This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Web Browser redirects to ad sites; Unsure if PC is infected.

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My OS is Windows Vista Home Premium These days very often when I click on links in forums using Firefox 3.6.13 it redirects to random ad sites and does not display the page. I manually copy the link location and then edit it to remove redirection after which I can get the site to load. Is there a firefox setting that I have enabled which causes this to happen or is my PC infected? The performance of my PC is fine and I generally don't have performance issues other than redirection. Could someone analyze the DDS logs for me please? Thanks. —————————– DDS.txt —————————– . DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 23:54:25.94 on Sun 01/16/2011 Internet Explorer: 9.0.7930.16406 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.852 [GMT -5:00] AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} SP: Symantec Endpoint Protection *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493} SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Norton Internet Security *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Citrix\GoToMyPC\g2svc.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Citrix\GoToMyPC\g2comm.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Citrix\GoToMyPC\g2pre.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Citrix\GoToMyPC\g2tray.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Winamp\winamp.exe C:\Program Files\Winamp\Elevator.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\BitDefender\BitDefender 2011\downloader.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\test\Desktop\PC Cleaning Software\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.bing.com/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop uURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File BHO: Bookmark Buddy Helper: {c6ceac32-d45c-11d4-94af-0050babd5fd6} - c:\program files\bookmark buddy\UrlOrgIE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No File BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: {0C8413C1-FAD1-446C-8584-BE50576F863E} - No File TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2011\IEToolbar.dll TB: {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - No File TB: {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2011\ieshow.exe" mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2011\bdagent.exe" mRun: [] mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe mRunOnce: ["c:\windows\system32\cmd.exe"] "c:\windows\system32\cmd.exe" /c "rmdir /s /q "c:\program files\jv16 PowerTools 2010"" uPolicies-explorer: NoFavoritesMenu = 1 (0x1) uPolicies-explorer: NoSMHelp = 1 (0x1) uPolicies-explorer: NoFind = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoFileAssociate = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: NoDispSettingsPage = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: igfxcui - igfxdev.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\test\appdata\roaming\mozilla\firefox\profiles\7xeov8pp.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com FF - component: c:\program files\bitdefender\bitdefender 2011\bdaphffext\components\bdaphff3.6.dll FF - component: c:\program files\bitdefender\bitdefender 2011\bdaphffext\components\bdaphff3.dll FF - plugin: c:\program files\common files\motive\npMotive.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\test\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2010-6-18 72784] R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-10-5 143184] R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-10-5 41936] R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};Power Control [2010/12/04 19:45:41];c:\program files\hp\quickplay\000.fcl [2010-12-4 87536] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088] R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2011\updatesrv.exe [2010-6-29 43424] R3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:\windows\system32\drivers\BazisVirtualCDBus.sys [2010-4-6 98400] R3 BDFM;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-5-13 152528] R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-17 21504] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-11-17 4247552] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2010-8-5 100496] R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2010-8-5 111312] S3 BrlAPI;BrlAPI;c:\cygwin\bin\cygrunsrv.exe –> c:\cygwin\bin\cygrunsrv.exe [?] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-2-21 55280] S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360] S3 ServiceEmulation;HP ServiceEmulation;"c:\program files\hp\loadrunner\apache-tomcat-5.5.17\bin\tomcat5.exe" //rs//serviceemulation –> c:\program files\hp\loadrunner\apache-tomcat-5.5.17\bin\tomcat5.exe [?] S3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [2010-8-20 26112] S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2010-6-29 307544] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] S4 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2010-6-28 633424] S4 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2010-6-28 970320] S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-10 133104] S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe" /service msvsmon80 –> c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [?] S4 SeaPort;SeaPort;"c:\program files\microsoft\search enhancement pack\seaport\seaport.exe" –> c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [?] SUnknown WPFFontCache_v0400;WPFFontCache_v0400; [x] =============== Created Last 30 ================ 2011-01-16 15:56 22 a–sh— c:\windows\Sys3390 SettingsCollection.bin 2011-01-16 15:56 22 a–sh— c:\users\test\appdata\roaming\Sys6925.Config Collection.sys 2011-01-16 15:56 –d—– c:\program files\jv16 PowerTools 2010 2011-01-16 15:12 1,493,528 a——- c:\windows\system32\D3DCompiler_39.dll 2011-01-16 15:12 467,984 a——- c:\windows\system32\d3dx10_39.dll 2011-01-16 15:12 3,851,784 a——- c:\windows\system32\D3DX9_39.dll 2011-01-16 15:11 –d—– c:\programdata\PassMark 2011-01-16 15:11 –d—– c:\progra~2\PassMark 2011-01-15 21:03 413,696 a——- c:\windows\system32\odbc32.dll 2011-01-15 21:03 1,169,408 a——- c:\windows\system32\sdclt.exe 2011-01-15 08:41 341,461,206 a——- c:\windows\MEMORY.DMP 2011-01-13 18:33 558 ——– c:\windows\hpomdl37.dat.temp 2011-01-10 23:45 0 a—h— c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf 2011-01-10 23:39 –d—– c:\users\test\.android 2011-01-10 23:38 –d—– c:\program files\Android 2011-01-07 21:17 –d—– c:\users\test\appdata\roaming\pdftoepub 2011-01-02 16:54 –d—– c:\users\test\appdata\roaming\HpUpdate 2011-01-02 16:52 –d—– c:\program files\Coupons 2011-01-02 16:51 –d—– c:\programdata\HP Photo Creations 2011-01-02 16:51 –d—– c:\program files\HP Photo Creations 2011-01-02 16:51 –d—– c:\progra~2\HP Photo Creations 2011-01-02 16:50 –d—– c:\programdata\HP Product Assistant 2011-01-02 16:42 –d—– c:\program files\common files\Hewlett-Packard 2011-01-02 16:41 271,704 a——- c:\windows\system32\hpzids01.dll 2011-01-02 16:41 121,344 a——- c:\windows\system32\hpf3l083.dll 2011-01-02 16:40 737,280 a——- c:\windows\system32\hposwia_d02a.dll 2011-01-02 16:40 598,016 a——- c:\windows\system32\hpost_d02a.dll 2011-01-02 16:40 372,736 a——- c:\windows\system32\hppldcoi.dll 2011-01-02 16:40 307,200 a——- c:\windows\system32\hposc_d02a.dll 2011-01-02 16:34 171,868 a——- c:\windows\hpoins37.dat 2010-12-28 14:23 16 a——- c:\windows\system32\asdict.dat 2010-12-28 12:09 –d—– c:\programdata\bdch 2010-12-28 12:09 –d—– c:\progra~2\bdch 2010-12-28 10:28 308,152 a——- c:\windows\system32\drivers\trufos.sys 2010-12-28 10:28 327,368 a——- c:\windows\system32\drivers\bdfsfltr.sys 2010-12-28 09:18 2,381,824 a——- c:\windows\system32\mshtml.tlb 2010-12-28 09:18 1,448,448 a——- c:\windows\system32\inetcpl.cpl 2010-12-28 04:54 –d—– C:\bd_logs 2010-12-26 21:34 48,128 a——- c:\windows\system32\simple.exe 2010-12-26 21:34 646 a——- c:\windows\system32\simple.obj 2010-12-26 21:33 93 a——- c:\windows\system32\simple.c 2010-12-25 23:01 –d—– c:\program files\Veetle 2010-12-22 20:26 –d—– c:\program files\Symantec 2010-12-21 08:22 52 a——- c:\windows\system32\ashttpstats.csv 2010-12-20 21:57 385 a——- c:\windows\system32\user_gensett.xml 2010-12-20 21:52 –d—– c:\users\test\appdata\roaming\BitDefender 2010-12-20 21:50 –d—– c:\program files\BitDefender 2010-12-20 21:44 –d—– c:\users\test\appdata\roaming\QuickScan 2010-12-20 21:44 –d—– c:\program files\common files\BitDefender 2010-12-20 21:44 –d—– c:\programdata\BitDefender 2010-12-20 21:44 –d—– c:\progra~2\BitDefender 2010-12-20 18:42 367,104 a——- c:\windows\system32\html.iec 2010-12-20 18:40 1,174,528 a——- c:\windows\system32\d3d10warp.dll 2010-12-20 18:40 1,068,032 a——- c:\windows\system32\DWrite.dll 2010-12-20 18:40 979,456 a——- c:\windows\system32\MFH264Dec.dll 2010-12-20 18:40 797,184 a——- c:\windows\system32\FntCache.dll 2010-12-20 18:40 680,960 a——- c:\windows\system32\d2d1.dll 2010-12-20 18:40 357,376 a——- c:\windows\system32\MFHEAACdec.dll 2010-12-20 18:40 302,592 a——- c:\windows\system32\mfmp4src.dll 2010-12-20 18:40 280,064 a——- c:\windows\system32\XpsGdiConverter.dll 2010-12-20 18:40 261,632 a——- c:\windows\system32\mfreadwrite.dll 2010-12-20 18:40 219,648 a——- c:\windows\system32\d3d10_1core.dll 2010-12-20 18:40 161,280 a——- c:\windows\system32\d3d10_1.dll 2010-12-20 18:40 135,680 a——- c:\windows\system32\XpsRasterService.dll 2010-12-20 18:39 –d—– c:\program files\Feedback Tool 2010-12-18 00:23 3,786,760 a——- c:\windows\system32\D3DX9_37.dll 2010-12-18 00:23 3,727,720 a——- c:\windows\system32\d3dx9_35.dll 2010-12-18 00:23 3,497,832 a——- c:\windows\system32\d3dx9_34.dll ==================== Find3M ==================== 2011-01-10 23:45 143,360 a——- c:\windows\inf\infstrng.dat 2011-01-10 23:45 51,200 a——- c:\windows\inf\infpub.dat 2011-01-10 23:45 143,360 a——- c:\windows\inf\infstor.dat 2011-01-10 23:34 472,808 a——- c:\windows\system32\deployJava1.dll 2011-01-10 23:31 581,192 a——- c:\windows\system32\WinUSBCoInstaller.dll 2011-01-10 23:31 1,112,288 a——- c:\windows\system32\WdfCoInstaller01007.dll 2010-12-28 11:07 72,784 a——- c:\windows\system32\drivers\bdfndisf6.sys 2010-12-20 18:09 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-20 18:08 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-12-12 15:49 959 a——- C:\ReBoot-Time.vbs 2010-12-09 18:39 7,053,264 a——- c:\users\test\gosetup.exe 2010-11-11 20:31 1,062,984 a——- c:\users\test\gotomypc_540.exe 2010-11-04 13:56 345,600 a——- c:\windows\system32\wmicmiplugin.dll 2010-11-04 13:55 352,768 a——- c:\windows\system32\taskschd.dll 2010-11-04 13:55 270,336 a——- c:\windows\system32\taskcomp.dll 2010-11-04 13:55 601,600 a——- c:\windows\system32\schedsvc.dll 2010-11-04 11:34 171,520 a——- c:\windows\system32\taskeng.exe 2010-10-28 10:44 34,304 a——- c:\windows\system32\atmlib.dll 2010-10-28 08:27 292,352 a——- c:\windows\system32\atmfd.dll 2010-10-28 08:20 2,048 a——- c:\windows\system32\tzres.dll 2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe 2010-08-10 13:01 72,080 a——- c:\users\test\g2mdlhlpx.exe 2010-03-29 18:40 100,256 a——- c:\program files\common files\LinkInstaller.exe 2009-11-06 01:38 665,600 a——- c:\windows\inf\drvindex.dat 2009-02-13 22:43 81 a——- c:\users\test\CTX.DAT 2008-10-19 04:25 174 a–sh— c:\program files\desktop.ini 2008-10-18 15:19 13,336,096 a——- c:\users\test\IE8-WindowsVista-x86-ENU.exe 2008-10-02 14:52 92,448 a——- c:\users\test\appdata\roaming\GDIPFONTCACHEV1.DAT 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2010-02-04 14:42 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2010-02-04 14:42 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2010-02-04 14:42 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat 2010-08-13 01:29 262,144 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 23:57:11.82 =============== ================================================================== Attach.txt ================================================================== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 7/20/2007 8:28:46 PM System Uptime: 1/16/2011 1:02:16 PM (10 hours ago) Motherboard: Quanta | | 30BB Processor: Intel® Core™ Duo CPU T2450 @ 2.00GHz | U2E1 | 2000/533mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 141 GiB total, 48.727 GiB free. D: is FIXED (NTFS) - 8 GiB total, 1.327 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Teefer2 Miniport Device ID: ROOT\SYMC_TEEFER2MP\0003 Manufacturer: Symantec Name: WAN Miniport (Network Monitor) - Teefer2 Miniport PNP Device ID: ROOT\SYMC_TEEFER2MP\0003 Service: Teefer2 Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Teefer2 Miniport Device ID: ROOT\SYMC_TEEFER2MP\0004 Manufacturer: Symantec Name: Intel® PRO/Wireless 3945ABG Network Connection - Teefer2 Miniport PNP Device ID: ROOT\SYMC_TEEFER2MP\0004 Service: Teefer2 Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Teefer2 Miniport Device ID: ROOT\SYMC_TEEFER2MP\0005 Manufacturer: Symantec Name: Intel® PRO/100 VE Network Connection - Teefer2 Miniport PNP Device ID: ROOT\SYMC_TEEFER2MP\0005 Service: Teefer2 Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Teefer2 Miniport Device ID: ROOT\SYMC_TEEFER2MP\0006 Manufacturer: Symantec Name: WAN Miniport (IP) - Teefer2 Miniport PNP Device ID: ROOT\SYMC_TEEFER2MP\0006 Service: Teefer2 Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Teefer2 Miniport Device ID: ROOT\SYMC_TEEFER2MP\0007 Manufacturer: Symantec Name: WAN Miniport (IPv6) - Teefer2 Miniport PNP Device ID: ROOT\SYMC_TEEFER2MP\0007 Service: Teefer2 ==== System Restore Points =================== RP1041: 1/16/2011 3:11:18 PM - Installed DirectX ==== Installed Programs ====================== 32 Bit HP CIO Components Installer 7-Zip 9.16 beta Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Shockwave Player Android SDK Tools Apple Application Support Apple Mobile Device Support Apple Software Update BitDefender Internet Security 2011 Bookmark Buddy BookMark Master v3.13 BufferChm CCleaner Conexant HD Audio Copy Coupon Printer for Windows Crystal Reports Basic for Visual Studio 2008 Destinations DeviceDiscovery Dexpot DivX Web Player DJ_AIO_05_F4400_Software_Min Dropbox EA Download Manager F4400 FIFA 10 FileZilla [removed] Foxit PDF Editor Foxit Reader GoToMyPC GPBaseService2 HDAUDIO Soft Data Fax Modem with SmartCP Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual Studio 2008 Professional Edition - ENU (KB971091) Hotfix for Microsoft Visual Studio 2008 Professional Edition - ENU (KB973674) HP Active Support Library 32 bit components HP Customer Participation Program 14.0 HP Deskjet F4400 Printer Driver Software 14.0 Rel. 5 HP Doc Viewer HP DVD Play 3.7 HP Imaging Device Functions 14.0 HP Photo Creations HP Smart Web Printing 4.60 HP Solution Center 14.0 HP Update HP User Guides 0082 HP Wireless Assistant HPPhotoGadget HPProductAssistant InfraRecorder Intel® Graphics Media Accelerator Driver Intel® Network Connections Drivers IrfanView (remove only) iTunes Java Auto Updater Java DB 10.5.3.0 Java™ 6 Update 23 Java™ 6 Update 7 Java™ SE Development Kit 6 Update 22 Java™ SE Development Kit 6 Update 23 Java™ SE Runtime Environment 6 K-Lite Mega Codec Pack 5.7.0 Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Compact Framework 3.5 Microsoft .NET Framework 3.5 SP1 Microsoft Device Emulator version 3.0 - ENU Microsoft Document Explorer 2008 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2) Microsoft Office Visual Web Developer 2007 Microsoft Office Visual Web Developer MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Compact 3.5 Design Tools ENU Microsoft SQL Server Compact 3.5 ENU Microsoft SQL Server Compact 3.5 for Devices ENU Microsoft SQL Server Database Publishing Wizard 1.2 Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual Studio 2005 Tools for Office Runtime Microsoft Visual Studio 2008 Professional Edition - ENU Microsoft Visual Studio Web Authoring Component Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense Microsoft Windows SDK for Visual Studio 2008 Tools Microsoft Windows SDK for Visual Studio 2008 Win32 Tools Microsoft WSE 2.0 SP3 Runtime Microsoft WSE 3.0 Runtime Mozilla Firefox (3.6.13) MSCU for Microsoft Vista MSVCRT MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NVIDIA Drivers Oracle VM VirtualBox 3.2.8 PDFCreator PuTTY 0.60 Real Alternative 1.9.0 Scan Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) SmartWebPrinting SolutionCenter SpywareBlaster 4.4 Status Synaptics Pointing Device Driver System Requirements Lab Toolbox TrayApp TrueCrypt Unlocker 1.9.0 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Visual Studio 2008 Professional Edition - ENU (KB972221) VC Runtimes MSI Veetle TV 0.9.18 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual Studio 2005 Tools for Office Second Edition Runtime Visual Studio Tools for the Office system 3.0 Runtime VLC media player 1.1.5 WebReg Winamp WinCDEmu WinDjView 1.0.3 Windows Installer Clean Up Windows Live Essentials Windows Media Player Firefox Plugin Windows Mobile 5.0 SDK R2 for Pocket PC Windows Mobile 5.0 SDK R2 for Smartphone WinPcap 4.1.2 Wireshark 1.4.0 ==== Event Viewer Messages From Past Week ======== 1/16/2011 1:04:17 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 1/16/2011 1:04:17 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 1/16/2011 1:01:24 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VSSERV service. ==== End Of File ===========================
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.
  • Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan
      • Only if Malicious objects are found then ensure Cure is selected
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
    please post the contents of that log TDSSKiller and GooredFix log.
Hi LDTate, Thanks a lot for your reply. I followed your instructions and have pasted the contents of the two log files below. Thanks. 1) GooredFix GooredFix by jpshortstuff (03.07.10.1) Log created at 13:23 on 18/01/2011 (test) Firefox version [Unable to determine] ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [13:33 21/12/2010] {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [01:59 31/10/2010] C:\Users\test\Application Data\Mozilla\Firefox\Profiles\7xeov8pp.default\extensions\ {20a82645-c095-46ed-80e3-08825760534b} [00:28 06/01/2011] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [02:51 29/12/2010] {DDC359D1-844A-42a7-9AA1-88A850A938A8} [18:54 12/01/2011] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] (Key not found) -=E.O.F=- 2) TDSSKiller.exe 2011/01/18 13:24:47.0038 TDSS rootkit removing tool 2.4.14.0 Jan 18 2011 09:33:51 2011/01/18 13:24:47.0038 ================================================================================ 2011/01/18 13:24:47.0038 SystemInfo: 2011/01/18 13:24:47.0038 2011/01/18 13:24:47.0038 OS Version: 6.0.6002 ServicePack: 2.0 2011/01/18 13:24:47.0038 Product type: Workstation 2011/01/18 13:24:47.0038 ComputerName: TEST-PC 2011/01/18 13:24:47.0039 UserName: test 2011/01/18 13:24:47.0039 Windows directory: C:\Windows 2011/01/18 13:24:47.0039 System windows directory: C:\Windows 2011/01/18 13:24:47.0039 Processor architecture: Intel x86 2011/01/18 13:24:47.0039 Number of processors: 2 2011/01/18 13:24:47.0039 Page size: 0x1000 2011/01/18 13:24:47.0039 Boot type: Normal boot 2011/01/18 13:24:47.0039 ================================================================================ 2011/01/18 13:24:47.0517 Initialize success 2011/01/18 13:24:57.0293 ================================================================================ 2011/01/18 13:24:57.0293 Scan started 2011/01/18 13:24:57.0293 Mode: Manual; 2011/01/18 13:24:57.0293 ================================================================================ 2011/01/18 13:24:58.0259 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/01/18 13:24:58.0337 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2011/01/18 13:24:58.0388 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2011/01/18 13:24:58.0437 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2011/01/18 13:24:58.0481 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2011/01/18 13:24:58.0553 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/01/18 13:24:58.0600 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2011/01/18 13:24:58.0635 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/01/18 13:24:58.0684 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 2011/01/18 13:24:58.0722 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2011/01/18 13:24:58.0752 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 2011/01/18 13:24:58.0791 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2011/01/18 13:24:58.0833 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2011/01/18 13:24:58.0897 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2011/01/18 13:24:58.0943 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2011/01/18 13:24:59.0002 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/01/18 13:24:59.0065 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/01/18 13:24:59.0166 avc3 (c6cf76384dfc739b0be55abb79ad4dc0) C:\Windows\system32\DRIVERS\avc3.sys 2011/01/18 13:24:59.0263 avckf (b758a219e95c085405b1e356a8267610) C:\Windows\system32\DRIVERS\avckf.sys 2011/01/18 13:24:59.0372 BazisVirtualCDBus (33ac10402622b7e92ca44075f1bec94b) C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys 2011/01/18 13:24:59.0434 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 2011/01/18 13:24:59.0479 BDFM (8d4efc5c378bffe34c298c92f37d3b14) C:\Windows\system32\DRIVERS\bdfm.sys 2011/01/18 13:24:59.0572 Bdfndisf (817fc12bc93a70b0449ebefaa4d6f4d2) c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys 2011/01/18 13:24:59.0628 bdfsfltr (4c44d82e372a87b3cb439a7f14cfef03) C:\Windows\system32\DRIVERS\bdfsfltr.sys 2011/01/18 13:24:59.0683 Bdftdif (c23a8547d5ea6d0c3589961bfb7ff6d3) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys 2011/01/18 13:24:59.0748 bdselfpr (1c947f018c7393eab0da5e4a50952f63) C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys 2011/01/18 13:24:59.0863 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/01/18 13:24:59.0980 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/01/18 13:25:00.0030 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/01/18 13:25:00.0067 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/01/18 13:25:00.0117 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/01/18 13:25:00.0156 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/01/18 13:25:00.0196 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/01/18 13:25:00.0232 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/01/18 13:25:00.0266 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/01/18 13:25:00.0337 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/01/18 13:25:00.0384 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/01/18 13:25:00.0428 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2011/01/18 13:25:00.0481 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/01/18 13:25:00.0550 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/01/18 13:25:00.0587 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 2011/01/18 13:25:00.0638 CnxtHdAudService (a4d44ab8423791db757b38150ec599a4) C:\Windows\system32\drivers\CHDRT32.sys 2011/01/18 13:25:00.0678 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/01/18 13:25:00.0715 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2011/01/18 13:25:00.0755 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2011/01/18 13:25:00.0816 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\Windows\system32\DRIVERS\CVirtA.sys 2011/01/18 13:25:00.0873 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/01/18 13:25:00.0929 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/01/18 13:25:01.0015 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 2011/01/18 13:25:01.0080 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 2011/01/18 13:25:01.0132 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 2011/01/18 13:25:01.0188 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/01/18 13:25:01.0257 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys 2011/01/18 13:25:01.0322 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\Windows\system32\DRIVERS\e100b325.sys 2011/01/18 13:25:01.0374 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/01/18 13:25:01.0419 eabfiltr (e88b0cfcecf745211bba87f44f85d0dd) C:\Windows\system32\DRIVERS\eabfiltr.sys 2011/01/18 13:25:01.0482 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/01/18 13:25:01.0560 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2011/01/18 13:25:01.0647 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/01/18 13:25:01.0701 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/01/18 13:25:01.0734 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2011/01/18 13:25:01.0804 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/01/18 13:25:01.0860 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/01/18 13:25:01.0895 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/01/18 13:25:01.0952 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/01/18 13:25:02.0037 fssfltr (574cea4d3510ec905c0163c42d305ba5) C:\Windows\system32\DRIVERS\fssfltr.sys 2011/01/18 13:25:02.0085 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/01/18 13:25:02.0135 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2011/01/18 13:25:02.0197 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/01/18 13:25:02.0272 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys 2011/01/18 13:25:02.0325 HBtnKey (de15777902a5d9121857d155873a1d1b) C:\Windows\system32\DRIVERS\cpqbttn.sys 2011/01/18 13:25:02.0419 HdAudAddService (07eee11d6e2b78122e17db3878b4c687) C:\Windows\system32\drivers\CHDART.sys 2011/01/18 13:25:02.0757 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/01/18 13:25:02.0831 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/01/18 13:25:02.0865 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/01/18 13:25:02.0922 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/01/18 13:25:02.0967 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2011/01/18 13:25:03.0064 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2011/01/18 13:25:03.0236 HSF_DPV (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/01/18 13:25:03.0325 HSXHWAZL (a44ddf3ba83e4664bf4de9220097578c) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/01/18 13:25:03.0396 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/01/18 13:25:03.0453 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2011/01/18 13:25:03.0515 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/01/18 13:25:03.0825 ialm (e5490aea3b791c454e9933bf749ca3d8) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/01/18 13:25:04.0009 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2011/01/18 13:25:04.0313 igfx (e5490aea3b791c454e9933bf749ca3d8) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/01/18 13:25:04.0552 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/01/18 13:25:04.0690 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/01/18 13:25:04.0736 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/01/18 13:25:04.0794 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/01/18 13:25:04.0873 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2011/01/18 13:25:04.0926 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/01/18 13:25:04.0979 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/01/18 13:25:05.0022 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2011/01/18 13:25:05.0075 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/01/18 13:25:05.0116 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/01/18 13:25:05.0154 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/01/18 13:25:05.0204 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/01/18 13:25:05.0252 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/01/18 13:25:05.0313 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/01/18 13:25:05.0439 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/01/18 13:25:05.0509 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2011/01/18 13:25:05.0541 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2011/01/18 13:25:05.0580 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2011/01/18 13:25:05.0630 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/01/18 13:25:05.0887 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/01/18 13:25:05.0964 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2011/01/18 13:25:06.0014 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/01/18 13:25:06.0056 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/01/18 13:25:06.0107 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/01/18 13:25:06.0144 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/01/18 13:25:06.0198 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/01/18 13:25:06.0247 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2011/01/18 13:25:06.0356 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/01/18 13:25:06.0406 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/01/18 13:25:06.0535 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS 2011/01/18 13:25:06.0597 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS 2011/01/18 13:25:06.0658 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/01/18 13:25:06.0717 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/01/18 13:25:06.0754 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/01/18 13:25:06.0795 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/01/18 13:25:06.0854 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/01/18 13:25:06.0912 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2011/01/18 13:25:06.0974 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/01/18 13:25:07.0023 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/01/18 13:25:07.0091 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/01/18 13:25:07.0144 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/01/18 13:25:07.0178 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/01/18 13:25:07.0228 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/01/18 13:25:07.0277 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/01/18 13:25:07.0314 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/01/18 13:25:07.0413 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/01/18 13:25:07.0478 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/01/18 13:25:07.0530 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/01/18 13:25:07.0620 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/01/18 13:25:07.0664 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/01/18 13:25:07.0721 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/01/18 13:25:07.0806 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/01/18 13:25:08.0008 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/01/18 13:25:08.0071 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/01/18 13:25:08.0209 NETw3v32 (ea30bd026a7d1b745a37516880c4ac1b) C:\Windows\system32\DRIVERS\NETw3v32.sys 2011/01/18 13:25:08.0422 NETw5v32 (054ba4a208c7aaf4f787e4f5466755e6) C:\Windows\system32\DRIVERS\NETw5v32.sys 2011/01/18 13:25:08.0577 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/01/18 13:25:08.0623 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys 2011/01/18 13:25:08.0671 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/01/18 13:25:08.0721 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/01/18 13:25:08.0813 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/01/18 13:25:08.0888 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/01/18 13:25:08.0926 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/01/18 13:25:08.0974 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 2011/01/18 13:25:09.0010 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 2011/01/18 13:25:09.0046 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2011/01/18 13:25:09.0169 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/01/18 13:25:09.0237 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/01/18 13:25:09.0290 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/01/18 13:25:09.0328 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/01/18 13:25:09.0392 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/01/18 13:25:09.0430 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 2011/01/18 13:25:09.0471 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/01/18 13:25:09.0544 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/01/18 13:25:09.0764 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/01/18 13:25:09.0836 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2011/01/18 13:25:09.0987 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/01/18 13:25:10.0026 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 2011/01/18 13:25:10.0090 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2011/01/18 13:25:10.0159 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/01/18 13:25:10.0220 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/01/18 13:25:10.0269 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/01/18 13:25:10.0338 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/01/18 13:25:10.0390 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/01/18 13:25:10.0443 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/01/18 13:25:10.0506 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/01/18 13:25:10.0563 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/01/18 13:25:10.0631 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 2011/01/18 13:25:10.0673 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/01/18 13:25:10.0722 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/01/18 13:25:10.0802 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\Windows\system32\DRIVERS\rimmptsk.sys 2011/01/18 13:25:10.0833 rimsptsk (db8eb01c58c9fada00c70b1775278ae0) C:\Windows\system32\DRIVERS\rimsptsk.sys 2011/01/18 13:25:10.0868 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\Windows\system32\DRIVERS\rixdptsk.sys 2011/01/18 13:25:10.0945 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/01/18 13:25:11.0000 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/01/18 13:25:11.0070 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 2011/01/18 13:25:11.0111 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/01/18 13:25:11.0167 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/01/18 13:25:11.0208 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/01/18 13:25:11.0263 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/01/18 13:25:11.0359 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 2011/01/18 13:25:11.0400 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2011/01/18 13:25:11.0447 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 2011/01/18 13:25:11.0479 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/01/18 13:25:11.0539 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2011/01/18 13:25:11.0595 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2011/01/18 13:25:11.0637 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2011/01/18 13:25:11.0716 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/01/18 13:25:11.0876 SNP2UVC (5140166bbcafe1393d4669353a1f8c0a) C:\Windows\system32\DRIVERS\snp2uvc.sys 2011/01/18 13:25:12.0013 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/01/18 13:25:12.0091 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\Windows\system32\Drivers\sptd.sys 2011/01/18 13:25:12.0091 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9 2011/01/18 13:25:12.0098 sptd - detected Locked file (1) 2011/01/18 13:25:12.0170 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/01/18 13:25:12.0216 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/01/18 13:25:12.0262 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/01/18 13:25:12.0336 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/01/18 13:25:12.0402 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/01/18 13:25:12.0438 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/01/18 13:25:12.0471 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/01/18 13:25:12.0529 SynTP (f5d926807bd9bc0af68f9376144de425) C:\Windows\system32\DRIVERS\SynTP.sys 2011/01/18 13:25:12.0596 tap0901 (11d34fc869f5bda29949fe3858380894) C:\Windows\system32\DRIVERS\tap0901.sys 2011/01/18 13:25:12.0688 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2011/01/18 13:25:12.0761 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2011/01/18 13:25:12.0821 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/01/18 13:25:12.0860 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/01/18 13:25:12.0901 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/01/18 13:25:12.0953 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/01/18 13:25:13.0010 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/01/18 13:25:13.0092 truecrypt (be45dad1c73a3216edc8c485916f6594) C:\Windows\system32\drivers\truecrypt.sys 2011/01/18 13:25:13.0153 Trufos (127dc1adaf55f99ab6696bb455820a96) C:\Windows\system32\DRIVERS\Trufos.sys 2011/01/18 13:25:13.0219 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/01/18 13:25:13.0268 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/01/18 13:25:13.0323 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/01/18 13:25:13.0381 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2011/01/18 13:25:13.0441 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/01/18 13:25:13.0513 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2011/01/18 13:25:13.0560 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2011/01/18 13:25:13.0605 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/01/18 13:25:13.0647 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/01/18 13:25:13.0694 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/01/18 13:25:13.0819 UnlockerDriver5 (bb879dcfd22926efbeb3298129898cbb) C:\Program Files\Unlocker\UnlockerDriver5.sys 2011/01/18 13:25:13.0897 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/01/18 13:25:13.0954 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/01/18 13:25:14.0017 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/01/18 13:25:14.0053 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/01/18 13:25:14.0102 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/01/18 13:25:14.0166 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/01/18 13:25:14.0224 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/01/18 13:25:14.0275 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/01/18 13:25:14.0334 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/01/18 13:25:14.0388 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/01/18 13:25:14.0450 VBoxDrv (3e4b3de332634151d10bca5c0f3dd226) C:\Windows\system32\DRIVERS\VBoxDrv.sys 2011/01/18 13:25:14.0505 VBoxNetAdp (02cf071ee8cad9667ec0736c57360b70) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 2011/01/18 13:25:14.0565 VBoxNetFlt (9200e34447dd628c0080f41b15378e83) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys 2011/01/18 13:25:14.0611 VBoxUSBMon (be71306e451c5f9de9a64b32038314ee) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 2011/01/18 13:25:14.0670 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/01/18 13:25:14.0721 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/01/18 13:25:14.0759 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2011/01/18 13:25:14.0792 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2011/01/18 13:25:14.0825 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 2011/01/18 13:25:14.0905 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/01/18 13:25:14.0955 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/01/18 13:25:15.0022 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/01/18 13:25:15.0098 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2011/01/18 13:25:15.0159 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/01/18 13:25:15.0224 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/01/18 13:25:15.0242 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/01/18 13:25:15.0296 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2011/01/18 13:25:15.0346 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 2011/01/18 13:25:15.0410 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/01/18 13:25:15.0535 winachsf (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/01/18 13:25:15.0659 WinUSB (676f4b665bdd8053eaa53ac1695b8074) C:\Windows\system32\DRIVERS\WinUSB.sys 2011/01/18 13:25:15.0718 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/01/18 13:25:15.0810 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/01/18 13:25:15.0883 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/01/18 13:25:15.0947 XAudio (19e7c173b6242ad7521e537ae54768bf) C:\Windows\system32\DRIVERS\xaudio.sys 2011/01/18 13:25:16.0052 {22D78859-9CE9-4B77-BF18-AC83E81A9263} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\HP\QuickPlay\000.fcl 2011/01/18 13:25:16.0133 ================================================================================ 2011/01/18 13:25:16.0133 Scan finished 2011/01/18 13:25:16.0133 ================================================================================ 2011/01/18 13:25:16.0150 Detected object count: 1 2011/01/18 13:25:24.0435 Locked file(sptd) - User select action: Skip 2011/01/18 13:25:31.0299 ================================================================================ 2011/01/18 13:25:31.0299 Scan started 2011/01/18 13:25:31.0299 Mode: Manual; 2011/01/18 13:25:31.0299 ================================================================================ 2011/01/18 13:25:31.0817 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/01/18 13:25:31.0917 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2011/01/18 13:25:32.0001 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2011/01/18 13:25:32.0039 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2011/01/18 13:25:32.0082 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2011/01/18 13:25:32.0155 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/01/18 13:25:32.0190 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2011/01/18 13:25:32.0225 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/01/18 13:25:32.0264 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 2011/01/18 13:25:32.0313 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2011/01/18 13:25:32.0341 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 2011/01/18 13:25:32.0381 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2011/01/18 13:25:32.0412 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2011/01/18 13:25:32.0465 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2011/01/18 13:25:32.0501 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2011/01/18 13:25:32.0549 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/01/18 13:25:32.0599 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/01/18 13:25:32.0679 avc3 (c6cf76384dfc739b0be55abb79ad4dc0) C:\Windows\system32\DRIVERS\avc3.sys 2011/01/18 13:25:32.0743 avckf (b758a219e95c085405b1e356a8267610) C:\Windows\system32\DRIVERS\avckf.sys 2011/01/18 13:25:32.0822 BazisVirtualCDBus (33ac10402622b7e92ca44075f1bec94b) C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys 2011/01/18 13:25:32.0891 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 2011/01/18 13:25:32.0925 BDFM (8d4efc5c378bffe34c298c92f37d3b14) C:\Windows\system32\DRIVERS\bdfm.sys 2011/01/18 13:25:33.0007 Bdfndisf (817fc12bc93a70b0449ebefaa4d6f4d2) c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys 2011/01/18 13:25:33.0062 bdfsfltr (4c44d82e372a87b3cb439a7f14cfef03) C:\Windows\system32\DRIVERS\bdfsfltr.sys 2011/01/18 13:25:33.0117 Bdftdif (c23a8547d5ea6d0c3589961bfb7ff6d3) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys 2011/01/18 13:25:33.0183 bdselfpr (1c947f018c7393eab0da5e4a50952f63) C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys 2011/01/18 13:25:33.0287 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/01/18 13:25:33.0403 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/01/18 13:25:33.0454 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/01/18 13:25:33.0491 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/01/18 13:25:33.0541 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/01/18 13:25:33.0580 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/01/18 13:25:33.0620 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/01/18 13:25:33.0667 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/01/18 13:25:33.0701 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/01/18 13:25:33.0761 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/01/18 13:25:33.0863 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/01/18 13:25:33.0941 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2011/01/18 13:25:34.0026 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/01/18 13:25:34.0084 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/01/18 13:25:34.0122 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 2011/01/18 13:25:34.0173 CnxtHdAudService (a4d44ab8423791db757b38150ec599a4) C:\Windows\system32\drivers\CHDRT32.sys 2011/01/18 13:25:34.0200 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/01/18 13:25:34.0237 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2011/01/18 13:25:34.0290 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2011/01/18 13:25:34.0351 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\Windows\system32\DRIVERS\CVirtA.sys 2011/01/18 13:25:34.0408 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/01/18 13:25:34.0461 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/01/18 13:25:34.0528 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 2011/01/18 13:25:34.0581 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 2011/01/18 13:25:34.0634 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 2011/01/18 13:25:34.0690 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/01/18 13:25:34.0758 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys 2011/01/18 13:25:34.0813 E100B (ac9cf17ee2ae003c98eb4f5336c38058) C:\Windows\system32\DRIVERS\e100b325.sys 2011/01/18 13:25:34.0864 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/01/18 13:25:34.0910 eabfiltr (e88b0cfcecf745211bba87f44f85d0dd) C:\Windows\system32\DRIVERS\eabfiltr.sys 2011/01/18 13:25:34.0972 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/01/18 13:25:35.0039 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2011/01/18 13:25:35.0126 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/01/18 13:25:35.0180 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/01/18 13:25:35.0214 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2011/01/18 13:25:35.0283 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/01/18 13:25:35.0339 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/01/18 13:25:35.0374 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/01/18 13:25:35.0431 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/01/18 13:25:35.0506 fssfltr (574cea4d3510ec905c0163c42d305ba5) C:\Windows\system32\DRIVERS\fssfltr.sys 2011/01/18 13:25:35.0553 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/01/18 13:25:35.0595 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2011/01/18 13:25:35.0632 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/01/18 13:25:35.0707 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys 2011/01/18 13:25:35.0760 HBtnKey (de15777902a5d9121857d155873a1d1b) C:\Windows\system32\DRIVERS\cpqbttn.sys 2011/01/18 13:25:35.0844 HdAudAddService (07eee11d6e2b78122e17db3878b4c687) C:\Windows\system32\drivers\CHDART.sys 2011/01/18 13:25:35.0959 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/01/18 13:25:36.0032 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/01/18 13:25:36.0122 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/01/18 13:25:36.0168 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/01/18 13:25:36.0212 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2011/01/18 13:25:36.0277 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2011/01/18 13:25:36.0384 HSF_DPV (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/01/18 13:25:36.0494 HSXHWAZL (a44ddf3ba83e4664bf4de9220097578c) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/01/18 13:25:36.0553 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/01/18 13:25:36.0599 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2011/01/18 13:25:36.0650 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/01/18 13:25:36.0770 ialm (e5490aea3b791c454e9933bf749ca3d8) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/01/18 13:25:36.0833 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2011/01/18 13:25:36.0949 igfx (e5490aea3b791c454e9933bf749ca3d8) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/01/18 13:25:36.0998 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/01/18 13:25:37.0058 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/01/18 13:25:37.0105 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/01/18 13:25:37.0162 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/01/18 13:25:37.0241 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2011/01/18 13:25:37.0305 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/01/18 13:25:37.0359 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/01/18 13:25:37.0401 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2011/01/18 13:25:37.0455 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/01/18 13:25:37.0485 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/01/18 13:25:37.0522 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/01/18 13:25:37.0572 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/01/18 13:25:37.0620 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/01/18 13:25:37.0693 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/01/18 13:25:37.0819 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/01/18 13:25:37.0933 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2011/01/18 13:25:37.0966 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2011/01/18 13:25:38.0004 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2011/01/18 13:25:38.0087 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/01/18 13:25:38.0178 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/01/18 13:25:38.0211 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2011/01/18 13:25:38.0269 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/01/18 13:25:38.0324 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/01/18 13:25:38.0375 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/01/18 13:25:38.0413 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/01/18 13:25:38.0467 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/01/18 13:25:38.0527 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2011/01/18 13:25:38.0558 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/01/18 13:25:38.0597 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/01/18 13:25:38.0704 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS 2011/01/18 13:25:38.0766 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS 2011/01/18 13:25:38.0827 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/01/18 13:25:38.0885 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/01/18 13:25:38.0922 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/01/18 13:25:38.0963 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/01/18 13:25:39.0012 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/01/18 13:25:39.0069 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2011/01/18 13:25:39.0123 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/01/18 13:25:39.0180 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/01/18 13:25:39.0249 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/01/18 13:25:39.0302 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/01/18 13:25:39.0335 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/01/18 13:25:39.0386 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/01/18 13:25:39.0423 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/01/18 13:25:39.0462 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/01/18 13:25:39.0515 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/01/18 13:25:39.0580 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/01/18 13:25:39.0654 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/01/18 13:25:39.0699 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/01/18 13:25:39.0755 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/01/18 13:25:39.0801 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/01/18 13:25:39.0885 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/01/18 13:25:39.0954 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/01/18 13:25:40.0018 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/01/18 13:25:40.0145 NETw3v32 (ea30bd026a7d1b745a37516880c4ac1b) C:\Windows\system32\DRIVERS\NETw3v32.sys 2011/01/18 13:25:40.0381 NETw5v32 (054ba4a208c7aaf4f787e4f5466755e6) C:\Windows\system32\DRIVERS\NETw5v32.sys 2011/01/18 13:25:40.0457 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/01/18 13:25:40.0514 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys 2011/01/18 13:25:40.0562 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/01/18 13:25:40.0623 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/01/18 13:25:40.0715 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/01/18 13:25:40.0757 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/01/18 13:25:40.0795 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/01/18 13:25:40.0832 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 2011/01/18 13:25:40.0868 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 2011/01/18 13:25:40.0915 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2011/01/18 13:25:41.0026 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/01/18 13:25:41.0083 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/01/18 13:25:41.0136 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/01/18 13:25:41.0175 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/01/18 13:25:41.0238 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/01/18 13:25:41.0273 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 2011/01/18 13:25:41.0318 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/01/18 13:25:41.0401 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/01/18 13:25:41.0526 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/01/18 13:25:41.0572 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2011/01/18 13:25:41.0645 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/01/18 13:25:41.0684 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 2011/01/18 13:25:41.0748 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2011/01/18 13:25:41.0795 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/01/18 13:25:41.0845 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/01/18 13:25:41.0893 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/01/18 13:25:41.0951 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/01/18 13:25:42.0004 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/01/18 13:25:42.0056 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/01/18 13:25:42.0121 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/01/18 13:25:42.0164 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/01/18 13:25:42.0234 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 2011/01/18 13:25:42.0264 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/01/18 13:25:42.0324 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/01/18 13:25:42.0393 rimmptsk (d85e3fa9f5b1f29bb4ed185c450d1470) C:\Windows\system32\DRIVERS\rimmptsk.sys 2011/01/18 13:25:42.0433 rimsptsk (db8eb01c58c9fada00c70b1775278ae0) C:\Windows\system32\DRIVERS\rimsptsk.sys 2011/01/18 13:25:42.0470 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\Windows\system32\DRIVERS\rixdptsk.sys 2011/01/18 13:25:42.0547 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/01/18 13:25:42.0602 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/01/18 13:25:42.0671 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 2011/01/18 13:25:42.0722 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/01/18 13:25:42.0769 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/01/18 13:25:42.0811 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/01/18 13:25:42.0865 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/01/18 13:25:42.0961 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 2011/01/18 13:25:43.0002 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2011/01/18 13:25:43.0049 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 2011/01/18 13:25:43.0074 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/01/18 13:25:43.0141 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2011/01/18 13:25:43.0186 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2011/01/18 13:25:43.0228 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2011/01/18 13:25:43.0296 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/01/18 13:25:43.0467 SNP2UVC (5140166bbcafe1393d4669353a1f8c0a) C:\Windows\system32\DRIVERS\snp2uvc.sys 2011/01/18 13:25:43.0538 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/01/18 13:25:43.0615 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\Windows\system32\Drivers\sptd.sys 2011/01/18 13:25:43.0615 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9 2011/01/18 13:25:43.0623 sptd - detected Locked file (1) 2011/01/18 13:25:43.0683 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/01/18 13:25:43.0719 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/01/18 13:25:43.0753 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/01/18 13:25:43.0827 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/01/18 13:25:43.0882 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/01/18 13:25:43.0918 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/01/18 13:25:43.0951 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/01/18 13:25:43.0998 SynTP (f5d926807bd9bc0af68f9376144de425) C:\Windows\system32\DRIVERS\SynTP.sys 2011/01/18 13:25:44.0065 tap0901 (11d34fc869f5bda29949fe3858380894) C:\Windows\system32\DRIVERS\tap0901.sys 2011/01/18 13:25:44.0157 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2011/01/18 13:25:44.0224 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2011/01/18 13:25:44.0279 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/01/18 13:25:44.0329 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/01/18 13:25:44.0369 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/01/18 13:25:44.0422 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/01/18 13:25:44.0479 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/01/18 13:25:44.0561 truecrypt (be45dad1c73a3216edc8c485916f6594) C:\Windows\system32\drivers\truecrypt.sys 2011/01/18 13:25:44.0633 Trufos (127dc1adaf55f99ab6696bb455820a96) C:\Windows\system32\DRIVERS\Trufos.sys 2011/01/18 13:25:44.0699 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/01/18 13:25:44.0747 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/01/18 13:25:44.0803 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/01/18 13:25:44.0861 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2011/01/18 13:25:44.0910 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/01/18 13:25:44.0982 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2011/01/18 13:25:45.0018 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2011/01/18 13:25:45.0062 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/01/18 13:25:45.0094 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/01/18 13:25:45.0152 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/01/18 13:25:45.0244 UnlockerDriver5 (bb879dcfd22926efbeb3298129898cbb) C:\Program Files\Unlocker\UnlockerDriver5.sys 2011/01/18 13:25:45.0333 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/01/18 13:25:45.0378 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/01/18 13:25:45.0441 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/01/18 13:25:45.0488 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/01/18 13:25:45.0526 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/01/18 13:25:45.0579 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/01/18 13:25:45.0626 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/01/18 13:25:45.0665 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/01/18 13:25:45.0714 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/01/18 13:25:45.0768 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/01/18 13:25:45.0819 VBoxDrv (3e4b3de332634151d10bca5c0f3dd226) C:\Windows\system32\DRIVERS\VBoxDrv.sys 2011/01/18 13:25:45.0863 VBoxNetAdp (02cf071ee8cad9667ec0736c57360b70) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 2011/01/18 13:25:45.0912 VBoxNetFlt (9200e34447dd628c0080f41b15378e83) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys 2011/01/18 13:25:45.0958 VBoxUSBMon (be71306e451c5f9de9a64b32038314ee) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 2011/01/18 13:25:46.0017 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/01/18 13:25:46.0068 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/01/18 13:25:46.0105 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2011/01/18 13:25:46.0138 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2011/01/18 13:25:46.0182 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 2011/01/18 13:25:46.0251 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/01/18 13:25:46.0312 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/01/18 13:25:46.0381 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/01/18 13:25:46.0467 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2011/01/18 13:25:46.0528 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/01/18 13:25:46.0582 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/01/18 13:25:46.0597 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/01/18 13:25:46.0644 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2011/01/18 13:25:46.0693 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 2011/01/18 13:25:46.0756 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/01/18 13:25:46.0871 winachsf (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/01/18 13:25:46.0961 WinUSB (676f4b665bdd8053eaa53ac1695b8074) C:\Windows\system32\DRIVERS\WinUSB.sys 2011/01/18 13:25:47.0020 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/01/18 13:25:47.0112 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/01/18 13:25:47.0186 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/01/18 13:25:47.0238 XAudio (19e7c173b6242ad7521e537ae54768bf) C:\Windows\system32\DRIVERS\xaudio.sys 2011/01/18 13:25:47.0342 {22D78859-9CE9-4B77-BF18-AC83E81A9263} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\HP\QuickPlay\000.fcl 2011/01/18 13:25:47.0435 ================================================================================ 2011/01/18 13:25:47.0435 Scan finished 2011/01/18 13:25:47.0435 ================================================================================ 2011/01/18 13:25:47.0458 Detected object count: 1 2011/01/18 13:25:54.0018 Locked file(sptd) - User select action: Skip 2011/01/18 13:25:57.0205 Deinitialize success
Hi, The redirects happen usually when I click on links in forums etc. I'm at work now and so won't be able to check it right away. Probably get back to you by tomorrow. Are the logs clean? I saw TDSSKiller detected 1 threat but that was probably because it was a locked file.

2011/01/18 13:25:54.0018 Locked file(sptd) - User select action: Skip

That one is fine, leave it alone :thumbup:

The logs look OK to me but I'd like for you to run MBAM.

Please download Malwarebytes' Anti-Malware to your desktop.


  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hi LDTate, I ran Malwarebytes and it found 2 infections both of which are in the registry. As far as my PC is concerned, it is not sluggish and I am pretty satisfied with it's performance. There has been no drastic performance slow down or anything. The weird thing though is that although I have disabled quite a few startup programs and services yet it takes me a good 4 minutes on an average to boot up. Add to this some random redirection when I click on links in forums that take me to ad sites. Thanks. The Malwarebytes log is : Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5550 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.7930.16406 1/18/2011 5:18:48 PM mbam-log-2011-01-18 (17-18-48).txt Scan type: Quick scan Objects scanned: 163504 Time elapsed: 5 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (PUM.Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind (PUM.Hijack.Find) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Hi LDTate,

I ran combofix and the log contents are:

ComboFix 11-01-18.02 - test 01/18/2011 21:42:46.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1142 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\PC Cleaning Software\ComboFix.exe
AV: BitDefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: BitDefender Antispyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Sys5889.Data Repository.sys
c:\users\test\AppData\Roaming\Desktopicon
c:\users\test\AppData\Roaming\EurekaLog
c:\users\test\AppData\Roaming\Kernel32.exe
c:\users\test\g2mdlhlpx.exe
c:\windows\host32.exe
c:\windows\system32\html
c:\windows\system32\html\calendar.html
c:\windows\system32\html\calendarbottom.html
c:\windows\system32\html\calendartop.html
c:\windows\system32\html\crystalexportdialog.htm
c:\windows\system32\html\crystalprinthost.html
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\system32\midas.dll

c:\windows\system32\imm32.dll . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2010-12-19 to 2011-01-19 )))))))))))))))))))))))))))))))
.

2011-01-19 03:03 . 2011-01-19 03:08 ——– d—–w- c:\users\test\AppData\Local\temp
2011-01-19 03:03 . 2011-01-19 03:03 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-01-19 03:03 . 2011-01-19 03:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-01-16 20:56 . 2011-01-16 20:56 22 –sha-w- c:\users\test\AppData\Roaming\Sys6925.Config Collection.sys
2011-01-16 20:56 . 2011-01-16 20:56 22 –sha-w- c:\windows\Sys3390 SettingsCollection.bin
2011-01-16 20:12 . 2011-01-16 20:12 ——– d—–w- c:\users\test\AppData\Local\PassMark
2011-01-16 20:12 . 2008-07-12 13:18 467984 —-a-w- c:\windows\system32\d3dx10_39.dll
2011-01-16 20:12 . 2008-07-12 13:18 1493528 —-a-w- c:\windows\system32\D3DCompiler_39.dll
2011-01-16 20:12 . 2008-07-12 13:18 3851784 —-a-w- c:\windows\system32\D3DX9_39.dll
2011-01-16 20:11 . 2011-01-16 20:11 ——– d—–w- c:\programdata\PassMark
2011-01-16 02:03 . 2010-12-28 15:55 413696 —-a-w- c:\windows\system32\odbc32.dll
2011-01-16 02:03 . 2010-12-28 15:53 253952 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-01-16 02:03 . 2010-12-28 15:53 241664 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-01-16 02:03 . 2010-12-28 15:53 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-01-16 02:03 . 2010-12-28 15:53 57344 —-a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2011-01-16 02:03 . 2010-12-28 15:53 180224 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-01-16 02:03 . 2010-12-14 14:49 1169408 —-a-w- c:\windows\system32\sdclt.exe
2011-01-13 23:32 . 2008-10-06 20:37 315392 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp083.dll
2011-01-11 04:39 . 2011-01-11 04:47 ——– d—–w- c:\users\test\.android
2011-01-11 04:38 . 2011-01-11 04:38 ——– d—–w- c:\program files\Android
2011-01-08 02:17 . 2011-01-09 07:24 ——– d—–w- c:\users\test\AppData\Roaming\pdftoepub
2011-01-02 21:54 . 2011-01-02 21:59 ——– d—–w- c:\users\test\AppData\Roaming\HpUpdate
2011-01-02 21:52 . 2011-01-02 21:52 ——– d—–w- c:\program files\Coupons
2011-01-02 21:51 . 2011-01-02 21:51 ——– d—–w- c:\program files\HP Photo Creations
2011-01-02 21:51 . 2011-01-02 21:51 ——– d—–w- c:\programdata\HP Photo Creations
2011-01-02 21:50 . 2011-01-02 21:50 ——– d—–w- c:\programdata\HP Product Assistant
2011-01-02 21:42 . 2011-01-02 21:42 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2011-01-02 21:41 . 2008-10-29 17:35 271704 —-a-w- c:\windows\system32\hpzids01.dll
2011-01-02 21:41 . 2008-10-06 20:38 121344 —-a-w- c:\windows\system32\hpf3l083.dll
2011-01-02 21:40 . 2008-10-29 17:37 737280 —-a-w- c:\windows\system32\hposwia_d02a.dll
2011-01-02 21:40 . 2008-10-29 17:37 598016 —-a-w- c:\windows\system32\hpost_d02a.dll
2011-01-02 21:40 . 2008-10-29 17:37 307200 —-a-w- c:\windows\system32\hposc_d02a.dll
2011-01-02 21:40 . 2008-10-28 09:31 372736 —-a-w- c:\windows\system32\hppldcoi.dll
2010-12-28 17:09 . 2010-12-28 17:09 ——– d—–w- c:\programdata\bdch
2010-12-28 15:28 . 2011-01-13 18:12 308152 —-a-w- c:\windows\system32\drivers\trufos.sys
2010-12-28 15:28 . 2010-12-28 16:08 327368 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-12-28 14:18 . 2010-11-01 22:59 2381824 —-a-w- c:\windows\system32\mshtml.tlb
2010-12-28 14:18 . 2010-11-01 23:03 1448448 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-28 13:51 . 2010-11-03 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-28 09:54 . 2010-12-28 09:55 ——– d—–w- C:\bd_logs
2010-12-27 02:34 . 2010-12-27 02:34 48128 —-a-w- c:\windows\system32\simple.exe
2010-12-26 04:01 . 2010-12-26 04:01 ——– d—–w- c:\program files\Veetle
2010-12-23 01:26 . 2010-12-28 15:16 ——– d—–w- c:\program files\Symantec
2010-12-21 02:52 . 2010-12-21 02:52 ——– d—–w- c:\users\test\AppData\Roaming\BitDefender
2010-12-21 02:50 . 2010-12-21 02:50 ——– d—–w- c:\program files\BitDefender
2010-12-21 02:44 . 2010-12-21 02:44 ——– d—–w- c:\users\test\AppData\Roaming\QuickScan
2010-12-21 02:44 . 2010-12-28 15:28 ——– d—–w- c:\program files\Common Files\BitDefender
2010-12-21 02:44 . 2010-12-28 15:59 ——– d—–w- c:\programdata\BitDefender
2010-12-21 00:29 . 2010-12-21 02:23 ——– d—–w- c:\program files\Opera
2010-12-20 23:42 . 2010-09-01 05:55 869688 —-a-w- c:\program files\Internet Explorer\iexplore.exe
2010-12-20 23:40 . 2010-08-17 23:54 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2010-12-20 23:40 . 2010-08-17 23:54 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2010-12-20 23:40 . 2010-08-17 23:52 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2010-12-20 23:40 . 2010-08-17 23:51 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2010-12-20 23:40 . 2010-08-17 23:51 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2010-12-20 23:40 . 2010-08-17 23:51 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2010-12-20 23:40 . 2010-08-17 23:50 680960 —-a-w- c:\windows\system32\d2d1.dll
2010-12-20 23:40 . 2010-08-17 23:49 1174528 —-a-w- c:\windows\system32\d3d10warp.dll
2010-12-20 23:40 . 2010-08-17 23:49 1068032 —-a-w- c:\windows\system32\DWrite.dll
2010-12-20 23:40 . 2010-08-17 23:49 797184 —-a-w- c:\windows\system32\FntCache.dll
2010-12-20 23:40 . 2010-08-17 23:48 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2010-12-20 23:40 . 2010-08-17 23:48 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2010-12-20 23:39 . 2010-12-20 23:39 ——– d—–w- c:\program files\Feedback Tool

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-11 04:34 . 2010-10-31 01:59 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-01-11 04:31 . 2010-06-21 18:13 581192 —-a-w- c:\windows\system32\WinUSBCoInstaller.dll
2011-01-11 04:31 . 2010-06-21 18:13 1112288 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-12-28 16:07 . 2010-06-18 21:11 72784 —-a-w- c:\windows\system32\drivers\bdfndisf6.sys
2010-12-28 14:14 . 2010-12-16 02:28 1680160 —-a-w- c:\programdata\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-12-28 14:07 . 2010-12-16 02:28 18368 —-a-w- c:\programdata\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-12-20 23:09 . 2009-11-10 02:47 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2009-11-10 02:46 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-16 07:38 . 2010-12-16 02:01 416 —-a-w- c:\programdata\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-12-09 23:39 . 2010-12-09 23:38 7053264 —-a-w- c:\users\test\gosetup.exe
2010-11-12 01:31 . 2010-11-12 01:31 1062984 —-a-w- c:\users\test\gotomypc_540.exe
2010-11-10 04:33 . 2010-12-07 07:42 6273872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{784A11BE-347B-4C23-89A8-4FC2BC7A4635}\mpengine.dll
2010-11-04 18:56 . 2010-12-16 08:39 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-04 18:55 . 2010-12-16 08:39 352768 —-a-w- c:\windows\system32\taskschd.dll
2010-11-04 18:55 . 2010-12-16 08:39 270336 —-a-w- c:\windows\system32\taskcomp.dll
2010-11-04 18:55 . 2010-12-16 08:39 601600 —-a-w- c:\windows\system32\schedsvc.dll
2010-11-04 16:34 . 2010-12-16 08:39 171520 —-a-w- c:\windows\system32\taskeng.exe
2010-10-29 01:06 . 2010-10-29 01:06 231248 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2010-10-28 15:44 . 2010-12-16 08:39 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-10-28 14:11 . 2010-04-06 18:12 98400 —-a-w- c:\windows\system32\drivers\BazisVirtualCDBus.sys
2010-10-28 13:27 . 2010-12-16 08:39 292352 —-a-w- c:\windows\system32\atmfd.dll
2010-10-28 13:20 . 2010-12-16 08:39 2048 —-a-w- c:\windows\system32\tzres.dll
2010-03-29 23:40 . 2010-03-29 23:40 100256 —-a-w- c:\program files\Common Files\LinkInstaller.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\test\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\test\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\test\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2010-12-28 71216]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2010-12-28 1418456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LoadRunner Agent Process.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\LoadRunner Agent Process.lnk
backup=c:\windows\pss\LoadRunner Agent Process.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^VPN Client.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk
backup=c:\windows\pss\VPN Client.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^test^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^test^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^test^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^test^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^test^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Trillian.lnk]
path=c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk
backup=c:\windows\pss\Trillian.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FeedDemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartupDelayer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2009
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dexpot]
2010-09-14 13:59 1273856 —-a-w- c:\program files\Dexpot\dexpot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-11-12 06:15 133104 —-atw- c:\users\test\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-06-18 21:01 166424 —-a-w- c:\windows\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 21:13 54576 —-a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2007-10-03 23:15 480560 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-06-18 21:01 141848 —-a-w- c:\windows\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 23:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-12-20 23:08 963976 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-07 02:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-06-18 21:01 133656 —-a-w- c:\windows\System32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2009-09-08 19:18 468264 —-a-w- c:\program files\Hp\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc]
2008-08-02 03:10 675840 —-a-w- c:\windows\vsnp2uvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 16:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-03-28 09:05 1045800 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-07-04 19:51 17408 —-a-w- c:\program files\Unlocker\UnlockerAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-12-09 10:45 74752 —-a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R3 BrlAPI;BrlAPI;c:\cygwin\bin\cygrunsrv.exe [x]
R3 ServiceEmulation;HP ServiceEmulation;c:\program files\Hp\LoadRunner\apache-tomcat-5.5.17\bin\tomcat5.exe [x]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2010-12-28 307544]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
R3 WPFFontCache_v0400;WPFFontCache_v0400; [x]
R4 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2010-06-28 633424]
R4 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2010-06-28 970320]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 133104]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-06-21 721904]
S1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2010-12-28 72784]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2010-08-05 143184]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2010-08-05 41936]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [2010-12-28 43424]
S3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:\windows\system32\DRIVERS\BazisVirtualCDBus.sys [2010-10-28 98400]
S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-05-13 152528]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-10-26 4247552]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2010-08-05 100496]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2010-08-05 111312]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2011-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 22:17]

2011-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-10 22:17]

2011-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3583619146-1925853717-31679610-1000Core.job
- c:\users\test\AppData\Local\Google\Update\GoogleUpdate.exe [2008-11-12 06:15]

2011-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3583619146-1925853717-31679610-1000UA.job
- c:\users\test\AppData\Local\Google\Update\GoogleUpdate.exe [2008-11-12 06:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\test\AppData\Roaming\Mozilla\Firefox\Profiles\7xeov8pp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
MSConfigStartUp-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-18 22:07
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3583619146-1925853717-31679610-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:b1,8c,79,40,58,7c,7b,7d,09,7f,f4,6b,fc,15,7d,a5,0b,9e,cd,b0,c4,
77,15,62,96,88,09,43,83,d0,81,36,44,27,bc,17,7a,d3,e4,68,73,b3,7b,ee,da,82,\
"rkeysecu"=hex:2c,4c,43,4d,8f,1b,2d,c0,e0,67,c9,b1,04,55,34,13

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3640)
c:\users\test\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
———————— Other Running Processes ————————
.
c:\program files\Citrix\GoToMyPC\g2svc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Citrix\GoToMyPC\g2comm.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Citrix\GoToMyPC\g2pre.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Citrix\GoToMyPC\g2tray.exe
c:\program files\BitDefender\BitDefender 2011\pchooklaunch32.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2011-01-18 22:17:53 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-19 03:17

Pre-Run: 41,597,505,536 bytes free
Post-Run: 41,507,823,616 bytes free

- - End Of File - - D4A5B058F1D09072186748FFB82F836F
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    imm32.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi LDTate, This is the output of the SystemLook.txt file: SystemLook 04.09.10 by jpshortstuff Log created at 10:36 on 19/01/2011 by test Administrator - Elevation successful ========== filefind ========== Searching for "imm32.dll" C:\WINDOWS\ERDNT\cache\imm32.dll –a—- 114688 bytes [03:12 19/01/2011] [06:28 11/04/2009] C8BDCECEE082B54F0BAC838BF0A34597 C:\WINDOWS\System32\imm32.dll –a—- 114688 bytes [11:47 18/09/2009] [06:28 11/04/2009] C8BDCECEE082B54F0BAC838BF0A34597 C:\WINDOWS\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6000.16386_none_5a1f5c1a7d7fec2e\imm32.dll –a—- 115200 bytes [08:38 02/11/2006] [09:46 02/11/2006] EE12864398F1C3BF5BEE91F6AF9842E1 C:\WINDOWS\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\imm32.dll –a—- 114688 bytes [19:57 17/09/2008] [07:34 19/01/2008] EC17194A193CD8E90D27CFB93DFA9A2E C:\WINDOWS\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6002.18005_none_5e419722778cc84e\imm32.dll –a—- 114688 bytes [11:47 18/09/2009] [06:28 11/04/2009] C8BDCECEE082B54F0BAC838BF0A34597 -= EOF =- Thanks.
See if you can copy the imm32.dll from here to C:\WINDOWS\System32\imm32.dll
C:\WINDOWS\winsxs\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6001.18000_none_5c561e167a6afd02\imm32.dll
Start Task Manager
To start Task Manager, take any of the following actions:
Press CTRL+ALT+DELETE, and then click Task Manager.
Press CTRL+SHIFT+ESC.

End the process for imm32.dll

Now try to do the copy.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI