processor architecture: Intel x86
08:46:52:281 4116 Number of processors: 2
08:46:52:281 4116 Page size: 0x1000
08:46:52:281 4116 Boot type: Normal boot
08:46:52:281 4116 ================================================================================
08:46:52:281 4116 Initialize success
08:46:52:281 4116
08:46:52:281 4116 Scanning Services …
08:46:52:281 4116 Raw services enum returned 393 services
08:46:52:281 4116
08:46:52:281 4116 Scanning Drivers …
08:46:52:281 4116 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
08:46:52:281 4116 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
08:46:52:281 4116 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
08:46:52:281 4116 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
08:46:52:281 4116 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
08:46:52:281 4116 AegisP (91f3df93f40a74d222cd166fe95db633) C:\WINDOWS\system32\DRIVERS\AegisP.sys
08:46:52:281 4116 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
08:46:52:281 4116 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
08:46:52:281 4116 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
08:46:52:281 4116 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
08:46:52:281 4116 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
08:46:52:281 4116 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
08:46:52:281 4116 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
08:46:52:281 4116 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
08:46:52:281 4116 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
08:46:52:281 4116 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
08:46:52:281 4116 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
08:46:52:281 4116 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
08:46:52:281 4116 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
08:46:52:281 4116 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
08:46:52:281 4116 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
08:46:52:281 4116 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys
08:46:52:281 4116 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
08:46:52:281 4116 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
08:46:52:281 4116 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
08:46:52:281 4116 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
08:46:52:281 4116 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
08:46:52:281 4116 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
08:46:52:281 4116 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
08:46:52:281 4116 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
08:46:52:281 4116 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
08:46:52:281 4116 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
08:46:52:281 4116 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
08:46:52:281 4116 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
08:46:52:281 4116 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
08:46:52:281 4116 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
08:46:52:281 4116 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
08:46:52:281 4116 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
08:46:52:281 4116 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
08:46:52:281 4116 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
08:46:52:281 4116 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
08:46:52:281 4116 DCamUSBUVT (f24360ae209c8e75da51ec3becbe05df) C:\WINDOWS\system32\Drivers\usbuvt.sys
08:46:52:281 4116 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
08:46:52:281 4116 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
08:46:52:281 4116 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
08:46:52:281 4116 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
08:46:52:281 4116 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
08:46:52:281 4116 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
08:46:52:281 4116 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
08:46:52:281 4116 drvmcdb (96bc8f872f0270c10edc3931f1c03776) C:\WINDOWS\system32\drivers\drvmcdb.sys
08:46:52:281 4116 drvnddm (5afbec7a6ac61b211633dfdb1d9e0c89) C:\WINDOWS\system32\drivers\drvnddm.sys
08:46:52:281 4116 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
08:46:52:281 4116 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
08:46:52:281 4116 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
08:46:52:281 4116 F-Secure Filter (d4980588ed87f8bb16be43ddd0fbd5fe) C:\Program Files\Shaw Secure\Anti-Virus\Win2K\FSfilter.sys
08:46:52:281 4116 F-Secure Gatekeeper (1dbeb37e602d9aaf60be2f49d5247dc9) C:\Program Files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys
08:46:52:281 4116 F-Secure HIPS (f5aca65237c7511d5803cdc5e7003d75) C:\Program Files\Shaw Secure\HIPS\drivers\fshs.sys
08:46:52:281 4116 F-Secure Recognizer (6ce1195511533c9359f91a9e63792f5e) C:\Program Files\Shaw Secure\Anti-Virus\Win2K\FSrec.sys
08:46:52:281 4116 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
08:46:52:281 4116 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
08:46:52:281 4116 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
08:46:52:281 4116 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
08:46:52:281 4116 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
08:46:52:281 4116 fsbts (de7cba8a38ae0c404eb2acd08d18aa3e) C:\WINDOWS\system32\Drivers\fsbts.sys
08:46:52:281 4116 FSFW (d93e91a800af12ccb14f3ee7cd3a22a2) C:\WINDOWS\system32\drivers\fsdfw.sys
08:46:52:281 4116 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
08:46:52:281 4116 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
08:46:52:281 4116 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
08:46:52:281 4116 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
08:46:52:281 4116 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
08:46:52:281 4116 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
08:46:52:281 4116 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
08:46:52:281 4116 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys
08:46:52:281 4116 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys
08:46:52:281 4116 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
08:46:52:281 4116 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
08:46:52:281 4116 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
08:46:52:281 4116 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
08:46:52:281 4116 ialm (93aa9660aacb82f73d854180afd9817e) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
08:46:52:281 4116 ICAM5USB (0a8a464d0dfd3257b72792248b44fc93) C:\WINDOWS\system32\Drivers\Icam5USB.sys
08:46:52:281 4116 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
08:46:52:281 4116 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
08:46:52:281 4116 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
08:46:52:281 4116 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
08:46:52:281 4116 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
08:46:52:281 4116 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
08:46:52:281 4116 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
08:46:52:281 4116 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
08:46:52:281 4116 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
08:46:52:281 4116 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
08:46:52:281 4116 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
08:46:52:281 4116 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
08:46:52:281 4116 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
08:46:52:281 4116 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
08:46:52:281 4116 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
08:46:52:281 4116 ManyCam (c6d085c7045200143528136a43a65fde) C:\WINDOWS\system32\DRIVERS\ManyCam.sys
08:46:52:281 4116 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
08:46:52:281 4116 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
08:46:52:281 4116 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
08:46:52:281 4116 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
08:46:52:281 4116 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
08:46:52:281 4116 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
08:46:52:281 4116 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
08:46:52:281 4116 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
08:46:52:281 4116 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
08:46:52:281 4116 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
08:46:52:281 4116 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
08:46:52:281 4116 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
08:46:52:281 4116 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
08:46:52:281 4116 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
08:46:52:281 4116 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
08:46:52:281 4116 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
08:46:52:281 4116 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
08:46:52:281 4116 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
08:46:52:281 4116 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
08:46:52:281 4116 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
08:46:52:281 4116 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
08:46:52:281 4116 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
08:46:52:281 4116 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
08:46:52:281 4116 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
08:46:52:281 4116 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
08:46:52:281 4116 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
08:46:52:281 4116 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
08:46:52:281 4116 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
08:46:52:281 4116 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
08:46:52:281 4116 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
08:46:52:281 4116 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
08:46:52:281 4116 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
08:46:52:281 4116 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
08:46:52:281 4116 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
08:46:52:281 4116 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
08:46:52:281 4116 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
08:46:52:281 4116 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
08:46:52:281 4116 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
08:46:52:281 4116 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
08:46:52:281 4116 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
08:46:52:281 4116 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
08:46:52:281 4116 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
08:46:52:281 4116 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
08:46:52:281 4116 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
08:46:52:281 4116 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
08:46:52:281 4116 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
08:46:52:281 4116 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys
08:46:52:281 4116 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
08:46:52:281 4116 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
08:46:52:281 4116 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
08:46:52:281 4116 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
08:46:52:281 4116 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
08:46:52:281 4116 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
08:46:52:281 4116 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
08:46:52:281 4116 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
08:46:52:281 4116 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
08:46:52:281 4116 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
08:46:52:281 4116 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
08:46:52:281 4116 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
08:46:52:281 4116 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
08:46:52:281 4116 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
08:46:52:281 4116 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
08:46:52:281 4116 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
08:46:52:281 4116 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
08:46:52:281 4116 s24trans (2c0e9e777ab1849b43494626c1f308b5) C:\WINDOWS\system32\DRIVERS\s24trans.sys
08:46:52:281 4116 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
08:46:52:281 4116 SDDMI2 (8edd7b9e4a4b4c16e2dab9188caa861b) C:\WINDOWS\system32\DDMI2.sys
08:46:52:281 4116 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
08:46:52:281 4116 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
08:46:52:281 4116 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
08:46:52:281 4116 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
08:46:52:281 4116 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
08:46:52:281 4116 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
08:46:52:281 4116 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
08:46:52:281 4116 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
08:46:52:281 4116 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
08:46:52:281 4116 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
08:46:52:281 4116 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
08:46:52:281 4116 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys
08:46:52:281 4116 sscdbhk5 (98625722ad52b40305e74aaa83c93086) C:\WINDOWS\system32\drivers\sscdbhk5.sys
08:46:52:281 4116 ssrtln (d79412e3942c8a257253487536d5a994) C:\WINDOWS\system32\drivers\ssrtln.sys
08:46:52:281 4116 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys
08:46:52:281 4116 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
08:46:52:281 4116 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
08:46:52:281 4116 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
08:46:52:281 4116 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
08:46:52:281 4116 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
08:46:52:281 4116 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
08:46:52:281 4116 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
08:46:52:281 4116 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys
08:46:52:281 4116 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
08:46:52:281 4116 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\WINDOWS\system32\DRIVERS\taphss.sys
08:46:52:281 4116 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
08:46:52:281 4116 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
08:46:52:281 4116 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
08:46:52:281 4116 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
08:46:52:281 4116 tfsnboio (d0177776e11b0b3f272eebd262a69661) C:\WINDOWS\system32\dla\tfsnboio.sys
08:46:52:281 4116 tfsncofs (599804bc938b8305a5422319774da871) C:\WINDOWS\system32\dla\tfsncofs.sys
08:46:52:281 4116 tfsndrct (a1902c00adc11c4d83f8e3ed947a6a32) C:\WINDOWS\system32\dla\tfsndrct.sys
08:46:52:281 4116 tfsndres (d8ddb3f2b1bef15cff6728d89c042c61) C:\WINDOWS\system32\dla\tfsndres.sys
08:46:52:281 4116 tfsnifs (c4f2dea75300971cdaee311007de138d) C:\WINDOWS\system32\dla\tfsnifs.sys
08:46:52:281 4116 tfsnopio (272925be0ea919f08286d2ee6f102b0f) C:\WINDOWS\system32\dla\tfsnopio.sys
08:46:52:281 4116 tfsnpool (7b7d955e5cebc2fb88b03ef875d52a2f) C:\WINDOWS\system32\dla\tfsnpool.sys
08:46:52:281 4116 tfsnudf (e3d01263109d800c1967c12c10a0b018) C:\WINDOWS\system32\dla\tfsnudf.sys
08:46:52:281 4116 tfsnudfa (b9e9c377906e3a65bc74598fff7f7458) C:\WINDOWS\system32\dla\tfsnudfa.sys
08:46:52:281 4116 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
08:46:52:281 4116 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
08:46:52:281 4116 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
08:46:52:281 4116 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
08:46:52:281 4116 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
08:46:52:281 4116 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
08:46:52:281 4116 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
08:46:52:281 4116 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
08:46:52:281 4116 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
08:46:52:281 4116 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
08:46:52:281 4116 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
08:46:52:281 4116 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
08:46:52:281 4116 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
08:46:52:281 4116 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
08:46:52:281 4116 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
08:46:52:281 4116 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
08:46:52:281 4116 w39n51 (95c7421f8bafc85ba09d33364058937d) C:\WINDOWS\system32\DRIVERS\w39n51.sys
08:46:52:281 4116 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
08:46:52:281 4116 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
08:46:52:281 4116 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys
08:46:52:281 4116 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
08:46:52:281 4116 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
08:46:52:281 4116 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
08:46:52:281 4116 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
08:46:52:281 4116 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
08:46:52:281 4116 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
08:46:52:281 4116
08:46:52:281 4116 Completed
08:46:52:281 4116
08:46:52:281 4116 Results:
08:46:52:281 4116 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
08:46:52:281 4116 File objects infected / cured / cured on reboot: 0 / 0 / 0
08:46:52:281 4116
08:46:52:281 4116 KLMD(ARK) unloaded successfully






here is the HAMeb log:

C:\Documents and Settings\mine\Desktop\HAMeb_check.exe
21/06/2010 at 10:29:31.09

Account active Yes
Local Group Memberships *Administrators

~~ Checking profile list ~~

S-1-5-21-789029489-1268896404-705703666-1005
%SystemDrive%\Documents and Settings\HelpAssistant

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85E4278A]<<
kernel: MBR read successfully
copy of MBR has been found in sector 0x0B77F389
malicious code @ sector 0x0B77F38C !
PE file found in sector at 0x0B77F3A2 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

~~ Checking for termsrv32.dll ~~

termsrv32.dll present!


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv32.dll

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"65533:TCP"=65533:TCP:*:Enabled:Services
"52344:TCP"=52344:TCP:*:Enabled:Services
"2519:TCP"=2519:TCP:*:Enabled:Services
"3538:TCP"=3538:TCP:*:Enabled:Services
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop
"3467:TCP"=3467:TCP:*:Enabled:Services
"5434:TCP"=5434:TCP:*:Enabled:Services
"6106:TCP"=6106:TCP:*:Enabled:Services
"6107:TCP"=6107:TCP:*:Enabled:Services
"5435:TCP"=5435:TCP:*:Enabled:Services
"9370:TCP"=9370:TCP:*:Enabled:Services
"9003:TCP"=9003:TCP:*:Enabled:Services
"9004:TCP"=9004:TCP:*:Enabled:Services

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=65533:TCP:*:Enabled:Services
"52344:TCP"=52344:TCP:*:Enabled:Services
"2519:TCP"=2519:TCP:*:Enabled:Services
"3538:TCP"=3538:TCP:*:Enabled:Services
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop
"5434:TCP"=5434:TCP:*:Enabled:Services
"3467:TCP"=3467:TCP:*:Enabled:Services
"6106:TCP"=6106:TCP:*:Enabled:Services
"6107:TCP"=6107:TCP:*:Enabled:Services
"5435:TCP"=5435:TCP:*:Enabled:Services
"9370:TCP"=9370:TCP:*:Enabled:Services
"9003:TCP"=9003:TCP:*:Enabled:Services
"9004:TCP"=9004:TCP:*:Enabled:Services


~~ EOF ~~
Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
Close out all other open programs and windows.
Double click the file to run it and follow any prompts.
If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !
When it completes, a log will open.
Please post the contents of that log.
Hi, Here is the Helpasst log:


C:\Documents and Settings\mine\Desktop\HelpAsst_mebroot_fix.exe
21/06/2010 at 20:06:28.32

HelpAssistant account Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
termsrv32.dll successfully removed

~~ Checking firewall ports ~~

backing up DomainProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
"3389:TCP"=-
"65533:TCP"=-
"52344:TCP"=-
"9004:TCP"=-
"9003:TCP"=-

backing up StandardProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
"3389:TCP"=-
"65533:TCP"=-
"52344:TCP"=-
"9004:TCP"=-
"9003:TCP"=-

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking mbr ~~

mbr infection detected! ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
copy of MBR has been found in sector 0x0B77F389
malicious code @ sector 0x0B77F38C !
PE file found in sector at 0x0B77F3A2 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x0B77F389
malicious code @ sector 0x0B77F38C !
PE file found in sector at 0x0B77F3A2 !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 21/06/2010 at 20:52:28.14

Account active Yes
Local Group Memberships *Administrators

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x0B77F389
malicious code @ sector 0x0B77F38C !
PE file found in sector at 0x0B77F3A2 !

~~ Checking for termsrv32.dll ~~

termsrv32.dll present!


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv32.dll

~~ Checking profile list ~~

S-1-5-21-789029489-1268896404-705703666-1005
%SystemDrive%\Documents and Settings\HelpAssistant.TANJA

~~ Checking for HelpAssistant directories ~~

HelpAssistant
HelpAssistant.TANJA

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop


~~ EOF ~~
Looking good.

Please click Start>Run and type (or copy and paste it) the following bolded command then hit Enter.

helpasst -cleanup

After the above please run a new Combofix scan and post the results.
Hi, heres the combofix log after the helpasst cleanup



ComboFix 10-06-22.01 - mine 22/06/2010 12:28:28.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.570 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Shaw Secure 9.01 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 9.01 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

((((((((((((((((((((((((( Files Created from 2010-05-22 to 2010-06-22 )))))))))))))))))))))))))))))))
.

2020-01-25 04:49 . 2020-01-25 04:49 ——– d—–w- c:\windows\Paltalk Messenger
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- C:\88058f1f4ec15c490d
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- c:\documents and settings\mine\Application Data\SlySoft
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(3)
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\mine\Application Data\Intel(3)
2010-10-13 00:50 . 2009-05-24 15:54 ——– d—–w- c:\program files\SlySoft
2010-06-21 00:41 . 2010-06-21 00:41 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-19 23:14 . 2010-06-19 23:14 ——– d—–w- c:\documents and settings\mine\Application Data\Malwarebytes
2010-06-19 23:13 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 23:13 . 2010-06-19 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 23:12 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-19 23:12 . 2010-06-19 23:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-18 20:05 . 2010-06-19 22:49 0 —-a-w- c:\windows\Mpovegizutazeti.bin
2010-06-18 20:05 . 2010-06-19 22:47 120 —-a-w- c:\windows\Eyubuzimocine.dat
2010-06-18 15:33 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\WINDOWS
2010-06-18 15:33 . 2010-06-20 00:06 ——– d—–w- c:\documents and settings\HelpAssistant\Tracing
2010-06-18 15:33 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-06-18 15:32 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\Shared
2010-06-18 15:32 . 2010-06-20 00:05 ——– d—–w- c:\documents and settings\HelpAssistant\PrivacIE
2010-06-17 05:51 . 2010-06-21 00:52 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 04:50 . 2010-06-22 01:27 ——– d—–w- c:\documents and settings\HelpAssistant
2010-06-10 18:05 . 2010-06-10 18:05 ——– d—–w- C:\ProgramData (x86)
2010-06-10 03:01 . 2010-06-10 03:01 ——– d—–w- c:\program files\ISO Image Burner
2010-06-10 02:03 . 2010-06-10 02:03 ——– d—–w- c:\program files\uTorrent
2010-06-10 02:03 . 2010-06-10 23:45 ——– d—–w- c:\documents and settings\mine\Application Data\uTorrent
2010-06-10 00:46 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 03:38 . 2010-05-30 03:38 ——– d—–w- c:\documents and settings\mine\dwhelper
2010-05-30 00:50 . 2010-01-30 17:48 266552 —-a-w- c:\windows\system32\HMIPCore.dll
2010-05-30 00:15 . 2010-05-30 01:07 ——– d—–w- C:\Hotspot Shield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2020-01-25 04:49 . 2007-01-13 07:54 ——– d—–w- c:\program files\Windows Media Connect 2
2020-01-25 04:48 . 2007-01-05 03:54 ——– d—–w- c:\program files\Replay Converter
2020-01-25 04:47 . 2006-12-17 23:12 ——– d—–w- c:\program files\Windows Defender
2020-01-25 04:24 . 2006-12-17 23:30 ——– d—–w- c:\program files\Ahead
2010-06-19 23:15 . 2010-06-20 00:05 0 —-a-w- c:\documents and settings\HelpAssistant\ntuser.tmp
2010-06-13 08:45 . 2007-03-11 22:41 ——– d—–w- c:\documents and settings\mine\Application Data\Skype
2010-06-12 06:15 . 2010-01-24 03:28 ——– d—–w- c:\program files\Google
2010-06-04 23:54 . 2009-08-01 06:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-28 19:40 . 2010-05-28 19:40 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcp71.dll
2010-05-28 19:40 . 2010-05-28 19:40 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\jmc.dll
2010-05-28 19:40 . 2010-05-28 19:40 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcr71.dll
2010-05-28 19:40 . 2010-05-28 19:40 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-sse.dll
2010-05-28 19:40 . 2010-05-28 19:40 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-d3d.dll
2010-05-21 20:14 . 2009-10-03 15:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-14 18:56 . 2006-04-23 07:52 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-14 00:30 . 2006-03-24 18:36 ——– d—–w- c:\program files\Java
2010-05-13 22:05 . 2010-05-13 22:05 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_D3DD076B988600E59BFD1E.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_CA1D36A8BD7C6E8B327132.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_A17D378A7C093FF2005726.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_6FEFF9B68218417F98F549.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_67DB1B8F6A28368D658316.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_64E749EF31745C29AAF314.exe
2010-05-11 02:28 . 2010-05-11 02:28 ——– d—–w- c:\program files\FriendFinder
2010-05-07 18:55 . 2010-05-07 18:55 255472 —-a-w- c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-05-06 10:41 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 18:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 18:50 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 23:29 . 2010-05-14 00:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-31 08:05 . 2010-03-31 08:05 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcp71.dll
2010-03-31 08:05 . 2010-03-31 08:05 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\jmc.dll
2010-03-31 08:05 . 2010-03-31 08:05 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcr71.dll
2010-03-31 08:05 . 2010-03-31 08:05 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-sse.dll
2010-03-31 08:05 . 2010-03-31 08:05 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-d3d.dll
2010-03-30 16:33 . 2008-11-12 22:14 33920 —-a-w- c:\windows\system32\drivers\fsbts.sys
2004-10-01 21:00 . 2006-12-17 22:44 40960 —-a-w- c:\program files\UNINSTALL_CDS.0XE
2009-07-26 22:06 . 2006-04-07 12:13 104 –sh–r- c:\windows\system32\38C8C11354.sys
2009-07-26 22:06 . 2006-04-07 12:13 4600 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5ba73b24-4614-4d17-b58e-0d9d95847e14}"= "c:\program files\AIR MILES TOOLBAR\Helper.dll" [2009-05-11 219648]

[HKEY_CLASSES_ROOT\clsid\{5ba73b24-4614-4d17-b58e-0d9d95847e14}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{DF11073E-3AFF-410F-9AC8-72459F32C80F}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{169A78DB-CFC2-4DA4-A9BD-A67B28D41FA7}]
2009-05-11 22:54 1292288 ——w- c:\program files\AIR MILES TOOLBAR\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-08 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-03-24 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"News Service"="c:\program files\Shaw Secure\FSGUI\ispnews.exe" [2005-05-31 356352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-08-05 199264]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\LIvVE\\System\\mIC.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\mine\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [12/11/2008 4:14 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [27/04/2007 11:03 PM 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [12/11/2008 4:04 PM 68064]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [27/04/2007 11:45 PM 113864]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [12/11/2008 4:04 PM 55992]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 4:06 AM 21632]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [06/06/2008 9:17 AM 95232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [27/04/2007 11:03 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [27/04/2007 11:03 PM 25184]
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006Core.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006UA.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/ig?hl=en
mWindow Title = Internet Explorer Provided by SHAW Internet
mSearch Bar = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://ca.search.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {1E3F888F-96D7-4A1B-8514-8991264E8B7D} - hxxp://www.pc.gc.ca/apps/dci/source/bin/iS3DCtrl.cab
DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} - hxxp://www.3dvista.com/downloads/viewer3dv.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&p=
FF - component: c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}\components\Engine.dll
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\documents and settings\mine\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\mine\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-22 12:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(704)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'explorer.exe'(3128)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(624)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
Completion time: 2010-06-22 12:49:51
ComboFix-quarantined-files.txt 2010-06-22 18:49
ComboFix2.txt 2010-06-21 02:07
ComboFix3.txt 2010-06-20 09:19
ComboFix4.txt 2007-02-03 19:38

Pre-Run: 56,749,060,096 bytes free
Post-Run: 56,730,509,312 bytes free

- - End Of File - - CC2A3B6C705349F306C6F01B870B78F8
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\windows\Mpovegizutazeti.bin
c:\windows\Eyubuzimocine.dat
c:\documents and settings\HelpAssistant\WINDOWS
c:\documents and settings\HelpAssistant\Tracing
c:\documents and settings\HelpAssistant\UserData
c:\documents and settings\HelpAssistant\Shared
c:\documents and settings\HelpAssistant\PrivacIE
c:\documents and settings\HelpAssistant\ntuser.tmp

Folder::
c:\documents and settings\HelpAssistant

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"=-
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv32.dll]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
after I drag the CFScript file into combo fix, it tells me there is a new version of combofix available, should I allow the update?

after I drag the CFScript file into combo fix, it tells me there is a new version of combofix available, should I allow the update?

Yes
Hi here is the current combofix log:

also , comp seems to be running fairly good, still hangs a little bit when opening aps tho',not sure why.


ComboFix 10-06-22.03 - mine 23/06/2010 9:28.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.518 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mine\Desktop\CFScript.txt
AV: Shaw Secure 9.01 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 9.01 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}

FILE ::
"c:\documents and settings\HelpAssistant\ntuser.tmp"
"c:\documents and settings\HelpAssistant\PrivacIE"
"c:\documents and settings\HelpAssistant\Shared"
"c:\documents and settings\HelpAssistant\Tracing"
"c:\documents and settings\HelpAssistant\UserData"
"c:\documents and settings\HelpAssistant\WINDOWS"
"c:\windows\Eyubuzimocine.dat"
"c:\windows\Mpovegizutazeti.bin"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HelpAssistant\ntuser.tmp
c:\windows\Eyubuzimocine.dat
c:\windows\Mpovegizutazeti.bin

.
((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
.

2020-01-25 04:49 . 2020-01-25 04:49 ——– d—–w- c:\windows\Paltalk Messenger
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- C:\88058f1f4ec15c490d
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- c:\documents and settings\mine\Application Data\SlySoft
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(3)
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\mine\Application Data\Intel(3)
2010-10-13 00:50 . 2009-05-24 15:54 ——– d—–w- c:\program files\SlySoft
2010-06-21 00:41 . 2010-06-21 00:41 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-19 23:14 . 2010-06-19 23:14 ——– d—–w- c:\documents and settings\mine\Application Data\Malwarebytes
2010-06-19 23:13 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 23:13 . 2010-06-19 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 23:12 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-19 23:12 . 2010-06-19 23:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-18 15:33 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\WINDOWS
2010-06-18 15:33 . 2010-06-20 00:06 ——– d—–w- c:\documents and settings\HelpAssistant\Tracing
2010-06-18 15:33 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-06-18 15:32 . 2010-06-18 15:33 ——– d—–w- c:\documents and settings\HelpAssistant\Shared
2010-06-18 15:32 . 2010-06-20 00:05 ——– d—–w- c:\documents and settings\HelpAssistant\PrivacIE
2010-06-17 05:51 . 2010-06-21 00:52 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 04:50 . 2010-06-23 15:36 ——– d—–w- c:\documents and settings\HelpAssistant
2010-06-10 18:05 . 2010-06-10 18:05 ——– d—–w- C:\ProgramData (x86)
2010-06-10 03:01 . 2010-06-10 03:01 ——– d—–w- c:\program files\ISO Image Burner
2010-06-10 02:03 . 2010-06-10 02:03 ——– d—–w- c:\program files\uTorrent
2010-06-10 02:03 . 2010-06-10 23:45 ——– d—–w- c:\documents and settings\mine\Application Data\uTorrent
2010-06-10 00:46 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 03:38 . 2010-05-30 03:38 ——– d—–w- c:\documents and settings\mine\dwhelper
2010-05-30 00:50 . 2010-01-30 17:48 266552 —-a-w- c:\windows\system32\HMIPCore.dll
2010-05-30 00:15 . 2010-05-30 01:07 ——– d—–w- C:\Hotspot Shield
2010-05-28 19:40 . 2010-05-28 19:40 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcp71.dll
2010-05-28 19:40 . 2010-05-28 19:40 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\jmc.dll
2010-05-28 19:40 . 2010-05-28 19:40 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcr71.dll
2010-05-28 19:40 . 2010-05-28 19:40 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-sse.dll
2010-05-28 19:40 . 2010-05-28 19:40 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2020-01-25 04:49 . 2007-01-13 07:54 ——– d—–w- c:\program files\Windows Media Connect 2
2020-01-25 04:48 . 2007-01-05 03:54 ——– d—–w- c:\program files\Replay Converter
2020-01-25 04:47 . 2006-12-17 23:12 ——– d—–w- c:\program files\Windows Defender
2020-01-25 04:24 . 2006-12-17 23:30 ——– d—–w- c:\program files\Ahead
2010-06-13 08:45 . 2007-03-11 22:41 ——– d—–w- c:\documents and settings\mine\Application Data\Skype
2010-06-12 06:15 . 2010-01-24 03:28 ——– d—–w- c:\program files\Google
2010-06-04 23:54 . 2009-08-01 06:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-21 20:14 . 2009-10-03 15:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-14 18:56 . 2006-04-23 07:52 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-14 00:30 . 2006-03-24 18:36 ——– d—–w- c:\program files\Java
2010-05-13 22:05 . 2010-05-13 22:05 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_D3DD076B988600E59BFD1E.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_CA1D36A8BD7C6E8B327132.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_A17D378A7C093FF2005726.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_6FEFF9B68218417F98F549.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_67DB1B8F6A28368D658316.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_64E749EF31745C29AAF314.exe
2010-05-11 02:28 . 2010-05-11 02:28 ——– d—–w- c:\program files\FriendFinder
2010-05-07 18:55 . 2010-05-07 18:55 255472 —-a-w- c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-05-06 10:41 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 18:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 18:50 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 23:29 . 2010-05-14 00:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-31 08:05 . 2010-03-31 08:05 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcp71.dll
2010-03-31 08:05 . 2010-03-31 08:05 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\jmc.dll
2010-03-31 08:05 . 2010-03-31 08:05 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcr71.dll
2010-03-31 08:05 . 2010-03-31 08:05 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-sse.dll
2010-03-31 08:05 . 2010-03-31 08:05 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-d3d.dll
2010-03-31 06:16 . 2010-03-31 06:16 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 06:10 . 2010-03-31 06:10 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2010-03-30 16:33 . 2008-11-12 22:14 33920 —-a-w- c:\windows\system32\drivers\fsbts.sys
2004-10-01 21:00 . 2006-12-17 22:44 40960 —-a-w- c:\program files\UNINSTALL_CDS.0XE
2009-07-26 22:06 . 2006-04-07 12:13 104 –sh–r- c:\windows\system32\38C8C11354.sys
2009-07-26 22:06 . 2006-04-07 12:13 4600 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-06-22_18.43.19 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-10 18:51 . 2010-06-10 14:47 75962 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:51 . 2010-06-23 09:04 75962 c:\windows\system32\perfc009.dat
+ 2009-11-07 07:07 . 2009-11-07 07:07 49488 c:\windows\system32\netfxperf.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 13664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2009-11-07 07:07 . 2009-11-07 07:07 86864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2010-06-23 09:08 . 2010-06-23 09:08 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
+ 2010-06-23 15:31 . 2010-06-23 15:31 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
+ 2010-06-23 09:07 . 2010-06-23 09:07 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
+ 2010-06-23 09:06 . 2010-06-23 09:06 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
- 2010-06-10 14:46 . 2010-06-10 14:46 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2004-08-10 18:51 . 2010-06-23 09:04 452628 c:\windows\system32\perfh009.dat
- 2004-08-10 18:51 . 2010-06-10 14:47 452628 c:\windows\system32\perfh009.dat
+ 2009-11-07 07:07 . 2009-11-07 07:07 297808 c:\windows\system32\mscoree.dll
+ 2010-03-31 06:16 . 2010-03-31 06:16 130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3a9fac9aea3ad913781fafbdcbb0cae\WindowsFormsIntegration.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\4131a3627fec69291dbaed236f30dc65\UIAutomationClient.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a10c2c7e38291c3ada631ad13e762818\PresentationFramework.Aero.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bef0992fb684e71dbfab5c0a99316af\PresentationFramework.Classic.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2f6687d394813d760496f60acf046384\PresentationFramework.Royale.ni.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2009-11-07 07:06 . 2009-11-07 07:06 1130824 c:\windows\system32\dfshim.dll
+ 2009-11-09 06:25 . 2009-11-09 06:25 1935360 c:\windows\Installer\67cab50.msp
+ 2010-06-23 09:06 . 2010-06-23 09:06 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\d8549ce90b26cdc3071224ab6f020189\UIAutomationClientsideProviders.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\af217ef58e5558991f331d482c2bdba6\System.Printing.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll
+ 2010-06-23 09:08 . 2010-06-23 09:08 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll
+ 2010-06-23 09:05 . 2010-06-23 09:05 1249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-06-23 09:05 . 2010-06-23 09:05 5279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2010-06-23 09:03 . 2010-06-23 09:03 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-06-10 14:46 . 2010-06-10 14:46 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2010-06-23 09:05 . 2010-06-23 09:05 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2009-08-18 13:45 . 2009-08-18 13:45 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2010-06-23 09:04 . 2010-06-23 09:04 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
- 2010-06-10 14:45 . 2010-06-10 14:45 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2010-03-31 07:23 . 2010-03-31 07:23 15638528 c:\windows\Installer\67cab5c.msp
+ 2010-06-23 09:08 . 2010-06-23 09:08 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll
+ 2010-06-23 09:07 . 2010-06-23 09:07 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5ba73b24-4614-4d17-b58e-0d9d95847e14}"= "c:\program files\AIR MILES TOOLBAR\Helper.dll" [2009-05-11 219648]

[HKEY_CLASSES_ROOT\clsid\{5ba73b24-4614-4d17-b58e-0d9d95847e14}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{DF11073E-3AFF-410F-9AC8-72459F32C80F}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{169A78DB-CFC2-4DA4-A9BD-A67B28D41FA7}]
2009-05-11 22:54 1292288 ——w- c:\program files\AIR MILES TOOLBAR\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-08 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-03-24 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"News Service"="c:\program files\Shaw Secure\FSGUI\ispnews.exe" [2005-05-31 356352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-08-05 199264]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\LIvVE\\System\\mIC.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\mine\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [12/11/2008 4:14 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [27/04/2007 11:03 PM 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [12/11/2008 4:04 PM 68064]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [27/04/2007 11:45 PM 113864]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [12/11/2008 4:04 PM 55992]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 4:06 AM 21632]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [06/06/2008 9:17 AM 95232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [27/04/2007 11:03 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [27/04/2007 11:03 PM 25184]
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006Core.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006UA.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/ig?hl=en
mWindow Title = Internet Explorer Provided by SHAW Internet
mSearch Bar = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://ca.search.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {1E3F888F-96D7-4A1B-8514-8991264E8B7D} - hxxp://www.pc.gc.ca/apps/dci/source/bin/iS3DCtrl.cab
DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} - hxxp://www.3dvista.com/downloads/viewer3dv.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&p=
FF - component: c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}\components\Engine.dll
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\documents and settings\mine\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\mine\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 09:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(704)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'csrss.exe'(624)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
Completion time: 2010-06-23 09:41:10
ComboFix-quarantined-files.txt 2010-06-23 15:41
ComboFix2.txt 2010-06-22 18:49
ComboFix3.txt 2010-06-21 02:07
ComboFix4.txt 2010-06-20 09:19
ComboFix5.txt 2010-06-23 15:23

Pre-Run: 56,520,335,360 bytes free
Post-Run: 56,516,173,824 bytes free

- - End Of File - - E9684D1F416AF440C6906856EF6D5C56
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Folder::
c:\documents and settings\HelpAssistant\WINDOWS
c:\documents and settings\HelpAssistant\Tracing
c:\documents and settings\HelpAssistant\UserData
c:\documents and settings\HelpAssistant\Shared
c:\documents and settings\HelpAssistant\PrivacIE
c:\documents and settings\HelpAssistant

Driver::


Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"=-

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
next combofix log:


ComboFix 10-06-23.01 - mine 23/06/2010 13:43:22.7.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.515 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mine\Desktop\CFScript.txt
AV: Shaw Secure 9.01 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 9.01 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HelpAssistant\PrivacIE
c:\documents and settings\HelpAssistant\PrivacIE\index.dat
c:\documents and settings\HelpAssistant\Shared
c:\documents and settings\HelpAssistant\Shared\Abba\AlbumArt_{7A48D370-0018-4463-B394-2EE4A3E91809}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Abba\AlbumArt_{7A48D370-0018-4463-B394-2EE4A3E91809}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Abba\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Abba\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Abba\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{0ABE881C-29CC-418A-AE13-F99109B4F43C}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{0ABE881C-29CC-418A-AE13-F99109B4F43C}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{3EC5F80D-07C7-4FB9-9D4A-C1BBB78EA112}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{3EC5F80D-07C7-4FB9-9D4A-C1BBB78EA112}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{9AD1A000-B27B-4882-AF35-FBCE87DE8935}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{9AD1A000-B27B-4882-AF35-FBCE87DE8935}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{B44A7213-3783-41A0-9E2D-D851FF5C1479}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{B44A7213-3783-41A0-9E2D-D851FF5C1479}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{D1DEF5A0-1FA2-4676-A817-FE09C96CDE0A}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArt_{D1DEF5A0-1FA2-4676-A817-FE09C96CDE0A}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\BeeGees\AlbumArt_{1417E2E6-AFF2-40B9-9B1B-B823001DF217}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\BeeGees\AlbumArt_{1417E2E6-AFF2-40B9-9B1B-B823001DF217}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\BeeGees\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\BeeGees\desktop.ini
c:\documents and settings\HelpAssistant\Shared\BeeGees\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Ben Harper\AlbumArt_{58745C4F-9206-4A3C-BA24-EC812BCEB385}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Ben Harper\AlbumArt_{58745C4F-9206-4A3C-BA24-EC812BCEB385}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Ben Harper\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Ben Harper\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Ben Harper\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Bruce Springsteen\AlbumArt_{7E3B913B-833C-413A-ABA2-D2022853BEAD}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Bruce Springsteen\AlbumArt_{7E3B913B-833C-413A-ABA2-D2022853BEAD}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Bruce Springsteen\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Bruce Springsteen\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Bruce Springsteen\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\city and color\AlbumArt_{00000000-0000-0000-0000-000000000000}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\city and color\AlbumArt_{00000000-0000-0000-0000-000000000000}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\city and color\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\city and color\desktop.ini
c:\documents and settings\HelpAssistant\Shared\city and color\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\colbie caillat\AlbumArt_{220C5316-8163-4035-9A79-AE3F5E448747}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\colbie caillat\AlbumArt_{220C5316-8163-4035-9A79-AE3F5E448747}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\colbie caillat\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\colbie caillat\desktop.ini
c:\documents and settings\HelpAssistant\Shared\colbie caillat\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\collin james\AlbumArt_{2BC7B36D-B837-4F68-B8F8-E9DB1334D9A0}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\collin james\AlbumArt_{2BC7B36D-B837-4F68-B8F8-E9DB1334D9A0}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\collin james\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\collin james\desktop.ini
c:\documents and settings\HelpAssistant\Shared\collin james\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Funnies n movie quotes\Cheech & Chong - From Dusk Till Dawn ###### Speech.mp3
c:\documents and settings\HelpAssistant\Shared\Funnies n movie quotes\Movie Quotes - Snatch - Franky Four Fingers.mp3
c:\documents and settings\HelpAssistant\Shared\Funnies n movie quotes\Simpsons - Homer's Thoughts on Gays.mp3
c:\documents and settings\HelpAssistant\Shared\Headstones\AlbumArt_{A95DB3A7-61AF-41F4-9558-81DA1F0C5714}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Headstones\AlbumArt_{A95DB3A7-61AF-41F4-9558-81DA1F0C5714}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Headstones\AlbumArt_{E2D60856-3B94-456E-9D7A-411EF6673EE5}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Headstones\AlbumArt_{E2D60856-3B94-456E-9D7A-411EF6673EE5}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Headstones\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Headstones\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Headstones\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\hedley\AlbumArt_{ABD50DEE-82CC-4F5B-8FE4-847D026C150C}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\hedley\AlbumArt_{ABD50DEE-82CC-4F5B-8FE4-847D026C150C}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\hedley\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\hedley\desktop.ini
c:\documents and settings\HelpAssistant\Shared\hedley\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\hoobstank\AlbumArt_{EDA3C930-2305-43EE-AA04-1A33545FEA8A}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\hoobstank\AlbumArt_{EDA3C930-2305-43EE-AA04-1A33545FEA8A}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\hoobstank\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\hoobstank\desktop.ini
c:\documents and settings\HelpAssistant\Shared\hoobstank\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Idle Sons\AlbumArt_{C0E50234-D4FA-48BD-9E62-792A539BF60E}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Idle Sons\AlbumArt_{C0E50234-D4FA-48BD-9E62-792A539BF60E}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Idle Sons\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Idle Sons\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Idle Sons\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\AlbumArt_{CA37FB1E-A581-41CE-928E-E1221B465430}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\AlbumArt_{CA37FB1E-A581-41CE-928E-E1221B465430}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\Iron & Wine - Sunset Soon Forgotten (Bonnaroo 05).mp3
c:\documents and settings\HelpAssistant\Shared\Iron & Wine\Iron & Wine - Woman King (Bonnaroo 05).mp3
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{16370D82-1E07-4231-8EED-B7906FE5808F}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{16370D82-1E07-4231-8EED-B7906FE5808F}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{3719D521-EA91-4010-8CA3-F67B84AA22DA}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{3719D521-EA91-4010-8CA3-F67B84AA22DA}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{5B42ADA4-F4DA-4BBF-BB8C-9F035C71D301}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{5B42ADA4-F4DA-4BBF-BB8C-9F035C71D301}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{810C1D6B-7AE6-4C17-BF48-C0CD6CAA434F}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{810C1D6B-7AE6-4C17-BF48-C0CD6CAA434F}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{EE9D5B64-BE8B-4F14-8BB7-6664A44BD568}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArt_{EE9D5B64-BE8B-4F14-8BB7-6664A44BD568}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\desktop.ini
c:\documents and settings\HelpAssistant\Shared\jack johnson songs to disc\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Jackson Browne\AlbumArt_{3BACB48B-A5B7-4075-8F23-393B66D9BCF9}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Jackson Browne\AlbumArt_{3BACB48B-A5B7-4075-8F23-393B66D9BCF9}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Jackson Browne\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Jackson Browne\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Jackson Browne\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\John Mayer\AlbumArt_{D6CCF8DC-ECAD-46C7-B1DF-EB9DB71FEB5A}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\John Mayer\AlbumArt_{D6CCF8DC-ECAD-46C7-B1DF-EB9DB71FEB5A}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\John Mayer\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\John Mayer\desktop.ini
c:\documents and settings\HelpAssistant\Shared\John Mayer\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{039FDA74-793F-434C-98BB-302EFCCB6BB5}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{039FDA74-793F-434C-98BB-302EFCCB6BB5}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{69D5840C-6CBE-4580-AA4C-B0064DC83AE8}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{69D5840C-6CBE-4580-AA4C-B0064DC83AE8}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{C9B72F78-BC42-40E9-AE85-C721DC81DDB7}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{C9B72F78-BC42-40E9-AE85-C721DC81DDB7}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{F2CEA05E-7DB1-4FBB-89C2-1DECE24A0D90}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArt_{F2CEA05E-7DB1-4FBB-89C2-1DECE24A0D90}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Nora Jones\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Nora Jones\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Red Hot Chilli Peppers\AlbumArt_{FEB4DC54-F7E6-4EB7-9798-E267C3BF183C}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Red Hot Chilli Peppers\AlbumArt_{FEB4DC54-F7E6-4EB7-9798-E267C3BF183C}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Red Hot Chilli Peppers\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Red Hot Chilli Peppers\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Red Hot Chilli Peppers\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Serena Ryder\AlbumArt_{29CE1904-BBA8-4FF4-8355-D1A7C4560B5A}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Serena Ryder\AlbumArt_{29CE1904-BBA8-4FF4-8355-D1A7C4560B5A}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Serena Ryder\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Serena Ryder\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Serena Ryder\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Snow Patrol\AlbumArt_{2FE16BBC-27AF-437F-AC7A-482F64BB0F6C}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\Snow Patrol\AlbumArt_{2FE16BBC-27AF-437F-AC7A-482F64BB0F6C}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\Snow Patrol\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\Snow Patrol\desktop.ini
c:\documents and settings\HelpAssistant\Shared\Snow Patrol\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\The Commitments\AlbumArt_{D93F8CFF-DA86-4247-959C-A9084DCAF178}_Large.jpg
c:\documents and settings\HelpAssistant\Shared\The Commitments\AlbumArt_{D93F8CFF-DA86-4247-959C-A9084DCAF178}_Small.jpg
c:\documents and settings\HelpAssistant\Shared\The Commitments\AlbumArtSmall.jpg
c:\documents and settings\HelpAssistant\Shared\The Commitments\desktop.ini
c:\documents and settings\HelpAssistant\Shared\The Commitments\Folder.jpg
c:\documents and settings\HelpAssistant\Shared\Thumbs.db
c:\documents and settings\HelpAssistant\Shared\zzzz\Thumbs.db
c:\documents and settings\HelpAssistant\Tracing
c:\documents and settings\HelpAssistant\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog
c:\documents and settings\HelpAssistant\UserData
c:\documents and settings\HelpAssistant\UserData\90GVPXWT\oWindowsUpdate[1].xml
c:\documents and settings\HelpAssistant\UserData\QNQRMDMV\sn[1].xml
c:\documents and settings\HelpAssistant\WINDOWS

.
((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
.

2020-01-25 04:49 . 2020-01-25 04:49 ——– d—–w- c:\windows\Paltalk Messenger
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- C:\88058f1f4ec15c490d
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- c:\documents and settings\mine\Application Data\SlySoft
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(3)
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\mine\Application Data\Intel(3)
2010-10-13 00:50 . 2009-05-24 15:54 ——– d—–w- c:\program files\SlySoft
2010-06-21 00:41 . 2010-06-21 00:41 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-19 23:14 . 2010-06-19 23:14 ——– d—–w- c:\documents and settings\mine\Application Data\Malwarebytes
2010-06-19 23:13 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 23:13 . 2010-06-19 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 23:12 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-19 23:12 . 2010-06-19 23:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 05:51 . 2010-06-21 00:52 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 04:50 . 2010-06-23 19:51 ——– d—–w- c:\documents and settings\HelpAssistant
2010-06-10 18:05 . 2010-06-10 18:05 ——– d—–w- C:\ProgramData (x86)
2010-06-10 03:01 . 2010-06-10 03:01 ——– d—–w- c:\program files\ISO Image Burner
2010-06-10 02:03 . 2010-06-10 02:03 ——– d—–w- c:\program files\uTorrent
2010-06-10 02:03 . 2010-06-10 23:45 ——– d—–w- c:\documents and settings\mine\Application Data\uTorrent
2010-06-10 00:46 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 03:38 . 2010-05-30 03:38 ——– d—–w- c:\documents and settings\mine\dwhelper
2010-05-30 00:50 . 2010-01-30 17:48 266552 —-a-w- c:\windows\system32\HMIPCore.dll
2010-05-30 00:15 . 2010-05-30 01:07 ——– d—–w- C:\Hotspot Shield
2010-05-28 19:40 . 2010-05-28 19:40 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcp71.dll
2010-05-28 19:40 . 2010-05-28 19:40 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\jmc.dll
2010-05-28 19:40 . 2010-05-28 19:40 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcr71.dll
2010-05-28 19:40 . 2010-05-28 19:40 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-sse.dll
2010-05-28 19:40 . 2010-05-28 19:40 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2020-01-25 04:49 . 2007-01-13 07:54 ——– d—–w- c:\program files\Windows Media Connect 2
2020-01-25 04:48 . 2007-01-05 03:54 ——– d—–w- c:\program files\Replay Converter
2020-01-25 04:47 . 2006-12-17 23:12 ——– d—–w- c:\program files\Windows Defender
2020-01-25 04:24 . 2006-12-17 23:30 ——– d—–w- c:\program files\Ahead
2010-06-13 08:45 . 2007-03-11 22:41 ——– d—–w- c:\documents and settings\mine\Application Data\Skype
2010-06-12 06:15 . 2010-01-24 03:28 ——– d—–w- c:\program files\Google
2010-06-04 23:54 . 2009-08-01 06:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-21 20:14 . 2009-10-03 15:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-14 18:56 . 2006-04-23 07:52 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-14 00:30 . 2006-03-24 18:36 ——– d—–w- c:\program files\Java
2010-05-13 22:05 . 2010-05-13 22:05 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_D3DD076B988600E59BFD1E.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_CA1D36A8BD7C6E8B327132.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_A17D378A7C093FF2005726.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_6FEFF9B68218417F98F549.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_67DB1B8F6A28368D658316.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_64E749EF31745C29AAF314.exe
2010-05-11 02:28 . 2010-05-11 02:28 ——– d—–w- c:\program files\FriendFinder
2010-05-07 18:55 . 2010-05-07 18:55 255472 —-a-w- c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-05-06 10:41 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 18:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 18:50 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 23:29 . 2010-05-14 00:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-31 08:05 . 2010-03-31 08:05 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcp71.dll
2010-03-31 08:05 . 2010-03-31 08:05 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\jmc.dll
2010-03-31 08:05 . 2010-03-31 08:05 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcr71.dll
2010-03-31 08:05 . 2010-03-31 08:05 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-sse.dll
2010-03-31 08:05 . 2010-03-31 08:05 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-d3d.dll
2010-03-31 06:16 . 2010-03-31 06:16 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 06:10 . 2010-03-31 06:10 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2010-03-30 16:33 . 2008-11-12 22:14 33920 —-a-w- c:\windows\system32\drivers\fsbts.sys
2004-10-01 21:00 . 2006-12-17 22:44 40960 —-a-w- c:\program files\UNINSTALL_CDS.0XE
2009-07-26 22:06 . 2006-04-07 12:13 104 –sh–r- c:\windows\system32\38C8C11354.sys
2009-07-26 22:06 . 2006-04-07 12:13 4600 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5ba73b24-4614-4d17-b58e-0d9d95847e14}"= "c:\program files\AIR MILES TOOLBAR\Helper.dll" [2009-05-11 219648]

[HKEY_CLASSES_ROOT\clsid\{5ba73b24-4614-4d17-b58e-0d9d95847e14}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{DF11073E-3AFF-410F-9AC8-72459F32C80F}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{169A78DB-CFC2-4DA4-A9BD-A67B28D41FA7}]
2009-05-11 22:54 1292288 ——w- c:\program files\AIR MILES TOOLBAR\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-08 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-03-24 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"News Service"="c:\program files\Shaw Secure\FSGUI\ispnews.exe" [2005-05-31 356352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-08-05 199264]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\LIvVE\\System\\mIC.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\mine\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [12/11/2008 4:14 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [27/04/2007 11:03 PM 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [12/11/2008 4:04 PM 68064]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [27/04/2007 11:45 PM 113864]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [12/11/2008 4:04 PM 55992]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 4:06 AM 21632]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [06/06/2008 9:17 AM 95232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [27/04/2007 11:03 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [27/04/2007 11:03 PM 25184]
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006Core.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006UA.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/ig?hl=en
mWindow Title = Internet Explorer Provided by SHAW Internet
mSearch Bar = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://ca.search.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {1E3F888F-96D7-4A1B-8514-8991264E8B7D} - hxxp://www.pc.gc.ca/apps/dci/source/bin/iS3DCtrl.cab
DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} - hxxp://www.3dvista.com/downloads/viewer3dv.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&p=
FF - component: c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}\components\Engine.dll
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\documents and settings\mine\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\mine\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 13:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(704)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'csrss.exe'(624)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
Completion time: 2010-06-23 13:57:48
ComboFix-quarantined-files.txt 2010-06-23 19:57
ComboFix2.txt 2010-06-23 15:41
ComboFix3.txt 2010-06-22 18:49
ComboFix4.txt 2010-06-21 02:07
ComboFix5.txt 2010-06-23 19:38

Pre-Run: 56,522,051,584 bytes free
Post-Run: 56,502,140,928 bytes free

- - End Of File - - 317CC88FDEC7A57EB5EABCC791B80893
One left :thumbup:

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Folder::
c:\documents and settings\HelpAssistant

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
next combofix log:


ComboFix 10-06-23.01 - mine 23/06/2010 16:17:59.8.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.432 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mine\Desktop\CFScript.txt
AV: Shaw Secure 9.01 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 9.01 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 )))))))))))))))))))))))))))))))
.

2020-01-25 04:49 . 2020-01-25 04:49 ——– d—–w- c:\windows\Paltalk Messenger
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- C:\88058f1f4ec15c490d
2020-01-25 04:48 . 2020-01-25 04:48 ——– d—–w- c:\documents and settings\mine\Application Data\SlySoft
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel(3)
2020-01-25 04:24 . 2020-01-25 04:47 ——– d—–w- c:\documents and settings\mine\Application Data\Intel(3)
2010-10-13 00:50 . 2009-05-24 15:54 ——– d—–w- c:\program files\SlySoft
2010-06-21 00:41 . 2010-06-21 00:41 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-19 23:14 . 2010-06-19 23:14 ——– d—–w- c:\documents and settings\mine\Application Data\Malwarebytes
2010-06-19 23:13 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 23:13 . 2010-06-19 23:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 23:12 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-19 23:12 . 2010-06-19 23:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 05:51 . 2010-06-21 00:52 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 04:50 . 2010-06-23 19:51 ——– d—–w- c:\documents and settings\HelpAssistant
2010-06-10 18:05 . 2010-06-10 18:05 ——– d—–w- C:\ProgramData (x86)
2010-06-10 03:01 . 2010-06-10 03:01 ——– d—–w- c:\program files\ISO Image Burner
2010-06-10 02:03 . 2010-06-10 02:03 ——– d—–w- c:\program files\uTorrent
2010-06-10 02:03 . 2010-06-10 23:45 ——– d—–w- c:\documents and settings\mine\Application Data\uTorrent
2010-06-10 00:46 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 03:38 . 2010-05-30 03:38 ——– d—–w- c:\documents and settings\mine\dwhelper
2010-05-30 00:50 . 2010-01-30 17:48 266552 —-a-w- c:\windows\system32\HMIPCore.dll
2010-05-30 00:15 . 2010-05-30 01:07 ——– d—–w- C:\Hotspot Shield
2010-05-28 19:40 . 2010-05-28 19:40 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcp71.dll
2010-05-28 19:40 . 2010-05-28 19:40 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\jmc.dll
2010-05-28 19:40 . 2010-05-28 19:40 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2834b44a-n\msvcr71.dll
2010-05-28 19:40 . 2010-05-28 19:40 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-sse.dll
2010-05-28 19:40 . 2010-05-28 19:40 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-12d04413-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2020-01-25 04:49 . 2007-01-13 07:54 ——– d—–w- c:\program files\Windows Media Connect 2
2020-01-25 04:48 . 2007-01-05 03:54 ——– d—–w- c:\program files\Replay Converter
2020-01-25 04:47 . 2006-12-17 23:12 ——– d—–w- c:\program files\Windows Defender
2020-01-25 04:24 . 2006-12-17 23:30 ——– d—–w- c:\program files\Ahead
2010-06-13 08:45 . 2007-03-11 22:41 ——– d—–w- c:\documents and settings\mine\Application Data\Skype
2010-06-12 06:15 . 2010-01-24 03:28 ——– d—–w- c:\program files\Google
2010-06-04 23:54 . 2009-08-01 06:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-21 20:14 . 2009-10-03 15:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-14 18:56 . 2006-04-23 07:52 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-14 00:30 . 2006-03-24 18:36 ——– d—–w- c:\program files\Java
2010-05-13 22:05 . 2010-05-13 22:05 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_D3DD076B988600E59BFD1E.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_CA1D36A8BD7C6E8B327132.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_A17D378A7C093FF2005726.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_6FEFF9B68218417F98F549.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_67DB1B8F6A28368D658316.exe
2010-05-11 02:28 . 2010-05-11 02:28 12846 —-a-r- c:\documents and settings\mine\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_64E749EF31745C29AAF314.exe
2010-05-11 02:28 . 2010-05-11 02:28 ——– d—–w- c:\program files\FriendFinder
2010-05-07 18:55 . 2010-05-07 18:55 255472 —-a-w- c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-05-06 10:41 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 18:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 18:50 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 23:29 . 2010-05-14 00:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-31 08:05 . 2010-03-31 08:05 503808 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcp71.dll
2010-03-31 08:05 . 2010-03-31 08:05 499712 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\jmc.dll
2010-03-31 08:05 . 2010-03-31 08:05 348160 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-655a4875-n\msvcr71.dll
2010-03-31 08:05 . 2010-03-31 08:05 61440 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-sse.dll
2010-03-31 08:05 . 2010-03-31 08:05 12800 —-a-w- c:\documents and settings\mine\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-12eb3e44-n\decora-d3d.dll
2010-03-31 06:16 . 2010-03-31 06:16 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 06:10 . 2010-03-31 06:10 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2010-03-30 16:33 . 2008-11-12 22:14 33920 —-a-w- c:\windows\system32\drivers\fsbts.sys
2004-10-01 21:00 . 2006-12-17 22:44 40960 —-a-w- c:\program files\UNINSTALL_CDS.0XE
2009-07-26 22:06 . 2006-04-07 12:13 104 –sh–r- c:\windows\system32\38C8C11354.sys
2009-07-26 22:06 . 2006-04-07 12:13 4600 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5ba73b24-4614-4d17-b58e-0d9d95847e14}"= "c:\program files\AIR MILES TOOLBAR\Helper.dll" [2009-05-11 219648]

[HKEY_CLASSES_ROOT\clsid\{5ba73b24-4614-4d17-b58e-0d9d95847e14}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{DF11073E-3AFF-410F-9AC8-72459F32C80F}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{169A78DB-CFC2-4DA4-A9BD-A67B28D41FA7}]
2009-05-11 22:54 1292288 ——w- c:\program files\AIR MILES TOOLBAR\Toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{789D9334-A44A-486E-8234-313A78E66E61}"= "c:\program files\AIR MILES TOOLBAR\Toolbar.dll" [2009-05-11 1292288]

[HKEY_CLASSES_ROOT\clsid\{789d9334-a44a-486e-8234-313a78e66e61}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{3AA580F6-AE52-436E-A24D-69082DF84CF9}]
[HKEY_CLASSES_ROOT\FCTB000056939.IEToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-08 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-03-24 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"News Service"="c:\program files\Shaw Secure\FSGUI\ispnews.exe" [2005-05-31 356352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-08-05 199264]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\LIvVE\\System\\mIC.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\mine\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [12/11/2008 4:14 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [27/04/2007 11:03 PM 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [12/11/2008 4:04 PM 68064]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [27/04/2007 11:45 PM 113864]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [12/11/2008 4:04 PM 55992]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 4:06 AM 21632]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [06/06/2008 9:17 AM 95232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [27/04/2007 11:03 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [27/04/2007 11:03 PM 25184]
.
Contents of the 'Scheduled Tasks' folder

2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006Core.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789029489-1268896404-705703666-1006UA.job
- c:\documents and settings\mine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-08 21:14]

2010-06-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.ca/ig?hl=en
mWindow Title = Internet Explorer Provided by SHAW Internet
mSearch Bar = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://ca.search.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {1E3F888F-96D7-4A1B-8514-8991264E8B7D} - hxxp://www.pc.gc.ca/apps/dci/source/bin/iS3DCtrl.cab
DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} - hxxp://www.3dvista.com/downloads/viewer3dv.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&p=
FF - component: c:\documents and settings\mine\Application Data\Mozilla\Firefox\Profiles\azy7vojz.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}\components\Engine.dll
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\documents and settings\mine\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\mine\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\mine\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPStreamPlug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-23 16:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(704)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'csrss.exe'(624)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
Completion time: 2010-06-23 16:31:02
ComboFix-quarantined-files.txt 2010-06-23 22:30
ComboFix2.txt 2010-06-23 19:57
ComboFix3.txt 2010-06-23 15:41
ComboFix4.txt 2010-06-22 18:49
ComboFix5.txt 2010-06-23 22:16

Pre-Run: 56,504,352,768 bytes free
Post-Run: 56,484,769,792 bytes free

- - End Of File - - A2C48F340720CB22D7EDACD3619B212E

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI