This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Restore Virus

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my computer has the windows restore virus. All the desktop icons are hidden and can only be viewed if I change the folder options to show hidden files and folder. Also messages keep popping up including "Windows - Delayed Write Filed Failed to save all the components for the file \\System32\\496A8300. The file is corrupted or unreadable. This error may be caused by a PC hardware problem.". Could someone please help me?







OTL logfile created on: 30/03/2011 2:58:26 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\sonam\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 916.44 Gb Total Space | 7.47 Gb Free Space | 0.81% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 10.17 Gb Free Space | 67.81% Space Free | Partition Type: NTFS

Computer Name: SONAM-PC | User Name: sonam | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe (Research In Motion)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\K-Meleon\k-meleon.exe (http://kmeleon.sf.net/)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Hotspot Shield\bin\openvpntray.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\sonam\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RoxLiveShare9) – File not found
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec AntiVirus\SNAC.EXE (Symantec Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (AresChatServer) – C:\Program Files\Ares\chatServer.exe (Ares Development Group)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20110330.003\NAVENG.SYS (Symantec Corporation)
DRV - (Lbd) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (HssDrv) – C:\Windows\System32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AnyDVD) – C:\Windows\System32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RtNdPt60) – C:\Windows\System32\drivers\RtNdPt60.sys (Windows ® Codename Longhorn DDK provider)
DRV - (tapvpn) – C:\Windows\System32\drivers\tapvpn.sys (The OpenVPN Project)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (RTL8187) – C:\Windows\System32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (pmxmouse) – C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) – C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (QCMerced) – C:\Windows\System32\drivers\lvcm.sys ()
DRV - (LVUSBSta) – C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/enterprise/securit…ponse/index.jsp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?lang=en-ca&OCID;=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 A3 23 3B 64 E6 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========


FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2010/10/06 18:17:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2010/10/06 18:18:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 06:39:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 06:39:26 | 000,000,000 | —D | M]

[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions
[2009/02/09 15:14:14 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Extensions\{ae2cff10-0d52-4066-8be9-4abcf119fa79}
[2011/03/28 19:45:33 | 000,000,000 | —D | M] (No name found) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions
[2010/05/03 10:45:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/15 19:00:06 | 000,000,000 | —D | M] (jDownFF) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{a3b24d40-bac4-11dc-95ff-0800200c9a66}
[2010/05/03 10:45:17 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/04 18:04:59 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/06/04 18:04:53 | 000,000,000 | —D | M] ("BitDefender QuickScan") – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/05/28 21:04:24 | 000,000,000 | —D | M] (TVU Web Player) – C:\Users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\extensions\[removed]
[2011/03/24 23:59:36 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/24 23:59:37 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

O1 HOSTS File: ([2010/01/05 18:08:21 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Veoh Video Compass) - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll (Veoh Networks)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QT Lite\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab (RIM AxLoader)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img11.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{6699b567-46de-11e0-92c7-0021703a9f80}\Shell\AutoRun\command - "" = J:\start.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/03/30 14:50:48 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:50:08 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{33AD8694-4811-4125-973D-CFBA1B5B716A}
[2011/03/25 00:00:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\skypePM
[2011/03/24 23:59:44 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Skype
[2011/03/24 23:59:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/03/24 23:59:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/03/24 23:59:00 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2011/03/24 23:58:46 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2011/03/23 03:22:47 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{3E593D15-4E84-4ED5-BAFB-632910E5C572}
[2011/03/22 18:08:21 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 18:08:21 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/18 15:10:33 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BkUp554
[2011/03/17 20:21:31 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{AC2A6EF1-8818-4002-870B-5376CBC63AD3}
[2011/03/16 03:25:25 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{43A2E345-378C-499F-929E-DB4AA7CF365E}
[2011/03/11 14:37:52 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{73BBFA43-A80D-4E47-BEDA-54EA2B5A1A70}
[2011/03/11 13:53:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2011/03/11 13:52:29 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Roaming\Dropbox
[2011/03/10 22:20:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/03/10 22:19:52 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2011/03/10 22:19:19 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2011/03/10 12:41:39 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{E361019C-C46E-48CD-8CAB-83B5C9FC61AB}
[2011/03/09 16:22:05 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 16:22:04 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 16:22:04 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 16:22:04 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2011/03/06 17:22:39 | 000,000,000 | —D | C] – C:\Users\sonam\Documents\BlackBerry
[2011/03/06 17:21:38 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\Research In Motion
[2011/03/06 17:15:51 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{B4A4FB8B-1774-4BDD-8A53-5075870837C1}
[2011/03/06 16:53:09 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2011/03/06 16:52:16 | 000,000,000 | —D | C] – C:\ProgramData\Research In Motion
[2011/03/06 16:40:35 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2011/03/05 00:16:27 | 000,000,000 | —D | C] – C:\Users\sonam\AppData\Local\{79597155-7FD4-47F4-BF7F-28693DA8670B}
[2011/03/04 13:03:52 | 000,000,000 | —D | C] – C:\Program Files\Pegasys Inc
[2011/03/03 19:52:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2008/10/22 11:56:11 | 000,047,360 | —- | C] (VSO Software) – C:\Users\sonam\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/03/30 14:55:18 | 000,001,057 | —- | M] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe
[2011/03/30 14:04:15 | 000,113,152 | —- | M] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/30 13:19:26 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/27 18:26:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000UA.job
[2011/03/27 15:26:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000Core.job
[2011/03/25 00:00:26 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/24 00:41:18 | 000,000,000 | —- | M] () – C:\Windows\System32\null
[2011/03/23 03:26:25 | 000,611,664 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/03/23 03:26:25 | 000,109,112 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:19:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2011/03/06 17:11:55 | 000,384,568 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/03/06 16:54:10 | 000,002,098 | —- | M] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/05 13:15:28 | 000,103,032 | —- | M] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:29 | 005,509,734 | —- | M] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | M] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk

========== Files Created - No Company Name ==========

[2011/03/25 00:00:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/03/24 23:59:06 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/03/06 16:54:10 | 000,002,098 | —- | C] () – C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
[2011/03/06 16:54:08 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2011/03/06 16:54:05 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011/03/06 16:53:13 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2011/03/05 13:15:22 | 000,103,032 | —- | C] () – C:\Users\sonam\Documents\cc_20110305_121354.reg
[2011/03/05 01:08:15 | 005,509,734 | —- | C] () – C:\Users\sonam\Documents\Backup-(2011-03-05).ipd
[2011/03/05 00:42:47 | 000,744,140 | —- | C] () – C:\Users\sonam\Documents\LoaderBackup-(2011-03-04).ipd
[2011/03/05 00:05:31 | 000,000,256 | —- | C] () – C:\Windows\System32\pool.bin
[2011/03/03 19:52:49 | 000,000,861 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2010/11/11 04:05:04 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/10/29 01:34:24 | 000,000,008 | —- | C] () – C:\Users\sonam\AppData\Roaming\vfzwln.dat
[2010/10/21 14:38:49 | 000,087,608 | —- | C] () – C:\Users\sonam\AppData\Roaming\inst.exe
[2010/09/22 13:58:11 | 000,113,152 | —- | C] () – C:\Users\sonam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/02 21:24:01 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/01/05 17:57:57 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/01/05 17:57:57 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/01/05 03:03:31 | 000,000,000 | —- | C] () – C:\Windows\System32\cd.dat
[2009/12/03 10:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/16 15:42:47 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2009/10/16 15:42:47 | 000,081,920 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2009/10/16 15:42:47 | 000,045,056 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2009/10/16 15:42:47 | 000,011,264 | —- | C] () – C:\Windows\System32\atimuixx.dll
[2009/10/11 01:01:05 | 000,000,046 | —- | C] () – C:\Windows\System32\DonationCoder_urlsnooper_InstallInfo.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/09/11 01:59:40 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/11 01:59:39 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/19 11:48:25 | 000,000,726 | —- | C] () – C:\Windows\Mp3CutterJoiner.ini
[2009/05/17 16:57:54 | 000,000,005 | —- | C] () – C:\Windows\System32\SySMP3CutJoin.dat
[2009/05/17 16:57:40 | 000,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2009/03/09 01:05:12 | 000,000,040 | -HS- | C] () – C:\ProgramData\.zreglib
[2009/02/24 15:55:27 | 000,001,057 | —- | C] () – C:\Users\sonam\AppData\Roaming\vso_ts_preview.xml
[2009/01/26 16:02:18 | 000,028,672 | —- | C] () – C:\Windows\System32\AVEQT.dll
[2008/12/25 14:40:14 | 000,129,024 | —- | C] () – C:\Windows\System32\AVERM.dll
[2008/12/23 11:33:18 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2008/11/02 17:05:06 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/10/28 18:29:16 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2008/10/22 11:56:11 | 000,007,887 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.cat
[2008/10/22 11:56:11 | 000,001,144 | —- | C] () – C:\Users\sonam\AppData\Roaming\pcouffin.inf
[2008/10/17 21:40:46 | 000,139,264 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/10/17 21:40:45 | 000,524,288 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/10/16 17:38:31 | 000,024,206 | —- | C] () – C:\Users\sonam\AppData\Roaming\UserTile.png
[2008/10/15 20:20:23 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/04 02:28:21 | 002,192,024 | —- | C] () – C:\Windows\System32\igkrng500.bin
[2008/10/04 02:28:21 | 000,495,376 | —- | C] () – C:\Windows\System32\igcompkrng500.bin
[2008/10/04 02:28:21 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1527.dll
[2008/10/04 02:28:21 | 000,147,172 | —- | C] () – C:\Windows\System32\igfcg550.bin
[2008/10/04 02:28:18 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/04 02:28:18 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/10/04 02:28:18 | 000,090,112 | —- | C] () – C:\Windows\System32\atibrtmon.exe
[2008/10/03 23:46:08 | 000,303,104 | —- | C] () – C:\Windows\System32\FontZoom.exe
[2008/10/03 23:46:08 | 000,131,062 | —- | C] () – C:\Windows\System32\DellPM.ini
[2008/10/03 18:34:16 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,384,568 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,611,664 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,109,112 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2005/05/27 09:32:52 | 001,317,152 | —- | C] () – C:\Windows\System32\drivers\lvcm.sys
[2005/05/27 09:10:26 | 000,009,255 | —- | C] () – C:\Windows\System32\lvcoinst.ini

========== LOP Check ==========

[2009/10/15 21:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\.anomos
[2009/12/25 15:20:01 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\AVSMedia
[2009/07/06 23:21:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\BOXEE
[2009/02/09 15:14:13 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Broad Intelligence
[2008/12/25 12:51:14 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Canneverbe_Limited
[2008/12/25 14:12:12 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\devede
[2009/10/11 01:01:05 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\DonationCoder
[2011/03/16 12:50:10 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Dropbox
[2009/06/18 23:22:41 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FFSJ
[2010/11/09 13:13:44 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\FrostWire
[2009/12/25 15:32:42 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GetRightToGo
[2009/03/02 15:22:16 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Graboid Inc
[2010/01/05 20:31:26 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\GrabPro
[2008/12/25 14:14:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\gtk-2.0
[2009/11/17 16:53:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ICAClient
[2008/11/14 18:24:38 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ImgBurn
[2009/03/03 23:40:45 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\iPodifier
[2010/10/06 18:20:59 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\K-Meleon
[2010/09/21 21:05:27 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Leadertech
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Livestation
[2010/10/17 23:56:39 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\ManyCam
[2009/10/08 15:53:54 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Mchid
[2009/10/18 01:04:11 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Moyea
[2009/06/07 15:27:17 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Octoshape
[2009/04/06 21:16:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Opera
[2011/03/17 15:25:24 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Orbit
[2008/10/16 17:38:31 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\PeerNetworking
[2011/02/18 12:18:03 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Pegasys Inc
[2010/12/14 19:43:51 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\QuickScan
[2010/10/28 19:31:04 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Red Kawa
[2011/03/06 17:22:08 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Research In Motion
[2011/03/30 15:02:35 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\uTorrent
[2011/03/30 14:55:20 | 000,000,000 | —D | M] – C:\Users\sonam\AppData\Roaming\Vso
[2011/03/23 03:20:31 | 000,000,276 | —- | M] () – C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2011/03/23 03:17:20 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/23 03:18:57 | 000,009,180 | —- | M] () – C:\aaw7boot.log
[2006/09/18 17:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/10/04 02:28:28 | 000,004,871 | RH– | M] () – C:\dell.sdr
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/03/23 03:19:01 | 3220,365,312 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/03/15 19:57:16 | 000,001,363 | —- | M] () – C:\MP4debug.log
[2011/03/23 03:18:58 | 3534,172,160 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/15 08:54:21 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 03:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/03 21:17:30 | 000,000,574 | -HS- | M] () – C:\Users\sonam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2008/11/02 16:46:58 | 004,411,392 | —- | M] (Gabest) – C:\Users\sonam\Desktop\mplayerc.exe
[2011/03/30 14:50:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\sonam\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 07:01:06

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >
Hello lelo and :welcome:
I'm RedCar92 and my name is Bill, I'll be glad to help you with your computer problems.

  • Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear. Malware removal can be stressful but we will clean it.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperative and could require a full reinstall of your OS, losing all your programs and data.

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

Stay with this topic until I give you the all clean post.
Greetings lelo,
P2P - I see you have P2P software uTorrent & Frostwire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please refrain from using them until we are done with malware removal and I have posted All Clean.

Next
Please download Unhide.exe   to your desktop:
  • Double-click on the Unhide.exe icon on your desktop and allow the program to run.
  • This program will remove the hidden attributes from all the files on your system.
  • Note: If you had purposely hidden any files, then you will need to hide them again after this tool has run.

Next
  • Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

Next
Please download DDS from LINK 1 or LINK 2
and save it to your desktop.
  • These tools MUST be run from the executable. (.exe) every time you run them
  • With Admin Rights (Right click, choose "Run as Administrator")

Save both reports to your desktop.
Please include the contents of the following in your reply using Copy / Paste:
DDS.txt & Attach.txt

Logs to post:
  • aswMBR.txt
  • DDS.txt
  • Attach.txt
Hi Bill, thanks for replying. I ran unhide.exe and everything appears to be visible now. Thank you :) . I tried to run aswMBR but it didn't work. I was given these errors "Initialize Error C000010e - driver not loaded Scan error:". Here are the DDS logs . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.19120 BrowserJavaVersion: 1.6.0_18 Run by [removed] at 1:40:11 on 2011-09-12 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.635 [GMT -4:00] . AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\atieclxx.exe C:\Program Files\Symantec AntiVirus\Smc.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\Symantec AntiVirus\SmcGui.exe C:\Windows\system32\taskeng.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\ico.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Hotspot Shield\bin\openvpnas.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe C:\Program Files\Hotspot Shield\bin\hsswd.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\Program Files\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\ehome\ehtray.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\ManyCam\Bin\ManyCam.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Windows\System32\mobsync.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\Pmxmiced.exe C:\Program Files\Hotspot Shield\bin\openvpntray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files\Java\jre6\bin\javaw.exe C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files\TeamViewer\Version6\TeamViewer.exe C:\Windows\Explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Users\sonam\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\explorer.exe C:\Program Files\VideoLAN\VLC\vlc.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.google.com/ uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local; uInternet Settings,ProxyServer = 0.0.0.0:80 uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: Veoh Video Compass: {52836eb0-631a-47b1-94a6-61f9d9112dae} - c:\program files\veoh networks\veoh video compass\SearchRecsPlugin.dll TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Google Update] "c:\users\sonam\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [ManyCam] "c:\program files\manycam\bin\ManyCam.exe" /silent uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [PMX Daemon] ICO.EXE mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [QuickTime Task] "c:\program files\qt lite\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Desktop Disc Tool] "c:\program files\roxio\roxio burn\RoxioBurnLauncher.exe" mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s dRunOnce: [] mExplorerRun: [] 1 (0x1) StartupFolder: c:\users\sonam\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Download; by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201 IE: &Grab; video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204 IE: Do&wnload; selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203 IE: Down&load; all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{5448833B-53FC-4A0D-8826-042F658B5020} : DhcpNameServer = 192.168.0.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q;= FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom.dll FF - component: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\opera\program\plugins\np_gp.dll FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll FF - plugin: c:\program files\tvuplayer\npTVUAx.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\sonam\appdata\local\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\users\sonam\appdata\roaming\mozilla\firefox\profiles\1arsg2p9.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll FF - plugin: c:\users\sonam\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\sonam\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\users\sonam\appdata\roaming\mozilla\plugins\npoctoshape.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-8 64288] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-6-23 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 67664] R2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt60.sys [2008-10-3 27648] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-7-8 8312832] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-7-7 244736] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-8-6 105592] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632] R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-10-3 18432] R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-10-3 19008] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-9-30 23888] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-22 39272] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-12-23 50704] S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2007-12-26 288768] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 12872] . =============== Created Last 30 ================ . 2011-09-11 23:16:05 ——– d—–w- c:\program files\TeamViewer 2011-09-11 02:41:29 ——– d—–w- c:\users\sonam\appdata\local\{3D6AA1B0-B7E9-4DEC-A04E-9FEF458D0B7D} 2011-09-11 02:41:09 ——– d—–w- c:\users\sonam\appdata\local\{84ACB26A-37A1-4B0B-BE0A-DD3E7837D284} 2011-09-09 10:41:01 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{fba76206-ed2c-41c4-8000-623fb36fa79c}\mpengine.dll 2011-09-08 21:30:23 ——– d—–w- c:\users\sonam\appdata\local\{0CCA7F1F-98F7-4ADC-A594-4C018987ED48} 2011-09-07 03:08:12 ——– d—–w- c:\users\sonam\appdata\local\{1858B932-0518-46B0-8683-8EA2481526A9} 2011-09-07 03:07:23 ——– d—–w- c:\users\sonam\appdata\local\{DB6BD965-7538-42E5-96BB-DDC418C3EA07} 2011-09-04 19:13:41 ——– d—–w- c:\program files\VS Revo Group 2011-09-04 10:47:49 ——– d—–w- c:\users\sonam\appdata\local\{8027C535-674C-4AA7-B30D-47D9C1E49B07} 2011-09-04 10:47:26 ——– d—–w- c:\users\sonam\appdata\local\{5E378FD6-E601-4A83-89DA-09B087CE4890} 2011-09-02 03:03:40 71552 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys 2011-09-02 01:58:52 69715 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll 2011-09-02 01:58:52 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe 2011-09-02 01:58:52 266240 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll 2011-09-02 01:58:52 192512 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll 2011-09-02 01:58:51 729088 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll 2011-09-02 01:58:50 188548 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll 2011-09-02 01:58:49 311428 —-a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll 2011-09-02 00:51:42 ——– d—–w- c:\users\sonam\appdata\local\{ECBAF258-6924-46C2-94A8-BBECEB056A62} 2011-09-02 00:51:19 ——– d—–w- c:\users\sonam\appdata\local\{04DCB6E6-B02A-49D4-9FBD-12D18181FA52} 2011-08-30 03:04:39 ——– d—–w- c:\users\sonam\appdata\local\{727DECE1-D3C9-4691-BED0-B7AC3585605B} 2011-08-30 03:04:18 ——– d—–w- c:\users\sonam\appdata\local\{71A44A9E-2992-42D0-B1B2-09A636114A5B} 2011-08-26 21:11:17 ——– d—–w- c:\windows\en 2011-08-26 20:56:07 ——– d—–w- c:\users\sonam\appdata\local\{17FD9D9A-9459-436F-B702-18773B583A28} 2011-08-26 20:55:44 ——– d—–w- c:\users\sonam\appdata\local\{222FF2AC-7111-4DB3-883A-D27255ACFE34} 2011-08-26 20:53:07 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-24 08:25:30 2048 —-a-w- c:\windows\system32\tzres.dll 2011-08-18 18:36:43 ——– d—–w- c:\users\sonam\appdata\local\{5DAD0AE3-7FC9-4ABB-811A-FA24C276AB7A} 2011-08-16 11:20:32 4892320 —-a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2011-08-16 06:01:54 ——– d—–w- c:\users\sonam\appdata\local\{267CC011-3D22-4BAA-AD9D-2131E7418183} 2011-08-16 06:01:17 ——– d—–w- c:\users\sonam\appdata\local\{D817CC2B-6216-4DF0-A73B-868E69600356} 2011-08-14 05:39:59 ——– d—–w- c:\users\sonam\appdata\local\{AE0C1088-A268-4D3B-9D70-98F19B475E62} 2011-08-13 21:48:04 ——– d—–w- c:\users\sonam\appdata\local\{A43C4C46-682B-4BAE-9FAB-EFDFEB7BE25C} 2011-08-13 21:47:40 ——– d—–w- c:\users\sonam\appdata\local\{DD6F1251-4555-4E06-9C9C-CF0DD42994D2} 2011-08-13 20:56:23 ——– d—–w- c:\users\sonam\appdata\local\{06D511FD-0150-4FE6-8AA7-E04D6D4C960B} 2011-08-13 20:37:57 ——– d—–w- c:\program files\AMD APP 2011-08-13 20:37:26 ——– d—–w- c:\program files\ATI Technologies 2011-08-13 20:31:28 ——– d—–w- C:\ATI 2011-08-13 20:20:37 ——– d—–w- c:\users\sonam\appdata\local\{77858E66-A1D1-4E89-8CAA-CE21E7B78E87} 2011-08-13 20:20:08 ——– d—–w- c:\users\sonam\appdata\local\{040C9B01-04DA-489B-99D9-60DBDA10F997} 2011-08-13 20:06:16 15712 —-a-w- c:\program files\common files\windows live\.cache\7578d17e1cc59f402\MeshBetaRemover.exe 2011-08-13 20:03:27 ——– d—–w- c:\users\sonam\appdata\local\{CF811B8E-85C8-4927-A54D-E3BA69377AB0} 2011-08-13 20:02:56 ——– d—–w- c:\users\sonam\appdata\local\{B3F298A1-5927-4CD1-87E0-07F86288225A} 2011-08-13 19:22:13 ——– d—–w- c:\users\sonam\appdata\local\{1C67653C-79D8-4FF7-A08A-E1965196C43E} 2011-08-13 07:29:36 ——– d—–w- c:\users\sonam\appdata\local\{1A7732B9-7D54-4305-86D1-4E36A26D43AA} 2011-08-13 07:29:13 ——– d—–w- c:\users\sonam\appdata\local\{A4B38AFE-8612-4E9C-8BB3-5FFFF61DA9A6} . ==================== Find3M ==================== . 2011-09-02 00:27:24 319456 —-a-w- c:\windows\DIFxAPI.dll 2011-08-16 22:46:04 3648424 —-a-w- c:\windows\system32\drivers\RTKVHDA.sys 2011-08-16 18:43:16 4228712 —-a-w- c:\windows\system32\RtkAPO.dll 2011-08-16 18:43:16 2269288 —-a-w- c:\windows\system32\RtkPgExt.dll 2011-08-15 20:47:14 77416 —-a-w- c:\windows\system32\RtkCoInst.dll 2011-07-29 18:46:56 1272424 —-a-w- c:\windows\system32\RtkApoApi.dll 2011-07-23 11:04:29 916480 —-a-w- c:\windows\system32\wininet.dll 2011-07-23 11:00:05 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-23 10:59:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-23 10:59:34 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-07-23 10:59:34 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-23 10:03:47 385024 —-a-w- c:\windows\system32\html.iec 2011-07-23 09:27:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-23 09:25:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-11 20:23:24 53848 —-a-w- c:\windows\system32\MBppld32.dll 2011-07-11 20:23:12 745560 —-a-w- c:\windows\system32\MBAPO32.dll 2011-07-11 18:17:00 1698408 —-a-w- c:\windows\RtlExUpd.dll 2011-07-08 04:14:40 8312832 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2011-07-08 03:37:28 53760 —-a-w- c:\windows\system32\OVDecode.dll 2011-07-08 03:37:06 43520 —-a-w- c:\windows\system32\OpenCL.dll 2011-07-08 03:36:46 13904896 —-a-w- c:\windows\system32\amdocl.dll 2011-07-08 03:33:28 17940992 —-a-w- c:\windows\system32\atioglxx.dll 2011-07-08 03:29:54 151552 —-a-w- c:\windows\system32\atiapfxx.exe 2011-07-08 03:29:44 689152 —-a-w- c:\windows\system32\aticfx32.dll 2011-07-08 03:25:48 462848 —-a-w- c:\windows\system32\ATIDEMGX.dll 2011-07-08 03:25:20 401408 —-a-w- c:\windows\system32\atieclxx.exe 2011-07-08 03:24:52 176128 —-a-w- c:\windows\system32\atiesrxx.exe 2011-07-08 03:23:40 159744 —-a-w- c:\windows\system32\atitmmxx.dll 2011-07-08 03:23:26 356352 —-a-w- c:\windows\system32\atipdlxx.dll 2011-07-08 03:23:14 278528 —-a-w- c:\windows\system32\Oemdspif.dll 2011-07-08 03:23:06 15872 —-a-w- c:\windows\system32\atimuixx.dll 2011-07-08 03:22:58 43520 —-a-w- c:\windows\system32\ati2edxx.dll 2011-07-08 03:19:50 4275712 —-a-w- c:\windows\system32\atidxx32.dll 2011-07-08 03:05:46 1828864 —-a-w- c:\windows\system32\atiumdmv.dll 2011-07-08 03:02:06 46080 —-a-w- c:\windows\system32\aticalrt.dll 2011-07-08 03:01:58 44032 —-a-w- c:\windows\system32\aticalcl.dll 2011-07-08 03:00:34 4367360 —-a-w- c:\windows\system32\atiumdag.dll 2011-07-08 02:58:52 6740480 —-a-w- c:\windows\system32\aticaldd.dll 2011-07-08 02:55:56 4039680 —-a-w- c:\windows\system32\atiumdva.dll 2011-07-08 02:54:28 52736 —-a-w- c:\windows\system32\coinst.dll 2011-07-08 02:47:34 266240 —-a-w- c:\windows\system32\atiadlxx.dll 2011-07-08 02:47:20 13312 —-a-w- c:\windows\system32\atiglpxx.dll 2011-07-08 02:47:10 32768 —-a-w- c:\windows\system32\atigktxx.dll 2011-07-08 02:46:42 244736 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2011-07-08 02:46:14 31744 —-a-w- c:\windows\system32\atiuxpag.dll 2011-07-08 02:45:58 29184 —-a-w- c:\windows\system32\atiu9pag.dll 2011-07-08 02:45:30 37376 —-a-w- c:\windows\system32\atitmpxx.dll 2011-07-08 02:45:10 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2011-07-08 02:40:48 52736 —-a-w- c:\windows\system32\atimpc32.dll 2011-07-08 02:40:48 52736 —-a-w- c:\windows\system32\amdpcom32.dll 2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-06 23:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-06 15:31:47 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-30 20:14:54 1497704 —-a-w- c:\windows\system32\RTSndMgr.cpl 2011-06-20 08:54:36 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-20 08:54:36 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-06-17 20:13:55 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-17 16:03:18 375808 —-a-w- c:\windows\system32\winsrv.dll 2011-06-16 07:34:06 79872 —-a-w- c:\windows\system32\SlotMaximizerAg.dll 2011-06-16 07:34:06 2117632 —-a-w- c:\windows\system32\SlotMaximizerBe.dll . ============= FINISH: 1:49:00.85 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 03/10/2008 6:35:47 PM System Uptime: 10/09/2011 10:37:06 PM (27 hours ago) . Motherboard: Dell Inc. | | 0M017G Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | CPU 1 | 1603/267mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 916 GiB total, 4.321 GiB free. D: is FIXED (NTFS) - 15 GiB total, 10.17 GiB free. E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) AAC Decoder AC3Filter (remove only) Acrobat.com Ad-Aware Ad-Aware Email Scanner for Outlook Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.5 Adobe Shockwave Player 11.5 Advanced File Joiner 1.12 AMD APP SDK Runtime AnyDVD Apple Application Support Apple Mobile Device Support Apple Software Update Ares 2.1.1 ATI Catalyst Install Manager µTorrent Audacity 1.2.6 Audacity Recovery Utility AutoUpdate AviSynth 2.5 AVS Update Manager 1.0 AVS Video Converter 6 AVS Video Editor 4 AVS YouTube Uploader version 2.1 AVS4YOU Software Navigator 1.3 Bing Bar BlackBerry App World Browser Plugin BlackBerry Desktop Software 6.1 BlackBerry Device Software v6.0.0 for the BlackBerry 9100/9105 smartphone Bonjour Boxee Browser Address Error Redirector Burn4Free CD and DVD Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy ccc-utility CCC Help English CCleaner CDBurnerXP Citrix Presentation Server Client - Web Only Click to Call with Skype CloneDVD [removed] Compatibility Pack for the 2007 Office system ConvertXtoDVD 4 english manual ConvertXtoDVD 4.1.2.336 d2mp D3DX10 Dell-eBay Dell Dock Dell Driver Download Manager Dell Driver Download Manager - 1 Dell Getting Started Guide Dell Support Center (Support Software) Dell Video Chat (remove only) DeVeDe 3.11b DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Version Checker DivX Web Player Dropbox DVD Decrypter (Remove Only) DVD Flick 1.3.0.7 DVD Shrink 3.2 DVDStyler v1.7.4 EDocs eMule ERUNT 1.1j ffdshow [rev 3164] [2009-12-14] Folder Size [removed] Free Ipod Video Converter V 2.6 FrostWire 4.21.1 Google Desktop Google Talk Plugin GoToAssist 8.0.0.514 H.264 Decoder Haali Media Splitter Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotspot Shield 1.37 ImgBurn Intel® Graphics Media Accelerator Driver iPodifier iTunes IZArc 3.81 Java Auto Updater Java™ 6 Update 18 Junk Mail filter update K-Meleon 1.5.4 en-US (remove only) Livestation LiveUpdate 3.3 (Symantec Corporation) Magic ISO Maker v5.5 (build 0281) Malwarebytes' Anti-Malware version 1.51.1.1800 ManyCam 2.6.55 (remove only) McAfee Security Scan Plus MediaCoder 0.6.2 Mesh Runtime Messenger Companion Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Primary Interoperability Assemblies 2005 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft Works MKV Splitter MKVtoolnix 2.2.0 Mouse Suite for Desktop Computers Mozilla ActiveX Control v1.7.12 Mozilla Firefox 6.0.2 (x86 en-US) MP3 Cutter Joiner 3.00 MPEG Joiner MSVCRT MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) neroxml Octoshape Streaming Services OpenAL Opera 10.51 Orbit Downloader PowerDVD QT Lite 2.7.0 QtWeb Internet Browser 3.7 QuickTime Real Alternative 2.0.1 Realtek 8169 8168 8101E 8102E Ethernet Driver Realtek Ethernet Network Card Diagnostic tool for Windows Vista Realtek High Definition Audio Driver Revo Uninstaller 1.93 Roxio Burn Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Safari Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office Groove 2007 (KB2494047) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Segoe UI Skype™ 5.5 Sothink Movie DVD Maker SoulSeek 157 NS 13c SpywareBlaster 4.2 StaxRip 1.1.1.0 SUPERAntiSpyware Free Edition Symantec Endpoint Protection TeamViewer 6 TMPGEnc 4.0 XPress TVAnts 1.0 TVUPlayer [removed] Ultra QuickTime Converter 2.3.0916 Ultra RM Converter 4.0.1127 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2509470) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (KB2586924) URL Snooper v2.23.01 VC80CRTRedist - 8.0.50727.762 Veetle TV 0.9.18 Veoh Video Compass Veoh Web Player VeohTV BETA Videora iPod Converter 6 VirtualDubMOD [removed] US Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 VLC media player 1.1.11 WinAVI MP4 Converter Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live OneCare safety scanner Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Player Firefox Plugin WinPcap 4.1 beta5 WinRAR archiver WinZip 15.0 XviD 1.1 final uninstall . ==== Event Viewer Messages From Past Week ======== . 11/09/2011 7:44:38 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 10/09/2011 12:51:46 AM, Error: volsnap [35] - The shadow copies of volume C: were aborted because the shadow copy storage failed to grow. 08/09/2011 5:25:59 PM, Error: EventLog [6008] - The previous system shutdown at 5:20:54 PM on 08/09/2011 was unexpected. 08/09/2011 5:24:44 PM, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied. 06/09/2011 11:18:11 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 06/09/2011 11:18:11 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 06/09/2011 11:09:56 PM, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting. 06/09/2011 11:03:08 PM, Error: EventLog [6008] - The previous system shutdown at 11:01:08 PM on 06/09/2011 was unexpected. . ==== End Of File ===========================
Greetings lelo
Let's try it this way please,
  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
  • Link 1
  • Link 2
  • Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • ]Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?
"

Next
Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Logs to post:
  • Rootkitunhooker report
  • mbrcheck.txt
Hi Bill, here are the rkunhooker and mbrcheck logs RkU Version: 3.8.389.593, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #4 ============================================== >Drivers ============================================== 0x8EA08000 C:\Windows\system32\DRIVERS\atikmdag.sys 8634368 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver) 0x82A3A000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System) 0x82A3A000 PnpManager 3907584 bytes 0x82A3A000 RAW 3907584 bytes 0x82A3A000 WMIxWDM 3907584 bytes 0x8FC0E000 C:\Windows\system32\drivers\RTKVHDA.sys 3645440 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x9360B000 C:\Windows\system32\DRIVERS\lvsvf2.sys 2207744 bytes (Logitech Inc., SmoothVision filter) 0xA5870000 C:\Windows\System32\win32k.sys 2113536 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x90802000 C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVEX15.SYS 1572864 bytes (Symantec Corporation, AV Engine) 0x8FAAD000 C:\Windows\system32\DRIVERS\LVCM.sys 1318912 bytes (-, -) 0x8AC05000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver) 0x8307D000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x83205000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver) 0x804DB000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xB08A3000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0xA9A0F000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0x8F244000 C:\Windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0x8F2F0000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x8300C000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x8060B000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime) 0x80411000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library) 0xA9B22000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x9B40E000 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 434176 bytes (Symantec Corporation, SPBBC Driver) 0x9B4EB000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xB082C000 C:\Windows\System32\DRIVERS\srv.sys 323584 bytes (Microsoft Corporation, Server driver) 0x8FF88000 C:\Windows\System32\Drivers\SRTSP.SYS 303104 bytes (Symantec Corporation, Symantec AutoProtect) 0x80726000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x9390F000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x8068A000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x8049A000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x8F602000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x83319000 C:\Windows\system32\DRIVERS\atikmpag.sys 262144 bytes (Advanced Micro Devices, Inc., AMD multi-vendor Miniport Driver) 0x8FA0F000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver) 0x8F388000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x9B4A0000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x831B3000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0x939C0000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x8AD15000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x8F792000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x82A07000 ACPI_HAL 208896 bytes 0x82A07000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB6201000 C:\Windows\System32\Drivers\RDPWD.SYS 208896 bytes (Microsoft Corporation, RDP Terminal Stack Driver) 0x807C2000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x93957000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x833AB000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x8FA4E000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x938CE000 C:\Windows\System32\Drivers\SYMTDI.SYS 184320 bytes (Symantec Corporation, Network Dispatch Driver) 0x83188000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8F66E000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0xA9ACF000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xB087B000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB0804000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8AD65000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x806E1000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x8FA7B000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x90982000 C:\Windows\system32\Drivers\SYMEVENT.SYS 151552 bytes (Symantec Corporation, Symantec Event Library) 0x8F6DF000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x83359000 C:\Windows\system32\DRIVERS\Rtlh86.sys 139264 bytes (Realtek Corporation , Realtek 8101E/8168/8169 NDIS6 32-bit Driver ) 0x9B478000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS) 0x8AD9D000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0xA9BDA000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x93853000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0x9B5D2000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x807A4000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x9B549000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 122880 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xA9B8F000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x832EF000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x9B5B7000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0xA9BAC000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x8337B000 C:\Windows\System32\Drivers\AnyDVD.sys 98304 bytes (SlySoft, Inc., AnyDVD Filter Driver) 0x83393000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0x8F7E5000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x9B567000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x8F6BD000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0x8FFD2000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xB6239000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x93989000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x938B8000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0xA9BC5000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8F725000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8FFE9000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 86016 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xB0997000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector) 0x909A7000 C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0x8F711000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xB63A6000 C:\Windows\System32\Drivers\RimUsb.sys 81920 bytes (Research In Motion Limited, BlackBerry Device Driver) 0x938FB000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0xA9B03000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x939AD000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x93874000 C:\Windows\system32\drivers\usbaudio.sys 73728 bytes (Microsoft Corporation, USB Audio Class Driver) 0xB09AC000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0x8AD8C000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8F7C7000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x80481000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x805BB000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0x909D1000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0x8F6AD000 C:\Windows\system32\DRIVERS\HssDrv.sys 65536 bytes (AnchorFree Inc., Hotspot Shield Routing Driver) 0xA9ABF000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x8078C000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x8F3D5000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0x8F753000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x8330A000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0x805CB000 C:\Windows\system32\DRIVERS\Lbd.sys 61440 bytes (Lavasoft AB, Boot Driver) 0x9B5A8000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x8AD56000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x80708000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8F702000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x8F3C6000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x80717000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x8F3E5000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xA5AB0000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x9399F000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x938A1000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x80777000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x8067C000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader) 0x9B57E000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x8F6A0000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0x8F661000 C:\Windows\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0) 0x8F785000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0xA9B16000 C:\Windows\system32\DRIVERS\RtNdPt60.sys 49152 bytes (Windows ® Codename Longhorn DDK provider, NDIS User mode I/O Driver) 0xB098B000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0xB09C9000 C:\Windows\System32\DRIVERS\tssecsrv.sys 49152 bytes (Microsoft Corporation, TS Security Filter Driver) 0x93847000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x8F2E4000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0xB6310000 C:\Users\sonam\AppData\Local\Temp\aswMBR.sys 45056 bytes 0x9B58B000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes 0x8F763000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x8FC00000 C:\Windows\system32\drivers\lvusbsta.sys 45056 bytes (Logitech Inc., USB Statistic Driver) 0x8F76E000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x93896000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8F6D4000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8F73A000 C:\Windows\system32\DRIVERS\tapvpn.sys 45056 bytes (The OpenVPN Project, TAP-Win32 Virtual Network Driver) 0x8F643000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0xB09BE000 C:\Windows\system32\drivers\tdtcp.sys 45056 bytes (Microsoft Corporation, TCP Transport Driver) 0x8ADE7000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x8F37D000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x9B59E000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8F77B000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0xA9AF9000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x9B4DC000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0x909BE000 C:\Windows\system32\DRIVERS\pmxmouse.sys 40960 bytes (Primax Electronics Ltd., Mouse Suite Driver (For Windows 2000 and Whistler Only)) 0x807F4000 C:\Windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xB0981000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0x93826000 C:\Windows\System32\Drivers\SRTSPX.SYS 40960 bytes (Symantec Corporation, Symantec AutoProtect) 0xB62BB000 C:\Windows\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver) 0x8ADBE000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x93830000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0x909C8000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0x909F2000 C:\Windows\system32\DRIVERS\kbdhid.sys 36864 bytes (Microsoft Corporation, HID Keyboard Filter Driver) 0x938AF000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xA5A90000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8ADF2000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x806D0000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x8079C000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x80492000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x9B596000 C:\Windows\System32\Drivers\dump_atapi.sys 32768 bytes 0x909EA000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0x806D9000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x93886000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x9388E000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8F698000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver) 0x8AD4E000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x93840000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0x909E1000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x80770000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xB6355000 C:\Users\sonam\AppData\Local\Temp\mbr.sys 28672 bytes 0x93839000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x80785000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0x8F74C000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver) 0x8F745000 C:\Windows\system32\DRIVERS\taphss.sys 28672 bytes (AnchorFree Inc, TAP-Win32 Virtual Network Driver) 0x8F3F3000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0x8F65B000 C:\Windows\system32\DRIVERS\ManyCam.sys 24576 bytes (ManyCam LLC., ManyCam Virtual Webcam, WDM Video Capture Driver) 0x9B49A000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS) 0x9B4E6000 C:\Windows\System32\Drivers\ElbyCDIO.sys 20480 bytes (Elaborate Bytes AG, ElbyCD Windows NT/2000/XP I/O driver) 0xB6234000 C:\Windows\System32\Drivers\SYMREDRV.SYS 20480 bytes (Symantec Corporation, Redirector Filter Driver) 0x909BB000 C:\Windows\system32\DRIVERS\pmxusblf.sys 12288 bytes (Primax Electronics Ltd., USB Mouse Low Filter Driver(Win2000 only)) 0x8040F000 C:\Windows\system32\kdcom.dll 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xB6365000 C:\Windows\system32\drivers\MSPCLOCK.sys 8192 bytes (Microsoft Corporation, MS Proxy Clock) 0xB632D000 C:\Windows\system32\drivers\MSPQM.sys 8192 bytes (Microsoft Corporation, MS Proxy Quality Manager) 0x8F779000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x909E8000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0x8713BF16 unknown_irp_handler 234 bytes ============================================== >Stealth ============================================== 0x8713E63B Unknown page with executable code, 2501 bytes 0x8713E108 Unknown thread object [ ETHREAD 0x87185970 ] TID: 236, 600 bytes 0x8713FA11 Unknown thread object [ ETHREAD 0x8714E970 ] TID: 248, 600 bytes MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: Dell Inc. BIOS Manufacturer: Dell Inc. System Manufacturer: Dell Inc. System Product Name: Studio 540 Logical Drives Mask: 0x000001fc Kernel Drivers (total 176): 0x82A3A000 \SystemRoot\system32\ntkrnlpa.exe 0x82A07000 \SystemRoot\system32\hal.dll 0x8040F000 \SystemRoot\system32\kdcom.dll 0x80411000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x80481000 \SystemRoot\system32\PSHED.dll 0x80492000 \SystemRoot\system32\BOOTVID.dll 0x8049A000 \SystemRoot\system32\CLFS.SYS 0x804DB000 \SystemRoot\system32\CI.dll 0x8060B000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8067C000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8068A000 \SystemRoot\system32\drivers\acpi.sys 0x806D0000 \SystemRoot\system32\drivers\WMILIB.SYS 0x806D9000 \SystemRoot\system32\drivers\msisadrv.sys 0x806E1000 \SystemRoot\system32\drivers\pci.sys 0x80708000 \SystemRoot\System32\drivers\partmgr.sys 0x80717000 \SystemRoot\system32\drivers\volmgr.sys 0x80726000 \SystemRoot\System32\drivers\volmgrx.sys 0x80770000 \SystemRoot\system32\DRIVERS\intelide.sys 0x80777000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x80785000 \SystemRoot\system32\drivers\pciide.sys 0x8078C000 \SystemRoot\System32\drivers\mountmgr.sys 0x8079C000 \SystemRoot\system32\drivers\atapi.sys 0x807A4000 \SystemRoot\system32\drivers\ataport.SYS 0x807C2000 \SystemRoot\system32\drivers\fltmgr.sys 0x805BB000 \SystemRoot\system32\drivers\fileinfo.sys 0x805CB000 \SystemRoot\system32\DRIVERS\Lbd.sys 0x807F4000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x8300C000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8307D000 \SystemRoot\system32\drivers\ndis.sys 0x83188000 \SystemRoot\system32\drivers\msrpc.sys 0x831B3000 \SystemRoot\system32\drivers\NETIO.SYS 0x83205000 \SystemRoot\System32\drivers\tcpip.sys 0x832EF000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8AC05000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8AD15000 \SystemRoot\system32\drivers\volsnap.sys 0x8AD4E000 \SystemRoot\System32\Drivers\spldr.sys 0x8AD56000 \SystemRoot\System32\Drivers\mup.sys 0x8AD65000 \SystemRoot\System32\drivers\ecache.sys 0x8AD8C000 \SystemRoot\system32\drivers\disk.sys 0x8AD9D000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x8ADBE000 \SystemRoot\system32\drivers\crcdisk.sys 0x8ADE7000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8ADF2000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x8330A000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x83319000 \SystemRoot\system32\DRIVERS\atikmpag.sys 0x8EA08000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x8F244000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8F2E4000 \SystemRoot\System32\drivers\watchdog.sys 0x8F2F0000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8F37D000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8F388000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8F3C6000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8F3D5000 \SystemRoot\system32\DRIVERS\ohci1394.sys 0x8F3E5000 \SystemRoot\system32\DRIVERS\1394BUS.SYS 0x83359000 \SystemRoot\system32\DRIVERS\Rtlh86.sys 0x8337B000 \SystemRoot\System32\Drivers\AnyDVD.sys 0x83393000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8F3F3000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x833AB000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8F602000 \SystemRoot\system32\DRIVERS\storport.sys 0x8F643000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8F65B000 \SystemRoot\system32\DRIVERS\ManyCam.sys 0x8F661000 \SystemRoot\system32\DRIVERS\STREAM.SYS 0x8F66E000 \SystemRoot\system32\DRIVERS\ks.sys 0x8F698000 \SystemRoot\System32\Drivers\RootMdm.sys 0x8F6A0000 \SystemRoot\system32\drivers\modem.sys 0x8F6AD000 \SystemRoot\system32\DRIVERS\HssDrv.sys 0x8F6BD000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8F6D4000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8F6DF000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8F702000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8F711000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8F725000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8F73A000 \SystemRoot\system32\DRIVERS\tapvpn.sys 0x8F745000 \SystemRoot\system32\DRIVERS\taphss.sys 0x8F74C000 \SystemRoot\system32\DRIVERS\RimSerial.sys 0x8F753000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8F763000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8F76E000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8F779000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8F77B000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8F785000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8F792000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8F7C7000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8FA0F000 \SystemRoot\system32\drivers\HdAudio.sys 0x8FA4E000 \SystemRoot\system32\drivers\portcls.sys 0x8FA7B000 \SystemRoot\system32\drivers\drmk.sys 0x8FC0E000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x8FF88000 \SystemRoot\System32\Drivers\SRTSP.SYS 0x90802000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVEX15.SYS 0x90982000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS 0x909A7000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVENG.SYS 0x909BB000 \SystemRoot\system32\DRIVERS\pmxusblf.sys 0x909BE000 \SystemRoot\system32\DRIVERS\pmxmouse.sys 0x909C8000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x909D1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x909E1000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x909E8000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x909EA000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8FFD2000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x909F2000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8FFE9000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x8FC00000 \SystemRoot\system32\drivers\lvusbsta.sys 0x8FAAD000 \SystemRoot\system32\DRIVERS\LVCM.sys 0x9360B000 \SystemRoot\system32\DRIVERS\lvsvf2.sys 0x93826000 \SystemRoot\System32\Drivers\SRTSPX.SYS 0x93830000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x93839000 \SystemRoot\System32\Drivers\Null.SYS 0x93840000 \SystemRoot\System32\Drivers\Beep.SYS 0x93847000 \SystemRoot\System32\drivers\vga.sys 0x93853000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x93874000 \SystemRoot\system32\drivers\usbaudio.sys 0x93886000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x9388E000 \SystemRoot\system32\drivers\rdpencdd.sys 0x93896000 \SystemRoot\System32\Drivers\Msfs.SYS 0x938A1000 \SystemRoot\System32\Drivers\Npfs.SYS 0x938AF000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x938B8000 \SystemRoot\system32\DRIVERS\tdx.sys 0x938CE000 \SystemRoot\System32\Drivers\SYMTDI.SYS 0x938FB000 \SystemRoot\system32\DRIVERS\smb.sys 0x9390F000 \SystemRoot\system32\drivers\afd.sys 0x93957000 \SystemRoot\System32\DRIVERS\netbt.sys 0x93989000 \SystemRoot\system32\DRIVERS\pacer.sys 0x9399F000 \SystemRoot\system32\DRIVERS\netbios.sys 0x939AD000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x9B40E000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 0x9B478000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 0x9B49A000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0x9B4A0000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x9B4DC000 \SystemRoot\system32\drivers\nsiproxy.sys 0x9B4E6000 \SystemRoot\System32\Drivers\ElbyCDIO.sys 0x9B4EB000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0x9B549000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0x9B567000 \SystemRoot\System32\Drivers\dfsc.sys 0x9B57E000 \SystemRoot\System32\Drivers\crashdmp.sys 0x9B58B000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x9B596000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xA5870000 \SystemRoot\System32\win32k.sys 0x9B59E000 \SystemRoot\System32\drivers\Dxapi.sys 0x9B5A8000 \SystemRoot\system32\DRIVERS\monitor.sys 0xA5A90000 \SystemRoot\System32\TSDDD.dll 0xA5AB0000 \SystemRoot\System32\cdd.dll 0x9B5B7000 \SystemRoot\system32\drivers\luafv.sys 0xA9A0F000 \SystemRoot\system32\drivers\spsys.sys 0xA9ABF000 \SystemRoot\system32\DRIVERS\lltdio.sys 0xA9ACF000 \SystemRoot\system32\DRIVERS\nwifi.sys 0xA9AF9000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA9B03000 \SystemRoot\system32\DRIVERS\rspndr.sys 0xA9B16000 \SystemRoot\system32\DRIVERS\RtNdPt60.sys 0xA9B22000 \SystemRoot\system32\drivers\HTTP.sys 0xA9B8F000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xA9BAC000 \SystemRoot\system32\DRIVERS\bowser.sys 0xA9BC5000 \SystemRoot\System32\drivers\mpsdrv.sys 0xA9BDA000 \SystemRoot\system32\drivers\mrxdav.sys 0x9B5D2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x939C0000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x8F7E5000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0xB0804000 \SystemRoot\System32\DRIVERS\srv2.sys 0xB082C000 \SystemRoot\System32\DRIVERS\srv.sys 0xB087B000 \SystemRoot\System32\Drivers\fastfat.SYS 0xB08A3000 \SystemRoot\system32\drivers\peauth.sys 0xB0981000 \SystemRoot\System32\Drivers\secdrv.SYS 0xB098B000 \SystemRoot\System32\drivers\tcpipreg.sys 0xB0997000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0xB09AC000 \SystemRoot\system32\DRIVERS\WUDFPf.sys 0xB09BE000 \SystemRoot\system32\drivers\tdtcp.sys 0xB09C9000 \SystemRoot\System32\DRIVERS\tssecsrv.sys 0xB6201000 \SystemRoot\System32\Drivers\RDPWD.SYS 0xB6234000 \SystemRoot\System32\Drivers\SYMREDRV.SYS 0xB6239000 \SystemRoot\system32\DRIVERS\cdfs.sys 0xB6310000 \??\C:\Users\sonam\AppData\Local\Temp\aswMBR.sys 0xB6355000 \??\C:\Users\sonam\AppData\Local\Temp\mbr.sys 0xB632D000 \SystemRoot\system32\drivers\MSPQM.sys 0xB6365000 \SystemRoot\system32\drivers\MSPCLOCK.sys 0xB63A6000 \SystemRoot\System32\Drivers\RimUsb.sys 0x77670000 \Windows\System32\ntdll.dll Processes (total 98): 0 System Idle Process 4 System 508 C:\Windows\System32\smss.exe 584 csrss.exe 656 csrss.exe 664 C:\Windows\System32\wininit.exe 708 C:\Windows\System32\winlogon.exe 748 C:\Windows\System32\services.exe 760 C:\Windows\System32\lsass.exe 780 C:\Windows\System32\lsm.exe 924 C:\Windows\System32\svchost.exe 988 C:\Windows\System32\svchost.exe 1052 C:\Windows\System32\svchost.exe 1136 C:\Windows\System32\atiesrxx.exe 1160 C:\Windows\System32\svchost.exe 1228 C:\Windows\System32\svchost.exe 1244 C:\Windows\System32\svchost.exe 1324 C:\Windows\System32\audiodg.exe 1352 C:\Windows\System32\svchost.exe 1372 C:\Windows\System32\SLsvc.exe 1412 C:\Windows\System32\svchost.exe 1532 C:\Program Files\Dell\DellDock\DockLogin.exe 1552 C:\Windows\System32\atieclxx.exe 1660 C:\Program Files\Symantec AntiVirus\Smc.exe 1936 C:\Windows\System32\dwm.exe 1948 C:\Windows\System32\svchost.exe 532 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 304 C:\Windows\System32\spoolsv.exe 1824 C:\Windows\System32\svchost.exe 2156 C:\Windows\System32\taskeng.exe 2400 C:\Program Files\Symantec AntiVirus\SmcGui.exe 2472 C:\Windows\System32\taskeng.exe 2696 C:\Program Files\SUPERAntiSpyware\SASCORE.EXE 2740 C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe 2752 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 2760 C:\Program Files\Windows Defender\MSASCui.exe 2788 C:\Windows\System32\ico.exe 2804 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 2872 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe 3032 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 3048 C:\Program Files\Common Files\Symantec Shared\ccApp.exe 3104 C:\Program Files\Bonjour\mDNSResponder.exe 3212 C:\Program Files\Hotspot Shield\bin\openvpnas.exe 3264 C:\Program Files\iTunes\iTunesHelper.exe 3296 C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe 3320 C:\Program Files\Hotspot Shield\bin\hsswd.exe 3364 C:\Program Files\CDBurnerXP\NMSAccessU.exe 3444 C:\Program Files\Roxio\Roxio Burn\RoxioBurnLauncher.exe 3488 C:\Windows\System32\svchost.exe 3520 C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe 3576 C:\Program Files\Microsoft\BingBar\SeaPort.EXE 3640 C:\Program Files\Dell Support Center\bin\sprtsvc.exe 3676 C:\Windows\System32\svchost.exe 3768 C:\Program Files\Symantec AntiVirus\Rtvscan.exe 3776 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe 3840 C:\Windows\System32\svchost.exe 3884 C:\Windows\ehome\ehtray.exe 3896 C:\Program Files\Dell Support Center\bin\sprtcmd.exe 3904 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE 3944 C:\Windows\System32\SearchIndexer.exe 4044 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE 2132 WUDFHost.exe 1884 C:\Program Files\ManyCam\Bin\ManyCam.exe 2920 C:\Windows\ehome\ehmsas.exe 2044 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe 1816 C:\Program Files\Windows Media Player\wmpnscfg.exe 4304 C:\Program Files\Windows Media Player\wmplayer.exe 4772 C:\Program Files\Windows Media Player\wmpnetwk.exe 5148 C:\Windows\System32\pmxmiced.exe 5504 C:\Program Files\Hotspot Shield\bin\openvpntray.exe 3180 C:\Program Files\iPod\bin\iPodService.exe 4104 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe 4420 C:\Windows\System32\svchost.exe 2904 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe 1464 C:\Program Files\iTunes\iTunes.exe 1812 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe 3504 C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe 900 C:\Program Files\Java\jre6\bin\javaw.exe 6636 C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe 7860 C:\Windows\explorer.exe 3728 C:\Windows\explorer.exe 5528 C:\Windows\System32\taskmgr.exe 7640 unsecapp.exe 8100 WmiPrvSE.exe 6932 C:\Program Files\Roxio\Roxio Burn\Roxio Burn.exe 5316 C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe 5500 C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe 7848 C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe 6324 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 8240 C:\Program Files\Mozilla Firefox\firefox.exe 4324 C:\Program Files\Mozilla Firefox\plugin-container.exe 6332 C:\Windows\servicing\TrustedInstaller.exe 8928 C:\Windows\System32\svchost.exe 9940 C:\Windows\System32\msiexec.exe 7796 9700 9088 C:\Program Files\Symantec AntiVirus\SymCorpUI.exe 5564 C:\Users\sonam\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`c4700000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`04700000 (NTFS) PhysicalDrive0 Model Number: ST31000340AS, Rev: DE12 Size Device Name MBR Status ——————————————– 931 GB \\.\PhysicalDrive0 MBR Code Faked! SHA1: 38BE7869FCCF026F920DA4A541B12E68993C36ED Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Greetings lelo,

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

    [external image: Posted Image]
  • If an infected file is detected, the default action will be Cure, click on Continue.

    [external image: Posted Image]
  • If a suspicious file is detected, the default action will be Skip, click on Continue.

    [external image: Posted Image]
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file in your next post.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_

    [Time]_log.txt
    ". Please copy and paste the contents of that file in your next post.

Next
***Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or

copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these

instructions.***

Download Combofix from any of the links below. Save it to your desktop.

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere

    with our tools
  • See this Link for programs that need to be

    disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the

connections.


Logs to post:
  • TDSSKiller.txt
  • Combofix.txt
Hi Bill, here are the tdsskiller and combofix logs 2011/09/16 13:08:45.0535 6404 TDSS rootkit removing tool 2.5.22.0 Sep 13 2011 15:55:17 2011/09/16 13:08:45.0912 6404 ================================================================================ 2011/09/16 13:08:45.0912 6404 SystemInfo: 2011/09/16 13:08:45.0912 6404 2011/09/16 13:08:45.0912 6404 OS Version: 6.0.6002 ServicePack: 2.0 2011/09/16 13:08:45.0912 6404 Product type: Workstation 2011/09/16 13:08:45.0912 6404 ComputerName: SONAM-PC 2011/09/16 13:08:45.0913 6404 UserName: sonam 2011/09/16 13:08:45.0913 6404 Windows directory: C:\Windows 2011/09/16 13:08:45.0913 6404 System windows directory: C:\Windows 2011/09/16 13:08:45.0913 6404 Processor architecture: Intel x86 2011/09/16 13:08:45.0913 6404 Number of processors: 4 2011/09/16 13:08:45.0913 6404 Page size: 0x1000 2011/09/16 13:08:45.0913 6404 Boot type: Normal boot 2011/09/16 13:08:45.0913 6404 ================================================================================ 2011/09/16 13:08:50.0329 6404 Initialize success 2011/09/16 13:09:24.0189 3176 ================================================================================ 2011/09/16 13:09:24.0189 3176 Scan started 2011/09/16 13:09:24.0189 3176 Mode: Manual; 2011/09/16 13:09:24.0189 3176 ================================================================================ 2011/09/16 13:09:25.0849 3176 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/09/16 13:09:25.0890 3176 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/09/16 13:09:26.0020 3176 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/09/16 13:09:26.0203 3176 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/09/16 13:09:26.0350 3176 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/09/16 13:09:26.0545 3176 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 2011/09/16 13:09:26.0577 3176 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/09/16 13:09:26.0687 3176 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/09/16 13:09:26.0823 3176 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2011/09/16 13:09:26.0913 3176 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/09/16 13:09:27.0002 3176 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2011/09/16 13:09:27.0049 3176 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/09/16 13:09:27.0084 3176 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 2011/09/16 13:09:27.0276 3176 amdkmdag (335ace2a8e97439733f0f6a1bbd818d5) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/09/16 13:09:27.0474 3176 amdkmdap (0b1b116d30f133dc918287fd8e212f1e) C:\Windows\system32\DRIVERS\atikmpag.sys 2011/09/16 13:09:27.0545 3176 AnyDVD (985e8a177af050105d7e1dee1d6cdfb3) C:\Windows\system32\Drivers\AnyDVD.sys 2011/09/16 13:09:27.0595 3176 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/09/16 13:09:27.0764 3176 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/09/16 13:09:27.0870 3176 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/09/16 13:09:27.0950 3176 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/09/16 13:09:28.0124 3176 atikmdag (335ace2a8e97439733f0f6a1bbd818d5) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/09/16 13:09:28.0213 3176 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/09/16 13:09:28.0255 3176 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/09/16 13:09:28.0317 3176 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 2011/09/16 13:09:28.0338 3176 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/09/16 13:09:28.0363 3176 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/09/16 13:09:28.0424 3176 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/09/16 13:09:28.0471 3176 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/09/16 13:09:28.0504 3176 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/09/16 13:09:28.0556 3176 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/09/16 13:09:28.0591 3176 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/09/16 13:09:28.0685 3176 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/09/16 13:09:28.0753 3176 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/09/16 13:09:28.0783 3176 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/09/16 13:09:28.0828 3176 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/09/16 13:09:28.0874 3176 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2011/09/16 13:09:29.0017 3176 COH_Mon (c586875ece5318c6309ed1ab79d0e55f) C:\Windows\system32\Drivers\COH_Mon.sys 2011/09/16 13:09:29.0038 3176 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 2011/09/16 13:09:29.0131 3176 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/09/16 13:09:29.0176 3176 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/09/16 13:09:29.0271 3176 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 2011/09/16 13:09:29.0318 3176 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/09/16 13:09:29.0377 3176 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/09/16 13:09:29.0426 3176 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/09/16 13:09:29.0519 3176 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys 2011/09/16 13:09:29.0578 3176 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/09/16 13:09:29.0644 3176 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/09/16 13:09:29.0729 3176 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/09/16 13:09:29.0852 3176 ElbyCDIO (178cc9403816c082d22a1d47fa1f9c85) C:\Windows\system32\Drivers\ElbyCDIO.sys 2011/09/16 13:09:29.0885 3176 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/09/16 13:09:30.0004 3176 EraserUtilRebootDrv (3ee14d400e0fdd0d214275a4a20b7022) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 2011/09/16 13:09:30.0115 3176 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/09/16 13:09:30.0197 3176 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/09/16 13:09:30.0261 3176 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/09/16 13:09:30.0285 3176 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/09/16 13:09:30.0341 3176 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/09/16 13:09:30.0382 3176 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/09/16 13:09:30.0416 3176 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/09/16 13:09:30.0448 3176 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/09/16 13:09:30.0500 3176 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys 2011/09/16 13:09:30.0707 3176 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/09/16 13:09:30.0730 3176 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/09/16 13:09:30.0859 3176 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2011/09/16 13:09:30.0940 3176 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 2011/09/16 13:09:31.0004 3176 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/09/16 13:09:31.0031 3176 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/09/16 13:09:31.0070 3176 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/09/16 13:09:31.0148 3176 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/09/16 13:09:31.0183 3176 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/09/16 13:09:31.0290 3176 HssDrv (30858b2d6dc0d8ed044dc28011ade6a2) C:\Windows\system32\DRIVERS\HssDrv.sys 2011/09/16 13:09:31.0356 3176 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/09/16 13:09:31.0386 3176 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/09/16 13:09:31.0495 3176 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/09/16 13:09:31.0545 3176 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\Windows\system32\drivers\iastor.sys 2011/09/16 13:09:31.0723 3176 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/09/16 13:09:31.0894 3176 igfx (0627fc0c422cd6e0f23e1b0d1d9f0899) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/09/16 13:09:32.0008 3176 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/09/16 13:09:32.0343 3176 IntcAzAudAddService (6cac927c002dd79d666aa71332eaf03a) C:\Windows\system32\drivers\RTKVHDA.sys 2011/09/16 13:09:32.0423 3176 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\DRIVERS\intelide.sys 2011/09/16 13:09:32.0479 3176 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/09/16 13:09:32.0521 3176 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/09/16 13:09:32.0578 3176 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/09/16 13:09:32.0630 3176 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/09/16 13:09:32.0699 3176 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/09/16 13:09:32.0770 3176 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/09/16 13:09:32.0964 3176 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/09/16 13:09:32.0992 3176 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/09/16 13:09:33.0175 3176 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/09/16 13:09:33.0236 3176 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/09/16 13:09:33.0298 3176 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/09/16 13:09:33.0368 3176 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/09/16 13:09:33.0507 3176 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys 2011/09/16 13:09:33.0538 3176 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/09/16 13:09:33.0580 3176 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/09/16 13:09:33.0691 3176 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/09/16 13:09:33.0767 3176 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/09/16 13:09:33.0888 3176 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/09/16 13:09:33.0967 3176 LVUSBSta (c5efbd05a5195402121711a6ebbb271f) C:\Windows\system32\drivers\lvusbsta.sys 2011/09/16 13:09:34.0021 3176 ManyCam (c6d085c7045200143528136a43a65fde) C:\Windows\system32\DRIVERS\ManyCam.sys 2011/09/16 13:09:34.0075 3176 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/09/16 13:09:34.0158 3176 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/09/16 13:09:34.0255 3176 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/09/16 13:09:34.0277 3176 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/09/16 13:09:34.0293 3176 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/09/16 13:09:34.0311 3176 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/09/16 13:09:34.0336 3176 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/09/16 13:09:34.0368 3176 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/09/16 13:09:34.0483 3176 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/09/16 13:09:34.0510 3176 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/09/16 13:09:34.0609 3176 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/09/16 13:09:34.0651 3176 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/09/16 13:09:34.0695 3176 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/09/16 13:09:34.0725 3176 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/09/16 13:09:34.0753 3176 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys 2011/09/16 13:09:34.0853 3176 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/09/16 13:09:34.0935 3176 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/09/16 13:09:34.0968 3176 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/09/16 13:09:35.0004 3176 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/09/16 13:09:35.0036 3176 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/09/16 13:09:35.0057 3176 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/09/16 13:09:35.0119 3176 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/09/16 13:09:35.0142 3176 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/09/16 13:09:35.0167 3176 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/09/16 13:09:35.0235 3176 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/09/16 13:09:35.0296 3176 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/09/16 13:09:35.0368 3176 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVENG.SYS 2011/09/16 13:09:35.0413 3176 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110907.017\NAVEX15.SYS 2011/09/16 13:09:35.0492 3176 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/09/16 13:09:35.0535 3176 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/09/16 13:09:35.0552 3176 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/09/16 13:09:35.0629 3176 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/09/16 13:09:35.0657 3176 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/09/16 13:09:35.0680 3176 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/09/16 13:09:35.0742 3176 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/09/16 13:09:35.0802 3176 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/09/16 13:09:35.0928 3176 NPF (c5f0202a00227aecb69e722c52385ffc) C:\Windows\system32\drivers\npf.sys 2011/09/16 13:09:35.0997 3176 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/09/16 13:09:36.0025 3176 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/09/16 13:09:36.0094 3176 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/09/16 13:09:36.0139 3176 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/09/16 13:09:36.0173 3176 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/09/16 13:09:36.0198 3176 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/09/16 13:09:36.0249 3176 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/09/16 13:09:36.0309 3176 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/09/16 13:09:36.0407 3176 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 2011/09/16 13:09:36.0479 3176 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/09/16 13:09:36.0555 3176 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/09/16 13:09:36.0579 3176 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/09/16 13:09:36.0687 3176 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/09/16 13:09:36.0710 3176 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 2011/09/16 13:09:36.0745 3176 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/09/16 13:09:36.0843 3176 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys 2011/09/16 13:09:36.0885 3176 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/09/16 13:09:36.0945 3176 pmxmouse (fab495f1defeb596c44b9752a25e2a60) C:\Windows\system32\DRIVERS\pmxmouse.sys 2011/09/16 13:09:36.0964 3176 pmxusblf (020eae9dfe3cd277994ce60e4c2c71cf) C:\Windows\system32\DRIVERS\pmxusblf.sys 2011/09/16 13:09:37.0001 3176 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/09/16 13:09:37.0023 3176 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/09/16 13:09:37.0080 3176 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/09/16 13:09:37.0124 3176 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys 2011/09/16 13:09:37.0203 3176 QCMerced (9a155d31b8e52f41b258282092cc93a7) C:\Windows\system32\DRIVERS\LVCM.sys 2011/09/16 13:09:37.0265 3176 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/09/16 13:09:37.0485 3176 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/09/16 13:09:37.0598 3176 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/09/16 13:09:37.0786 3176 R300 (335ace2a8e97439733f0f6a1bbd818d5) C:\Windows\system32\DRIVERS\atikmdag.sys 2011/09/16 13:09:37.0867 3176 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/09/16 13:09:37.0906 3176 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/09/16 13:09:37.0988 3176 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/09/16 13:09:38.0028 3176 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/09/16 13:09:38.0132 3176 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/09/16 13:09:38.0158 3176 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/09/16 13:09:38.0199 3176 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/09/16 13:09:38.0241 3176 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/09/16 13:09:38.0282 3176 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/09/16 13:09:38.0354 3176 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\Windows\system32\Drivers\RimUsb.sys 2011/09/16 13:09:38.0486 3176 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys 2011/09/16 13:09:38.0511 3176 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys 2011/09/16 13:09:38.0554 3176 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/09/16 13:09:38.0599 3176 RTL8169 (125c504a34d0a2e152517e342e7e432c) C:\Windows\system32\DRIVERS\Rtlh86.sys 2011/09/16 13:09:38.0667 3176 RTL8187 (99c27fceb21347daf3ee9e8c205314d6) C:\Windows\system32\DRIVERS\wg111v2.sys 2011/09/16 13:09:38.0738 3176 RtNdPt60 (7f8d15ee000577be703537849d4f9397) C:\Windows\system32\DRIVERS\RtNdPt60.sys 2011/09/16 13:09:38.0839 3176 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 2011/09/16 13:09:38.0974 3176 SASENUM (7ce61c25c159f50f9eaf6d77fc83fa35) C:\Program Files\SUPERAntiSpyware\SASENUM.SYS 2011/09/16 13:09:39.0093 3176 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 2011/09/16 13:09:39.0190 3176 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/09/16 13:09:39.0297 3176 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/09/16 13:09:39.0337 3176 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/09/16 13:09:39.0397 3176 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/09/16 13:09:39.0430 3176 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/09/16 13:09:39.0565 3176 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/09/16 13:09:39.0627 3176 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/09/16 13:09:39.0665 3176 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/09/16 13:09:39.0703 3176 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/09/16 13:09:39.0758 3176 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/09/16 13:09:39.0815 3176 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/09/16 13:09:39.0849 3176 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/09/16 13:09:39.0974 3176 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/09/16 13:09:40.0069 3176 SPBBCDrv (e621bb5839cf45fa477f48092edd2b40) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 2011/09/16 13:09:40.0150 3176 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/09/16 13:09:40.0215 3176 SRTSP (2abf82c8452ab0b9ffc74a2d5da91989) C:\Windows\system32\Drivers\SRTSP.SYS 2011/09/16 13:09:40.0247 3176 SRTSPL (e2f9e5887bea5bd8784d337e06eda31b) C:\Windows\system32\Drivers\SRTSPL.SYS 2011/09/16 13:09:40.0357 3176 SRTSPX (3b974c158fabd910186f98df8d3e23f3) C:\Windows\system32\Drivers\SRTSPX.SYS 2011/09/16 13:09:40.0414 3176 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 2011/09/16 13:09:40.0465 3176 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 2011/09/16 13:09:40.0485 3176 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 2011/09/16 13:09:40.0539 3176 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/09/16 13:09:40.0598 3176 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/09/16 13:09:40.0648 3176 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\Windows\system32\Drivers\SYMEVENT.SYS 2011/09/16 13:09:40.0704 3176 SYMREDRV (394b2368212114d538316812af60fddd) C:\Windows\System32\Drivers\SYMREDRV.SYS 2011/09/16 13:09:40.0731 3176 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\Windows\System32\Drivers\SYMTDI.SYS 2011/09/16 13:09:40.0763 3176 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/09/16 13:09:40.0868 3176 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/09/16 13:09:40.0958 3176 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\Windows\system32\DRIVERS\taphss.sys 2011/09/16 13:09:41.0009 3176 tapvpn (27a2c318cd28cfb3eb2200fd96af1e58) C:\Windows\system32\DRIVERS\tapvpn.sys 2011/09/16 13:09:41.0084 3176 Tcpip (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys 2011/09/16 13:09:41.0151 3176 Tcpip6 (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys 2011/09/16 13:09:41.0196 3176 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/09/16 13:09:41.0248 3176 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/09/16 13:09:41.0292 3176 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/09/16 13:09:41.0360 3176 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/09/16 13:09:41.0439 3176 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/09/16 13:09:41.0552 3176 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/09/16 13:09:41.0583 3176 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/09/16 13:09:41.0648 3176 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/09/16 13:09:41.0689 3176 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/09/16 13:09:41.0822 3176 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/09/16 13:09:41.0871 3176 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/09/16 13:09:41.0945 3176 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/09/16 13:09:42.0030 3176 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/09/16 13:09:42.0108 3176 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/09/16 13:09:42.0170 3176 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/09/16 13:09:42.0201 3176 UMPass (88bd96a1baeed33ee8bdf9499c07a841) C:\Windows\system32\DRIVERS\umpass.sys 2011/09/16 13:09:42.0264 3176 USBAAPL (60a68a5ea173a97971ee9f1ff49eb2b3) C:\Windows\system32\Drivers\usbaapl.sys 2011/09/16 13:09:42.0313 3176 usbaudio (f6bf998ae33e3fb6c7d27f0560f1173f) C:\Windows\system32\drivers\usbaudio.sys 2011/09/16 13:09:42.0376 3176 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/09/16 13:09:42.0449 3176 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/09/16 13:09:42.0540 3176 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/09/16 13:09:42.0607 3176 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/09/16 13:09:42.0649 3176 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2011/09/16 13:09:42.0683 3176 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys 2011/09/16 13:09:42.0752 3176 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/09/16 13:09:42.0810 3176 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/09/16 13:09:42.0846 3176 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/09/16 13:09:42.0876 3176 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/09/16 13:09:42.0904 3176 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/09/16 13:09:43.0002 3176 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/09/16 13:09:43.0078 3176 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2011/09/16 13:09:43.0163 3176 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/09/16 13:09:43.0226 3176 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/09/16 13:09:43.0305 3176 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/09/16 13:09:43.0334 3176 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/09/16 13:09:43.0476 3176 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/09/16 13:09:43.0517 3176 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/16 13:09:43.0533 3176 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/09/16 13:09:43.0571 3176 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/09/16 13:09:43.0665 3176 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 2011/09/16 13:09:43.0792 3176 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 2011/09/16 13:09:43.0877 3176 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 2011/09/16 13:09:43.0906 3176 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/09/16 13:09:43.0978 3176 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/09/16 13:09:44.0060 3176 xnacc (9eea6d029fef5f3016d089b1a603837d) C:\Windows\system32\DRIVERS\xnacc.sys 2011/09/16 13:09:44.0111 3176 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0 2011/09/16 13:09:44.0115 3176 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0) 2011/09/16 13:09:44.0125 3176 Boot (0x1200) (5b5d68d66cf89d9b0fe3b1f978275110) \Device\Harddisk0\DR0\Partition0 2011/09/16 13:09:44.0144 3176 Boot (0x1200) (7ca969fc4b880464eaf9e29284a87eb4) \Device\Harddisk0\DR0\Partition1 2011/09/16 13:09:44.0150 3176 ================================================================================ 2011/09/16 13:09:44.0150 3176 Scan finished 2011/09/16 13:09:44.0150 3176 ================================================================================ 2011/09/16 13:09:44.0163 4432 Detected object count: 1 2011/09/16 13:09:44.0163 4432 Actual detected object count: 1 2011/09/16 13:09:56.0918 4432 \Device\Harddisk0\DR0 (Rootkit.Boot.SST.a) - will be cured after reboot 2011/09/16 13:09:56.0918 4432 \Device\Harddisk0\DR0 - ok 2011/09/16 13:09:56.0918 4432 Rootkit.Boot.SST.a(\Device\Harddisk0\DR0) - User select action: Cure 2011/09/16 13:18:16.0027 6712 Deinitialize success ComboFix 11-09-16.01 - sonam 16/09/2011 13:35:04.1.4 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3070.1820 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\program files\Hotspot Shield\hssie\HsSIe.dll c:\users\sonam\AppData\Roaming\Adobe\plugs c:\users\sonam\AppData\Roaming\Adobe\shed c:\users\sonam\AppData\Roaming\inst.exe c:\users\sonam\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\System Recovery.lnk c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Recovery c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Recovery\System Recovery.lnk c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Recovery\Uninstall System Recovery.lnk c:\users\sonam\Desktop\System Recovery.lnk c:\users\sonam\GoToAssistDownloadHelper.exe c:\windows\system32\comct332.ocx c:\windows\system32\mfc100deu.dll c:\windows\system32\ShellManager310E2D762.dll . Infected copy of c:\windows\system32\Drivers\atapi.sys was found and disinfected Restored copy from - c:\windows\ERDNT\cache\atapi.sys . . ((((((((((((((((((((((((( Files Created from 2011-08-16 to 2011-09-16 ))))))))))))))))))))))))))))))) . . 2011-09-16 17:41 . 2011-09-16 17:41 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-09-16 17:41 . 2011-09-16 17:41 ——– d—–w- c:\users\Mcx1\AppData\Local\temp 2011-09-16 17:41 . 2011-09-16 17:41 ——– d—–w- c:\users\Guest\AppData\Local\temp 2011-09-16 06:39 . 2011-08-12 02:44 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8397ADD1-6928-4387-A9F5-F8FEBB79CECD}\mpengine.dll 2011-09-15 04:50 . 2011-08-10 12:14 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-09-11 23:16 . 2011-09-11 23:16 ——– d—–w- c:\program files\TeamViewer 2011-09-04 19:13 . 2011-09-04 19:13 ——– d—–w- c:\program files\VS Revo Group 2011-09-02 03:03 . 2006-11-02 08:55 71552 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys 2011-09-02 01:58 . 2003-11-10 22:13 69715 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2011-09-02 01:58 . 2003-11-10 22:12 266240 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2011-09-02 01:58 . 2003-11-10 22:12 192512 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2011-09-02 01:58 . 2003-11-10 22:11 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2011-09-02 01:58 . 2003-11-10 22:14 729088 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2011-09-02 01:58 . 2011-09-02 01:58 188548 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2011-09-02 01:58 . 2011-09-02 01:58 311428 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2011-08-26 21:11 . 2011-08-26 21:11 ——– d—–w- c:\windows\en 2011-08-26 20:53 . 2011-08-26 20:53 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-24 08:25 . 2011-07-11 13:25 2048 —-a-w- c:\windows\system32\tzres.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-02 00:27 . 2009-10-16 20:01 319456 —-a-w- c:\windows\DIFxAPI.dll 2011-08-31 21:00 . 2010-01-05 06:42 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-26 21:04 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-07-23 11:04 . 2011-08-10 04:30 916480 —-a-w- c:\windows\system32\wininet.dll 2011-07-23 11:00 . 2011-08-10 04:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-23 10:59 . 2011-08-10 04:30 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-23 10:59 . 2011-08-10 04:30 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-07-23 10:59 . 2011-08-10 04:30 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-23 10:03 . 2011-08-10 04:30 385024 —-a-w- c:\windows\system32\html.iec 2011-07-23 09:27 . 2011-08-10 04:30 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-23 09:25 . 2011-08-10 04:30 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-08 04:14 . 2011-07-08 04:14 8312832 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2011-07-08 03:37 . 2011-07-08 03:37 53760 —-a-w- c:\windows\system32\OVDecode.dll 2011-07-08 03:37 . 2011-07-08 03:37 43520 —-a-w- c:\windows\system32\OpenCL.dll 2011-07-08 03:36 . 2011-07-08 03:36 13904896 —-a-w- c:\windows\system32\amdocl.dll 2011-07-08 03:33 . 2011-07-08 03:33 17940992 —-a-w- c:\windows\system32\atioglxx.dll 2011-07-08 03:29 . 2011-07-08 03:29 151552 —-a-w- c:\windows\system32\atiapfxx.exe 2011-07-08 03:29 . 2011-07-08 03:29 689152 —-a-w- c:\windows\system32\aticfx32.dll 2011-07-08 03:25 . 2011-07-08 03:25 462848 —-a-w- c:\windows\system32\ATIDEMGX.dll 2011-07-08 03:25 . 2011-07-08 03:25 401408 —-a-w- c:\windows\system32\atieclxx.exe 2011-07-08 03:24 . 2011-07-08 03:24 176128 —-a-w- c:\windows\system32\atiesrxx.exe 2011-07-08 03:23 . 2011-07-08 03:23 159744 —-a-w- c:\windows\system32\atitmmxx.dll 2011-07-08 03:23 . 2011-07-08 03:23 356352 —-a-w- c:\windows\system32\atipdlxx.dll 2011-07-08 03:23 . 2011-07-08 03:23 278528 —-a-w- c:\windows\system32\Oemdspif.dll 2011-07-08 03:23 . 2011-07-08 03:23 15872 —-a-w- c:\windows\system32\atimuixx.dll 2011-07-08 03:22 . 2011-07-08 03:22 43520 —-a-w- c:\windows\system32\ati2edxx.dll 2011-07-08 03:19 . 2011-07-08 03:19 4275712 —-a-w- c:\windows\system32\atidxx32.dll 2011-07-08 03:05 . 2011-07-08 03:05 1828864 —-a-w- c:\windows\system32\atiumdmv.dll 2011-07-08 03:02 . 2011-07-08 03:02 46080 —-a-w- c:\windows\system32\aticalrt.dll 2011-07-08 03:01 . 2011-07-08 03:01 44032 —-a-w- c:\windows\system32\aticalcl.dll 2011-07-08 03:00 . 2008-10-16 23:07 4367360 —-a-w- c:\windows\system32\atiumdag.dll 2011-07-08 02:58 . 2011-07-08 02:58 6740480 —-a-w- c:\windows\system32\aticaldd.dll 2011-07-08 02:55 . 2008-10-16 23:07 4039680 —-a-w- c:\windows\system32\atiumdva.dll 2011-07-08 02:54 . 2011-07-08 02:54 52736 —-a-w- c:\windows\system32\coinst.dll 2011-07-08 02:47 . 2011-07-08 02:47 266240 —-a-w- c:\windows\system32\atiadlxx.dll 2011-07-08 02:47 . 2011-07-08 02:47 13312 —-a-w- c:\windows\system32\atiglpxx.dll 2011-07-08 02:47 . 2011-07-08 02:47 32768 —-a-w- c:\windows\system32\atigktxx.dll 2011-07-08 02:46 . 2011-07-08 02:46 244736 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2011-07-08 02:46 . 2011-07-08 02:46 31744 —-a-w- c:\windows\system32\atiuxpag.dll 2011-07-08 02:45 . 2011-07-08 02:45 29184 —-a-w- c:\windows\system32\atiu9pag.dll 2011-07-08 02:45 . 2011-07-08 02:45 37376 —-a-w- c:\windows\system32\atitmpxx.dll 2011-07-08 02:45 . 2011-07-08 02:45 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2011-07-08 02:40 . 2011-07-08 02:40 52736 —-a-w- c:\windows\system32\atimpc32.dll 2011-07-08 02:40 . 2011-07-08 02:40 52736 —-a-w- c:\windows\system32\amdpcom32.dll 2011-07-06 15:31 . 2011-08-10 04:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-20 08:54 . 2011-08-10 04:30 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-20 08:54 . 2011-08-10 04:30 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2009-04-15 20:24 . 2009-04-15 20:24 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll 2009-04-15 20:24 . 2009-04-15 20:24 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll 2011-09-07 03:09 . 2011-03-30 19:46 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-04-06 19:04 . 2010-02-04 23:44 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 —-a-w- c:\users\sonam\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 —-a-w- c:\users\sonam\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 —-a-w- c:\users\sonam\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:36 94208 —-a-w- c:\users\sonam\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] "ManyCam"="c:\program files\ManyCam\Bin\ManyCam.exe" [2011-05-13 1756232] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PMX Daemon"="ICO.EXE" [2006-11-08 49152] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-04-06 30192] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-17 150040] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-17 170520] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-17 145944] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-09-30 115560] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208] "QuickTime Task"="c:\program files\QT Lite\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208] "Desktop Disc Tool"="c:\program files\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2010-08-19 522736] "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-08 336384] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-08-16 10820200] . c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024] . c:\users\Mcx1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024] . c:\users\sonam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-04 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-10-20 15:25 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2008-10-04 04:01 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)] 2011-08-31 21:00 1047208 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] 2011-05-13 20:03 4283256 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin] 2009-10-06 00:14 2075384 —-a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2009-09-30 23888] R3 EraserUtilDrv10631;EraserUtilDrv10631;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10631.sys [x] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2011-04-06 30192] R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-06-17 1355968] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-12-23 50704] R3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-12-26 288768] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2011-04-11 12872] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-04 64288] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-09-04 12880] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2011-09-04 67664] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-09-04 116608] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [2009-11-17 87968] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-07-08 176128] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-01-08 285744] S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2008-07-21 27648] S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-07-27 105592] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632] S3 pmxmouse;pmxmouse;c:\windows\system32\DRIVERS\pmxmouse.sys [2007-06-01 18432] S3 pmxusblf;pmxusblf;c:\windows\system32\DRIVERS\pmxusblf.sys [2007-05-24 19008] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-09-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000Core.job - c:\users\sonam\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 15:16] . 2011-09-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-807892715-3149862127-586907164-1000UA.job - c:\users\sonam\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 15:16] . 2011-09-16 c:\windows\Tasks\RtlNICDiagVistaStart.job - c:\program files\Realtek\RTNICDiag\RTNICDiag.exe [2008-10-04 11:18] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local; uInternet Settings,ProxyServer = 0.0.0.0:80 uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab FF - ProfilePath - c:\users\sonam\AppData\Roaming\Mozilla\Firefox\Profiles\1arsg2p9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q= FF - prefs.js: browser.startup.homepage - hxxp://www.sciencedaily.com/ FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q= FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe SafeBoot-Symantec Antvirus MSConfigStartUp-BlackBerryAutoUpdate - c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a4,9b,bc,aa,ac,f6,c4,43,9f,41,6f,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a4,9b,bc,aa,ac,f6,c4,43,9f,41,6f,\ . [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(1840) c:\users\sonam\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . ———————— Other Running Processes ———————— . c:\windows\system32\atieclxx.exe c:\program files\Symantec AntiVirus\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\program files\Symantec AntiVirus\SmcGui.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Hotspot Shield\bin\openvpnas.exe c:\program files\Hotspot Shield\HssWPR\hsssrv.exe c:\program files\CDBurnerXP\NMSAccessU.exe c:\program files\Microsoft\BingBar\SeaPort.EXE c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\WUDFHost.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2011-09-16 13:51:45 - machine was rebooted ComboFix-quarantined-files.txt 2011-09-16 17:50 . Pre-Run: 32,912,748,544 bytes free Post-Run: 36,846,014,464 bytes free . - - End Of File - - 86836918D3983BD40CA911FEC297CC7A
Greetings lelo,

I see in your logs that you have Malwarebytes installed on your system.
  • Double click on MalwareBytes, mbam.exe to run it.
  • If Malwarebytes asks to update click on yes, if you are not asked.
  • Click on the Update tab then click on Check for updates.
  • After updates finish, click on the Scanner tab. Select Perform quick scan.
  • Click on Scan button.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Next
Please use Internet Explorer to download and run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes if there are any infections you will see a List of found threats.
  • Click Export to text file
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
  • If no threats are found there will be no list, this is good, just tell me that no threats were found.

Logs to post:
  • mbam.txt
  • eset results
Hi Bill, here is the MBAM log and eset results Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7737 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19120 17/09/2011 9:14:23 PM mbam-log-2011-09-17 (21-14-23).txt Scan type: Quick scan Objects scanned: 217974 Time elapsed: 6 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Eset: C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application C:\Users\sonam\Documents\Downloads\cnet_Vista_Win7_R264_exe.exe a variant of Win32/InstallCore.C application
My computer is running a lot better now. Internet Explorer is no longer opening on its own and it appears that Firefox is no longer redirecting me to different pages like it used to. Also files are no longer hidden. Thank a lot for your help Bill :notworthy:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI