This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer infected (WinNT/Alureon.S, Win32/Winwebsec, Gen-Nullo[Short])

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I think our computer was infected within the last two weeks. We have been using Microsoft Security Essentials, SuperAntSpyware Remover, Malware and SpyBot to try to remove the infection(s). We've been seeing multiple iexplore.exe processes. At one point in time, almost all the files/folders on the computer were hidden and we had to unhide every folder. We have been asked for the WIndows passwords in suspect popup windows. When Windows starts, there is a window that states that the C:\WINDOWS\uNerli.dll is missing/not running. The computer is running at a crawl. We have pasted the results of a hijackthis scan below. Any help is greatly appreciated as this is our one and only computer!

-Tim, Mattias, and Linda


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:37:03, on 5/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Mattias\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…px&id=64855
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1713] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC453] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2194] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8776] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Program Files\NOS\bin\getPlusUninst_Adobe.exe" /Get1noarp
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Hyufapaxi] rundll32.exe "C:\WINDOWS\uNerli.dll",Startup
O4 - HKCU\..\RunOnce: [SpybotDeletingB5411] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1557] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5956] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5582] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://mcrlink.mayo.edu/vdesk/cachecleaner…,2010,0122,2102
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} (F5 Networks VPN Manager) - https://mcrlink.mayo.edu/vdesk/terminal/urx…1,2010,125,2117
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} (F5 Networks Dynamic Application Tunnel Control) - https://mcrlink.mayo.edu/vdesk/terminal/f5t…,2009,1204,1610
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://mcrlink.mayo.edu/vdesk/terminal/Ins…,2009,1204,1613
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} (F5 Virtual Sandbox Class) - https://mcrlink.mayo.edu/vdesk/terminal/vde…,2009,1212,1610
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1608
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1604
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: HP Smart Card Monitor Service (scwatch) - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Session Allocation Client\scwatch.exe
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
O23 - Service: VMware View Client Service (wsnm) - VMware, Inc. - C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe

–
End of file - 11402 bytes
Hi there let me get a proper look at your system as Hijackthis does not show the reality

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

THEN

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    volsnap.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /mp /s
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
Thank you for the prompt reply.

Here are the logs:


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-15 10:19:57
—————————–
10:19:57.593 OS Version: Windows 5.1.2600 Service Pack 3
10:19:57.593 Number of processors: 2 586 0x604
10:19:57.593 ComputerName: SARAH UserName:
10:19:58.812 Initialize success
10:20:01.515 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
10:20:01.515 Disk 0 Vendor: Intel___ 1.0. Size: 152585MB BusType: 3
10:20:01.531 Disk 0 MBR read successfully
10:20:01.531 Disk 0 MBR scan
10:20:01.531 Disk 0 unknown MBR code
10:20:01.546 Disk 0 scanning sectors +312480315
10:20:01.562 Disk 0 scanning C:\WINDOWS\system32\drivers
10:20:08.281 Service scanning
10:20:09.375 Disk 0 trace - called modules:
10:20:09.375
10:20:09.375 Scan finished successfully
10:20:24.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Mattias\Desktop\MBR.dat"
10:20:24.328 The log file has been saved successfully to "C:\Documents and Settings\Mattias\Desktop\aswMBR.txt"





OTL logfile created on: 5/15/2011 10:23:33 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mattias\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 320.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.57 Gb Total Space | 52.78 Gb Free Space | 48.62% Space Free | Partition Type: NTFS
Drive D: | 37.13 Gb Total Space | 1.03 Gb Free Space | 2.77% Space Free | Partition Type: NTFS

Computer Name: SARAH | User Name: Mattias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
PRC - [2011/05/05 22:33:29 | 002,424,192 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/11/30 14:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/02/10 13:54:12 | 000,151,552 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/07/25 05:23:07 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\javaw.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/06/06 14:34:48 | 000,151,552 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
PRC - [2005/06/17 06:55:58 | 000,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe


========== Modules (SafeList) ==========

MOD - [2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (WMPNetworkSvc)
SRV - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/07/31 22:03:31 | 000,200,192 | —- | M] (Hewlett-Packard Development Company, L.P. ) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Session Allocation Client\scwatch.exe – (scwatch)
SRV - [2010/02/10 13:54:12 | 000,151,552 | —- | M] (VMware, Inc.) [Auto | Running] – C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe – (wsnm)
SRV - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2006/11/03 20:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2005/06/17 06:55:58 | 000,086,140 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe – (IAANTMon) Intel®


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Running] – – (MpKslf9e5da9f)
DRV - [2011/05/14 22:22:27 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsl38276a0d.sys – (MpKsl38276a0d)
DRV - [2010/05/10 13:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/02/09 22:41:54 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\drivers\sptd.sys – (sptd)
DRV - [2010/01/25 16:18:51 | 000,033,920 | —- | M] (F5 Networks, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\covpndrv.sys – (urvpndrv)
DRV - [2010/01/25 16:18:46 | 000,010,752 | —- | M] (F5 Networks) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\urfltw2k.sys – (f5ipfw)
DRV - [2009/10/07 01:46:36 | 000,025,752 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/03/25 11:06:30 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/03/25 11:06:28 | 000,214,024 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/03/25 11:06:28 | 000,079,880 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/03/25 11:06:28 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/03/25 11:05:54 | 000,034,216 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2008/12/17 01:02:08 | 000,023,832 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvcflt.sys – (FilterService)
DRV - [2008/12/17 01:01:44 | 006,364,440 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvc.sys – (LVUVC) Logitech QuickCam S5500(UVC)
DRV - [2008/12/17 01:01:22 | 000,041,752 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2008/12/17 01:00:14 | 000,768,024 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS)
DRV - [2007/04/04 15:58:26 | 000,024,344 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\klim5.sys – (klim5)
DRV - [2006/06/19 08:49:52 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/11/16 20:36:00 | 001,047,816 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2005/09/08 04:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 04:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 04:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 04:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 04:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 04:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 04:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 11:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 11:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2005/08/04 03:10:18 | 001,273,344 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/06/30 12:23:34 | 000,004,608 | —- | M] (NVIDIA Corporation.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvport.sys – (nvport)
DRV - [2005/06/13 16:27:56 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2002/06/27 21:00:00 | 000,016,509 | —- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PalmUSBD.sys – (PalmUSBD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…px&id;=64855
IE - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{AF6074BD-805C-4A09-88D5-27FEE035D64A}: C:\Documents and Settings\Mattias\Local Settings\Application Data\{AF6074BD-805C-4A09-88D5-27FEE035D64A}\ [2011/05/13 22:38:35 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/05/03 15:39:19 | 000,000,025 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EverioService] C:\Program Files\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [Hyufapaxi] File not found
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKLM..\RunOnce: [RegistryCleanerFreeunstall] File not found
O4 - HKLM..\RunOnce: [SpybotDeletingA1713] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2194] C:\WINDOWS\System32\command.com ()
O4 - HKLM..\RunOnce: [SpybotDeletingC453] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC8776] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingB5411] C:\WINDOWS\System32\command.com ()
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingB5956] C:\WINDOWS\System32\command.com ()
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingD1557] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingD5582] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} https://install.charter.com/diskless/bin/ssctlsma.dll (SmartAccess Ctl Class)
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://mcrlink.mayo.edu/vdesk/cachecleaner…,2010,0122,2102 (F5 Networks CacheCleaner)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} https://mcrlink.mayo.edu/vdesk/terminal/urx…1,2010,125,2117 (F5 Networks VPN Manager)
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} https://mcrlink.mayo.edu/vdesk/terminal/f5t…,2009,1204,1610 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://mcrlink.mayo.edu/vdesk/terminal/Ins…,2009,1204,1613 (F5 Networks Auto Update)
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} https://mcrlink.mayo.edu/vdesk/terminal/vde…,2009,1212,1610 (F5 Virtual Sandbox Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1608 (F5 Networks SuperHost Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1604 (F5 Networks Host Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Mattias\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mattias\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Unable to start service SrService!

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 10:20:56 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
[2011/05/15 10:19:27 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\Mattias\Desktop\aswMBR.exe
[2011/05/14 22:36:13 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mattias\Desktop\HiJackThis.exe
[2011/05/14 22:10:15 | 000,000,000 | —D | C] – C:\Program Files\WOT
[2011/05/14 21:49:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/05/14 21:32:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Desktop\New Folder
[2011/05/14 16:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Application Data\RegistryCleanerFree
[2011/05/14 16:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegistryCleanerFree
[2011/05/14 16:00:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Local Settings\Application Data\PackageAware
[2011/05/13 22:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Local Settings\Application Data\{AF6074BD-805C-4A09-88D5-27FEE035D64A}
[2011/05/13 20:42:22 | 000,000,000 | R–D | C] – C:\Documents and Settings\Mattias\Recent
[2011/05/13 20:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\aH06511OkEpH06511
[2011/05/04 06:39:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Sarah's Project
[2011/05/04 06:33:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\MOM'S PIX
[2011/05/04 06:18:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Pictures for Sarah
[2011/05/04 06:18:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Baby Maximilian
[2011/05/04 06:17:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Rob's wedding 1
[2011/05/04 06:17:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\MAYO residency
[2011/04/29 20:48:32 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/04/28 15:30:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/04/28 15:30:47 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/04/28 15:30:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/04/28 15:30:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/04/28 15:21:30 | 000,000,000 | —D | C] – C:\WINDOWS\$NtServicePackUninstall$
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
[2011/05/15 10:20:24 | 000,000,512 | —- | M] () – C:\Documents and Settings\Mattias\Desktop\MBR.dat
[2011/05/15 10:19:32 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\Mattias\Desktop\aswMBR.exe
[2011/05/15 09:37:32 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/14 23:37:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/14 23:20:32 | 000,000,031 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/05/14 22:36:14 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mattias\Desktop\HiJackThis.exe
[2011/05/14 22:21:33 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/14 22:20:37 | 000,445,560 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/14 22:20:37 | 000,072,766 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/14 22:19:03 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/14 22:16:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/14 22:16:16 | 1071,788,032 | -HS- | M] () – C:\hiberfil.sys
[2011/05/14 21:56:48 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/14 21:26:55 | 000,003,854 | —- | M] () – C:\WINDOWS\wininit.ini
[2011/05/13 23:11:50 | 000,000,784 | —- | M] () – C:\Documents and Settings\Mattias\Desktop\Malwarebytes.lnk
[2011/05/13 22:38:37 | 000,000,000 | —- | M] () – C:\WINDOWS\Dzewi.bin
[2011/05/13 22:38:36 | 000,000,120 | —- | M] () – C:\WINDOWS\Drezimaxeqa.dat
[2011/05/13 20:43:07 | 000,000,336 | —- | M] () – C:\Documents and Settings\All Users\Application Data\18865956
[2011/05/13 20:33:09 | 000,000,000 | —- | M] () – C:\Documents and Settings\Mattias\2gweorjqjutp92vjy9gake
[2011/05/11 21:01:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/04 00:17:20 | 000,000,346 | —- | M] () – C:\Documents and Settings\All Users\Documents\Shortcut to Shared Documents.lnk
[2011/05/03 15:39:19 | 000,000,025 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/30 21:47:16 | 000,285,312 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/30 21:21:28 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/28 15:48:43 | 002,408,121 | —- | M] () – C:\WINDOWS\iis6.BAK
[2011/04/28 15:24:47 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/24 15:33:39 | 000,192,512 | —- | M] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 11:39:33 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/04/24 11:39:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 10:20:24 | 000,000,512 | —- | C] () – C:\Documents and Settings\Mattias\Desktop\MBR.dat
[2011/05/14 21:56:48 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/14 21:56:47 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/13 23:11:50 | 000,000,784 | —- | C] () – C:\Documents and Settings\Mattias\Desktop\Malwarebytes.lnk
[2011/05/13 20:42:41 | 000,000,336 | —- | C] () – C:\Documents and Settings\All Users\Application Data\18865956
[2011/05/13 20:33:09 | 000,000,000 | —- | C] () – C:\Documents and Settings\Mattias\2gweorjqjutp92vjy9gake
[2011/04/30 21:08:36 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/01/17 21:16:53 | 000,709,456 | —- | C] () – C:\WINDOWS\is-FQRIP.exe
[2010/07/31 22:20:05 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/31 22:20:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/31 22:20:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/31 22:20:05 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/31 22:20:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/17 19:11:30 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2010/01/12 12:05:01 | 000,000,120 | —- | C] () – C:\WINDOWS\Drezimaxeqa.dat
[2010/01/12 12:05:01 | 000,000,000 | —- | C] () – C:\WINDOWS\Dzewi.bin
[2010/01/12 12:00:42 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/20 08:58:42 | 000,081,110 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/20 22:48:35 | 000,000,026 | —- | C] () – C:\WINDOWS\RBASSE~1.INI
[2009/07/19 20:16:35 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2009/07/10 16:07:20 | 005,433,520 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall.exe
[2009/07/10 16:07:20 | 000,014,373 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2009/05/18 21:55:02 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/05/15 09:59:34 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/04/15 21:51:54 | 000,166,304 | —- | C] () – C:\WINDOWS\hpoins28.dat
[2009/04/15 21:51:54 | 000,000,796 | —- | C] () – C:\WINDOWS\hpomdl28.dat
[2008/11/03 19:43:49 | 000,002,938 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/07/30 11:04:34 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/07/23 09:03:57 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/03/24 09:47:02 | 000,000,012 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\userdic.tlx
[2007/11/28 22:44:18 | 000,000,130 | —- | C] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\fusioncache.dat
[2007/11/08 09:50:57 | 000,082,258 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2007/11/08 09:50:57 | 000,082,258 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2007/10/23 18:40:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/10/19 19:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 04:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/22 19:28:40 | 000,000,761 | —- | C] () – C:\WINDOWS\eReg.dat
[2007/05/28 15:37:05 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/03/26 15:19:17 | 000,192,512 | —- | C] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/26 11:21:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/03/18 13:36:09 | 000,061,678 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\PFP120JPR.{PB
[2007/03/18 13:36:09 | 000,012,358 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\PFP120JCM.{PB
[2006/10/26 19:45:10 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\DD44460B58.sys
[2006/10/16 10:11:15 | 000,001,088 | —- | C] () – C:\WINDOWS\checkip.dat
[2006/07/21 10:42:32 | 000,004,184 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/07/21 10:42:32 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\580B4644DD.sys
[2006/07/20 20:28:25 | 000,205,312 | R— | C] () – C:\WINDOWS\patchw32.dll
[2006/07/20 20:27:51 | 000,205,312 | R— | C] () – C:\WINDOWS\pw32a.dll
[2006/06/19 09:04:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/19 08:58:06 | 000,003,854 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/06/19 08:55:01 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/06/19 08:52:48 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/06/19 08:49:15 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/19 08:29:20 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/19 08:29:16 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/06/19 08:28:48 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 16:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 16:19:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/11 16:12:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 16:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 16:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 16:06:43 | 000,285,312 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 16:00:30 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/11 16:00:28 | 000,445,560 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/11 16:00:28 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/11 16:00:28 | 000,072,766 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/11 16:00:28 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/11 16:00:27 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/11 16:00:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/11 16:00:24 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/11 16:00:19 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/11 16:00:19 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/11 16:00:12 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/11 16:00:04 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin

========== LOP Check ==========

[2011/05/13 20:50:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\aH06511OkEpH06511
[2007/11/20 19:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anonymizer
[2008/08/04 13:00:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010/02/09 22:41:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/12/25 18:56:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\gPhBl08200
[2011/05/14 16:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegistryCleanerFree
[2007/11/21 09:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/06/19 08:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/10/08 21:39:00 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2007/11/20 19:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Anonymizer
[2011/03/30 18:32:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\BitTorrent
[2008/03/17 20:06:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\BitTorrent DNA
[2009/05/14 18:46:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\DAEMON Tools Lite
[2009/07/10 16:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\dBpoweramp
[2010/03/23 22:08:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\DNA
[2007/01/14 20:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Leadertech
[2011/04/14 07:06:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Opera
[2008/08/04 15:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Paltalk
[2010/07/31 22:32:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Qabu
[2009/10/16 16:40:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Quicken WillMaker
[2011/05/14 16:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\RegistryCleanerFree
[2010/07/31 21:50:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Suruu
[2011/05/11 21:01:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/05/14 22:21:33 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2004/08/04 04:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 04:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\i386\svchost.exe
[2004/08/04 04:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2004/08/04 04:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\ERDNT\cache\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 04:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\i386\userinit.exe
[2004/08/04 04:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004/08/04 04:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: VOLSNAP.INF >
[2004/08/04 04:00:00 | 000,001,095 | —- | M] () MD5=1C43F4D998567C9D2463E18669F33A3C – C:\i386\volsnap.inf
[2004/08/04 04:00:00 | 000,001,095 | —- | M] () MD5=1C43F4D998567C9D2463E18669F33A3C – C:\WINDOWS\inf\volsnap.inf

< MD5 for: VOLSNAP.PNF >
[2006/06/19 08:39:21 | 000,004,964 | —- | M] () MD5=0ACEB3D0438767B73A6796FC424F7862 – C:\WINDOWS\inf\volsnap.PNF

< MD5 for: VOLSNAP.SYS >
[2008/04/13 13:41:01 | 000,052,352 | —- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 – C:\WINDOWS\ServicePackFiles\i386\volsnap.sys
[2008/04/13 13:41:01 | 000,052,352 | —- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 – C:\WINDOWS\system32\drivers\volsnap.sys
[2004/08/04 04:00:00 | 000,052,352 | —- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B – C:\i386\volsnap.sys
[2004/08/04 04:00:00 | 000,052,352 | —- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B – C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys

< MD5 for: WINLOGON.EXE >
[2004/08/04 04:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 04:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 04:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/02/18 06:49:53 | 000,173,568 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" [2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation)

========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9638A27E

< End of report >




OTL Extras logfile created on: 5/15/2011 10:23:33 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mattias\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 320.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.57 Gb Total Space | 52.78 Gb Free Space | 48.62% Space Free | Partition Type: NTFS
Drive D: | 37.13 Gb Total Space | 1.03 Gb Free Space | 2.77% Space Free | Partition Type: NTFS

Computer Name: SARAH | User Name: Mattias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – "C:\Program Files\Opera\opera.exe" "%1"
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Lexmark 1300 Series\app4r.exe" = C:\Program Files\Lexmark 1300 Series\app4r.exe:*:Enabled:Lexmark Imaging Studio
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe
"C:\Program Files\VMware\VMware View\Client\bin\vmware-remotemks.exe" = C:\Program Files\VMware\VMware View\Client\bin\vmware-remotemks.exe:*:Enabled:VMware Remote MKS – (VMware, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe – (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC
"C:\Program Files\VMware\VMware View\Client\bin\vmware-remotemks.exe" = C:\Program Files\VMware\VMware View\Client\bin\vmware-remotemks.exe:*:Enabled:VMware Remote MKS – (VMware, Inc.)
"C:\Program Files\VMware\VMware View\Client\bin\wswc.exe" = C:\Program Files\VMware\VMware View\Client\bin\wswc.exe:*:Disabled:VMware View Client – (VMware, Inc.)
"C:\Program Files\CyberLink\PCM4Everio\EverioService.exe" = C:\Program Files\CyberLink\PCM4Everio\EverioService.exe:*:Enabled:CyberLink PowerCinema NE for Everio Resident Program – (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDirector Express\PDX.exe" = C:\Program Files\CyberLink\PowerDirector Express\PDX.exe:*:Enabled:CyberLink PowerDirector Express – (CyberLink Corp.)
"C:\Documents and Settings\Mattias\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Mattias\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Disabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent
"C:\Documents and Settings\Mattias\Desktop\BitTorrent-7.2.exe" = C:\Documents and Settings\Mattias\Desktop\BitTorrent-7.2.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{055FEF8E-4B86-400F-A5C6-8FAC0042DCD9}" = NVIDIA PureVideo Decoder
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D10C273-3F95-42A2-8371-AB6B1F59821B}" = WOT for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 15
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{39CEE1F2-12B6-4C50-9131-04BFCA110578}" = PowerCinema NE for Everio
"{403EF592-953B-4794-BCEF-ECAB835C2095}" =
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{55BF0E5F-EA8E-4C13-A8B4-9E4857F5A2DE}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{60D4F9F1-B828-4048-A5AB-9AA2FD0C4751}" = DJ_AIO_03_F4200_Software
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6365C963-4B72-43F8-8392-2A5441EC2A86}" = DJ_AIO_03_F4200_ProductContext
"{6710FE30-27F7-492B-A660-D31D4A898A43}" = MSN Toolbar
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87885939-F824-42bf-B790-231B1E8EF2BB}" = dj_sf_software
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9EE5F80C-7542-47CE-885B-4D317E3B0783}" = HP Session Allocation Client
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B61A79BE-E94C-42C0-921D-8B7E5217069C}" = F4200
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BE8A9C2C-8E41-445B-A746-BEB0B1F992F8}" = DJ_AIO_03_F4200_Software_Min
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C3B6AEB1-390C-4792-8677-CD87F8B2C959}" = HP Deskjet F4200 All-In-One Driver Software 11.0 Rel .3
"{C41F4616-44B6-4E8D-BFC7-4267862A2CE1}" = CinepPlayer 30 Update
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Picture Package Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D0EBD385-7764-402D-892C-B5EA03E0DEEC}" = VMware View Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F445476A-42DE-11D4-80D0-00C04F2750A6}" = Epocrates Essentials
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"{F8A5531E-FEB4-4F7C-AF51-342E40FA7A0D}" = F4200_Help
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ATI Display Driver" = ATI Display Driver
"AudioPlugin.dll" =
"Connection Manager" =
"CopyNow.dll" =
"DataPlugin.dll" =
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"dlatray.exe" =
"Epocrates" =
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"File Shredder_is1" = File Shredder 2.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Interactive Training" =
"Microsoft Security Client" = Microsoft Security Essentials
"MobileOptionPack" =
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NetMeeting" =
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OutlookExpress" =
"PCHealth" =
"PROSet" = Intel® PRO Network Connections Drivers
"Quicken WillMaker Plus 2009" = Quicken WillMaker Plus 2009
"SchedulingAgent" =
"StreetPlugin" = Learn2 Player (Uninstall Only)
"V3.2_is1" = File Scavenger 3.2
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/4/2011 7:10:37 AM | Computer Name = SARAH | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 5/12/2011 3:12:52 PM | Computer Name = SARAH | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 5/13/2011 9:51:59 PM | Computer Name = SARAH | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/13/2011 11:58:16 PM | Computer Name = SARAH | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office Standard Edition 2003 – Error 1706. Setup
cannot find the required files. Check your connection to the network, or CD-ROM
drive. For other potential solutions to this problem, see C:\Program Files\Microsoft
Office\OFFICE11\1033\SETUP.CHM.

Error - 5/14/2011 12:00:11 AM | Computer Name = SARAH | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office Standard Edition 2003 – Error 1706. Setup
cannot find the required files. Check your connection to the network, or CD-ROM
drive. For other potential solutions to this problem, see C:\Program Files\Microsoft
Office\OFFICE11\1033\SETUP.CHM.

Error - 5/14/2011 5:25:30 PM | Computer Name = SARAH | Source = Application Error | ID = 1000
Description = Faulting application registrycleanerfree.exe, version 2.2.7.2, faulting
module registrycleanerfree.exe, version 2.2.7.2, fault address 0x00047eb8.

Error - 5/14/2011 10:47:19 PM | Computer Name = SARAH | Source = Spybot - Search & Destroy | ID = 0
Description =

Error - 5/14/2011 11:13:18 PM | Computer Name = SARAH | Source = MsiInstaller | ID = 11316
Description = Product: WOT for Internet Explorer – Error 1316. A network error
occurred while attempting to read from the file: C:\Documents and Settings\Mattias\Local
Settings\Temporary Internet Files\Content.IE5\5BXY85QS\WOT-latest[1].msi

Error - 5/15/2011 12:27:10 AM | Computer Name = SARAH | Source = MsiInstaller | ID = 11722
Description = Product: Java™ 6 Update 24 – Error 1722.There is a problem with
this Windows Installer package. A program run as part of the setup did not finish
as expected. Contact your support personnel or package vendor. Action patchjre,
location: C:\Program Files\Java\jre6\patchjre.exe, command: -s "C:\Program Files\Java\jre6"


[ System Events ]
Error - 5/14/2011 11:16:37 PM | Computer Name = SARAH | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 5/14/2011 11:16:37 PM | Computer Name = SARAH | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%5

Error - 5/15/2011 6:46:28 AM | Computer Name = SARAH | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001372D77344 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).

Error - 5/15/2011 8:37:12 AM | Computer Name = SARAH | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.2 on
the Network Card with network address 001372D77344.

Error - 5/15/2011 8:37:34 AM | Computer Name = SARAH | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.2 on
the Network Card with network address 001372D77344.

Error - 5/15/2011 8:45:00 AM | Computer Name = SARAH | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.2 on
the Network Card with network address 001372D77344.

Error - 5/15/2011 9:41:23 AM | Computer Name = SARAH | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 001372D77344 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).

Error - 5/15/2011 11:17:48 AM | Computer Name = SARAH | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.100.2 for the Network Card with network
address 001372D77344 has been denied by the DHCP server 192.168.100.1 (The DHCP
Server sent a DHCPNACK message).

Error - 5/15/2011 11:24:15 AM | Computer Name = SARAH | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/15/2011 11:24:15 AM | Computer Name = SARAH | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%5


< End of report >
On completion of this run can you let me know what problems remain


Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - No CLSID value found.
    O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - No CLSID value found.
    O3 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [Hyufapaxi] File not found
    O4 - HKLM..\RunOnce: [RegistryCleanerFreeunstall] File not found
    O4 - HKLM..\RunOnce: [SpybotDeletingA1713] C:\WINDOWS\System32\command.com ()
    O4 - HKLM..\RunOnce: [SpybotDeletingA2194] C:\WINDOWS\System32\command.com ()
    O4 - HKLM..\RunOnce: [SpybotDeletingC453] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [SpybotDeletingC8776] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
    O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
    O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingB5411] C:\WINDOWS\System32\command.com ()
    O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingB5956] C:\WINDOWS\System32\command.com ()
    O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingD1557] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\RunOnce: [SpybotDeletingD5582] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
    [2011/05/13 20:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\aH06511OkEpH06511
    [2011/05/13 22:38:37 | 000,000,000 | —- | M] () – C:\WINDOWS\Dzewi.bin
    [2011/05/13 22:38:36 | 000,000,120 | —- | M] () – C:\WINDOWS\Drezimaxeqa.dat
    [2011/05/13 20:43:07 | 000,000,336 | —- | M] () – C:\Documents and Settings\All Users\Application Data\18865956
    [2011/05/13 20:33:09 | 000,000,000 | —- | M] () – C:\Documents and Settings\Mattias\2gweorjqjutp92vjy9gake
    [2011/05/13 20:42:41 | 000,000,336 | —- | C] () – C:\Documents and Settings\All Users\Application Data\18865956
    [2011/05/13 20:33:09 | 000,000,000 | —- | C] () – C:\Documents and Settings\Mattias\2gweorjqjutp92vjy9gake
    [2011/05/13 20:50:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\aH06511OkEpH06511
    [2010/12/25 18:56:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\gPhBl08200


    :Files
    ipconfig /flushdns /c
    C:\Documents and Settings\Mattias\2gweorjqjutp92vjy9gake
    C:\Documents and Settings\All Users\Application Data\aH06511OkEpH06511
    C:\Documents and Settings\All Users\Application Data\gPhBl08200

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure, click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Ok.

I ran OTL-Run/Fix with your quote pasted in and rebooted the computer. Upon startup the attached Spybot Search and Destroy entry (attached as screen shot) appeared. Should this be allowed or denied?

Did you want me to run the OTL scan with any information in the Custom Scans/Fixes box?

This is the result of the OTL quick scan with no information entered in the Custom Scans/Fixes box.

OTL logfile created on: 5/15/2011 1:34:15 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mattias\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 448.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.57 Gb Total Space | 53.18 Gb Free Space | 48.98% Space Free | Partition Type: NTFS
Drive D: | 37.13 Gb Total Space | 1.03 Gb Free Space | 2.77% Space Free | Partition Type: NTFS

Computer Name: SARAH | User Name: Mattias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
PRC - [2011/05/05 22:33:29 | 002,424,192 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/11/30 14:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/02/10 13:54:12 | 000,151,552 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/06/06 14:34:48 | 000,151,552 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
PRC - [2005/06/17 06:55:58 | 000,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe


========== Modules (SafeList) ==========

MOD - [2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (WMPNetworkSvc)
SRV - [2010/11/11 13:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/07/31 22:03:31 | 000,200,192 | —- | M] (Hewlett-Packard Development Company, L.P. ) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Session Allocation Client\scwatch.exe – (scwatch)
SRV - [2010/02/10 13:54:12 | 000,151,552 | —- | M] (VMware, Inc.) [Auto | Running] – C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe – (wsnm)
SRV - [2009/10/07 01:47:34 | 000,154,136 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2006/11/03 20:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2005/06/17 06:55:58 | 000,086,140 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe – (IAANTMon) Intel®


========== Driver Services (SafeList) ==========

DRV - [2011/05/15 13:23:06 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsle1cb8664.sys – (MpKsle1cb8664)
DRV - [2011/05/14 22:22:27 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsl38276a0d.sys – (MpKsl38276a0d)
DRV - [2010/05/10 13:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/02/09 22:41:54 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\drivers\sptd.sys – (sptd)
DRV - [2010/01/25 16:18:51 | 000,033,920 | —- | M] (F5 Networks, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\covpndrv.sys – (urvpndrv)
DRV - [2010/01/25 16:18:46 | 000,010,752 | —- | M] (F5 Networks) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\urfltw2k.sys – (f5ipfw)
DRV - [2009/10/07 01:46:36 | 000,025,752 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2009/03/25 11:06:30 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/03/25 11:06:28 | 000,214,024 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/03/25 11:06:28 | 000,079,880 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/03/25 11:06:28 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/03/25 11:05:54 | 000,034,216 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2008/12/17 01:02:08 | 000,023,832 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvcflt.sys – (FilterService)
DRV - [2008/12/17 01:01:44 | 006,364,440 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvuvc.sys – (LVUVC) Logitech QuickCam S5500(UVC)
DRV - [2008/12/17 01:01:22 | 000,041,752 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2008/12/17 01:00:14 | 000,768,024 | R— | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lvrs.sys – (LVRS)
DRV - [2007/04/04 15:58:26 | 000,024,344 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\klim5.sys – (klim5)
DRV - [2006/06/19 08:49:52 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/11/16 20:36:00 | 001,047,816 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2005/09/08 04:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 04:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 04:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 04:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 04:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 04:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 04:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 11:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 11:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2005/08/04 03:10:18 | 001,273,344 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/06/30 12:23:34 | 000,004,608 | —- | M] (NVIDIA Corporation.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvport.sys – (nvport)
DRV - [2005/06/13 16:27:56 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2002/06/27 21:00:00 | 000,016,509 | —- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\PalmUSBD.sys – (PalmUSBD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin…px&id=64855
IE - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{AF6074BD-805C-4A09-88D5-27FEE035D64A}: C:\Documents and Settings\Mattias\Local Settings\Application Data\{AF6074BD-805C-4A09-88D5-27FEE035D64A}\ [2011/05/13 22:38:35 | 000,000,000 | —D | M]


O1 HOSTS File: ([2011/05/15 13:17:25 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {0347C33E-8762-4905-BF09-768834316C61} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (no name) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EverioService] C:\Program Files\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3151629530-3822985213-3209864044-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} https://install.charter.com/diskless/bin/ssctlsma.dll (SmartAccess Ctl Class)
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} https://mcrlink.mayo.edu/vdesk/cachecleaner…,2010,0122,2102 (F5 Networks CacheCleaner)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} https://mcrlink.mayo.edu/vdesk/terminal/urx…1,2010,125,2117 (F5 Networks VPN Manager)
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} https://mcrlink.mayo.edu/vdesk/terminal/f5t…,2009,1204,1610 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://mcrlink.mayo.edu/vdesk/terminal/Ins…,2009,1204,1613 (F5 Networks Auto Update)
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} https://mcrlink.mayo.edu/vdesk/terminal/vde…,2009,1212,1610 (F5 Virtual Sandbox Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1608 (F5 Networks SuperHost Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} https://mcrlink.mayo.edu/vdesk/terminal/urx…,2009,1204,1604 (F5 Networks Host Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} https://mcrlink.mayo.edu/vdesk/terminal/f5o…0,2010,331,1206 (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Mattias\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mattias\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/15 13:17:23 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/15 10:20:56 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
[2011/05/15 10:19:27 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\Mattias\Desktop\aswMBR.exe
[2011/05/14 22:36:13 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mattias\Desktop\HiJackThis.exe
[2011/05/14 22:10:15 | 000,000,000 | —D | C] – C:\Program Files\WOT
[2011/05/14 21:49:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/05/14 21:32:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Desktop\New Folder
[2011/05/14 16:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Application Data\RegistryCleanerFree
[2011/05/14 16:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegistryCleanerFree
[2011/05/14 16:00:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Local Settings\Application Data\PackageAware
[2011/05/13 22:38:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Mattias\Local Settings\Application Data\{AF6074BD-805C-4A09-88D5-27FEE035D64A}
[2011/05/13 20:42:22 | 000,000,000 | R–D | C] – C:\Documents and Settings\Mattias\Recent
[2011/05/04 06:39:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Sarah's Project
[2011/05/04 06:33:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\MOM'S PIX
[2011/05/04 06:18:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Pictures for Sarah
[2011/05/04 06:18:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Baby Maximilian
[2011/05/04 06:17:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Rob's wedding 1
[2011/05/04 06:17:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\MAYO residency
[2011/04/29 20:48:32 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/04/28 15:30:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/04/28 15:30:47 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/04/28 15:30:47 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/04/28 15:30:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/04/28 15:21:30 | 000,000,000 | —D | C] – C:\WINDOWS\$NtServicePackUninstall$
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/15 13:37:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/15 13:28:06 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/15 13:27:33 | 000,029,488 | —- | M] () – C:\Documents and Settings\Mattias\Desktop\Spybot screen capture.JPG
[2011/05/15 13:27:12 | 000,445,560 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/15 13:27:12 | 000,072,766 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/15 13:23:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/15 13:23:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/15 13:22:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/15 13:22:48 | 1071,788,032 | -HS- | M] () – C:\hiberfil.sys
[2011/05/15 13:17:25 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/05/15 10:20:57 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mattias\Desktop\OTL.exe
[2011/05/15 10:20:24 | 000,000,512 | —- | M] () – C:\Documents and Settings\Mattias\Desktop\MBR.dat
[2011/05/15 10:19:32 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\Mattias\Desktop\aswMBR.exe
[2011/05/14 23:20:32 | 000,000,031 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/05/14 22:36:14 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mattias\Desktop\HiJackThis.exe
[2011/05/14 21:56:48 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/14 21:26:55 | 000,003,854 | —- | M] () – C:\WINDOWS\wininit.ini
[2011/05/13 23:11:50 | 000,000,784 | —- | M] () – C:\Documents and Settings\Mattias\Desktop\Malwarebytes.lnk
[2011/05/11 21:01:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/04 00:17:20 | 000,000,346 | —- | M] () – C:\Documents and Settings\All Users\Documents\Shortcut to Shared Documents.lnk
[2011/04/30 21:47:16 | 000,285,312 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/30 21:21:28 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/28 15:48:43 | 002,408,121 | —- | M] () – C:\WINDOWS\iis6.BAK
[2011/04/28 15:24:47 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/24 15:33:39 | 000,192,512 | —- | M] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 11:39:33 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/04/24 11:39:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/15 13:27:33 | 000,029,488 | —- | C] () – C:\Documents and Settings\Mattias\Desktop\Spybot screen capture.JPG
[2011/05/15 10:20:24 | 000,000,512 | —- | C] () – C:\Documents and Settings\Mattias\Desktop\MBR.dat
[2011/05/14 21:56:48 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/05/14 21:56:47 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/05/13 23:11:50 | 000,000,784 | —- | C] () – C:\Documents and Settings\Mattias\Desktop\Malwarebytes.lnk
[2011/04/30 21:08:36 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/01/17 21:16:53 | 000,709,456 | —- | C] () – C:\WINDOWS\is-FQRIP.exe
[2010/07/31 22:20:05 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/31 22:20:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/31 22:20:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/31 22:20:05 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/31 22:20:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/17 19:11:30 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2010/01/12 12:00:42 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/20 08:58:42 | 000,081,110 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/20 22:48:35 | 000,000,026 | —- | C] () – C:\WINDOWS\RBASSE~1.INI
[2009/07/19 20:16:35 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2009/07/10 16:07:20 | 005,433,520 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall.exe
[2009/07/10 16:07:20 | 000,014,373 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2009/05/18 21:55:02 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/05/15 09:59:34 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/04/15 21:51:54 | 000,166,304 | —- | C] () – C:\WINDOWS\hpoins28.dat
[2009/04/15 21:51:54 | 000,000,796 | —- | C] () – C:\WINDOWS\hpomdl28.dat
[2008/11/03 19:43:49 | 000,002,938 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/07/30 11:04:34 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/07/23 09:03:57 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/03/24 09:47:02 | 000,000,012 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\userdic.tlx
[2007/11/28 22:44:18 | 000,000,130 | —- | C] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\fusioncache.dat
[2007/11/08 09:50:57 | 000,082,258 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2007/11/08 09:50:57 | 000,082,258 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2007/10/23 18:40:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/10/19 19:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 04:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/22 19:28:40 | 000,000,761 | —- | C] () – C:\WINDOWS\eReg.dat
[2007/05/28 15:37:05 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/03/26 15:19:17 | 000,192,512 | —- | C] () – C:\Documents and Settings\Mattias\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/26 11:21:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/03/18 13:36:09 | 000,061,678 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\PFP120JPR.{PB
[2007/03/18 13:36:09 | 000,012,358 | —- | C] () – C:\Documents and Settings\Mattias\Application Data\PFP120JCM.{PB
[2006/10/26 19:45:10 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\DD44460B58.sys
[2006/10/16 10:11:15 | 000,001,088 | —- | C] () – C:\WINDOWS\checkip.dat
[2006/07/21 10:42:32 | 000,004,184 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/07/21 10:42:32 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\580B4644DD.sys
[2006/07/20 20:28:25 | 000,205,312 | R— | C] () – C:\WINDOWS\patchw32.dll
[2006/07/20 20:27:51 | 000,205,312 | R— | C] () – C:\WINDOWS\pw32a.dll
[2006/06/19 09:04:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/19 08:58:06 | 000,003,854 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/06/19 08:55:01 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/06/19 08:52:48 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/06/19 08:49:15 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/19 08:29:20 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/19 08:29:16 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/06/19 08:28:48 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 16:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 16:19:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/11 16:12:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 16:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 16:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 16:06:43 | 000,285,312 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 16:00:30 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/11 16:00:28 | 000,445,560 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/11 16:00:28 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/11 16:00:28 | 000,072,766 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/11 16:00:28 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/11 16:00:27 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/11 16:00:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/11 16:00:24 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/11 16:00:19 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/11 16:00:19 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/11 16:00:12 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/11 16:00:04 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin

========== LOP Check ==========

[2007/11/20 19:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anonymizer
[2008/08/04 13:00:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010/02/09 22:41:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/05/14 16:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegistryCleanerFree
[2007/11/21 09:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/06/19 08:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/10/08 21:39:00 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2007/11/20 19:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Anonymizer
[2011/03/30 18:32:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\BitTorrent
[2008/03/17 20:06:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\BitTorrent DNA
[2009/05/14 18:46:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\DAEMON Tools Lite
[2009/07/10 16:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\dBpoweramp
[2010/03/23 22:08:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\DNA
[2007/01/14 20:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Leadertech
[2011/04/14 07:06:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Opera
[2008/08/04 15:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Paltalk
[2010/07/31 22:32:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Qabu
[2009/10/16 16:40:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Quicken WillMaker
[2011/05/14 16:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\RegistryCleanerFree
[2010/07/31 21:50:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Mattias\Application Data\Suruu
[2011/05/11 21:01:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/05/15 13:28:06 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9638A27E

< End of report >



As soon as you give the go ahead, I will run the TDSSkiller.

Thanks!
TDSSKiller results: 2011/05/15 13:45:19.0000 0564 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29 2011/05/15 13:45:19.0343 0564 ================================================================================ 2011/05/15 13:45:19.0343 0564 SystemInfo: 2011/05/15 13:45:19.0343 0564 2011/05/15 13:45:19.0343 0564 OS Version: 5.1.2600 ServicePack: 3.0 2011/05/15 13:45:19.0343 0564 Product type: Workstation 2011/05/15 13:45:19.0343 0564 ComputerName: SARAH 2011/05/15 13:45:19.0343 0564 UserName: Mattias 2011/05/15 13:45:19.0343 0564 Windows directory: C:\WINDOWS 2011/05/15 13:45:19.0343 0564 System windows directory: C:\WINDOWS 2011/05/15 13:45:19.0343 0564 Processor architecture: Intel x86 2011/05/15 13:45:19.0343 0564 Number of processors: 2 2011/05/15 13:45:19.0343 0564 Page size: 0x1000 2011/05/15 13:45:19.0343 0564 Boot type: Normal boot 2011/05/15 13:45:19.0343 0564 ================================================================================ 2011/05/15 13:45:20.0031 0564 Initialize success 2011/05/15 13:45:26.0046 0268 ================================================================================ 2011/05/15 13:45:26.0046 0268 Scan started 2011/05/15 13:45:26.0046 0268 Mode: Manual; 2011/05/15 13:45:26.0046 0268 ================================================================================ 2011/05/15 13:45:26.0343 0268 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2011/05/15 13:45:26.0421 0268 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/05/15 13:45:26.0468 0268 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/05/15 13:45:26.0515 0268 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2011/05/15 13:45:26.0609 0268 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/05/15 13:45:26.0687 0268 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/05/15 13:45:26.0734 0268 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/05/15 13:45:26.0843 0268 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2011/05/15 13:45:26.0890 0268 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2011/05/15 13:45:26.0937 0268 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2011/05/15 13:45:26.0984 0268 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2011/05/15 13:45:27.0046 0268 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2011/05/15 13:45:27.0109 0268 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2011/05/15 13:45:27.0156 0268 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2011/05/15 13:45:27.0203 0268 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2011/05/15 13:45:27.0250 0268 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2011/05/15 13:45:27.0312 0268 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2011/05/15 13:45:27.0359 0268 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2011/05/15 13:45:27.0421 0268 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 2011/05/15 13:45:27.0515 0268 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/05/15 13:45:27.0593 0268 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/05/15 13:45:27.0750 0268 ati2mtag (03621f7f968ff63713943405deb777f9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/05/15 13:45:27.0843 0268 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/05/15 13:45:27.0875 0268 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/05/15 13:45:27.0906 0268 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/05/15 13:45:27.0968 0268 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2011/05/15 13:45:28.0015 0268 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/05/15 13:45:28.0046 0268 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/05/15 13:45:28.0062 0268 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2011/05/15 13:45:28.0109 0268 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/05/15 13:45:28.0140 0268 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/05/15 13:45:28.0171 0268 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/05/15 13:45:28.0250 0268 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2011/05/15 13:45:28.0296 0268 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2011/05/15 13:45:28.0328 0268 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2011/05/15 13:45:28.0359 0268 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2011/05/15 13:45:28.0406 0268 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/05/15 13:45:28.0453 0268 DLABOIOM (e2d0de31442390c35e3163c87cb6a9eb) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/05/15 13:45:28.0500 0268 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/05/15 13:45:28.0546 0268 DLADResN (83545593e297f50a8e2524b4c071a153) C:\WINDOWS\system32\DLA\DLADResN.SYS 2011/05/15 13:45:28.0656 0268 DLAIFS_M (96e01d901cdc98c7817155cc057001bf) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/05/15 13:45:28.0687 0268 DLAOPIOM (0a60a39cc5e767980a31ca5d7238dfa9) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/05/15 13:45:28.0734 0268 DLAPoolM (9fe2b72558fc808357f427fd83314375) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/05/15 13:45:28.0843 0268 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 2011/05/15 13:45:28.0906 0268 DLAUDFAM (f08e1dafac457893399e03430a6a1397) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/05/15 13:45:28.0953 0268 DLAUDF_M (e7d105ed1e694449d444a9933df8e060) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/05/15 13:45:29.0046 0268 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/05/15 13:45:29.0140 0268 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/05/15 13:45:29.0187 0268 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/05/15 13:45:29.0265 0268 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/05/15 13:45:29.0328 0268 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2011/05/15 13:45:29.0390 0268 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/05/15 13:45:29.0468 0268 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/05/15 13:45:29.0578 0268 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/05/15 13:45:29.0656 0268 E100B (95974e66d3de4951d29e28e8bc0b644c) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/05/15 13:45:29.0734 0268 f5ipfw (92537c3b0483297e21afc7f650fea07e) C:\WINDOWS\system32\drivers\urfltw2k.sys 2011/05/15 13:45:29.0890 0268 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/05/15 13:45:29.0984 0268 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/05/15 13:45:30.0046 0268 FilterService (1edc0df2da14e04504dd3bac21aa32cd) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys 2011/05/15 13:45:30.0093 0268 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/05/15 13:45:30.0156 0268 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/05/15 13:45:30.0203 0268 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/05/15 13:45:30.0250 0268 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/05/15 13:45:30.0296 0268 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/05/15 13:45:30.0359 0268 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/05/15 13:45:30.0421 0268 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/05/15 13:45:30.0500 0268 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/05/15 13:45:30.0562 0268 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2011/05/15 13:45:30.0656 0268 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/05/15 13:45:30.0718 0268 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/05/15 13:45:30.0875 0268 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/05/15 13:45:30.0937 0268 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/05/15 13:45:31.0015 0268 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2011/05/15 13:45:31.0093 0268 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2011/05/15 13:45:31.0125 0268 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/05/15 13:45:31.0218 0268 ialm (5a8e05f1d5c36abd58cffa111eb325ea) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/05/15 13:45:31.0343 0268 iastor (9a65e42664d1534b68512caad0efe963) C:\WINDOWS\system32\drivers\iastor.sys 2011/05/15 13:45:31.0421 0268 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/05/15 13:45:31.0484 0268 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2011/05/15 13:45:31.0562 0268 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/05/15 13:45:31.0609 0268 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/05/15 13:45:31.0671 0268 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/05/15 13:45:31.0734 0268 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/05/15 13:45:31.0906 0268 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/05/15 13:45:31.0953 0268 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/05/15 13:45:32.0015 0268 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/05/15 13:45:32.0093 0268 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/05/15 13:45:32.0156 0268 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/05/15 13:45:32.0218 0268 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/05/15 13:45:32.0281 0268 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/05/15 13:45:32.0359 0268 klim5 (967e2224217431b21f1d04fbb4c68a4b) C:\WINDOWS\system32\DRIVERS\klim5.sys 2011/05/15 13:45:32.0421 0268 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/05/15 13:45:32.0484 0268 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/05/15 13:45:32.0656 0268 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys 2011/05/15 13:45:32.0734 0268 LVRS (e22fd7852e74f04cceb6b8a684a51f3e) C:\WINDOWS\system32\DRIVERS\lvrs.sys 2011/05/15 13:45:32.0843 0268 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys 2011/05/15 13:45:33.0031 0268 LVUVC (e89df2b88ee659954de79827ddf46dc9) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 2011/05/15 13:45:33.0250 0268 mfeavfk (26653763d99ea717fc9e069f6be6771e) C:\WINDOWS\system32\drivers\mfeavfk.sys 2011/05/15 13:45:33.0312 0268 mfebopk (e65ce1279f2c1fd9bd81184ceb7f5468) C:\WINDOWS\system32\drivers\mfebopk.sys 2011/05/15 13:45:33.0375 0268 mfehidk (f817bfca67475cf04925ece4fcf9c3c0) C:\WINDOWS\system32\drivers\mfehidk.sys 2011/05/15 13:45:33.0437 0268 mferkdk (fe03be0b990983a08a33389c00636175) C:\WINDOWS\system32\drivers\mferkdk.sys 2011/05/15 13:45:33.0500 0268 mfesmfk (9c73aca963ad8883b9fc44b410e70b71) C:\WINDOWS\system32\drivers\mfesmfk.sys 2011/05/15 13:45:33.0562 0268 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/05/15 13:45:33.0671 0268 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/05/15 13:45:33.0703 0268 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/05/15 13:45:33.0796 0268 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/05/15 13:45:33.0875 0268 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/05/15 13:45:33.0953 0268 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 2011/05/15 13:45:34.0062 0268 MpKsl38276a0d (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsl38276a0d.sys 2011/05/15 13:45:34.0125 0268 MpKsle1cb8664 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsle1cb8664.sys 2011/05/15 13:45:34.0171 0268 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2011/05/15 13:45:34.0218 0268 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/05/15 13:45:34.0265 0268 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/05/15 13:45:34.0343 0268 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/05/15 13:45:34.0437 0268 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/05/15 13:45:34.0500 0268 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/05/15 13:45:34.0546 0268 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/05/15 13:45:34.0656 0268 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/05/15 13:45:34.0703 0268 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/05/15 13:45:34.0765 0268 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/05/15 13:45:34.0859 0268 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/05/15 13:45:34.0906 0268 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/05/15 13:45:34.0984 0268 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/05/15 13:45:35.0015 0268 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/05/15 13:45:35.0093 0268 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/05/15 13:45:35.0140 0268 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/05/15 13:45:35.0218 0268 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/05/15 13:45:35.0296 0268 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/05/15 13:45:35.0359 0268 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/05/15 13:45:35.0453 0268 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/05/15 13:45:35.0531 0268 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/05/15 13:45:35.0625 0268 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/05/15 13:45:35.0734 0268 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/05/15 13:45:35.0875 0268 nvport (df61a72d300be9274db459ebe4895eb2) C:\WINDOWS\system32\Drivers\nvport.sys 2011/05/15 13:45:35.0921 0268 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/05/15 13:45:35.0968 0268 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/05/15 13:45:36.0046 0268 PalmUSBD (803cf09c795290825607505d37819135) C:\WINDOWS\system32\drivers\PalmUSBD.sys 2011/05/15 13:45:36.0125 0268 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/05/15 13:45:36.0187 0268 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/05/15 13:45:36.0234 0268 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/05/15 13:45:36.0296 0268 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/05/15 13:45:36.0390 0268 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/05/15 13:45:36.0453 0268 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/05/15 13:45:36.0625 0268 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2011/05/15 13:45:36.0656 0268 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2011/05/15 13:45:36.0734 0268 pfc (da86016f0672ada925f589ede715f185) C:\WINDOWS\system32\drivers\pfc.sys 2011/05/15 13:45:36.0859 0268 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/05/15 13:45:36.0906 0268 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/05/15 13:45:36.0953 0268 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/05/15 13:45:37.0031 0268 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/05/15 13:45:37.0109 0268 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2011/05/15 13:45:37.0140 0268 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2011/05/15 13:45:37.0171 0268 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2011/05/15 13:45:37.0203 0268 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2011/05/15 13:45:37.0265 0268 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2011/05/15 13:45:37.0312 0268 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/05/15 13:45:37.0390 0268 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/05/15 13:45:37.0437 0268 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/05/15 13:45:37.0484 0268 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/05/15 13:45:37.0531 0268 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/05/15 13:45:37.0609 0268 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/05/15 13:45:37.0687 0268 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/05/15 13:45:37.0750 0268 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/05/15 13:45:37.0828 0268 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/05/15 13:45:37.0953 0268 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/05/15 13:45:37.0968 0268 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/05/15 13:45:38.0062 0268 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/05/15 13:45:38.0140 0268 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/05/15 13:45:38.0187 0268 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/05/15 13:45:38.0281 0268 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/05/15 13:45:38.0375 0268 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2011/05/15 13:45:38.0437 0268 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/05/15 13:45:38.0500 0268 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2011/05/15 13:45:38.0562 0268 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2011/05/15 13:45:38.0640 0268 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/05/15 13:45:38.0718 0268 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 2011/05/15 13:45:38.0828 0268 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/05/15 13:45:38.0890 0268 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/05/15 13:45:38.0968 0268 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys 2011/05/15 13:45:39.0046 0268 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/05/15 13:45:39.0093 0268 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/05/15 13:45:39.0140 0268 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/05/15 13:45:39.0203 0268 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2011/05/15 13:45:39.0234 0268 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2011/05/15 13:45:39.0265 0268 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2011/05/15 13:45:39.0296 0268 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2011/05/15 13:45:39.0359 0268 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/05/15 13:45:39.0437 0268 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/05/15 13:45:39.0515 0268 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/05/15 13:45:39.0625 0268 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/05/15 13:45:39.0734 0268 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/05/15 13:45:39.0843 0268 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2011/05/15 13:45:39.0953 0268 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/05/15 13:45:40.0015 0268 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2011/05/15 13:45:40.0109 0268 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/05/15 13:45:40.0187 0268 urvpndrv (197a7b3bb98add3e0a4c105a936385a8) C:\WINDOWS\system32\DRIVERS\covpndrv.sys 2011/05/15 13:45:40.0250 0268 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/05/15 13:45:40.0296 0268 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/05/15 13:45:40.0359 0268 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/05/15 13:45:40.0421 0268 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/05/15 13:45:40.0500 0268 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/05/15 13:45:40.0578 0268 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/05/15 13:45:40.0671 0268 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/05/15 13:45:40.0734 0268 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/05/15 13:45:40.0890 0268 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 2011/05/15 13:45:40.0953 0268 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/05/15 13:45:41.0015 0268 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2011/05/15 13:45:41.0078 0268 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 2011/05/15 13:45:41.0125 0268 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/05/15 13:45:41.0203 0268 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/05/15 13:45:41.0343 0268 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/05/15 13:45:41.0515 0268 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/05/15 13:45:41.0593 0268 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/05/15 13:45:41.0656 0268 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/05/15 13:45:41.0718 0268 ================================================================================ 2011/05/15 13:45:41.0718 0268 Scan finished 2011/05/15 13:45:41.0718 0268 ================================================================================ 2011/05/15 13:45:49.0937 3840 ================================================================================ 2011/05/15 13:45:49.0937 3840 Scan started 2011/05/15 13:45:49.0937 3840 Mode: Manual; 2011/05/15 13:45:49.0937 3840 ================================================================================ 2011/05/15 13:45:50.0171 3840 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2011/05/15 13:45:50.0265 3840 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/05/15 13:45:50.0328 3840 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/05/15 13:45:50.0390 3840 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2011/05/15 13:45:50.0468 3840 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/05/15 13:45:50.0531 3840 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/05/15 13:45:50.0640 3840 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/05/15 13:45:50.0687 3840 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2011/05/15 13:45:50.0734 3840 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2011/05/15 13:45:50.0828 3840 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2011/05/15 13:45:50.0890 3840 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2011/05/15 13:45:50.0937 3840 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2011/05/15 13:45:51.0015 3840 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2011/05/15 13:45:51.0078 3840 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2011/05/15 13:45:51.0125 3840 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2011/05/15 13:45:51.0171 3840 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2011/05/15 13:45:51.0218 3840 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2011/05/15 13:45:51.0281 3840 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2011/05/15 13:45:51.0343 3840 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 2011/05/15 13:45:51.0437 3840 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/05/15 13:45:51.0484 3840 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/05/15 13:45:51.0656 3840 ati2mtag (03621f7f968ff63713943405deb777f9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/05/15 13:45:51.0750 3840 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/05/15 13:45:51.0828 3840 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/05/15 13:45:51.0890 3840 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/05/15 13:45:51.0984 3840 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2011/05/15 13:45:52.0031 3840 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/05/15 13:45:52.0093 3840 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/05/15 13:45:52.0156 3840 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2011/05/15 13:45:52.0203 3840 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/05/15 13:45:52.0250 3840 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/05/15 13:45:52.0328 3840 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/05/15 13:45:52.0437 3840 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2011/05/15 13:45:52.0500 3840 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2011/05/15 13:45:52.0562 3840 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2011/05/15 13:45:52.0656 3840 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2011/05/15 13:45:52.0734 3840 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/05/15 13:45:52.0843 3840 DLABOIOM (e2d0de31442390c35e3163c87cb6a9eb) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/05/15 13:45:52.0890 3840 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/05/15 13:45:52.0953 3840 DLADResN (83545593e297f50a8e2524b4c071a153) C:\WINDOWS\system32\DLA\DLADResN.SYS 2011/05/15 13:45:53.0000 3840 DLAIFS_M (96e01d901cdc98c7817155cc057001bf) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/05/15 13:45:53.0031 3840 DLAOPIOM (0a60a39cc5e767980a31ca5d7238dfa9) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/05/15 13:45:53.0078 3840 DLAPoolM (9fe2b72558fc808357f427fd83314375) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/05/15 13:45:53.0109 3840 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 2011/05/15 13:45:53.0171 3840 DLAUDFAM (f08e1dafac457893399e03430a6a1397) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/05/15 13:45:53.0203 3840 DLAUDF_M (e7d105ed1e694449d444a9933df8e060) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/05/15 13:45:53.0296 3840 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/05/15 13:45:53.0375 3840 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/05/15 13:45:53.0437 3840 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/05/15 13:45:53.0515 3840 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/05/15 13:45:53.0656 3840 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2011/05/15 13:45:53.0734 3840 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/05/15 13:45:53.0890 3840 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/05/15 13:45:53.0937 3840 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/05/15 13:45:53.0984 3840 E100B (95974e66d3de4951d29e28e8bc0b644c) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/05/15 13:45:54.0078 3840 f5ipfw (92537c3b0483297e21afc7f650fea07e) C:\WINDOWS\system32\drivers\urfltw2k.sys 2011/05/15 13:45:54.0156 3840 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/05/15 13:45:54.0250 3840 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/05/15 13:45:54.0312 3840 FilterService (1edc0df2da14e04504dd3bac21aa32cd) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys 2011/05/15 13:45:54.0375 3840 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/05/15 13:45:54.0437 3840 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/05/15 13:45:54.0500 3840 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/05/15 13:45:54.0546 3840 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/05/15 13:45:54.0656 3840 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/05/15 13:45:54.0765 3840 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/05/15 13:45:54.0843 3840 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/05/15 13:45:54.0937 3840 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/05/15 13:45:55.0000 3840 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2011/05/15 13:45:55.0046 3840 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2011/05/15 13:45:55.0093 3840 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2011/05/15 13:45:55.0171 3840 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2011/05/15 13:45:55.0250 3840 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/05/15 13:45:55.0312 3840 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2011/05/15 13:45:55.0359 3840 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2011/05/15 13:45:55.0406 3840 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/05/15 13:45:55.0500 3840 ialm (5a8e05f1d5c36abd58cffa111eb325ea) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/05/15 13:45:55.0578 3840 iastor (9a65e42664d1534b68512caad0efe963) C:\WINDOWS\system32\drivers\iastor.sys 2011/05/15 13:45:55.0656 3840 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/05/15 13:45:55.0734 3840 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2011/05/15 13:45:55.0812 3840 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/05/15 13:45:55.0890 3840 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/05/15 13:45:55.0968 3840 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/05/15 13:45:56.0031 3840 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/05/15 13:45:56.0062 3840 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/05/15 13:45:56.0093 3840 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/05/15 13:45:56.0140 3840 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/05/15 13:45:56.0218 3840 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/05/15 13:45:56.0265 3840 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/05/15 13:45:56.0312 3840 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/05/15 13:45:56.0390 3840 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/05/15 13:45:56.0453 3840 klim5 (967e2224217431b21f1d04fbb4c68a4b) C:\WINDOWS\system32\DRIVERS\klim5.sys 2011/05/15 13:45:56.0531 3840 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/05/15 13:45:56.0609 3840 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/05/15 13:45:56.0750 3840 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys 2011/05/15 13:45:56.0875 3840 LVRS (e22fd7852e74f04cceb6b8a684a51f3e) C:\WINDOWS\system32\DRIVERS\lvrs.sys 2011/05/15 13:45:56.0921 3840 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys 2011/05/15 13:45:57.0109 3840 LVUVC (e89df2b88ee659954de79827ddf46dc9) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 2011/05/15 13:45:57.0234 3840 mfeavfk (26653763d99ea717fc9e069f6be6771e) C:\WINDOWS\system32\drivers\mfeavfk.sys 2011/05/15 13:45:57.0296 3840 mfebopk (e65ce1279f2c1fd9bd81184ceb7f5468) C:\WINDOWS\system32\drivers\mfebopk.sys 2011/05/15 13:45:57.0375 3840 mfehidk (f817bfca67475cf04925ece4fcf9c3c0) C:\WINDOWS\system32\drivers\mfehidk.sys 2011/05/15 13:45:57.0421 3840 mferkdk (fe03be0b990983a08a33389c00636175) C:\WINDOWS\system32\drivers\mferkdk.sys 2011/05/15 13:45:57.0484 3840 mfesmfk (9c73aca963ad8883b9fc44b410e70b71) C:\WINDOWS\system32\drivers\mfesmfk.sys 2011/05/15 13:45:57.0546 3840 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/05/15 13:45:57.0625 3840 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/05/15 13:45:57.0671 3840 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/05/15 13:45:57.0718 3840 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/05/15 13:45:57.0765 3840 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/05/15 13:45:57.0859 3840 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 2011/05/15 13:45:57.0968 3840 MpKsl38276a0d (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsl38276a0d.sys 2011/05/15 13:45:58.0046 3840 MpKsle1cb8664 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D2AF8CE-C6F3-46B5-97EB-5165A2A05573}\MpKsle1cb8664.sys 2011/05/15 13:45:58.0109 3840 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2011/05/15 13:45:58.0156 3840 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/05/15 13:45:58.0250 3840 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/05/15 13:45:58.0328 3840 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/05/15 13:45:58.0390 3840 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/05/15 13:45:58.0453 3840 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/05/15 13:45:58.0500 3840 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/05/15 13:45:58.0546 3840 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/05/15 13:45:58.0687 3840 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/05/15 13:45:58.0734 3840 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/05/15 13:45:58.0828 3840 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/05/15 13:45:58.0890 3840 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/05/15 13:45:58.0937 3840 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/05/15 13:45:58.0984 3840 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/05/15 13:45:59.0046 3840 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/05/15 13:45:59.0109 3840 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/05/15 13:45:59.0187 3840 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/05/15 13:45:59.0250 3840 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/05/15 13:45:59.0312 3840 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/05/15 13:45:59.0406 3840 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/05/15 13:45:59.0468 3840 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/05/15 13:45:59.0531 3840 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/05/15 13:45:59.0625 3840 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/05/15 13:45:59.0718 3840 nvport (df61a72d300be9274db459ebe4895eb2) C:\WINDOWS\system32\Drivers\nvport.sys 2011/05/15 13:45:59.0812 3840 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/05/15 13:45:59.0890 3840 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/05/15 13:45:59.0953 3840 PalmUSBD (803cf09c795290825607505d37819135) C:\WINDOWS\system32\drivers\PalmUSBD.sys 2011/05/15 13:46:00.0031 3840 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/05/15 13:46:00.0078 3840 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/05/15 13:46:00.0125 3840 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/05/15 13:46:00.0171 3840 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/05/15 13:46:00.0265 3840 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/05/15 13:46:00.0343 3840 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/05/15 13:46:00.0546 3840 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2011/05/15 13:46:00.0640 3840 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2011/05/15 13:46:00.0718 3840 pfc (da86016f0672ada925f589ede715f185) C:\WINDOWS\system32\drivers\pfc.sys 2011/05/15 13:46:00.0890 3840 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/05/15 13:46:00.0937 3840 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/05/15 13:46:00.0984 3840 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/05/15 13:46:01.0046 3840 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/05/15 13:46:01.0093 3840 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2011/05/15 13:46:01.0140 3840 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2011/05/15 13:46:01.0187 3840 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2011/05/15 13:46:01.0250 3840 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2011/05/15 13:46:01.0296 3840 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2011/05/15 13:46:01.0359 3840 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/05/15 13:46:01.0421 3840 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/05/15 13:46:01.0484 3840 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/05/15 13:46:01.0531 3840 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/05/15 13:46:01.0625 3840 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/05/15 13:46:01.0687 3840 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/05/15 13:46:01.0781 3840 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/05/15 13:46:01.0875 3840 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/05/15 13:46:01.0953 3840 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/05/15 13:46:02.0062 3840 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/05/15 13:46:02.0093 3840 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 2011/05/15 13:46:02.0187 3840 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/05/15 13:46:02.0250 3840 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/05/15 13:46:02.0312 3840 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/05/15 13:46:02.0406 3840 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/05/15 13:46:02.0515 3840 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2011/05/15 13:46:02.0578 3840 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/05/15 13:46:02.0687 3840 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2011/05/15 13:46:02.0734 3840 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2011/05/15 13:46:02.0843 3840 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/05/15 13:46:02.0906 3840 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys 2011/05/15 13:46:02.0968 3840 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/05/15 13:46:03.0062 3840 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/05/15 13:46:03.0125 3840 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys 2011/05/15 13:46:03.0203 3840 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/05/15 13:46:03.0250 3840 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/05/15 13:46:03.0296 3840 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/05/15 13:46:03.0359 3840 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2011/05/15 13:46:03.0406 3840 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2011/05/15 13:46:03.0453 3840 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2011/05/15 13:46:03.0500 3840 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2011/05/15 13:46:03.0578 3840 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/05/15 13:46:03.0671 3840 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/05/15 13:46:03.0750 3840 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/05/15 13:46:03.0875 3840 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/05/15 13:46:03.0953 3840 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/05/15 13:46:04.0031 3840 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2011/05/15 13:46:04.0093 3840 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/05/15 13:46:04.0156 3840 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2011/05/15 13:46:04.0234 3840 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/05/15 13:46:04.0312 3840 urvpndrv (197a7b3bb98add3e0a4c105a936385a8) C:\WINDOWS\system32\DRIVERS\covpndrv.sys 2011/05/15 13:46:04.0390 3840 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/05/15 13:46:04.0421 3840 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/05/15 13:46:04.0484 3840 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/05/15 13:46:04.0546 3840 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/05/15 13:46:04.0656 3840 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/05/15 13:46:04.0703 3840 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/05/15 13:46:04.0796 3840 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/05/15 13:46:04.0843 3840 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/05/15 13:46:04.0906 3840 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 2011/05/15 13:46:04.0953 3840 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/05/15 13:46:05.0015 3840 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2011/05/15 13:46:05.0046 3840 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 2011/05/15 13:46:05.0109 3840 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/05/15 13:46:05.0203 3840 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/05/15 13:46:05.0375 3840 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/05/15 13:46:05.0546 3840 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/05/15 13:46:05.0671 3840 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/05/15 13:46:05.0750 3840 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/05/15 13:46:05.0828 3840 ================================================================================ 2011/05/15 13:46:05.0828 3840 Scan finished 2011/05/15 13:46:05.0828 3840 ================================================================================
What are your current problems ?

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
I believe the issues have been resolved. Is there another scan you want me to run to make sure the malware/spyware is gone? Also, what can I do to better protect against future malware? Thank you for all your assistance! How do we make a donation to help support whatthetech.com? Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6586 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/15/2011 6:13:13 PM mbam-log-2011-05-15 (18-13-13).txt Scan type: Quick scan Objects scanned: 184361 Time elapsed: 6 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Nope if you are happy then so am I. Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check

[external image: Posted Image]


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

[external image: Posted Image] Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update


To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Ok - I ran OTl and the following log was presented. Also, after the reboot the attached spybot warning windows appeared. I allowed the changes.


All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator2
->Temp folder emptied: 805 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: Mattias
->Temp folder emptied: 542368 bytes
->Temporary Internet Files folder emptied: 23514622 bytes
->Java cache emptied: 488 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 3715 bytes

User: NetworkService
->Temp folder emptied: 13498 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: SarahC
->Temp folder emptied: 836 bytes
->Temporary Internet Files folder emptied: 1100685 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 136059 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 24.00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator2
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: Mattias
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: SarahC
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.22.3 log created on 05162011_151252

Files\Folders moved on Reboot…
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\ZZE41F75\iframescript[1].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\ZZE41F75\like[1].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\V5K2VCKW\ads[1].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\V5K2VCKW\iframe[1].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\NMPUD3P9\ads[4].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\NMPUD3P9\index[3].htm moved successfully.
C:\Documents and Settings\Mattias\Local Settings\Temporary Internet Files\Content.IE5\737MS3U2\ads[3].htm moved successfully.

Registry entries deleted on Reboot…


I will now proceed with the other tasks you assigned. Let me know if there is a problem with all the spybot warnings…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI