Hi ran ran SRENG and there was one entry with an ERROR which was repaired , however COMBOfix.EXE would not open on the infected computer, I kept getting that Security warning message that I am getting for every EXE file. Should I rename COMBOFIX to a .COM extension and try that/
Hello
babbagene
Should I rename COMBOFIX to a .COM extension and try that/
Please do. If that does not work you may have to drop into Safe Mode and try again.
Let me know how you get on
Hi thanks again for all your help! when trying to runthe FIX about 20 windoews opened up saying CONNECTING , finally I was able to get it to run. I got a message saying "could not find HIDEC.exe.
Here is the LOG:
ComboFix 11-02-22.01 - babbagene 02/22/2011 19:16:50.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.2168 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.Com
AV: Norton Security Suite *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton Security Suite *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton Security Suite *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
c:\users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}
c:\users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}\chrome.manifest
c:\users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}\chrome\content\_cfg.js
c:\users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}\chrome\content\overlay.xul
c:\users\babbagene\AppData\Local\{6AC1BE8D-DE20-4042-B500-D30D6C6708A8}\install.rdf
c:\windows\system32\jusched.exe
c:\windows\system32\Nagasoft
.
((((((((((((((((((((((((( Files Created from 2011-01-23 to 2011-02-23 )))))))))))))))))))))))))))))))
.
2011-02-23 00:21 . 2011-02-23 00:21 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-02-23 00:21 . 2011-02-23 00:21 ——– d—–w- c:\users\babbagene\AppData\Local\temp
2011-02-22 20:09 . 2011-02-22 20:09 63115 —-a-w- c:\progra~2\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-02-22 00:51 . 2011-02-22 00:51 ——– d—–w- C:\_OTL
2011-02-20 04:57 . 2011-02-20 04:57 ——– d–h–w- c:\windows\PIF
2011-02-18 07:06 . 2011-01-13 09:41 5890896 —-a-w- c:\progra~2\Microsoft\Windows Defender\Definition Updates\{C8AC04E0-7493-4FE5-86AF-13B9501D324B}\mpengine.dll
2011-02-12 05:40 . 2011-02-12 05:40 ——– d—–w- c:\users\babbagene\AppData\Roaming\Friday's games
2011-02-09 19:43 . 2010-12-31 13:57 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-09 19:43 . 2010-10-15 14:08 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-09 19:43 . 2010-10-15 13:48 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-09 19:43 . 2010-10-15 14:08 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-09 19:43 . 2011-01-06 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-01-31 02:04 . 2011-01-31 02:04 ——– d—–w- c:\users\babbagene\AppData\Roaming\SpinTop Games
2011-01-27 19:11 . 2011-01-27 19:11 ——– d—–w- c:\users\babbagene\AppData\Roaming\CyberLink
2011-01-27 19:11 . 2011-01-27 19:11 ——– d—–w- c:\progra~2\CyberLink
2011-01-27 18:45 . 2011-01-31 03:54 ——– d—–w- c:\users\babbagene\AppData\Roaming\BitZipper
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-28 15:55 . 2011-01-12 11:45 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-20 23:09 . 2009-06-15 00:02 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2009-06-15 00:02 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 14:49 . 2011-01-12 11:45 1169408 —-a-w- c:\windows\system32\sdclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-01-12 972344]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"cdloader"="c:\users\babbagene\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-12-14 467240]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-09 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-06-05 17:39 292136 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPAP]
2010-04-26 09:09 185800 —-a-w- c:\program files\Common Files\PPLiveNetwork\ppap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2010-03-02 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2010-03-02 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2010-03-02 482432]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110218.003\IDSvix86.sys [2010-11-09 353912]
S2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [2010-09-27 176408]
S2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe [2010-03-02 117640]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-07-26 102448]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2010-03-02 48688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2011-02-08 c:\windows\Tasks\HPCeeScheduleForbabbagene.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-06-19 03:03]
2011-02-22 c:\windows\Tasks\User_Feed_Synchronization-{4F74C39B-E843-46E1-9C70-C9134C90FBF5}.job
- c:\windows\system32\msfeedssync.exe [2011-02-09 04:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.foxtab.com/?s=0&chnl=irn&cd=2XzutCtN2Y1L1QzutDtDtBtBtCyDtByDzyyBtDyCtN0C0Czu0U0StN0D0TzutBtDtCtCtDtBt
CtA&cr=1294908807
mSearch Bar = hxxp://www.google.com
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-vShare - c:\program files\vShare\UNINSTALL.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-02-22 19:27:37
ComboFix-quarantined-files.txt 2011-02-23 00:27
Pre-Run: 254,350,598,144 bytes free
Post-Run: 253,433,720,832 bytes free
- - End Of File - - C15E37FD04CBEB7DBB678152D6333AEA
Hi , I was able to get mban to run by giving it a .com extension, here is the log:
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 6.0.6002 Service Pack 2
2/22/2011 9:53:48 PM
mbam-log-2011-02-22 (21-53-38).txt
Scan type: Full Scan (C:\|)
Objects scanned: 241020
Time elapsed: 1 hour(s), 43 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8ca5ed52-f3fb-4414-a105-2e3491156990} (Adware.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\babbagene\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\Users\babbagene\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
C:\Users\babbagene\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
Note: the MALAWARE version that I ran was old , because my computer would not allow the updates to download.
JONTOM,I took the liberty of running the3 programs you initailly instructed me to run in your first post ,since they all run now ,here is the current LOGS for all 3 , hope I did not screw you up by doing this:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 02/23/2011 at 1:37:35.
Operating System: Windows Vista ™ Home Premium
Processes terminated by Rkill or while it was running:
Rkill completed on 02/23/2011 at 1:37:45.
DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 1:40:21.35 on Wed 02/23/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1814 [GMT -5:00]
AV: Norton Security Suite *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Security Suite *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Users\babbagene\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.foxtab.com/?s=0&chnl=irn&cd=2XzutCtN2Y1L1QzutDtDtBtBtCyDtByDzyyBtDyCtN0C0Czu0U0StN0D0TzutBtDtCtCtDtBt
CtA&cr=1294908807
mSearch Bar = hxxp://www.google.com
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.8.0.41\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [cdloader] "c:\users\babbagene\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://www.opentopia.com/support/activex/AxisCamControl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/armhelper.ocx
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.8.0.41\CoIEPlg.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-3-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-3-2 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-3-2 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20110221.001\IDSvix86.sys [2011-2-22 353912]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2010-9-27 176408]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.8.0.41\ccSvcHst.exe [2010-3-2 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-21 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0308000.029\symndisv.sys [2010-3-2 48688]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Symantec Core LC;Symantec Core LC; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-02-23 04:37:45 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-23 04:37:45 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2011-02-23 00:27:42 ——– d-sh–w- C:\$RECYCLE.BIN
2011-02-23 00:27:39 ——– d—–w- c:\users\babbag~1\appdata\local\temp
2011-02-23 00:15:50 98816 —-a-w- c:\windows\sed.exe
2011-02-23 00:15:50 89088 —-a-w- c:\windows\MBR.exe
2011-02-23 00:15:50 256512 —-a-w- c:\windows\PEV.exe
2011-02-23 00:15:50 161792 —-a-w- c:\windows\SWREG.exe
2011-02-23 00:15:42 ——– d—–w- C:\ComboFix
2011-02-22 00:51:50 ——– d—–w- C:\_OTL
2011-02-20 04:57:04 ——– d–h–w- c:\windows\PIF
2011-02-18 07:06:40 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{c8ac04e0-7493-4fe5-86af-13b9501d324b}\mpengine.dll
2011-02-12 05:40:16 ——– d—–w- c:\users\babbag~1\appdata\roaming\Friday's games
2011-02-09 19:43:06 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-09 19:43:03 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-09 19:43:03 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-09 19:43:02 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-09 19:43:00 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-31 02:04:53 ——– d—–w- c:\users\babbag~1\appdata\roaming\SpinTop Games
2011-01-27 18:45:29 ——– d—–w- c:\users\babbag~1\appdata\roaming\BitZipper
==================== Find3M ====================
2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
2011-01-04 16:36:39 21258 —-a-w- c:\windows\cscmondump.bin
2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-18 06:27:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-18 06:22:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-18 06:22:27 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-18 06:22:11 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-12-18 06:22:11 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-12-18 05:25:26 385024 —-a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe
============= FINISH: 1:41:18.32 ===============
ATTACHED.Text
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/14/2009 2:40:28 AM
System Uptime: 2/23/2011 1:24:12 AM (0 hours ago)
Motherboard: OEM_MB | | NARRA3
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2600/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 325 GiB total, 235.986 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.344 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&37EFC377&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&37EFC377&0
Service: i8042prt
==== System Restore Points ===================
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.0
Adobe Shockwave Player 11.5
AIO_Scan
Apple Mobile Device Support
Apple Software Update
Bonjour
BufferChm
C5200
C5200_doccd
c5200_Help
CBE2_1
CCleaner
Cisco Network Magic
Compatibility Pack for the 2007 Office system
Copy
CustomerResearchQFolder
CyberLink DVD Suite Deluxe
CyberLink PowerDirector
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DHTML Editing Component
DocProc
DocProcQFolder
Download Updater (AOL LLC)
Enhanced Multimedia Keyboard Solution
eSupportQFolder
Eusing Free Registry Cleaner
Fax
Hardware Diagnostic Tools
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Feedback
HP Customer Participation Program 9.0
HP Demo
HP Games
HP Imaging Device Functions 9.0
HP OCR Software 9.0
HP Photosmart All-In-One Software 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Picasso Media Center Add-In
HP Smart Web Printing
HP Solution Center 9.0
HP Total Care Advisor
HP Update
HPProductAssistant
HPSSupply
HPTCSSetup
iTunes
Java Auto Updater
Java™ 6 Update 18
Java™ SE Runtime Environment 6 Update 1
LabelPrint
LightScribe System Software
LightScribeTemplateLabeler
LiveUpdate (Symantec Corporation)
magicJack
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Move Media Player
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
Network Magic
Norton Security Suite
NVIDIA Drivers
OGA Notifier 2.0.0048.0
PanoStandAlone
Power2Go
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_min
PSSWCORE
Pure Networks Platform
Python 2.5
QuickTime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
Revo Uninstaller 1.88
Samantha Swift 3
Savings Bond Wizard
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Snapfish Picture Mover
Soft Data Fax Modem with SmartCP
SolutionCenter
Spybot - Search & Destroy
Status
Toolbox
TrayApp
Turbo Lister 2
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Veetle TV 0.9.18
VideoToolkit01
Viewpoint Media Player
Visual C++ 8.0 CRT (x86) WinSXS MSM
WebEx Support Manager for Internet Explorer
WebReg
Windows Live ID Sign-in Assistant
==== End Of File ===========================
Hello
babbagene
Thank you for the log.
my computer would not allow the updates to download
Strange? Please run MBAM again and allow it to remove what it finds.
Please un-install Java™ SE Runtime Environment 6 Update 1
Click on "Start" then on "Control Panel" and then on "Add or remove programs" . Click on "remove a program" . A list of currently installed programs will be displayed. Find the "Java™ SE Runtime Environment 6 Update 1" program, click on it once and then click on the "uninstall" button. NOTE DO NOT uninstall Java™ 6 Update 18.If you are prompted to re-boot your computer to complete the uninstall please do so.
Please update your Java
To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup). In the window that opens, click on the "Update" tab, and then on "Update Now" . Your Java should begin to update. Please follow any prompts that you receive.
Clean out your temporary files
Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop. Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop. Check the boxes to the left of the following:
Windows Temp Current User Temp All Users Temp Temporary Internet Files Java Cache
The rest are optional . If you want to remove everything check the "Select All" box.Click on "Empty Selected" to begin cleaning. Once the "Done Cleaning" message appears, click OK . If you use Firefox , Click on the Firefox tab and repeat the above process. When you have finished cleaning, click on the "Exit" button in the main menu.
Please run the following scan
Note: You will need to use Internet Explorer for this scan.Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator" . Please disable your real time security programs before performing the scan.
Scan your system with Eset Online Scanner Place a check mark in the box YES, I accept the Terms Of Use. Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps). Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop.
Check [external image: Posted Image] Click the [external image: Posted Image] button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option to "Remove Found Threats" is UN checked. Push the "Start" button. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. Push the [external image: Posted Image] button. Push [external image: Posted Image]
Please post the MBAM and ESET logs in your next reply and let me know how the machine is running now.
Here is theMban LOG:
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 6.0.6002 Service Pack 2
2/23/2011 8:16:56 PM
mbam-log-2011-02-23 (20-16-56).txt
Scan type: Full Scan (C:\|)
Objects scanned: 240898
Time elapsed: 1 hour(s), 45 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the ESETLog:
C:\System Volume Information\SystemRestore\FRStaging\Users\babbagene\AppData\Local\Temp\del48522207.exe probably a variant of Win32/SweetIM.B application cleaned by deleting - quarantined
C:\System Volume Information\SystemRestore\FRStaging\Users\babbagene\AppData\Roaming\OpenCandy\OpenCandy_8FA5AA0E87594F75872C0A71C163FC62\p1v1_PPIRegistryReviver_w.exe a variant of Win32/SlowPCfighter application deleted - quarantined
C:\System Volume Information\SystemRestore\FRStaging\Users\babbagene\AppData\Roaming\OpenCandy\OpenCandy_8FA5AA0E87594F75872C0A71C163FC62\PPIRegistryReviverSetup.exe a variant of Win32/SlowPCfighter application cleaned by deleting - quarantined
C:\Users\babbagene\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\e6ebfab-2471b886 multiple threats deleted - quarantined
I restarted myinfected computer,and the computer still triedtoopen up 17 different files, with each of the files it tried to open I received the following message File Download-Security WarningDo you want to RUN or ave this file , here are thefiles that were trying to open :
MBAMgui.exe
wmpnscfg.exe
HPAdvisor.exe
ehtray.exe
Qttask.exe
kbdStub.exe
nmctxth.exe
hpwuSchd2.exe
realsched.exe
cdloader2.exe
rundll32.exe
AdobeARM.exe
reader_sl.exe
rundll32.exe
Jusched.exe
Teatimer.exe
hpsysdrv.exe
Hello
babbagene
MBAM runs clean and ESET has removed some infected restore points and an infected Java cache.
Please work your way through the following steps:
Please create a new System Restore point
Click on the "Windows Orb" and then Right click on "Computer" and select "Properties" Click on the “System Protection” link on the left hand side. Now select the “System Protection” tab to get to the System Restore section. Click the “Create” button to create a new restore point. You’ll be prompted for a name, and you might want to give it a useful name that you’ll be able to easily identify later (such as todays date). Click the Create button, and then the system will create the restore point.
Please Clear Your Sun Java Cache
Click on "Windows Orb" , then on "Control Panel" and then on the Java icon (looks like a coffee cup). If you do not see the icon, look to your left and click "Switch to Classic View" . On the "General" tab, under "Temporary Internet Files" , click the "Settings" button. Next, click on the "Delete Files" button. There are two options in the window to clear the cache - ("Applications and Applets" and "Trace and Log Files") . Leave BOTH Checked Click "OK" on Delete Temporary Files Window. Note: This deletes all of the Downloaded Applications and Applets from the Cache.Click "OK" to leave the Temporary Files Window. Click "OK" to leave the Java Control Panel.
Foistware
I can see from your log that you have Viewpoint Media Player and installed. Viewpoint Manager is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".It is recommended that you remove Viewpoint products. However, this choice is up to you. To remove these programs, Click on the "Windows Orb" (bottom left hand corner of your screen), then on "Computer" and then on the "Uninstall or Change a Program" tab. A list of currently installed programs will be displayed. Find the "Viewpoint Media Player" program, click on it once and then click on the "Uninstall" button. If you are prompted to re-boot your computer to complete the uninstall please do so.
Please post a new DDS scan log in your next reply and let me know of you are still receiving the "open or save" message. Besides receiving the messages, how is the machine running now?
Hi,I did what you instructed in the preceding post,Please keepin mind that the MBAM that I am running is NOT up tpo date because for some reason it will notupdate to the current version ,it is scanning with version 1.34 I believe.
When I started the computer up again I again receved the 17 files trying to open , I also see that if I try to open Realplayer or Ebay thru my desktop I get the same Message about Security Download, and they will not open.
I AM able to get on the internet. Here is the log you asked for:
DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 12:40:06.55 on Thu 02/24/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1894 [GMT -5:00]
AV: Norton Security Suite *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Security Suite *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\babbagene\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.foxtab.com/?s=0&chnl=irn&cd=2XzutCtN2Y1L1QzutDtDtBtBtCyDtByDzyyBtDyCtN0C0Czu0U0StN0D0TzutBtDtCtCtDtBt
CtA&cr=1294908807
mSearch Bar = hxxp://www.google.com
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.8.0.41\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [cdloader] "c:\users\babbagene\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://www.opentopia.com/support/activex/AxisCamControl.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Vacation%20Quest%20-%20The%20Hawaiian%20Islands/Images/armhelper.ocx
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.8.0.41\CoIEPlg.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-3-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-3-2 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-3-2 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20110223.001\IDSvix86.sys [2011-2-23 353912]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2010-9-27 176408]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.8.0.41\ccSvcHst.exe [2010-3-2 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-1-21 102448]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0308000.029\symndisv.sys [2010-3-2 48688]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Symantec Core LC;Symantec Core LC; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-02-24 08:02:25 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-02-24 08:02:04 40448 —-a-w- c:\windows\system32\winrs.exe
2011-02-24 08:02:04 20480 —-a-w- c:\windows\system32\winrshost.exe
2011-02-24 08:02:04 12800 —-a-w- c:\windows\system32\wsmprovhost.exe
2011-02-24 08:02:02 10240 —-a-w- c:\windows\system32\wsmplpxy.dll
2011-02-24 08:02:02 10240 —-a-w- c:\windows\system32\winrssrv.dll
2011-02-24 08:02:01 81408 —-a-w- c:\windows\system32\wevtfwd.dll
2011-02-24 08:02:01 79872 —-a-w- c:\windows\system32\wecutil.exe
2011-02-24 08:02:01 56320 —-a-w- c:\windows\system32\wecapi.dll
2011-02-24 08:02:01 54272 —-a-w- c:\windows\system32\WsmRes.dll
2011-02-24 08:02:01 146944 —-a-w- c:\windows\system32\wecsvc.dll
2011-02-24 08:02:00 41472 —-a-w- c:\windows\system32\pwrshplugin.dll
2011-02-24 08:01:44 201184 —-a-w- c:\windows\system32\winrm.vbs
2011-02-24 08:01:31 252416 —-a-w- c:\windows\system32\WSManMigrationPlugin.dll
2011-02-24 08:01:31 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-02-24 08:01:31 241152 —-a-w- c:\windows\system32\winrscmd.dll
2011-02-24 08:01:31 214016 —-a-w- c:\windows\system32\WsmWmiPl.dll
2011-02-24 08:01:31 145408 —-a-w- c:\windows\system32\WsmAuto.dll
2011-02-24 08:01:31 1181696 —-a-w- c:\windows\system32\WsmSvc.dll
2011-02-23 21:20:32 ——– d—–w- c:\program files\ESET
2011-02-23 21:16:42 411368 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-23 21:07:05 0 —-a-w- c:\windows\system32\REN607B.tmp
2011-02-23 21:07:05 0 —-a-w- c:\windows\system32\REN607A.tmp
2011-02-23 21:07:05 0 —-a-w- c:\windows\system32\REN6079.tmp
2011-02-23 04:37:45 ——– d—–w- c:\progra~2\Spybot - Search & Destroy
2011-02-23 00:27:42 ——– d-sh–w- C:\$RECYCLE.BIN
2011-02-23 00:27:39 ——– d—–w- c:\users\babbag~1\appdata\local\temp
2011-02-23 00:15:50 98816 —-a-w- c:\windows\sed.exe
2011-02-23 00:15:50 89088 —-a-w- c:\windows\MBR.exe
2011-02-23 00:15:50 256512 —-a-w- c:\windows\PEV.exe
2011-02-23 00:15:50 161792 —-a-w- c:\windows\SWREG.exe
2011-02-23 00:15:42 ——– d—–w- C:\ComboFix
2011-02-22 00:51:50 ——– d—–w- C:\_OTL
2011-02-20 04:57:04 ——– d–h–w- c:\windows\PIF
2011-02-18 07:06:40 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{c8ac04e0-7493-4fe5-86af-13b9501d324b}\mpengine.dll
2011-02-12 05:40:16 ——– d—–w- c:\users\babbag~1\appdata\roaming\Friday's games
2011-02-09 19:43:06 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-09 19:43:03 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-09 19:43:03 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-09 19:43:02 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-09 19:43:00 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-31 02:04:53 ——– d—–w- c:\users\babbag~1\appdata\roaming\SpinTop Games
2011-01-27 18:45:29 ——– d—–w- c:\users\babbag~1\appdata\roaming\BitZipper
==================== Find3M ====================
2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
2011-01-04 16:36:39 21258 —-a-w- c:\windows\cscmondump.bin
2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-18 06:27:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-18 06:22:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-18 06:22:27 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-18 06:22:11 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-12-18 06:22:11 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-12-18 05:25:26 385024 —-a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
c:\windows\system32\drivers\nvstor32.sys NVIDIA Corporation NVIDIA nForce™ SATA Driver
1 ntkrnlpa!IofCallDriver[0x82657912] -> \Device\Harddisk0\DR0[0x85FF60E0]
3 CLASSPNP[0x807388B3] -> ntkrnlpa!IofCallDriver[0x82657912] -> [0x855DACB8]
5 acpi[0x806156BC] -> ntkrnlpa!IofCallDriver[0x82657912] -> \Device\0000005b[0x8564AA88]
kernel: MBR read successfully
_asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x5d; }
user != kernel MBR !!!
============= FINISH: 12:40:30.06 ===============
Here is also an ATTACH.TXT report:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/14/2009 2:40:28 AM
System Uptime: 2/24/2011 12:34:28 PM (0 hours ago)
Motherboard: OEM_MB | | NARRA3
Processor: AMD Athlon™ 64 X2 Dual Core Processor 5000+ | Socket AM2 | 2400/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 325 GiB total, 235.48 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 1.344 GiB free.
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&37EFC377&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&37EFC377&0
Service: i8042prt
==== System Restore Points ===================
RP668: 1/30/2011 4:16:31 AM - Scheduled Checkpoint
RP669: 1/31/2011 2:48:03 AM - Scheduled Checkpoint
RP670: 2/1/2011 12:12:47 AM - Scheduled Checkpoint
RP671: 2/1/2011 1:42:53 AM - Windows Update
RP672: 2/2/2011 2:21:20 AM - Scheduled Checkpoint
RP673: 2/3/2011 12:38:05 AM - Scheduled Checkpoint
RP674: 2/4/2011 1:42:55 AM - Windows Update
RP675: 2/8/2011 1:42:50 AM - Windows Update
RP676: 2/8/2011 4:22:25 PM - Scheduled Checkpoint
RP677: 2/10/2011 2:05:28 AM - Scheduled Checkpoint
RP678: 2/10/2011 3:00:14 AM - Windows Update
RP679: 2/11/2011 2:11:48 AM - Windows Update
RP680: 2/12/2011 5:13:02 AM - Norton 360 Registry Clean
RP681: 2/13/2011 5:27:37 AM - Scheduled Checkpoint
RP682: 2/14/2011 4:55:50 AM - Scheduled Checkpoint
RP683: 2/15/2011 12:49:45 AM - Scheduled Checkpoint
RP684: 2/15/2011 1:43:53 AM - Windows Update
RP685: 2/16/2011 12:14:59 AM - Scheduled Checkpoint
RP686: 2/17/2011 4:52:04 AM - Scheduled Checkpoint
RP687: 2/18/2011 2:06:05 AM - Windows Update
RP688: 2/18/2011 4:34:04 AM - Norton 360 Registry Clean
RP690: 2/18/2011 5:03:04 AM - Windows Defender Checkpoint
RP691: 2/19/2011 12:16:24 AM - Restore Operation
RP692: 2/19/2011 12:28:28 AM - Restore Operation
RP694: 2/19/2011 4:06:06 AM - Windows Defender Checkpoint
RP696: 2/20/2011 3:24:51 PM - Scheduled Checkpoint
RP697: 2/21/2011 8:10:10 AM - OTL Restore Point
RP698: 2/22/2011 7:07:13 PM - Scheduled Checkpoint
RP699: 2/23/2011 2:12:34 PM - Scheduled Checkpoint
RP700: 2/23/2011 4:06:43 PM - Removed Java™ SE Runtime Environment 6 Update 1
RP701: 2/23/2011 4:15:01 PM - Installed Java™ 6 Update 20
RP702: 2/24/2011 3:00:25 AM - Windows Update
RP703: 2/24/2011 12:17:22 PM - new restore 02-24-2011
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.0
Adobe Shockwave Player 11.5
AIO_Scan
Apple Mobile Device Support
Apple Software Update
Bonjour
BufferChm
C5200
C5200_doccd
c5200_Help
CBE2_1
CCleaner
Cisco Network Magic
Compatibility Pack for the 2007 Office system
Copy
CustomerResearchQFolder
CyberLink DVD Suite Deluxe
CyberLink PowerDirector
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DHTML Editing Component
DocProc
DocProcQFolder
Download Updater (AOL LLC)
Enhanced Multimedia Keyboard Solution
ESET Online Scanner v3
eSupportQFolder
Eusing Free Registry Cleaner
Fax
Hardware Diagnostic Tools
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Customer Feedback
HP Customer Participation Program 9.0
HP Demo
HP Games
HP Imaging Device Functions 9.0
HP OCR Software 9.0
HP Photosmart All-In-One Software 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Picasso Media Center Add-In
HP Smart Web Printing
HP Solution Center 9.0
HP Total Care Advisor
HP Update
HPProductAssistant
HPSSupply
HPTCSSetup
iTunes
Java Auto Updater
Java™ 6 Update 20
LabelPrint
LightScribe System Software
LightScribeTemplateLabeler
LiveUpdate (Symantec Corporation)
magicJack
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Move Media Player
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
Network Magic
Norton Security Suite
NVIDIA Drivers
OGA Notifier 2.0.0048.0
PanoStandAlone
Power2Go
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_min
PSSWCORE
Pure Networks Platform
Python 2.5
QuickTime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
Revo Uninstaller 1.88
Samantha Swift 3
Savings Bond Wizard
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Snapfish Picture Mover
Soft Data Fax Modem with SmartCP
SolutionCenter
Status
Toolbox
TrayApp
Turbo Lister 2
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Veetle TV 0.9.18
VideoToolkit01
Visual C++ 8.0 CRT (x86) WinSXS MSM
WebEx Support Manager for Internet Explorer
WebReg
Windows Live ID Sign-in Assistant
==== Event Viewer Messages From Past Week ========
2/24/2011 12:36:50 PM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
2/24/2011 12:36:28 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
2/24/2011 12:27:30 PM, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer WebEx Document Loader with shared resource name WebEx Document Loader. Error 2114. The printer cannot be used by others on the network.
2/23/2011 1:40:52 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer SAMANTHA that believes that it is the master browser for the domain on transport NetBT_Tcpip_{6CA0F23B-C7FC-430F-93B0-CB54DE0E3. The master browser is stopping or an election is being forced.
2/23/2011 1:25:30 AM, Error: EventLog [6008] - The previous system shutdown at 1:21:02 AM on 2/23/2011 was unexpected.
2/22/2011 7:44:35 PM, Error: EventLog [6008] - The previous system shutdown at 7:39:16 PM on 2/22/2011 was unexpected.
2/22/2011 7:21:46 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
2/22/2011 7:16:16 PM, Error: Service Control Manager [7034] - The XAudioService service terminated unexpectedly. It has done this 1 time(s).
2/21/2011 8:20:09 PM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
2/20/2011 1:55:05 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx86 ccHP DfsC eeCtrl i8042prt IDSVix86 NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr SRTSP SRTSPX SymIM SYMTDI Tcpip tdx Wanarpv6
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:55:05 PM, Error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2011 1:54:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
2/20/2011 1:54:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
2/20/2011 1:54:12 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
2/20/2011 1:54:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/20/2011 1:54:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
2/19/2011 1:23:55 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BHDrvx86 ccHP eeCtrl i8042prt IDSVix86 spldr SRTSP SRTSPX SYMTDI Wanarpv6
2/18/2011 3:07:29 PM, Error: EventLog [6008] - The previous system shutdown at 3:01:19 PM on 2/18/2011 was unexpected.
==== End Of File ===========================
Hello
babbagene
Is this a neworked machine? If so, please disconnect it from the network while we try and get it cleaned.
Please keepin mind that the MBAM that I am running is NOT up tpo date because for some reason it will notupdate to the current version
Do you receive any error messages when trying to update MBAM?
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Not sure why your MBAM is not updating but
1.34 is a very old version of the program, and I suspect that the database has not been updated for some considerable time (the current dastabase version is 5871).
Before we try and sort out the MBAM issue, I would like to check on something with the following tools:
TDSS Killer
Please read carefully and follow these steps. Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and Right click on TDSSKiller.exe and select "Run as Administrator" to run the application. Click on Start Scan. If an infected file is detected, the default action will be Cure , click on Continue. If a suspicious file is detected, the default action will be Skip , click on Continue. It may ask you to reboot the computer to complete the process. Click on Reboot Now . If no reboot is require, click on Report . A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt ". Please copy and paste the contents of that file here.
MBRCheck
Please download MBRCheck by clicking here and save it to your desktop. Be sure to disable your security programs. Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt). A window will open on your desktop. If an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice. If nothing unusual is found just press Enter . A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop. Please post the contents of that file in your next reply.
Please post the TDSSKiller log and the MBRCheck log in your next reply.
Hi here is the TDS Report:
2011/02/24 18:30:16.0238 3116 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08
2011/02/24 18:30:16.0347 3116 ================================================================================
2011/02/24 18:30:16.0347 3116 SystemInfo:
2011/02/24 18:30:16.0347 3116
2011/02/24 18:30:16.0347 3116 OS Version: 6.0.6002 ServicePack: 2.0
2011/02/24 18:30:16.0347 3116 Product type: Workstation
2011/02/24 18:30:16.0347 3116 ComputerName: SAM
2011/02/24 18:30:16.0347 3116 UserName: babbagene
2011/02/24 18:30:16.0347 3116 Windows directory: C:\Windows
2011/02/24 18:30:16.0347 3116 System windows directory: C:\Windows
2011/02/24 18:30:16.0347 3116 Processor architecture: Intel x86
2011/02/24 18:30:16.0347 3116 Number of processors: 2
2011/02/24 18:30:16.0347 3116 Page size: 0x1000
2011/02/24 18:30:16.0347 3116 Boot type: Normal boot
2011/02/24 18:30:16.0347 3116 ================================================================================
2011/02/24 18:30:16.0737 3116 Initialize success
2011/02/24 18:30:33.0538 5148 ================================================================================
2011/02/24 18:30:33.0538 5148 Scan started
2011/02/24 18:30:33.0538 5148 Mode: Manual;
2011/02/24 18:30:33.0538 5148 ================================================================================
2011/02/24 18:30:34.0272 5148 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/02/24 18:30:34.0303 5148 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/02/24 18:30:34.0350 5148 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/02/24 18:30:34.0365 5148 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/02/24 18:30:34.0412 5148 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/02/24 18:30:34.0490 5148 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/02/24 18:30:34.0521 5148 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/02/24 18:30:34.0552 5148 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/02/24 18:30:34.0584 5148 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/02/24 18:30:34.0599 5148 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/02/24 18:30:34.0630 5148 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/02/24 18:30:34.0693 5148 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/02/24 18:30:34.0724 5148 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/02/24 18:30:34.0818 5148 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/02/24 18:30:34.0849 5148 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/02/24 18:30:34.0896 5148 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/24 18:30:34.0927 5148 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/02/24 18:30:34.0974 5148 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/02/24 18:30:35.0036 5148 BHDrvx86 (76154fa6a742c613b44bb636b1a7c057) C:\Windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys
2011/02/24 18:30:35.0098 5148 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/02/24 18:30:35.0176 5148 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/24 18:30:35.0208 5148 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/24 18:30:35.0239 5148 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/02/24 18:30:35.0286 5148 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/02/24 18:30:35.0301 5148 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/02/24 18:30:35.0332 5148 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/24 18:30:35.0348 5148 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/02/24 18:30:35.0395 5148 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/02/24 18:30:35.0613 5148 ccHP (8973ff34b83572d867b5b928905ad5ac) C:\Windows\System32\Drivers\N360\0308000.029\ccHPx86.sys
2011/02/24 18:30:35.0691 5148 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/24 18:30:35.0738 5148 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/24 18:30:35.0816 5148 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/02/24 18:30:35.0894 5148 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/02/24 18:30:35.0956 5148 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/02/24 18:30:36.0019 5148 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
2011/02/24 18:30:36.0066 5148 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/02/24 18:30:36.0128 5148 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/02/24 18:30:36.0222 5148 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/02/24 18:30:36.0268 5148 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/02/24 18:30:36.0331 5148 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
2011/02/24 18:30:36.0378 5148 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/02/24 18:30:36.0424 5148 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/02/24 18:30:36.0487 5148 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/02/24 18:30:36.0549 5148 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/24 18:30:36.0580 5148 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/02/24 18:30:36.0643 5148 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/02/24 18:30:36.0736 5148 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/02/24 18:30:36.0892 5148 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/02/24 18:30:37.0017 5148 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2011/02/24 18:30:37.0033 5148 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/02/24 18:30:37.0111 5148 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/02/24 18:30:37.0142 5148 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/02/24 18:30:37.0189 5148 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/24 18:30:37.0236 5148 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/02/24 18:30:37.0267 5148 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/02/24 18:30:37.0314 5148 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/24 18:30:37.0376 5148 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/02/24 18:30:37.0423 5148 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/24 18:30:37.0454 5148 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/24 18:30:37.0501 5148 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/24 18:30:37.0579 5148 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/02/24 18:30:37.0626 5148 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/24 18:30:37.0672 5148 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/02/24 18:30:37.0704 5148 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/02/24 18:30:37.0766 5148 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/24 18:30:37.0813 5148 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/02/24 18:30:37.0891 5148 HSF_DP (88749fbf8beb18c90e7d6626c8c1910b) C:\Windows\system32\DRIVERS\HSX_DP.sys
2011/02/24 18:30:37.0969 5148 HSXHWBS2 (fe440536bd98af772130dc3a6fe1915f) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
2011/02/24 18:30:38.0016 5148 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/02/24 18:30:38.0047 5148 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/02/24 18:30:38.0062 5148 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/24 18:30:38.0094 5148 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/02/24 18:30:38.0187 5148 IDSVix86 (33ca0e61eab15d439a1f592ddc020712) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110223.001\IDSvix86.sys
2011/02/24 18:30:38.0250 5148 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/02/24 18:30:38.0359 5148 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys
2011/02/24 18:30:38.0452 5148 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/02/24 18:30:38.0499 5148 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/24 18:30:38.0530 5148 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/24 18:30:38.0608 5148 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/24 18:30:38.0640 5148 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/24 18:30:38.0686 5148 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/02/24 18:30:38.0733 5148 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/02/24 18:30:38.0764 5148 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/24 18:30:38.0811 5148 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/02/24 18:30:38.0842 5148 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/02/24 18:30:38.0874 5148 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/24 18:30:38.0920 5148 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/02/24 18:30:38.0983 5148 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/24 18:30:39.0092 5148 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/24 18:30:39.0139 5148 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/24 18:30:39.0201 5148 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/24 18:30:39.0232 5148 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/24 18:30:39.0279 5148 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/02/24 18:30:39.0342 5148 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/02/24 18:30:39.0388 5148 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/02/24 18:30:39.0435 5148 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/02/24 18:30:39.0498 5148 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/02/24 18:30:39.0544 5148 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/24 18:30:39.0576 5148 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/24 18:30:39.0607 5148 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/24 18:30:39.0638 5148 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/02/24 18:30:39.0700 5148 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/02/24 18:30:39.0763 5148 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/24 18:30:39.0810 5148 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/24 18:30:39.0841 5148 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/02/24 18:30:39.0919 5148 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/24 18:30:39.0966 5148 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/24 18:30:40.0012 5148 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/24 18:30:40.0075 5148 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/02/24 18:30:40.0106 5148 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/02/24 18:30:40.0184 5148 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/02/24 18:30:40.0215 5148 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/02/24 18:30:40.0262 5148 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/24 18:30:40.0278 5148 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/24 18:30:40.0309 5148 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/02/24 18:30:40.0402 5148 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/02/24 18:30:40.0465 5148 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/24 18:30:40.0527 5148 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/02/24 18:30:40.0590 5148 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/02/24 18:30:40.0683 5148 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/24 18:30:40.0792 5148 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.003\NAVENG.SYS
2011/02/24 18:30:40.0870 5148 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.003\NAVEX15.SYS
2011/02/24 18:30:40.0995 5148 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/02/24 18:30:41.0042 5148 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/24 18:30:41.0058 5148 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/24 18:30:41.0104 5148 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/24 18:30:41.0136 5148 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/02/24 18:30:41.0167 5148 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/24 18:30:41.0214 5148 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/24 18:30:41.0276 5148 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/02/24 18:30:41.0338 5148 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/02/24 18:30:41.0370 5148 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/24 18:30:41.0448 5148 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/02/24 18:30:41.0494 5148 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/02/24 18:30:41.0526 5148 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
2011/02/24 18:30:41.0557 5148 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/02/24 18:30:41.0619 5148 NVENETFD (ae78a7285df03a277415fc62f8ce8f24) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/02/24 18:30:41.0806 5148 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/02/24 18:30:41.0978 5148 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/02/24 18:30:42.0009 5148 nvrd32 (0d15327134e5871c922760acd7449e84) C:\Windows\system32\drivers\nvrd32.sys
2011/02/24 18:30:42.0056 5148 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\drivers\nvsmu.sys
2011/02/24 18:30:42.0103 5148 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/02/24 18:30:42.0134 5148 nvstor32 (fa7b8eca6e845b244b7e30a9dcd82c6c) C:\Windows\system32\drivers\nvstor32.sys
2011/02/24 18:30:42.0181 5148 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/02/24 18:30:42.0306 5148 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/24 18:30:42.0352 5148 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/02/24 18:30:42.0399 5148 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/02/24 18:30:42.0430 5148 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/02/24 18:30:42.0524 5148 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/02/24 18:30:42.0555 5148 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2011/02/24 18:30:42.0586 5148 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/02/24 18:30:42.0649 5148 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/02/24 18:30:42.0758 5148 pnarp (63200893c9d5934a7504d20f68276cc7) C:\Windows\system32\DRIVERS\pnarp.sys
2011/02/24 18:30:42.0883 5148 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/24 18:30:42.0945 5148 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/02/24 18:30:42.0992 5148 Ps2 (390c204ced3785609ab24e9c52054a84) C:\Windows\system32\DRIVERS\PS2.sys
2011/02/24 18:30:43.0070 5148 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/24 18:30:43.0101 5148 purendis (748bcab4eff5959ed347c05a1c1a0af8) C:\Windows\system32\DRIVERS\purendis.sys
2011/02/24 18:30:43.0164 5148 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/02/24 18:30:43.0210 5148 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/02/24 18:30:43.0242 5148 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/24 18:30:43.0273 5148 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/24 18:30:43.0304 5148 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/24 18:30:43.0351 5148 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/24 18:30:43.0398 5148 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/24 18:30:43.0444 5148 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/24 18:30:43.0476 5148 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/24 18:30:43.0507 5148 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/02/24 18:30:43.0538 5148 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/24 18:30:43.0585 5148 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/02/24 18:30:43.0678 5148 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys
2011/02/24 18:30:43.0710 5148 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/24 18:30:43.0756 5148 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/02/24 18:30:43.0819 5148 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/02/24 18:30:43.0881 5148 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/02/24 18:30:43.0912 5148 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/02/24 18:30:43.0944 5148 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/02/24 18:30:44.0037 5148 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/02/24 18:30:44.0053 5148 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/24 18:30:44.0084 5148 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/24 18:30:44.0115 5148 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/02/24 18:30:44.0178 5148 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/02/24 18:30:44.0193 5148 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/02/24 18:30:44.0224 5148 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/02/24 18:30:44.0302 5148 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/02/24 18:30:44.0365 5148 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/02/24 18:30:44.0427 5148 SRTSP (e81f6caeab9ad5732e94c07c97866aa2) C:\Windows\System32\Drivers\N360\0308000.029\SRTSP.SYS
2011/02/24 18:30:44.0474 5148 SRTSPX (e28de499d942b08058bffac69d4122b6) C:\Windows\system32\drivers\N360\0308000.029\SRTSPX.SYS
2011/02/24 18:30:44.0521 5148 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/02/24 18:30:44.0568 5148 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/24 18:30:44.0599 5148 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/24 18:30:44.0677 5148 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/24 18:30:44.0724 5148 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/02/24 18:30:44.0833 5148 SymEFA (d0885f6e24259a6c65e68d6ad749910a) C:\Windows\system32\drivers\N360\0308000.029\SYMEFA.SYS
2011/02/24 18:30:44.0864 5148 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS
2011/02/24 18:30:44.0911 5148 SYMFW (1e825026436c4eac3e1a11d1e9c33f2c) C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS
2011/02/24 18:30:45.0004 5148 SymIM (34f1c9d5dcc19df1e824d6b73767b8af) C:\Windows\system32\DRIVERS\SymIMv.sys
2011/02/24 18:30:45.0098 5148 SYMNDISV (dcbf73da96cce94933c8cc6eded3c98b) C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS
2011/02/24 18:30:45.0176 5148 SYMTDI (e4fa8bbb96e314e9508865de1a767538) C:\Windows\System32\Drivers\N360\0308000.029\SYMTDI.SYS
2011/02/24 18:30:45.0223 5148 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/02/24 18:30:45.0254 5148 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/02/24 18:30:45.0332 5148 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/02/24 18:30:45.0394 5148 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/24 18:30:45.0441 5148 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/24 18:30:45.0488 5148 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/02/24 18:30:45.0519 5148 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/02/24 18:30:45.0582 5148 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/24 18:30:45.0613 5148 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/24 18:30:45.0691 5148 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/24 18:30:45.0722 5148 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/24 18:30:45.0753 5148 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/24 18:30:45.0800 5148 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/02/24 18:30:45.0847 5148 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/24 18:30:45.0909 5148 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/24 18:30:45.0940 5148 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/02/24 18:30:45.0956 5148 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/02/24 18:30:46.0003 5148 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/02/24 18:30:46.0034 5148 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/24 18:30:46.0081 5148 USBAAPL (60a68a5ea173a97971ee9f1ff49eb2b3) C:\Windows\system32\Drivers\usbaapl.sys
2011/02/24 18:30:46.0143 5148 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
2011/02/24 18:30:46.0190 5148 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/24 18:30:46.0237 5148 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/02/24 18:30:46.0284 5148 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/24 18:30:46.0330 5148 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/24 18:30:46.0377 5148 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2011/02/24 18:30:46.0408 5148 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/02/24 18:30:46.0471 5148 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/02/24 18:30:46.0518 5148 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/02/24 18:30:46.0564 5148 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/02/24 18:30:46.0611 5148 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/02/24 18:30:46.0674 5148 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/02/24 18:30:46.0689 5148 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/02/24 18:30:46.0705 5148 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/02/24 18:30:46.0752 5148 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/02/24 18:30:46.0767 5148 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/02/24 18:30:46.0814 5148 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/02/24 18:30:46.0861 5148 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/02/24 18:30:46.0892 5148 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/02/24 18:30:46.0939 5148 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/02/24 18:30:46.0986 5148 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/24 18:30:47.0001 5148 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/24 18:30:47.0095 5148 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/02/24 18:30:47.0126 5148 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/02/24 18:30:47.0220 5148 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2011/02/24 18:30:47.0360 5148 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/02/24 18:30:47.0438 5148 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/02/24 18:30:47.0500 5148 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/02/24 18:30:47.0547 5148 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/02/24 18:30:47.0594 5148 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2011/02/24 18:30:47.0766 5148 ================================================================================
2011/02/24 18:30:47.0766 5148 Scan finished
2011/02/24 18:30:47.0766 5148 ================================================================================
Here is the MBR CHECK:
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: OEM_MB
BIOS Manufacturer: Phoenix Technologies, LTD
System Manufacturer: HP-Pavilion
System Product Name: KZ761AA-ABA a6522f
Logical Drives Mask: 0x000003dc
Kernel Drivers (total 158):
0x82611000 \SystemRoot\system32\ntkrnlpa.exe
0x829CB000 \SystemRoot\system32\hal.dll
0x8040A000 \SystemRoot\system32\kdcom.dll
0x80411000 \SystemRoot\system32\PSHED.dll
0x80422000 \SystemRoot\system32\BOOTVID.dll
0x8042A000 \SystemRoot\system32\CLFS.SYS
0x8046B000 \SystemRoot\system32\CI.dll
0x8054B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x805C7000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80605000 \SystemRoot\system32\drivers\acpi.sys
0x8064B000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80654000 \SystemRoot\system32\drivers\msisadrv.sys
0x8065C000 \SystemRoot\system32\drivers\pci.sys
0x80683000 \SystemRoot\System32\drivers\partmgr.sys
0x80692000 \SystemRoot\system32\drivers\volmgr.sys
0x806A1000 \SystemRoot\System32\drivers\volmgrx.sys
0x806EB000 \SystemRoot\system32\drivers\pciide.sys
0x806F2000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x80700000 \SystemRoot\System32\drivers\mountmgr.sys
0x80710000 \SystemRoot\system32\drivers\nvraid.sys
0x8072B000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8074C000 \SystemRoot\system32\drivers\atapi.sys
0x80754000 \SystemRoot\system32\drivers\ataport.SYS
0x80772000 \SystemRoot\system32\drivers\nvstor32.sys
0x80796000 \SystemRoot\system32\drivers\storport.sys
0x8A001000 \SystemRoot\system32\drivers\fltmgr.sys
0x8A033000 \SystemRoot\system32\drivers\fileinfo.sys
0x8A043000 \SystemRoot\system32\drivers\N360\0308000.029\SYMEFA.SYS
0x8A092000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8A206000 \SystemRoot\system32\drivers\ndis.sys
0x8A311000 \SystemRoot\system32\drivers\msrpc.sys
0x8A33C000 \SystemRoot\system32\drivers\NETIO.SYS
0x8A40E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8A51E000 \SystemRoot\system32\drivers\volsnap.sys
0x8A557000 \SystemRoot\System32\Drivers\spldr.sys
0x8A55F000 \SystemRoot\System32\Drivers\mup.sys
0x8A56E000 \SystemRoot\System32\drivers\ecache.sys
0x8A595000 \SystemRoot\system32\drivers\disk.sys
0x8A5A6000 \SystemRoot\system32\drivers\crcdisk.sys
0x8A5EA000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8A5F5000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8A377000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x8A400000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8A39A000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8A3A4000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8A3E2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8A103000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8A3F1000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8A113000 \SystemRoot\system32\DRIVERS\HSXHWBS2.sys
0x8A15F000 \SystemRoot\system32\DRIVERS\ks.sys
0x8E00B000 \SystemRoot\system32\DRIVERS\HSX_DP.sys
0x8E10D000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8E1C2000 \SystemRoot\system32\drivers\modem.sys
0x8E402000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8E48F000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8E58C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8E5A4000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8E60E000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8ED2D000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8EDCD000 \SystemRoot\System32\drivers\watchdog.sys
0x8E5AA000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EDD9000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EDE4000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8E600000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8E5D9000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8E1CF000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8E1DE000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8A189000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8A19E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8E1F2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8E60B000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8E000000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8A1AE000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8A1BB000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8A387000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8F206000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8F413000 \SystemRoot\system32\drivers\portcls.sys
0x8F440000 \SystemRoot\system32\drivers\drmk.sys
0x8F465000 \SystemRoot\System32\Drivers\N360\0308000.029\SRTSP.SYS
0x8F4B8000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8F4CF000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F4D1000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8F4DA000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8F4EA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8F4F1000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8F4FA000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
0x8F501000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x9000D000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.003\NAVEX15.SYS
0x90158000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x9017D000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x90192000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20110224.003\NAVENG.SYS
0x901A6000 \SystemRoot\system32\drivers\N360\0308000.029\SRTSPX.SYS
0x901B0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x901B9000 \SystemRoot\System32\Drivers\Null.SYS
0x901C0000 \SystemRoot\System32\Drivers\Beep.SYS
0x901C7000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x901DA000 \SystemRoot\System32\drivers\vga.sys
0x8F509000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x901E6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x901EE000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90000000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F52A000 \SystemRoot\System32\Drivers\Npfs.SYS
0x901F6000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x9240A000 \SystemRoot\System32\drivers\tcpip.sys
0x924F4000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x9250F000 \SystemRoot\system32\DRIVERS\tdx.sys
0x92525000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMTDI.SYS
0x92559000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMNDISV.SYS
0x92567000 \SystemRoot\System32\Drivers\N360\0308000.029\SYMFW.SYS
0x9257C000 \SystemRoot\system32\DRIVERS\smb.sys
0x92590000 \SystemRoot\system32\drivers\afd.sys
0x8F538000 \SystemRoot\System32\DRIVERS\netbt.sys
0x925D8000 \SystemRoot\system32\DRIVERS\pacer.sys
0x925EE000 \SystemRoot\system32\DRIVERS\SymIMv.sys
0x8F56A000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F578000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F58B000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92400000 \SystemRoot\system32\drivers\nsiproxy.sys
0x95E03000 \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20110223.001\IDSvix86.sys
0x95E5E000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x95EBC000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0x95ED9000 \SystemRoot\System32\Drivers\dfsc.sys
0x95EF0000 \SystemRoot\System32\Drivers\N360\0308000.029\ccHPx86.sys
0x95F6B000 \SystemRoot\System32\Drivers\N360\0308000.029\BHDrvx86.sys
0x95FAD000 \SystemRoot\System32\Drivers\crashdmp.sys
0x95FBA000 \SystemRoot\System32\Drivers\dump_diskdump.sys
0x95FC4000 \SystemRoot\System32\Drivers\dump_nvstor32.sys
0x9FC80000 \SystemRoot\System32\win32k.sys
0x95FE8000 \SystemRoot\System32\drivers\Dxapi.sys
0x8F5C7000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9FEA0000 \SystemRoot\System32\TSDDD.dll
0x9FEC0000 \SystemRoot\System32\cdd.dll
0x8F5D6000 \SystemRoot\system32\drivers\luafv.sys
0xA6600000 \SystemRoot\system32\drivers\spsys.sys
0xA66B0000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xA66C0000 \SystemRoot\system32\DRIVERS\pnarp.sys
0xA66CA000 \SystemRoot\system32\DRIVERS\purendis.sys
0xA66D4000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xA66E7000 \SystemRoot\system32\drivers\HTTP.sys
0xA6754000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA6771000 \SystemRoot\system32\DRIVERS\bowser.sys
0xA678A000 \SystemRoot\System32\drivers\mpsdrv.sys
0xA679F000 \SystemRoot\system32\drivers\mrxdav.sys
0xA67C0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x8A5AF000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA67DF000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x807D7000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA7C0A000 \SystemRoot\System32\DRIVERS\srv.sys
0xA7C70000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xA7C74000 \SystemRoot\system32\drivers\peauth.sys
0xA7D52000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA7D5C000 \SystemRoot\System32\drivers\tcpipreg.sys
0xA7D68000 \SystemRoot\system32\DRIVERS\xaudio.sys
0xA7D70000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0xA7D85000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0xA7D97000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xA7DAD000 \SystemRoot\system32\DRIVERS\udfs.sys
0x771F0000 \WINDOWS\System32\ntdll.dll
Processes (total 56):
0 System Idle Process
4 System
508 C:\WINDOWS\System32\smss.exe
580 csrss.exe
632 C:\WINDOWS\System32\wininit.exe
644 csrss.exe
680 C:\WINDOWS\System32\winlogon.exe
716 C:\WINDOWS\System32\services.exe
728 C:\WINDOWS\System32\lsass.exe
740 C:\WINDOWS\System32\lsm.exe
884 C:\WINDOWS\System32\svchost.exe
928 C:\WINDOWS\System32\nvvsvc.exe
968 C:\WINDOWS\System32\svchost.exe
1112 C:\WINDOWS\System32\svchost.exe
1136 C:\WINDOWS\System32\svchost.exe
1148 C:\WINDOWS\System32\svchost.exe
1268 C:\WINDOWS\System32\audiodg.exe
1296 C:\WINDOWS\System32\svchost.exe
1316 C:\WINDOWS\System32\SLsvc.exe
1356 C:\WINDOWS\System32\rundll32.exe
1388 C:\WINDOWS\System32\svchost.exe
1552 C:\WINDOWS\System32\svchost.exe
1732 C:\WINDOWS\System32\spoolsv.exe
1756 C:\WINDOWS\System32\svchost.exe
348 C:\WINDOWS\System32\dwm.exe
484 C:\WINDOWS\System32\taskeng.exe
556 C:\WINDOWS\explorer.exe
1100 C:\WINDOWS\System32\taskeng.exe
2744 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
2780 C:\Program Files\Bonjour\mDNSResponder.exe
2816 C:\WINDOWS\System32\svchost.exe
2864 C:\Program Files\iWin Games\iWinTrusted.exe
3032 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
3064 C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
3080 C:\WINDOWS\System32\svchost.exe
3224 C:\WINDOWS\System32\svchost.exe
3320 C:\WINDOWS\System32\svchost.exe
3340 C:\WINDOWS\System32\svchost.exe
3420 C:\WINDOWS\System32\svchost.exe
3556 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
3676 WUDFHost.exe
3720 C:\WINDOWS\System32\drivers\XAudio.exe
3752 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
1372 C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
2740 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
2676 C:\Program Files\Internet Explorer\iexplore.exe
6076 C:\Program Files\Internet Explorer\iexplore.exe
5196 C:\WINDOWS\System32\Macromed\Flash\FlashUtil10e.exe
6068 dllhost.exe
5180 C:\WINDOWS\System32\svchost.exe
4892 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
4828 C:\Program Files\Windows Media Player\wmpnscfg.exe
4848 C:\Program Files\Windows Media Player\wmpnetwk.exe
268 dllhost.exe
3440 dllhost.exe
4812 C:\Users\babbagene\Desktop\MBRCheck.com
\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive0 at offset 0x00000051`47100000 (NTFS)
PhysicalDrive0 Model Number: ST3360320AS, Rev: 3.CH
Size Device Name MBR Status
——————————————–
335 GB \\.\PhysicalDrive0 Hewlett-Packard MBR code detected
SHA1: F362CE084BC77B454330005C1657154A64FB9456
Done!
After running the above programs I restarted my computer with the same results.As a last chance effort I ran a program called called
File association fixes for Windows Vista
,which can be found here:
http://www.winhelponline.com/articles/105/…dows-Vista.html
As soon as I ran this program and restarted the computer everything worked fine.
Thank You for your help.
Regards
Sam