This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Removed Trojans, now can't access internet

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have used AVG 2011 free anti virus to remove two trojans. When prompted to remove a third file my internet connection didn't work. What do I do to restore my internet connection?
Try doing a system restore to before the file removal

then post the start up logs so we can clean your system safely

http://bertk.mvps.org/html/restoresysv.html

If you still cannot connect, download the following programs to USB and transfer them to the infected machine and run them

next


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
I have given you the links for the programs do you have access to another machine where you can download them, and then transfer to the infected machine via USB?
Here are the text files as requested:-

1)DDS

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 14:21:36 on 2011-08-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1875 [GMT 1:00]
.
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Packard bell\SAXO27\HIDSERVICE.EXE
C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\WinTV\TVServer\CaptureGenPCI.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Packard Bell\SrvCDEject.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\WinTV\WinTV7\WinTVTray.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uStart Page = hxxp://www.yahoo.co.uk/
uDefault_Page_URL = hxxp://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=8&key=IESTART
uInternet Settings,ProxyServer = http=127.0.0.1:51859
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [SmpcSys] c:\program files\packard bell\setupmypc\SmpSys.exe
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe" -autorun
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [toolbar_eula_launcher] c:\program files\packard bell\google_eula\EULALauncher.exe
mRun: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
StartupFolder: c:\users\a\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\a\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autost~1.lnk - c:\program files\wintv\Ir.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wintvr~1.lnk - c:\program files\wintv\wintv7\WinTVTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{CB6D968A-C038-48F9-9FF9-9C4B4268601A} : DhcpNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2010\HelpAsyncPluggableProtocol.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\a\appdata\roaming\mozilla\firefox\profiles\914ez3ua.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 51859
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\users\a\appdata\local\yahoo!\browserplus\2.8.1\plugins\npybrowserplus_2.8.1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
============= SERVICES / DRIVERS ===============
.
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20091110.002\IDSvix86.sys [2009-11-12 272432]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-9-4 21504]
R2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\wintv\tvserver\HauppaugeTVServer.exe [2011-6-25 562176]
R2 SrvCDEject;SrvCDEject;c:\program files\packard bell\SrvCDEject.exe [2008-2-11 600064]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2008-10-9 14336]
R3 HCW713x;Hauppauge WinTV-HVR 713X PCI Card;c:\windows\system32\drivers\HCW713x.sys [2011-7-5 1156736]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2008-2-11 1251720]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2007-5-18 38200]
S3 Ph3xIB32;Philips 713x VU PCI TV Card;c:\windows\system32\drivers\Ph3xIB32.sys [2007-4-3 1131136]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2011-08-23 18:16:59 386560 —-a-w- c:\program files\internet explorer\jsdbgui.dll
2011-08-23 18:16:59 22016 —-a-w- c:\program files\internet explorer\ExtExport.exe
2011-08-23 18:16:59 149504 —-a-w- c:\program files\internet explorer\jsprofilerui.dll
2011-08-23 18:16:59 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-08-23 18:14:16 ——– d–h–w- C:\$AVG
2011-08-23 17:53:55 ——– d—–w- c:\users\a\appdata\roaming\AVG10
2011-08-23 17:50:59 ——– d—–w- c:\windows\system32\drivers\AVG
2011-08-23 17:50:59 ——– d—–w- c:\programdata\AVG10
2011-08-23 17:49:24 ——– d—–w- c:\program files\AVG
2011-08-23 17:42:27 ——– d—–w- c:\programdata\MFAData
2011-08-23 17:42:13 6962000 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{0ab04d74-d5de-4a8a-84b7-bc969b056a4c}\mpengine.dll
2011-08-12 13:36:40 ——– d—–w- c:\users\a\appdata\local\Graboid_Inc
2011-08-12 13:36:39 ——– d—–w- c:\users\a\appdata\local\Graboid
2011-08-12 13:36:31 ——– d—–w- c:\users\a\appdata\local\Geckofx
2011-08-12 13:30:41 ——– d—–w- c:\program files\Graboid
.
==================== Find3M ====================
.
2011-08-27 10:16:34 140624 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-08-27 10:12:28 266752 —-a-w- c:\windows\system32\PnkBstrB.xtr
2011-08-27 10:12:28 266752 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-08-21 13:46:09 266752 —-a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-03 09:37:03 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 13:34:49 2043392 —-a-w- c:\windows\system32\win32k.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: ST3360320AS rev.3.AAM -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84D941F8]<<
_asm { MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX; PUSH 0x84d94008; MOV EAX, 0x806ab2f8; CALL EAX; }
1 ntkrnlpa!IofCallDriver[0x8224F912] -> \Device\Harddisk0\DR0[0x8648EA70]
3 CLASSPNP[0x8ABB98B3] -> ntkrnlpa!IofCallDriver[0x8224F912] -> [0x85881A70]
5 acpi[0x805BD6BC] -> ntkrnlpa!IofCallDriver[0x8224F912] -> \Device\Ide\IdeDeviceP0T0L0-0[0x85854B98]
\Driver\atapi[0x85878D40] -> IRP_MJ_CREATE -> 0x84D941F8
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
detected disk devices:
detected hooks:
\Driver\atapi -> 0x84d941f8
user != kernel MBR !!!
Warning: possible MBR rootkit infection !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 14:21:51.54 ===============

2) Attach

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 20/08/2009 20:20:15
System Uptime: 28/08/2011 14:13:19 (0 hours ago)
.
Motherboard: Packard Bell BV | | PT890-8237A
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | Socket 775 | 2400/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 327 GiB total, 210.567 GiB free.
D: is FIXED (NTFS) - 335 GiB total, 326.691 GiB free.
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is CDROM (UDF)
J: is CDROM ()
K: is Removable
L: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP363: 05/08/2011 13:37:26 - Scheduled Checkpoint
RP364: 07/08/2011 17:08:08 - Scheduled Checkpoint
RP366: 08/08/2011 15:35:53 - Installed Battlefield 2142 Update v1.51
RP368: 10/08/2011 13:57:31 - Configured Battlefield 2142
RP370: 10/08/2011 13:58:21 - Removed Battlefield 2142
RP372: 10/08/2011 14:04:02 - Installed Battlefield 2142
RP373: 10/08/2011 14:13:33 - Installed GameSpy Comrade
RP375: 10/08/2011 14:14:42 - Installed DirectX
RP377: 10/08/2011 14:47:09 - Installed Battlefield 2142 Update v1.50
RP378: 12/08/2011 11:33:33 - Windows Update
RP379: 12/08/2011 12:47:35 - Restore Operation
RP381: 14/08/2011 11:06:51 - Installed Battlefield 2142 Update v1.50
RP383: 14/08/2011 12:11:38 - Installed Battlefield 2142 Update v1.51
RP384: 20/08/2011 18:44:23 - Scheduled Checkpoint
RP386: 23/08/2011 17:16:03 - Windows Defender Checkpoint
RP387: 23/08/2011 18:01:51 - Windows Update
RP389: 23/08/2011 18:04:11 - Windows Defender Checkpoint
RP390: 23/08/2011 18:13:51 - Restore Operation
RP391: 23/08/2011 18:28:34 - Windows Update
RP393: 23/08/2011 18:30:51 - Windows Defender Checkpoint
RP394: 23/08/2011 18:36:03 - Restore Operation
RP395: 23/08/2011 18:49:13 - Installed AVG 2011
RP396: 23/08/2011 18:49:41 - Installed AVG 2011
RP397: 23/08/2011 19:09:12 - Windows Update
RP398: 23/08/2011 20:11:50 - Restore Operation
RP399: 23/08/2011 20:32:43 - Restore Operation
RP400: 23/08/2011 21:05:16 - Restore Operation
RP401: 27/08/2011 14:14:52 - Restore Operation
RP402: 27/08/2011 14:29:43 - Restore Operation
RP403: 27/08/2011 14:47:55 - Removed AVG 2011
RP404: 27/08/2011 14:51:27 - Removed AVG 2011
RP405: 27/08/2011 15:08:45 - Restore Operation
.
==== Installed Programs ======================
.
.
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 9 Plugin
Adobe Media Player
Adobe Photoshop CS5
Adobe Reader 8
Adobe Shockwave Player
Antivirus Scan Ultimate
AppCore
AV
Battlefield 2142
Battlefield: Bad Company™ 2
Canon ScanGear Starter
CanoScan Toolbox Ver4.9
ccCommon
Compatibility Pack for the 2007 Office system
Creator 9
DeadLine Equation Solver
Excel Password Recovery 2.2
Fallout 3
Firefox
Flash Player 9 Internet Explorer
GameSpy Comrade
GearDrvs
Graph 4.3
Hauppauge MCE XP/Vista Software Encoder (2.0.28104)
Hauppauge WinTV 7
HDReg
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Infocentre Rev. 2.0
IrfanView (remove only)
ISO Recorder
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
MagicDisc 2.7.105
Metaboli
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Works
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.10)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Norton 360
Norton 360 (Symantec Corporation)
Norton 360 Help
Norton Confidential Browser Component
Norton Confidential Web Authentification Component
Norton Confidential Web Protection Component
NVIDIA Drivers
OF Dragon Rising
Packard Bell ImageWriter
Packard Bell LCD Test
Packard Bell Updator
PasswordTools
PDF Settings CS5
Picasa2
PunkBuster Services
QuickBooks
QuickBooks SimpleStart Free Limited Editon
RAR Password Recovery 5.0
Realtek HD Audio V6.0.1.5377
Realtek High Definition Audio Driver
Roxio Creator 9 LE
S.T.A.L.K.E.R. - Clear Sky
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio 3
SeaTools for Windows
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
SetUp My PC
Shockwave player 10
Sib Font Editor
SPBBC 32bit
Spotify
Stellar Phoenix Zip Recovery v1.0
SupportSoft Assisted Service
SuppSoft
Symantec Real Time Storage Protection Component
Symantec Technical Support Controls
SymNet
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
USB 3G Super GSM Reader II v2.8.8
USB 3G Super GSM Reader II v2.8.8 (C:\Program Files\3G Super GSM Reader II v2.8.8\)
USB 3G Super GSM Reader II v2.8.8 (C:\Program Files\3G Super GSM Reader II v2.8.8\) #3
USB 3G Super GSM Reader II v2.8.8 (C:\Program Files\3G Super GSM Reader II v2.8.8\) #4
Video NVIDIA v162.22
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Zip Password Recovery Processor
VLC media player 1.0.1
Vodafone Mobile Connect Lite
WinRAR archiver
Yahoo! BrowserPlus 2.8.1
Zip Files Opener 1.0
Zip Password Recovery - Ver: 1.42
Zip Password Recovery 2.2
Zip Password Tool v. 2.3
Zip Recovery Toolbox 1.0
.
==== Event Viewer Messages From Past Week ========
.
27/08/2011 15:07:02, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Modules Installer service to connect.
27/08/2011 15:07:02, Error: Service Control Manager [7000] - The Windows Modules Installer service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
27/08/2011 15:07:02, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service TrustedInstaller with arguments "" in order to run the server: {752073A1-23F2-4396-85F0-8FDB879ED0ED}
27/08/2011 14:31:56, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\??\Volume{d410325d-8dbd-11de-8aaa-806e6f6e6963}\System Volume Information\SystemRestore\New-software' was corrupted and it has been recovered. Some data might have been lost.
27/08/2011 14:27:29, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Center Scheduler Service service to connect.
27/08/2011 14:27:28, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service ehSched with arguments "-Service" in order to run the server: {4B635ECB-0887-4015-8CA6-D621362F98D1}
27/08/2011 14:26:36, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
27/08/2011 14:26:36, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
27/08/2011 11:09:02, Error: EventLog [6008] - The previous system shutdown at 11:07:08 on 27/08/2011 was unexpected.
23/08/2011 19:18:55, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows Vista (KB2567680).
23/08/2011 19:18:49, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2567680 (Security Update) into Resolving(Resolving) state
23/08/2011 19:18:49, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2567680 (Security Update) into Absent(Absent) state
23/08/2011 19:18:29, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows Vista (KB2536276).
23/08/2011 19:18:23, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2536276 (Security Update) into Resolving(Resolving) state
23/08/2011 19:18:23, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2536276 (Security Update) into Installed(Installed) state
23/08/2011 19:18:23, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2536276 (Security Update) into Absent(Absent) state
23/08/2011 19:16:02, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows Vista (KB2510531).
23/08/2011 19:15:57, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2510531 (Security Update) into Resolving(Resolving) state
23/08/2011 19:15:57, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2510531 (Security Update) into Absent(Absent) state
23/08/2011 19:15:56, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2510531-4_neutral_GDR from package KB2510531(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:56, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2510531-3_neutral_LDR from package KB2510531(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:56, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2510531-2_neutral_GDR from package KB2510531(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:56, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2510531-1_neutral_LDR from package KB2510531(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:55, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for .NET Framework 3.5 SP1, Windows Vista SP2, and Windows Server 2008 SP2 x86 (KB2518866).
23/08/2011 19:15:49, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2518866 (Security Update) into Resolving(Resolving) state
23/08/2011 19:15:49, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2518866 (Security Update) into Absent(Absent) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-9_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-8_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-7_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-6_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-5_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-4_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-36_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-35_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-34_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-33_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-3_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-2_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-12_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-11_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-10_neutral_GDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:48, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2518866-1_neutral_LDR from package KB2518866(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:39, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Internet Explorer 8 for Windows Vista (KB2544521).
23/08/2011 19:15:34, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2544521 (Security Update) into Resolving(Resolving) state
23/08/2011 19:15:34, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2544521 (Security Update) into Absent(Absent) state
23/08/2011 19:15:33, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2544521-2_neutral_GDR from package KB2544521(Security Update) into Resolving(Resolving) state
23/08/2011 19:15:33, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2544521-1_neutral_LDR from package KB2544521(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:14, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Cumulative Security Update for Internet Explorer 8 for Windows Vista (KB2559049).
23/08/2011 19:12:08, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2559049 (Security Update) into Resolving(Resolving) state
23/08/2011 19:12:08, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2559049 (Security Update) into Absent(Absent) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-9_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-8_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-7_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-6_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-5_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-48_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-47_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-46_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-45_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-44_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-43_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-42_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-41_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-40_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-4_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-39_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-38_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-37_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-36_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-35_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-34_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-33_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-32_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-31_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-30_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-3_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-29_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-28_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-27_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-26_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-25_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-24_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-23_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-22_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-21_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-20_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-2_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-19_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-18_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-17_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-16_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-15_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-14_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-13_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-12_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-11_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-10_neutral_GDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:12:03, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2559049-1_neutral_LDR from package KB2559049(Security Update) into Resolving(Resolving) state
23/08/2011 19:11:37, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Microsoft .NET Framework 2.0 SP2 on Windows Vista SP2 and Windows Server 2008 SP2 x86 (KB2539633).
23/08/2011 19:11:32, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2539633 (Security Update) into Resolving(Resolving) state
23/08/2011 19:11:32, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2539633 (Security Update) into Absent(Absent) state
23/08/2011 19:10:38, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2539633-2_neutral_GDR from package KB2539633(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:38, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2539633-14_neutral_GDR from package KB2539633(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:38, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2539633-13_neutral_LDR from package KB2539633(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:38, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2539633-1_neutral_LDR from package KB2539633(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:28, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows Vista (KB2556532).
23/08/2011 19:10:23, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2556532 (Security Update) into Resolving(Resolving) state
23/08/2011 19:10:23, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2556532 (Security Update) into Absent(Absent) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-6_neutral_GDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-5_neutral_LDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-4_neutral_LDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-3_neutral_GDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-2_neutral_LDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:21, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2556532-1_neutral_LDR from package KB2556532(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:18, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows Vista (KB2563894).
23/08/2011 19:10:13, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2563894 (Security Update) into Resolving(Resolving) state
23/08/2011 19:10:13, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2563894 (Security Update) into Absent(Absent) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-6_neutral_GDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-5_neutral_LDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-4_neutral_LDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-3_neutral_GDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-2_neutral_LDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:10:11, Error: Microsoft-Windows-Servicing [4385] - Windows Servicing failed to complete the process of changing update 2563894-1_neutral_LDR from package KB2563894(Security Update) into Resolving(Resolving) state
23/08/2011 19:02:39, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
23/08/2011 18:42:13, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.107.1837.0 Loading engine version: 1.1.6903.0
23/08/2011 18:31:04, Error: Microsoft-Windows-Windows Defender [3006] - Windows Defender Real-Time Protection agent has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…threatid=155167 Scan ID: {EA63E718-924C-4156-97A9-CAC46A8560EB} User: a-PC\a Name: Backdoor:Win32/Cycbot.B ID: 155167 Severity ID: 5 Category ID: 6 Path: Alert Type: Spyware or other potentially unwanted software Action: Remove Error Code: 0x80508022 Error description: To finish removing spyware and other potentially unwanted software, restart the computer.
23/08/2011 18:23:46, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.107.1837.0 Loading engine version: 1.1.6903.0
23/08/2011 18:04:24, Error: Microsoft-Windows-Windows Defender [3006] - Windows Defender Real-Time Protection agent has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…threatid=155167 Scan ID: {6AEF03B5-15FF-42A4-AEAE-C9C39F864613} User: a-PC\a Name: Backdoor:Win32/Cycbot.B ID: 155167 Severity ID: 5 Category ID: 6 Path: Alert Type: Spyware or other potentially unwanted software Action: Remove Error Code: 0x80508022 Error description: To finish removing spyware and other potentially unwanted software, restart the computer.
21/08/2011 14:40:28, Error: EventLog [6008] - The previous system shutdown at 14:38:16 on 21/08/2011 was unexpected.
21/08/2011 14:06:24, Error: EventLog [6008] - The previous system shutdown at 14:04:47 on 21/08/2011 was unexpected.
.
==== End Of File ===========================

3) aswMBR text file

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-08-28 14:23:00
—————————–
14:23:00.714 OS Version: Windows 6.0.6002 Service Pack 2
14:23:00.714 Number of processors: 4 586 0xF0B
14:23:00.714 ComputerName: A-PC UserName: a
14:23:01.509 Initialize success
14:23:11.579 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:23:11.579 Disk 0 Vendor: ST3360320AS 3.AAM Size: 343399MB BusType: 3
14:23:11.595 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1
14:23:11.595 Disk 1 Vendor: ST3360320AS 3.AAM Size: 343399MB BusType: 3
14:23:13.639 Disk 0 MBR read successfully
14:23:13.654 Disk 0 MBR scan
14:23:13.654 Disk 0 Windows VISTA default MBR code
14:23:13.685 Disk 0 scanning sectors +703279104
14:23:13.748 Disk 0 scanning C:\Windows\system32\drivers
14:23:21.563 Service scanning
14:23:22.359 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
14:23:22.936 Modules scanning
14:23:28.474 Disk 0 trace - called modules:
14:23:28.505 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84d941f8]<<
14:23:28.505 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8648ea70]
14:23:28.505 3 CLASSPNP.SYS[8abb98b3] -> nt!IofCallDriver -> [0x85881a70]
14:23:28.521 5 acpi.sys[805bd6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85854b98]
14:23:28.521 \Driver\atapi[0x85878d40] -> IRP_MJ_CREATE -> 0x84d941f8
14:23:28.521 Scan finished successfully
14:24:05.477 Disk 0 MBR has been saved successfully to "K:\MBR.dat"
14:24:05.477 The log file has been saved successfully to "K:\aswMBR.txt"

Thanks for alll your help
Hi

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT


Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Hello. The internet connection is working now! Thank you very much indeed! Here are the logs as requested.

1) TDS Log:-

2011/08/29 09:53:02.0032 3440 TDSS rootkit removing tool 2.5.17.0 Aug 22 2011 15:46:57
2011/08/29 09:53:02.0048 3440 ================================================================================
2011/08/29 09:53:02.0048 3440 SystemInfo:
2011/08/29 09:53:02.0048 3440
2011/08/29 09:53:02.0048 3440 OS Version: 6.0.6002 ServicePack: 2.0
2011/08/29 09:53:02.0048 3440 Product type: Workstation
2011/08/29 09:53:02.0048 3440 ComputerName: A-PC
2011/08/29 09:53:02.0048 3440 UserName: a
2011/08/29 09:53:02.0048 3440 Windows directory: C:\Windows
2011/08/29 09:53:02.0048 3440 System windows directory: C:\Windows
2011/08/29 09:53:02.0048 3440 Processor architecture: Intel x86
2011/08/29 09:53:02.0048 3440 Number of processors: 4
2011/08/29 09:53:02.0048 3440 Page size: 0x1000
2011/08/29 09:53:02.0048 3440 Boot type: Normal boot
2011/08/29 09:53:02.0048 3440 ================================================================================
2011/08/29 09:53:03.0280 3440 Initialize success
2011/08/29 09:53:07.0773 1160 ================================================================================
2011/08/29 09:53:07.0773 1160 Scan started
2011/08/29 09:53:07.0773 1160 Mode: Manual;
2011/08/29 09:53:07.0773 1160 ================================================================================
2011/08/29 09:53:09.0162 1160 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/08/29 09:53:09.0645 1160 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2011/08/29 09:53:09.0910 1160 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2011/08/29 09:53:10.0254 1160 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2011/08/29 09:53:10.0519 1160 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2011/08/29 09:53:10.0878 1160 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
2011/08/29 09:53:11.0002 1160 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/08/29 09:53:11.0127 1160 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2011/08/29 09:53:11.0299 1160 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2011/08/29 09:53:11.0346 1160 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2011/08/29 09:53:11.0392 1160 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2011/08/29 09:53:11.0408 1160 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2011/08/29 09:53:11.0439 1160 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2011/08/29 09:53:11.0486 1160 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2011/08/29 09:53:11.0533 1160 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/08/29 09:53:11.0580 1160 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/08/29 09:53:11.0642 1160 atksgt (f9c24d25d9ff29f894995a64812b4d85) C:\Windows\system32\DRIVERS\atksgt.sys
2011/08/29 09:53:11.0845 1160 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/08/29 09:53:11.0938 1160 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/08/29 09:53:12.0079 1160 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/08/29 09:53:12.0126 1160 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/08/29 09:53:12.0172 1160 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/08/29 09:53:12.0219 1160 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/08/29 09:53:12.0266 1160 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/08/29 09:53:12.0344 1160 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/08/29 09:53:12.0406 1160 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/08/29 09:53:12.0516 1160 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/08/29 09:53:12.0609 1160 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/08/29 09:53:12.0656 1160 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2011/08/29 09:53:12.0703 1160 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/08/29 09:53:12.0750 1160 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2011/08/29 09:53:12.0796 1160 Compbatt (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\drivers\compbatt.sys
2011/08/29 09:53:12.0843 1160 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2011/08/29 09:53:12.0874 1160 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2011/08/29 09:53:13.0062 1160 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
2011/08/29 09:53:13.0264 1160 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/08/29 09:53:13.0452 1160 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/08/29 09:53:13.0623 1160 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/08/29 09:53:13.0732 1160 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/08/29 09:53:13.0935 1160 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/08/29 09:53:14.0122 1160 eeCtrl (96bcd90ed9235a21629effde5e941fb1) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/08/29 09:53:14.0637 1160 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2011/08/29 09:53:14.0918 1160 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/08/29 09:53:15.0074 1160 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/08/29 09:53:15.0246 1160 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2011/08/29 09:53:15.0433 1160 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/08/29 09:53:15.0480 1160 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/08/29 09:53:15.0526 1160 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/08/29 09:53:15.0604 1160 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/08/29 09:53:15.0698 1160 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/08/29 09:53:15.0745 1160 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2011/08/29 09:53:15.0792 1160 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2011/08/29 09:53:15.0932 1160 HCW713x (61066edf92bff63e63b119e084bc578a) C:\Windows\system32\DRIVERS\HCW713x.sys
2011/08/29 09:53:16.0150 1160 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/08/29 09:53:16.0213 1160 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/08/29 09:53:16.0260 1160 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/08/29 09:53:16.0306 1160 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/08/29 09:53:16.0384 1160 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2011/08/29 09:53:16.0447 1160 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/08/29 09:53:16.0525 1160 hwdatacard (4154079a88089155d10168333b19627f) C:\Windows\system32\DRIVERS\ewusbmdm.sys
2011/08/29 09:53:16.0587 1160 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2011/08/29 09:53:16.0665 1160 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/08/29 09:53:16.0712 1160 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2011/08/29 09:53:16.0946 1160 IDSvix86 (74f2b7d99b8613eac36edf22a2ab3b08) C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20091110.002\IDSvix86.sys
2011/08/29 09:53:17.0102 1160 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/08/29 09:53:17.0757 1160 IntcAzAudAddService (4a705bf2a6f7972f2f2ad8a0d8079f95) C:\Windows\system32\drivers\RTKVHDA.sys
2011/08/29 09:53:18.0007 1160 intelide (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
2011/08/29 09:53:18.0132 1160 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/08/29 09:53:18.0319 1160 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/08/29 09:53:18.0475 1160 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2011/08/29 09:53:18.0600 1160 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/08/29 09:53:18.0927 1160 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/08/29 09:53:19.0177 1160 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2011/08/29 09:53:19.0364 1160 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/08/29 09:53:19.0426 1160 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/08/29 09:53:19.0489 1160 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/08/29 09:53:19.0536 1160 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/08/29 09:53:19.0926 1160 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/08/29 09:53:20.0238 1160 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/08/29 09:53:20.0409 1160 lirsgt (8ccf9ed46d52af1375875f74a91ffacf) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/08/29 09:53:20.0596 1160 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/08/29 09:53:20.0830 1160 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2011/08/29 09:53:20.0893 1160 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2011/08/29 09:53:20.0971 1160 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2011/08/29 09:53:21.0080 1160 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/08/29 09:53:21.0174 1160 mcdbus (af61a1c34e2d3f7543f9ccfc323170b8) C:\Windows\system32\DRIVERS\mcdbus.sys
2011/08/29 09:53:21.0252 1160 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2011/08/29 09:53:21.0298 1160 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/08/29 09:53:21.0376 1160 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/08/29 09:53:21.0423 1160 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/08/29 09:53:21.0548 1160 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/08/29 09:53:21.0610 1160 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/08/29 09:53:21.0688 1160 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2011/08/29 09:53:21.0735 1160 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/08/29 09:53:21.0766 1160 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/08/29 09:53:21.0813 1160 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/08/29 09:53:22.0219 1160 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/08/29 09:53:22.0734 1160 mrxsmb10 (d4a3c7c580c4ccb5c06f2ada933ad507) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/08/29 09:53:23.0217 1160 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/08/29 09:53:23.0451 1160 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
2011/08/29 09:53:23.0779 1160 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2011/08/29 09:53:23.0997 1160 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/08/29 09:53:24.0138 1160 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/08/29 09:53:24.0559 1160 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/08/29 09:53:24.0933 1160 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/08/29 09:53:25.0214 1160 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/08/29 09:53:25.0292 1160 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/08/29 09:53:25.0464 1160 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/08/29 09:53:25.0947 1160 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/08/29 09:53:26.0119 1160 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/08/29 09:53:26.0384 1160 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/08/29 09:53:27.0133 1160 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/08/29 09:53:27.0289 1160 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/08/29 09:53:27.0460 1160 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/08/29 09:53:28.0006 1160 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/08/29 09:53:28.0116 1160 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/08/29 09:53:28.0209 1160 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/08/29 09:53:28.0381 1160 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/08/29 09:53:28.0474 1160 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/08/29 09:53:28.0537 1160 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/08/29 09:53:28.0599 1160 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/08/29 09:53:29.0020 1160 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/08/29 09:53:29.0208 1160 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/08/29 09:53:29.0457 1160 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/08/29 09:53:30.0939 1160 nvlddmkm (484844c0d892b42ecc5e6b063d072a38) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/08/29 09:53:31.0470 1160 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2011/08/29 09:53:31.0579 1160 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2011/08/29 09:53:31.0672 1160 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2011/08/29 09:53:31.0828 1160 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/08/29 09:53:31.0922 1160 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/08/29 09:53:31.0984 1160 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/08/29 09:53:32.0047 1160 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/08/29 09:53:32.0094 1160 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/08/29 09:53:32.0125 1160 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2011/08/29 09:53:32.0156 1160 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/08/29 09:53:32.0328 1160 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/08/29 09:53:32.0858 1160 Ph3xIB32 (9f2f541c52cd7a452e235e885f7d95de) C:\Windows\system32\DRIVERS\Ph3xIB32.sys
2011/08/29 09:53:33.0232 1160 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/08/29 09:53:33.0342 1160 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2011/08/29 09:53:33.0498 1160 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/08/29 09:53:33.0841 1160 PxHelp20 (f7bb4e7a7c02ab4a2672937e124e306e) C:\Windows\system32\Drivers\PxHelp20.sys
2011/08/29 09:53:34.0215 1160 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2011/08/29 09:53:34.0371 1160 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/08/29 09:53:34.0543 1160 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/08/29 09:53:34.0605 1160 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/08/29 09:53:34.0652 1160 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/08/29 09:53:34.0792 1160 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/08/29 09:53:34.0870 1160 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/08/29 09:53:34.0948 1160 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/08/29 09:53:34.0980 1160 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/08/29 09:53:35.0026 1160 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2011/08/29 09:53:35.0058 1160 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/08/29 09:53:35.0089 1160 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/08/29 09:53:35.0338 1160 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/08/29 09:53:35.0432 1160 RTL8023xp (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys
2011/08/29 09:53:35.0650 1160 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/08/29 09:53:35.0728 1160 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/08/29 09:53:35.0791 1160 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/08/29 09:53:35.0838 1160 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/08/29 09:53:36.0165 1160 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/08/29 09:53:36.0415 1160 sffdisk (51cf56aa8bcc241f134b420b8f850406) C:\Windows\system32\drivers\sffdisk.sys
2011/08/29 09:53:36.0508 1160 sffp_mmc (96ded8b20c734ac41641ce275250e55d) C:\Windows\system32\drivers\sffp_mmc.sys
2011/08/29 09:53:36.0571 1160 sffp_sd (8b08cab1267b2c377883fc9e56981f90) C:\Windows\system32\drivers\sffp_sd.sys
2011/08/29 09:53:36.0633 1160 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/08/29 09:53:36.0883 1160 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2011/08/29 09:53:36.0930 1160 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2011/08/29 09:53:37.0023 1160 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/08/29 09:53:37.0257 1160 SPBBCDrv (cdea9a0a0e547fef4c44ccae35a9b09c) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
2011/08/29 09:53:37.0554 1160 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/08/29 09:53:37.0850 1160 sptd (a80cd850d69d996c832bea37e3a6aa1e) C:\Windows\system32\Drivers\sptd.sys
2011/08/29 09:53:37.0850 1160 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: a80cd850d69d996c832bea37e3a6aa1e
2011/08/29 09:53:37.0866 1160 sptd - detected LockedFile.Multi.Generic (1)
2011/08/29 09:53:38.0380 1160 SRTSP (655773f2f1a3730c6cf20280a49f4ee1) C:\Windows\system32\Drivers\SRTSP.SYS
2011/08/29 09:53:38.0708 1160 SRTSPL (2a0aaf370d4c6574a34ae2f4a0709cae) C:\Windows\system32\Drivers\SRTSPL.SYS
2011/08/29 09:53:38.0802 1160 SRTSPX (3104bdceace2d5710776dd05e6a286c1) C:\Windows\system32\Drivers\SRTSPX.SYS
2011/08/29 09:53:39.0160 1160 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/08/29 09:53:39.0363 1160 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
2011/08/29 09:53:39.0504 1160 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
2011/08/29 09:53:39.0597 1160 ssm_bus (14622ae81c72b08691eedaabc1d4a129) C:\Windows\system32\DRIVERS\ssm_bus.sys
2011/08/29 09:53:39.0738 1160 ssm_mdfl (43ee5e9fda61a5e0eac4c1de699e6e4d) C:\Windows\system32\DRIVERS\ssm_mdfl.sys
2011/08/29 09:53:39.0816 1160 ssm_mdm (918cfd32c7feb174f356a0a6fad11f4b) C:\Windows\system32\DRIVERS\ssm_mdm.sys
2011/08/29 09:53:39.0940 1160 StarOpen (306521935042fc0a6988d528643619b3) C:\Windows\system32\drivers\StarOpen.sys
2011/08/29 09:53:40.0065 1160 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/08/29 09:53:40.0190 1160 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/08/29 09:53:40.0268 1160 SYMDNS (a16d76baa5d2cbe45c57fa582c1208e5) C:\Windows\System32\Drivers\SYMDNS.SYS
2011/08/29 09:53:40.0393 1160 SymEvent (06b95820df51502099a8a15c93e87986) C:\Windows\system32\Drivers\SYMEVENT.SYS
2011/08/29 09:53:40.0486 1160 SYMFW (c64d200569a18ea6c676266dee3ac158) C:\Windows\System32\Drivers\SYMFW.SYS
2011/08/29 09:53:40.0580 1160 SYMIDS (7764d3d7a3c858f04ced3c1f16410d89) C:\Windows\System32\Drivers\SYMIDS.SYS
2011/08/29 09:53:40.0642 1160 SYMNDISV (d193684004658fe4f3f143ca6dd9ef8b) C:\Windows\System32\Drivers\SYMNDISV.SYS
2011/08/29 09:53:40.0689 1160 SYMREDRV (829830a3ca1c5e329d68e26c9cd2de8d) C:\Windows\System32\Drivers\SYMREDRV.SYS
2011/08/29 09:53:40.0705 1160 SYMTDI (b1aa9704124b494c34e8d372e6654196) C:\Windows\System32\Drivers\SYMTDI.SYS
2011/08/29 09:53:40.0892 1160 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/08/29 09:53:41.0001 1160 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/08/29 09:53:41.0282 1160 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/08/29 09:53:41.0672 1160 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/08/29 09:53:41.0906 1160 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/08/29 09:53:42.0109 1160 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/08/29 09:53:42.0296 1160 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/08/29 09:53:42.0390 1160 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/08/29 09:53:42.0514 1160 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/08/29 09:53:42.0717 1160 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/08/29 09:53:43.0029 1160 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/08/29 09:53:43.0123 1160 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/08/29 09:53:43.0232 1160 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\DRIVERS\uagp35.sys
2011/08/29 09:53:43.0326 1160 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/08/29 09:53:43.0700 1160 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2011/08/29 09:53:43.0762 1160 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2011/08/29 09:53:43.0809 1160 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/08/29 09:53:43.0856 1160 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/08/29 09:53:43.0918 1160 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/08/29 09:53:43.0981 1160 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/08/29 09:53:44.0028 1160 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/08/29 09:53:44.0137 1160 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/08/29 09:53:44.0340 1160 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/08/29 09:53:44.0449 1160 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/08/29 09:53:44.0496 1160 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/08/29 09:53:44.0558 1160 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/08/29 09:53:44.0620 1160 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/08/29 09:53:44.0901 1160 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/08/29 09:53:45.0088 1160 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/08/29 09:53:45.0182 1160 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/08/29 09:53:45.0244 1160 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2011/08/29 09:53:45.0276 1160 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2011/08/29 09:53:45.0322 1160 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/08/29 09:53:45.0385 1160 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/08/29 09:53:45.0478 1160 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/08/29 09:53:45.0525 1160 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/08/29 09:53:45.0619 1160 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2011/08/29 09:53:45.0837 1160 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/08/29 09:53:45.0884 1160 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/29 09:53:45.0931 1160 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/29 09:53:46.0009 1160 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2011/08/29 09:53:46.0071 1160 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/08/29 09:53:46.0383 1160 WmiAcpi (17eac0d023a65fa9b02114cc2baacad5) C:\Windows\system32\drivers\wmiacpi.sys
2011/08/29 09:53:46.0492 1160 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/08/29 09:53:46.0633 1160 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/08/29 09:53:46.0711 1160 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
2011/08/29 09:53:46.0742 1160 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
2011/08/29 09:53:46.0758 1160 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk6\DR6
2011/08/29 09:53:46.0804 1160 Boot (0x1200) (c393a99ff47b742f69541788e31131b1) \Device\Harddisk0\DR0\Partition0
2011/08/29 09:53:46.0820 1160 Boot (0x1200) (ad22eb355df71aa5b5f00490ea2b3d72) \Device\Harddisk1\DR1\Partition0
2011/08/29 09:53:46.0836 1160 Boot (0x1200) (3764430ada0d058ce8c6d6f718a2058b) \Device\Harddisk6\DR6\Partition0
2011/08/29 09:53:46.0851 1160 ================================================================================
2011/08/29 09:53:46.0851 1160 Scan finished
2011/08/29 09:53:46.0851 1160 ================================================================================
2011/08/29 09:53:46.0867 3632 Detected object count: 1
2011/08/29 09:53:46.0867 3632 Actual detected object count: 1
2011/08/29 09:55:15.0537 3632 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/08/29 09:55:21.0606 5160 ================================================================================
2011/08/29 09:55:21.0606 5160 Scan started
2011/08/29 09:55:21.0606 5160 Mode: Manual;
2011/08/29 09:55:21.0606 5160 ================================================================================
2011/08/29 09:55:22.0354 5160 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/08/29 09:55:22.0604 5160 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
2011/08/29 09:55:22.0698 5160 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
2011/08/29 09:55:22.0932 5160 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
2011/08/29 09:55:22.0994 5160 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
2011/08/29 09:55:23.0337 5160 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
2011/08/29 09:55:23.0384 5160 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/08/29 09:55:23.0696 5160 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
2011/08/29 09:55:23.0758 5160 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
2011/08/29 09:55:23.0977 5160 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
2011/08/29 09:55:24.0211 5160 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
2011/08/29 09:55:24.0367 5160 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys
2011/08/29 09:55:24.0601 5160 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
2011/08/29 09:55:24.0741 5160 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
2011/08/29 09:55:24.0913 5160 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/08/29 09:55:25.0147 5160 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/08/29 09:55:25.0350 5160 atksgt (f9c24d25d9ff29f894995a64812b4d85) C:\Windows\system32\DRIVERS\atksgt.sys
2011/08/29 09:55:25.0537 5160 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/08/29 09:55:25.0755 5160 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/08/29 09:55:25.0896 5160 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/08/29 09:55:26.0270 5160 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/08/29 09:55:26.0379 5160 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/08/29 09:55:26.0410 5160 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/08/29 09:55:26.0520 5160 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/08/29 09:55:26.0722 5160 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/08/29 09:55:26.0800 5160 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/08/29 09:55:26.0910 5160 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/08/29 09:55:27.0019 5160 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/08/29 09:55:27.0066 5160 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
2011/08/29 09:55:27.0159 5160 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/08/29 09:55:27.0409 5160 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
2011/08/29 09:55:27.0487 5160 Compbatt (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\drivers\compbatt.sys
2011/08/29 09:55:27.0705 5160 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
2011/08/29 09:55:27.0752 5160 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
2011/08/29 09:55:27.0908 5160 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
2011/08/29 09:55:28.0189 5160 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/08/29 09:55:28.0438 5160 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/08/29 09:55:28.0782 5160 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/08/29 09:55:29.0109 5160 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/08/29 09:55:29.0452 5160 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/08/29 09:55:29.0811 5160 eeCtrl (96bcd90ed9235a21629effde5e941fb1) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/08/29 09:55:30.0186 5160 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
2011/08/29 09:55:30.0482 5160 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/08/29 09:55:30.0778 5160 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/08/29 09:55:31.0075 5160 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
2011/08/29 09:55:31.0324 5160 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/08/29 09:55:31.0496 5160 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/08/29 09:55:31.0558 5160 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/08/29 09:55:31.0683 5160 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/08/29 09:55:31.0730 5160 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/08/29 09:55:31.0824 5160 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
2011/08/29 09:55:31.0902 5160 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2011/08/29 09:55:32.0073 5160 HCW713x (61066edf92bff63e63b119e084bc578a) C:\Windows\system32\DRIVERS\HCW713x.sys
2011/08/29 09:55:32.0182 5160 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/08/29 09:55:32.0276 5160 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/08/29 09:55:32.0338 5160 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/08/29 09:55:32.0401 5160 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/08/29 09:55:32.0479 5160 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
2011/08/29 09:55:32.0604 5160 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/08/29 09:55:32.0728 5160 hwdatacard (4154079a88089155d10168333b19627f) C:\Windows\system32\DRIVERS\ewusbmdm.sys
2011/08/29 09:55:32.0822 5160 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
2011/08/29 09:55:32.0916 5160 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/08/29 09:55:33.0056 5160 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
2011/08/29 09:55:33.0368 5160 IDSvix86 (74f2b7d99b8613eac36edf22a2ab3b08) C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20091110.002\IDSvix86.sys
2011/08/29 09:55:33.0508 5160 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/08/29 09:55:33.0836 5160 IntcAzAudAddService (4a705bf2a6f7972f2f2ad8a0d8079f95) C:\Windows\system32\drivers\RTKVHDA.sys
2011/08/29 09:55:33.0945 5160 intelide (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
2011/08/29 09:55:34.0023 5160 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/08/29 09:55:34.0086 5160 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/08/29 09:55:34.0179 5160 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
2011/08/29 09:55:34.0320 5160 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/08/29 09:55:34.0522 5160 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/08/29 09:55:34.0710 5160 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
2011/08/29 09:55:34.0912 5160 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/08/29 09:55:35.0037 5160 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/08/29 09:55:35.0115 5160 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/08/29 09:55:35.0178 5160 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/08/29 09:55:35.0256 5160 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/08/29 09:55:35.0380 5160 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/08/29 09:55:35.0474 5160 lirsgt (8ccf9ed46d52af1375875f74a91ffacf) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/08/29 09:55:35.0536 5160 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/08/29 09:55:35.0630 5160 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
2011/08/29 09:55:35.0739 5160 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
2011/08/29 09:55:35.0848 5160 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
2011/08/29 09:55:35.0880 5160 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/08/29 09:55:35.0958 5160 mcdbus (af61a1c34e2d3f7543f9ccfc323170b8) C:\Windows\system32\DRIVERS\mcdbus.sys
2011/08/29 09:55:36.0067 5160 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
2011/08/29 09:55:36.0129 5160 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/08/29 09:55:36.0192 5160 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/08/29 09:55:36.0348 5160 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/08/29 09:55:36.0519 5160 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/08/29 09:55:36.0722 5160 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/08/29 09:55:36.0894 5160 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
2011/08/29 09:55:37.0346 5160 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/08/29 09:55:37.0580 5160 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/08/29 09:55:37.0767 5160 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/08/29 09:55:37.0923 5160 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/08/29 09:55:38.0157 5160 mrxsmb10 (d4a3c7c580c4ccb5c06f2ada933ad507) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/08/29 09:55:38.0376 5160 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/08/29 09:55:38.0532 5160 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
2011/08/29 09:55:38.0610 5160 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
2011/08/29 09:55:38.0812 5160 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/08/29 09:55:38.0922 5160 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/08/29 09:55:39.0093 5160 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/08/29 09:55:39.0280 5160 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/08/29 09:55:39.0405 5160 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/08/29 09:55:39.0546 5160 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/08/29 09:55:39.0624 5160 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/08/29 09:55:39.0702 5160 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/08/29 09:55:39.0780 5160 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/08/29 09:55:39.0904 5160 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/08/29 09:55:40.0482 5160 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/08/29 09:55:40.0653 5160 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/08/29 09:55:40.0903 5160 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/08/29 09:55:40.0996 5160 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/08/29 09:55:41.0106 5160 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/08/29 09:55:41.0215 5160 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/08/29 09:55:41.0308 5160 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/08/29 09:55:41.0511 5160 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/08/29 09:55:41.0620 5160 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/08/29 09:55:41.0823 5160 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/08/29 09:55:42.0182 5160 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/08/29 09:55:42.0432 5160 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/08/29 09:55:42.0572 5160 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/08/29 09:55:43.0290 5160 nvlddmkm (484844c0d892b42ecc5e6b063d072a38) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/08/29 09:55:43.0570 5160 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
2011/08/29 09:55:43.0648 5160 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
2011/08/29 09:55:43.0882 5160 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
2011/08/29 09:55:44.0194 5160 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/08/29 09:55:44.0522 5160 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/08/29 09:55:44.0678 5160 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/08/29 09:55:44.0740 5160 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/08/29 09:55:44.0818 5160 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/08/29 09:55:44.0896 5160 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys
2011/08/29 09:55:44.0974 5160 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/08/29 09:55:45.0130 5160 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/08/29 09:55:45.0692 5160 Ph3xIB32 (9f2f541c52cd7a452e235e885f7d95de) C:\Windows\system32\DRIVERS\Ph3xIB32.sys
2011/08/29 09:55:45.0988 5160 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/08/29 09:55:46.0098 5160 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
2011/08/29 09:55:46.0207 5160 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/08/29 09:55:46.0519 5160 PxHelp20 (f7bb4e7a7c02ab4a2672937e124e306e) C:\Windows\system32\Drivers\PxHelp20.sys
2011/08/29 09:55:46.0690 5160 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
2011/08/29 09:55:46.0878 5160 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/08/29 09:55:47.0049 5160 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/08/29 09:55:47.0299 5160 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/08/29 09:55:47.0455 5160 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/08/29 09:55:47.0673 5160 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/08/29 09:55:47.0720 5160 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/08/29 09:55:47.0829 5160 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/08/29 09:55:48.0048 5160 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/08/29 09:55:48.0250 5160 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
2011/08/29 09:55:48.0469 5160 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/08/29 09:55:48.0687 5160 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/08/29 09:55:48.0968 5160 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/08/29 09:55:49.0062 5160 RTL8023xp (959ef612d2ccfdb6d9e443f8e3655013) C:\Windows\system32\DRIVERS\Rtnicxp.sys
2011/08/29 09:55:49.0296 5160 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/08/29 09:55:49.0514 5160 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/08/29 09:55:49.0561 5160 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/08/29 09:55:49.0592 5160 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/08/29 09:55:49.0639 5160 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/08/29 09:55:49.0686 5160 sffdisk (51cf56aa8bcc241f134b420b8f850406) C:\Windows\system32\drivers\sffdisk.sys
2011/08/29 09:55:49.0717 5160 sffp_mmc (96ded8b20c734ac41641ce275250e55d) C:\Windows\system32\drivers\sffp_mmc.sys
2011/08/29 09:55:49.0748 5160 sffp_sd (8b08cab1267b2c377883fc9e56981f90) C:\Windows\system32\drivers\sffp_sd.sys
2011/08/29 09:55:49.0779 5160 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/08/29 09:55:49.0842 5160 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
2011/08/29 09:55:49.0873 5160 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
2011/08/29 09:55:49.0920 5160 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/08/29 09:55:50.0029 5160 SPBBCDrv (cdea9a0a0e547fef4c44ccae35a9b09c) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
2011/08/29 09:55:50.0122 5160 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/08/29 09:55:50.0185 5160 sptd (a80cd850d69d996c832bea37e3a6aa1e) C:\Windows\system32\Drivers\sptd.sys
2011/08/29 09:55:50.0185 5160 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: a80cd850d69d996c832bea37e3a6aa1e
2011/08/29 09:55:50.0200 5160 sptd - detected LockedFile.Multi.Generic (1)
2011/08/29 09:55:50.0263 5160 SRTSP (655773f2f1a3730c6cf20280a49f4ee1) C:\Windows\system32\Drivers\SRTSP.SYS
2011/08/29 09:55:50.0325 5160 SRTSPL (2a0aaf370d4c6574a34ae2f4a0709cae) C:\Windows\system32\Drivers\SRTSPL.SYS
2011/08/29 09:55:50.0356 5160 SRTSPX (3104bdceace2d5710776dd05e6a286c1) C:\Windows\system32\Drivers\SRTSPX.SYS
2011/08/29 09:55:50.0403 5160 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/08/29 09:55:50.0466 5160 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
2011/08/29 09:55:50.0544 5160 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
2011/08/29 09:55:50.0606 5160 ssm_bus (14622ae81c72b08691eedaabc1d4a129) C:\Windows\system32\DRIVERS\ssm_bus.sys
2011/08/29 09:55:50.0653 5160 ssm_mdfl (43ee5e9fda61a5e0eac4c1de699e6e4d) C:\Windows\system32\DRIVERS\ssm_mdfl.sys
2011/08/29 09:55:50.0668 5160 ssm_mdm (918cfd32c7feb174f356a0a6fad11f4b) C:\Windows\system32\DRIVERS\ssm_mdm.sys
2011/08/29 09:55:50.0731 5160 StarOpen (306521935042fc0a6988d528643619b3) C:\Windows\system32\drivers\StarOpen.sys
2011/08/29 09:55:50.0778 5160 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/08/29 09:55:50.0965 5160 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/08/29 09:55:51.0012 5160 SYMDNS (a16d76baa5d2cbe45c57fa582c1208e5) C:\Windows\System32\Drivers\SYMDNS.SYS
2011/08/29 09:55:51.0043 5160 SymEvent (06b95820df51502099a8a15c93e87986) C:\Windows\system32\Drivers\SYMEVENT.SYS
2011/08/29 09:55:51.0074 5160 SYMFW (c64d200569a18ea6c676266dee3ac158) C:\Windows\System32\Drivers\SYMFW.SYS
2011/08/29 09:55:51.0090 5160 SYMIDS (7764d3d7a3c858f04ced3c1f16410d89) C:\Windows\System32\Drivers\SYMIDS.SYS
2011/08/29 09:55:51.0183 5160 SYMNDISV (d193684004658fe4f3f143ca6dd9ef8b) C:\Windows\System32\Drivers\SYMNDISV.SYS
2011/08/29 09:55:51.0355 5160 SYMREDRV (829830a3ca1c5e329d68e26c9cd2de8d) C:\Windows\System32\Drivers\SYMREDRV.SYS
2011/08/29 09:55:51.0558 5160 SYMTDI (b1aa9704124b494c34e8d372e6654196) C:\Windows\System32\Drivers\SYMTDI.SYS
2011/08/29 09:55:51.0714 5160 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/08/29 09:55:51.0760 5160 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/08/29 09:55:51.0948 5160 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/08/29 09:55:52.0244 5160 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/08/29 09:55:52.0353 5160 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/08/29 09:55:52.0540 5160 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/08/29 09:55:52.0650 5160 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/08/29 09:55:52.0712 5160 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/08/29 09:55:52.0774 5160 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/08/29 09:55:52.0852 5160 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/08/29 09:55:52.0977 5160 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/08/29 09:55:53.0086 5160 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/08/29 09:55:53.0164 5160 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\DRIVERS\uagp35.sys
2011/08/29 09:55:53.0227 5160 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/08/29 09:55:53.0367 5160 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
2011/08/29 09:55:53.0492 5160 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
2011/08/29 09:55:53.0601 5160 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/08/29 09:55:53.0913 5160 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/08/29 09:55:54.0225 5160 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/08/29 09:55:54.0428 5160 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/08/29 09:55:54.0584 5160 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/08/29 09:55:54.0771 5160 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/08/29 09:55:55.0083 5160 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/08/29 09:55:55.0146 5160 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/08/29 09:55:55.0317 5160 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys
2011/08/29 09:55:55.0411 5160 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/08/29 09:55:55.0551 5160 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/08/29 09:55:55.0645 5160 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/08/29 09:55:55.0723 5160 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/08/29 09:55:55.0801 5160 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/08/29 09:55:55.0832 5160 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
2011/08/29 09:55:55.0894 5160 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
2011/08/29 09:55:56.0050 5160 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/08/29 09:55:56.0191 5160 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/08/29 09:55:56.0550 5160 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/08/29 09:55:56.0784 5160 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/08/29 09:55:56.0846 5160 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
2011/08/29 09:55:57.0111 5160 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/08/29 09:55:57.0205 5160 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/29 09:55:57.0220 5160 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/29 09:55:57.0345 5160 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
2011/08/29 09:55:57.0501 5160 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/08/29 09:55:57.0844 5160 WmiAcpi (17eac0d023a65fa9b02114cc2baacad5) C:\Windows\system32\drivers\wmiacpi.sys
2011/08/29 09:55:58.0063 5160 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/08/29 09:55:58.0188 5160 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/08/29 09:55:58.0234 5160 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
2011/08/29 09:55:58.0312 5160 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
2011/08/29 09:55:58.0328 5160 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk6\DR6
2011/08/29 09:55:58.0375 5160 Boot (0x1200) (c393a99ff47b742f69541788e31131b1) \Device\Harddisk0\DR0\Partition0
2011/08/29 09:55:58.0406 5160 Boot (0x1200) (ad22eb355df71aa5b5f00490ea2b3d72) \Device\Harddisk1\DR1\Partition0
2011/08/29 09:55:58.0422 5160 Boot (0x1200) (3764430ada0d058ce8c6d6f718a2058b) \Device\Harddisk6\DR6\Partition0
2011/08/29 09:55:58.0437 5160 ================================================================================
2011/08/29 09:55:58.0437 5160 Scan finished
2011/08/29 09:55:58.0437 5160 ================================================================================
2011/08/29 09:55:58.0437 5152 Detected object count: 1
2011/08/29 09:55:58.0437 5152 Actual detected object count: 1
2011/08/29 09:56:32.0143 5152 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/08/29 09:56:37.0852 3656 Deinitialize success

2) Combo Fix Log:-

ComboFix 11-08-28.01 - a 29/08/2011 9:59.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1995 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\antivirus scan ultimate
c:\program files\antivirus scan ultimate\Cannot read access control list. Error code
c:\program files\antivirus scan ultimate\config.cfg
c:\program files\antivirus scan ultimate\db\daily.cld
c:\program files\antivirus scan ultimate\db\Data.s
c:\program files\antivirus scan ultimate\db\mirrors.dat
c:\program files\antivirus scan ultimate\license.txt
c:\program files\antivirus scan ultimate\readme.txt
c:\program files\antivirus scan ultimate\uninstall.exe
c:\users\a\AppData\Roaming\9628.1C3
c:\windows\system32\comct332.ocx
.
.
((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 09:05 . 2011-08-29 09:05 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-23 18:16 . 2011-08-23 18:16 386560 —-a-w- c:\program files\Internet Explorer\jsdbgui.dll
2011-08-23 18:16 . 2011-08-23 18:16 22016 —-a-w- c:\program files\Internet Explorer\ExtExport.exe
2011-08-23 18:16 . 2011-08-23 18:16 149504 —-a-w- c:\program files\Internet Explorer\jsprofilerui.dll
2011-08-23 18:16 . 2011-08-23 18:16 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-08-23 18:14 . 2011-08-23 18:14 ——– d—–w- C:\$AVG
2011-08-23 17:53 . 2011-08-23 17:53 ——– d—–w- c:\users\a\AppData\Roaming\AVG10
2011-08-23 17:50 . 2011-08-27 14:04 ——– d—–w- c:\programdata\AVG10
2011-08-23 17:50 . 2011-08-27 13:50 ——– d—–w- c:\windows\system32\drivers\AVG
2011-08-23 17:49 . 2011-08-23 17:49 ——– d—–w- c:\program files\AVG
2011-08-23 17:42 . 2011-08-27 14:02 ——– d—–w- c:\programdata\MFAData
2011-08-23 17:42 . 2011-05-18 11:37 6962000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0AB04D74-D5DE-4A8A-84B7-BC969B056A4C}\mpengine.dll
2011-08-12 13:36 . 2011-08-27 14:14 ——– d—–w- c:\users\a\AppData\Roaming\vlc
2011-08-12 13:36 . 2011-08-12 13:36 ——– d—–w- c:\users\a\AppData\Local\Graboid
2011-08-12 13:36 . 2011-08-12 13:36 ——– d—–w- c:\users\a\AppData\Local\Geckofx
2011-08-12 13:30 . 2011-08-14 09:51 ——– d—–w- c:\program files\Graboid
2011-08-10 13:13 . 2011-08-10 13:13 ——– d—–w- c:\program files\GameSpy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-27 10:16 . 2009-09-13 13:29 140624 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-08-27 10:12 . 2009-09-13 13:34 266752 —-a-w- c:\windows\system32\PnkBstrB.xtr
2011-08-27 10:12 . 2009-09-13 13:29 266752 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-08-21 13:46 . 2009-09-13 13:29 266752 —-a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-03 09:37 . 2011-07-03 09:37 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-25 12:41 . 2011-06-25 12:41 784136 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-02 13:34 . 2011-07-16 15:16 2043392 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 1120568]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2009-08-05 224712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 232184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-18 115816]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-10-09 2086912]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-11-18 623880]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
.
c:\users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-9-11 575488]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2011-6-25 117344]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-5-3 984408]
WinTV Recording Status..lnk - c:\program files\WinTV\WinTV7\WinTVTray.exe [2011-6-25 82944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 SrvCDEject;SrvCDEject;c:\program files\Packard Bell\SrvCDEject.exe [2007-09-07 600064]
R3 Ph3xIB32;Philips 713x VU PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-10-15 722416]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20091110.002\IDSvix86.sys [2009-07-03 272432]
S2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [2011-04-15 562176]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-10-09 14336]
S3 HCW713x;Hauppauge WinTV-HVR 713X PCI Card;c:\windows\system32\DRIVERS\HCW713x.sys [2010-11-10 1156736]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2007-05-18 38200]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 21949439
*NewlyCreated* - COMHOST
*Deregistered* - 21949439
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2009-09-04 c:\windows\Tasks\HDReg.job
- c:\program files\HDReg\HDRegRem.exe [2003-07-15 09:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyServer = http=127.0.0.1:51859
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\a\AppData\Roaming\Mozilla\Firefox\Profiles\914ez3ua.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 51859
FF - prefs.js: network.proxy.type - 1
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-Antivirus Scan Ultimate - c:\program files\Antivirus Scan Ultimate\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-29 10:05
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\a\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: ST3360320AS rev.3.AAM -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2887509634-308989567-3342084679-1002\Software\SecuROM\License information*]
"datasecu"=hex:3a,98,e0,8b,b1,6e,fd,96,2b,f1,71,f9,f4,8d,c7,c1,57,a8,cb,2e,2a,
de,97,6b,7d,9b,0a,8d,b1,b7,2a,a9,08,0e,c7,43,e0,f8,f2,33,d6,14,26,9a,09,31,\
"rkeysecu"=hex:5b,b8,82,b2,e8,a2,54,cb,2b,6c,76,25,25,aa,7e,08
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-08-29 10:07:59
ComboFix-quarantined-files.txt 2011-08-29 09:07
.
Pre-Run: 225,416,871,936 bytes free
Post-Run: 226,575,597,568 bytes free
.
- - End Of File - - FDA270A85008EEA1318B2536BBAA3957
Hi


Very glad to hear you can now connect. We still have a little more work to do.


Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:51859

FireFox::
FF - ProfilePath - c:\users\a\AppData\Roaming\Mozilla\Firefox\Profiles\914ez3ua.default\
FF - prefs.js: network.proxy.http_port - 51859

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT



Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
hello

have tried running malware bytes software and have gotten message of "illegal operation attempted on a registry key that has been marked for deletion".

here is the combofix log:-

ComboFix 11-08-29.01 - a 29/08/2011 11:19:45.2.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3070.1761 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\a\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 10:24 . 2011-08-29 10:24 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-23 18:16 . 2011-08-23 18:16 386560 —-a-w- c:\program files\Internet Explorer\jsdbgui.dll
2011-08-23 18:16 . 2011-08-23 18:16 22016 —-a-w- c:\program files\Internet Explorer\ExtExport.exe
2011-08-23 18:16 . 2011-08-23 18:16 149504 —-a-w- c:\program files\Internet Explorer\jsprofilerui.dll
2011-08-23 18:16 . 2011-08-23 18:16 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-08-23 18:14 . 2011-08-23 18:14 ——– d—–w- C:\$AVG
2011-08-23 17:53 . 2011-08-23 17:53 ——– d—–w- c:\users\a\AppData\Roaming\AVG10
2011-08-23 17:50 . 2011-08-27 14:04 ——– d—–w- c:\programdata\AVG10
2011-08-23 17:50 . 2011-08-27 13:50 ——– d—–w- c:\windows\system32\drivers\AVG
2011-08-23 17:49 . 2011-08-23 17:49 ——– d—–w- c:\program files\AVG
2011-08-23 17:42 . 2011-08-27 14:02 ——– d—–w- c:\programdata\MFAData
2011-08-23 17:42 . 2011-05-18 11:37 6962000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0AB04D74-D5DE-4A8A-84B7-BC969B056A4C}\mpengine.dll
2011-08-12 13:36 . 2011-08-27 14:14 ——– d—–w- c:\users\a\AppData\Roaming\vlc
2011-08-12 13:36 . 2011-08-12 13:36 ——– d—–w- c:\users\a\AppData\Local\Graboid
2011-08-12 13:36 . 2011-08-12 13:36 ——– d—–w- c:\users\a\AppData\Local\Geckofx
2011-08-12 13:30 . 2011-08-14 09:51 ——– d—–w- c:\program files\Graboid
2011-08-10 13:13 . 2011-08-10 13:13 ——– d—–w- c:\program files\GameSpy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-27 10:16 . 2009-09-13 13:29 140624 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-08-27 10:12 . 2009-09-13 13:34 266752 —-a-w- c:\windows\system32\PnkBstrB.xtr
2011-08-27 10:12 . 2009-09-13 13:29 266752 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-08-21 13:46 . 2009-09-13 13:29 266752 —-a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-03 09:37 . 2011-07-03 09:37 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-25 12:41 . 2011-06-25 12:41 784136 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-02 13:34 . 2011-07-16 15:16 2043392 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 1120568]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2009-08-05 224712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 232184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-18 115816]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-10-09 2086912]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-11-18 623880]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
.
c:\users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-9-11 575488]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2011-6-25 117344]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-5-3 984408]
WinTV Recording Status..lnk - c:\program files\WinTV\WinTV7\WinTVTray.exe [2011-6-25 82944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 SrvCDEject;SrvCDEject;c:\program files\Packard Bell\SrvCDEject.exe [2007-09-07 600064]
R3 Ph3xIB32;Philips 713x VU PCI TV Card;c:\windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-10-15 722416]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20091110.002\IDSvix86.sys [2009-07-03 272432]
S2 HauppaugeTVServer;HauppaugeTVServer;c:\program files\WinTV\TVServer\HauppaugeTVServer.exe [2011-04-15 562176]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-10-09 14336]
S3 HCW713x;Hauppauge WinTV-HVR 713X PCI Card;c:\windows\system32\DRIVERS\HCW713x.sys [2010-11-10 1156736]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2007-05-18 38200]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 21949439
*NewlyCreated* - COMHOST
*Deregistered* - 21949439
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2009-09-04 c:\windows\Tasks\HDReg.job
- c:\program files\HDReg\HDRegRem.exe [2003-07-15 09:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\a\AppData\Roaming\Mozilla\Firefox\Profiles\914ez3ua.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.type - 1
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-29 11:24
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: ST3360320AS rev.3.AAM -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2887509634-308989567-3342084679-1002\Software\SecuROM\License information*]
"datasecu"=hex:3a,98,e0,8b,b1,6e,fd,96,2b,f1,71,f9,f4,8d,c7,c1,57,a8,cb,2e,2a,
de,97,6b,7d,9b,0a,8d,b1,b7,2a,a9,08,0e,c7,43,e0,f8,f2,33,d6,14,26,9a,09,31,\
"rkeysecu"=hex:5b,b8,82,b2,e8,a2,54,cb,2b,6c,76,25,25,aa,7e,08
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-08-29 11:25:45
ComboFix-quarantined-files.txt 2011-08-29 10:25
ComboFix2.txt 2011-08-29 09:07
.
Pre-Run: 228,105,269,248 bytes free
Post-Run: 228,124,798,976 bytes free
.
- - End Of File - - D20C781879556A336424F8BE1310C707
Hello I keep on getting "illegal operation attempted on a registry key that has been marked for deletion" every time I try to run a program. Can't progress any further with your instructions.
Hello Can't get ESET to work: it keeps on asking if proxy is configured and can't get updates. Here are logs for MBAM:- Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7604 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 29/08/2011 14:06:40 mbam-log-2011-08-29 (14-06-40).txt Scan type: Quick scan Objects scanned: 166019 Time elapsed: 5 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\programdata\microsoft\Windows\start menu\antivirus scan ultimate.lnk (Trojan.Zlob) -> Quarantined and deleted successfully.
go into add/remove programs and see if any temporary installation files were downloaded for ESET > if so > remove them

clear your internet browsing history and cookies

run Temp File Cleaner

If you are using FireFox > switch to I.E. and give it another try:



Download TFC to your desktop
Mirror
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI