This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Speaker Tones

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just upgraded my Dell Inspiron 530 to Windows 7 from XP. Had no problems with install transfered my files over and reinstalled all my programs. Have searched and updated all drivers. I now have a repeating tone sound coming from my speakers. 2 seperate tones repeating over and over again. Again I have updated drivers, when I go into Device manager and have Windows search for updated driver, it replies that I have the best driver. I have tried another set of speakers, still the sounds.I have downloaded drivers from Dell site and Realtek site with no change. Went into device manager disabled the on board sound and installed a PCI sound card still have the tones. Antivirus and antimalware are up to date not showing any infections. Have the latest BIOS from Dell. I have no other issues other than the tones coming out of my speakers. I keep the system sounds muted as not to hear them, music movies etc sound fine no issues. The tones start as soon as the computer is booted up and never change

Here are the results of Hijack this run
Thanks

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:06:20 PM, on 11/21/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEKA.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Ray\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0071120
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PC Pitstop PC Matic Reminder] C:\Program Files\PCPitstop\PC Matic\Reminder-PCMatic.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [EPSON WorkForce 600 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEKA.EXE /FU "C:\Windows\TEMP\E_S9701.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [CTRegRun] C:\Windows\CTRegRun.EXE
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s…el_4.3.13.0.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - C:\Windows\system32\IProsetMonitor.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PCPitstop Scheduling - PC Pitstop LLC - C:\Program Files\PCPitstop\PCPitstopScheduleService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 11042 bytes
Hi, Ray,

Lets do this to start

Step 1 | Download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Here is the MBRCheck MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: Dell Inc. BIOS Manufacturer: Dell Inc. System Manufacturer: Dell Inc. System Product Name: Inspiron 530 Logical Drives Mask: 0x000007fc Kernel Drivers (total 168): 0x82C52000 \SystemRoot\system32\ntkrnlpa.exe 0x82C1B000 \SystemRoot\system32\halmacpi.dll 0x80BAC000 \SystemRoot\system32\kdcom.dll 0x8323D000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x832B5000 \SystemRoot\system32\PSHED.dll 0x832C6000 \SystemRoot\system32\BOOTVID.dll 0x832CE000 \SystemRoot\system32\CLFS.SYS 0x83310000 \SystemRoot\system32\CI.dll 0x8382C000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8389D000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x838AB000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x838F3000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x838FC000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x83904000 \SystemRoot\system32\DRIVERS\pci.sys 0x8392E000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x83939000 \SystemRoot\System32\drivers\partmgr.sys 0x8394A000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x8395A000 \SystemRoot\System32\drivers\volmgrx.sys 0x839A5000 \SystemRoot\system32\DRIVERS\pciide.sys 0x839AC000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x839BA000 \SystemRoot\System32\drivers\mountmgr.sys 0x839D0000 \SystemRoot\system32\DRIVERS\atapi.sys 0x839D9000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x83800000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x833BB000 \SystemRoot\system32\drivers\fltmgr.sys 0x83809000 \SystemRoot\system32\drivers\fileinfo.sys 0x8381A000 \SystemRoot\system32\DRIVERS\Lbd.sys 0x83200000 \SystemRoot\System32\Drivers\DRVMCDB.SYS 0x83216000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x83A1A000 \SystemRoot\System32\Drivers\Ntfs.sys 0x83B49000 \SystemRoot\System32\Drivers\msrpc.sys 0x83B74000 \SystemRoot\System32\Drivers\ksecdd.sys 0x83B87000 \SystemRoot\System32\Drivers\cng.sys 0x83BE4000 \SystemRoot\System32\drivers\pcw.sys 0x83BF2000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x8B415000 \SystemRoot\system32\drivers\ndis.sys 0x8B4CC000 \SystemRoot\system32\drivers\NETIO.SYS 0x8B50A000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8B63B000 \SystemRoot\System32\drivers\tcpip.sys 0x8B784000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8B52F000 \SystemRoot\system32\DRIVERS\timntr.sys 0x8B7B5000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x8B82A000 \SystemRoot\system32\DRIVERS\tdrpm258.sys 0x8B907000 \SystemRoot\System32\Drivers\spldr.sys 0x8B90F000 \SystemRoot\system32\DRIVERS\snapman.sys 0x8B934000 \SystemRoot\System32\drivers\rdyboost.sys 0x8B961000 \SystemRoot\System32\Drivers\mup.sys 0x8B971000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8B979000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x8B9AB000 \SystemRoot\system32\DRIVERS\disk.sys 0x8B9BC000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x8B600000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8B5BC000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0x8B81A000 \SystemRoot\System32\Drivers\DLACDBHM.SYS 0x8B81C000 \SystemRoot\System32\Drivers\Null.SYS 0x8B823000 \SystemRoot\System32\Drivers\Beep.SYS 0x8B9F9000 \SystemRoot\System32\Drivers\DLARTL_M.SYS 0x8B61F000 \SystemRoot\System32\drivers\vga.sys 0x8B5DF000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8B62B000 \SystemRoot\System32\drivers\watchdog.sys 0x8B7F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8B400000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8B408000 \SystemRoot\system32\drivers\rdprefmp.sys 0x83A00000 \SystemRoot\System32\Drivers\Msfs.SYS 0x83A0B000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8321F000 \SystemRoot\system32\DRIVERS\tdx.sys 0x833EF000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x9021E000 \SystemRoot\system32\drivers\afd.sys 0x90278000 \SystemRoot\System32\DRIVERS\netbt.sys 0x902AA000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x902B1000 \SystemRoot\system32\DRIVERS\pacer.sys 0x902D0000 \SystemRoot\system32\DRIVERS\netbios.sys 0x902DE000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x902F1000 \SystemRoot\system32\DRIVERS\termdd.sys 0x90301000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0x90323000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0x90329000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x9036A000 \SystemRoot\system32\drivers\nsiproxy.sys 0x90374000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x9037E000 \SystemRoot\System32\drivers\discache.sys 0x9038A000 \SystemRoot\System32\Drivers\dfsc.sys 0x903A2000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x903B0000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x903D1000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x91806000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x91D0F000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x91DC6000 \SystemRoot\System32\drivers\dxgmms1.sys 0x91401000 \SystemRoot\system32\DRIVERS\e1e6232.sys 0x9143A000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x91445000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x91490000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x9149F000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x9122D000 \SystemRoot\system32\drivers\P17.sys 0x91385000 \SystemRoot\system32\drivers\portcls.sys 0x913B4000 \SystemRoot\system32\drivers\drmk.sys 0x914BE000 \SystemRoot\system32\drivers\ks.sys 0x913CD000 \SystemRoot\system32\DRIVERS\fdc.sys 0x913D8000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x913E5000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x91200000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x91218000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x914F2000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x91514000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x9152C000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x91543000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x9155A000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x91567000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x91223000 \SystemRoot\system32\DRIVERS\swenum.sys 0x91574000 \SystemRoot\system32\DRIVERS\umbus.sys 0x91582000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x915C6000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x915D7000 \SystemRoot\System32\Drivers\crashdmp.sys 0x915E4000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x913F7000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x915EF000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x972F0000 \SystemRoot\System32\win32k.sys 0x903E3000 \SystemRoot\System32\drivers\Dxapi.sys 0x903ED000 \SystemRoot\system32\DRIVERS\monitor.sys 0x97550000 \SystemRoot\System32\TSDDD.dll 0x90200000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x91225000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x97580000 \SystemRoot\System32\cdd.dll 0x8B800000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8B9E1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x90217000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8FA1A000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x8FA31000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8FA3D000 \SystemRoot\system32\DRIVERS\usbscan.sys 0x8FA4B000 \SystemRoot\system32\DRIVERS\usbprint.sys 0x8FA56000 \SystemRoot\system32\drivers\luafv.sys 0x8FA71000 \SystemRoot\System32\Drivers\DRVNDDM.SYS 0x8FA7C000 \SystemRoot\System32\DLA\DLADResM.SYS 0x8FA7D000 \SystemRoot\System32\DLA\DLAIFS_M.SYS 0x8FA95000 \SystemRoot\System32\DLA\DLAOPIOM.SYS 0x8FA9A000 \SystemRoot\System32\DLA\DLAPoolM.SYS 0x8FA9C000 \SystemRoot\system32\drivers\WudfPf.sys 0x8FAB6000 \SystemRoot\System32\DLA\DLABMFSM.SYS 0x8FABD000 \SystemRoot\System32\DLA\DLABOIOM.SYS 0x8FAC4000 \SystemRoot\System32\DLA\DLAUDFAM.SYS 0x8FADA000 \SystemRoot\System32\DLA\DLAUDF_M.SYS 0x8FAF1000 \SystemRoot\system32\DRIVERS\dc3d.sys 0x8FAFB000 \SystemRoot\system32\DRIVERS\NuidFltr.sys 0x8FAFF000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8FB0A000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x8FB1A000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x8FB2D000 \SystemRoot\system32\drivers\HTTP.sys 0x8FBB2000 \SystemRoot\system32\DRIVERS\bowser.sys 0x8FBCB000 \SystemRoot\system32\DRIVERS\MpNWMon.sys 0x8FBD4000 \SystemRoot\System32\drivers\mpsdrv.sys 0x99C1C000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x99C3F000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x99C7A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x99CAD000 \??\C:\Windows\system32\drivers\cpuz133_x32.sys 0x99CB1000 \??\C:\Windows\system32\drivers\cpuz134_x32.sys 0x99CB5000 \SystemRoot\system32\DRIVERS\afcdp.sys 0x99CDB000 \SystemRoot\system32\drivers\peauth.sys 0x99D72000 \SystemRoot\System32\Drivers\secdrv.SYS 0x99D7C000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x99D9D000 \SystemRoot\System32\drivers\tcpipreg.sys 0x99DAA000 \SystemRoot\System32\DRIVERS\srv2.sys 0x9A20E000 \SystemRoot\System32\DRIVERS\srv.sys 0x9A25F000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0x9A280000 \SystemRoot\System32\Drivers\fastfat.SYS 0x9A2AA000 \SystemRoot\system32\drivers\spsys.sys 0x9A314000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x77780000 \Windows\System32\ntdll.dll 0x48080000 \Windows\System32\smss.exe 0x779C0000 \Windows\System32\apisetschema.dll Processes (total 78): 0 System Idle Process 4 System 424 C:\Windows\System32\smss.exe 556 csrss.exe 612 csrss.exe 620 C:\Windows\System32\wininit.exe 668 C:\Windows\System32\services.exe 700 C:\Windows\System32\winlogon.exe 824 C:\Windows\System32\lsass.exe 840 C:\Windows\System32\lsm.exe 944 C:\Windows\System32\svchost.exe 1204 C:\Windows\System32\nvvsvc.exe 1252 C:\Windows\System32\svchost.exe 1304 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe 1476 C:\Windows\System32\svchost.exe 1528 C:\Windows\System32\svchost.exe 1568 C:\Windows\System32\svchost.exe 1628 C:\Windows\System32\audiodg.exe 1756 C:\Program Files\Creative\Shared Files\CTAudSvc.exe 1796 C:\Windows\System32\svchost.exe 1904 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe 1928 C:\Windows\System32\svchost.exe 564 C:\Windows\System32\spoolsv.exe 604 C:\Windows\System32\svchost.exe 1640 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 1964 C:\Windows\System32\AERTSrv.exe 2072 C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe 2172 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE 2272 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE 2300 C:\Windows\System32\svchost.exe 2324 C:\Windows\System32\IPROSetMonitor.exe 2356 C:\PROGRA~1\McAfee\SITEAD~1\McSACore.exe 2416 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe 2468 C:\Windows\System32\rundll32.exe 2736 C:\Windows\System32\dwm.exe 2768 C:\Windows\System32\svchost.exe 2808 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 2904 C:\Windows\System32\taskhost.exe 3012 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 3060 C:\Windows\explorer.exe 3316 C:\Windows\System32\svchost.exe 3540 WmiPrvSE.exe 3576 WUDFHost.exe 3720 C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe 3740 C:\Windows\RtHDVCpl.exe 3784 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe 3800 C:\Windows\System32\igfxpers.exe 3944 C:\Windows\System32\rundll32.exe 3952 C:\Windows\System32\igfxtray.exe 3960 C:\Windows\System32\hkcmd.exe 4000 C:\Windows\System32\igfxsrvc.exe 4048 C:\Program Files\Epson Software\Event Manager\EEventManager.exe 1748 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe 2232 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe 492 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe 2920 C:\Program Files\Windows Sidebar\sidebar.exe 3168 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe 2268 C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEKA.EXE 2696 C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe 3996 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe 3688 C:\Windows\System32\SearchIndexer.exe 4212 C:\Program Files\Windows Media Player\wmpnetwk.exe 4328 C:\Windows\System32\SearchProtocolHost.exe 4512 C:\Windows\System32\svchost.exe 5180 dllhost.exe 5612 C:\Program Files\Internet Explorer\iexplore.exe 5680 C:\Program Files\Internet Explorer\iexplore.exe 5820 C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe 6024 C:\Program Files\Internet Explorer\iexplore.exe 456 C:\Windows\System32\sppsvc.exe 728 WmiPrvSE.exe 5160 C:\Windows\servicing\TrustedInstaller.exe 2060 taskhost.exe 5368 C:\Users\Ray\Desktop\MBRCheck.exe 4924 C:\Windows\System32\conhost.exe 5360 C:\Windows\System32\dllhost.exe 5176 C:\Windows\System32\SearchProtocolHost.exe 5168 C:\Windows\System32\SearchFilterHost.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`04e71400 (NTFS) \\.\K: –> \\.\PhysicalDrive6 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: WDCWD5001AALS-00L3B2, Rev: 01.03B01 PhysicalDrive6 Model Number: WD800BB External, Rev: 0602 Size Device Name MBR Status ——————————————– 465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 74 GB \\.\PhysicalDrive6 RE: Unknown MBR code SHA1: 2109F29445E77C0BCB56987F39830EB288D04575 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Lets run this scan

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.
Here is the GMER scan

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-24 18:07:57
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5001AALS-00L3B2 rev.01.03B01
Running: gmer.exe; Driver: C:\Users\Ray\AppData\Local\Temp\uwldrpow.sys


—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C8F599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB3F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

Device \Driver\ACPI_HAL \Device\00000042 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume9 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume9 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

—- EOF - GMER 1.0.15 —-
Here is the second scan not sure what I did wrong in the first looked at picture and matched up checks and no checks
Thanks


GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-24 19:38:10
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5001AALS-00L3B2 rev.01.03B01
Running: gmer.exe; Driver: C:\Users\Ray\AppData\Local\Temp\uwldrpow.sys


—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C8F599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB3F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!CreateWindowExW 75830E51 5 Bytes JMP 69C38187 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!DialogBoxIndirectParamW 75854AA7 5 Bytes JMP 69D5FE50 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!DialogBoxParamW 7585564A 5 Bytes JMP 69B54BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!DialogBoxParamA 7586CF6A 5 Bytes JMP 69D5FDED C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!DialogBoxIndirectParamA 7586D29C 5 Bytes JMP 69D5FEB3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!MessageBoxIndirectA 7587E8C9 5 Bytes JMP 69D5FD82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!MessageBoxIndirectW 7587E9C3 5 Bytes JMP 69D5FD17 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!MessageBoxExA 7587EA29 5 Bytes JMP 69D5FCB5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1888] USER32.dll!MessageBoxExW 7587EA4D 5 Bytes JMP 69D5FC53 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CreateDialogParamW 75829BFF 5 Bytes JMP 69B8C570 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!EnableWindow 7582A72E 5 Bytes JMP 69B8C4EB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!GetAsyncKeyState 7582C09A 5 Bytes JMP 69B4D6E9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!UnhookWindowsHookEx 7582CC7B 5 Bytes JMP 69C4838A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CallNextHookEx 7582CC8F 5 Bytes JMP 69C29D7C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CreateWindowExW 75830E51 5 Bytes JMP 69C38187 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!SetWindowsHookExW 7583210A 5 Bytes JMP 69BE4633 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!GetKeyState 75834FDA 5 Bytes JMP 69B8D762 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!IsDialogMessageW 75836F06 5 Bytes JMP 69B54284 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CreateDialogParamA 75843E79 5 Bytes JMP 69D60A6C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!IsDialogMessage 7584407A 5 Bytes JMP 69D6030D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CreateDialogIndirectParamA 75849110 5 Bytes JMP 69D60AA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!CreateDialogIndirectParamW 758508AD 5 Bytes JMP 69D60ADA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!DialogBoxIndirectParamW 75854AA7 5 Bytes JMP 69D5FE50 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!EndDialog 7585555C 5 Bytes JMP 69B55AE9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!DialogBoxParamW 7585564A 5 Bytes JMP 69B54BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!SetKeyboardState 75856B52 5 Bytes JMP 69D60672 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!SendInput 75857055 5 Bytes JMP 69D61238 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!SetCursorPos 7586C1D8 5 Bytes JMP 69D61290 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!DialogBoxParamA 7586CF6A 5 Bytes JMP 69D5FDED C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!DialogBoxIndirectParamA 7586D29C 5 Bytes JMP 69D5FEB3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!MessageBoxIndirectA 7587E8C9 5 Bytes JMP 69D5FD82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!MessageBoxIndirectW 7587E9C3 5 Bytes JMP 69D5FD17 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!MessageBoxExA 7587EA29 5 Bytes JMP 69D5FCB5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!MessageBoxExW 7587EA4D 5 Bytes JMP 69D5FC53 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] USER32.dll!keybd_event 7587EC9B 5 Bytes JMP 69D615C3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] SHELL32.dll!SHChangeNotification_Lock + 45BA 7667B440 4 Bytes [11, 36, 78, 6F] {ADC [ESI], ESI; JS 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] SHELL32.dll!SHChangeNotification_Lock + 45C2 7667B448 8 Bytes [5F, 35, 78, 6F, D0, 73, 77, …] {POP EDI; XOR EAX, 0x73d06f78; JA 0x77}
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] ole32.dll!OleLoadFromStream 758F5BF6 5 Bytes JMP 69D601C9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] ole32.dll!CoCreateInstance 7594590C 5 Bytes JMP 69C38C75 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] WININET.dll!InternetCloseHandle 7572C83E 5 Bytes JMP 01E2EE00 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] WININET.dll!InternetReadFile 7572E264 5 Bytes JMP 01E2EF20 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] WININET.dll!HttpOpenRequestA 757303FA 5 Bytes JMP 01E2F060 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5684] WININET.dll!InternetConnectA 7573050F 5 Bytes JMP 01E2F160 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

Device \Driver\ACPI_HAL \Device\00000042 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

—- EOF - GMER 1.0.15 —-
Thanks Ray,

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Happy Thanksgiving! Here is the ComboFix ComboFix 10-11-24.04 - Ray 11/25/2010 9:09.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3061.2035 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\hosts . ((((((((((((((((((((((((( Files Created from 2010-10-25 to 2010-11-25 ))))))))))))))))))))))))))))))) . 2010-11-25 14:15 . 2010-11-25 14:15 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-11-25 13:16 . 2010-11-10 04:33 6273872 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4D5F53EF-EC0B-4771-AEA6-69101ED5BE3C}\mpengine.dll 2010-11-24 22:19 . 2010-10-19 08:10 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2010-11-21 22:33 . 2010-11-21 22:44 ——– d—–w- c:\programdata\PCPitstop 2010-11-21 22:32 . 2010-11-21 22:32 ——– d—–w- c:\program files\PCPitstop 2010-11-21 20:01 . 2010-11-21 20:01 ——– d—–w- c:\program files\Common Files\McAfee 2010-11-21 20:01 . 2010-11-21 22:10 ——– d—–w- c:\program files\McAfee 2010-11-21 20:01 . 2010-11-21 20:01 ——– d—–w- c:\programdata\McAfee 2010-11-21 02:10 . 2010-11-21 02:10 ——– d—–w- c:\windows\system32\RTCOM 2010-11-20 18:19 . 2010-11-20 18:19 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2010-11-20 18:19 . 2010-11-20 18:19 ——– d—–w- c:\program files\SUPERAntiSpyware 2010-11-14 19:24 . 2010-05-11 17:00 20072 —-a-w- c:\windows\system32\drivers\cpuz133_x32.sys 2010-11-14 18:07 . 2009-04-02 16:33 2873820 ——w- c:\windows\system32\Sens_oal.dll 2010-11-14 17:49 . 2009-03-26 19:46 148480 —-a-w- c:\windows\system32\APOMngr.DLL 2010-11-14 17:49 . 2009-02-06 23:52 73728 —-a-w- c:\windows\system32\CmdRtr.DLL 2010-11-13 01:40 . 2010-11-20 21:44 ——– d—–w- c:\program files\Creative 2010-11-12 01:44 . 2010-11-20 21:45 413696 —-a-w- c:\windows\system32\wrap_oal.dll 2010-11-12 01:44 . 2010-11-20 21:45 110592 —-a-w- c:\windows\system32\OpenAL32.dll 2010-11-11 01:59 . 2006-10-06 19:17 53248 ——w- c:\windows\Ctregrun.exe 2010-11-11 01:29 . 2003-06-13 04:25 7062 —-a-w- c:\windows\system32\audiopid.vxd 2010-11-11 01:28 . 2010-11-11 01:28 ——– d—–w- c:\program files\Common Files\Creative Labs Shared 2010-11-11 01:27 . 2010-11-14 19:08 ——– d—–w- c:\programdata\Creative 2010-11-11 01:10 . 2007-03-13 01:51 45568 —-a-w- c:\windows\system32\ctppld.dll 2010-11-11 01:10 . 2007-11-26 08:21 171520 —-a-w- c:\windows\system32\ctdvinst.dll 2010-11-11 01:10 . 2007-11-26 08:21 86016 —-a-w- c:\windows\system32\ctcoinst.dll 2010-11-11 01:10 . 2010-11-11 01:10 390 —-a-w- c:\windows\ctrunonce.reg 2010-11-09 01:36 . 2010-11-09 01:36 ——– d—–w- c:\program files\CleanUp! 2010-11-08 23:48 . 2009-09-23 16:50 398336 —-a-w- c:\windows\system32\TVWizudlg.exe 2010-11-08 23:48 . 2009-09-23 16:49 140288 —-a-w- c:\windows\system32\igfxtvcx.dll 2010-11-08 23:48 . 2010-11-08 23:48 ——– d—–w- c:\windows\system32\Lang 2010-11-08 23:46 . 2010-11-08 23:46 ——– d—–w- c:\windows\system32\x64 2010-11-08 23:46 . 2009-09-24 00:30 1002008 —-a-w- c:\windows\system32\igxpun.exe 2010-11-07 23:40 . 2009-05-01 05:00 128392 —-a-w- c:\windows\system32\esdevapp.exe 2010-11-07 22:56 . 2010-11-10 04:33 6273872 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2010-11-07 22:55 . 2009-08-07 02:24 35552 —-a-w- c:\windows\system32\wups.dll 2010-11-07 22:55 . 2009-08-07 02:23 575704 —-a-w- c:\windows\system32\wuapi.dll 2010-11-07 22:55 . 2009-08-07 01:44 87552 —-a-w- c:\windows\system32\wudriver.dll 2010-11-07 22:55 . 2009-08-07 00:23 171608 —-a-w- c:\windows\system32\wuwebv.dll 2010-11-07 22:55 . 2009-08-06 23:44 33792 —-a-w- c:\windows\system32\wuapp.exe 2010-11-07 22:55 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll 2010-11-07 22:55 . 2009-08-07 02:24 53472 —-a-w- c:\windows\system32\wuauclt.exe 2010-11-07 22:55 . 2009-08-07 02:23 1929952 —-a-w- c:\windows\system32\wuaueng.dll 2010-11-07 22:55 . 2009-08-07 01:45 2421760 —-a-w- c:\windows\system32\wucltux.dll 2010-11-07 22:54 . 2010-11-07 22:58 ——– d—–w- C:\fddb45247a5b87ec8cd5dad7e15d 2010-11-07 22:51 . 2007-12-07 07:08 86528 —-a-w- c:\windows\system32\E_FLBEKA.DLL 2010-11-07 22:51 . 2007-12-07 07:01 78848 —-a-w- c:\windows\system32\E_FD4BEKA.DLL 2010-11-07 22:38 . 2009-08-18 18:44 53248 —-a-w- c:\windows\system32\CSVer.dll 2010-11-07 22:26 . 2010-10-16 18:55 888424 —-a-w- c:\windows\system32\nvdispco322050.dll 2010-11-07 22:26 . 2010-10-16 18:55 813672 —-a-w- c:\windows\system32\nvgenco322030.dll 2010-11-07 22:26 . 2010-10-16 18:55 57960 —-a-w- c:\windows\system32\OpenCL.dll 2010-11-07 22:26 . 2010-10-16 18:55 4837480 —-a-w- c:\windows\system32\nvcuda.dll 2010-11-07 22:26 . 2010-10-16 18:55 2912360 —-a-w- c:\windows\system32\nvcuvid.dll 2010-11-07 22:26 . 2010-10-16 18:55 2666600 —-a-w- c:\windows\system32\nvcuvenc.dll 2010-11-07 22:26 . 2010-10-16 18:55 14899816 —-a-w- c:\windows\system32\nvoglv32.dll 2010-11-07 22:26 . 2010-10-16 18:55 13019752 —-a-w- c:\windows\system32\nvcompiler.dll 2010-11-07 22:26 . 2010-10-16 18:55 10084360 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-11-07 21:54 . 2010-11-07 21:54 ——– d—–w- c:\programdata\UAB 2010-11-07 21:51 . 2010-11-07 21:51 ——– d—–w- c:\programdata\Driver Boost 2010-11-07 21:50 . 2010-11-07 21:50 ——– d—–w- c:\program files\DriverBoost 2010-11-07 21:13 . 2010-11-07 22:34 ——– d—–w- c:\programdata\DriverCure 2010-11-07 20:40 . 2010-09-24 22:13 739416 —-a-w- c:\windows\system32\MBAPO32.dll 2010-11-07 20:40 . 2010-07-03 00:40 70232 —-a-w- c:\windows\system32\MBWrp32.dll 2010-11-07 20:40 . 2010-11-07 20:56 ——– d—–w- c:\program files\Realtek 2010-11-07 20:37 . 2010-11-11 00:44 ——– d–h–w- c:\program files\Temp 2010-11-07 18:57 . 2010-09-23 07:46 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-11-07 18:34 . 2010-09-23 07:46 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-11-07 18:34 . 2010-11-07 18:34 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-11-07 18:24 . 2010-11-07 18:24 ——– dc-h–w- c:\programdata\{E961CE1B-C3EA-4882-9F67-F859B555D097} 2010-11-07 18:24 . 2010-11-07 18:34 ——– d—–w- c:\programdata\Lavasoft 2010-11-07 18:24 . 2010-11-07 18:24 ——– d—–w- c:\program files\Lavasoft 2010-11-07 16:45 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-11-07 16:45 . 2010-11-07 16:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-11-07 16:45 . 2010-11-07 16:45 ——– d—–w- c:\programdata\Malwarebytes 2010-11-07 16:45 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-11-07 15:54 . 2010-07-09 18:18 20328 —-a-w- c:\windows\system32\drivers\cpuz134_x32.sys 2010-11-07 15:54 . 2010-11-14 19:24 ——– d—–w- c:\program files\CPUID 2010-11-07 14:15 . 2010-11-07 14:15 ——– d—–w- c:\program files\MSXML 4.0 2010-11-07 04:39 . 2010-11-07 04:39 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2010-11-07 04:39 . 2010-11-07 04:39 4277016 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2010-11-07 04:28 . 2010-11-07 04:28 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2010-11-07 04:28 . 2010-11-07 04:28 588096 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2010-11-07 03:21 . 2010-11-07 03:21 ——– d—–w- c:\programdata\ArcSoft 2010-11-07 03:20 . 2010-11-07 04:53 ——– d—–w- c:\program files\ArcSoft 2010-11-07 03:20 . 2010-11-07 04:53 ——– d—–w- c:\program files\Common Files\ArcSoft 2010-11-07 03:19 . 2010-11-07 03:20 ——– d—–w- c:\program files\Common Files\Kodak 2010-11-07 03:19 . 2010-11-07 03:19 ——– d—–w- c:\program files\Kodak 2010-11-07 02:57 . 2010-11-07 03:21 ——– d—–w- c:\programdata\Kodak 2010-11-07 02:32 . 2010-11-07 02:32 ——– d—–w- c:\programdata\RoboForm 2010-11-07 02:31 . 2010-11-07 02:31 ——– d—–w- c:\program files\Siber Systems 2010-11-07 02:21 . 2010-11-07 02:21 160288 —-a-w- c:\windows\system32\drivers\afcdp.sys 2010-11-07 02:21 . 2010-11-07 02:21 911680 —-a-w- c:\windows\system32\drivers\tdrpm258.sys 2010-11-07 02:21 . 2010-11-07 02:21 581984 —-a-w- c:\windows\system32\drivers\timntr.sys 2010-11-07 02:21 . 2010-11-07 02:21 158272 —-a-w- c:\windows\system32\drivers\snapman.sys 2010-11-07 02:20 . 2010-11-07 02:21 ——– d—–w- c:\program files\Common Files\Acronis 2010-11-07 02:20 . 2010-11-07 02:20 ——– d—–w- c:\program files\Acronis 2010-11-07 01:17 . 2010-11-07 16:38 ——– d—–w- c:\programdata\STOPzilla! 2010-11-07 00:56 . 2010-11-07 00:56 ——– d—–w- c:\windows\en 2010-11-07 00:56 . 2010-11-07 18:34 ——– dc—-w- c:\windows\system32\DRVSTORE 2010-11-07 00:56 . 2010-11-07 00:56 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2010-11-07 00:55 . 2010-11-07 00:55 ——– d—–w- c:\windows\PCHEALTH 2010-11-07 00:55 . 2010-11-07 05:00 ——– d—–w- c:\program files\Windows Live 2010-11-07 00:55 . 2010-11-07 01:11 ——– d—–w- c:\program files\Microsoft 2010-11-07 00:54 . 2009-09-05 00:44 69464 —-a-w- c:\windows\system32\XAPOFX1_3.dll 2010-11-07 00:54 . 2009-09-05 00:44 515416 —-a-w- c:\windows\system32\XAudio2_5.dll 2010-11-07 00:54 . 2009-09-05 00:29 453456 —-a-w- c:\windows\system32\d3dx10_42.dll 2010-11-07 00:54 . 2006-11-29 20:06 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll 2010-11-07 00:18 . 2010-11-07 00:20 ——– d—–w- c:\windows\system32\DLA 2010-11-07 00:18 . 2007-02-09 19:34 51768 —-a-w- c:\windows\system32\drivers\DRVNDDM.SYS 2010-11-07 00:18 . 2007-02-09 03:05 28120 —-a-w- c:\windows\system32\drivers\DLARTL_M.SYS 2010-11-07 00:18 . 2007-02-09 03:05 12856 —-a-w- c:\windows\system32\drivers\DLACDBHM.SYS 2010-11-07 00:18 . 2006-10-26 23:21 92920 —-a-w- c:\windows\DLA.EXE 2010-11-07 00:18 . 2006-07-21 18:21 99176 —-a-w- c:\windows\system32\drivers\DRVMCDB.SYS 2010-11-07 00:17 . 2010-11-07 00:17 ——– d—–w- c:\programdata\Sonic 2010-11-07 00:16 . 2010-11-07 00:20 ——– d—–w- c:\programdata\Roxio 2010-11-07 00:14 . 2010-11-07 00:14 ——– d—–w- c:\programdata\InstallShield 2010-11-07 00:14 . 2010-11-07 00:18 ——– d—–w- c:\program files\Roxio 2010-11-06 23:56 . 2010-11-07 22:27 ——– d—–w- c:\programdata\NVIDIA 2010-11-06 23:33 . 2010-11-06 23:33 ——– d—–w- c:\program files\Common Files\Windows Live 2010-11-06 23:32 . 2010-11-06 23:32 ——– d—–w- c:\programdata\NVIDIA Corporation 2010-11-06 23:32 . 2010-11-07 22:27 ——– d—–w- c:\program files\NVIDIA Corporation 2010-11-06 23:31 . 2010-11-06 23:31 ——– d—–w- c:\program files\Microsoft Silverlight 2010-11-06 23:31 . 2010-05-23 10:11 196608 —-a-w- c:\windows\system32\mfreadwrite.dll 2010-11-06 23:31 . 2010-05-23 10:11 3181568 —-a-w- c:\windows\system32\mf.dll 2010-11-06 23:31 . 2010-05-23 10:15 1619456 —-a-w- c:\windows\system32\WMVDECOD.DLL 2010-11-06 23:30 . 2009-10-10 02:57 12800 —-a-w- c:\windows\system32\drivers\sffp_sd.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-10-16 18:55 . 2010-11-07 22:26 10920 —-a-w- c:\windows\system32\drivers\nvBridge.kmd 2010-10-16 18:55 . 2009-06-10 21:19 10023528 —-a-w- c:\windows\system32\nvd3dum.dll 2010-10-16 18:55 . 2007-05-14 07:33 1719912 —-a-w- c:\windows\system32\nvapi.dll 2010-10-16 17:42 . 2010-10-16 17:42 600680 —-a-w- c:\windows\system32\nvvsvc.exe 2010-10-16 17:42 . 2010-10-16 17:42 110696 —-a-w- c:\windows\system32\nvmctray.dll 2010-10-16 17:42 . 2010-10-16 17:42 3420776 —-a-w- c:\windows\system32\nvcpl.dll 2010-10-16 17:42 . 2010-10-16 17:42 2079336 —-a-w- c:\windows\system32\nvsvc.dll 2010-09-23 07:32 . 2010-09-23 07:32 301936 —-a-w- c:\windows\WLXPGSS.SCR 2010-09-21 21:03 . 2010-09-21 21:03 208768 —-a-w- c:\windows\system32\LIVESSP.DLL 2010-09-21 17:50 . 2010-09-21 17:50 182784 —-a-w- c:\windows\system32\Ncs2Setp.dll 2010-09-09 14:03 . 2010-09-09 14:03 239768 —-a-w- c:\windows\system32\PRONtObj.dll 2010-09-03 16:38 . 2010-09-03 16:38 657528 —-a-w- c:\windows\system32\ncs2dmix.dll 2010-09-03 16:38 . 2010-09-03 16:38 508536 —-a-w- c:\windows\system32\accesor.dll 2010-09-03 16:15 . 2010-09-03 16:15 134264 —-a-w- c:\windows\system32\ncs2instutility.dll 2010-09-03 15:57 . 2010-09-03 15:57 1842296 —-a-w- c:\windows\system32\ncscolib.dll 2010-09-02 05:26 . 2010-09-02 05:26 30368 —-a-w- c:\windows\system32\drivers\iqvw32.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-10-25 2424560] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504] "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-11-07 160328] "CTRegRun"="c:\windows\CTRegRun.EXE" [2006-10-06 53248] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-11-12 5106904] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552] "PC Pitstop PC Matic Reminder"="c:\program files\PCPitstop\PC Matic\Reminder-PCMatic.exe" [2010-10-13 324848] "P17RunE"="P17RunE.dll" [2008-03-28 14848] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592] "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-02-20 591696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-11-12 361632] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2010-1-27 323584] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-11-24 1375992] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [2010-05-20 88176] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-11-11 79360] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2010-11-07 15264] R3 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [2010-10-13 90864] R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2009-07-13 266752] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-06 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-09-23 64288] S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-11-07 911680] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824] S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-11-07 2480048] S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072] S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328] S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2010-08-12 87712] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-11-07 160288] S3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-02 44432] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-26 42368] . Contents of the 'Scheduled Tasks' folder 2010-11-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-23 22:17] . . ——- Supplementary Scan ——- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://www.yahoo.com/?ilc=1 mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html uSearchURL,(Default) = hxxp://search.yahoo.com IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab . - - - - ORPHANS REMOVED - - - - HKLM-Run-VolPanel - c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-343402584-3351777963-4057284205-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" [HKEY_USERS\S-1-5-21-343402584-3351777963-4057284205-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2010-11-25 09:16:23 ComboFix-quarantined-files.txt 2010-11-25 14:16 Pre-Run: 426,672,914,432 bytes free Post-Run: 426,645,372,928 bytes free - - End Of File - - 3F19EE90A8B2802CD900280098B5AA4B
Happy Thanksgiving Ray

Nothing really bad was removed and nothing bad on the log. There is an infection going around that sends sounds ( Ads Actually ) through the speakers , I was leaning towards this but none of the scans are picking it up.

Lets try a couple of more things.


  • Download TDSSKiller and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
  • Please post the content of the TDSSKiller log






Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
TDDSKiller Log 2010/11/25 10:47:08.0869 TDSS rootkit removing tool 2.4.8.0 Nov 17 2010 07:23:12 2010/11/25 10:47:08.0869 ================================================================================ 2010/11/25 10:47:08.0869 SystemInfo: 2010/11/25 10:47:08.0869 2010/11/25 10:47:08.0869 OS Version: 6.1.7600 ServicePack: 0.0 2010/11/25 10:47:08.0869 Product type: Workstation 2010/11/25 10:47:08.0869 ComputerName: RAY-PC 2010/11/25 10:47:08.0869 UserName: Ray 2010/11/25 10:47:08.0869 Windows directory: C:\Windows 2010/11/25 10:47:08.0869 System windows directory: C:\Windows 2010/11/25 10:47:08.0869 Processor architecture: Intel x86 2010/11/25 10:47:08.0869 Number of processors: 2 2010/11/25 10:47:08.0869 Page size: 0x1000 2010/11/25 10:47:08.0869 Boot type: Normal boot 2010/11/25 10:47:08.0869 ================================================================================ 2010/11/25 10:47:12.0364 Initialize success 2010/11/25 10:47:15.0031 ================================================================================ 2010/11/25 10:47:15.0031 Scan started 2010/11/25 10:47:15.0031 Mode: Manual; 2010/11/25 10:47:15.0031 ================================================================================ 2010/11/25 10:47:16.0482 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/11/25 10:47:16.0513 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 2010/11/25 10:47:16.0544 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/11/25 10:47:16.0576 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/11/25 10:47:16.0591 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 2010/11/25 10:47:16.0607 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 2010/11/25 10:47:16.0685 afcdp (ef1afa9752e468013584585666a3b119) C:\Windows\system32\DRIVERS\afcdp.sys 2010/11/25 10:47:16.0716 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 2010/11/25 10:47:16.0732 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 2010/11/25 10:47:16.0778 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 2010/11/25 10:47:16.0794 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 2010/11/25 10:47:16.0810 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 2010/11/25 10:47:16.0841 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 2010/11/25 10:47:16.0856 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 2010/11/25 10:47:16.0872 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 2010/11/25 10:47:16.0903 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 2010/11/25 10:47:16.0919 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/11/25 10:47:16.0934 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 2010/11/25 10:47:16.0950 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 2010/11/25 10:47:16.0997 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 2010/11/25 10:47:17.0028 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 2010/11/25 10:47:17.0059 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/11/25 10:47:17.0075 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 2010/11/25 10:47:17.0122 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 2010/11/25 10:47:17.0137 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 2010/11/25 10:47:17.0184 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 2010/11/25 10:47:17.0200 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/11/25 10:47:17.0231 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 2010/11/25 10:47:17.0246 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/11/25 10:47:17.0262 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/11/25 10:47:17.0293 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 2010/11/25 10:47:17.0340 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/11/25 10:47:17.0356 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/11/25 10:47:17.0371 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/11/25 10:47:17.0402 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/11/25 10:47:17.0543 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 2010/11/25 10:47:17.0590 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 2010/11/25 10:47:17.0605 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 2010/11/25 10:47:17.0652 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 2010/11/25 10:47:17.0683 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/11/25 10:47:17.0699 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 2010/11/25 10:47:17.0730 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 2010/11/25 10:47:17.0761 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 2010/11/25 10:47:17.0777 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/11/25 10:47:17.0839 cpuz133 (743c403d20a89db5ed84c874768b7119) C:\Windows\system32\drivers\cpuz133_x32.sys 2010/11/25 10:47:17.0886 cpuz134 (75fa19142531cbf490770c2988a7db64) C:\Windows\system32\drivers\cpuz134_x32.sys 2010/11/25 10:47:17.0917 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/11/25 10:47:17.0995 dc3d (b6672f62f75fb952d7ae7cb4e80011a9) C:\Windows\system32\DRIVERS\dc3d.sys 2010/11/25 10:47:18.0042 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 2010/11/25 10:47:18.0058 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 2010/11/25 10:47:18.0104 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 2010/11/25 10:47:18.0151 DLABMFSM (a53723176d0002feb486eff8e17812f2) C:\Windows\system32\DLA\DLABMFSM.SYS 2010/11/25 10:47:18.0167 DLABOIOM (d4587063acea776699251e177d719586) C:\Windows\system32\DLA\DLABOIOM.SYS 2010/11/25 10:47:18.0198 DLACDBHM (5230cdb7e715f3a3b4a882e254cdd35d) C:\Windows\system32\Drivers\DLACDBHM.SYS 2010/11/25 10:47:18.0214 DLADResM (c950c2e7b9ed1a4fc4a2ac7ec044f1d6) C:\Windows\system32\DLA\DLADResM.SYS 2010/11/25 10:47:18.0245 DLAIFS_M (24400137e387a24410c52a591f3cfb4d) C:\Windows\system32\DLA\DLAIFS_M.SYS 2010/11/25 10:47:18.0260 DLAOPIOM (29a303feceb28641ecebdae89eb71c63) C:\Windows\system32\DLA\DLAOPIOM.SYS 2010/11/25 10:47:18.0276 DLAPoolM (c93e33a22a1ae0c5508f3fb1f6d0a50c) C:\Windows\system32\DLA\DLAPoolM.SYS 2010/11/25 10:47:18.0307 DLARTL_M (77fe51f0f8d86804cb81f6ef6bfb86dd) C:\Windows\system32\Drivers\DLARTL_M.SYS 2010/11/25 10:47:18.0323 DLAUDFAM (b953498c35a31e5ac98f49adbcf3e627) C:\Windows\system32\DLA\DLAUDFAM.SYS 2010/11/25 10:47:18.0354 DLAUDF_M (4897704c093c1f59ce58fc65e1e1ef1e) C:\Windows\system32\DLA\DLAUDF_M.SYS 2010/11/25 10:47:18.0401 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 2010/11/25 10:47:18.0432 DRVMCDB (c00440385cf9f3d142917c63f989e244) C:\Windows\system32\Drivers\DRVMCDB.SYS 2010/11/25 10:47:18.0448 DRVNDDM (ffc371525aa55d1bae18715ebcb8797c) C:\Windows\system32\Drivers\DRVNDDM.SYS 2010/11/25 10:47:18.0494 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys 2010/11/25 10:47:18.0557 e1express (339cbffbbc29580dbc3b235f2fb74f74) C:\Windows\system32\DRIVERS\e1e6232.sys 2010/11/25 10:47:18.0666 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 2010/11/25 10:47:18.0760 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 2010/11/25 10:47:18.0806 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 2010/11/25 10:47:18.0869 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 2010/11/25 10:47:18.0884 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 2010/11/25 10:47:18.0916 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 2010/11/25 10:47:18.0947 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 2010/11/25 10:47:18.0978 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 2010/11/25 10:47:18.0994 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/11/25 10:47:19.0025 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 2010/11/25 10:47:19.0056 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 2010/11/25 10:47:19.0087 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 2010/11/25 10:47:19.0118 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys 2010/11/25 10:47:19.0134 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/11/25 10:47:19.0165 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 2010/11/25 10:47:19.0243 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 2010/11/25 10:47:19.0259 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/11/25 10:47:19.0306 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/11/25 10:47:19.0321 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 2010/11/25 10:47:19.0352 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 2010/11/25 10:47:19.0399 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 2010/11/25 10:47:19.0430 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/11/25 10:47:19.0462 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 2010/11/25 10:47:19.0493 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 2010/11/25 10:47:19.0508 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/11/25 10:47:19.0540 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/11/25 10:47:19.0820 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 2010/11/25 10:47:19.0867 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 2010/11/25 10:47:19.0961 IntcAzAudAddService (f8f53c5449f15b23d4c61d51d2701da8) C:\Windows\system32\drivers\RTKVHDA.sys 2010/11/25 10:47:20.0008 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 2010/11/25 10:47:20.0023 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 2010/11/25 10:47:20.0054 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/11/25 10:47:20.0086 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/11/25 10:47:20.0101 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 2010/11/25 10:47:20.0132 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 2010/11/25 10:47:20.0148 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 2010/11/25 10:47:20.0164 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/11/25 10:47:20.0210 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/11/25 10:47:20.0226 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/11/25 10:47:20.0257 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 2010/11/25 10:47:20.0288 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys 2010/11/25 10:47:20.0413 Lavasoft Kernexplorer (0bd6d3f477df86420de942a741dabe37) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 2010/11/25 10:47:20.0460 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys 2010/11/25 10:47:20.0491 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/11/25 10:47:20.0538 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/11/25 10:47:20.0554 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/11/25 10:47:20.0585 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/11/25 10:47:20.0616 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/11/25 10:47:20.0632 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 2010/11/25 10:47:20.0663 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 2010/11/25 10:47:20.0710 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/11/25 10:47:20.0741 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 2010/11/25 10:47:20.0756 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 2010/11/25 10:47:20.0788 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 2010/11/25 10:47:20.0803 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 2010/11/25 10:47:20.0819 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 2010/11/25 10:47:20.0866 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\Windows\system32\DRIVERS\MpFilter.sys 2010/11/25 10:47:20.0897 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 2010/11/25 10:47:20.0912 MpNWMon (aeb186afff5d9cfed823c15d846aac3b) C:\Windows\system32\DRIVERS\MpNWMon.sys 2010/11/25 10:47:20.0928 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 2010/11/25 10:47:20.0959 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 2010/11/25 10:47:21.0006 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/11/25 10:47:21.0022 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/11/25 10:47:21.0053 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/11/25 10:47:21.0084 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 2010/11/25 10:47:21.0115 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 2010/11/25 10:47:21.0146 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 2010/11/25 10:47:21.0178 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 2010/11/25 10:47:21.0193 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/11/25 10:47:21.0256 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 2010/11/25 10:47:21.0318 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/11/25 10:47:21.0334 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 2010/11/25 10:47:21.0349 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 2010/11/25 10:47:21.0396 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/11/25 10:47:21.0443 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 2010/11/25 10:47:21.0474 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/11/25 10:47:21.0490 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 2010/11/25 10:47:21.0568 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 2010/11/25 10:47:21.0599 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 2010/11/25 10:47:21.0630 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/11/25 10:47:21.0661 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/11/25 10:47:21.0692 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/11/25 10:47:21.0708 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/11/25 10:47:21.0724 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 2010/11/25 10:47:21.0755 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 2010/11/25 10:47:21.0770 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 2010/11/25 10:47:21.0817 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/11/25 10:47:21.0864 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 2010/11/25 10:47:21.0880 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 2010/11/25 10:47:21.0942 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 2010/11/25 10:47:21.0989 NuidFltr (ef2b9a14ec5dd74ade3417faf1b45e16) C:\Windows\system32\DRIVERS\NuidFltr.sys 2010/11/25 10:47:22.0020 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 2010/11/25 10:47:22.0628 nvlddmkm (bd409de5681c74c1de51d72427dc202d) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2010/11/25 10:47:22.0722 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/11/25 10:47:22.0753 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 2010/11/25 10:47:22.0784 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/11/25 10:47:22.0816 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/11/25 10:47:22.0862 P17 (da4be540a939471779d0593b59d6ccc1) C:\Windows\system32\drivers\P17.sys 2010/11/25 10:47:22.0909 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 2010/11/25 10:47:22.0925 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 2010/11/25 10:47:22.0940 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 2010/11/25 10:47:22.0972 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 2010/11/25 10:47:23.0003 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 2010/11/25 10:47:23.0018 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/11/25 10:47:23.0050 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 2010/11/25 10:47:23.0081 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 2010/11/25 10:47:23.0174 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 2010/11/25 10:47:23.0206 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 2010/11/25 10:47:23.0237 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 2010/11/25 10:47:23.0284 PxHelp20 (feffcfdc528764a04c8ed63d5fa6e711) C:\Windows\system32\Drivers\PxHelp20.sys 2010/11/25 10:47:23.0346 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 2010/11/25 10:47:23.0377 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/11/25 10:47:23.0408 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 2010/11/25 10:47:23.0424 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 2010/11/25 10:47:23.0471 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/11/25 10:47:23.0486 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/11/25 10:47:23.0518 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/11/25 10:47:23.0533 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 2010/11/25 10:47:23.0549 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 2010/11/25 10:47:23.0580 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/11/25 10:47:23.0611 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/11/25 10:47:23.0627 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 2010/11/25 10:47:23.0658 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 2010/11/25 10:47:23.0705 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 2010/11/25 10:47:23.0720 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 2010/11/25 10:47:23.0767 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 2010/11/25 10:47:23.0876 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2010/11/25 10:47:23.0908 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2010/11/25 10:47:23.0939 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/11/25 10:47:23.0970 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 2010/11/25 10:47:24.0017 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/11/25 10:47:24.0064 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 2010/11/25 10:47:24.0095 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 2010/11/25 10:47:24.0126 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 2010/11/25 10:47:24.0188 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/11/25 10:47:24.0204 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/11/25 10:47:24.0235 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/11/25 10:47:24.0266 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/11/25 10:47:24.0298 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 2010/11/25 10:47:24.0329 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/11/25 10:47:24.0360 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/11/25 10:47:24.0407 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 2010/11/25 10:47:24.0485 snapman (5bceb1b306878035dacba6dd18366eda) C:\Windows\system32\DRIVERS\snapman.sys 2010/11/25 10:47:24.0500 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 2010/11/25 10:47:24.0563 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\Windows\system32\DRIVERS\srv.sys 2010/11/25 10:47:24.0610 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\Windows\system32\DRIVERS\srv2.sys 2010/11/25 10:47:24.0641 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\Windows\system32\DRIVERS\srvnet.sys 2010/11/25 10:47:24.0688 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 2010/11/25 10:47:24.0734 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 2010/11/25 10:47:24.0844 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys 2010/11/25 10:47:24.0984 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys 2010/11/25 10:47:25.0015 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 2010/11/25 10:47:25.0046 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 2010/11/25 10:47:25.0093 tdrpman258 (8de3e45000ba8c9ebb16737d3f83e216) C:\Windows\system32\DRIVERS\tdrpm258.sys 2010/11/25 10:47:25.0109 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 2010/11/25 10:47:25.0140 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 2010/11/25 10:47:25.0156 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 2010/11/25 10:47:25.0218 timounter (3e06987fedbcdfbff8e85ef8108565f9) C:\Windows\system32\DRIVERS\timntr.sys 2010/11/25 10:47:25.0265 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/11/25 10:47:25.0296 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 2010/11/25 10:47:25.0343 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 2010/11/25 10:47:25.0374 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 2010/11/25 10:47:25.0421 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/11/25 10:47:25.0436 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 2010/11/25 10:47:25.0468 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 2010/11/25 10:47:25.0483 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/11/25 10:47:25.0514 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 2010/11/25 10:47:25.0546 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 2010/11/25 10:47:25.0561 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 2010/11/25 10:47:25.0592 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 2010/11/25 10:47:25.0624 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 2010/11/25 10:47:25.0686 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 2010/11/25 10:47:25.0702 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/11/25 10:47:25.0733 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/11/25 10:47:25.0748 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/11/25 10:47:25.0795 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/11/25 10:47:25.0811 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 2010/11/25 10:47:25.0842 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/11/25 10:47:25.0873 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 2010/11/25 10:47:25.0904 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 2010/11/25 10:47:25.0920 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 2010/11/25 10:47:25.0936 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/11/25 10:47:25.0967 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 2010/11/25 10:47:25.0982 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 2010/11/25 10:47:26.0014 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/11/25 10:47:26.0060 VSTHWBS2 (682fcf7d2eb5158cd30408e976562408) C:\Windows\system32\DRIVERS\VSTBS23.SYS 2010/11/25 10:47:26.0092 VST_DPV (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 2010/11/25 10:47:26.0123 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 2010/11/25 10:47:26.0154 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 2010/11/25 10:47:26.0185 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/25 10:47:26.0185 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/25 10:47:26.0232 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 2010/11/25 10:47:26.0263 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2010/11/25 10:47:26.0326 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/11/25 10:47:26.0341 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 2010/11/25 10:47:26.0388 winachsf (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 2010/11/25 10:47:26.0466 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/11/25 10:47:26.0513 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/11/25 10:47:26.0560 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 2010/11/25 10:47:26.0591 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/11/25 10:47:26.0653 ================================================================================ 2010/11/25 10:47:26.0653 Scan finished 2010/11/25 10:47:26.0653 ================================================================================ ESET Log ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1d82131aca555946a27b5fbea92516fd # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-25 05:09:05 # local_time=2010-11-25 12:09:05 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=5891 16776573 100 100 0 20201327 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=205637 # found=1 # cleaned=1 # scan_time=4196 K:\Good Back up\Backup of Drive C ©\Documents and Settings\Ray J\Local Settings\Temporary Internet Files\Content.IE5\INEJX01H\index[1].htm HTML/ScrInject.B.Gen virus (deleted - quarantined) 00000000000000000000000000000000
Hello Ray,

No signs of a rootkit that could be causing those sounds.

Lets run one more scan to see if it picks up something the others have not.

Random System Information Tool
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Good Morning Ray, I need to have you do a few things and answer some questions please . If you have not run RSIT yet, go ahead and run it, this scan may pick up something the others have not and post the logs. 1. Did you get these tones prior to upgrading to Win 7 ? 2. Are you experiencing anything else that would make you think your computer is infected in the form of pop up windows, are your searches being redirected ? 3. I need you to power off and disconnect your external hard drive ( physically disconnect the cables) , did this stop the tones from your speakers ? 4. With your external drive powered off and disconnected, reboot your computer * Did your computer boot up normally ? * Do you still hear the tones ? 5. Drag the log from MBRCheck to the trash and with the external drive still disconnected run the program again and post the new log please

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI