This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CPU Usage 90% and slow Internet speed

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I have a HP Touch Smart 300 PC with 4 GB Ram, 2.70 GHz Processor and Windows 7 Home premium(64 bit).

Have noticed for the last month or so that my CPU speed goes almost upto 100% when I am downloading stuff over the internet. or watching video content(like Yahoo Movie trailers/You tube etc). At that time, the sound and video starts stuttering. Once the download or viewing stops, the CPU is back to normal. At the same time, the internet speed also has slowed down considerably. I have cable connection and the download speed always shows up around 8 Mb/s. Whereas i have an office laptop on the same wireless(with lesser config than my machine), where the speed shows up as 14 Mb/s. I normally use Firefox(3.6), but the same issue is with IE as well.

Here is the log file from Hijack this as well. Appreciate any help!!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:26:07 AM, on 12/6/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\JAN2OSD.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Thomas\Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ire&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ire&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ire&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ire&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [HP KEYBOARDx] "C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE"
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Buttons & OSDs control application gen3] c:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
O4 - HKCU\..\Run: [Google Update] "C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.tvnsports.com/vjocx-en-black.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10966 bytes
Hi,


Please do the following:


Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


NEXT



  • Download OTL and save it to your desktop.
  • Double click on the [external image: Posted Image] icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks for the response CatByte.

(1) Here is the output from MBRCheck

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: PEGATRON CORPORATION
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: HP-Pavilion
System Product Name: NY644AA-ABA 300-1003
Logical Drives Mask: 0x0000007c

Kernel Drivers (total 206):
0x02A0E000 \SystemRoot\system32\ntoskrnl.exe
0x02FEA000 \SystemRoot\system32\hal.dll
0x00BD4000 \SystemRoot\system32\kdcom.dll
0x00CD4000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x00CE1000 \SystemRoot\system32\PSHED.dll
0x00CF5000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00D53000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00CC0000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00ED5000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00F2C000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00F35000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00F3F000 \SystemRoot\system32\DRIVERS\pci.sys
0x00F72000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00F7F000 \SystemRoot\System32\drivers\partmgr.sys
0x00F94000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00E00000 \SystemRoot\System32\drivers\volmgrx.sys
0x00E5C000 \SystemRoot\System32\drivers\mountmgr.sys
0x00E76000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x0109D000 \SystemRoot\system32\DRIVERS\storport.sys
0x010FF000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x0110A000 \SystemRoot\system32\drivers\fltmgr.sys
0x01156000 \SystemRoot\system32\drivers\fileinfo.sys
0x01251000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0116A000 \SystemRoot\System32\Drivers\msrpc.sys
0x01200000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01000000 \SystemRoot\System32\Drivers\cng.sys
0x0121A000 \SystemRoot\System32\drivers\pcw.sys
0x0122B000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01435000 \SystemRoot\system32\drivers\ndis.sys
0x01527000 \SystemRoot\system32\drivers\NETIO.SYS
0x01587000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01602000 \SystemRoot\System32\drivers\tcpip.sys
0x015B2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x00FA9000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01400000 \SystemRoot\System32\Drivers\spldr.sys
0x00E8A000 \SystemRoot\System32\drivers\rdyboost.sys
0x01408000 \SystemRoot\System32\Drivers\mup.sys
0x0141A000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01880000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x018BA000 \SystemRoot\system32\DRIVERS\disk.sys
0x018D0000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01900000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys
0x0190A000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x01951000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0197B000 \SystemRoot\System32\Drivers\Null.SYS
0x01984000 \SystemRoot\System32\Drivers\Beep.SYS
0x0198B000 \SystemRoot\System32\drivers\vga.sys
0x01999000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x019BE000 \SystemRoot\System32\drivers\watchdog.sys
0x019CE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x019D7000 \SystemRoot\system32\drivers\rdpencdd.sys
0x019E0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x019E9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01800000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01811000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0182F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x0183C000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x02C58000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02C9D000 \SystemRoot\system32\drivers\afd.sys
0x02D27000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x02D31000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02D3A000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02D60000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02D76000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02D85000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02DA0000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02C00000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02DB4000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02DC0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02DCB000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0x02DD6000 \SystemRoot\System32\drivers\discache.sys
0x0184C000 \SystemRoot\System32\Drivers\dfsc.sys
0x02DE5000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x01073000 \SystemRoot\System32\Drivers\aswSP.SYS
0x011C8000 \SystemRoot\SysWOW64\drivers\archlp.sys
0x03AEB000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x03B11000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x03B26000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x03CFD000 \SystemRoot\system32\DRIVERS\atipmdag.sys
0x03C00000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04361000 \SystemRoot\System32\drivers\dxgmms1.sys
0x03A00000 \SystemRoot\system32\DRIVERS\netr28x.sys
0x043A7000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x043B4000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x043F1000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x03B5A000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x03BB0000 \SystemRoot\system32\DRIVERS\usbfilter.sys
0x03BBC000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x03BCD000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x03CF4000 \SystemRoot\system32\DRIVERS\OSDACPI.SYS
0x03AB3000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x03AC3000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04497000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x044BB000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x044C7000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x044F6000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04511000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04532000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x0454C000 \SystemRoot\system32\DRIVERS\tap0901.sys
0x04559000 \SystemRoot\System32\Drivers\pcouffin.sys
0x0456E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x0457D000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x0458C000 \SystemRoot\system32\DRIVERS\VClone.sys
0x0459B000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x045CA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04400000 \SystemRoot\system32\DRIVERS\ks.sys
0x04443000 \SystemRoot\system32\DRIVERS\circlass.sys
0x04455000 \SystemRoot\system32\DRIVERS\umbus.sys
0x052E7000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x05341000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05356000 \SystemRoot\system32\drivers\ADIHdAud.sys
0x05200000 \SystemRoot\system32\drivers\portcls.sys
0x0523D000 \SystemRoot\system32\drivers\drmk.sys
0x0525F000 \SystemRoot\system32\drivers\ksthunk.sys
0x05265000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x05280000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x05282000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x0529F000 \SystemRoot\system32\DRIVERS\NW1950.sys
0x064BD000 \SystemRoot\system32\DRIVERS\NWTransLib.sys
0x06D2C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x000A0000 \SystemRoot\System32\win32k.sys
0x06D35000 \SystemRoot\System32\drivers\Dxapi.sys
0x06D41000 \SystemRoot\System32\drivers\mshidkmdf.sys
0x06D49000 \SystemRoot\System32\drivers\HIDCLASS.SYS
0x06D62000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x06D70000 \SystemRoot\system32\DRIVERS\MTConfig.sys
0x06D7A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x06D87000 \SystemRoot\system32\DRIVERS\usbcir.sys
0x06DA6000 \SystemRoot\System32\Drivers\usbvideo.sys
0x06DD4000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x06DE2000 \SystemRoot\system32\DRIVERS\hidir.sys
0x06400000 \SystemRoot\System32\Drivers\crashdmp.sys
0x0640E000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x06418000 \SystemRoot\System32\Drivers\dump_amdsata.sys
0x0642C000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x0643F000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00550000 \SystemRoot\System32\TSDDD.dll
0x00630000 \SystemRoot\System32\cdd.dll
0x00810000 \SystemRoot\System32\ATMFD.DLL
0x0644D000 \SystemRoot\system32\drivers\luafv.sys
0x06470000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x064AA000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x052AA000 \SystemRoot\system32\drivers\WudfPf.sys
0x052CB000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x0344E000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x034A1000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x034B4000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x034CC000 \SystemRoot\system32\drivers\HTTP.sys
0x03594000 \SystemRoot\system32\DRIVERS\bowser.sys
0x035B2000 \SystemRoot\System32\drivers\mpsdrv.sys
0x035CA000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x03400000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x053D6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x05E97000 \SystemRoot\system32\drivers\peauth.sys
0x05F3D000 \SystemRoot\System32\Drivers\secdrv.SYS
0x05F48000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x05F75000 \SystemRoot\System32\drivers\tcpipreg.sys
0x05F87000 \SystemRoot\System32\DRIVERS\srv2.sys
0x05E00000 \SystemRoot\System32\DRIVERS\srv.sys
0x045CC000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x05FEE000 \??\C:\Windows\system32\drivers\mbam.sys
0x04467000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x035F7000 \SystemRoot\System32\drivers\pxkbf.sys
0x01926000 \SystemRoot\System32\drivers\pxrts.sys
0x06DF3000 \SystemRoot\System32\drivers\pxscan.sys
0x772B0000 \Windows\System32\ntdll.dll
0x484C0000 \Windows\System32\smss.exe
0xFF5D0000 \Windows\System32\apisetschema.dll
0xFFA70000 \Windows\System32\autochk.exe
0xFF540000 \Windows\System32\shlwapi.dll
0xFF4A0000 \Windows\System32\clbcatq.dll
0x77480000 \Windows\System32\normaliz.dll
0xFF3D0000 \Windows\System32\usp10.dll
0xFF380000 \Windows\System32\ws2_32.dll
0xFE5F0000 \Windows\System32\shell32.dll
0xFE5E0000 \Windows\System32\lpk.dll
0xFE540000 \Windows\System32\comdlg32.dll
0xFE410000 \Windows\System32\wininet.dll
0x77470000 \Windows\System32\psapi.dll
0xFE1B0000 \Windows\System32\iertutil.dll
0xFDFA0000 \Windows\System32\ole32.dll
0x77190000 \Windows\System32\kernel32.dll
0xFDE90000 \Windows\System32\msctf.dll
0xFDE70000 \Windows\System32\sechost.dll
0xFDE00000 \Windows\System32\gdi32.dll
0xFDD80000 \Windows\System32\difxapi.dll
0xFDD30000 \Windows\System32\Wldap32.dll
0xFDD10000 \Windows\System32\imagehlp.dll
0x77090000 \Windows\System32\user32.dll
0xFDC30000 \Windows\System32\advapi32.dll
0xFDAB0000 \Windows\System32\urlmon.dll
0xFD8D0000 \Windows\System32\setupapi.dll
0xFD830000 \Windows\System32\msvcrt.dll
0xFD700000 \Windows\System32\rpcrt4.dll
0xFD620000 \Windows\System32\oleaut32.dll
0xFD610000 \Windows\System32\nsi.dll
0xFD5E0000 \Windows\System32\imm32.dll
0xFD5A0000 \Windows\System32\wintrust.dll
0xFD580000 \Windows\System32\devobj.dll
0xFD410000 \Windows\System32\crypt32.dll
0xFD370000 \Windows\System32\comctl32.dll
0xFD300000 \Windows\System32\KernelBase.dll
0xFD2C0000 \Windows\System32\cfgmgr32.dll
0xFD2B0000 \Windows\System32\msasn1.dll
0x75110000 \Windows\SysWOW64\normaliz.dll

Processes (total 66):
0 System Idle Process
4 System
260 C:\Windows\System32\smss.exe
408 csrss.exe
504 csrss.exe
512 C:\Windows\System32\wininit.exe
564 C:\Windows\System32\services.exe
572 C:\Windows\System32\lsass.exe
580 C:\Windows\System32\lsm.exe
616 C:\Windows\System32\winlogon.exe
720 C:\Windows\System32\svchost.exe
816 C:\Windows\System32\svchost.exe
908 C:\Windows\System32\svchost.exe
940 C:\Windows\System32\svchost.exe
964 C:\Windows\System32\svchost.exe
496 C:\Windows\System32\svchost.exe
800 C:\Windows\System32\svchost.exe
1208 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
1240 C:\Windows\System32\wisptis.exe
1556 C:\Windows\System32\spoolsv.exe
1608 C:\Windows\System32\svchost.exe
1756 C:\Windows\System32\svchost.exe
1824 C:\Windows\System32\taskhost.exe
1932 C:\Windows\System32\wisptis.exe
1972 C:\Windows\System32\dwm.exe
1980 C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
2016 C:\Windows\explorer.exe
2032 C:\Windows\System32\svchost.exe
1696 C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
2288 C:\Windows\System32\taskeng.exe
2520 C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
2608 WUDFHost.exe
2964 C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
2168 C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
2232 C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
1180 C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
1188 C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
2028 C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
2008 C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
2532 C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\JAN2OSD.exe
2712 C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
2796 C:\Windows\System32\SearchIndexer.exe
2500 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
3188 C:\Windows\System32\taskeng.exe
3280 C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
3288 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
3296 C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
3312 C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
3340 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
3544 WmiPrvSE.exe
3848 C:\Program Files\Windows Media Player\wmpnetwk.exe
660 C:\Windows\System32\svchost.exe
3148 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
1576 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
3084 C:\Windows\System32\svchost.exe
2640 C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
308 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
3952 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
3500 C:\Users\Thomas\Desktop\MovieCollector.exe
4460 C:\Windows\System32\audiodg.exe
8004 C:\Windows\SysWOW64\ctfmon.exe
7664 C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
1868 C:\Users\Thomas\Desktop\MBRCheck.exe
3436 C:\Windows\System32\conhost.exe
6928 C:\Windows\System32\dllhost.exe
8968 taskhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000091`daf00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHDT721064SLA360, Rev: STDOA39D

Size Device Name MBR Status
——————————————–
596 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 97FE8AB43E8297853BCC42EC189039D862003A31


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!

(2) Here is the output from OTL.txt

OTL logfile created on: 12/9/2010 8:15:33 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Thomas\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.32 Gb Total Space | 8.49 Gb Free Space | 1.45% Space Free | Partition Type: NTFS
Drive D: | 12.75 Gb Total Space | 2.29 Gb Free Space | 17.98% Space Free | Partition Type: NTFS

Computer Name: THOMAS-PC | User Name: Thomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/12/09 07:20:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Thomas\Desktop\OTL.exe
PRC - [2010/09/07 09:12:02 | 002,838,912 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 09:11:59 | 000,040,384 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/03/29 23:46:14 | 000,303,952 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/03/18 06:25:12 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/20 13:50:34 | 000,128,296 | —- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/07/15 09:58:40 | 000,715,264 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
PRC - [2009/07/09 13:21:32 | 000,385,024 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\JAN2OSD.exe
PRC - [2009/07/03 12:17:50 | 000,212,992 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
PRC - [2009/07/02 15:58:40 | 000,406,016 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
PRC - [2009/06/22 15:58:44 | 003,866,624 | —- | M] (Analog Devices, Inc.) – C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
PRC - [2009/06/22 08:57:30 | 001,314,816 | —- | M] (Analog Devices, Inc.) – C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
PRC - [2009/06/17 05:44:11 | 000,085,160 | —- | M] (Elaborate Bytes AG) – C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
PRC - [2009/05/26 02:36:13 | 000,656,896 | —- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2008/11/20 11:47:28 | 000,062,768 | —- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2010/12/09 07:20:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Thomas\Desktop\OTL.exe
MOD - [2010/08/20 23:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Stopped] – C:\Windows\SysNative\nagasoft\vjocx.dll – (vvdsvc)
SRV:64bit: - [2010/12/08 12:19:46 | 006,746,280 | —- | M] (Prevx) [Auto | Stopped] – C:\Program Files\Prevx\prevx.exe – (CSIScanner)
SRV:64bit: - [2010/09/07 09:11:59 | 000,040,384 | —- | M] (AVAST Software) [On_Demand | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV:64bit: - [2010/09/07 09:11:59 | 000,040,384 | —- | M] (AVAST Software) [On_Demand | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV:64bit: - [2010/09/07 09:11:59 | 000,040,384 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2010/07/28 08:07:16 | 002,404,488 | —- | M] (mobile concepts GmbH) [Disabled | Stopped] – C:\Program Files\S.A.D\CyberGhost VPN\CGVPNCliService.exe – (CGVPNCliSrvc)
SRV:64bit: - [2010/02/02 22:17:12 | 000,202,752 | —- | M] (AMD) [Disabled | Stopped] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/07/13 19:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2008/07/15 07:09:48 | 000,111,616 | —- | M] (Andrea Electronics Corporation) [Disabled | Stopped] – C:\Windows\SysNative\AEADISRV.EXE – (AEADIFilters)
SRV - [2010/03/29 23:46:14 | 000,303,952 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/30 00:13:48 | 000,867,080 | —- | M] (Acresso Software Inc.) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2009/07/09 12:05:00 | 000,021,560 | —- | M] (Hewlett-Packard) [Disabled | Stopped] – C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe – (CalendarSynchService)
SRV - [2009/06/10 15:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/22 12:02:20 | 000,250,616 | —- | M] (WildTangent, Inc.) [Disabled | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2009/03/18 14:04:44 | 001,685,024 | —- | M] (NanJing Nagasoft Co, LTD.) [Auto | Stopped] – C:\Windows\SysWOW64\nagasoft\vjocx.dll – (vvdsvc)
SRV - [2009/01/26 14:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Disabled | Stopped] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/12/08 12:19:47 | 000,065,736 | —- | M] (Prevx) [File_System | System | Running] – C:\Windows\SysNative\drivers\pxrts.sys – (pxrts)
DRV:64bit: - [2010/12/08 12:19:47 | 000,036,384 | —- | M] (Prevx) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pxscan.sys – (pxscan)
DRV:64bit: - [2010/12/08 12:19:46 | 000,024,024 | —- | M] (Prevx) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\pxkbf.sys – (pxkbf)
DRV:64bit: - [2010/09/13 15:28:00 | 000,027,216 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AVGIDSEH.sys – (AVGIDSEH)
DRV:64bit: - [2010/09/07 08:47:33 | 000,061,008 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2010/03/29 23:45:56 | 000,024,664 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2010/02/25 17:51:02 | 000,029,696 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tap0901.sys – (tap0901)
DRV:64bit: - [2010/02/05 19:04:06 | 000,028,728 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/02/05 19:04:04 | 000,070,712 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2010/02/02 22:55:20 | 006,366,720 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2010/02/02 22:55:20 | 006,366,720 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atipmdag.sys – (amdkmdag)
DRV:64bit: - [2010/02/02 21:24:00 | 000,186,880 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2009/12/17 22:34:16 | 000,082,816 | —- | M] (VSO Software) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\pcouffin.sys – (pcouffin)
DRV:64bit: - [2009/12/17 16:25:17 | 000,034,472 | —- | M] (Elaborate Bytes AG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ElbyCDIO.sys – (ElbyCDIO)
DRV:64bit: - [2009/08/09 15:25:45 | 000,036,352 | —- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VClone.sys – (VClone)
DRV:64bit: - [2009/07/29 04:37:10 | 000,013,816 | —- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hidkmdf.sys – (hidkmdf)
DRV:64bit: - [2009/07/29 04:37:08 | 000,024,568 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NW1950.sys – (NW1950)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 08:31:42 | 000,233,472 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/06/22 09:01:26 | 000,497,152 | —- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ADIHdAud.sys – (ADIHdAudAddService)
DRV:64bit: - [2009/06/17 12:08:24 | 000,017,992 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\OSDACPI.SYS – (ACPIService)
DRV:64bit: - [2009/06/10 14:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/19 15:48:42 | 000,702,976 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2009/05/05 04:00:28 | 000,016,440 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\AtiPcie.sys – (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/03 07:39:58 | 000,034,872 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/06/22 11:06:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/03 05:59:14 | 000,000,000 | —D | M]

[2009/12/09 19:32:06 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Mozilla\Extensions
[2010/12/08 08:24:54 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\0egx6xlg.default\extensions
[2010/06/01 09:55:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\0egx6xlg.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/10/28 07:29:24 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/08/20 21:49:26 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/05/15 19:07:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 07:29:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/12/30 01:26:55 | 000,000,865 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:64bit: - HKLM..\Run: [SoundMAX] C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Buttons & OSDs control application gen3] c:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP KEYBOARDx] C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE (Hewlett-Packard)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.tvnsports.com/vjocx-en-black.cab (VodClient Control Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7f0edd12-f09a-11de-abc5-90e6ba498c4b}\Shell - "" = AutoRun
O33 - MountPoints2\{7f0edd12-f09a-11de-abc5-90e6ba498c4b}\Shell\AutoRun\command - "" = CD_Start.exe
O33 - MountPoints2\{a611d6ce-9ed7-11df-88a7-90e6ba498c4b}\Shell - "" = AutoRun
O33 - MountPoints2\{a611d6ce-9ed7-11df-88a7-90e6ba498c4b}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/09 07:20:46 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Thomas\Desktop\OTL.exe
[2010/12/08 12:31:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\SystemRequirementsLab
[2010/12/08 12:31:38 | 000,000,000 | —D | C] – C:\Users\Thomas\AppData\Roaming\SystemRequirementsLab
[2010/12/08 12:19:48 | 000,062,976 | —- | C] (Prevx) – C:\Windows\SysWow64\PxSecure.dll
[2010/12/08 12:19:47 | 000,065,736 | —- | C] (Prevx) – C:\Windows\SysNative\drivers\pxrts.sys
[2010/12/08 12:19:47 | 000,036,384 | —- | C] (Prevx) – C:\Windows\SysNative\drivers\pxscan.sys
[2010/12/08 12:19:46 | 000,024,024 | —- | C] (Prevx) – C:\Windows\SysNative\drivers\pxkbf.sys
[2010/12/08 12:19:46 | 000,000,000 | —D | C] – C:\Program Files\Prevx
[2010/12/08 12:19:16 | 000,000,000 | —D | C] – C:\ProgramData\PrevxCSI
[2010/12/08 12:19:00 | 000,945,272 | —- | C] (Prevx) – C:\Users\Thomas\Documents\prevxcsifree.exe
[2010/12/06 20:54:40 | 000,000,000 | —D | C] – C:\Windows\pss
[2010/12/06 11:34:29 | 000,029,696 | —- | C] (The OpenVPN Project) – C:\Windows\SysNative\drivers\tap0901.sys
[2010/12/06 11:34:27 | 000,000,000 | —D | C] – C:\Program Files\S.A.D
[2010/12/06 11:33:38 | 000,818,824 | —- | C] (mobile concepts GmbH) – C:\Users\Thomas\Documents\CGWebInstall.exe
[2010/12/05 22:02:08 | 000,659,456 | —- | C] (Speed Guide Inc.) – C:\Users\Thomas\Documents\TCPOptimizer.exe
[2010/12/05 21:49:04 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Thomas\Documents\HijackThis.exe
[2010/12/01 08:15:19 | 000,000,000 | —D | C] – C:\Users\Thomas\AppData\Roaming\GlarySoft
[2010/12/01 08:15:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Glary Registry Repair
[2010/12/01 08:14:24 | 003,843,464 | —- | C] (GlarySoft.com ) – C:\Users\Thomas\Documents\rrsetup.exe
[2010/11/30 21:17:00 | 000,000,000 | —D | C] – C:\SmartOnLine
[2010/11/28 21:11:07 | 000,000,000 | —D | C] – C:\Tiana
[2009/12/17 22:34:15 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Thomas\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2010/12/09 08:03:17 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/09 08:03:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/09 07:36:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001UA.job
[2010/12/09 07:20:50 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Thomas\Desktop\OTL.exe
[2010/12/09 07:20:32 | 000,080,384 | —- | M] () – C:\Users\Thomas\Desktop\MBRCheck.exe
[2010/12/08 17:36:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001Core.job
[2010/12/08 14:51:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/08 12:19:48 | 000,062,976 | —- | M] (Prevx) – C:\Windows\SysWow64\PxSecure.dll
[2010/12/08 12:19:47 | 000,065,736 | —- | M] (Prevx) – C:\Windows\SysNative\drivers\pxrts.sys
[2010/12/08 12:19:47 | 000,036,384 | —- | M] (Prevx) – C:\Windows\SysNative\drivers\pxscan.sys
[2010/12/08 12:19:46 | 000,024,024 | —- | M] (Prevx) – C:\Windows\SysNative\drivers\pxkbf.sys
[2010/12/08 12:19:04 | 000,945,272 | —- | M] (Prevx) – C:\Users\Thomas\Documents\prevxcsifree.exe
[2010/12/08 08:30:34 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/08 08:30:34 | 000,015,792 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/07 06:34:27 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForThomas.job
[2010/12/07 06:33:55 | 3019,300,864 | -HS- | M] () – C:\hiberfil.sys
[2010/12/06 11:34:30 | 000,000,902 | —- | M] () – C:\Users\Public\Desktop\CyberGhost VPN.lnk
[2010/12/06 11:33:40 | 000,818,824 | —- | M] (mobile concepts GmbH) – C:\Users\Thomas\Documents\CGWebInstall.exe
[2010/12/05 22:03:45 | 000,001,707 | —- | M] () – C:\Users\Thomas\Documents\sg_backup_2010-12-05-2203.spg
[2010/12/05 22:03:45 | 000,001,707 | —- | M] () – C:\Users\Thomas\Documents\FirstBackup.spg
[2010/12/05 22:02:09 | 000,659,456 | —- | M] (Speed Guide Inc.) – C:\Users\Thomas\Documents\TCPOptimizer.exe
[2010/12/05 21:49:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Thomas\Documents\HijackThis.exe
[2010/12/04 14:16:38 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/12/04 14:16:38 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/12/04 14:16:38 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/12/03 00:46:29 | 000,002,342 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/12/01 08:15:20 | 000,001,015 | —- | M] () – C:\Users\Thomas\Desktop\Glary Registry Repair.lnk
[2010/12/01 08:15:20 | 000,000,145 | —- | M] () – C:\Users\Thomas\Desktop\Glary Utilities Freeware.url
[2010/12/01 08:14:31 | 003,843,464 | —- | M] (GlarySoft.com ) – C:\Users\Thomas\Documents\rrsetup.exe
[2010/11/30 21:16:06 | 013,889,664 | —- | M] () – C:\Users\Thomas\Documents\install_smartol.exe
[2010/11/30 19:39:02 | 000,002,241 | —- | M] () – C:\Users\Thomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/11/30 11:13:47 | 000,000,552 | —- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2010/11/09 14:26:33 | 442,626,984 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/09 11:13:09 | 000,007,597 | —- | M] () – C:\Users\Thomas\AppData\Local\Resmon.ResmonCfg

========== Files Created - No Company Name ==========

[2010/12/09 07:20:27 | 000,080,384 | —- | C] () – C:\Users\Thomas\Desktop\MBRCheck.exe
[2010/12/06 11:34:30 | 000,000,902 | —- | C] () – C:\Users\Public\Desktop\CyberGhost VPN.lnk
[2010/12/05 22:03:45 | 000,001,707 | —- | C] () – C:\Users\Thomas\Documents\sg_backup_2010-12-05-2203.spg
[2010/12/05 22:03:45 | 000,001,707 | —- | C] () – C:\Users\Thomas\Documents\FirstBackup.spg
[2010/12/01 08:15:20 | 000,001,015 | —- | C] () – C:\Users\Thomas\Desktop\Glary Registry Repair.lnk
[2010/12/01 08:15:20 | 000,000,145 | —- | C] () – C:\Users\Thomas\Desktop\Glary Utilities Freeware.url
[2010/11/30 21:15:55 | 013,889,664 | —- | C] () – C:\Users\Thomas\Documents\install_smartol.exe
[2010/11/09 10:55:49 | 000,007,597 | —- | C] () – C:\Users\Thomas\AppData\Local\Resmon.ResmonCfg
[2010/08/20 21:51:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/06/29 23:12:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/12/17 22:35:02 | 000,000,034 | —- | C] () – C:\Users\Thomas\AppData\Roaming\pcouffin.log
[2009/12/17 22:34:16 | 000,099,384 | —- | C] () – C:\Users\Thomas\AppData\Roaming\inst.exe
[2009/12/17 22:34:16 | 000,007,859 | —- | C] () – C:\Users\Thomas\AppData\Roaming\pcouffin.cat
[2009/12/17 22:34:15 | 000,001,167 | —- | C] () – C:\Users\Thomas\AppData\Roaming\pcouffin.inf
[2009/12/12 21:45:14 | 000,000,252 | —- | C] () – C:\Users\Thomas\AppData\Roaming\wklnhst.dat
[2009/10/26 01:40:18 | 000,000,012 | —- | C] () – C:\ProgramData\GEN3BrightnessLevel.INI
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/02/06 20:40:56 | 000,161,792 | —- | C] () – C:\Windows\SysWow64\drivers\ArcHlp.sys
[2007/04/10 13:40:22 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\mr320exd.dll
[2007/04/03 18:45:36 | 000,049,152 | —- | C] () – C:\Windows\SysWow64\mr320exv.dll

========== LOP Check ==========

[2010/10/21 09:51:23 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\AVG10
[2010/06/13 19:34:09 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Broderbund
[2010/06/06 21:39:51 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Canon
[2010/07/08 07:38:07 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\FFSJ
[2010/12/06 21:45:06 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\foobar2000
[2010/06/01 09:56:38 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\GARMIN
[2010/12/01 10:08:12 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\GlarySoft
[2010/02/28 11:49:42 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\ImgBurn
[2010/07/02 18:29:56 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\LEGO Company
[2010/12/08 12:31:47 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\SystemRequirementsLab
[2010/01/08 18:46:24 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Template
[2010/12/05 22:04:07 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\uTorrent
[2010/12/05 12:34:09 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\Vso
[2009/12/31 00:06:01 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\WildTangent
[2009/12/10 10:36:56 | 000,000,000 | —D | M] – C:\Users\Thomas\AppData\Roaming\WinBatch
[2010/11/30 11:13:47 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/08/24 05:26:34 | 000,032,654 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 183 bytes -> C:\ProgramData\Temp:56DA0F9E

< End of report >

I will post the 3rd file in the next reply.
(3) And here's the output from Extra.txt file. Thanks a lot!!

OTL Extras logfile created on: 12/9/2010 8:15:33 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Thomas\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.32 Gb Total Space | 8.49 Gb Free Space | 1.45% Space Free | Partition Type: NTFS
Drive D: | 12.75 Gb Total Space | 2.29 Gb Free Space | 17.98% Space Free | Partition Type: NTFS

Computer Name: THOMAS-PC | User Name: Thomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Digital Photo Professional] – C:\Program Files (x86)\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series" = Canon MP560 series MP Drivers
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Virtual Earth 3D (Beta)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{948B1FD6-9F98-47EE-AABF-8697F2FD44B0}" = ccc-utility64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{E50A5077-1654-BEAE-986B-7B7133DA7C48}" = ATI Catalyst Install Manager
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD1}" = Paint.NET v3.5.5
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CyberGhost VPN_is1" = CyberGhost VPN
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"PCSI" = Prevx

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP TouchSmart Webcam
"{04D66C1E-E5E2-483C-8715-916C42703924}" = HP TouchSmart Calendar
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08235411-48C8-A293-8642-D9575891E7D9}" = Catalyst Control Center InstallProxy
"{08548558-3EC9-BD0B-3D09-632500268F59}" = CCC Help Portuguese
"{137B2CE7-30A2-4836-0830-707F1010F517}" = CCC Help English
"{13A5A060-F2EF-449C-AD0E-293C459271FF}" = HP TouchSmart Netflix
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1AFC20E3-35B0-4916-9809-F6C46A92A695}" = HP TouchSmart Weather
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F959C31-3C22-404B-8284-534A416119B0}" = Buttons & OSDs control application gen3
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{22139F5D-9405-455A-BDEB-658B1A4E4861}" = Catalyst Control Center - Branding
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25F2A86D-E2E2-C2AD-8173-86C18632F214}" = CCC Help Chinese Traditional
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{2842077A-7895-5310-4F0C-42C83501E770}" = CCC Help Thai
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{297C2073-4ED9-4AD7-B4DA-EA2565568379}" = HP TouchSmart Link
"{2ACAB850-69A5-8090-08B7-D27CC6D8652C}" = CCC Help German
"{2BAD00A4-7FD1-61C5-10C3-8275723943AD}" = CCC Help Danish
"{2BF943D5-1468-589A-50E3-DD0ED6596022}" = Catalyst Control Center Graphics Full New
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP TouchSmart Movie Themes
"{34DB1D69-9FFC-7899-6F4D-22C4C15ADD54}" = CCC Help Polish
"{37D59F62-2FC7-412D-AA55-3D0E6A9BD9C7}" = Microsoft Live Search Toolbar
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{3E450CF1-F8C4-C8D6-29D1-87AD090E8F2A}" = Catalyst Control Center InstallProxy
"{3F310D8D-AC3B-5478-5AEA-D2EF5D7437E7}" = CCC Help Swedish
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{424CECC6-CEB1-4A5F-9A42-ADE64F035DEB}" = HP TouchSmart
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EDD5F10-3961-48C2-ACD9-63D5C125EA8F}" = HP TouchSmart Clock
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{55CA337D-2BE3-4AA4-BA1E-652F4C02E893}" = HP TouchSmart Notes
"{574736E1-57BD-413B-8CA8-2945F94185CE}" = PC Camera
"{58F9D852-9443-4955-A1ED-12C9E0504DD0}" = Mavis Beacon Teaches Typing Platinum 20
"{595007B2-E139-535C-D723-4B0442FC40F5}" = CCC Help Italian
"{5A21C631-0494-7377-1E3B-99353E04F83B}" = CCC Help Japanese
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{695C04CF-CF98-FAD6-9590-6C555B2E2E79}" = CCC Help Chinese Standard
"{6F277272-77D6-1E03-B8BB-B408B26C5140}" = CCC Help Czech
"{717CC8F7-D8EF-4339-AC51-A501DC9EC7B6}" = HP TouchSmart Tutorials
"{7240A994-0ED4-4841-AD3B-5E5F72850F67}" = Catalyst Control Center Graphics Previews Vista
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7C66E480-E42D-3664-B207-5CE9A706BC1F}" = Catalyst Control Center Graphics Light
"{7CAAA7B2-D9EA-2416-9D63-DDBC8E669059}" = CCC Help French
"{82809116-D1EE-443C-AE31-F19E709DDF7A}" = AMD USB Filter Driver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{84B4C4F4-F244-6A7E-EDC6-ECD46ACAAE59}" = CCC Help Greek
"{870F1750-BA89-11DA-A94D-0800200C9A66}_is1" = VSO CopyToDVD 4
"{885F5AC6-4413-4D30-99A9-F4494BFA4923}" = Logitech Harmony Remote Software 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ABB6A99-E2D5-47E4-905A-2FD4657D235E}" = HP TouchSmart RSS
"{8FF90DB8-6DED-44A3-B182-244FEC09012F}" = Microsoft Touch Pack for Windows 7
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A58E9FA7-23E7-4D87-AD5B-E8331821B84B}" = HP TouchSmart Canvas
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AE566093-655C-416B-8D25-4B4D85887978}" = HP TouchSmart RecipeBox
"{AE8C4181-26D7-4E92-A6EF-81BB2A8E0230}" = HP TouchSmart Twitter
"{AF4A82A7-F453-CE12-A942-E55FAC234387}" = ccc-core-static
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP TouchSmart Music/Photo/Video
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5B7E8FF-62F6-FA85-4C4A-83AAF816CE6E}" = CCC Help Spanish
"{B5F47039-9B19-4AC3-9A4A-E1CA3068E59F}" = ArcSoft TotalMedia Theatre 3
"{B8089767-9A45-0E84-FCDE-15698650FF17}" = CCC Help Hungarian
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Activate Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C9496C0E-BE4C-7800-900B-5E66B958AEC1}" = CCC Help Russian
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{DFD6EBE3-F0DA-4E24-9202-37AF8D20888B}" = HP TouchSmart Browser
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EB1A6595-613F-9654-E58E-0876F8B0E8F3}" = Catalyst Control Center Localization All
"{EDD1E22B-249A-5ED7-BA0A-C41BAA8256ED}" = CCC Help Korean
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F252C428-A4AE-C73E-031A-C451FDD660A9}" = CCC Help Norwegian
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{F67EA3C6-38B0-675A-E2F9-8C343DE1C826}" = Catalyst Control Center Graphics Full Existing
"{F686E613-03C4-085F-188A-9E5DC1455787}" = CCC Help Turkish
"{F7F7626C-4612-BF7B-38D5-07E247973A1A}" = Catalyst Control Center Core Implementation
"{F8CA8746-F561-61D7-A496-8D4C4E1F8A57}" = CCC Help Dutch
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FCDDC9D3-5524-9AD1-651C-467910CC1903}" = CCC Help Finnish
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"avast5" = avast! Free Antivirus
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon MP560 series User Registration" = Canon MP560 series User Registration
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dora's World Adventure" = Dora's World Adventure
"DPP" = Canon Utilities Digital Photo Professional 3.3
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"EOS Utility" = Canon Utilities EOS Utility
"foobar2000" = foobar2000 v0.9.6.9
"Glary Registry Repair_is1" = Glary Registry Repair 3.3.0.852
"Google Chrome" = Google Chrome
"HP Keyboard_is1" = HP Desktop Keyboard
"HP Remote Solution" = HP Remote Solution
"ImgBurn" = ImgBurn
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP TouchSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP TouchSmart Movie Themes
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP TouchSmart Music/Photo/Video
"InstallShield_{B5F47039-9B19-4AC3-9A4A-E1CA3068E59F}" = ArcSoft TotalMedia Theatre 3
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MyCamera" = Canon Utilities MyCamera
"New LEGO Digital Designer" = LEGO Digital Designer
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"PROPLUS" = Microsoft Office Professional Plus 2007
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealAlt_is1" = Real Alternative 2.0.1
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"SystemRequirementsLab" = System Requirements Lab
"TurboTax 2009" = TurboTax 2009
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"WildTangent hp Master Uninstall" = HP Games
"WinRAR archiver" = WinRAR archiver
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"HuluDesktop" = Hulu Desktop

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi

Please do the following;

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Thanks for the response. Here's the output from Combofix. ComboFix 10-12-08.04 - Thomas 12/09/2010 11:59:09.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2223 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\users\Thomas\AppData\Roaming\inst.exe . ((((((((((((((((((((((((( Files Created from 2010-11-09 to 2010-12-09 ))))))))))))))))))))))))))))))) . 2010-12-09 18:02 . 2010-12-09 18:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-12-08 18:31 . 2010-12-08 18:31 ——– d—–w- c:\program files (x86)\SystemRequirementsLab 2010-12-08 18:31 . 2010-12-08 18:31 ——– d—–w- c:\users\Thomas\AppData\Roaming\SystemRequirementsLab 2010-12-08 18:19 . 2010-12-08 18:19 62976 —-a-w- c:\windows\SysWow64\PxSecure.dll 2010-12-08 18:19 . 2010-12-08 18:19 65736 —-a-w- c:\windows\system32\drivers\pxrts.sys 2010-12-08 18:19 . 2010-12-08 18:19 36384 —-a-w- c:\windows\system32\drivers\pxscan.sys 2010-12-08 18:19 . 2010-12-08 18:19 24024 —-a-w- c:\windows\system32\drivers\pxkbf.sys 2010-12-08 18:19 . 2010-12-08 18:19 ——– d—–w- c:\program files\Prevx 2010-12-08 18:19 . 2010-12-08 18:22 ——– d—–w- c:\programdata\PrevxCSI 2010-12-07 19:29 . 2010-11-10 05:35 8199504 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{335771CF-A3C6-45E3-A450-2D60EF4DFE74}\mpengine.dll 2010-12-06 17:34 . 2010-02-25 23:51 29696 —-a-w- c:\windows\system32\drivers\tap0901.sys 2010-12-06 17:34 . 2010-12-06 17:34 ——– d—–w- c:\program files\S.A.D 2010-12-01 14:15 . 2010-12-01 16:08 ——– d—–w- c:\users\Thomas\AppData\Roaming\GlarySoft 2010-12-01 14:15 . 2010-12-01 14:15 ——– d—–w- c:\program files (x86)\Glary Registry Repair 2010-12-01 03:17 . 2010-12-09 04:19 ——– d—–w- C:\SmartOnLine 2010-11-29 03:11 . 2010-11-29 03:11 ——– d—–w- C:\Tiana 2010-11-24 04:29 . 2010-10-19 08:47 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2010-11-24 04:29 . 2010-10-19 08:10 7680 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll 2010-11-18 05:54 . 2010-11-18 05:54 169320 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10135.bin . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-10-19 16:41 . 2010-02-09 04:15 270720 ——w- c:\windows\system32\MpSigStub.exe 2010-09-15 09:50 . 2010-05-16 01:07 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2010-09-13 21:28 . 2010-09-13 21:28 27216 —-a-w- c:\windows\system32\drivers\AVGIDSEH.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "HP KEYBOARDx"="c:\program files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE" [2009-07-15 715264] "SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1314816] "Buttons & OSDs control application gen3"="c:\program files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe" [2009-07-03 212992] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-05-13 581480] "UpdatePRCShortCut"="c:\program files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-03-30 437584] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-03 98304] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2010-12-08 6746280] R3 hidkmdf;Microsoft HID Class Shim for KMDF;c:\windows\system32\DRIVERS\hidkmdf.sys [2009-07-29 13816] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-22 1255736] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-02-03 202752] R4 CalendarSynchService;CalendarSynchService;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2009-07-09 21560] R4 CGVPNCliSrvc;CyberGhost VPN Client;c:\program files\S.A.D\CyberGhost VPN\CGVPNCliService.exe [2010-07-28 2404488] R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 136176] R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 27216] S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2010-12-08 36384] S1 archlp;archlp;SysWOW64\drivers\archlp.sys [x] S1 aswSP;aswSP; [x] S1 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2010-12-08 65736] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-03-30 303952] S3 ACPIService;Buttons and OSDs ACPI driver gen2;c:\windows\system32\DRIVERS\OSDACPI.SYS [2009-06-17 17992] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-02-03 6366720] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-02-03 186880] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-03-30 24664] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2009-05-19 702976] S3 NW1950;NextWindow 1950 Touch Screen;c:\windows\system32\DRIVERS\NW1950.sys [2009-07-29 24568] S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2010-12-08 24024] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-13 233472] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872] — Other Services/Drivers In Memory — *NewlyCreated* - PXRTS *NewlyCreated* - PXSCAN [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc . Contents of the 'Scheduled Tasks' folder 2010-12-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 19:41] 2010-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 19:41] 2010-12-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001Core.job - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 03:21] 2010-12-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001UA.job - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 03:21] 2010-12-07 c:\windows\Tasks\HPCeeScheduleForThomas.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 10:22] 2010-11-30 c:\windows\Tasks\PCDRScheduledMaintenance.job - c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-06-10 11:04] . ——— x86-64 ———– [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAX"="c:\program files (x86)\Analog Devices\SoundMAX\soundmax.exe" [2009-06-22 3866624] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=crossfire&pf=cndt uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=crossfire&pf=cndt mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 Trusted Zone: intuit.com\ttlc FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\0egx6xlg.default\ FF - plugin: c:\program files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL FF - plugin: c:\program files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files (x86)\Virtual Earth 3D\npVE3D.dll FF - plugin: c:\users\Thomas\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\users\Thomas\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll FF - plugin: c:\users\Thomas\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\Thomas\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} . - - - - ORPHANS REMOVED - - - - Wow6432Node-HKLM-Run-HP Remote Solution - %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2010-12-09 12:05:24 ComboFix-quarantined-files.txt 2010-12-09 18:05 Pre-Run: 9,689,079,808 bytes free Post-Run: 9,634,467,840 bytes free - - End Of File - - 7C6714F35F0D711DA90E34A9590BE1C8
Hi

Please run the following program:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Thanks for the response. There were no malicious objects found. Here is the log file: 2010/12/09 19:06:40.0366 TDSS rootkit removing tool 2.4.11.0 Dec 8 2010 14:46:40 2010/12/09 19:06:40.0366 ================================================================================ 2010/12/09 19:06:40.0366 SystemInfo: 2010/12/09 19:06:40.0366 2010/12/09 19:06:40.0366 OS Version: 6.1.7600 ServicePack: 0.0 2010/12/09 19:06:40.0366 Product type: Workstation 2010/12/09 19:06:40.0367 ComputerName: THOMAS-PC 2010/12/09 19:06:40.0367 UserName: Thomas 2010/12/09 19:06:40.0367 Windows directory: C:\Windows 2010/12/09 19:06:40.0367 System windows directory: C:\Windows 2010/12/09 19:06:40.0367 Running under WOW64 2010/12/09 19:06:40.0367 Processor architecture: Intel x64 2010/12/09 19:06:40.0367 Number of processors: 2 2010/12/09 19:06:40.0367 Page size: 0x1000 2010/12/09 19:06:40.0367 Boot type: Normal boot 2010/12/09 19:06:40.0367 ================================================================================ 2010/12/09 19:06:40.0368 Utility is running under WOW64 2010/12/09 19:06:41.0013 Initialize success 2010/12/09 19:06:46.0773 ================================================================================ 2010/12/09 19:06:46.0773 Scan started 2010/12/09 19:06:46.0773 Mode: Manual; 2010/12/09 19:06:46.0773 ================================================================================ 2010/12/09 19:06:49.0172 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/12/09 19:06:49.0466 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 2010/12/09 19:06:49.0753 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/12/09 19:06:50.0038 ACPIService (de7e8d852a806be6091983838bf9697f) C:\Windows\system32\DRIVERS\OSDACPI.SYS 2010/12/09 19:06:50.0338 ADIHdAudAddService (0fa60a409e1c8ab9a81901311d15393d) C:\Windows\system32\drivers\ADIHdAud.sys 2010/12/09 19:06:50.0636 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/12/09 19:06:50.0935 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 2010/12/09 19:06:51.0226 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 2010/12/09 19:06:51.0543 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys 2010/12/09 19:06:51.0837 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 2010/12/09 19:06:52.0405 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 2010/12/09 19:06:52.0706 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 2010/12/09 19:06:53.0001 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 2010/12/09 19:06:53.0413 amdkmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atipmdag.sys 2010/12/09 19:06:53.0752 amdkmdap (ebc963d8f5b04c98f5ef597aae79cddd) C:\Windows\system32\DRIVERS\atikmpag.sys 2010/12/09 19:06:54.0032 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2010/12/09 19:06:54.0351 amdsata (f747497a0ee5498f79b207f215b3d2d8) C:\Windows\system32\DRIVERS\amdsata.sys 2010/12/09 19:06:54.0637 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/12/09 19:06:54.0938 amdxata (2946d695e158615baaa16248e63c7adb) C:\Windows\system32\DRIVERS\amdxata.sys 2010/12/09 19:06:55.0252 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 2010/12/09 19:06:55.0561 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 2010/12/09 19:06:55.0875 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 2010/12/09 19:06:56.0191 aswFsBlk (b76182f203e0bd5eb6a5f6538f0faee4) C:\Windows\system32\drivers\aswFsBlk.sys 2010/12/09 19:06:56.0491 aswMonFlt (a88e9544edda1ce83825dd22d6a8b5f9) C:\Windows\system32\drivers\aswMonFlt.sys 2010/12/09 19:06:56.0781 aswRdr (cfad2fb33b22e7039c9dc233baacbf8b) C:\Windows\system32\drivers\aswRdr.sys 2010/12/09 19:06:57.0092 aswSP (594365e887f4a5ad3970870b352eb887) C:\Windows\system32\drivers\aswSP.sys 2010/12/09 19:06:57.0447 aswTdi (4ba0a0e1d36f88f536180ffe5efd8b7c) C:\Windows\system32\drivers\aswTdi.sys 2010/12/09 19:06:57.0724 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/12/09 19:06:58.0004 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 2010/12/09 19:06:58.0421 atikmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atikmdag.sys 2010/12/09 19:06:58.0752 AtiPcie (7c5d273e29dcc5505469b299c6f29163) C:\Windows\system32\DRIVERS\AtiPcie.sys 2010/12/09 19:06:59.0097 AVGIDSEH (656366fd0c0e2481a89196fb3d1be49a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 2010/12/09 19:06:59.0419 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 2010/12/09 19:06:59.0719 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2010/12/09 19:07:00.0016 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2010/12/09 19:07:00.0306 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/12/09 19:07:00.0584 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys 2010/12/09 19:07:00.0882 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/12/09 19:07:01.0124 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/12/09 19:07:01.0380 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2010/12/09 19:07:01.0616 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/12/09 19:07:01.0900 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/12/09 19:07:02.0136 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/12/09 19:07:02.0750 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/12/09 19:07:03.0087 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/12/09 19:07:03.0379 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 2010/12/09 19:07:03.0685 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 2010/12/09 19:07:03.0871 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2010/12/09 19:07:04.0189 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/12/09 19:07:04.0436 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 2010/12/09 19:07:04.0685 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 2010/12/09 19:07:04.0975 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2010/12/09 19:07:05.0260 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/12/09 19:07:05.0561 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/12/09 19:07:05.0905 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys 2010/12/09 19:07:06.0146 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2010/12/09 19:07:06.0442 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 2010/12/09 19:07:06.0732 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2010/12/09 19:07:07.0029 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys 2010/12/09 19:07:07.0329 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 2010/12/09 19:07:07.0665 ElbyCDIO (9a47ac3dfcf81d30922cdaaf1c2d579f) C:\Windows\system32\Drivers\ElbyCDIO.sys 2010/12/09 19:07:08.0135 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 2010/12/09 19:07:08.0374 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 2010/12/09 19:07:08.0675 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2010/12/09 19:07:08.0996 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2010/12/09 19:07:09.0343 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 2010/12/09 19:07:09.0721 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2010/12/09 19:07:09.0971 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2010/12/09 19:07:10.0244 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/12/09 19:07:10.0619 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 2010/12/09 19:07:10.0894 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2010/12/09 19:07:11.0171 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2010/12/09 19:07:11.0467 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 2010/12/09 19:07:11.0759 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/12/09 19:07:12.0190 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2010/12/09 19:07:12.0481 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys 2010/12/09 19:07:12.0773 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/12/09 19:07:13.0141 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/12/09 19:07:13.0387 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 2010/12/09 19:07:13.0639 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 2010/12/09 19:07:13.0873 hidkmdf (d4bfba2eec009e26854fe61110ef509f) C:\Windows\system32\DRIVERS\hidkmdf.sys 2010/12/09 19:07:14.0162 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 2010/12/09 19:07:14.0477 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/12/09 19:07:14.0765 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 2010/12/09 19:07:15.0029 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 2010/12/09 19:07:15.0324 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/12/09 19:07:15.0659 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/12/09 19:07:16.0009 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 2010/12/09 19:07:16.0287 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 2010/12/09 19:07:16.0582 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 2010/12/09 19:07:17.0118 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/12/09 19:07:17.0362 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/12/09 19:07:17.0604 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2010/12/09 19:07:17.0895 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2010/12/09 19:07:18.0134 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 2010/12/09 19:07:18.0364 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/12/09 19:07:18.0703 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/12/09 19:07:18.0999 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/12/09 19:07:19.0272 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 2010/12/09 19:07:19.0584 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 2010/12/09 19:07:19.0882 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2010/12/09 19:07:20.0240 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2010/12/09 19:07:20.0533 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/12/09 19:07:20.0814 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/12/09 19:07:21.0094 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/12/09 19:07:21.0392 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/12/09 19:07:21.0677 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2010/12/09 19:07:21.0969 MBAMProtector (4a46fa98de81ff55a7cfc0c26262cb33) C:\Windows\system32\drivers\mbam.sys 2010/12/09 19:07:22.0285 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 2010/12/09 19:07:22.0582 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/12/09 19:07:22.0983 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2010/12/09 19:07:23.0291 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2010/12/09 19:07:23.0613 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2010/12/09 19:07:23.0909 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2010/12/09 19:07:24.0152 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 2010/12/09 19:07:24.0399 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 2010/12/09 19:07:24.0657 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2010/12/09 19:07:24.0924 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 2010/12/09 19:07:25.0206 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/12/09 19:07:25.0476 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/12/09 19:07:25.0741 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/12/09 19:07:26.0018 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 2010/12/09 19:07:26.0396 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 2010/12/09 19:07:26.0783 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2010/12/09 19:07:27.0033 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2010/12/09 19:07:27.0289 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/12/09 19:07:27.0571 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2010/12/09 19:07:27.0846 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/12/09 19:07:28.0121 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2010/12/09 19:07:28.0363 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 2010/12/09 19:07:28.0611 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/12/09 19:07:28.0895 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2010/12/09 19:07:29.0173 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/12/09 19:07:29.0680 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2010/12/09 19:07:29.0982 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2010/12/09 19:07:30.0533 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 2010/12/09 19:07:30.0872 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/12/09 19:07:31.0147 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/12/09 19:07:31.0490 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/12/09 19:07:31.0726 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/12/09 19:07:31.0968 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 2010/12/09 19:07:32.0252 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2010/12/09 19:07:32.0492 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 2010/12/09 19:07:32.0808 netr28x (44d4bd55191624c82a2745296ba42814) C:\Windows\system32\DRIVERS\netr28x.sys 2010/12/09 19:07:33.0103 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/12/09 19:07:33.0391 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2010/12/09 19:07:33.0632 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2010/12/09 19:07:33.0900 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys 2010/12/09 19:07:34.0170 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2010/12/09 19:07:34.0458 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/12/09 19:07:34.0811 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys 2010/12/09 19:07:35.0062 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/12/09 19:07:35.0290 NW1950 (1a71763dd0df7ab7b435efa1dde710c6) C:\Windows\system32\DRIVERS\NW1950.sys 2010/12/09 19:07:35.0571 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/12/09 19:07:35.0872 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 2010/12/09 19:07:36.0122 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 2010/12/09 19:07:36.0397 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 2010/12/09 19:07:37.0006 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 2010/12/09 19:07:37.0242 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/12/09 19:07:37.0531 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys 2010/12/09 19:07:37.0778 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2010/12/09 19:07:38.0031 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2010/12/09 19:07:38.0298 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 2010/12/09 19:07:38.0537 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 2010/12/09 19:07:38.0826 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 2010/12/09 19:07:39.0138 pxkbf (ba5f7c107eace67973b4b798832a74c7) C:\Windows\system32\drivers\pxkbf.sys 2010/12/09 19:07:39.0566 pxrts (007e57428802f587d0d6737ae7a9d989) C:\Windows\system32\drivers\pxrts.sys 2010/12/09 19:07:39.0866 pxscan (66d4d00c8908888a68b749d91f1e6789) C:\Windows\system32\drivers\pxscan.sys 2010/12/09 19:07:40.0165 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 2010/12/09 19:07:40.0458 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/12/09 19:07:40.0691 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2010/12/09 19:07:40.0916 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2010/12/09 19:07:41.0152 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/12/09 19:07:41.0383 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/12/09 19:07:41.0637 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/12/09 19:07:41.0873 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2010/12/09 19:07:42.0287 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 2010/12/09 19:07:42.0525 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/12/09 19:07:42.0823 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/12/09 19:07:43.0115 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2010/12/09 19:07:43.0373 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2010/12/09 19:07:43.0622 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 2010/12/09 19:07:43.0923 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 2010/12/09 19:07:44.0252 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2010/12/09 19:07:44.0545 RTL8167 (91296f0b2653281b2f11e0fce56aa427) C:\Windows\system32\DRIVERS\Rt64win7.sys 2010/12/09 19:07:44.0812 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/12/09 19:07:45.0114 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 2010/12/09 19:07:45.0417 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2010/12/09 19:07:45.0679 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 2010/12/09 19:07:45.0911 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 2010/12/09 19:07:46.0202 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 2010/12/09 19:07:46.0466 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/12/09 19:07:46.0704 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/12/09 19:07:47.0029 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/12/09 19:07:47.0267 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/12/09 19:07:47.0719 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/12/09 19:07:47.0961 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/12/09 19:07:48.0284 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2010/12/09 19:07:48.0600 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2010/12/09 19:07:48.0896 srv (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys 2010/12/09 19:07:49.0197 srv2 (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys 2010/12/09 19:07:49.0500 srvnet (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys 2010/12/09 19:07:49.0779 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 2010/12/09 19:07:50.0074 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 2010/12/09 19:07:50.0399 tap0901 (4ef44915e522f3ecd1a3ff540aa64126) C:\Windows\system32\DRIVERS\tap0901.sys 2010/12/09 19:07:50.0755 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys 2010/12/09 19:07:51.0130 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys 2010/12/09 19:07:51.0404 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 2010/12/09 19:07:51.0654 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2010/12/09 19:07:51.0896 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2010/12/09 19:07:52.0199 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 2010/12/09 19:07:52.0436 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 2010/12/09 19:07:52.0866 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/12/09 19:07:53.0152 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 2010/12/09 19:07:53.0399 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 2010/12/09 19:07:53.0661 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 2010/12/09 19:07:53.0934 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/12/09 19:07:54.0230 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 2010/12/09 19:07:54.0472 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 2010/12/09 19:07:54.0725 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/12/09 19:07:55.0050 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 2010/12/09 19:07:55.0289 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 2010/12/09 19:07:55.0526 usbfilter (6648c6d7323a2ce0c4776c36cefbcb14) C:\Windows\system32\DRIVERS\usbfilter.sys 2010/12/09 19:07:55.0826 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys 2010/12/09 19:07:56.0071 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 2010/12/09 19:07:56.0315 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2010/12/09 19:07:56.0571 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/12/09 19:07:56.0842 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/12/09 19:07:57.0141 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 2010/12/09 19:07:57.0395 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys 2010/12/09 19:07:57.0721 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/12/09 19:07:58.0139 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/12/09 19:07:58.0380 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2010/12/09 19:07:58.0617 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/12/09 19:07:58.0951 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 2010/12/09 19:07:59.0204 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/12/09 19:07:59.0462 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 2010/12/09 19:07:59.0711 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 2010/12/09 19:08:00.0006 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/12/09 19:08:00.0301 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 2010/12/09 19:08:00.0544 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 2010/12/09 19:08:00.0819 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 2010/12/09 19:08:01.0113 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/09 19:08:01.0150 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/09 19:08:01.0445 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 2010/12/09 19:08:01.0709 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2010/12/09 19:08:02.0036 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/12/09 19:08:02.0278 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2010/12/09 19:08:02.0639 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/12/09 19:08:02.0883 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/12/09 19:08:03.0470 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2010/12/09 19:08:03.0748 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 2010/12/09 19:08:04.0050 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/12/09 19:08:04.0288 ================================================================================ 2010/12/09 19:08:04.0288 Scan finished 2010/12/09 19:08:04.0288 ================================================================================ 2010/12/09 19:08:21.0994 Deinitialize success
Thanks for the response. There were no malicious objects found. Here is the log file: 2010/12/09 19:06:40.0366 TDSS rootkit removing tool 2.4.11.0 Dec 8 2010 14:46:40 2010/12/09 19:06:40.0366 ================================================================================ 2010/12/09 19:06:40.0366 SystemInfo: 2010/12/09 19:06:40.0366 2010/12/09 19:06:40.0366 OS Version: 6.1.7600 ServicePack: 0.0 2010/12/09 19:06:40.0366 Product type: Workstation 2010/12/09 19:06:40.0367 ComputerName: THOMAS-PC 2010/12/09 19:06:40.0367 UserName: Thomas 2010/12/09 19:06:40.0367 Windows directory: C:\Windows 2010/12/09 19:06:40.0367 System windows directory: C:\Windows 2010/12/09 19:06:40.0367 Running under WOW64 2010/12/09 19:06:40.0367 Processor architecture: Intel x64 2010/12/09 19:06:40.0367 Number of processors: 2 2010/12/09 19:06:40.0367 Page size: 0x1000 2010/12/09 19:06:40.0367 Boot type: Normal boot 2010/12/09 19:06:40.0367 ================================================================================ 2010/12/09 19:06:40.0368 Utility is running under WOW64 2010/12/09 19:06:41.0013 Initialize success 2010/12/09 19:06:46.0773 ================================================================================ 2010/12/09 19:06:46.0773 Scan started 2010/12/09 19:06:46.0773 Mode: Manual; 2010/12/09 19:06:46.0773 ================================================================================ 2010/12/09 19:06:49.0172 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 2010/12/09 19:06:49.0466 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 2010/12/09 19:06:49.0753 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 2010/12/09 19:06:50.0038 ACPIService (de7e8d852a806be6091983838bf9697f) C:\Windows\system32\DRIVERS\OSDACPI.SYS 2010/12/09 19:06:50.0338 ADIHdAudAddService (0fa60a409e1c8ab9a81901311d15393d) C:\Windows\system32\drivers\ADIHdAud.sys 2010/12/09 19:06:50.0636 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 2010/12/09 19:06:50.0935 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 2010/12/09 19:06:51.0226 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 2010/12/09 19:06:51.0543 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys 2010/12/09 19:06:51.0837 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 2010/12/09 19:06:52.0405 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 2010/12/09 19:06:52.0706 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 2010/12/09 19:06:53.0001 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 2010/12/09 19:06:53.0413 amdkmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atipmdag.sys 2010/12/09 19:06:53.0752 amdkmdap (ebc963d8f5b04c98f5ef597aae79cddd) C:\Windows\system32\DRIVERS\atikmpag.sys 2010/12/09 19:06:54.0032 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2010/12/09 19:06:54.0351 amdsata (f747497a0ee5498f79b207f215b3d2d8) C:\Windows\system32\DRIVERS\amdsata.sys 2010/12/09 19:06:54.0637 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 2010/12/09 19:06:54.0938 amdxata (2946d695e158615baaa16248e63c7adb) C:\Windows\system32\DRIVERS\amdxata.sys 2010/12/09 19:06:55.0252 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 2010/12/09 19:06:55.0561 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 2010/12/09 19:06:55.0875 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 2010/12/09 19:06:56.0191 aswFsBlk (b76182f203e0bd5eb6a5f6538f0faee4) C:\Windows\system32\drivers\aswFsBlk.sys 2010/12/09 19:06:56.0491 aswMonFlt (a88e9544edda1ce83825dd22d6a8b5f9) C:\Windows\system32\drivers\aswMonFlt.sys 2010/12/09 19:06:56.0781 aswRdr (cfad2fb33b22e7039c9dc233baacbf8b) C:\Windows\system32\drivers\aswRdr.sys 2010/12/09 19:06:57.0092 aswSP (594365e887f4a5ad3970870b352eb887) C:\Windows\system32\drivers\aswSP.sys 2010/12/09 19:06:57.0447 aswTdi (4ba0a0e1d36f88f536180ffe5efd8b7c) C:\Windows\system32\drivers\aswTdi.sys 2010/12/09 19:06:57.0724 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/12/09 19:06:58.0004 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 2010/12/09 19:06:58.0421 atikmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atikmdag.sys 2010/12/09 19:06:58.0752 AtiPcie (7c5d273e29dcc5505469b299c6f29163) C:\Windows\system32\DRIVERS\AtiPcie.sys 2010/12/09 19:06:59.0097 AVGIDSEH (656366fd0c0e2481a89196fb3d1be49a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 2010/12/09 19:06:59.0419 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 2010/12/09 19:06:59.0719 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2010/12/09 19:07:00.0016 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2010/12/09 19:07:00.0306 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2010/12/09 19:07:00.0584 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys 2010/12/09 19:07:00.0882 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2010/12/09 19:07:01.0124 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2010/12/09 19:07:01.0380 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2010/12/09 19:07:01.0616 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2010/12/09 19:07:01.0900 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2010/12/09 19:07:02.0136 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2010/12/09 19:07:02.0750 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/12/09 19:07:03.0087 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/12/09 19:07:03.0379 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 2010/12/09 19:07:03.0685 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 2010/12/09 19:07:03.0871 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2010/12/09 19:07:04.0189 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/12/09 19:07:04.0436 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 2010/12/09 19:07:04.0685 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 2010/12/09 19:07:04.0975 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2010/12/09 19:07:05.0260 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 2010/12/09 19:07:05.0561 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 2010/12/09 19:07:05.0905 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys 2010/12/09 19:07:06.0146 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2010/12/09 19:07:06.0442 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 2010/12/09 19:07:06.0732 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2010/12/09 19:07:07.0029 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys 2010/12/09 19:07:07.0329 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 2010/12/09 19:07:07.0665 ElbyCDIO (9a47ac3dfcf81d30922cdaaf1c2d579f) C:\Windows\system32\Drivers\ElbyCDIO.sys 2010/12/09 19:07:08.0135 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 2010/12/09 19:07:08.0374 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 2010/12/09 19:07:08.0675 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2010/12/09 19:07:08.0996 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2010/12/09 19:07:09.0343 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 2010/12/09 19:07:09.0721 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2010/12/09 19:07:09.0971 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2010/12/09 19:07:10.0244 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/12/09 19:07:10.0619 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 2010/12/09 19:07:10.0894 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2010/12/09 19:07:11.0171 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2010/12/09 19:07:11.0467 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 2010/12/09 19:07:11.0759 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 2010/12/09 19:07:12.0190 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2010/12/09 19:07:12.0481 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys 2010/12/09 19:07:12.0773 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/12/09 19:07:13.0141 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 2010/12/09 19:07:13.0387 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 2010/12/09 19:07:13.0639 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 2010/12/09 19:07:13.0873 hidkmdf (d4bfba2eec009e26854fe61110ef509f) C:\Windows\system32\DRIVERS\hidkmdf.sys 2010/12/09 19:07:14.0162 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 2010/12/09 19:07:14.0477 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 2010/12/09 19:07:14.0765 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 2010/12/09 19:07:15.0029 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 2010/12/09 19:07:15.0324 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/12/09 19:07:15.0659 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys 2010/12/09 19:07:16.0009 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 2010/12/09 19:07:16.0287 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 2010/12/09 19:07:16.0582 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 2010/12/09 19:07:17.0118 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/12/09 19:07:17.0362 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 2010/12/09 19:07:17.0604 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2010/12/09 19:07:17.0895 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2010/12/09 19:07:18.0134 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 2010/12/09 19:07:18.0364 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/12/09 19:07:18.0703 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/12/09 19:07:18.0999 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/12/09 19:07:19.0272 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 2010/12/09 19:07:19.0584 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 2010/12/09 19:07:19.0882 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2010/12/09 19:07:20.0240 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2010/12/09 19:07:20.0533 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 2010/12/09 19:07:20.0814 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 2010/12/09 19:07:21.0094 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2010/12/09 19:07:21.0392 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2010/12/09 19:07:21.0677 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2010/12/09 19:07:21.0969 MBAMProtector (4a46fa98de81ff55a7cfc0c26262cb33) C:\Windows\system32\drivers\mbam.sys 2010/12/09 19:07:22.0285 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 2010/12/09 19:07:22.0582 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 2010/12/09 19:07:22.0983 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2010/12/09 19:07:23.0291 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2010/12/09 19:07:23.0613 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2010/12/09 19:07:23.0909 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2010/12/09 19:07:24.0152 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 2010/12/09 19:07:24.0399 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 2010/12/09 19:07:24.0657 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2010/12/09 19:07:24.0924 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 2010/12/09 19:07:25.0206 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/12/09 19:07:25.0476 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/12/09 19:07:25.0741 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/12/09 19:07:26.0018 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 2010/12/09 19:07:26.0396 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 2010/12/09 19:07:26.0783 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2010/12/09 19:07:27.0033 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2010/12/09 19:07:27.0289 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 2010/12/09 19:07:27.0571 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2010/12/09 19:07:27.0846 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/12/09 19:07:28.0121 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2010/12/09 19:07:28.0363 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 2010/12/09 19:07:28.0611 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/12/09 19:07:28.0895 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2010/12/09 19:07:29.0173 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 2010/12/09 19:07:29.0680 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2010/12/09 19:07:29.0982 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2010/12/09 19:07:30.0533 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 2010/12/09 19:07:30.0872 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2010/12/09 19:07:31.0147 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/12/09 19:07:31.0490 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/12/09 19:07:31.0726 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/12/09 19:07:31.0968 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 2010/12/09 19:07:32.0252 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2010/12/09 19:07:32.0492 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 2010/12/09 19:07:32.0808 netr28x (44d4bd55191624c82a2745296ba42814) C:\Windows\system32\DRIVERS\netr28x.sys 2010/12/09 19:07:33.0103 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 2010/12/09 19:07:33.0391 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2010/12/09 19:07:33.0632 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2010/12/09 19:07:33.0900 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys 2010/12/09 19:07:34.0170 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2010/12/09 19:07:34.0458 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys 2010/12/09 19:07:34.0811 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys 2010/12/09 19:07:35.0062 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 2010/12/09 19:07:35.0290 NW1950 (1a71763dd0df7ab7b435efa1dde710c6) C:\Windows\system32\DRIVERS\NW1950.sys 2010/12/09 19:07:35.0571 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/12/09 19:07:35.0872 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 2010/12/09 19:07:36.0122 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 2010/12/09 19:07:36.0397 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 2010/12/09 19:07:37.0006 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 2010/12/09 19:07:37.0242 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 2010/12/09 19:07:37.0531 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys 2010/12/09 19:07:37.0778 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2010/12/09 19:07:38.0031 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2010/12/09 19:07:38.0298 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 2010/12/09 19:07:38.0537 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 2010/12/09 19:07:38.0826 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 2010/12/09 19:07:39.0138 pxkbf (ba5f7c107eace67973b4b798832a74c7) C:\Windows\system32\drivers\pxkbf.sys 2010/12/09 19:07:39.0566 pxrts (007e57428802f587d0d6737ae7a9d989) C:\Windows\system32\drivers\pxrts.sys 2010/12/09 19:07:39.0866 pxscan (66d4d00c8908888a68b749d91f1e6789) C:\Windows\system32\drivers\pxscan.sys 2010/12/09 19:07:40.0165 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 2010/12/09 19:07:40.0458 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 2010/12/09 19:07:40.0691 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2010/12/09 19:07:40.0916 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2010/12/09 19:07:41.0152 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2010/12/09 19:07:41.0383 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/12/09 19:07:41.0637 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/12/09 19:07:41.0873 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2010/12/09 19:07:42.0287 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 2010/12/09 19:07:42.0525 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2010/12/09 19:07:42.0823 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/12/09 19:07:43.0115 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2010/12/09 19:07:43.0373 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2010/12/09 19:07:43.0622 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 2010/12/09 19:07:43.0923 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 2010/12/09 19:07:44.0252 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2010/12/09 19:07:44.0545 RTL8167 (91296f0b2653281b2f11e0fce56aa427) C:\Windows\system32\DRIVERS\Rt64win7.sys 2010/12/09 19:07:44.0812 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 2010/12/09 19:07:45.0114 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 2010/12/09 19:07:45.0417 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2010/12/09 19:07:45.0679 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 2010/12/09 19:07:45.0911 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 2010/12/09 19:07:46.0202 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 2010/12/09 19:07:46.0466 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/12/09 19:07:46.0704 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 2010/12/09 19:07:47.0029 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/12/09 19:07:47.0267 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 2010/12/09 19:07:47.0719 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2010/12/09 19:07:47.0961 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 2010/12/09 19:07:48.0284 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2010/12/09 19:07:48.0600 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2010/12/09 19:07:48.0896 srv (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys 2010/12/09 19:07:49.0197 srv2 (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys 2010/12/09 19:07:49.0500 srvnet (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys 2010/12/09 19:07:49.0779 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 2010/12/09 19:07:50.0074 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 2010/12/09 19:07:50.0399 tap0901 (4ef44915e522f3ecd1a3ff540aa64126) C:\Windows\system32\DRIVERS\tap0901.sys 2010/12/09 19:07:50.0755 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys 2010/12/09 19:07:51.0130 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys 2010/12/09 19:07:51.0404 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 2010/12/09 19:07:51.0654 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2010/12/09 19:07:51.0896 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2010/12/09 19:07:52.0199 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 2010/12/09 19:07:52.0436 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 2010/12/09 19:07:52.0866 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/12/09 19:07:53.0152 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 2010/12/09 19:07:53.0399 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 2010/12/09 19:07:53.0661 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 2010/12/09 19:07:53.0934 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 2010/12/09 19:07:54.0230 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 2010/12/09 19:07:54.0472 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 2010/12/09 19:07:54.0725 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/12/09 19:07:55.0050 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 2010/12/09 19:07:55.0289 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 2010/12/09 19:07:55.0526 usbfilter (6648c6d7323a2ce0c4776c36cefbcb14) C:\Windows\system32\DRIVERS\usbfilter.sys 2010/12/09 19:07:55.0826 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys 2010/12/09 19:07:56.0071 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 2010/12/09 19:07:56.0315 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2010/12/09 19:07:56.0571 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/12/09 19:07:56.0842 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/12/09 19:07:57.0141 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 2010/12/09 19:07:57.0395 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys 2010/12/09 19:07:57.0721 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 2010/12/09 19:07:58.0139 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/12/09 19:07:58.0380 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2010/12/09 19:07:58.0617 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 2010/12/09 19:07:58.0951 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 2010/12/09 19:07:59.0204 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 2010/12/09 19:07:59.0462 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 2010/12/09 19:07:59.0711 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 2010/12/09 19:08:00.0006 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 2010/12/09 19:08:00.0301 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 2010/12/09 19:08:00.0544 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 2010/12/09 19:08:00.0819 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 2010/12/09 19:08:01.0113 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/09 19:08:01.0150 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/09 19:08:01.0445 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 2010/12/09 19:08:01.0709 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2010/12/09 19:08:02.0036 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2010/12/09 19:08:02.0278 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2010/12/09 19:08:02.0639 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 2010/12/09 19:08:02.0883 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/12/09 19:08:03.0470 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2010/12/09 19:08:03.0748 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 2010/12/09 19:08:04.0050 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/12/09 19:08:04.0288 ================================================================================ 2010/12/09 19:08:04.0288 Scan finished 2010/12/09 19:08:04.0288 ================================================================================ 2010/12/09 19:08:21.0994 Deinitialize success
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi, Sorry for the delay in reply. Here goes: (1) MBAM Log File Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5284 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 12/10/2010 1:24:24 PM mbam-log-2010-12-10 (13-24-24).txt Scan type: Quick scan Objects scanned: 154644 Time elapsed: 2 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) (2) ESET Log C:\Old PC Backups\Administrator\Local Settings\Temp\122007184326\z4barSpInstall.exe a variant of Win32/AdInstaller application C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1dd6a40c-2f5788b9 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1dd6a40c-660f10cd Java/TrojanDownloader.Agent.NBK trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3a9373cc-2f3dce5b multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\7bb99554-7b4ff294 Java/TrojanDownloader.Agent.NBL trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\16646899-63a3f3dc multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\108c9a9b-276c5ef8 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\6570075d-1f7502d3 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\7adbb65d-77ddd976 Java/TrojanDownloader.Agent.NBK trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\30feb821-727b53d0 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\64db5f66-71bb0572 a variant of Java/Exploit.Agent.NAC trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\6bafd9a6-774b2843 Java/TrojanDownloader.Agent.NBM trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\3dd53984-6a846b69 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\23ea3369-1c78ad32 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\556445eb-650cda71 probably a variant of Win32/Agent.DYXWUMY trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\5473416c-6fa54cde multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\472eb3f0-7c76def4 Java/TrojanDownloader.Agent.NBK trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\1eff1eb1-30c45439 probably a variant of Win32/Agent.DYXWUMY trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\1eff1eb1-5a2cca65 Java/TrojanDownloader.Agent.NBL trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\43172bc5-12ab4bf2 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\31bba1f4-5d0cce9d Java/TrojanDownloader.Agent.NBL trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\e649f74-6ca1fb18 multiple threats C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\42441975-197ffeb7 Java/TrojanDownloader.Agent.NBM trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\fa8f07a-7f7f68ed probably a variant of Win32/Agent.DYXWUMY trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\481ee53d-348130f0 Java/TrojanDownloader.Agent.NBL trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\43e0867f-29ea24d2 probably a variant of Win32/Agent.DYXWUMY trojan C:\Users\Thomas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\6321f0ff-2aadc4f7 multiple threats C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Applications etc\zlsSetup_70_462_000_en.exe a variant of Win32/AdInstaller application C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com Book Collector Pro 4.6.2.rar probably a variant of Win32/Agent.BGBFXIB trojan C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com MP3 Collector Pro v2.2.4.rar probably a variant of Win32/Agent.MAQPBZZ trojan Thanks!!
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

File::
C:\Old PC Backups\Administrator\Local Settings\Temp\122007184326\z4barSpInstall.exe 
C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Applications etc\zlsSetup_70_462_000_en.exe 
C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com Book Collector Pro 4.6.2.rar 
C:\Users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com MP3 Collector Pro v2.2.4.rar

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



Please advise how the computer is running now and if there are any outstanding issues
Hi, Here's the log file: ComboFix 10-12-13.02 - Thomas 12/13/2010 21:22:29.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2379 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Thomas\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FILE :: "c:\old pc backups\Administrator\Local Settings\Temp\122007184326\z4barSpInstall.exe" "c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Applications etc\zlsSetup_70_462_000_en.exe" "c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com Book Collector Pro 4.6.2.rar" "c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com MP3 Collector Pro v2.2.4.rar" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\old pc backups\Administrator\Local Settings\Temp\122007184326\z4barSpInstall.exe c:\users\Thomas\AppData\Roaming\EurekaLog c:\users\Thomas\AppData\Roaming\EurekaLog\CyberGhost\CyberGhost.elf c:\users\Thomas\AppData\Roaming\EurekaLog\EurekaLog.ini c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Applications etc\zlsSetup_70_462_000_en.exe c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com Book Collector Pro 4.6.2.rar c:\users\Thomas\Documents\TEMP BACKUPS\Torrents\Collectorz.com Apps\Collectorz.com MP3 Collector Pro v2.2.4.rar . ((((((((((((((((((((((((( Files Created from 2010-11-14 to 2010-12-14 ))))))))))))))))))))))))))))))) . 2010-12-14 03:27 . 2010-12-14 03:27 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-12-13 03:50 . 2010-02-23 08:16 294912 —-a-w- c:\windows\system32\browserchoice.exe 2010-12-12 04:47 . 2010-12-12 04:47 ——– d—–w- c:\program files (x86)\ESET 2010-12-10 13:24 . 2010-11-10 05:35 8199504 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{764CA807-DECA-4909-BADC-99E728DE5A7E}\mpengine.dll 2010-12-10 01:30 . 2010-12-10 01:30 ——– d—–w- c:\programdata\Uniblue 2010-12-10 01:30 . 2010-12-10 01:30 ——– d—–w- c:\users\Thomas\AppData\Roaming\Uniblue 2010-12-08 18:31 . 2010-12-08 18:31 ——– d—–w- c:\program files (x86)\SystemRequirementsLab 2010-12-08 18:31 . 2010-12-08 18:31 ——– d—–w- c:\users\Thomas\AppData\Roaming\SystemRequirementsLab 2010-12-06 17:34 . 2010-02-25 23:51 29696 —-a-w- c:\windows\system32\drivers\tap0901.sys 2010-12-06 17:34 . 2010-12-06 17:34 ——– d—–w- c:\program files\S.A.D 2010-12-01 14:15 . 2010-12-01 16:08 ——– d—–w- c:\users\Thomas\AppData\Roaming\GlarySoft 2010-12-01 14:15 . 2010-12-01 14:15 ——– d—–w- c:\program files (x86)\Glary Registry Repair 2010-12-01 03:17 . 2010-12-09 04:19 ——– d—–w- C:\SmartOnLine 2010-11-29 03:11 . 2010-11-29 03:11 ——– d—–w- C:\Tiana 2010-11-24 04:29 . 2010-10-19 08:47 7680 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2010-11-24 04:29 . 2010-10-19 08:10 7680 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll 2010-11-18 05:54 . 2010-11-18 05:54 169320 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10135.bin . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-29 23:42 . 2010-02-14 18:25 38224 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2010-11-29 23:42 . 2010-02-14 18:25 24152 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-19 16:41 . 2010-02-09 04:15 270720 ——w- c:\windows\system32\MpSigStub.exe 2010-09-15 09:50 . 2010-05-16 01:07 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll . ((((((((((((((((((((((((((((( SnapShot@2010-12-09_18.02.55 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2010-12-09 16:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2010-12-14 03:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2010-12-09 16:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2010-12-14 03:30 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2010-12-09 16:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2010-12-14 03:30 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-09-04 06:51 . 2010-12-14 03:31 48588 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2010-12-14 03:31 44500 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-12-10 01:11 . 2010-12-14 03:31 15004 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2893100710-462183256-3003619119-1001_UserData.bin + 2009-07-23 00:24 . 2009-07-23 00:24 97792 c:\windows\system32\RTNUninst64.dll - 2009-09-04 07:23 . 2009-05-08 09:03 13931 c:\windows\system32\RaCoInst.dat + 2009-10-12 12:40 . 2009-10-12 12:40 13931 c:\windows\system32\RaCoInst.dat + 2009-07-14 05:30 . 2010-12-10 02:51 86016 c:\windows\system32\DriverStore\infpub.dat - 2009-07-14 05:30 . 2010-12-06 17:35 86016 c:\windows\system32\DriverStore\infpub.dat + 2009-07-23 00:24 . 2009-07-23 00:24 97792 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_amd64_neutral_f9e57a11458a56da\RTNUninst64.dll + 2009-03-05 20:54 . 2009-03-05 20:54 67584 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_amd64_neutral_f9e57a11458a56da\RtNicProp64.dll + 2009-10-12 12:40 . 2009-10-12 12:40 13931 c:\windows\system32\DriverStore\FileRepository\netr28x.inf_amd64_neutral_9273a81105164ee0\RaCoInst.dat + 2009-12-10 01:05 . 2010-12-13 03:51 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-12-10 01:05 . 2010-12-06 16:28 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-12-10 01:05 . 2010-12-06 16:28 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-12-10 01:05 . 2010-12-13 03:51 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2010-12-13 03:51 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2010-12-06 16:28 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:46 . 2010-12-13 15:02 78720 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat - 2009-12-10 01:15 . 2010-12-07 16:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-12-10 01:15 . 2010-12-13 15:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-12-10 01:15 . 2010-12-13 15:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-12-10 01:15 . 2010-12-07 16:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-04-17 21:09 . 2010-12-10 02:42 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe - 2010-04-17 21:09 . 2010-04-17 21:09 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe - 2010-04-17 21:09 . 2010-04-17 21:09 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe + 2010-04-17 21:09 . 2010-12-10 02:42 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe + 2010-04-17 21:09 . 2010-12-10 02:42 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe - 2010-04-17 21:09 . 2010-04-17 21:09 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe - 2010-04-17 21:09 . 2010-04-17 21:09 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe + 2010-04-17 21:09 . 2010-12-10 02:42 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe - 2010-04-17 21:09 . 2010-04-17 21:09 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\ARPPRODUCTICON.exe + 2010-04-17 21:09 . 2010-12-10 02:42 77542 c:\windows\Installer\{E50A5077-1654-BEAE-986B-7B7133DA7C48}\ARPPRODUCTICON.exe - 2010-12-07 12:34 . 2010-12-07 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2010-12-14 03:29 . 2010-12-14 03:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2010-12-14 03:29 . 2010-12-14 03:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2010-12-07 12:34 . 2010-12-07 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-12-10 03:09 . 2010-12-13 13:57 330868 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin - 2009-07-14 05:30 . 2010-12-06 17:35 143360 c:\windows\system32\DriverStore\infstrng.dat + 2009-07-14 05:30 . 2010-12-10 02:51 143360 c:\windows\system32\DriverStore\infstrng.dat + 2009-07-14 05:30 . 2010-12-10 02:50 143360 c:\windows\system32\DriverStore\infstor.dat - 2009-07-14 05:30 . 2010-12-06 17:35 143360 c:\windows\system32\DriverStore\infstor.dat + 2009-08-21 06:05 . 2009-08-21 06:05 239616 c:\windows\system32\DriverStore\FileRepository\netrtx64.inf_amd64_neutral_f9e57a11458a56da\Rt64win7.sys + 2009-10-12 12:40 . 2009-10-12 12:40 305152 c:\windows\system32\DriverStore\FileRepository\netr28x.inf_amd64_neutral_9273a81105164ee0\RaCoInstx.dll + 2009-10-12 12:42 . 2009-10-12 12:42 763904 c:\windows\system32\DriverStore\FileRepository\netr28x.inf_amd64_neutral_9273a81105164ee0\netr28x.sys + 2009-08-21 06:05 . 2009-08-21 06:05 239616 c:\windows\system32\drivers\Rt64win7.sys + 2009-10-12 12:42 . 2009-10-12 12:42 763904 c:\windows\system32\drivers\netr28x.sys + 2010-02-22 09:44 . 2010-02-22 09:44 449024 c:\windows\Installer\d5529c7.msi - 2009-07-14 04:45 . 2010-11-29 04:14 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat + 2009-07-14 04:45 . 2010-12-13 13:25 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat - 2010-10-26 03:57 . 2010-12-07 03:45 7317944 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2010-10-26 03:57 . 2010-12-14 03:28 7317944 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2010-02-22 09:38 . 2010-02-22 09:38 6665216 c:\windows\Installer\d5529d2.msi - 2009-07-14 02:34 . 2010-12-09 12:52 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat + 2009-07-14 02:34 . 2010-12-13 23:57 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "HP KEYBOARDx"="c:\program files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE" [2009-07-15 715264] "SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1314816] "Buttons & OSDs control application gen3"="c:\program files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe" [2009-07-03 212992] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-05-13 581480] "UpdatePRCShortCut"="c:\program files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-03 98304] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-11-29 443728] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 hidkmdf;Microsoft HID Class Shim for KMDF;c:\windows\system32\DRIVERS\hidkmdf.sys [2009-07-29 13816] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-22 1255736] R4 CalendarSynchService;CalendarSynchService;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2009-07-09 21560] R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 136176] R4 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 27216] S1 archlp;archlp;SysWOW64\drivers\archlp.sys [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-02-03 202752] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 61008] S2 CGVPNCliSrvc;CyberGhost VPN Client;c:\program files\S.A.D\CyberGhost VPN\CGVPNCliService.exe [2010-07-28 2404488] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2010-11-29 363344] S3 ACPIService;Buttons and OSDs ACPI driver gen2;c:\windows\system32\DRIVERS\OSDACPI.SYS [2009-06-17 17992] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-02-03 6366720] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-02-03 186880] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-11-29 24152] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2009-10-12 763904] S3 NW1950;NextWindow 1950 Touch Screen;c:\windows\system32\DRIVERS\NW1950.sys [2009-07-29 24568] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-21 239616] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc . Contents of the 'Scheduled Tasks' folder 2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 19:41] 2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-22 19:41] 2010-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001Core.job - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 03:21] 2010-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2893100710-462183256-3003619119-1001UA.job - c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 03:21] 2010-12-14 c:\windows\Tasks\HPCeeScheduleForThomas.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 10:22] 2010-11-30 c:\windows\Tasks\PCDRScheduledMaintenance.job - c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-06-10 11:04] . ——— x86-64 ———– . ——- Supplementary Scan ——- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=crossfire&pf=cndt uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=crossfire&pf=cndt mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 Trusted Zone: intuit.com\ttlc FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\0egx6xlg.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} . - - - - ORPHANS REMOVED - - - - Wow6432Node-HKCU-Run-DriverScanner - c:\program files (x86)\Uniblue\DriverScanner\launcher.exe WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\JAN2OSD.exe c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe c:\program files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe . ************************************************************************** . Completion time: 2010-12-13 21:35:04 - machine was rebooted ComboFix-quarantined-files.txt 2010-12-14 03:35 ComboFix2.txt 2010-12-09 18:05 Pre-Run: 9,136,111,616 bytes free Post-Run: 9,774,899,200 bytes free - - End Of File - - C7138FACD3BC3E228D3409F5C1F6AA28 The internet is running much faster now:-) So just curious, what sort of issues were there in my machine? Thanks!!
you had a java exploit, trojan downloader.

Just some housekeeping to do now.

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

You can delete the TDSSKiller, MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Now we need to create a new clean SYSTEM RESTORE point.

  • press the Win key on the keyboard, type Restore then press enter to get to the System Restore section.
  • Click "Create a restore point" Click on the "Create" button to create a new restore point. You may be prompted for permission to continue - ALLOW it to continue. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Win key on the keyboard, type cleanmgr to access the disk cleanup
  • choose all files on the computer, then choose the C: drive, press OK Disk cleanup calculates the files, this takes a few minutes > another menu will pop up.
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • You will be asked if you’re sure, click on the Delete button, click OK > Delete Files


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Should you wish to contribute to my ongoing fight against malware, donations are being accepted >>Here<<


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI