MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: MP061
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 158):
0x8444C000 \SystemRoot\system32\ntkrnlpa.exe
0x84419000 \SystemRoot\system32\hal.dll
0x80409000 \SystemRoot\system32\kdcom.dll
0x80410000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80480000 \SystemRoot\system32\PSHED.dll
0x80491000 \SystemRoot\system32\BOOTVID.dll
0x80499000 \SystemRoot\system32\CLFS.SYS
0x804DA000 \SystemRoot\system32\CI.dll
0x80609000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80685000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80692000 \SystemRoot\system32\drivers\acpi.sys
0x806D8000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806E1000 \SystemRoot\system32\drivers\msisadrv.sys
0x806E9000 \SystemRoot\system32\drivers\pci.sys
0x80710000 \SystemRoot\System32\drivers\partmgr.sys
0x8071F000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x80722000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8072C000 \SystemRoot\system32\drivers\volmgr.sys
0x8073B000 \SystemRoot\System32\drivers\volmgrx.sys
0x80785000 \SystemRoot\system32\drivers\intelide.sys
0x8078C000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8079A000 \SystemRoot\system32\DRIVERS\pciide.sys
0x807A1000 \SystemRoot\System32\drivers\mountmgr.sys
0x807B1000 \SystemRoot\system32\drivers\atapi.sys
0x807B9000 \SystemRoot\system32\drivers\ataport.SYS
0x805BA000 \SystemRoot\system32\drivers\fltmgr.sys
0x807D7000 \SystemRoot\system32\drivers\fileinfo.sys
0x807E7000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x84A02000 \SystemRoot\System32\Drivers\ksecdd.sys
0x84A73000 \SystemRoot\system32\drivers\ndis.sys
0x84B7E000 \SystemRoot\system32\drivers\msrpc.sys
0x84BA9000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A00F000 \SystemRoot\System32\drivers\tcpip.sys
0x8A0F9000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8A20B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8A31B000 \SystemRoot\system32\drivers\volsnap.sys
0x8A354000 \SystemRoot\System32\Drivers\spldr.sys
0x8A35C000 \SystemRoot\System32\Drivers\mup.sys
0x8A36B000 \SystemRoot\system32\drivers\klbg.sys
0x8A378000 \SystemRoot\System32\drivers\ecache.sys
0x8A39F000 \SystemRoot\system32\drivers\disk.sys
0x8A3B0000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8A3D1000 \SystemRoot\system32\drivers\crcdisk.sys
0x8A200000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8A114000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8A11D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8A12C000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8A3FA000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8E207000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8E8B5000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8E956000 \SystemRoot\System32\drivers\watchdog.sys
0x8E962000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8A135000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8E9EF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8A1BB000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8A000000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x84BE4000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys
0x807F0000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x805EC000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8EA0B000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8EA25000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8EA33000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8EA47000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8EA98000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EAAB000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EAD6000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8EAD8000 \SystemRoot\system32\DRIVERS\klmouflt.sys
0x8EAE1000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EAEC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EAF7000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EB17000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EB46000 \SystemRoot\system32\DRIVERS\storport.sys
0x8EB87000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EB92000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EBA9000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EBB4000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EBD7000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EBE6000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8EE0A000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EE1F000 \SystemRoot\System32\Drivers\pcouffin.sys
0x8EE2B000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8EE3B000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8EE3D000 \SystemRoot\system32\DRIVERS\ks.sys
0x8EE67000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8EE71000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EE7E000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EEB3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8EEC4000 \SystemRoot\system32\drivers\stwrt.sys
0x8EF67000 \SystemRoot\system32\drivers\portcls.sys
0x8EF94000 \SystemRoot\system32\drivers\drmk.sys
0x8EFB9000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x8F20E000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8F311000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8F3C5000 \SystemRoot\system32\drivers\modem.sys
0x8F404000 \SystemRoot\system32\DRIVERS\klif.sys
0x8F455000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F45E000 \SystemRoot\System32\Drivers\Null.SYS
0x8F465000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F475000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F47C000 \SystemRoot\System32\drivers\vga.sys
0x8F488000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F4A9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F4B1000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F4B9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F4C4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F4D2000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F4DB000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F80C000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8FD2C000 \SystemRoot\system32\DRIVERS\smb.sys
0x8FD40000 \SystemRoot\system32\drivers\afd.sys
0x8FD88000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8FDBA000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8FDD0000 \SystemRoot\system32\DRIVERS\klim6.sys
0x8FDD7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8FDE5000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F4F1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8F800000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8F52D000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F544000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8F54D000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8FDF8000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
0x8F55D000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8F565000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8F572000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8F57D000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x99A60000 \SystemRoot\System32\win32k.sys
0x8F585000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F58F000 \SystemRoot\system32\DRIVERS\monitor.sys
0x99C80000 \SystemRoot\System32\TSDDD.dll
0x99CA0000 \SystemRoot\System32\cdd.dll
0x8F59E000 \SystemRoot\system32\drivers\luafv.sys
0xAB40E000 \SystemRoot\system32\drivers\spsys.sys
0xAB4BE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xAB4CE000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xAB4F8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAB502000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAB515000 \SystemRoot\system32\drivers\HTTP.sys
0xAB582000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAB59F000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAB5B8000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAB5CD000 \SystemRoot\system32\drivers\mrxdav.sys
0x8F5C1000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xABE07000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xABE40000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xABE58000 \SystemRoot\System32\DRIVERS\srv2.sys
0xABE7F000 \SystemRoot\System32\DRIVERS\srv.sys
0xABECD000 \??\C:\Program Files\DellSupport\Drivers\dsunidrv.sys
0xABECF000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xABED3000 \SystemRoot\system32\drivers\peauth.sys
0xABFB1000 \SystemRoot\System32\Drivers\fastfat.SYS
0xABFD9000 \SystemRoot\System32\Drivers\secdrv.SYS
0xABFE3000 \SystemRoot\System32\drivers\tcpipreg.sys
0xABFEF000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x8F5E0000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xABFF7000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xABE02000 \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
0xAB400000 \SystemRoot\system32\DRIVERS\serscan.sys
0x77BC0000 \Windows\System32\ntdll.dll
Processes (total 83):
0 System Idle Process
4 System
516 C:\Windows\System32\smss.exe
584 csrss.exe
628 C:\Windows\System32\wininit.exe
636 csrss.exe
680 C:\Windows\System32\services.exe
708 C:\Windows\System32\winlogon.exe
724 C:\Windows\System32\lsass.exe
744 C:\Windows\System32\lsm.exe
928 C:\Windows\System32\svchost.exe
996 C:\Windows\System32\svchost.exe
1040 C:\Windows\System32\svchost.exe
1140 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\svchost.exe
1344 C:\Windows\System32\audiodg.exe
1372 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\SLsvc.exe
1428 C:\Windows\System32\svchost.exe
1780 C:\Windows\System32\spoolsv.exe
1816 C:\Windows\System32\svchost.exe
2008 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
124 C:\Windows\System32\svchost.exe
360 C:\Windows\System32\svchost.exe
384 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
828 C:\Windows\System32\svchost.exe
1628 C:\Windows\System32\svchost.exe
1872 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2096 C:\Windows\System32\svchost.exe
2140 C:\Windows\System32\svchost.exe
2224 C:\Windows\System32\SearchIndexer.exe
2724 C:\Windows\System32\taskeng.exe
1220 C:\Windows\System32\svchost.exe
3604 C:\Windows\System32\dwm.exe
1852 C:\Windows\explorer.exe
2120 C:\Windows\System32\taskeng.exe
1012 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2732 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1716 C:\Windows\System32\igfxpers.exe
3164 C:\Windows\System32\hkcmd.exe
2348 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
3032 C:\Windows\System32\WLTRAY.EXE
3068 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
2856 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
3152 C:\Windows\sttray.exe
864 C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
3244 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3188 C:\Program Files\Windows Sidebar\sidebar.exe
2932 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
2720 C:\Windows\ehome\ehtray.exe
3968 C:\Program Files\DellSupport\DSAgnt.exe
4052 C:\Program Files\Windows Media Player\wmpnscfg.exe
3676 C:\Program Files\Digital Line Detect\DLG.exe
2336 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
3772 C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
2904 C:\Windows\ehome\ehmsas.exe
3692 C:\Program Files\Windows Media Player\wmpnetwk.exe
2148 C:\Windows\System32\wbem\unsecapp.exe
3688 WmiPrvSE.exe
1812 C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
896 C:\Program Files\Common Files\Teleca Shared\logger.exe
4120 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
4192 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
4460 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
4552 C:\Program Files\Common Files\Teleca Shared\Generic.exe
4804 C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
4840 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
4912 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\dbgout.exe
5716 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
5860 C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
5592 C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
2476 C:\Program Files\HTC\HTC Sync\Sync Manager\SyncIndicator.exe
5268 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
4444 C:\Windows\System32\svchost.exe
3512 C:\Program Files\Internet Explorer\iexplore.exe
1440 C:\Program Files\Internet Explorer\iexplore.exe
4148 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
4116 C:\Program Files\Windows Live\Toolbar\wltuser.exe
4732
2692
796 C:\Users\White\Desktop\WTT - Aug 11 2010\MBRCheck.exe
5228 C:\Windows\System32\conime.exe
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000002`83000000 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`03000000 (NTFS)
PhysicalDrive0 Model Number: SAMSUNGHM120JI, Rev: YF100-15
Size Device Name MBR Status
——————————————–
111 GB \\.\PhysicalDrive0 Windows Vista MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
Done!
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 15:43:27.03 on 2010-08-15
Internet Explorer: 8.0.6001.18943
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1015 [GMT -4:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Windows\sttray.exe
C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\logger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\DbgOut.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\HTC\HTC Sync\Sync Manager\syncindicator.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\White\Desktop\WTT - Aug 11 2010\dds.com
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Mobile Connectivity Suite] "c:\program files\htc\htc sync\application launcher\Application Launcher.exe" /startoptions
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\white\appdata\roaming\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - c:\program files\quicktax 2009\ic2009pp.dll
Notify: igfxcui - igfxdev.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~2\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~2\kloehk.dll
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-9-14 21520]
R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-19 21504]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2010-4-21 24576]
S3 mr97310c;CIF Dual-Mode Camera;c:\windows\system32\drivers\mr97310c.sys [2008-3-27 116992]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-7-5 27192]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
============== File Associations ===============
regfile=regedit.exe "%1" %*
scrfile="%1" %*
=============== Created Last 30 ================
2010-08-10 20:17:43 2037760 —-a-w- c:\windows\system32\win32k.sys
2010-08-10 20:17:40 36864 —-a-w- c:\windows\system32\rtutils.dll
2010-08-10 20:17:36 3600768 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-10 20:17:35 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-08-10 20:17:30 1248768 —-a-w- c:\windows\system32\msxml3.dll
2010-08-10 20:17:27 302080 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-10 20:17:27 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-08-10 20:17:23 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
==================== Find3M ====================
2010-07-29 21:52:58 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 21:52:58 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-07-17 09:00:04 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:05:49 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02:15 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02:15 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25:02 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-06-11 16:16:20 274944 —-a-w- c:\windows\system32\schannel.dll
2010-05-27 20:08:17 81920 —-a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06:41 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-04-21 23:20:55 51200 —-a-w- c:\windows\inf\infpub.dat
2010-04-21 23:20:54 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-04-21 23:20:54 143360 —-a-w- c:\windows\inf\infstor.dat
2010-02-22 08:27:45 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-01-13 03:26:41 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-04-13 10:40:55 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-04-13 10:40:55 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-04-13 10:40:55 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2010-02-06 05:14:41 16384 –sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\low\history.ie5\index.dat
2010-02-06 05:14:41 32768 –sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\index.dat
2010-02-06 05:14:41 16384 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\cookies\low\index.dat
2010-01-29 23:34:23 6813216 –sha-w- c:\windows\system32\drivers\fidbox.dat
2010-01-29 23:34:23 1294368 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2007-02-05 18:48:42 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 15:45:55.09 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 2007-02-05 05:56:17 AM
System Uptime: 2010-08-15 02:19:40 AM (13 hours ago)
Motherboard: Dell Inc. | | 0FF049
Processor: Intel® Core™2 CPU T5200 @ 1.60GHz | Microprocessor | 1600/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 100 GiB total, 19.408 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 6.011 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart C7200 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C7200 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
==== System Restore Points ===================
RP1616: 2010-08-11 06:51:54 PM - Installed HiJackThis
RP1617: 2010-08-11 06:58:36 PM - Removed HiJackThis
RP1618: 2010-08-12 07:28:19 AM - Scheduled Checkpoint
RP1619: 2010-08-13 12:31:06 AM - Scheduled Checkpoint
RP1620: 2010-08-13 01:52:28 AM - Windows Update
RP1621: 2010-08-14 12:00:03 AM - Scheduled Checkpoint
RP1622: 2010-08-15 09:59:02 AM - Scheduled Checkpoint
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 2 (SP2)
32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.2
AIO_Scan
AnswerWorks 5.0 English Runtime
Any Video Converter 2.6.7
Art Explosion Greeting Card Factory Express
AutoCAD 2000
BufferChm
C7200
c7200_Help
Caillou's Colors Shapes
Cards_Calendar_OrderGift_DoMorePlugout
Conexant HDA D110 MDC V.92 Modem
Copy
Coupon Printer for Windows
CSI-Dark Motives
CustomerResearchQFolder
Dell Support Center (Support Software)
Dell Wireless WLAN Card
DellSupport
Destination Component
DeviceDiscovery
DeviceManagementQFolder
Digital Line Detect
Disney's Mickey Mouse Toddler
Disney's Winnie the Pooh Preschool
Disney's Winnie the Pooh Toddler
DocProc
DVD-CLONER V7.00 Build 990
EGS Recipe Center
ESET Online Scanner v3
eSupportQFolder
Fax
Free Mp3 Wma Converter V 1.8.0
Galaxy of Games Blue Edition
Garmin City Navigator North America NT 2009 Update
Garmin City Navigator North America NT 2010.40
Garmin City Navigator North America NT 2011.10 Update
Garmin Communicator Plugin
Garmin USB Drivers
Garmin WebUpdater
GearDrvs
Google SketchUp 6
Google SketchUp 7
GoToAssist 8.0.0.514
GPBaseService
Guitar Pro 5.0
Hidden Relics
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 10.0
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HP Update
HP_Network_UserGuide
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
HTC Driver
HTC Sync
I am an Air Traffic Controller3
Java Auto Updater
Java™ 6 Update 21
Kaspersky Internet Security 2010
Lernout & Hauspie TruVoice American English TTS Engine
LiveUpdate 3.2 (Symantec Corporation)
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
MarketResearch
Mavis Beacon Teaches Typing 15
MediaDirect
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Search Enhancement Pack
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Modem Diagnostic Tool
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery Case Files - Prime Suspects
NetDeviceManager
NetWaiting
NiBiRu
NutriBase
OCR Software by I.R.I.S. 10.0
OpenOffice.org 3.0
OutlookAddinSetup
OverDrive Media Console
PanoStandAlone
Picture Package Music Transfer
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_Min
PSSWCORE
Quicken 2010
QuickSet
QuickTax 2006
QuickTax 2007
QuickTax 2008
QuickTax 2009
QuickTax Tracker
QuickTime
Revo Uninstaller Pro 2.2.3
Safari
Scan
Security Update for 2007 Microsoft Office System (KB2277947)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2251419)
Shop for HP Supplies
SigmaTel Audio
Smart Menus (Windows Live Toolbar)
SmartWebPrintingOC
SolutionCenter
Sonic Activation Module
Sony Picture Utility
Status
Synaptics Pointing Device Driver
Toolbox
TrayApp
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb2279264)
User's Guides
VideoToolkit01
WebReg
Winamp Toolbar for Firefox
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Upload Tool
WinRAR archiver
Xilisoft AVI to DVD Converter
Xvid 1.2.2 final uninstall
==== Event Viewer Messages From Past Week ========
2010-08-15 12:33:12 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
2010-08-14 09:31:56 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ASPI32
2010-08-14 09:31:52 AM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
2010-08-14 04:15:11 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
2010-08-11 06:03:14 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
2010-08-11 06:03:14 AM, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2010-08-11 04:51:02 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
2010-08-11 04:48:12 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
2010-08-11 04:48:09 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the stisvc service.
2010-08-10 09:23:33 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
==== End Of File ===========================
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-08-15 20:28:38
Windows 6.0.6002 Service Pack 2
Running: uzf7xwf5.exe; Driver: C:\Users\White\AppData\Local\Temp\uglcqpow.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x8F423BD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8F42552C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8F425782]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8F4259FC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8F424450]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x8F424B32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x8F424F3C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateFile [0x8F4245F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x8F424E14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0x8F4237D6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x8F424CD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8F423992]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8F42506E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0x8F426CB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x8F4240EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x8F424D72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8F4266A2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8F427672]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwFsControlFile [0x8F424752]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8F426734]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8F426D64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x8F424FDE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenFile [0x8F4244D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x8F424EAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x8F423DD6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8F426CDA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8F425110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x8F423CFA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8F425C3E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8F42707C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8F4269CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8F42549A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8F425360]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8F426442]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8F427554]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x8F42486C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x8F42430C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8F425CF2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSecurityObject [0x8F42682E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8F4271BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8F4272A0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8F4273C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8F4265CE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x8F423F4E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x8F423EA4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8F426F32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8F42402E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x8F4241EE]
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 119 844F887C 4 Bytes [D0, 3B, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 13D 844F88A0 8 Bytes [2C, 55, 42, 8F, 82, 57, 42, …]
.text ntkrnlpa.exe!KeSetEvent + 181 844F88E4 4 Bytes [FC, 59, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1A9 844F890C 4 Bytes [50, 44, 42, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1C1 844F8924 4 Bytes [32, 4B, 42, 8F]
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!SetWindowsHookExW 76F887AD 5 Bytes JMP 6E5F9AD5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!CallNextHookEx 76F88E3B 5 Bytes JMP 6E5ED135 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!UnhookWindowsHookEx 76F898DB 5 Bytes JMP 6E564666 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!CreateWindowExW 76F91305 5 Bytes JMP 6E5FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxParamW 76FB10B0 5 Bytes JMP 6E525501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxIndirectParamW 76FB2EF5 5 Bytes JMP 6E6F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxParamA 76FC8152 5 Bytes JMP 6E6F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!DialogBoxIndirectParamA 76FC847D 5 Bytes JMP 6E6F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxIndirectA 76FDD4D9 5 Bytes JMP 6E6F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxIndirectW 76FDD5D3 5 Bytes JMP 6E6F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxExA 76FDD639 5 Bytes JMP 6E6F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] USER32.dll!MessageBoxExW 76FDD65D 5 Bytes JMP 6E6F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ole32.dll!OleLoadFromStream 77A91E12 5 Bytes JMP 6E6F4ED0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ole32.dll!CoCreateInstance 77AC9EA6 5 Bytes JMP 6E5FDB80 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!closesocket 77DF330C 5 Bytes JMP 65FF41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!recv 77DF343A 5 Bytes JMP 65FF4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!socket 77DF36D1 5 Bytes JMP 65FF354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!connect 77DF40D9 5 Bytes JMP 65FF35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!getaddrinfo 77DF418A 5 Bytes JMP 65FF3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1440] ws2_32.dll!send 77DF659B 5 Bytes JMP 65FF3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2008] USER32.dll!SetScrollInfo + 7A8 76F97980 4 Bytes [70, 11, 33, 6D]
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] C:\Windows\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] C:\Windows\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2856] USER32.dll!SetScrollInfo + 7A8 76F97980 4 Bytes [70, 11, 33, 6D]
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!CreateWindowExW 76F91305 5 Bytes JMP 6E5FDB24 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxParamW 76FB10B0 5 Bytes JMP 6E525501 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxIndirectParamW 76FB2EF5 5 Bytes JMP 6E6F4B4F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxParamA 76FC8152 5 Bytes JMP 6E6F4AEC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!DialogBoxIndirectParamA 76FC847D 5 Bytes JMP 6E6F4BB2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxIndirectA 76FDD4D9 5 Bytes JMP 6E6F4A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxIndirectW 76FDD5D3 5 Bytes JMP 6E6F4A16 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxExA 76FDD639 5 Bytes JMP 6E6F49B4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3512] USER32.dll!MessageBoxExW 76FDD65D 5 Bytes JMP 6E6F4952 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[5592] kernel32.dll!SetUnhandledExceptionFilter 779BA84F 4 Bytes JMP 64645164 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE[5592] ole32.dll!OleLoadFromStream 77A91E12 5 Bytes JMP 650F9D32 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- EOF - GMER 1.0.15 —-