This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

intrusion attempt blocked by norton whenever internet explorer used

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi, i have been recieving notifications from my norton antivirus that an intrusion attempt has been blocked every few minutes whenever i am on internet explorer. in the details a couple of different sources have commonly been popping up. here are a few Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,Risk Name,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 2/20/2011 8:44 PM,High,An intrusion attempt by sh1ik0nuc.com was blocked.,Blocked,No Action Required,HTTP Tidserv Request,"sh1ik0nuc.com (91.200.240.31, 80)","sh1ik0nuc.com/yVZ4qbae7Y6JZyc2dmVyPTQuMCZiaWQ9ZmQ2ZGMxYzI5YjJhYTNiNzIyY2ZmM2JiM2MxZDQyNGM3MWI1 OTIyMiZhaWQ9MzAwMzQmc2lkPTAmcmQ9MCZlbmc9Y2Euc2VhcmNoLnlhaG9vLmNvbSZxPW0237h","my ip address",[removed] ([removed]),"TCP, www-http" Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,Risk Name,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 2/20/2011 8:41 PM,High,An intrusion attempt by switcho81.com was blocked.,Blocked,No Action Required,HTTP Tidserv Request,"switcho81.com (194.60.205.233, 80)","switcho81.com/RvC20P2L5E7Y0Hc9dmVyPTQuMCZiaWQ9ZmQ2ZGMxYzI5YjJhYTNiNzIyY2ZmM2JiM2MxZDQyNGM3MWI1 OTIyMiZhaWQ9MzAwMzQmc2lkPTAmcmQ9MCZlbmc9Y2Euc2VhcmNoLnlhaG9vLmNvbSZxPXNlYXJjaCBwY WdlcyB3b24ndCBvcGVu07g","my computer",[removed] ([removed]),"TCP, www-http" Category: Intrusion Prevention Date & Time,Risk,Activity,Status,Recommended Action,Risk Name,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description 2/20/2011 8:41 PM,High,An intrusion attempt by jikdooyt0.com was blocked.,Blocked,No Action Required,HTTP Tidserv Request,"jikdooyt0.com (199.101.28.21, 80)","jikdooyt0.com/aa011zhE736q9Qs4dmVyPTQuMCZiaWQ9ZmQ2ZGMxYzI5YjJhYTNiNzIyY2ZmM2JiM2MxZDQyNGM3MWI1 OTIyMiZhaWQ9MzAwMzQmc2lkPTAmcmQ9MCZlbmc9Y2Euc2VhcmNoLnlhaG9vLmNvbSZxPXNlYXJjaCBwY WdlcyB3b24ndCBvcGVu38k","my computer" [removed] ([removed]),"TCP, www-http" these occure every few minutes while i am on the internet. when i read more detailed descriptions of the intrusions, I noticed that all of them have something to do with the internet explorer.exe file in my program files. I am not really an expert when it comes to computer and thus any help at all would be greatly appreciated. I need the internet on a regular basis as i am a student and this is making life very difficult. :pullhair: thank you for reading this :)
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello Mowman, Thank you for the reply. TDSSKiller log: 2011/02/21 16:26:07.0771 5712 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08 2011/02/21 16:26:08.0380 5712 ================================================================================ 2011/02/21 16:26:08.0380 5712 SystemInfo: 2011/02/21 16:26:08.0380 5712 2011/02/21 16:26:08.0380 5712 OS Version: 6.0.6002 ServicePack: 2.0 2011/02/21 16:26:08.0380 5712 Product type: Workstation 2011/02/21 16:26:08.0380 5712 ComputerName: HP-PC 2011/02/21 16:26:08.0380 5712 UserName: hp 2011/02/21 16:26:08.0380 5712 Windows directory: C:\Windows 2011/02/21 16:26:08.0380 5712 System windows directory: C:\Windows 2011/02/21 16:26:08.0380 5712 Processor architecture: Intel x86 2011/02/21 16:26:08.0380 5712 Number of processors: 2 2011/02/21 16:26:08.0380 5712 Page size: 0x1000 2011/02/21 16:26:08.0380 5712 Boot type: Normal boot 2011/02/21 16:26:08.0380 5712 ================================================================================ 2011/02/21 16:26:09.0425 5712 Initialize success 2011/02/21 16:26:14.0292 3192 ================================================================================ 2011/02/21 16:26:14.0292 3192 Scan started 2011/02/21 16:26:14.0292 3192 Mode: Manual; 2011/02/21 16:26:14.0292 3192 ================================================================================ 2011/02/21 16:26:17.0474 3192 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/02/21 16:26:17.0646 3192 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2011/02/21 16:26:17.0849 3192 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2011/02/21 16:26:17.0974 3192 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2011/02/21 16:26:18.0052 3192 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2011/02/21 16:26:18.0208 3192 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/02/21 16:26:18.0364 3192 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2011/02/21 16:26:18.0629 3192 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/02/21 16:26:18.0800 3192 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 2011/02/21 16:26:18.0956 3192 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2011/02/21 16:26:19.0284 3192 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 2011/02/21 16:26:19.0424 3192 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2011/02/21 16:26:19.0643 3192 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2011/02/21 16:26:20.0142 3192 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2011/02/21 16:26:20.0267 3192 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2011/02/21 16:26:20.0407 3192 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/02/21 16:26:20.0516 3192 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/02/21 16:26:20.0672 3192 athr (0437199c88f6e88a387cfec8a8886a6e) C:\Windows\system32\DRIVERS\athr.sys 2011/02/21 16:26:20.0906 3192 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/02/21 16:26:21.0218 3192 BHDrvx86 (83a2fec59a0a0fc73bf6598e901b2fbd) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys 2011/02/21 16:26:21.0546 3192 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/02/21 16:26:21.0686 3192 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/02/21 16:26:21.0858 3192 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/02/21 16:26:22.0061 3192 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/02/21 16:26:22.0201 3192 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/02/21 16:26:22.0747 3192 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/02/21 16:26:22.0888 3192 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/02/21 16:26:22.0997 3192 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/02/21 16:26:23.0168 3192 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/02/21 16:26:23.0293 3192 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/02/21 16:26:23.0418 3192 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2011/02/21 16:26:23.0590 3192 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/02/21 16:26:23.0746 3192 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/02/21 16:26:23.0886 3192 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 2011/02/21 16:26:24.0229 3192 CnxtHdAudService (2e39f9c51912f4f211b0334aed33e7bd) C:\Windows\system32\drivers\CHDRT32.sys 2011/02/21 16:26:24.0572 3192 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/02/21 16:26:24.0713 3192 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2011/02/21 16:26:24.0775 3192 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2011/02/21 16:26:24.0994 3192 CSC (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys 2011/02/21 16:26:25.0165 3192 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/02/21 16:26:25.0337 3192 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/02/21 16:26:25.0540 3192 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 2011/02/21 16:26:25.0680 3192 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 2011/02/21 16:26:25.0742 3192 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 2011/02/21 16:26:25.0898 3192 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/02/21 16:26:26.0054 3192 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/02/21 16:26:26.0195 3192 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/02/21 16:26:26.0288 3192 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/02/21 16:26:26.0476 3192 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/02/21 16:26:26.0663 3192 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2011/02/21 16:26:26.0866 3192 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/02/21 16:26:27.0068 3192 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/02/21 16:26:27.0209 3192 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/02/21 16:26:27.0365 3192 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2011/02/21 16:26:27.0599 3192 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/02/21 16:26:27.0880 3192 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/02/21 16:26:28.0020 3192 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/02/21 16:26:28.0176 3192 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/02/21 16:26:28.0363 3192 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/02/21 16:26:28.0519 3192 fvevol (fecf4c2e42440a8d132bf94eee3c3fc9) C:\Windows\system32\DRIVERS\fvevol.sys 2011/02/21 16:26:28.0644 3192 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2011/02/21 16:26:28.0784 3192 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/02/21 16:26:28.0956 3192 HBtnKey (88a78635b41ed4b261365fadeb28fe81) C:\Windows\system32\DRIVERS\cpqbttn.sys 2011/02/21 16:26:29.0096 3192 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/02/21 16:26:29.0252 3192 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/02/21 16:26:29.0440 3192 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/02/21 16:26:29.0580 3192 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/02/21 16:26:29.0752 3192 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/02/21 16:26:29.0908 3192 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2011/02/21 16:26:30.0079 3192 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 2011/02/21 16:26:30.0298 3192 HSF_DPV (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/02/21 16:26:30.0469 3192 HSXHWAZL (a44ddf3ba83e4664bf4de9220097578c) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/02/21 16:26:30.0641 3192 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/02/21 16:26:30.0812 3192 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2011/02/21 16:26:31.0062 3192 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/02/21 16:26:31.0280 3192 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2011/02/21 16:26:31.0608 3192 IDSVix86 (33ca0e61eab15d439a1f592ddc020712) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110218.003\IDSvix86.sys 2011/02/21 16:26:31.0904 3192 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/02/21 16:26:32.0092 3192 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/02/21 16:26:32.0388 3192 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/02/21 16:26:32.0669 3192 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/02/21 16:26:32.0825 3192 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/02/21 16:26:33.0121 3192 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2011/02/21 16:26:33.0246 3192 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/02/21 16:26:33.0480 3192 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/02/21 16:26:33.0652 3192 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2011/02/21 16:26:33.0964 3192 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/02/21 16:26:34.0120 3192 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/02/21 16:26:34.0260 3192 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/02/21 16:26:34.0478 3192 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/02/21 16:26:34.0603 3192 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/02/21 16:26:34.0790 3192 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/02/21 16:26:34.0993 3192 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/02/21 16:26:35.0180 3192 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2011/02/21 16:26:35.0321 3192 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2011/02/21 16:26:35.0492 3192 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2011/02/21 16:26:35.0648 3192 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/02/21 16:26:35.0742 3192 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/02/21 16:26:35.0867 3192 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2011/02/21 16:26:36.0054 3192 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/02/21 16:26:36.0210 3192 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/02/21 16:26:36.0366 3192 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/02/21 16:26:36.0460 3192 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/02/21 16:26:36.0600 3192 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/02/21 16:26:36.0787 3192 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2011/02/21 16:26:36.0928 3192 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/02/21 16:26:37.0021 3192 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/02/21 16:26:37.0193 3192 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/02/21 16:26:37.0364 3192 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/02/21 16:26:37.0442 3192 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/02/21 16:26:37.0583 3192 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/02/21 16:26:37.0754 3192 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/02/21 16:26:37.0895 3192 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2011/02/21 16:26:38.0332 3192 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/02/21 16:26:38.0456 3192 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/02/21 16:26:38.0628 3192 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/02/21 16:26:38.0815 3192 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/02/21 16:26:38.0971 3192 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/02/21 16:26:39.0096 3192 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/02/21 16:26:39.0174 3192 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/02/21 16:26:39.0314 3192 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/02/21 16:26:39.0502 3192 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/02/21 16:26:39.0658 3192 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/02/21 16:26:39.0923 3192 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\NAVENG.SYS 2011/02/21 16:26:40.0219 3192 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\NAVEX15.SYS 2011/02/21 16:26:40.0422 3192 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/02/21 16:26:40.0562 3192 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/02/21 16:26:40.0718 3192 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/02/21 16:26:40.0796 3192 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/02/21 16:26:40.0968 3192 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/02/21 16:26:41.0124 3192 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/02/21 16:26:41.0186 3192 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/02/21 16:26:41.0374 3192 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/02/21 16:26:41.0545 3192 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/02/21 16:26:41.0670 3192 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/02/21 16:26:41.0857 3192 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/02/21 16:26:41.0982 3192 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/02/21 16:26:42.0107 3192 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/02/21 16:26:42.0263 3192 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 2011/02/21 16:26:42.0403 3192 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 2011/02/21 16:26:42.0637 3192 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2011/02/21 16:26:43.0012 3192 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 2011/02/21 16:26:43.0246 3192 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/02/21 16:26:43.0448 3192 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/02/21 16:26:43.0558 3192 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/02/21 16:26:43.0651 3192 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/02/21 16:26:43.0776 3192 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 2011/02/21 16:26:43.0916 3192 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/02/21 16:26:44.0104 3192 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/02/21 16:26:44.0400 3192 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/02/21 16:26:44.0525 3192 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2011/02/21 16:26:44.0681 3192 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/02/21 16:26:44.0852 3192 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2011/02/21 16:26:45.0086 3192 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/02/21 16:26:45.0211 3192 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/02/21 16:26:45.0352 3192 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/02/21 16:26:45.0492 3192 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/02/21 16:26:45.0632 3192 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/02/21 16:26:45.0757 3192 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/02/21 16:26:45.0898 3192 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/02/21 16:26:46.0054 3192 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/02/21 16:26:46.0225 3192 rdpdr (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys 2011/02/21 16:26:46.0366 3192 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/02/21 16:26:46.0428 3192 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/02/21 16:26:46.0584 3192 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys 2011/02/21 16:26:46.0678 3192 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/02/21 16:26:46.0818 3192 RTL8023xp (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys 2011/02/21 16:26:46.0958 3192 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/02/21 16:26:47.0130 3192 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/02/21 16:26:47.0317 3192 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/02/21 16:26:47.0458 3192 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/02/21 16:26:47.0598 3192 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/02/21 16:26:47.0785 3192 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys 2011/02/21 16:26:47.0926 3192 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2011/02/21 16:26:48.0097 3192 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys 2011/02/21 16:26:48.0144 3192 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/02/21 16:26:48.0300 3192 Sftfs (cc895997c0995a07b6b2779a3b21918b) C:\Windows\system32\DRIVERS\Sftfslh.sys 2011/02/21 16:26:48.0456 3192 Sftplay (cf5e9798637795db59697f5e40fca993) C:\Windows\system32\DRIVERS\Sftplaylh.sys 2011/02/21 16:26:48.0596 3192 Sftredir (4c8076ff8938b365eeec9123969e0350) C:\Windows\system32\DRIVERS\Sftredirlh.sys 2011/02/21 16:26:48.0752 3192 Sftvol (6095a5f221eca9dada2c9ee80ec0d92d) C:\Windows\system32\DRIVERS\Sftvollh.sys 2011/02/21 16:26:48.0908 3192 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2011/02/21 16:26:49.0033 3192 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2011/02/21 16:26:49.0111 3192 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2011/02/21 16:26:49.0283 3192 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/02/21 16:26:49.0439 3192 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/02/21 16:26:49.0673 3192 SRTSP (a7a104a61c4e30de9c58f8c372a5c209) C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 2011/02/21 16:26:49.0876 3192 SRTSPX (2833445f786bd000bb14c84a9d91347a) C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 2011/02/21 16:26:50.0032 3192 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/02/21 16:26:50.0156 3192 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/02/21 16:26:50.0281 3192 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/02/21 16:26:50.0500 3192 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/02/21 16:26:50.0656 3192 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/02/21 16:26:50.0858 3192 SymDS (bdf077b897b5f9f929b6bf0cfd436962) C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS 2011/02/21 16:26:51.0108 3192 SymEFA (7732298ad2eddd364c1d4f439d99ae7c) C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS 2011/02/21 16:26:51.0295 3192 SymEvent (5c76a63fac8a5580c5a1c4a4ed827782) C:\Windows\system32\Drivers\SYMEVENT.SYS 2011/02/21 16:26:51.0498 3192 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS 2011/02/21 16:26:51.0716 3192 SYMTDIv (c93e93bff7cba0cd1c1ea282d791b772) C:\Windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS 2011/02/21 16:26:51.0841 3192 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/02/21 16:26:51.0982 3192 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/02/21 16:26:52.0200 3192 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2011/02/21 16:26:52.0356 3192 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2011/02/21 16:26:52.0543 3192 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/02/21 16:26:52.0715 3192 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/02/21 16:26:52.0777 3192 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/02/21 16:26:52.0902 3192 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/02/21 16:26:53.0042 3192 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/02/21 16:26:53.0230 3192 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/02/21 16:26:53.0370 3192 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/02/21 16:26:53.0401 3192 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/02/21 16:26:53.0479 3192 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2011/02/21 16:26:53.0620 3192 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/02/21 16:26:53.0776 3192 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2011/02/21 16:26:53.0885 3192 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2011/02/21 16:26:54.0025 3192 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/02/21 16:26:54.0166 3192 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/02/21 16:26:54.0244 3192 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/02/21 16:26:54.0431 3192 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/02/21 16:26:54.0540 3192 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/02/21 16:26:54.0712 3192 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/02/21 16:26:54.0868 3192 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/02/21 16:26:54.0992 3192 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/02/21 16:26:55.0133 3192 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/02/21 16:26:55.0273 3192 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/02/21 16:26:55.0336 3192 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/02/21 16:26:55.0460 3192 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/02/21 16:26:55.0601 3192 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/02/21 16:26:55.0772 3192 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/02/21 16:26:55.0928 3192 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/02/21 16:26:56.0053 3192 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2011/02/21 16:26:56.0225 3192 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2011/02/21 16:26:56.0365 3192 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 2011/02/21 16:26:56.0537 3192 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/02/21 16:26:56.0708 3192 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/02/21 16:26:56.0849 3192 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/02/21 16:26:56.0974 3192 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2011/02/21 16:26:57.0161 3192 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/02/21 16:26:57.0239 3192 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/02/21 16:26:57.0286 3192 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/02/21 16:26:57.0457 3192 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2011/02/21 16:26:57.0551 3192 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/02/21 16:26:57.0769 3192 winachsf (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/02/21 16:26:57.0988 3192 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/02/21 16:26:58.0175 3192 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/02/21 16:26:58.0346 3192 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/02/21 16:26:58.0518 3192 XAudio (19e7c173b6242ad7521e537ae54768bf) C:\Windows\system32\DRIVERS\xaudio.sys 2011/02/21 16:26:58.0674 3192 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/02/21 16:26:58.0690 3192 ================================================================================ 2011/02/21 16:26:58.0690 3192 Scan finished 2011/02/21 16:26:58.0690 3192 ================================================================================ 2011/02/21 16:26:58.0721 3360 Detected object count: 1 2011/02/21 16:27:12.0277 3360 \HardDisk0 - will be cured after reboot 2011/02/21 16:27:12.0277 3360 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure 2011/02/21 16:27:20.0701 4572 Deinitialize success When I restarted, the program did not start by itself again so I opened it and ran another scan, here is the log 2011/02/21 16:30:44.0987 5324 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08 2011/02/21 16:30:47.0015 5324 ================================================================================ 2011/02/21 16:30:47.0015 5324 SystemInfo: 2011/02/21 16:30:47.0015 5324 2011/02/21 16:30:47.0015 5324 OS Version: 6.0.6002 ServicePack: 2.0 2011/02/21 16:30:47.0015 5324 Product type: Workstation 2011/02/21 16:30:47.0015 5324 ComputerName: HP-PC 2011/02/21 16:30:47.0015 5324 UserName: hp 2011/02/21 16:30:47.0015 5324 Windows directory: C:\Windows 2011/02/21 16:30:47.0015 5324 System windows directory: C:\Windows 2011/02/21 16:30:47.0015 5324 Processor architecture: Intel x86 2011/02/21 16:30:47.0015 5324 Number of processors: 2 2011/02/21 16:30:47.0015 5324 Page size: 0x1000 2011/02/21 16:30:47.0015 5324 Boot type: Normal boot 2011/02/21 16:30:47.0015 5324 ================================================================================ 2011/02/21 16:30:47.0701 5324 Initialize success 2011/02/21 16:30:52.0522 5364 ================================================================================ 2011/02/21 16:30:52.0522 5364 Scan started 2011/02/21 16:30:52.0522 5364 Mode: Manual; 2011/02/21 16:30:52.0522 5364 ================================================================================ 2011/02/21 16:30:53.0910 5364 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/02/21 16:30:54.0409 5364 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2011/02/21 16:30:54.0737 5364 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2011/02/21 16:30:54.0986 5364 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2011/02/21 16:30:55.0267 5364 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2011/02/21 16:30:55.0517 5364 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys 2011/02/21 16:30:55.0813 5364 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2011/02/21 16:30:56.0000 5364 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/02/21 16:30:56.0266 5364 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 2011/02/21 16:30:56.0422 5364 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2011/02/21 16:30:56.0593 5364 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 2011/02/21 16:30:56.0780 5364 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2011/02/21 16:30:57.0139 5364 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2011/02/21 16:30:57.0326 5364 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2011/02/21 16:30:57.0623 5364 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2011/02/21 16:30:57.0935 5364 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/02/21 16:30:58.0247 5364 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/02/21 16:30:58.0450 5364 athr (0437199c88f6e88a387cfec8a8886a6e) C:\Windows\system32\DRIVERS\athr.sys 2011/02/21 16:30:58.0699 5364 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/02/21 16:30:59.0276 5364 BHDrvx86 (83a2fec59a0a0fc73bf6598e901b2fbd) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys 2011/02/21 16:30:59.0963 5364 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2011/02/21 16:31:00.0322 5364 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/02/21 16:31:00.0493 5364 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/02/21 16:31:00.0680 5364 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/02/21 16:31:00.0961 5364 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/02/21 16:31:01.0258 5364 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/02/21 16:31:01.0460 5364 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/02/21 16:31:01.0679 5364 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/02/21 16:31:01.0897 5364 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/02/21 16:31:02.0131 5364 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/02/21 16:31:02.0303 5364 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2011/02/21 16:31:02.0552 5364 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/02/21 16:31:02.0740 5364 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/02/21 16:31:02.0942 5364 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 2011/02/21 16:31:03.0176 5364 CnxtHdAudService (2e39f9c51912f4f211b0334aed33e7bd) C:\Windows\system32\drivers\CHDRT32.sys 2011/02/21 16:31:03.0426 5364 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/02/21 16:31:03.0722 5364 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2011/02/21 16:31:04.0159 5364 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2011/02/21 16:31:04.0596 5364 CSC (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys 2011/02/21 16:31:05.0516 5364 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys 2011/02/21 16:31:06.0328 5364 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/02/21 16:31:06.0718 5364 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 2011/02/21 16:31:06.0936 5364 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 2011/02/21 16:31:07.0170 5364 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 2011/02/21 16:31:07.0654 5364 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/02/21 16:31:07.0919 5364 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/02/21 16:31:08.0106 5364 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/02/21 16:31:08.0543 5364 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/02/21 16:31:08.0980 5364 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/02/21 16:31:09.0338 5364 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2011/02/21 16:31:09.0728 5364 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/02/21 16:31:09.0931 5364 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/02/21 16:31:10.0103 5364 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/02/21 16:31:10.0493 5364 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2011/02/21 16:31:10.0805 5364 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/02/21 16:31:10.0961 5364 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/02/21 16:31:11.0070 5364 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/02/21 16:31:11.0382 5364 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/02/21 16:31:11.0647 5364 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/02/21 16:31:11.0866 5364 fvevol (fecf4c2e42440a8d132bf94eee3c3fc9) C:\Windows\system32\DRIVERS\fvevol.sys 2011/02/21 16:31:12.0053 5364 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2011/02/21 16:31:12.0271 5364 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/02/21 16:31:12.0521 5364 HBtnKey (88a78635b41ed4b261365fadeb28fe81) C:\Windows\system32\DRIVERS\cpqbttn.sys 2011/02/21 16:31:12.0755 5364 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/02/21 16:31:13.0114 5364 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/02/21 16:31:13.0426 5364 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/02/21 16:31:13.0816 5364 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/02/21 16:31:14.0081 5364 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/02/21 16:31:14.0377 5364 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2011/02/21 16:31:14.0705 5364 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 2011/02/21 16:31:15.0313 5364 HSF_DPV (1882827f41dee51c70e24c567c35bfb5) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/02/21 16:31:15.0500 5364 HSXHWAZL (a44ddf3ba83e4664bf4de9220097578c) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/02/21 16:31:15.0890 5364 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/02/21 16:31:16.0140 5364 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2011/02/21 16:31:16.0452 5364 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/02/21 16:31:16.0670 5364 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2011/02/21 16:31:17.0450 5364 IDSVix86 (33ca0e61eab15d439a1f592ddc020712) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110218.003\IDSvix86.sys 2011/02/21 16:31:17.0809 5364 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/02/21 16:31:18.0106 5364 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/02/21 16:31:18.0355 5364 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/02/21 16:31:18.0776 5364 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/02/21 16:31:18.0979 5364 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/02/21 16:31:19.0369 5364 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2011/02/21 16:31:19.0510 5364 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/02/21 16:31:19.0728 5364 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/02/21 16:31:19.0931 5364 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2011/02/21 16:31:20.0180 5364 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/02/21 16:31:20.0368 5364 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/02/21 16:31:20.0648 5364 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/02/21 16:31:20.0867 5364 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/02/21 16:31:21.0522 5364 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/02/21 16:31:21.0896 5364 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/02/21 16:31:22.0208 5364 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/02/21 16:31:22.0411 5364 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2011/02/21 16:31:22.0583 5364 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2011/02/21 16:31:22.0754 5364 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2011/02/21 16:31:22.0942 5364 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/02/21 16:31:23.0254 5364 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/02/21 16:31:23.0519 5364 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2011/02/21 16:31:23.0659 5364 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/02/21 16:31:23.0784 5364 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/02/21 16:31:23.0924 5364 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/02/21 16:31:24.0127 5364 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/02/21 16:31:24.0330 5364 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/02/21 16:31:24.0580 5364 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2011/02/21 16:31:24.0720 5364 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/02/21 16:31:24.0860 5364 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/02/21 16:31:25.0048 5364 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/02/21 16:31:25.0219 5364 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/02/21 16:31:25.0406 5364 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/02/21 16:31:25.0594 5364 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/02/21 16:31:25.0796 5364 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/02/21 16:31:26.0015 5364 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2011/02/21 16:31:26.0218 5364 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/02/21 16:31:26.0405 5364 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/02/21 16:31:26.0576 5364 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/02/21 16:31:26.0748 5364 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/02/21 16:31:26.0888 5364 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/02/21 16:31:27.0029 5364 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/02/21 16:31:27.0278 5364 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/02/21 16:31:27.0481 5364 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/02/21 16:31:27.0653 5364 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/02/21 16:31:27.0856 5364 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/02/21 16:31:28.0214 5364 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\NAVENG.SYS 2011/02/21 16:31:28.0651 5364 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\NAVEX15.SYS 2011/02/21 16:31:28.0948 5364 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/02/21 16:31:29.0135 5364 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/02/21 16:31:29.0369 5364 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/02/21 16:31:29.0587 5364 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/02/21 16:31:29.0743 5364 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/02/21 16:31:29.0884 5364 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/02/21 16:31:30.0180 5364 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/02/21 16:31:30.0383 5364 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/02/21 16:31:30.0570 5364 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/02/21 16:31:30.0679 5364 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/02/21 16:31:30.0757 5364 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/02/21 16:31:30.0913 5364 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/02/21 16:31:31.0085 5364 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/02/21 16:31:31.0272 5364 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 2011/02/21 16:31:31.0428 5364 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 2011/02/21 16:31:31.0693 5364 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2011/02/21 16:31:32.0442 5364 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 2011/02/21 16:31:32.0629 5364 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/02/21 16:31:32.0754 5364 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/02/21 16:31:32.0972 5364 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/02/21 16:31:33.0128 5364 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/02/21 16:31:33.0253 5364 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 2011/02/21 16:31:33.0534 5364 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/02/21 16:31:33.0721 5364 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/02/21 16:31:34.0002 5364 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/02/21 16:31:34.0142 5364 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2011/02/21 16:31:34.0408 5364 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/02/21 16:31:34.0548 5364 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2011/02/21 16:31:34.0704 5364 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/02/21 16:31:34.0907 5364 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/02/21 16:31:35.0078 5364 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/02/21 16:31:35.0250 5364 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/02/21 16:31:35.0531 5364 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/02/21 16:31:35.0749 5364 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/02/21 16:31:35.0921 5364 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/02/21 16:31:36.0077 5364 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/02/21 16:31:36.0264 5364 rdpdr (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys 2011/02/21 16:31:36.0467 5364 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/02/21 16:31:36.0794 5364 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/02/21 16:31:37.0106 5364 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys 2011/02/21 16:31:37.0309 5364 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/02/21 16:31:37.0434 5364 RTL8023xp (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys 2011/02/21 16:31:37.0668 5364 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/02/21 16:31:38.0011 5364 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/02/21 16:31:38.0245 5364 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/02/21 16:31:38.0448 5364 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/02/21 16:31:38.0604 5364 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/02/21 16:31:38.0869 5364 sffdisk (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys 2011/02/21 16:31:38.0994 5364 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2011/02/21 16:31:39.0259 5364 sffp_sd (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys 2011/02/21 16:31:39.0431 5364 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/02/21 16:31:39.0774 5364 Sftfs (cc895997c0995a07b6b2779a3b21918b) C:\Windows\system32\DRIVERS\Sftfslh.sys 2011/02/21 16:31:40.0008 5364 Sftplay (cf5e9798637795db59697f5e40fca993) C:\Windows\system32\DRIVERS\Sftplaylh.sys 2011/02/21 16:31:40.0336 5364 Sftredir (4c8076ff8938b365eeec9123969e0350) C:\Windows\system32\DRIVERS\Sftredirlh.sys 2011/02/21 16:31:40.0523 5364 Sftvol (6095a5f221eca9dada2c9ee80ec0d92d) C:\Windows\system32\DRIVERS\Sftvollh.sys 2011/02/21 16:31:40.0788 5364 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2011/02/21 16:31:41.0006 5364 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2011/02/21 16:31:41.0116 5364 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2011/02/21 16:31:41.0474 5364 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/02/21 16:31:41.0771 5364 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/02/21 16:31:42.0457 5364 SRTSP (a7a104a61c4e30de9c58f8c372a5c209) C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 2011/02/21 16:31:42.0816 5364 SRTSPX (2833445f786bd000bb14c84a9d91347a) C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 2011/02/21 16:31:43.0471 5364 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys 2011/02/21 16:31:44.0111 5364 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys 2011/02/21 16:31:44.0329 5364 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys 2011/02/21 16:31:44.0641 5364 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/02/21 16:31:44.0860 5364 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/02/21 16:31:45.0374 5364 SymDS (bdf077b897b5f9f929b6bf0cfd436962) C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS 2011/02/21 16:31:45.0749 5364 SymEFA (7732298ad2eddd364c1d4f439d99ae7c) C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS 2011/02/21 16:31:45.0967 5364 SymEvent (5c76a63fac8a5580c5a1c4a4ed827782) C:\Windows\system32\Drivers\SYMEVENT.SYS 2011/02/21 16:31:46.0279 5364 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS 2011/02/21 16:31:46.0747 5364 SYMTDIv (c93e93bff7cba0cd1c1ea282d791b772) C:\Windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS 2011/02/21 16:31:47.0044 5364 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/02/21 16:31:47.0246 5364 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/02/21 16:31:47.0558 5364 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys 2011/02/21 16:31:47.0839 5364 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys 2011/02/21 16:31:48.0120 5364 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/02/21 16:31:48.0276 5364 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/02/21 16:31:48.0541 5364 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/02/21 16:31:48.0760 5364 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/02/21 16:31:49.0025 5364 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/02/21 16:31:49.0274 5364 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/02/21 16:31:49.0446 5364 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/02/21 16:31:49.0618 5364 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/02/21 16:31:49.0774 5364 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2011/02/21 16:31:49.0961 5364 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/02/21 16:31:50.0257 5364 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2011/02/21 16:31:50.0538 5364 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2011/02/21 16:31:50.0678 5364 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/02/21 16:31:50.0866 5364 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/02/21 16:31:51.0006 5364 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/02/21 16:31:51.0193 5364 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/02/21 16:31:51.0427 5364 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/02/21 16:31:51.0661 5364 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/02/21 16:31:52.0004 5364 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/02/21 16:31:52.0238 5364 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/02/21 16:31:52.0597 5364 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2011/02/21 16:31:52.0816 5364 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 2011/02/21 16:31:52.0987 5364 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/02/21 16:31:53.0143 5364 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/02/21 16:31:53.0346 5364 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2011/02/21 16:31:53.0658 5364 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/02/21 16:31:53.0876 5364 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/02/21 16:31:54.0032 5364 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2011/02/21 16:31:54.0235 5364 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2011/02/21 16:31:54.0407 5364 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 2011/02/21 16:31:54.0578 5364 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/02/21 16:31:54.0937 5364 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/02/21 16:31:55.0218 5364 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/02/21 16:31:55.0452 5364 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2011/02/21 16:31:55.0639 5364 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/02/21 16:31:55.0764 5364 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/02/21 16:31:55.0795 5364 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/02/21 16:31:56.0014 5364 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2011/02/21 16:31:56.0606 5364 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/02/21 16:31:57.0418 5364 winachsf (e096ffb754f1e45ae1bddac1275ae2c5) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/02/21 16:31:57.0667 5364 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/02/21 16:31:57.0948 5364 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/02/21 16:31:58.0338 5364 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/02/21 16:31:58.0666 5364 XAudio (19e7c173b6242ad7521e537ae54768bf) C:\Windows\system32\DRIVERS\xaudio.sys 2011/02/21 16:31:58.0775 5364 ================================================================================ 2011/02/21 16:31:58.0775 5364 Scan finished 2011/02/21 16:31:58.0775 5364 ================================================================================
OTL logfile created on: 2/21/2011 4:37:53 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\hp\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 158.14 Gb Free Space | 67.91% Space Free | Partition Type: NTFS

Computer Name: HP-PC | User Name: hp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\navex15.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110220.002\naveng.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110218.003\IDSvix86.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba.aol.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 5F 48 8E FD A4 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/02/21 16:16:16 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O24 - Desktop BackupWallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\AutoRun\command - "" = System\DriveGuard\DriveProtect.exe -run 
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Explore\Command - "" = System\DriveGuard\DriveProtect.exe -run  
O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Open\Command - "" = System\DriveGuard\DriveProtect.exe -run 
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\AutoRun\command - "" = D:\hbcd\wintools\autorun.exe
O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\Option1\Command - "" = D:\hbcd\wintools\autorun.exe
O33 - MountPoints2\{283e29ed-ca25-11de-9d20-001eec767838}\Shell\AutoRun\command - "" = F:\wt.BAT
O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell - "" = AutoRun
O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell\AutoRun\command - "" = G:\HPLauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.vp60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/02/21 16:35:46 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:25:57 | 001,372,248 | —- | C] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 20:31:29 | 000,652,336 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.sys
[2011/02/20 20:31:29 | 000,509,560 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.sys
[2011/02/20 20:31:29 | 000,340,016 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symds.sys
[2011/02/20 20:31:29 | 000,330,360 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symtdiv.sys
[2011/02/20 20:31:29 | 000,295,032 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symnets.sys
[2011/02/20 20:31:29 | 000,136,312 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\ironx86.sys
[2011/02/20 20:31:29 | 000,050,168 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.sys
[2011/02/20 20:31:08 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV\1205000.07D
[2011/02/20 19:24:35 | 000,126,512 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/02/20 19:23:22 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV
[2011/02/20 19:23:16 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/02/20 19:23:16 | 000,000,000 | —D | C] – C:\Program Files\Norton AntiVirus
[2011/02/20 19:23:14 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/02/16 18:34:34 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/02/16 18:34:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/16 18:34:29 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/02/16 18:34:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 13:07:00 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/02/09 16:40:26 | 002,039,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 16:40:01 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 16:40:00 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 16:39:51 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/02/09 16:39:51 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/02/09 16:39:51 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2011/02/09 16:39:50 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/02/09 16:39:50 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/02/09 16:39:49 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/02/09 16:39:49 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/09 16:39:49 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/09 16:39:49 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/02/09 16:39:48 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/02/09 16:39:47 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/02/09 16:39:47 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/02/09 16:39:47 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/02/09 16:39:47 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/02/09 16:39:46 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/02/09 16:39:46 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/02/09 16:39:46 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/02/09 16:39:46 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/02/09 16:39:45 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/02/09 16:39:45 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/02/09 16:39:44 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/02/09 16:39:44 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/02/09 16:39:42 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/02/09 16:39:41 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/02/09 16:39:41 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/02/09 16:38:57 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/02/09 16:38:57 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 16:38:56 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 16:38:56 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 16:38:56 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 16:38:56 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 16:38:56 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/02/09 16:38:56 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/02/09 16:38:56 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/02/09 16:38:56 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/02/09 16:38:56 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/02/09 16:38:55 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 16:38:55 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/02/09 16:38:55 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 16:38:55 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 16:38:55 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/02/09 16:38:55 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 16:38:44 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 16:38:44 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/02/07 17:32:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2011/02/07 17:32:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2011/02/07 17:32:15 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2011/02/07 17:30:32 | 000,118,272 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\hpz3l5mu.dll
[2011/02/07 17:30:02 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2011/02/07 17:20:30 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2011/02/07 17:20:26 | 000,271,704 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpzids01.dll
[2011/02/07 17:20:25 | 000,729,088 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpowiax7.dll
[2011/02/07 17:20:25 | 000,372,736 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hppldcoi.dll
[2011/02/07 17:20:24 | 000,581,632 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpotscl6.dll
[2011/02/07 17:20:24 | 000,303,104 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpovst15.dll
[2011/02/07 17:08:26 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/02/07 17:07:48 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/01/31 15:45:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/01/31 15:44:46 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/01/31 15:44:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/01/23 12:57:59 | 000,000,000 | —D | C] – C:\Users\hp\Documents\tv

========== Files - Modified Within 30 Days ==========

[2011/08/16 20:28:06 | 000,022,683 | —- | M] () – C:\Users\hp\Documents\grey.jpg
[2011/02/21 16:36:35 | 000,611,992 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/21 16:36:35 | 000,107,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/21 16:36:12 | 000,035,064 | —- | M] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:35:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:29:29 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 16:29:29 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/21 16:29:21 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/21 16:29:15 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2011/02/21 16:25:44 | 001,257,772 | —- | M] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:14:00 | 002,081,958 | —- | M] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/21 16:13:59 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 21:24:39 | 000,000,036 | —- | M] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 21:06:41 | 000,175,616 | —- | M] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/20 19:38:10 | 334,104,196 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/02/20 19:24:30 | 000,126,512 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:30 | 000,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/20 17:42:29 | 000,000,412 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job
[2011/02/16 20:51:35 | 000,062,432 | —- | M] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:34 | 000,062,925 | —- | M] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 18:34:34 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/13 19:23:37 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/02/10 12:04:24 | 000,374,680 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 17:37:12 | 000,017,447 | —- | M] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 17:35:59 | 000,163,142 | —- | M] () – C:\Windows\hpoins28.dat
[2011/02/07 11:38:55 | 000,043,812 | —- | M] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:02:06 | 731,430,913 | —- | M] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk

========== Files Created - No Company Name ==========

[2011/02/21 16:36:11 | 000,035,064 | —- | C] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:25:38 | 001,257,772 | —- | C] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:12:45 | 002,081,958 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/20 21:24:39 | 000,000,036 | —- | C] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 20:31:29 | 000,007,877 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.cat
[2011/02/20 20:31:29 | 000,007,528 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.cat
[2011/02/20 20:31:29 | 000,007,458 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.cat
[2011/02/20 20:31:29 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.cat
[2011/02/20 20:31:29 | 000,007,454 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.cat
[2011/02/20 20:31:29 | 000,003,374 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.inf
[2011/02/20 20:31:29 | 000,002,792 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.inf
[2011/02/20 20:31:29 | 000,001,474 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.inf
[2011/02/20 20:31:29 | 000,001,446 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.inf
[2011/02/20 20:31:29 | 000,001,389 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.inf
[2011/02/20 20:31:29 | 000,001,383 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.inf
[2011/02/20 20:31:29 | 000,000,742 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.inf
[2011/02/20 20:31:08 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\isolate.ini
[2011/02/20 19:24:35 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:35 | 000,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/20 19:24:09 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/16 20:51:34 | 000,062,432 | —- | C] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:30 | 000,062,925 | —- | C] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 20:28:53 | 000,022,683 | —- | C] () – C:\Users\hp\Documents\grey.jpg
[2011/02/16 18:34:34 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 13:06:27 | 334,104,196 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/02/07 17:20:33 | 000,000,355 | —- | C] () – C:\ProgramData\hpzinstall.log
[2011/02/07 17:20:32 | 000,163,142 | —- | C] () – C:\Windows\hpoins28.dat
[2011/02/07 17:20:32 | 000,000,796 | —- | C] () – C:\Windows\hpomdl28.dat
[2011/02/07 13:34:16 | 000,017,447 | —- | C] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 11:38:53 | 000,043,812 | —- | C] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:01:32 | 731,430,913 | —- | C] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/03 16:08:03 | 000,000,161 | —- | C] () – C:\Windows\AutoKMS.ini
[2010/10/11 12:03:21 | 000,000,065 | —- | C] () – C:\Windows\DIPLOMA.INI
[2010/10/11 12:03:21 | 000,000,047 | —- | C] () – C:\Windows\BRGVARS.INI
[2010/10/11 12:03:20 | 000,000,023 | —- | C] () – C:\Windows\VBCTL3D.INI
[2010/09/26 22:21:53 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/18 23:32:56 | 000,175,616 | —- | C] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/18 22:06:11 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2010/09/12 22:36:09 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2010/05/24 14:33:00 | 004,670,829 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | —- | C] () – C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,336,384 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | —- | C] () – C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | —- | C] () – C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | —- | C] () – C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | —- | C] () – C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | —- | C] () – C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | —- | C] () – C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | —- | C] () – C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | —- | C] () – C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\QSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\DSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\AtStart.txt
[2009/11/05 10:52:39 | 000,000,680 | —- | C] () – C:\Users\hp\AppData\Local\d3d9caps.dat
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2008/11/06 10:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/02/11 19:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/08/20 23:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 23:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 07:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2011/02/21 16:27:27 | 000,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/20 17:42:29 | 000,000,412 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/11/05 12:19:25 | 000,000,086 | —- | M] () – C:\bcmwl6.log
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/11/05 10:43:05 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/04/14 22:51:45 | 000,171,136 | RHS- | M] () – C:\grldr
[2011/02/21 16:29:15 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2011/02/21 16:29:14 | 3524,546,560 | -HS- | M] () – C:\pagefile.sys
[2011/02/21 16:27:20 | 000,064,340 | —- | M] () – C:\TDSSKiller.2.4.18.0_21.02.2011_16.26.07_log.txt
[2011/02/21 16:36:17 | 000,063,734 | —- | M] () – C:\TDSSKiller.2.4.18.0_21.02.2011_16.30.44_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 07:35:26 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:35:26 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:35:26 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/10/11 12:22:13 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 07:34:09 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/09/26 21:42:16 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/26 22:50:02 | 000,000,286 | -HS- | M] () – C:\Users\hp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/02/21 16:35:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2006/11/02 07:33:56 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/11/05 10:52:53 | 000,000,402 | -HS- | M] () – C:\Users\hp\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/02/07 17:36:00 | 000,000,355 | —- | M] () – C:\ProgramData\hpzinstall.log

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-10 16:00:43

< End of report >
OTL Extras logfile created on: 2/21/2011 4:37:53 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\hp\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 158.14 Gb Free Space | 67.91% Space Free | Partition Type: NTFS

Computer Name: HP-PC | User Name: hp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2302B15E-F015-49B4-BC7F-5396AF6642EB}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{54293828-8AA1-436A-BA4C-89DF9630C7B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8515AB70-C4B7-4043-A161-E75D82053348}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{865319C2-AF70-4A21-8B63-B5CBDC470257}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EBFD163E-DF81-4170-AAE2-FBE681DBF81C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6C4FA24E-3BB0-4DE6-AD3D-D200B750B1E4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{7EAD890B-808E-45D4-8E0E-629405A60EE4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A55EB598-BF11-4D7D-AA6C-F407DED2D93E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B7792545-2B4C-40D3-A5E8-E4564BF80808}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{C4957F1A-52C9-4FA2-BBD8-29AE568BF37A}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{CA4F766D-A3BC-4442-B308-B4043C38E4B8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4651981-3060-4111-94C1-719A0953E9A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FBAD3D45-4F8E-4CAF-847D-B2EFFF202EA6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FE123324-F6A9-4FC8-B677-906505A9A79D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"TCP Query User{0D32CE96-2B9A-4911-BC05-8BD33E867FEF}C:\windows\kmsemulator.exe" = protocol=6 | dir=in | app=c:\windows\kmsemulator.exe |
"TCP Query User{2CB916FB-32FD-4844-82C7-590C9932A963}C:\program files\usmle\2011fredv2step1\ned.exe" = protocol=6 | dir=in | app=c:\program files\usmle\2011fredv2step1\ned.exe |
"TCP Query User{F5E83074-8CC8-4765-896F-EDA7952E4C1D}C:\program files\usmle\2011fredv2step1\fredv2orient.exe" = protocol=6 | dir=in | app=c:\program files\usmle\2011fredv2step1\fredv2orient.exe |
"TCP Query User{F8F10AC3-C22B-4018-B720-C8BC7C31E1FC}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{07981CFC-F825-4304-AB9E-CD918EEB4A73}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{86590688-72B6-4562-9C31-4E6054E0F4FC}C:\program files\usmle\2011fredv2step1\ned.exe" = protocol=17 | dir=in | app=c:\program files\usmle\2011fredv2step1\ned.exe |
"UDP Query User{8B7AED81-A363-4916-8E70-DF4043390B18}C:\windows\kmsemulator.exe" = protocol=17 | dir=in | app=c:\windows\kmsemulator.exe |
"UDP Query User{DF9555DE-9905-4AC1-A8B2-E4E6DD318296}C:\program files\usmle\2011fredv2step1\fredv2orient.exe" = protocol=17 | dir=in | app=c:\program files\usmle\2011fredv2step1\fredv2orient.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 23
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{BE8A9C2C-8E41-445B-A746-BEB0B1F992F8}" = DJ_AIO_03_F4200_Software_Min
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C3B6AEB1-390C-4792-8677-CD87F8B2C959}" = HP Deskjet F4200 All-In-One Driver 11.0 03
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EA50F6E4-8542-4B2B-B344-D080D5DA0EB1}" = BlackBerry Device Software Updater
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"DivX Setup.divx.com" = DivX Setup
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HDMI" = Intel® Graphics Media Accelerator Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NAV" = Norton AntiVirus
"NMS Review for the USMLE Step 1, 6th Ed. with Tutor Testing Software" = NMS Review for the USMLE Step 1, 6th Ed. with Tutor Testing Software
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"TVWiz" = Intel® TV Wizard
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/16/2011 9:43:24 PM | Computer Name = hp-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19019 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 122c Start Time: 01cbce43e3266eb1 Termination Time: 0

Error - 2/17/2011 10:41:59 AM | Computer Name = hp-PC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 6.0.6001.18000, time stamp
0x47918b89, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436,
exception code 0xc000071b, fault offset 0x00088d15, process id 0x4a4, application
start time 0x01cbceadfe2c865e.

Error - 2/18/2011 1:30:46 AM | Computer Name = hp-PC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 6.0.6001.18000, time stamp
0x47918b89, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436,
exception code 0xc000071b, fault offset 0x00088d15, process id 0x488, application
start time 0x01cbcf21c7d4313a.

Error - 2/20/2011 8:31:52 PM | Computer Name = hp-PC | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 6.0.6001.18000, time stamp
0x47918b89, faulting module AcroPDF.dll_unloaded, version 0.0.0.0, time stamp 0x4d457c83,
exception code 0xc0000005, fault offset 0x7360e583, process id 0x484, application
start time 0x01cbd14eb3afa493.

Error - 2/20/2011 9:38:17 PM | Computer Name = hp-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19019 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14e8 Start Time: 01cbd167ec3fa2b6 Termination Time: 0

Error - 2/20/2011 9:39:21 PM | Computer Name = hp-PC | Source = VSS | ID = 8194
Description =

Error - 2/20/2011 9:39:40 PM | Computer Name = hp-PC | Source = SPP | ID = 16387
Description =

Error - 2/20/2011 9:39:40 PM | Computer Name = hp-PC | Source = System Restore | ID = 8193
Description =

Error - 2/20/2011 10:03:26 PM | Computer Name = hp-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.19019 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1778 Start Time: 01cbd16834fc4586 Termination Time: 0

Error - 2/21/2011 5:15:32 PM | Computer Name = hp-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19019, time stamp
0x4d0c3d4c, faulting module Scxpx86.dll, version 9.2.2.4, time stamp 0x4c180bc2,
exception code 0xc0000005, fault offset 0x00046568, process id 0xe6c, application
start time 0x01cbd20c650e0810.

[ System Events ]
Error - 2/17/2011 10:44:23 AM | Computer Name = hp-PC | Source = DCOM | ID = 10010
Description =

Error - 2/17/2011 11:06:32 AM | Computer Name = hp-PC | Source = DCOM | ID = 10005
Description =

Error - 2/17/2011 11:27:52 AM | Computer Name = hp-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort2.

Error - 2/17/2011 11:28:16 AM | Computer Name = hp-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:26:28 AM on 2/17/2011 was unexpected.

Error - 2/18/2011 12:10:08 AM | Computer Name = hp-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort2.

Error - 2/18/2011 1:33:01 AM | Computer Name = hp-PC | Source = DCOM | ID = 10010
Description =

Error - 2/20/2011 6:36:40 PM | Computer Name = hp-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort2.

Error - 2/20/2011 8:37:50 PM | Computer Name = hp-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort2.

Error - 2/20/2011 8:38:24 PM | Computer Name = hp-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:34:57 PM on 2/20/2011 was unexpected.

Error - 2/21/2011 5:12:38 PM | Computer Name = hp-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort2.


< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\AutoRun\command - "" = System\DriveGuard\DriveProtect.exe -run 
    O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Explore\Command - "" = System\DriveGuard\DriveProtect.exe -run  
    O33 - MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\Shell\Open\Command - "" = System\DriveGuard\DriveProtect.exe -run 
    O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\AutoRun\command - "" = D:\hbcd\wintools\autorun.exe
    O33 - MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\Shell\Option1\Command - "" = D:\hbcd\wintools\autorun.exe
    O33 - MountPoints2\{283e29ed-ca25-11de-9d20-001eec767838}\Shell\AutoRun\command - "" = F:\wt.BAT
    O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell - "" = AutoRun
    O33 - MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\Shell\AutoRun\command - "" = G:\HPLauncher.exe
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )










Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
OTL log: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ not found. File System\DriveGuard\DriveProtect.exe -run not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ not found. File System\DriveGuard\DriveProtect.exe -run not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04ab7b3c-ea9d-11df-81d4-001eec87380e}\ not found. File System\DriveGuard\DriveProtect.exe -run not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ not found. File D:\hbcd\wintools\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0b1568ee-ca22-11de-8d60-806e6f6e6963}\ not found. File D:\hbcd\wintools\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{283e29ed-ca25-11de-9d20-001eec767838}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{283e29ed-ca25-11de-9d20-001eec767838}\ not found. File F:\wt.BAT not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7f778b13-f724-11df-bdae-001eec87380e}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7f778b13-f724-11df-bdae-001eec87380e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7f778b13-f724-11df-bdae-001eec87380e}\ not found. File G:\HPLauncher.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: hp ->Temp folder emptied: 361134827 bytes ->Temporary Internet Files folder emptied: 1137993366 bytes ->Java cache emptied: 1411601 bytes ->Flash cache emptied: 97633 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 21407397 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,452.00 mb OTL by OldTimer - Version 3.2.20.6 log created on 02222011_130432 Files\Folders moved on Reboot… File\Folder C:\Users\hp\AppData\Local\Temp\~DF3D72.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DF3D8F.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DF3DA4.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DF3DBA.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DF3E3C.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DF3EF2.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAE22.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAE2E.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAE75.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAE7C.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAEAF.tmp not found! File\Folder C:\Users\hp\AppData\Local\Temp\~DFAEB6.tmp not found! C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HWOQFV5S\iframe[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HWOQFV5S\iframe[2].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HWOQFV5S\like[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AWHTQZRH\findByTrackNumber[2].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\AWHTQZRH\iframe[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7HDMHCGP\iframe[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\64BQR85N\iframe[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\64BQR85N\iframe[2].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\64BQR85N\iframe[3].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\64BQR85N\index[1].htm moved successfully. C:\Users\hp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
combofix log

ComboFix 11-02-21.02 - hp 02/22/2011 13:21:35.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3061.1829 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Norton AntiVirus *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\XSxS

.
((((((((((((((((((((((((( Files Created from 2011-01-22 to 2011-02-22 )))))))))))))))))))))))))))))))
.

2011-02-22 18:27 . 2011-02-22 18:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-02-22 18:04 . 2011-02-22 18:04 ——– d—–w- C:\_OTL
2011-02-21 00:24 . 2011-02-21 00:24 126512 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-21 00:24 . 2011-02-21 00:31 ——– d—–w- c:\program files\Common Files\Symantec Shared
2011-02-21 00:24 . 2011-02-21 00:24 ——– d—–w- c:\program files\Symantec
2011-02-21 00:23 . 2011-02-21 21:16 ——– d—–w- c:\windows\system32\drivers\NAV
2011-02-21 00:23 . 2011-02-21 00:23 ——– d—–w- c:\program files\Norton AntiVirus
2011-02-21 00:23 . 2011-02-21 00:27 ——– d—–w- c:\programdata\Norton
2011-02-21 00:23 . 2011-02-21 00:23 ——– d—–w- c:\program files\NortonInstaller
2011-02-16 23:34 . 2010-12-20 23:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-16 23:34 . 2011-02-16 23:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-16 23:34 . 2010-12-20 23:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-09 21:40 . 2010-12-31 13:57 2039808 —-a-w- c:\windows\system32\win32k.sys
2011-02-09 21:40 . 2010-10-15 14:08 3602320 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-09 21:40 . 2010-10-15 13:48 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-02-09 21:40 . 2010-10-15 14:08 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-09 21:30 . 2011-01-13 09:41 5890896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E92ADB5D-F608-43E9-8188-6B5AEFE1CFDD}\mpengine.dll
2011-02-07 22:32 . 2011-02-07 22:32 ——– d—–w- c:\program files\Common Files\HP
2011-02-07 22:32 . 2011-02-07 22:32 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2011-02-07 22:32 . 2011-02-07 22:32 ——– d—–w- c:\programdata\Hewlett-Packard
2011-02-07 22:32 . 2007-10-20 23:21 278016 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2011-02-07 22:30 . 2007-10-20 23:25 118272 —-a-w- c:\windows\system32\hpz3l5mu.dll
2011-02-07 22:20 . 2011-02-07 22:20 ——– d—–w- c:\programdata\HP
2011-02-07 22:20 . 2008-01-25 12:23 271704 —-a-w- c:\windows\system32\hpzids01.dll
2011-02-07 22:20 . 2008-01-25 12:22 729088 —-a-w- c:\windows\system32\hpowiax7.dll
2011-02-07 22:20 . 2008-01-25 12:22 372736 —-a-w- c:\windows\system32\hppldcoi.dll
2011-02-07 22:20 . 2008-01-25 12:22 303104 —-a-w- c:\windows\system32\hpovst15.dll
2011-02-07 22:20 . 2008-01-25 12:22 581632 —-a-w- c:\windows\system32\hpotscl6.dll
2011-02-07 22:08 . 2011-02-07 22:30 ——– d—–w- c:\program files\HP
2011-02-07 22:07 . 2011-02-07 22:07 ——– d—–w- c:\windows\Downloaded Installations
2011-01-31 20:44 . 2011-01-31 20:44 ——– d—–w- c:\program files\iPod
2011-01-31 20:44 . 2011-01-31 20:45 ——– d—–w- c:\program files\iTunes
2011-01-30 15:45 . 2011-01-30 15:45 135568 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-28 15:55 . 2011-01-12 19:38 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-14 14:49 . 2011-01-12 19:38 1169408 —-a-w- c:\windows\system32\sdclt.exe
2010-11-29 22:38 . 2010-11-29 22:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38 . 2010-11-29 22:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-02 202032]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 20:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS [2010-10-21 340016]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS [2010-11-18 652336]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys [2010-11-23 691248]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110218.003\IDSvix86.sys [2010-11-09 353912]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS [2010-11-16 136312]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS [2010-12-01 330360]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe [2010-11-24 130000]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-08-13 102448]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2010-04-24 550760]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2010-04-24 195944]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2010-04-24 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2010-04-24 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2011-02-21 c:\windows\Tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job
- c:\windows\system32\msfeedssync.exe [2011-02-09 04:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://toshiba.aol.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-22 13:28
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\18.5.0.125\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-02-22 13:30:44
ComboFix-quarantined-files.txt 2011-02-22 18:30

Pre-Run: 166,766,366,720 bytes free
Post-Run: 166,696,640,512 bytes free

- - End Of File - - 176FD132E883B8AD8E1C60A82D34C50B
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5848 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19019 2/22/2011 8:48:59 PM mbam-log-2011-02-22 (20-48-59).txt Scan type: Quick scan Objects scanned: 148159 Time elapsed: 5 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
i ran an OTL scan under default settings. I am no longer recieving notifications from norton as i was before. but internet explorer stops responding every now and then.

here is the OTL log

OTL logfile created on: 2/23/2011 11:54:13 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\hp\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 156.84 Gb Free Space | 67.35% Space Free | Partition Type: NTFS

Computer Name: HP-PC | User Name: hp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\hp\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe (Symantec Corporation)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110223.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110223.002\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\NAV\1205000.07D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\NAV\1205000.07D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\NAV\1205000.07D\SRTSPX.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110114.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\NAV\1205000.07D\Ironx86.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110221.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\NAV\1205000.07D\SYMDS.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://toshiba.aol.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1D 5F 48 8E FD A4 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/02/21 16:16:16 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.5.0.125\ips\ipsbho.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O24 - Desktop BackupWallPaper: C:\Users\hp\Pictures\wallpaper2 copy.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/22 20:51:48 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/22 18:01:46 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2011/02/22 17:59:18 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2011/02/22 17:59:11 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2011/02/22 17:59:11 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2011/02/22 17:59:11 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2011/02/22 17:59:09 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2011/02/22 17:59:09 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2011/02/22 17:59:09 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2011/02/22 17:59:09 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2011/02/22 17:59:09 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2011/02/22 17:59:09 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2011/02/22 17:59:08 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2011/02/22 17:59:02 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2011/02/22 17:59:02 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2011/02/22 17:59:02 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2011/02/22 17:59:02 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2011/02/22 17:59:02 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2011/02/22 13:31:19 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/02/22 13:30:07 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/02/22 13:18:53 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/02/22 13:18:53 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/02/22 13:18:53 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/02/22 13:18:07 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2011/02/22 13:17:41 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/02/22 13:16:37 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/22 13:04:32 | 000,000,000 | —D | C] – C:\_OTL
[2011/02/21 16:35:46 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:25:57 | 001,372,248 | —- | C] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 20:31:29 | 000,652,336 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.sys
[2011/02/20 20:31:29 | 000,509,560 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.sys
[2011/02/20 20:31:29 | 000,340,016 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symds.sys
[2011/02/20 20:31:29 | 000,330,360 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symtdiv.sys
[2011/02/20 20:31:29 | 000,295,032 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\symnets.sys
[2011/02/20 20:31:29 | 000,136,312 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\ironx86.sys
[2011/02/20 20:31:29 | 000,050,168 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.sys
[2011/02/20 20:31:08 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV\1205000.07D
[2011/02/20 19:24:35 | 000,126,512 | —- | C] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/02/20 19:24:30 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/02/20 19:23:22 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\NAV
[2011/02/20 19:23:16 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton AntiVirus
[2011/02/20 19:23:16 | 000,000,000 | —D | C] – C:\Program Files\Norton AntiVirus
[2011/02/20 19:23:14 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2011/02/20 19:23:00 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/02/16 18:34:34 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/02/16 18:34:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/16 18:34:29 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/02/16 18:34:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 13:07:00 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/02/09 16:40:26 | 002,039,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/02/09 16:40:01 | 003,602,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/02/09 16:40:00 | 003,550,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/02/09 16:39:51 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2011/02/09 16:39:51 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/02/09 16:39:51 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FntCache.dll
[2011/02/09 16:39:50 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFH264Dec.dll
[2011/02/09 16:39:50 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/02/09 16:39:49 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpsservices.dll
[2011/02/09 16:39:49 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/02/09 16:39:49 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/02/09 16:39:49 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2011/02/09 16:39:48 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFHEAACdec.dll
[2011/02/09 16:39:47 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OpcServices.dll
[2011/02/09 16:39:47 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2011/02/09 16:39:47 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfmp4src.dll
[2011/02/09 16:39:47 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2011/02/09 16:39:46 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2011/02/09 16:39:46 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2011/02/09 16:39:46 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2011/02/09 16:39:46 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/02/09 16:39:45 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2011/02/09 16:39:45 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2011/02/09 16:39:44 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2011/02/09 16:39:44 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2011/02/09 16:39:42 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2011/02/09 16:39:41 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2011/02/09 16:39:41 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2011/02/09 16:38:57 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/02/09 16:38:57 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/02/09 16:38:56 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/02/09 16:38:56 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/02/09 16:38:56 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/02/09 16:38:56 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/02/09 16:38:56 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/02/09 16:38:56 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/02/09 16:38:56 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/02/09 16:38:56 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/02/09 16:38:56 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/02/09 16:38:55 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/02/09 16:38:55 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/02/09 16:38:55 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/02/09 16:38:55 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/02/09 16:38:55 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/02/09 16:38:55 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/02/09 16:38:44 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2011/02/09 16:38:44 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2011/02/07 17:32:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2011/02/07 17:32:43 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2011/02/07 17:32:15 | 000,000,000 | —D | C] – C:\ProgramData\Hewlett-Packard
[2011/02/07 17:30:32 | 000,118,272 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\hpz3l5mu.dll
[2011/02/07 17:30:02 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/02/07 17:20:30 | 000,000,000 | —D | C] – C:\ProgramData\HP
[2011/02/07 17:20:26 | 000,271,704 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpzids01.dll
[2011/02/07 17:20:25 | 000,729,088 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hpowiax7.dll
[2011/02/07 17:20:25 | 000,372,736 | —- | C] (Hewlett-Packard) – C:\Windows\System32\hppldcoi.dll
[2011/02/07 17:20:24 | 000,581,632 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpotscl6.dll
[2011/02/07 17:20:24 | 000,303,104 | —- | C] (Hewlett-Packard Co.) – C:\Windows\System32\hpovst15.dll
[2011/02/07 17:08:26 | 000,000,000 | —D | C] – C:\Program Files\HP
[2011/02/07 17:07:48 | 000,000,000 | —D | C] – C:\Windows\Downloaded Installations
[2011/01/31 15:45:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/01/31 15:44:46 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/01/31 15:44:44 | 000,000,000 | —D | C] – C:\Program Files\iTunes

========== Files - Modified Within 30 Days ==========

[2011/08/16 20:28:06 | 000,022,683 | —- | M] () – C:\Users\hp\Documents\grey.jpg
[2011/02/23 11:16:44 | 000,611,992 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/23 11:16:44 | 000,107,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/23 11:09:21 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/23 11:09:20 | 000,003,648 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/23 11:09:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/23 11:09:06 | 3210,756,096 | -HS- | M] () – C:\hiberfil.sys
[2011/02/22 20:09:36 | 000,000,412 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{AA33D315-A20A-4FC4-B90C-F28A545631BA}.job
[2011/02/22 18:01:11 | 002,093,526 | —- | M] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/22 13:17:58 | 004,272,549 | R— | M] () – C:\Users\hp\Desktop\ComboFix.exe
[2011/02/21 16:36:12 | 000,035,064 | —- | M] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:35:52 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\hp\Desktop\OTL.exe
[2011/02/21 16:25:44 | 001,257,772 | —- | M] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:13:59 | 000,002,136 | —- | M] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – C:\Users\hp\Desktop\TDSSKiller.exe
[2011/02/20 21:24:39 | 000,000,036 | —- | M] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 21:06:41 | 000,175,616 | —- | M] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/20 19:38:10 | 334,104,196 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/02/20 19:24:30 | 000,126,512 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2011/02/20 19:24:30 | 000,007,456 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:30 | 000,000,805 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/16 20:51:35 | 000,062,432 | —- | M] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:34 | 000,062,925 | —- | M] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 18:34:34 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/13 19:23:37 | 000,001,892 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/02/10 12:04:24 | 000,374,680 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 17:37:12 | 000,017,447 | —- | M] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 17:35:59 | 000,163,142 | —- | M] () – C:\Windows\hpoins28.dat
[2011/02/07 11:38:55 | 000,043,812 | —- | M] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:02:06 | 731,430,913 | —- | M] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk

========== Files Created - No Company Name ==========

[2011/02/22 17:59:03 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2011/02/22 17:59:03 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2011/02/22 17:59:03 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2011/02/22 13:18:53 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/02/22 13:18:53 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/02/22 13:18:53 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/02/22 13:18:53 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/02/22 13:18:53 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/02/22 13:13:51 | 004,272,549 | R— | C] () – C:\Users\hp\Desktop\ComboFix.exe
[2011/02/21 16:36:11 | 000,035,064 | —- | C] () – C:\Users\hp\Documents\Hello Mowman.docx
[2011/02/21 16:25:38 | 001,257,772 | —- | C] () – C:\Users\hp\Desktop\tdsskiller.zip
[2011/02/21 16:12:45 | 002,093,526 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\Cat.DB
[2011/02/20 21:24:39 | 000,000,036 | —- | C] () – C:\Users\hp\AppData\Local\housecall.guid.cache
[2011/02/20 20:31:29 | 000,007,877 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.cat
[2011/02/20 20:31:29 | 000,007,528 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.cat
[2011/02/20 20:31:29 | 000,007,458 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.cat
[2011/02/20 20:31:29 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.cat
[2011/02/20 20:31:29 | 000,007,454 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.cat
[2011/02/20 20:31:29 | 000,007,450 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.cat
[2011/02/20 20:31:29 | 000,003,374 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symefa.inf
[2011/02/20 20:31:29 | 000,002,792 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symds.inf
[2011/02/20 20:31:29 | 000,001,474 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnetv.inf
[2011/02/20 20:31:29 | 000,001,446 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\symnet.inf
[2011/02/20 20:31:29 | 000,001,389 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtspx.inf
[2011/02/20 20:31:29 | 000,001,383 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\srtsp.inf
[2011/02/20 20:31:29 | 000,000,742 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\iron.inf
[2011/02/20 20:31:08 | 000,000,172 | —- | C] () – C:\Windows\System32\drivers\NAV\1205000.07D\isolate.ini
[2011/02/20 19:24:35 | 000,007,456 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2011/02/20 19:24:35 | 000,000,805 | —- | C] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2011/02/20 19:24:09 | 000,002,136 | —- | C] () – C:\Users\Public\Desktop\Norton AntiVirus.lnk
[2011/02/16 20:51:34 | 000,062,432 | —- | C] () – C:\Users\hp\Documents\myreport khan.pdf
[2011/02/16 20:49:30 | 000,062,925 | —- | C] () – C:\Users\hp\Documents\myreport hunain.pdf
[2011/02/16 20:28:53 | 000,022,683 | —- | C] () – C:\Users\hp\Documents\grey.jpg
[2011/02/16 18:34:34 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 13:06:27 | 334,104,196 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/02/07 17:20:33 | 000,000,355 | —- | C] () – C:\ProgramData\hpzinstall.log
[2011/02/07 17:20:32 | 000,163,142 | —- | C] () – C:\Windows\hpoins28.dat
[2011/02/07 17:20:32 | 000,000,796 | —- | C] () – C:\Windows\hpomdl28.dat
[2011/02/07 13:34:16 | 000,017,447 | —- | C] () – C:\Users\hp\Documents\hunain CV.docx
[2011/02/07 11:38:53 | 000,043,812 | —- | C] () – C:\Users\hp\Documents\myreport.PDF
[2011/02/05 00:01:32 | 731,430,913 | —- | C] () – C:\Users\hp\Documents\the hangover.avi
[2011/01/31 15:45:47 | 000,001,664 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/03 16:08:03 | 000,000,161 | —- | C] () – C:\Windows\AutoKMS.ini
[2010/10/11 12:03:21 | 000,000,065 | —- | C] () – C:\Windows\DIPLOMA.INI
[2010/10/11 12:03:21 | 000,000,047 | —- | C] () – C:\Windows\BRGVARS.INI
[2010/10/11 12:03:20 | 000,000,023 | —- | C] () – C:\Windows\VBCTL3D.INI
[2010/09/26 22:21:53 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/09/18 23:32:56 | 000,175,616 | —- | C] () – C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/18 22:06:11 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2010/09/12 22:36:09 | 000,140,288 | —- | C] () – C:\Windows\System32\igfxtvcx.dll
[2010/05/24 14:33:00 | 004,670,829 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | —- | C] () – C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,336,384 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | —- | C] () – C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | —- | C] () – C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | —- | C] () – C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | —- | C] () – C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | —- | C] () – C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | —- | C] () – C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | —- | C] () – C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | —- | C] () – C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\QSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\DSwitch.txt
[2009/11/05 11:18:32 | 000,000,000 | —- | C] () – C:\Users\hp\AppData\Local\AtStart.txt
[2009/11/05 10:52:39 | 000,000,680 | —- | C] () – C:\Users\hp\AppData\Local\d3d9caps.dat
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2008/11/06 10:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/02/11 19:55:18 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1437.dll
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/08/20 23:34:08 | 000,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1318.dll
[2007/08/20 23:25:00 | 000,910,720 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2006/11/02 07:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

< End of report >
You could try resetting IE to see if that helps as i can see no more signs of malware in your logs http://support.microsoft.com/kb/923737


please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.







img]http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 24 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 24 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u24 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u24-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI