This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Delayed Writer Failed...virus, malware? [Solved]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think this is that #2 choice even thought the #1 choice was still highlited in yellow color?

RogueKiller V6.1.12 [12/02/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode
User: Brian [Admin rights]
Mode: Remove – Date : 12/04/2011 10:42:45

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKLM\[…]\Run : vMttfGqwJXmmgo.exe (C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe) -> DELETED
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> DELETED
[HJ] HKCU\[…]\Advanced : Start_ShowMyComputer (0) -> REPLACED (1)
[HJ] HKCU\[…]\Advanced : Start_ShowSearch (0) -> REPLACED (1)
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Good job

You didn’t tell me how the computer is running now. Please do so in the next post

Try running these in normal mode if you can. If not, run them in safe mode.

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    [2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
    [2011/11/30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
    [2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
    [2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
    [2011/11/30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
    [2011/11/30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
    
    :Commands
    [purity]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
==================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Logs to include:

OTL fix log
New OTL log
ComboFix.txt


Please also remember to tell me how things are with the computer.

Thanks

Satchfan
I rebooted out of SAFE MODE, and things appeared te OK except all my desktop icons were somewhat shaddowy rather than crisp and clear. I began to put all of these 'programs and logs into a single folder on my desktop for eventual deleteion, BUT I ran into trouble with one indicated icon shortcut called "System Fix". It appears to have a Microsoft logo, but I don't think it is such. …in fact now I know it is NOT. When I went to move that shortcut icon to that floder I created, It opened that same old window I was having trouble with before. It insist I neeed to run a scan….and I can not close this window, nor minimize it !! It persit on my desktop. When I tried to move it around it opened another window to say "Filed Indexation Prcess Failed"….and I can't close that window without being forced to click "resolve this issue"…which I close not to do. So I guess I have to shut off this computer again and reopen it in Safe Mode These FREAKING spam writers should be put in JAIL, and/or hung up by their fingers so they can remember the next time they decide to type this carp** up While I was typing this forum response, suddenly that 'rouge window' disappeared and my Security Essentials program wnidow opened up to say one new threat was found….and then eliminated ("removed"). A look in the history says it was "Trojan:Win32/FakeSysdef " It sited these items, files as a reference: 1) file: C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe 2) file: c\documents and settings\brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.Ink 3) file: c\documents and settings\brian\Desktop\System Fix.Ink 4) folder: c\documentsand settings\brian\Strart Menu\Programs\System Fix\ 5) process:pid 1664 Now I have rebooted again into normal mode, and that icon "System Fix' is no longer there, BUT all my other icons on the desktop are shaddowy rather than clear?? I feel something is still here??
OKAY here is OTL run again

(while this was happening my Security Essentials program window opened up to inform me that this history threat should be removed from my computer, so I clicked OK)

OTL logfile created on: 12/4/2011 12:40:05 PM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\Desktop\VIRUS FIX
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

991.48 Mb Total Physical Memory | 564.52 Mb Available Physical Memory | 56.94% Memory free
2.34 Gb Paging File | 1.99 Gb Available in Paging File | 85.16% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 131.37 Gb Free Space | 88.14% Space Free | Partition Type: NTFS

Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Brian\Desktop\VIRUS FIX\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ltmsg.exe (Agere Systems)
PRC - C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MpKslef447c30) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\MpKslef447c30.sys (Microsoft Corporation)
DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ppsio2) – C:\WINDOWS\System32\drivers\ppsio2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1281530804562 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1281533633281 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{74154A94-5F2B-46A0-A274-CDAA7769E700}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (NVDESK32.DLL) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 07:36:55 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/04 11:35:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Desktop\VIRUS FIX
[2011/12/03 11:22:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Brian\Recent
[2011/11/30 12:51:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\System Fix
[2011/11/15 15:55:56 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\My Documents\DudleyDix 55 stuff
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/04 12:44:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
[2011/12/04 12:30:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/04 12:25:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/04 12:25:03 | 1039,716,352 | -HS- | M] () – C:\hiberfil.sys
[2011/12/04 10:43:32 | 000,111,872 | —- | M] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/12/03 11:21:55 | 000,013,646 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:44:04 | 000,445,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/29 13:14:46 | 000,000,077 | -H– | M] () – C:\WINDOWS\mydebug.ini
[2011/11/25 11:11:06 | 000,263,214 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/24 13:03:02 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/24 00:27:43 | 000,414,368 | -H– | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/23 14:58:51 | 000,054,017 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 22:51:57 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/11/09 17:34:04 | 000,292,513 | -H– | M] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/11/06 09:47:05 | 000,311,604 | -H– | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 09:47:05 | 000,039,992 | -H– | M] () – C:\WINDOWS\System32\perfc009.dat
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/04 11:30:53 | 1039,716,352 | -HS- | C] () – C:\hiberfil.sys
[2011/12/04 08:47:57 | 000,111,872 | —- | C] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/11/30 12:51:09 | 000,000,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:51:03 | 000,000,416 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:47:08 | 000,445,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/25 11:11:06 | 000,263,214 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/23 17:06:48 | 000,054,017 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 17:34:04 | 000,292,513 | -H– | C] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/07/13 18:13:34 | 000,000,077 | -H– | C] () – C:\WINDOWS\mydebug.ini
[2010/12/14 09:58:02 | 000,023,200 | -H– | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2010/12/14 09:52:34 | 000,000,090 | -H– | C] () – C:\WINDOWS\calera.ini
[2010/09/13 16:26:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/09/11 16:47:33 | 000,006,656 | -H– | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/25 19:33:07 | 000,001,456 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2010/08/25 19:33:00 | 000,269,312 | -H– | C] () – C:\WINDOWS\System32\FPXIG.DLL
[2010/08/25 19:33:00 | 000,068,096 | -H– | C] () – C:\WINDOWS\System32\IGFPX32P.DLL
[2010/08/25 19:33:00 | 000,065,024 | -H– | C] () – C:\WINDOWS\System32\JPEGACC.DLL
[2010/08/25 19:32:40 | 000,101,376 | -H– | C] () – C:\WINDOWS\System32\WELSOF32.DLL
[2010/08/17 20:58:39 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/11 08:09:31 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 07:41:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 07:34:53 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/11 03:31:43 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/11 03:30:24 | 000,119,744 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/07/16 15:54:55 | 000,004,594 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,311,604 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,039,992 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/31 13:03:00 | 000,001,024 | -H– | C] () – C:\WINDOWS\System32\drivers\jedih2rx.bin
[2002/03/31 13:03:00 | 000,000,122 | -H– | C] () – C:\WINDOWS\System32\drivers\ramsed.bin

========== Custom Scans ==========


< :Services >

< >

< :OTL >

< [2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv >
Invalid Switch: 30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv


< [2011/11/30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk >
Invalid Switch: 30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk


< [2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv >
Invalid Switch: 30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv


< [2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr >
Invalid Switch: 30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr


< [2011/11/30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe >
Invalid Switch: 30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe


< [2011/11/30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk >
Invalid Switch: 30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk


< >

< :Commands >

< [purity] >

< [Reboot] >

< >

< End of report >
…and ComboFix run:

ComboFix 11-12-04.03 - Brian 12/04/2011 13:31:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.576 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS FIX\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Brian\Start Menu\Programs\System Fix
c:\documents and settings\Brian\Start Menu\Programs\System Fix\System Fix.lnk
c:\documents and settings\Brian\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
c:\documents and settings\Brian\WINDOWS
c:\windows\system32\spool\prtprocs\w32x86\Ppbiproc.dll
c:\windows\system32\usmt\migwiz_a.exe
c:\windows\tsoc.log
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 17:50 . 2011-12-04 17:50 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\MpKsl259b5f4c.sys
2011-12-04 17:50 . 2011-12-04 17:50 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\offreg.dll
2011-12-04 16:44 . 2011-11-21 07:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\mpengine.dll
2011-12-04 13:47 . 2011-12-04 15:43 111872 —-a-w- c:\windows\system32\drivers\TrueSight.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 05:27 . 2011-07-13 13:39 414368 —ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2010-08-11 12:35 692736 —ha-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2010-08-13 11:25 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2003-03-20 20:18 599040 —ha-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2011-09-26 15:41 611328 —h–w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2003-07-16 20:40 220160 —ha-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2003-07-16 20:40 20480 —ha-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2003-07-16 20:51 1858944 —ha-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="c:\progra~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2001-08-10 40960]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LTMSG"="LTMSG.exe 7" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2001-09-10 86016]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Brian\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 MpKsl259b5f4c;MpKsl259b5f4c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\MpKsl259b5f4c.sys [12/4/2011 12:50 PM 29904]
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [12/14/2010 9:58 AM 23200]
S1 MpKsl2566cd55;MpKsl2566cd55;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1ECD322C-41E1-4C57-A174-859FD9B7C8F1}\MpKsl2566cd55.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1ECD322C-41E1-4C57-A174-859FD9B7C8F1}\MpKsl2566cd55.sys [?]
S1 MpKsl3684ff9f;MpKsl3684ff9f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9B95E8AB-C6E3-4366-B54F-056440F62C6A}\MpKsl3684ff9f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9B95E8AB-C6E3-4366-B54F-056440F62C6A}\MpKsl3684ff9f.sys [?]
S1 MpKsl4496611b;MpKsl4496611b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DA828752-379C-4F1F-9331-032EC68C7D85}\MpKsl4496611b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DA828752-379C-4F1F-9331-032EC68C7D85}\MpKsl4496611b.sys [?]
S1 MpKsl490f2a2e;MpKsl490f2a2e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24E42B56-EEB8-4903-B71D-9214B67924BB}\MpKsl490f2a2e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24E42B56-EEB8-4903-B71D-9214B67924BB}\MpKsl490f2a2e.sys [?]
S1 MpKsl6d9298ee;MpKsl6d9298ee;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D061D4B-1AB2-4470-BAAB-EB485C61AFA0}\MpKsl6d9298ee.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D061D4B-1AB2-4470-BAAB-EB485C61AFA0}\MpKsl6d9298ee.sys [?]
S1 MpKsl7597b668;MpKsl7597b668;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8BA7479A-E650-4891-B37E-6BC2A8B4F6E8}\MpKsl7597b668.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8BA7479A-E650-4891-B37E-6BC2A8B4F6E8}\MpKsl7597b668.sys [?]
S1 MpKsl7701f4bc;MpKsl7701f4bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7EF2F18-3253-4F08-96F5-34453A8C9FC4}\MpKsl7701f4bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7EF2F18-3253-4F08-96F5-34453A8C9FC4}\MpKsl7701f4bc.sys [?]
S1 MpKsl9c38bf9f;MpKsl9c38bf9f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7986C9CF-F671-499D-AE4F-D3FB93D9D1BD}\MpKsl9c38bf9f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7986C9CF-F671-499D-AE4F-D3FB93D9D1BD}\MpKsl9c38bf9f.sys [?]
S1 MpKsl9e15f1ab;MpKsl9e15f1ab;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsl9e15f1ab.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsl9e15f1ab.sys [?]
S1 MpKsla4c31466;MpKsla4c31466;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EFF2CAEB-8F59-4050-A323-74B37ED1BBF3}\MpKsla4c31466.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EFF2CAEB-8F59-4050-A323-74B37ED1BBF3}\MpKsla4c31466.sys [?]
S1 MpKslafdb40e7;MpKslafdb40e7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EAE62FA4-23D3-49F2-B6A8-57C46C20927D}\MpKslafdb40e7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EAE62FA4-23D3-49F2-B6A8-57C46C20927D}\MpKslafdb40e7.sys [?]
S1 MpKsldeaa0461;MpKsldeaa0461;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsldeaa0461.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsldeaa0461.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL259B5F4C
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-12-04 c:\windows\Tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
TCP: DhcpNameServer = 192.168.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 13:35
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-12-04 13:39:11
ComboFix-quarantined-files.txt 2011-12-04 18:39
.
Pre-Run: 141,076,656,128 bytes free
Post-Run: 141,997,502,464 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 383CD8E476559EEBDE428C9960472443
Now it appears as though my computer is back to normal….and my desktop icons are 'bright' again rather than shaddowy.

If we truly have it fixed now, I would ask one other question? Why do I seem to get a lot of "hungapp" with this computer, and then it shutting itself off to avert damaging itself?? I then have to restart it to get it going again. Can you tell anything from the file records I have included??

At one time I thought it might have something to do with the graphics card that has never been changed out. I think it is an older NVIDA G Force item? At one point in the past I had a message that my "nv_disp driver has stopped working normally".

I went out an bought on-line a new Matrox G550 Dual DVI video card anticipating that I might replace the video card and do so with a dual screen setup, BUT i never did install it yet.
There could be many reasons for Internet Explorer to be “hanging” but this is not my area of expertise. You would be better to start a topic in our Windows forum when we finish up here.

Meanwhile, I’d like to see a copy of the OTL fix log and another OTL scan as I don’t understand some of the files that appeared in your last log.

The OTL fix log can be found at C:\_OTL\MovedFiles. The file name will consist of numbers that reflect the date and time the fix was run. It will be something like 04122011_111009.log.

Please copy and paste the contents into your next reply.

NEXT

Run OTL
  • open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • post the OTL.txt log it produces in your next reply.
Please post back with the log and the fix log

Meanwhile, I’d like to see a copy of the OTL fix log and another OTL scan as I don’t understand some of the files that appeared in your last log.

The OTL fix log can be found at C:\_OTL\MovedFiles. The file name will consist of numbers that reflect the date and time the fix was run. It will be something like 04122011_111009.log.

I couldn't find that file when I did a search. Is that file the same one I posted in posting#20 above? That is the one I did when you requested that same info??



.

NEXT

Run OTL

  • open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
  • post the OTL.txt log it produces in your next reply.
Please post back with the log and the fix log

Now I will do that.

Run OTL
•open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
•post the OTL.txt log it produces in your next reply.

I just tried to do this run and as soon as I click on Quick Scan the boxes beside LOP check and Purity automatically get checked….and I am unable to uncheck them??

Then when I try to close that OTL window I get a message that it is NOT responding….then I get the message 'hung app' ??? Tried this several times and all ways the same…it would not let me run the OTL as a Quick Scan
Ignore the previous instructions and do the following

Run TDSSKiller

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan

Ignore the previous instructions and do the following

Run TDSSKiller

Please download TDSSKiller.zip

  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

I ran this 'killer' scan, and it found NO problems. It also gave me a 'report window' that I was unable to copy and save onto this forum. It said 'report' but offered no way to save it or copy it??

I could not even right click, copy and paste it??
Opps, maybe I just found a copy on my C drive after I did a search for it. Is this it?? 09:39:23.0828 2772 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 09:39:23.0921 2772 ============================================================ 09:39:23.0921 2772 Current date / time: 2011/12/06 09:39:23.0921 09:39:23.0921 2772 SystemInfo: 09:39:23.0921 2772 09:39:23.0921 2772 OS Version: 5.1.2600 ServicePack: 3.0 09:39:23.0921 2772 Product type: Workstation 09:39:23.0921 2772 ComputerName: BRIANS 09:39:23.0921 2772 UserName: Brian 09:39:23.0921 2772 Windows directory: C:\WINDOWS 09:39:23.0921 2772 System windows directory: C:\WINDOWS 09:39:23.0921 2772 Processor architecture: Intel x86 09:39:23.0921 2772 Number of processors: 1 09:39:23.0921 2772 Page size: 0x1000 09:39:23.0921 2772 Boot type: Normal boot 09:39:23.0921 2772 ============================================================ 09:39:25.0062 2772 Initialize success 09:39:27.0828 3136 ============================================================ 09:39:27.0828 3136 Scan started 09:39:27.0828 3136 Mode: Manual; 09:39:27.0828 3136 ============================================================ 09:39:28.0390 3136 Abiosdsk - ok 09:39:28.0421 3136 abp480n5 - ok 09:39:28.0484 3136 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 09:39:28.0484 3136 ACPI - ok 09:39:28.0546 3136 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 09:39:28.0546 3136 ACPIEC - ok 09:39:28.0578 3136 adpu160m - ok 09:39:28.0640 3136 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 09:39:28.0640 3136 aec - ok 09:39:28.0718 3136 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 09:39:28.0718 3136 AFD - ok 09:39:28.0750 3136 Aha154x - ok 09:39:28.0781 3136 aic78u2 - ok 09:39:28.0812 3136 aic78xx - ok 09:39:28.0921 3136 AliIde - ok 09:39:28.0984 3136 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS\system32\DRIVERS\amdk7.sys 09:39:28.0984 3136 AmdK7 - ok 09:39:29.0031 3136 amsint - ok 09:39:29.0093 3136 asc - ok 09:39:29.0171 3136 asc3350p - ok 09:39:29.0218 3136 asc3550 - ok 09:39:29.0281 3136 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 09:39:29.0281 3136 AsyncMac - ok 09:39:29.0328 3136 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 09:39:29.0328 3136 atapi - ok 09:39:29.0359 3136 Atdisk - ok 09:39:29.0437 3136 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 09:39:29.0437 3136 Atmarpc - ok 09:39:29.0484 3136 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 09:39:29.0500 3136 audstub - ok 09:39:29.0578 3136 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 09:39:29.0578 3136 Beep - ok 09:39:29.0671 3136 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 09:39:29.0671 3136 cbidf2k - ok 09:39:29.0703 3136 cd20xrnt - ok 09:39:29.0781 3136 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 09:39:29.0781 3136 Cdaudio - ok 09:39:29.0828 3136 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 09:39:29.0843 3136 Cdfs - ok 09:39:29.0875 3136 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 09:39:29.0875 3136 Cdrom - ok 09:39:29.0953 3136 Changer - ok 09:39:30.0078 3136 CmdIde - ok 09:39:30.0187 3136 Cpqarray - ok 09:39:30.0250 3136 dac2w2k - ok 09:39:30.0296 3136 dac960nt - ok 09:39:30.0390 3136 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 09:39:30.0390 3136 Disk - ok 09:39:30.0515 3136 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 09:39:30.0515 3136 dmboot - ok 09:39:30.0562 3136 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 09:39:30.0562 3136 dmio - ok 09:39:30.0609 3136 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 09:39:30.0609 3136 dmload - ok 09:39:30.0671 3136 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 09:39:30.0671 3136 DMusic - ok 09:39:30.0765 3136 dpti2o - ok 09:39:30.0812 3136 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 09:39:30.0812 3136 drmkaud - ok 09:39:30.0937 3136 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 09:39:30.0968 3136 Fastfat - ok 09:39:31.0015 3136 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 09:39:31.0031 3136 Fdc - ok 09:39:31.0093 3136 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 09:39:31.0093 3136 Fips - ok 09:39:31.0125 3136 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 09:39:31.0140 3136 Flpydisk - ok 09:39:31.0187 3136 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 09:39:31.0187 3136 FltMgr - ok 09:39:31.0234 3136 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 09:39:31.0234 3136 Fs_Rec - ok 09:39:31.0281 3136 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 09:39:31.0296 3136 Ftdisk - ok 09:39:31.0328 3136 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys 09:39:31.0343 3136 gameenum - ok 09:39:31.0375 3136 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 09:39:31.0375 3136 Gpc - ok 09:39:31.0500 3136 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 09:39:31.0500 3136 hidusb - ok 09:39:31.0546 3136 hpn - ok 09:39:31.0625 3136 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 09:39:31.0640 3136 HTTP - ok 09:39:31.0671 3136 i2omgmt - ok 09:39:31.0734 3136 i2omp - ok 09:39:31.0781 3136 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 09:39:31.0781 3136 i8042prt - ok 09:39:31.0828 3136 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 09:39:31.0843 3136 Imapi - ok 09:39:31.0921 3136 ini910u - ok 09:39:32.0000 3136 IntelIde - ok 09:39:32.0078 3136 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 09:39:32.0078 3136 ip6fw - ok 09:39:32.0109 3136 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 09:39:32.0109 3136 IpFilterDriver - ok 09:39:32.0156 3136 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 09:39:32.0156 3136 IpInIp - ok 09:39:32.0203 3136 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 09:39:32.0203 3136 IpNat - ok 09:39:32.0265 3136 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 09:39:32.0265 3136 IPSec - ok 09:39:32.0312 3136 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 09:39:32.0312 3136 IRENUM - ok 09:39:32.0390 3136 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 09:39:32.0390 3136 isapnp - ok 09:39:32.0453 3136 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 09:39:32.0453 3136 Kbdclass - ok 09:39:32.0500 3136 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 09:39:32.0500 3136 kmixer - ok 09:39:32.0562 3136 KMWDFILTER (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys 09:39:32.0562 3136 KMWDFILTER - ok 09:39:32.0609 3136 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 09:39:32.0609 3136 KSecDD - ok 09:39:32.0671 3136 lbrtfdc - ok 09:39:32.0812 3136 ltmodem5 (3070246fba35aa2e0c2251d55f5848f8) C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys 09:39:32.0828 3136 ltmodem5 - ok 09:39:32.0906 3136 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 09:39:32.0906 3136 mnmdd - ok 09:39:32.0968 3136 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 09:39:32.0984 3136 Modem - ok 09:39:33.0015 3136 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 09:39:33.0031 3136 Mouclass - ok 09:39:33.0078 3136 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 09:39:33.0078 3136 mouhid - ok 09:39:33.0140 3136 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 09:39:33.0140 3136 MountMgr - ok 09:39:33.0187 3136 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 09:39:33.0187 3136 MpFilter - ok 09:39:33.0234 3136 MpKsl2566cd55 - ok 09:39:33.0250 3136 MpKsl3684ff9f - ok 09:39:33.0296 3136 MpKsl4496611b - ok 09:39:33.0343 3136 MpKsl490f2a2e - ok 09:39:33.0390 3136 MpKsl6d9298ee - ok 09:39:33.0421 3136 MpKsl7597b668 - ok 09:39:33.0468 3136 MpKsl7701f4bc - ok 09:39:33.0515 3136 MpKsl9c38bf9f - ok 09:39:33.0562 3136 MpKsl9e15f1ab - ok 09:39:33.0593 3136 MpKsla4c31466 - ok 09:39:33.0640 3136 MpKslafdb40e7 - ok 09:39:33.0703 3136 MpKslb300a684 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9C32EAEA-7224-4D57-ADAC-3CF2D4DAF530}\MpKslb300a684.sys 09:39:33.0703 3136 MpKslb300a684 - ok 09:39:33.0734 3136 MpKsldeaa0461 - ok 09:39:33.0781 3136 mraid35x - ok 09:39:33.0828 3136 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 09:39:33.0828 3136 MRxDAV - ok 09:39:33.0906 3136 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 09:39:33.0906 3136 MRxSmb - ok 09:39:33.0968 3136 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 09:39:33.0968 3136 Msfs - ok 09:39:34.0062 3136 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 09:39:34.0062 3136 MSKSSRV - ok 09:39:34.0125 3136 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 09:39:34.0140 3136 MSPCLOCK - ok 09:39:34.0171 3136 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 09:39:34.0171 3136 MSPQM - ok 09:39:34.0250 3136 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 09:39:34.0250 3136 mssmbios - ok 09:39:34.0296 3136 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys 09:39:34.0296 3136 ms_mpu401 - ok 09:39:34.0359 3136 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 09:39:34.0359 3136 Mup - ok 09:39:34.0421 3136 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 09:39:34.0421 3136 NDIS - ok 09:39:34.0484 3136 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 09:39:34.0484 3136 NdisTapi - ok 09:39:34.0515 3136 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 09:39:34.0515 3136 Ndisuio - ok 09:39:34.0546 3136 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 09:39:34.0546 3136 NdisWan - ok 09:39:34.0625 3136 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 09:39:34.0625 3136 NDProxy - ok 09:39:34.0656 3136 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 09:39:34.0656 3136 NetBIOS - ok 09:39:34.0718 3136 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 09:39:34.0718 3136 NetBT - ok 09:39:34.0859 3136 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 09:39:34.0859 3136 Npfs - ok 09:39:34.0937 3136 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 09:39:34.0937 3136 Ntfs - ok 09:39:35.0046 3136 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 09:39:35.0046 3136 Null - ok 09:39:35.0156 3136 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 09:39:35.0187 3136 nv - ok 09:39:35.0250 3136 nvax (47b3852808dd579a463fce7085b77413) C:\WINDOWS\system32\drivers\nvax.sys 09:39:35.0250 3136 nvax - ok 09:39:35.0312 3136 NVENET (fbbd6ad506566910e53ffd07eed4ad65) C:\WINDOWS\system32\DRIVERS\NVENET.sys 09:39:35.0312 3136 NVENET - ok 09:39:35.0375 3136 nvnforce (adbcba116496229a163193bbe0bb28ce) C:\WINDOWS\system32\drivers\nvapu.sys 09:39:35.0375 3136 nvnforce - ok 09:39:35.0421 3136 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 09:39:35.0421 3136 NwlnkFlt - ok 09:39:35.0453 3136 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 09:39:35.0453 3136 NwlnkFwd - ok 09:39:35.0531 3136 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 09:39:35.0531 3136 Parport - ok 09:39:35.0562 3136 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 09:39:35.0562 3136 PartMgr - ok 09:39:35.0640 3136 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 09:39:35.0640 3136 ParVdm - ok 09:39:35.0687 3136 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 09:39:35.0687 3136 PCI - ok 09:39:35.0718 3136 PCIDump - ok 09:39:35.0750 3136 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 09:39:35.0765 3136 PCIIde - ok 09:39:35.0796 3136 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 09:39:35.0796 3136 Pcmcia - ok 09:39:35.0828 3136 PDCOMP - ok 09:39:35.0875 3136 PDFRAME - ok 09:39:35.0921 3136 PDRELI - ok 09:39:35.0968 3136 PDRFRAME - ok 09:39:36.0015 3136 perc2 - ok 09:39:36.0046 3136 perc2hib - ok 09:39:36.0265 3136 ppsio2 (de4dfb09bf96fd5f810750140e2aa236) C:\WINDOWS\system32\drivers\ppsio2.sys 09:39:36.0265 3136 ppsio2 - ok 09:39:36.0312 3136 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 09:39:36.0312 3136 PptpMiniport - ok 09:39:36.0390 3136 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 09:39:36.0390 3136 PSched - ok 09:39:36.0437 3136 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 09:39:36.0453 3136 Ptilink - ok 09:39:36.0484 3136 ql1080 - ok 09:39:36.0515 3136 Ql10wnt - ok 09:39:36.0562 3136 ql12160 - ok 09:39:36.0609 3136 ql1240 - ok 09:39:36.0656 3136 ql1280 - ok 09:39:36.0718 3136 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 09:39:36.0718 3136 RasAcd - ok 09:39:36.0781 3136 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 09:39:36.0781 3136 Rasl2tp - ok 09:39:36.0843 3136 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 09:39:36.0843 3136 RasPppoe - ok 09:39:36.0890 3136 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 09:39:36.0890 3136 Raspti - ok 09:39:36.0953 3136 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 09:39:36.0953 3136 Rdbss - ok 09:39:36.0984 3136 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 09:39:37.0000 3136 RDPCDD - ok 09:39:37.0093 3136 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 09:39:37.0109 3136 RDPWD - ok 09:39:37.0156 3136 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 09:39:37.0156 3136 redbook - ok 09:39:37.0375 3136 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 09:39:37.0375 3136 Secdrv - ok 09:39:37.0437 3136 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 09:39:37.0437 3136 serenum - ok 09:39:37.0484 3136 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 09:39:37.0484 3136 Serial - ok 09:39:37.0531 3136 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 09:39:37.0531 3136 Sfloppy - ok 09:39:37.0609 3136 Simbad - ok 09:39:37.0656 3136 Sparrow - ok 09:39:37.0718 3136 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 09:39:37.0718 3136 splitter - ok 09:39:37.0781 3136 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 09:39:37.0796 3136 sr - ok 09:39:37.0875 3136 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 09:39:37.0890 3136 Srv - ok 09:39:37.0984 3136 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 09:39:37.0984 3136 swenum - ok 09:39:38.0031 3136 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 09:39:38.0031 3136 swmidi - ok 09:39:38.0109 3136 symc810 - ok 09:39:38.0156 3136 symc8xx - ok 09:39:38.0203 3136 sym_hi - ok 09:39:38.0265 3136 sym_u3 - ok 09:39:38.0328 3136 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 09:39:38.0328 3136 sysaudio - ok 09:39:38.0468 3136 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 09:39:38.0468 3136 Tcpip - ok 09:39:38.0515 3136 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 09:39:38.0515 3136 TDPIPE - ok 09:39:38.0546 3136 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 09:39:38.0546 3136 TDTCP - ok 09:39:38.0593 3136 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 09:39:38.0593 3136 TermDD - ok 09:39:38.0703 3136 TosIde - ok 09:39:38.0796 3136 TrueSight (f69641efdb19acb4753b0155f7fdeed5) c:\windows\system32\drivers\TrueSight.sys 09:39:38.0796 3136 TrueSight - ok 09:39:38.0859 3136 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 09:39:38.0859 3136 Udfs - ok 09:39:38.0906 3136 ultra - ok 09:39:38.0984 3136 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 09:39:38.0984 3136 Update - ok 09:39:39.0062 3136 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 09:39:39.0062 3136 usbehci - ok 09:39:39.0109 3136 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 09:39:39.0109 3136 usbhub - ok 09:39:39.0140 3136 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 09:39:39.0140 3136 usbohci - ok 09:39:39.0203 3136 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 09:39:39.0203 3136 usbprint - ok 09:39:39.0281 3136 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 09:39:39.0281 3136 usbscan - ok 09:39:39.0312 3136 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 09:39:39.0312 3136 USBSTOR - ok 09:39:39.0359 3136 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 09:39:39.0359 3136 VgaSave - ok 09:39:39.0390 3136 ViaIde - ok 09:39:39.0453 3136 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 09:39:39.0453 3136 VolSnap - ok 09:39:39.0562 3136 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 09:39:39.0562 3136 Wanarp - ok 09:39:39.0593 3136 WDICA - ok 09:39:39.0656 3136 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 09:39:39.0656 3136 wdmaud - ok 09:39:39.0968 3136 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 09:39:39.0968 3136 WudfPf - ok 09:39:40.0031 3136 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 09:39:40.0031 3136 WudfRd - ok 09:39:40.0156 3136 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 09:39:40.0296 3136 \Device\Harddisk0\DR0 - ok 09:39:40.0312 3136 Boot (0x1200) (68c8d614aa9fc8d5db38ceb73b55b84b) \Device\Harddisk0\DR0\Partition0 09:39:40.0312 3136 \Device\Harddisk0\DR0\Partition0 - ok 09:39:40.0328 3136 ============================================================ 09:39:40.0328 3136 Scan finished 09:39:40.0328 3136 ============================================================ 09:39:40.0390 3128 Detected object count: 0 09:39:40.0390 3128 Actual detected object count: 0 09:43:46.0609 0752 Deinitialize success
OK, Combo Fix log

ComboFix 11-12-06.01 - Brian 12/06/2011 17:42:41.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.535 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\VIRUS FIX\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-06 22:17 . 2011-12-06 22:17 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9C32EAEA-7224-4D57-ADAC-3CF2D4DAF530}\MpKsl68489111.sys
2011-12-06 22:17 . 2011-12-06 22:17 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9C32EAEA-7224-4D57-ADAC-3CF2D4DAF530}\offreg.dll
2011-12-06 03:48 . 2011-11-21 07:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9C32EAEA-7224-4D57-ADAC-3CF2D4DAF530}\mpengine.dll
2011-12-04 19:57 . 2011-12-06 03:37 ——– d—–w- c:\program files\Common Files\Panda Software
2011-12-04 13:47 . 2011-12-04 15:43 111872 —-a-w- c:\windows\system32\drivers\TrueSight.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 05:27 . 2011-07-13 13:39 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-21 07:47 . 2010-08-13 11:25 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2010-08-11 12:35 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2003-03-20 20:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2011-09-26 15:41 611328 ——w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2003-07-16 20:40 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2003-07-16 20:40 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="c:\progra~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2001-08-10 40960]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LTMSG"="LTMSG.exe 7" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2001-09-10 86016]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Brian\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 MpKsl68489111;MpKsl68489111;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9C32EAEA-7224-4D57-ADAC-3CF2D4DAF530}\MpKsl68489111.sys [12/6/2011 5:17 PM 29904]
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [12/14/2010 9:58 AM 23200]
S1 MpKsl2566cd55;MpKsl2566cd55;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1ECD322C-41E1-4C57-A174-859FD9B7C8F1}\MpKsl2566cd55.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1ECD322C-41E1-4C57-A174-859FD9B7C8F1}\MpKsl2566cd55.sys [?]
S1 MpKsl3684ff9f;MpKsl3684ff9f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9B95E8AB-C6E3-4366-B54F-056440F62C6A}\MpKsl3684ff9f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9B95E8AB-C6E3-4366-B54F-056440F62C6A}\MpKsl3684ff9f.sys [?]
S1 MpKsl4496611b;MpKsl4496611b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DA828752-379C-4F1F-9331-032EC68C7D85}\MpKsl4496611b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DA828752-379C-4F1F-9331-032EC68C7D85}\MpKsl4496611b.sys [?]
S1 MpKsl490f2a2e;MpKsl490f2a2e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24E42B56-EEB8-4903-B71D-9214B67924BB}\MpKsl490f2a2e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24E42B56-EEB8-4903-B71D-9214B67924BB}\MpKsl490f2a2e.sys [?]
S1 MpKsl6d9298ee;MpKsl6d9298ee;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D061D4B-1AB2-4470-BAAB-EB485C61AFA0}\MpKsl6d9298ee.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6D061D4B-1AB2-4470-BAAB-EB485C61AFA0}\MpKsl6d9298ee.sys [?]
S1 MpKsl7597b668;MpKsl7597b668;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8BA7479A-E650-4891-B37E-6BC2A8B4F6E8}\MpKsl7597b668.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8BA7479A-E650-4891-B37E-6BC2A8B4F6E8}\MpKsl7597b668.sys [?]
S1 MpKsl7701f4bc;MpKsl7701f4bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7EF2F18-3253-4F08-96F5-34453A8C9FC4}\MpKsl7701f4bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A7EF2F18-3253-4F08-96F5-34453A8C9FC4}\MpKsl7701f4bc.sys [?]
S1 MpKsl9c38bf9f;MpKsl9c38bf9f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7986C9CF-F671-499D-AE4F-D3FB93D9D1BD}\MpKsl9c38bf9f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7986C9CF-F671-499D-AE4F-D3FB93D9D1BD}\MpKsl9c38bf9f.sys [?]
S1 MpKsl9e15f1ab;MpKsl9e15f1ab;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsl9e15f1ab.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsl9e15f1ab.sys [?]
S1 MpKsla4c31466;MpKsla4c31466;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EFF2CAEB-8F59-4050-A323-74B37ED1BBF3}\MpKsla4c31466.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EFF2CAEB-8F59-4050-A323-74B37ED1BBF3}\MpKsla4c31466.sys [?]
S1 MpKslafdb40e7;MpKslafdb40e7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EAE62FA4-23D3-49F2-B6A8-57C46C20927D}\MpKslafdb40e7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EAE62FA4-23D3-49F2-B6A8-57C46C20927D}\MpKslafdb40e7.sys [?]
S1 MpKsldeaa0461;MpKsldeaa0461;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsldeaa0461.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D6898087-57AD-4DEA-A9E9-3B22A1D37858}\MpKsldeaa0461.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL68489111
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-12-06 c:\windows\Tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
TCP: DhcpNameServer = 192.168.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-06 17:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-06 17:50:23
ComboFix-quarantined-files.txt 2011-12-06 22:50
.
Pre-Run: 141,670,752,256 bytes free
Post-Run: 141,786,603,520 bytes free
.
- - End Of File - - F0EBAD049EF31C3EFB1FAFB5DF2C925D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI