This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

KeyLogger and Locked Files on Virus Scan

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a Windows XP system that's relatively new. A few weeks ago it started running really slow and we began experiencing issues with our wireless network. The desktop connects to it and the three laptops, but even when only one user is on it takes forever to load and locks up. I called the cable company who, after running test, told me the problem was on my end with the router.

I cleaned the computer and ran the AVG Free and Microsoft Security Essentials. Both came up with curious issues they had not found on previous runs (I clean about once every week or two and scan daily). The Microsoft Essentials found "Monitoring Tool:win32/ActualSpy" in my system volume (I tried to get a screen shot but I didn't know how to do that and when I tried to look it up the internet locked up). AVG discovered a series of locked files :


"";"E:\WINDOWS\TEMP\TMP000000086BE819521FE74EF4";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\config\system";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\config\software";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\config\SECURITY";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\config\SAM";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\config\default";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\pagefile.sys";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\pagefile.sys";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\Phil\NTUSER.DAT";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\Phil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\NetworkService\NTUSER.DAT";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\LocalService\NTUSER.DAT";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Scans\MpDiag.bin";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpScanCache-0.bin";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\BOINC\slots\3\boinc_lockfile";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\BOINC\slots\2\boinc_lockfile";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\BOINC\slots\1\boinc_lockfile";"Locked file. Not tested.";"Locked file. Not tested."
"";"E:\Documents and Settings\All Users\Application Data\BOINC\slots\0\boinc_lockfile";"Locked file. Not tested.";"Locked file. Not tested."

The computer runs slow, the internet intermittently stops responding or runs too slow and times out, and though the only virus has been found on this computer, when we use the laptops to connect to the internet we run at less than dial up speeds and give up. This has only been happening for the last two to three weeks, before that everything worked fine. Any help wpuld be greatly appreciated!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:24:01 AM, on 11/28/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\PROGRA~1\AVG\AVG10\avgchsvx.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
e:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
E:\Program Files\AVG\AVG10\avgtray.exe
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\AVG\AVG10\avgwdsvc.exe
E:\Program Files\Lexmark 7100 Series\lxbxmon.exe
E:\Program Files\Lexmark 7100 Series\ezprint.exe
E:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
E:\Program Files\BOINC\boincmgr.exe
E:\Program Files\BOINC\boinctray.exe
E:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Microsoft Security Client\msseces.exe
E:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\RINGCE~1\RINGCE~1\RCUI.exe
E:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\McAfee Security Scan\2.1.121\SSScheduler.exe
E:\WINDOWS\System32\snmp.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
E:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
E:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
E:\Program Files\AVG\AVG10\avgnsx.exe
E:\Program Files\AVG\AVG10\avgemcx.exe
E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
E:\WINDOWS\system32\lxbxcoms.exe
E:\Program Files\BOINC\boinc.exe
E:\WINDOWS\System32\svchost.exe
E:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_faah_autodock_6.40_windows_intelx86
E:\Program Files\Common Files\Java\Java Update\jucheck.exe
E:\PROGRA~1\AVG\AVG10\avgrsx.exe
E:\Program Files\AVG\AVG10\avgcsrvx.exe
E:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_dsfl_6.19_windows_intelx86
E:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.40_windows_intelx86
E:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.40_windows_intelx86
E:\Documents and Settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_dsfl_vina_6.19_windows_intelx86
E:\Program Files\AVG\AVG10\avgui.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Program Files\Google\Chrome\Application\chrome.exe
E:\Documents and Settings\Phil\My Documents\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R3 - URLSearchHook: YTNavAssist.YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - E:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AVG_TRAY] E:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [LXBXCATS] rundll32 E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "E:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "E:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "E:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "E:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [boincmgr] "E:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "E:\Program Files\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [HPWQTOOLBOX] E:\Program Files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe "-i"
O4 - HKLM\..\Run: [MpsOnn] E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "e:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "E:\Documents and Settings\Phil\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [RCUI] "E:\PROGRA~1\RINGCE~1\RINGCE~1\RCUI.exe"
O4 - HKCU\..\Run: [RCHotKey] "E:\PROGRA~1\RINGCE~1\RINGCE~1\RCHotKey.exe"
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = E:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: subst.lnk = E:\WINDOWS\system32\subst.exe
O8 - Extra context menu item: Google Sidewiki… - res://E:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - E:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1291816519064
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1291817578765
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - E:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - E:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - E:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - E:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - E:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - E:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - E:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - E:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11500 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


Since the other machines are also experiencing the slowness, I would like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You may need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router.

If you have not already done so after doing this, please go into your router's settings and change the default password to a stronger one.

Please let me know if this helps at all. If this does not help with the other machines, then we can evaluate them after we have finished with this computer, or you can start a new thread for each of the different machines. It is simply to confusing to try and diagnose more than one machine in a thread at a time.



HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt




Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and paste it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Patndoris, I'm not sure what this issue is but when I click "download" on DDS absolutely nothing happens. I was able to download and run GMER but every time I do it locks up the computer or shuts down the internet and the scan before it complete. Please advise.
Hi ppnj4,

My name is Jeff. Patndois had to step away. I will be helping you with your malware problems if that is alright? :)
———-

Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode with Networking menu item
  • Press Enter.

Once in Safe Mode, please try to download DDS once again using the link provided earlier and then go ahead and run the program in Safe Mode. If you are still having problems please let me know. :)
I won't be able to get to the computer until tomorrow, I will post how it goes then. Thanks for helping me out! Ireally appreciate it!
I'm sorry I had to be away for a few days, but I am back now. Do you still need assistance? Have you been able to try the downloads in Safe Mode with Networking?
here is the DDS file: . DDS (Ver_2011-06-23.01) - NTFSx86 NETWORK Internet Explorer: 8.0.6001.18702 Run by [removed] at 21:55:29 on 2011-12-06 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3039.2534 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . E:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe e:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe E:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe E:\WINDOWS\Explorer.EXE E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe . ============== Pseudo HJT Report =============== . mDefault_Page_URL = hxxp://www.yahoo.com mStart Page = hxxp://www.yahoo.com mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - e:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - e:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - e:\program files\avg\avg10\avgssie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - e:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - e:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - e:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - e:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - e:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - e:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - e:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - e:\program files\avg\avg10\toolbar\IEToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - e:\program files\google\google toolbar\GoogleToolbar_32.dll mRun: [AVG_TRAY] e:\program files\avg\avg10\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE e:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE e:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [LXBXCATS] rundll32 e:\windows\system32\spool\drivers\w32x86\3\LXBXtime.dll,_RunDLLEntry@16 mRun: [lxbxmon.exe] "e:\program files\lexmark 7100 series\lxbxmon.exe" mRun: [FaxCenterServer4_in_1] "e:\program files\lexmark 7100 series\fm3032.exe" /s mRun: [] mRun: [EzPrint] "e:\program files\lexmark 7100 series\ezprint.exe" mRun: [Microsoft Default Manager] "e:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [boincmgr] "e:\program files\boinc\boincmgr.exe" /a /s mRun: [boinctray] "e:\program files\boinc\boinctray.exe" mRun: [HPWQTOOLBOX] e:\program files\hewlett-packard\hp deskjet 9800 series\toolbox\HPWQTBX.exe "-i" mRun: [MpsOnn] e:\windows\system32\spool\drivers\w32x86\3\MpsOnn.exe mRun: [Adobe ARM] "e:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe" mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - e:\program files\common files\autodesk shared\acstart16.exe StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - e:\program files\mcafee security scan\2.1.121\SSScheduler.exe StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\subst.lnk - e:\windows\system32\subst.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - e:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - e:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1291816519064 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1291817578765 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{ED8673E8-7B6E-4F5F-AAA5-DA8EF7AF18C6} : DhcpNameServer = 192.168.2.1 Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - e:\program files\avg\avg10\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - e:\program files\avg\avg10\avgpp.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;e:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [2010-11-9 297168] R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;e:\windows\system32\drivers\lne100v5.sys [2010-12-8 36224] S1 Avgldx86;AVG AVI Loader Driver;e:\windows\system32\drivers\avgldx86.sys [2010-9-7 248656] S1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;e:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896] S1 BIOS;BIOS;e:\windows\system32\drivers\BIOS.sys [2010-12-8 13696] S1 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] S1 MpKsl3654f97a;MpKsl3654f97a;e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e35890c3-ca45-4d6b-9d6f-ba8aae1992af}\MpKsl3654f97a.sys [2011-12-6 29904] S2 AVGIDSAgent;AVGIDSAgent;e:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-8-18 7390560] S2 avgwd;AVG WatchDog;e:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] S2 gupdate;Google Update Service (gupdate);e:\program files\google\update\GoogleUpdate.exe [2010-12-13 136176] S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [2010-12-8 1684736] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;e:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-5-12 1025352] S3 AVGIDSDriver;AVGIDSDriver;e:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480] S3 AVGIDSFilter;AVGIDSFilter;e:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144] S3 AVGIDSShim;AVGIDSShim;e:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216] S3 gupdatem;Google Update Service (gupdatem);e:\program files\google\update\GoogleUpdate.exe [2010-12-13 136176] S3 McComponentHostService;McAfee Security Scan Component Host Service;e:\program files\mcafee security scan\2.1.121\McCHSvc.exe [2010-9-3 227232] S3 Revoflt;Revoflt;e:\windows\system32\drivers\revoflt.sys [2011-11-22 27064] . =============== Created Last 30 ================ . 2011-12-07 02:55:26 ——– d–h–w- e:\windows\PIF 2011-12-06 18:04:48 29904 —-a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e35890c3-ca45-4d6b-9d6f-ba8aae1992af}\MpKsl3654f97a.sys 2011-12-06 18:04:44 56200 —-a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e35890c3-ca45-4d6b-9d6f-ba8aae1992af}\offreg.dll 2011-12-06 05:12:55 6823496 —-a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e35890c3-ca45-4d6b-9d6f-ba8aae1992af}\mpengine.dll 2011-11-22 12:59:17 27064 —-a-w- e:\windows\system32\drivers\revoflt.sys 2011-11-22 12:59:13 ——– d—–w- e:\program files\VS Revo Group 2011-11-22 11:48:30 22216 —-a-w- e:\windows\system32\drivers\mbam.sys . ==================== Find3M ==================== . 2011-11-17 14:00:43 414368 —-a-w- e:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22:41 692736 ——w- e:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- e:\windows\system32\crypt32.dll 2011-09-26 15:41:20 611328 —-a-w- e:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- e:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- e:\windows\system32\oleaccrc.dll 1997-06-23 08:00:00 123664 –sha-w- e:\windows\system32\Msjint35.dll 1997-06-23 17:06:50 24848 –sha-w- e:\windows\system32\Msjter35.dll 1997-06-23 17:06:50 252176 –sha-w- e:\windows\system32\Msrd2x35.dll 1997-06-23 17:06:50 287504 –sha-w- e:\windows\system32\Msxbse35.dll . ============= FINISH: 21:56:00.96 =============== When I tried running the GMER file it shut down the computer again after a few minutes of scanning, and that's in Safe Mode with Networking. Please advise… Thanks! Nicole
As a side note - I tried to run my Malwarebytes Anti-Malware free software and I get this error : Program_Error_Load_Database (2,2,createsdk) The system cannot find the file specified….this is a new issue as it worked before.
It would appear that you have more than one anti-virus solution on your machine. I can see both AVG and Microsoft Security Eessentials installed.
Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.
Before continuing on, please completely uninstall one of the programs. Personally, I find AVG bogs systems down, but the choice is yours. You can go to your Control Panel > Add/Remove Programs and Uninstall whichever of the programs you do not wish to keep.

If you are not instructed to do so as a part of the un-install, please reboot the computer after doing the removal.


Please try to run the next instructions in normal mode. If you are not albe to then please do them in Safe Mode with Networking again (and let me know that you had to do so).




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


Also - Please do NOT run any other tools (such as Malwarebytes) while we are working. Any tools that may remove parts of infections can make it harder for us to clean your machine. I appreciate that you are trying to fix things and make it run better, but while we are working, it can actually make it harder for us to fix.
here is the log - I had no problems downloading and running - though it didn't appear to find anything. Let me know what's next if anything - thanks! 06:16:36.0953 1088 TDSS rootkit removing tool [removed] Dec 7 2011 13:21:06 06:16:37.0078 1088 ============================================================ 06:16:37.0093 1088 Current date / time: 2011/12/08 06:16:37.0078 06:16:37.0093 1088 SystemInfo: 06:16:37.0093 1088 06:16:37.0093 1088 OS Version: 5.1.2600 ServicePack: 3.0 06:16:37.0093 1088 Product type: Workstation 06:16:37.0093 1088 ComputerName: DESKTOP 06:16:37.0093 1088 UserName: Phil 06:16:37.0093 1088 Windows directory: E:\WINDOWS 06:16:37.0093 1088 System windows directory: E:\WINDOWS 06:16:37.0093 1088 Processor architecture: Intel x86 06:16:37.0093 1088 Number of processors: 4 06:16:37.0093 1088 Page size: 0x1000 06:16:37.0093 1088 Boot type: Normal boot 06:16:37.0093 1088 ============================================================ 06:16:37.0437 1088 Initialize success 06:17:07.0125 3256 ============================================================ 06:17:07.0125 3256 Scan started 06:17:07.0125 3256 Mode: Manual; 06:17:07.0125 3256 ============================================================ 06:17:07.0296 3256 Abiosdsk - ok 06:17:07.0343 3256 abp480n5 - ok 06:17:07.0375 3256 ACPI (8fd99680a539792a30e97944fdaecf17) E:\WINDOWS\system32\DRIVERS\ACPI.sys 06:17:07.0375 3256 ACPI - ok 06:17:07.0406 3256 ACPIEC (9859c0f6936e723e4892d7141b1327d5) E:\WINDOWS\system32\drivers\ACPIEC.sys 06:17:07.0406 3256 ACPIEC - ok 06:17:07.0406 3256 adpu160m - ok 06:17:07.0437 3256 aec (8bed39e3c35d6a489438b8141717a557) E:\WINDOWS\system32\drivers\aec.sys 06:17:07.0437 3256 aec - ok 06:17:07.0468 3256 AFD (1e44bc1e83d8fd2305f8d452db109cf9) E:\WINDOWS\System32\drivers\afd.sys 06:17:07.0468 3256 AFD - ok 06:17:07.0468 3256 Aha154x - ok 06:17:07.0484 3256 aic78u2 - ok 06:17:07.0484 3256 aic78xx - ok 06:17:07.0500 3256 AliIde - ok 06:17:07.0562 3256 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) E:\WINDOWS\system32\drivers\Ambfilt.sys 06:17:07.0578 3256 Ambfilt - ok 06:17:07.0609 3256 AmdPPM (033448d435e65c4bd72e70521fd05c76) E:\WINDOWS\system32\DRIVERS\AmdPPM.sys 06:17:07.0609 3256 AmdPPM - ok 06:17:07.0625 3256 amsint - ok 06:17:07.0656 3256 AN983 (116bff96077a4a724e0aab800525ceb5) E:\WINDOWS\system32\DRIVERS\AN983.sys 06:17:07.0656 3256 AN983 - ok 06:17:07.0671 3256 asc - ok 06:17:07.0671 3256 asc3350p - ok 06:17:07.0687 3256 asc3550 - ok 06:17:07.0750 3256 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) E:\WINDOWS\system32\DRIVERS\asyncmac.sys 06:17:07.0750 3256 AsyncMac - ok 06:17:07.0765 3256 atapi (9f3a2f5aa6875c72bf062c712cfa2674) E:\WINDOWS\system32\DRIVERS\atapi.sys 06:17:07.0765 3256 atapi - ok 06:17:07.0781 3256 Atdisk - ok 06:17:07.0812 3256 Atmarpc (9916c1225104ba14794209cfa8012159) E:\WINDOWS\system32\DRIVERS\atmarpc.sys 06:17:07.0812 3256 Atmarpc - ok 06:17:07.0843 3256 audstub (d9f724aa26c010a217c97606b160ed68) E:\WINDOWS\system32\DRIVERS\audstub.sys 06:17:07.0843 3256 audstub - ok 06:17:07.0859 3256 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) E:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 06:17:07.0859 3256 AVGIDSEH - ok 06:17:07.0890 3256 Avgtdix (aaf0ebcad95f2164cffb544e00392498) E:\WINDOWS\system32\DRIVERS\avgtdix.sys 06:17:07.0890 3256 Avgtdix - ok 06:17:07.0906 3256 Beep (da1f27d85e0d1525f6621372e7b685e9) E:\WINDOWS\system32\drivers\Beep.sys 06:17:07.0906 3256 Beep - ok 06:17:07.0937 3256 BIOS (be5d50529799b9bab6be879ec768b6cf) E:\WINDOWS\system32\drivers\BIOS.sys 06:17:07.0953 3256 BIOS - ok 06:17:07.0968 3256 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) E:\WINDOWS\system32\drivers\cbidf2k.sys 06:17:07.0968 3256 cbidf2k - ok 06:17:07.0984 3256 cd20xrnt - ok 06:17:08.0015 3256 Cdaudio (c1b486a7658353d33a10cc15211a873b) E:\WINDOWS\system32\drivers\Cdaudio.sys 06:17:08.0015 3256 Cdaudio - ok 06:17:08.0046 3256 Cdfs (c885b02847f5d2fd45a24e219ed93b32) E:\WINDOWS\system32\drivers\Cdfs.sys 06:17:08.0046 3256 Cdfs - ok 06:17:08.0062 3256 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) E:\WINDOWS\system32\DRIVERS\cdrom.sys 06:17:08.0062 3256 Cdrom - ok 06:17:08.0062 3256 Changer - ok 06:17:08.0093 3256 CmdIde - ok 06:17:08.0109 3256 Cpqarray - ok 06:17:08.0125 3256 dac2w2k - ok 06:17:08.0140 3256 dac960nt - ok 06:17:08.0156 3256 Disk (044452051f3e02e7963599fc8f4f3e25) E:\WINDOWS\system32\DRIVERS\disk.sys 06:17:08.0156 3256 Disk - ok 06:17:08.0187 3256 dmboot (d992fe1274bde0f84ad826acae022a41) E:\WINDOWS\system32\drivers\dmboot.sys 06:17:08.0203 3256 dmboot - ok 06:17:08.0218 3256 dmio (7c824cf7bbde77d95c08005717a95f6f) E:\WINDOWS\system32\drivers\dmio.sys 06:17:08.0218 3256 dmio - ok 06:17:08.0234 3256 dmload (e9317282a63ca4d188c0df5e09c6ac5f) E:\WINDOWS\system32\drivers\dmload.sys 06:17:08.0234 3256 dmload - ok 06:17:08.0265 3256 DMusic (8a208dfcf89792a484e76c40e5f50b45) E:\WINDOWS\system32\drivers\DMusic.sys 06:17:08.0265 3256 DMusic - ok 06:17:08.0281 3256 dpti2o - ok 06:17:08.0343 3256 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) E:\WINDOWS\system32\drivers\drmkaud.sys 06:17:08.0343 3256 drmkaud - ok 06:17:08.0375 3256 Fastfat (38d332a6d56af32635675f132548343e) E:\WINDOWS\system32\drivers\Fastfat.sys 06:17:08.0375 3256 Fastfat - ok 06:17:08.0390 3256 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) E:\WINDOWS\system32\DRIVERS\fdc.sys 06:17:08.0390 3256 Fdc - ok 06:17:08.0406 3256 Fips (d45926117eb9fa946a6af572fbe1caa3) E:\WINDOWS\system32\drivers\Fips.sys 06:17:08.0406 3256 Fips - ok 06:17:08.0406 3256 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) E:\WINDOWS\system32\DRIVERS\flpydisk.sys 06:17:08.0421 3256 Flpydisk - ok 06:17:08.0421 3256 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) E:\WINDOWS\system32\drivers\fltmgr.sys 06:17:08.0421 3256 FltMgr - ok 06:17:08.0437 3256 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) E:\WINDOWS\system32\drivers\Fs_Rec.sys 06:17:08.0437 3256 Fs_Rec - ok 06:17:08.0453 3256 Ftdisk (6ac26732762483366c3969c9e4d2259d) E:\WINDOWS\system32\DRIVERS\ftdisk.sys 06:17:08.0453 3256 Ftdisk - ok 06:17:08.0468 3256 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) E:\WINDOWS\system32\DRIVERS\msgpc.sys 06:17:08.0468 3256 Gpc - ok 06:17:08.0484 3256 HDAudBus (573c7d0a32852b48f3058cfd8026f511) E:\WINDOWS\system32\DRIVERS\HDAudBus.sys 06:17:08.0484 3256 HDAudBus - ok 06:17:08.0500 3256 hidusb (ccf82c5ec8a7326c3066de870c06daf1) E:\WINDOWS\system32\DRIVERS\hidusb.sys 06:17:08.0500 3256 hidusb - ok 06:17:08.0515 3256 hpn - ok 06:17:08.0562 3256 HTTP (f80a415ef82cd06ffaf0d971528ead38) E:\WINDOWS\system32\Drivers\HTTP.sys 06:17:08.0562 3256 HTTP - ok 06:17:08.0578 3256 i2omgmt - ok 06:17:08.0593 3256 i2omp - ok 06:17:08.0625 3256 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) E:\WINDOWS\system32\drivers\i8042prt.sys 06:17:08.0625 3256 i8042prt - ok 06:17:08.0640 3256 Imapi (083a052659f5310dd8b6a6cb05edcf8e) E:\WINDOWS\system32\DRIVERS\imapi.sys 06:17:08.0640 3256 Imapi - ok 06:17:08.0656 3256 ini910u - ok 06:17:08.0765 3256 IntcAzAudAddService (3fa02c6e3e9ebe8523a2d4e51d0ece1f) E:\WINDOWS\system32\drivers\RtkHDAud.sys 06:17:08.0781 3256 IntcAzAudAddService - ok 06:17:08.0828 3256 IntelIde - ok 06:17:08.0843 3256 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) E:\WINDOWS\system32\drivers\ip6fw.sys 06:17:08.0843 3256 Ip6Fw - ok 06:17:08.0890 3256 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) E:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 06:17:08.0890 3256 IpFilterDriver - ok 06:17:08.0906 3256 IpInIp (b87ab476dcf76e72010632b5550955f5) E:\WINDOWS\system32\DRIVERS\ipinip.sys 06:17:08.0906 3256 IpInIp - ok 06:17:08.0937 3256 IpNat (cc748ea12c6effde940ee98098bf96bb) E:\WINDOWS\system32\DRIVERS\ipnat.sys 06:17:08.0937 3256 IpNat - ok 06:17:08.0937 3256 IPSec (23c74d75e36e7158768dd63d92789a91) E:\WINDOWS\system32\DRIVERS\ipsec.sys 06:17:08.0937 3256 IPSec - ok 06:17:08.0953 3256 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) E:\WINDOWS\system32\DRIVERS\irenum.sys 06:17:08.0953 3256 IRENUM - ok 06:17:08.0984 3256 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) E:\WINDOWS\system32\DRIVERS\isapnp.sys 06:17:08.0984 3256 isapnp - ok 06:17:08.0984 3256 Kbdclass (463c1ec80cd17420a542b7f36a36f128) E:\WINDOWS\system32\DRIVERS\kbdclass.sys 06:17:08.0984 3256 Kbdclass - ok 06:17:09.0000 3256 kbdhid (9ef487a186dea361aa06913a75b3fa99) E:\WINDOWS\system32\DRIVERS\kbdhid.sys 06:17:09.0000 3256 kbdhid - ok 06:17:09.0031 3256 kmixer (692bcf44383d056aed41b045a323d378) E:\WINDOWS\system32\drivers\kmixer.sys 06:17:09.0031 3256 kmixer - ok 06:17:09.0078 3256 KSecDD (b467646c54cc746128904e1654c750c1) E:\WINDOWS\system32\drivers\KSecDD.sys 06:17:09.0078 3256 KSecDD - ok 06:17:09.0078 3256 lbrtfdc - ok 06:17:09.0109 3256 LNE100 (e7a30b307ac29afbb993049df04bb91b) E:\WINDOWS\system32\DRIVERS\LNE100V5.sys 06:17:09.0109 3256 LNE100 - ok 06:17:09.0125 3256 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) E:\WINDOWS\system32\drivers\mnmdd.sys 06:17:09.0125 3256 mnmdd - ok 06:17:09.0140 3256 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) E:\WINDOWS\system32\drivers\Modem.sys 06:17:09.0140 3256 Modem - ok 06:17:09.0187 3256 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) E:\WINDOWS\system32\drivers\Monfilt.sys 06:17:09.0218 3256 Monfilt - ok 06:17:09.0234 3256 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) E:\WINDOWS\system32\DRIVERS\mouclass.sys 06:17:09.0234 3256 Mouclass - ok 06:17:09.0265 3256 mouhid (b1c303e17fb9d46e87a98e4ba6769685) E:\WINDOWS\system32\DRIVERS\mouhid.sys 06:17:09.0265 3256 mouhid - ok 06:17:09.0281 3256 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) E:\WINDOWS\system32\drivers\MountMgr.sys 06:17:09.0281 3256 MountMgr - ok 06:17:09.0296 3256 MpFilter (fee0baded54222e9f1dae9541212aab1) E:\WINDOWS\system32\DRIVERS\MpFilter.sys 06:17:09.0296 3256 MpFilter - ok 06:17:09.0375 3256 MpKslef0e93ad (a69630d039c38018689190234f866d77) e:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A6E1A84-1852-4D5C-94E8-FAC9731B4F95}\MpKslef0e93ad.sys 06:17:09.0375 3256 MpKslef0e93ad - ok 06:17:09.0390 3256 mraid35x - ok 06:17:09.0390 3256 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) E:\WINDOWS\system32\DRIVERS\mrxdav.sys 06:17:09.0390 3256 MRxDAV - ok 06:17:09.0437 3256 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) E:\WINDOWS\system32\DRIVERS\mrxsmb.sys 06:17:09.0437 3256 MRxSmb - ok 06:17:09.0437 3256 Msfs (c941ea2454ba8350021d774daf0f1027) E:\WINDOWS\system32\drivers\Msfs.sys 06:17:09.0453 3256 Msfs - ok 06:17:09.0468 3256 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) E:\WINDOWS\system32\drivers\MSKSSRV.sys 06:17:09.0468 3256 MSKSSRV - ok 06:17:09.0484 3256 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) E:\WINDOWS\system32\drivers\MSPCLOCK.sys 06:17:09.0484 3256 MSPCLOCK - ok 06:17:09.0500 3256 MSPQM (bad59648ba099da4a17680b39730cb3d) E:\WINDOWS\system32\drivers\MSPQM.sys 06:17:09.0500 3256 MSPQM - ok 06:17:09.0515 3256 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) E:\WINDOWS\system32\DRIVERS\mssmbios.sys 06:17:09.0515 3256 mssmbios - ok 06:17:09.0531 3256 Mup (de6a75f5c270e756c5508d94b6cf68f5) E:\WINDOWS\system32\drivers\Mup.sys 06:17:09.0531 3256 Mup - ok 06:17:09.0562 3256 NDIS (1df7f42665c94b825322fae71721130d) E:\WINDOWS\system32\drivers\NDIS.sys 06:17:09.0562 3256 NDIS - ok 06:17:09.0578 3256 NdisTapi (0109c4f3850dfbab279542515386ae22) E:\WINDOWS\system32\DRIVERS\ndistapi.sys 06:17:09.0578 3256 NdisTapi - ok 06:17:09.0593 3256 Ndisuio (f927a4434c5028758a842943ef1a3849) E:\WINDOWS\system32\DRIVERS\ndisuio.sys 06:17:09.0593 3256 Ndisuio - ok 06:17:09.0593 3256 NdisWan (edc1531a49c80614b2cfda43ca8659ab) E:\WINDOWS\system32\DRIVERS\ndiswan.sys 06:17:09.0593 3256 NdisWan - ok 06:17:09.0609 3256 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) E:\WINDOWS\system32\drivers\NDProxy.sys 06:17:09.0609 3256 NDProxy - ok 06:17:09.0625 3256 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) E:\WINDOWS\system32\DRIVERS\netbios.sys 06:17:09.0625 3256 NetBIOS - ok 06:17:09.0656 3256 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) E:\WINDOWS\system32\DRIVERS\netbt.sys 06:17:09.0656 3256 NetBT - ok 06:17:09.0671 3256 Npfs (3182d64ae053d6fb034f44b6def8034a) E:\WINDOWS\system32\drivers\Npfs.sys 06:17:09.0671 3256 Npfs - ok 06:17:09.0687 3256 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) E:\WINDOWS\system32\drivers\Ntfs.sys 06:17:09.0687 3256 Ntfs - ok 06:17:09.0718 3256 Null (73c1e1f395918bc2c6dd67af7591a3ad) E:\WINDOWS\system32\drivers\Null.sys 06:17:09.0718 3256 Null - ok 06:17:09.0796 3256 nv (eb2858f920b8135b807b5ccaa3ed73dc) E:\WINDOWS\system32\DRIVERS\nv4_mini.sys 06:17:09.0859 3256 nv - ok 06:17:09.0890 3256 NVENETFD (7d275ecda4628318912f6c945d5cf963) E:\WINDOWS\system32\DRIVERS\NVENETFD.sys 06:17:09.0890 3256 NVENETFD - ok 06:17:09.0921 3256 nvgts (ea98bfe4931bd13d747d647c1859796e) E:\WINDOWS\system32\DRIVERS\nvgts.sys 06:17:09.0921 3256 nvgts - ok 06:17:09.0968 3256 nvnetbus (b64aacefad2be5bff5353fe681253c67) E:\WINDOWS\system32\DRIVERS\nvnetbus.sys 06:17:09.0968 3256 nvnetbus - ok 06:17:09.0968 3256 nvsmu (2a085aec3ab2b1211611d2a7b9e22456) E:\WINDOWS\system32\DRIVERS\nvsmu.sys 06:17:09.0968 3256 nvsmu - ok 06:17:10.0000 3256 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) E:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 06:17:10.0000 3256 NwlnkFlt - ok 06:17:10.0015 3256 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) E:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 06:17:10.0015 3256 NwlnkFwd - ok 06:17:10.0031 3256 Parport (5575faf8f97ce5e713d108c2a58d7c7c) E:\WINDOWS\system32\DRIVERS\parport.sys 06:17:10.0031 3256 Parport - ok 06:17:10.0046 3256 PartMgr (beb3ba25197665d82ec7065b724171c6) E:\WINDOWS\system32\drivers\PartMgr.sys 06:17:10.0046 3256 PartMgr - ok 06:17:10.0062 3256 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) E:\WINDOWS\system32\drivers\ParVdm.sys 06:17:10.0062 3256 ParVdm - ok 06:17:10.0062 3256 PCI (a219903ccf74233761d92bef471a07b1) E:\WINDOWS\system32\DRIVERS\pci.sys 06:17:10.0078 3256 PCI - ok 06:17:10.0078 3256 PCIDump - ok 06:17:10.0093 3256 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) E:\WINDOWS\system32\DRIVERS\pciide.sys 06:17:10.0093 3256 PCIIde - ok 06:17:10.0125 3256 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) E:\WINDOWS\system32\drivers\Pcmcia.sys 06:17:10.0125 3256 Pcmcia - ok 06:17:10.0125 3256 PDCOMP - ok 06:17:10.0140 3256 PDFRAME - ok 06:17:10.0140 3256 PDRELI - ok 06:17:10.0156 3256 PDRFRAME - ok 06:17:10.0156 3256 perc2 - ok 06:17:10.0171 3256 perc2hib - ok 06:17:10.0218 3256 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) E:\WINDOWS\system32\DRIVERS\raspptp.sys 06:17:10.0218 3256 PptpMiniport - ok 06:17:10.0218 3256 Processor (a32bebaf723557681bfc6bd93e98bd26) E:\WINDOWS\system32\DRIVERS\processr.sys 06:17:10.0218 3256 Processor - ok 06:17:10.0234 3256 PSched (09298ec810b07e5d582cb3a3f9255424) E:\WINDOWS\system32\DRIVERS\psched.sys 06:17:10.0234 3256 PSched - ok 06:17:10.0250 3256 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) E:\WINDOWS\system32\DRIVERS\ptilink.sys 06:17:10.0250 3256 Ptilink - ok 06:17:10.0250 3256 ql1080 - ok 06:17:10.0265 3256 Ql10wnt - ok 06:17:10.0265 3256 ql12160 - ok 06:17:10.0281 3256 ql1240 - ok 06:17:10.0281 3256 ql1280 - ok 06:17:10.0296 3256 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) E:\WINDOWS\system32\DRIVERS\rasacd.sys 06:17:10.0296 3256 RasAcd - ok 06:17:10.0312 3256 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) E:\WINDOWS\system32\DRIVERS\rasl2tp.sys 06:17:10.0312 3256 Rasl2tp - ok 06:17:10.0328 3256 RasPppoe (5bc962f2654137c9909c3d4603587dee) E:\WINDOWS\system32\DRIVERS\raspppoe.sys 06:17:10.0328 3256 RasPppoe - ok 06:17:10.0328 3256 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) E:\WINDOWS\system32\DRIVERS\raspti.sys 06:17:10.0328 3256 Raspti - ok 06:17:10.0343 3256 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) E:\WINDOWS\system32\DRIVERS\rdbss.sys 06:17:10.0343 3256 Rdbss - ok 06:17:10.0359 3256 RDPCDD (4912d5b403614ce99c28420f75353332) E:\WINDOWS\system32\DRIVERS\RDPCDD.sys 06:17:10.0359 3256 RDPCDD - ok 06:17:10.0390 3256 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) E:\WINDOWS\system32\drivers\RDPWD.sys 06:17:10.0390 3256 RDPWD - ok 06:17:10.0406 3256 redbook (f828dd7e1419b6653894a8f97a0094c5) E:\WINDOWS\system32\DRIVERS\redbook.sys 06:17:10.0406 3256 redbook - ok 06:17:10.0437 3256 Revoflt (8b5b8a11306190c6963d3473f052d3c8) E:\WINDOWS\system32\DRIVERS\revoflt.sys 06:17:10.0468 3256 Revoflt - ok 06:17:10.0500 3256 Secdrv (90a3935d05b494a5a39d37e71f09a677) E:\WINDOWS\system32\DRIVERS\secdrv.sys 06:17:10.0500 3256 Secdrv - ok 06:17:10.0515 3256 serenum (0f29512ccd6bead730039fb4bd2c85ce) E:\WINDOWS\system32\DRIVERS\serenum.sys 06:17:10.0515 3256 serenum - ok 06:17:10.0531 3256 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) E:\WINDOWS\system32\DRIVERS\serial.sys 06:17:10.0531 3256 Serial - ok 06:17:10.0546 3256 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) E:\WINDOWS\system32\drivers\Sfloppy.sys 06:17:10.0546 3256 Sfloppy - ok 06:17:10.0562 3256 Simbad - ok 06:17:10.0593 3256 Sparrow - ok 06:17:10.0640 3256 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) E:\WINDOWS\system32\drivers\splitter.sys 06:17:10.0640 3256 splitter - ok 06:17:10.0656 3256 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) E:\WINDOWS\system32\DRIVERS\sr.sys 06:17:10.0656 3256 sr - ok 06:17:10.0703 3256 Srv (47ddfc2f003f7f9f0592c6874962a2e7) E:\WINDOWS\system32\DRIVERS\srv.sys 06:17:10.0703 3256 Srv - ok 06:17:10.0718 3256 swenum (3941d127aef12e93addf6fe6ee027e0f) E:\WINDOWS\system32\DRIVERS\swenum.sys 06:17:10.0718 3256 swenum - ok 06:17:10.0734 3256 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) E:\WINDOWS\system32\drivers\swmidi.sys 06:17:10.0734 3256 swmidi - ok 06:17:10.0750 3256 symc810 - ok 06:17:10.0750 3256 symc8xx - ok 06:17:10.0765 3256 sym_hi - ok 06:17:10.0765 3256 sym_u3 - ok 06:17:10.0781 3256 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) E:\WINDOWS\system32\drivers\sysaudio.sys 06:17:10.0781 3256 sysaudio - ok 06:17:10.0828 3256 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) E:\WINDOWS\system32\DRIVERS\tcpip.sys 06:17:10.0828 3256 Tcpip - ok 06:17:10.0859 3256 TDPIPE (6471a66807f5e104e4885f5b67349397) E:\WINDOWS\system32\drivers\TDPIPE.sys 06:17:10.0859 3256 TDPIPE - ok 06:17:10.0875 3256 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) E:\WINDOWS\system32\drivers\TDTCP.sys 06:17:10.0875 3256 TDTCP - ok 06:17:10.0875 3256 TermDD (88155247177638048422893737429d9e) E:\WINDOWS\system32\DRIVERS\termdd.sys 06:17:10.0875 3256 TermDD - ok 06:17:10.0890 3256 TosIde - ok 06:17:10.0953 3256 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) E:\WINDOWS\system32\drivers\Udfs.sys 06:17:10.0953 3256 Udfs - ok 06:17:10.0968 3256 ultra - ok 06:17:11.0000 3256 Update (402ddc88356b1bac0ee3dd1580c76a31) E:\WINDOWS\system32\DRIVERS\update.sys 06:17:11.0015 3256 Update - ok 06:17:11.0046 3256 usbaudio (e919708db44ed8543a7c017953148330) E:\WINDOWS\system32\drivers\usbaudio.sys 06:17:11.0046 3256 usbaudio - ok 06:17:11.0062 3256 usbccgp (173f317ce0db8e21322e71b7e60a27e8) E:\WINDOWS\system32\DRIVERS\usbccgp.sys 06:17:11.0062 3256 usbccgp - ok 06:17:11.0078 3256 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) E:\WINDOWS\system32\DRIVERS\usbehci.sys 06:17:11.0078 3256 usbehci - ok 06:17:11.0093 3256 usbhub (1ab3cdde553b6e064d2e754efe20285c) E:\WINDOWS\system32\DRIVERS\usbhub.sys 06:17:11.0093 3256 usbhub - ok 06:17:11.0125 3256 usbohci (0daecce65366ea32b162f85f07c6753b) E:\WINDOWS\system32\DRIVERS\usbohci.sys 06:17:11.0125 3256 usbohci - ok 06:17:11.0125 3256 usbprint (a717c8721046828520c9edf31288fc00) E:\WINDOWS\system32\DRIVERS\usbprint.sys 06:17:11.0125 3256 usbprint - ok 06:17:11.0187 3256 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) E:\WINDOWS\system32\DRIVERS\usbscan.sys 06:17:11.0187 3256 usbscan - ok 06:17:11.0187 3256 usbstor (a32426d9b14a089eaa1d922e0c5801a9) E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 06:17:11.0187 3256 usbstor - ok 06:17:11.0218 3256 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) E:\WINDOWS\System32\drivers\vga.sys 06:17:11.0218 3256 VgaSave - ok 06:17:11.0218 3256 ViaIde - ok 06:17:11.0234 3256 VolSnap (4c8fcb5cc53aab716d810740fe59d025) E:\WINDOWS\system32\drivers\VolSnap.sys 06:17:11.0234 3256 VolSnap - ok 06:17:11.0250 3256 Wanarp (e20b95baedb550f32dd489265c1da1f6) E:\WINDOWS\system32\DRIVERS\wanarp.sys 06:17:11.0250 3256 Wanarp - ok 06:17:11.0265 3256 WDICA - ok 06:17:11.0296 3256 wdmaud (6768acf64b18196494413695f0c3a00f) E:\WINDOWS\system32\drivers\wdmaud.sys 06:17:11.0296 3256 wdmaud - ok 06:17:11.0359 3256 WpdUsb (cf4def1bf66f06964dc0d91844239104) E:\WINDOWS\system32\DRIVERS\wpdusb.sys 06:17:11.0359 3256 WpdUsb - ok 06:17:11.0375 3256 WudfPf (f15feafffbb3644ccc80c5da584e6311) E:\WINDOWS\system32\DRIVERS\WudfPf.sys 06:17:11.0375 3256 WudfPf - ok 06:17:11.0390 3256 WudfRd (28b524262bce6de1f7ef9f510ba3985b) E:\WINDOWS\system32\DRIVERS\wudfrd.sys 06:17:11.0390 3256 WudfRd - ok 06:17:11.0421 3256 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 06:17:11.0468 3256 \Device\Harddisk0\DR0 - ok 06:17:11.0484 3256 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR2 06:17:11.0484 3256 \Device\Harddisk1\DR2 - ok 06:17:11.0484 3256 Boot (0x1200) (e412f573eafe1da06c77bcdc9d51350b) \Device\Harddisk0\DR0\Partition0 06:17:11.0484 3256 \Device\Harddisk0\DR0\Partition0 - ok 06:17:11.0500 3256 Boot (0x1200) (32ca3c565da2fe83a7e22d496c72a44e) \Device\Harddisk1\DR2\Partition0 06:17:11.0500 3256 \Device\Harddisk1\DR2\Partition0 - ok 06:17:11.0500 3256 ============================================================ 06:17:11.0500 3256 Scan finished 06:17:11.0500 3256 ============================================================ 06:17:11.0500 3260 Detected object count: 0 06:17:11.0500 3260 Actual detected object count: 0
I'm not experiencing any difference after removing AVG. The slowness on the network seemed to diminish after resetting the router - but the computer shutting sown every time I tried to download your program makes me concerned - did the logs show anything? Nicole
I am not seeing anything in the logs, but the behavior you describe is certinaly suspicious, and the fact that a keylogger was found by Microsoft Security Essentials does bother me.

I would like to run a tool and see if we are able to get any relief from the symptoms you have been having.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click ANYWHERE on your screen while Combofix is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
He hasn't complained about the computer - so I think it's running ok, though it does seem to stall on me here and there. Here is the log, let me know what you think.


ComboFix 11-12-12.01 - Phil 12/12/2011 6:35.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3039.2216 [GMT -5:00]
Running from: e:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
E:\data
e:\data\d9f78bt_o\us_sres.data
e:\documents and settings\All Users\Application Data\TEMP
e:\documents and settings\Phil\Application Data\log.txt
e:\documents and settings\Phil\WINDOWS
E:\Thumbs.db
e:\windows\system32\Cache
e:\windows\system32\Cache\272512937d9e61a4.fb
e:\windows\system32\Cache\287204568329e189.fb
e:\windows\system32\Cache\28bc8f716fd76a47.fb
e:\windows\system32\Cache\2c53092c95605355.fb
e:\windows\system32\Cache\3917078cb68ec657.fb
e:\windows\system32\Cache\590ba23ce359fd0c.fb
e:\windows\system32\Cache\610289e025a3ee9a.fb
e:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
e:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
e:\windows\system32\Cache\ad10a52aff5e038d.fb
e:\windows\system32\Cache\cd48833ce0442046.fb
e:\windows\system32\Cache\d201ef9910cd39de.fb
e:\windows\system32\Cache\d2e94710a5708128.fb
e:\windows\system32\Cache\d79b9dfe81484ec4.fb
e:\windows\system32\ReadMe.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-11-12 to 2011-12-12 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:26 . 2011-12-12 05:26 29904 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DAFF4F65-2A0D-45F1-BAE8-9995A3D33DC6}\MpKslf4f68c82.sys
2011-12-12 05:26 . 2011-12-12 05:26 56200 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DAFF4F65-2A0D-45F1-BAE8-9995A3D33DC6}\offreg.dll
2011-12-12 05:26 . 2011-11-21 10:47 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DAFF4F65-2A0D-45F1-BAE8-9995A3D33DC6}\mpengine.dll
2011-12-08 11:08 . 2011-12-08 11:08 ——– d—–w- e:\documents and settings\Phil\Application Data\AVG Secure Search
2011-12-08 11:08 . 2011-12-08 11:08 ——– d—–w- e:\program files\Common Files\AVG Secure Search
2011-12-08 11:08 . 2011-12-09 10:38 ——– d—–w- e:\program files\AVG Secure Search
2011-12-07 02:55 . 2011-12-07 02:55 ——– d–h–w- e:\windows\PIF
2011-12-07 02:52 . 2011-12-07 03:05 ——– d—–w- e:\documents and settings\Administrator
2011-11-22 12:59 . 2011-11-22 12:59 ——– d—–w- e:\documents and settings\Phil\Local Settings\Application Data\VS Revo Group
2011-11-22 12:59 . 2009-12-30 16:20 27064 —-a-w- e:\windows\system32\drivers\revoflt.sys
2011-11-22 12:59 . 2011-11-22 12:59 ——– d—–w- e:\program files\VS Revo Group
2011-11-22 11:48 . 2011-08-31 22:00 22216 —-a-w- e:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-08-15 23:56 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-17 14:00 . 2011-05-18 12:05 414368 —-a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:42 . 2011-10-24 12:42 20909356 —-a-w- E:\GEDC0052.zip
2011-10-10 14:22 . 2010-12-09 01:05 692736 ——w- e:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- e:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- e:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —-a-w- e:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- e:\windows\system32\oleaccrc.dll
1997-06-23 08:00 123664 –sha-w- e:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 –sha-w- e:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 –sha-w- e:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 –sha-w- e:\windows\system32\Msxbse35.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "e:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-09 10:38 1451336 —-a-w- e:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "e:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-09 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="e:\documents and settings\Phil\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"RCUI"="e:\progra~1\RINGCE~1\RINGCE~1\RCUI.exe" [2010-11-23 500992]
"RCHotKey"="e:\progra~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2010-11-23 38144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="e:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]
"LXBXCATS"="e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="e:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="e:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="e:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Microsoft Default Manager"="e:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"boincmgr"="e:\program files\BOINC\boincmgr.exe" [2010-09-23 4543232]
"boinctray"="e:\program files\BOINC\boinctray.exe" [2010-09-23 58112]
"HPWQTOOLBOX"="e:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"MpsOnn"="e:\windows\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [2007-05-27 28232]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"MSC"="e:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"vProt"="e:\program files\AVG Secure Search\vprot.exe" [2011-12-08 218440]
.
e:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - e:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-24 10872]
subst.lnk - e:\windows\system32\subst.exe [2004-8-4 9216]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sh–w- e:\program files\Messenger\msmsgs.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\WINDOWS\\system32\\lxbxcoms.exe"=
"e:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxbxPSWX.EXE"=
"e:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"e:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"e:\\Program Files\\RingCentral\\RingCentral Call Controller\\RCUI.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"e:\\Documents and Settings\\Phil\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [11/9/2010 10:20 PM 297168]
R1 BIOS;BIOS;e:\windows\system32\drivers\BIOS.sys [12/8/2010 1:53 PM 13696]
R1 MpKslef0e93ad;MpKslef0e93ad;\??\e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A6E1A84-1852-4D5C-94E8-FAC9731B4F95}\MpKslef0e93ad.sys –> e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7A6E1A84-1852-4D5C-94E8-FAC9731B4F95}\MpKslef0e93ad.sys [?]
R1 MpKslf4f68c82;MpKslf4f68c82;e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DAFF4F65-2A0D-45F1-BAE8-9995A3D33DC6}\MpKslf4f68c82.sys [12/12/2011 12:26 AM 29904]
R2 avgwd;AVG WatchDog;e:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 4:33 AM 269520]
R2 vToolbarUpdater;vToolbarUpdater;e:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/8/2011 6:08 AM 246600]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;e:\windows\system32\drivers\lne100v5.sys [12/8/2010 8:51 AM 36224]
S2 gupdate;Google Update Service (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [12/8/2010 1:56 PM 1684736]
S3 gupdatem;Google Update Service (gupdatem);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 Revoflt;Revoflt;e:\windows\system32\drivers\revoflt.sys [11/22/2011 7:59 AM 27064]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL7F2D0338
*NewlyCreated* - MPKSLBE80A023
*NewlyCreated* - MPKSLF4F68C82
*NewlyCreated* - MPKSLFB116041
*Deregistered* - MpKsl7f2d0338
*Deregistered* - MpKslbe80a023
*Deregistered* - MpKslfb116041
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-11 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-12 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-12 e:\windows\Tasks\MP Scheduled Scan.job
- e:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.yahoo.com
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - e:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-12 06:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE255"): The system cannot find the file specified.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
Completion time: 2011-12-12 06:39:21
ComboFix-quarantined-files.txt 2011-12-12 11:39
.
Pre-Run: 467,439,685,632 bytes free
Post-Run: 467,974,197,248 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - DAA032A8CF142063FA9628ED2CBDB9C1

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI