This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help, my computer hasbeen taken over [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This has sbeen a great forum to me. Thank you so much, I am very glad I found you guys.

I know that this is an outdated version of HiJackThis but, my computer will not allow me to puta new version on it at this time. I am am gridlock…

Please Help…

Dell Vostro 1400
Windows XP

Scan saved at 1:03:58 PM, on 12/2/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.streetscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080326
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by MSN & Bing
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.9.0.12\IPSBHO.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Hot Corners] "C:\Program Files\Hot Corners\HotC.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://nationalfinancial.webex.com/client/…ing/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Cron Service for Prey (CronService) - Fork Ltd. - C:\Prey\platform\windows\cronsvc.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.9.0.12\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SlingAgentService - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 11121 bytes
:welcome:

See if you can run these programs.


Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Thank you. These ran fine

At one point the computer told me that aswMBR.exe is a corrupt file… is this the virus trying to trick me?

aswMBR:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-06 09:19:48
—————————–
09:19:48.609 OS Version: Windows 5.1.2600 Service Pack 3
09:19:48.609 Number of processors: 2 586 0x1706
09:19:48.609 ComputerName: SGHCOMP UserName:
09:19:49.718 Initialize success
09:25:53.484 AVAST engine defs: 11120601
09:43:35.609 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
09:43:35.640 Disk 0 Vendor: FUJITSU_ 0085 Size: 238475MB BusType: 3
09:43:35.703 Disk 0 MBR read successfully
09:43:35.734 Disk 0 MBR scan
09:43:35.796 Disk 0 Windows XP default MBR code
09:43:35.828 Disk 0 scanning sectors +488392065
09:43:35.953 Disk 0 scanning C:\WINDOWS\system32\drivers
09:43:50.359 Service scanning
09:43:59.437 Modules scanning
09:44:23.718 Disk 0 trace - called modules:
09:44:23.750 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
09:44:23.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b080030]
09:44:23.765 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8b0a7030]
09:44:24.468 AVAST engine scan C:\WINDOWS
09:44:56.187 AVAST engine scan C:\WINDOWS\system32
09:46:57.531 AVAST engine scan C:\WINDOWS\system32\drivers
09:47:16.953 AVAST engine scan C:\Documents and Settings\Sam G. Huszczo
10:10:10.984 AVAST engine scan C:\Documents and Settings\All Users
11:05:15.640 Scan finished successfully
11:14:09.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sam G. Huszczo\Desktop\MBR.dat"
11:14:09.250 The log file has been saved successfully to "C:\Documents and Settings\Sam G. Huszczo\Desktop\aswMBR.txt"


DDS:

.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by [removed] at 11:14:39 on 2011-12-06
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2102 [GMT -5:00]
.
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sam G. Huszczo\Desktop\aswMBR.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam G. Huszczo\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.streetscape.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
uWindow Title = Windows Internet Explorer provided by MSN & Bing
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\17.9.0.12\IPSBHO.DLL
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [Google Update] "c:\documents and settings\sam g. huszczo\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Hot Corners] "c:\program files\hot corners\HotC.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: streetscape.com
Trusted Zone: streetscape.com\nfanalysis
Trusted Zone: streetscape.com\reports
Trusted Zone: streetscape.com\www
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://nationalfinancial.webex.com/client/T27L/training/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{5788ED06-4F1B-434C-8EC3-0D921E48BB3E} : DhcpNameServer = [removed] [removed]
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1109000.00c\symds.sys [2011-10-11 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1109000.00c\symefa.sys [2011-10-11 173176]
S1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\bashdefs\20111114.002\BHDrvx86.sys [2011-11-14 819320]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1109000.00c\cchpx86.sys [2011-10-11 485512]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1109000.00c\ironx86.sys [2011-10-11 116784]
S2 CronService;Cron Service for Prey;c:\prey\platform\windows\cronsvc.exe [2010-8-30 16384]
S2 DisplayLinkService;DisplayLinkManager;c:\program files\displaylink core software\DisplayLinkManager.exe [2011-10-5 6831464]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-14 136176]
S2 MSSQL$ACT7;MSSQL$ACT7;c:\program files\microsoft sql server\mssql$act7\binn\sqlservr.exe -sact7 –> c:\program files\microsoft sql server\mssql$act7\binn\sqlservr.exe -sACT7 [?]
S2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\17.9.0.12\ccsvchst.exe [2011-10-11 126400]
S2 NeatReceipts Database Controller;NeatReceipts Database Controller;c:\program files\common files\neatreceipts\db controller\NeatReceiptsDBController.exe [2008-2-5 228480]
S2 SlingAgentService;SlingAgentService;c:\program files\sling media\slingagent\SlingAgentService.exe [2009-9-25 93960]
S3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2005-11-25 31896]
S3 DisplayLinkFilter;DisplayLinkFilter;c:\windows\system32\drivers\DisplayLinkFilter.sys [2011-10-5 7296]
S3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [2011-10-5 40576]
S3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [2011-10-5 24448]
S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort_6.0.32700.0.sys [2011-11-14 21888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-11-10 106104]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2009-12-19 18560]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-14 136176]
S3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\ipsdefs\20111124.030\IDSXpx86.sys [2011-11-24 356280]
S3 MSSQL$NR2007;SQL Server (NR2007);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2007-2-10 29178224]
S3 NAVENG;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20111128.002\naveng.sys –> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20111128.002\NAVENG.SYS [?]
S3 NAVEX15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20111128.002\navex15.sys –> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\virusdefs\20111128.002\NAVEX15.SYS [?]
S3 SQLAgent$ACT7;SQLAgent$ACT7;c:\program files\microsoft sql server\mssql$act7\binn\sqlagent.exe -i act7 –> c:\program files\microsoft sql server\mssql$act7\binn\sqlagent.EXE -i ACT7 [?]
.
=============== Created Last 30 ================
.
2011-12-02 18:12:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-12-02 18:12:22 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-02 16:37:46 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-02 16:37:46 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-02 16:37:04 ——– d—–w- c:\program files\iPod
2011-11-29 15:00:47 ——– d—–w- c:\program files\iPod(2)
2011-11-29 14:59:27 ——– d—–w- c:\program files\Apple Software Update(2)
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-11-21 19:08:55 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-11-14 18:26:16 ——– d—–w- c:\program files\DisplayLink Graphics
2011-11-14 18:26:09 21888 —-a-w- c:\windows\system32\drivers\DisplayLinkUsbPort_6.0.32700.0.sys
2011-11-14 18:26:09 1978368 —-a-w- c:\windows\system32\DisplayLinkUsbCo2_6.0.32700.0.dll
.
==================== Find3M ====================
.
2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-05 21:28:51 7296 —-a-w- c:\windows\system32\drivers\DisplayLinkFilter.sys
2011-10-05 21:28:51 40576 —-a-w- c:\windows\system32\drivers\DisplayLinkGAport.sys
2011-10-05 21:28:51 32512 —-a-w- c:\windows\system32\DisplayLinkGAdisp.dll
2011-10-05 21:28:51 24448 —-a-w- c:\windows\system32\drivers\DisplayLinkmirrorport.sys
2011-10-05 21:28:51 18816 —-a-w- c:\windows\system32\DisplayLinkmirrordisp.dll
2011-10-03 10:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 11:15:54.03 ===============

Attachments:

  • [attachment removed: attach.zip]
Hi,

Nothing really jumping out at me. When you say the computer has been taking over, what exactly do you mean, are you getting any browser redirects or unwanted pop up windows ??

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Hello, Windows will not boot up on its own. when i let the computer turn on, the desktop shows up for a second and then it freezes. if i wait long enough after this freeze, then a blue screen pops up with a bunch of code in it and something to the effect that win32k.sys is either corrupt or failed… When i try to open up norton, it freezes up, when i tried to system restore, it freezes up. right now, my computer will only start in safe mode… i cant print anything and the computer is super slow in safe mode. that is all i know. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8292 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 12/6/2011 1:18:33 PM mbam-log-2011-12-06 (13-18-33).txt Scan type: Quick scan Objects scanned: 195657 Time elapsed: 3 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
win32k.sys is a legit windows file as long as its in the system32 folder, otherwise it could be a virus.


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
     win32k.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
This is my memory from last week. the specific name of the file might be slightly off of this. While running SystemLook: It tried to tell me that systemlook.exe is a corrupt file too… and to use the chkdsk utility… Also said C:/$Mft is corrupt and unreadable… and to use the chkdsk utility… SystemLook 30.07.11 by jpshortstuff Log created at 13:39 on 06/12/2011 by Sam G. Huszczo Administrator - Elevation successful ========== filefind ========== Searching for "win32k.sys" C:\i386\win32k.sys –a—- 1843584 bytes [16:42 02/04/2008] [13:47 08/03/2007] 5B5AD4F40BE00F56F51F286BE72C0376 C:\WINDOWS\$hf_mig$\KB2160329\SP3QFE\win32k.sys –a—- 1861120 bytes [02:14 24/06/2010] [02:14 24/06/2010] C0B2DA12C5CB448F9EA3AF16416745CB C:\WINDOWS\$hf_mig$\KB2436673\SP3QFE\win32k.sys –a—- 1862272 bytes [13:27 26/10/2010] [13:27 26/10/2010] ED970A04FDAEAB9D9A5FA9B25E9196A8 C:\WINDOWS\$hf_mig$\KB2479628\SP3QFE\win32k.sys –a—- 1864064 bytes [13:14 31/12/2010] [13:14 31/12/2010] 62FC2280FBEA1DCC64A276BCF71709D9 C:\WINDOWS\$hf_mig$\KB2506223\SP3QFE\win32k.sys –a—- 1866880 bytes [13:27 03/03/2011] [13:27 03/03/2011] D302C0D9ADC931B598405D2C953B334B C:\WINDOWS\$hf_mig$\KB2555917\SP3QFE\win32k.sys –a—- 1867904 bytes [14:07 02/06/2011] [14:07 02/06/2011] BE79F0A0273DEF353BA5D1F43CBAD858 C:\WINDOWS\$hf_mig$\KB2567053\SP3QFE\win32k.sys –a—- 1867904 bytes [13:25 06/09/2011] [13:25 06/09/2011] C30AAF3B63F3BE3B515B50FB7292EA9F C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\win32k.sys –a—- 1836160 bytes [01:11 02/03/2005] [01:11 02/03/2005] F92DA2BB088A56B3A5FB8151E58F2964 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\win32k.sys –a—- 1843968 bytes [21:35 26/03/2008] [13:49 08/03/2007] B9D8F5E6D1A7AC9977CC50ECE7C7FF74 C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys –a—- 1845888 bytes [09:40 19/03/2008] [09:40 19/03/2008] 86E966164A647BE68EC6941B84BEF123 C:\WINDOWS\$hf_mig$\KB954211\SP3QFE\win32k.sys –a—- 1846912 bytes [13:23 16/10/2008] [12:25 15/09/2008] 692E8FC363300FA7951594A1A7A1F193 C:\WINDOWS\$hf_mig$\KB958690\SP3QFE\win32k.sys –a—- 1847552 bytes [11:08 09/02/2009] [11:08 09/02/2009] 1D20198F208006C3BB5ACB50D32CFC66 C:\WINDOWS\$hf_mig$\KB968537\SP3QFE\win32k.sys –a—- 1847808 bytes [10:50 17/04/2009] [10:50 17/04/2009] 7CEDA3396DECF312144BC788D699EE48 C:\WINDOWS\$hf_mig$\KB969947\SP3QFE\win32k.sys –a—- 1859712 bytes [12:19 14/08/2009] [12:19 14/08/2009] F6B54A56F02D24BF43E72662D44A6B14 C:\WINDOWS\$hf_mig$\KB979559\SP3QFE\win32k.sys –a—- 1860352 bytes [06:34 02/05/2010] [06:34 02/05/2010] A3D4A7B714D4A74B7CD4296302F1A9FA C:\WINDOWS\$hf_mig$\KB981957\SP3QFE\win32k.sys –a—- 1861888 bytes [13:38 31/08/2010] [13:38 31/08/2010] 51420D569A883CC13D656783B2C86D8E C:\WINDOWS\$NtServicePackUninstall$\win32k.sys —–c- 1845248 bytes [12:58 23/09/2008] [09:47 19/03/2008] E0F718290D19531FD10328EFB09808EC C:\WINDOWS\$NtUninstallKB2160329$\win32k.sys —–c- 1851264 bytes [07:02 13/08/2010] [05:22 02/05/2010] B9D41312F6D9FFA8D1D80488D9FDE849 C:\WINDOWS\$NtUninstallKB2436673$\win32k.sys —–c- 1852800 bytes [08:03 16/12/2010] [13:42 31/08/2010] A77B5764CD2106D36148CB5E5DDF6BC6 C:\WINDOWS\$NtUninstallKB2479628$\win32k.sys —–c- 1853312 bytes [08:37 09/02/2011] [13:25 26/10/2010] E40E572FD5DA970921A893B05FB217D9 C:\WINDOWS\$NtUninstallKB2506223$\win32k.sys —–c- 1854976 bytes [07:08 14/04/2011] [13:10 31/12/2010] 4F404415E13DDC541CB34294D266B65C C:\WINDOWS\$NtUninstallKB2555917$\win32k.sys —–c- 1857920 bytes [07:00 13/07/2011] [13:21 03/03/2011] 4F97E6BAAA847EA90EBBCD90A3FFA8E5 C:\WINDOWS\$NtUninstallKB2567053$\win32k.sys —–c- 1858944 bytes [07:03 14/10/2011] [14:02 02/06/2011] E97153BE7D053976348554EFD71C53A8 C:\WINDOWS\$NtUninstallKB941693$\win32k.sys —–c- 1843584 bytes [21:41 09/04/2008] [13:47 08/03/2007] 5B5AD4F40BE00F56F51F286BE72C0376 C:\WINDOWS\$NtUninstallKB954211$\win32k.sys —–c- 1845632 bytes [13:29 16/10/2008] [19:30 13/04/2008] DE01D79A607C7B9AE7FF88E934D0FFB2 C:\WINDOWS\$NtUninstallKB958690$\win32k.sys —–c- 1846400 bytes [21:08 11/03/2009] [12:12 15/09/2008] D21A189185D3A74512CC8E68F16E3FCF C:\WINDOWS\$NtUninstallKB968537$\win32k.sys —–c- 1846784 bytes [07:00 11/06/2009] [11:13 09/02/2009] 16B961A0552BC09B9E3A338FC816FFE5 C:\WINDOWS\$NtUninstallKB969947$\win32k.sys —–c- 1847168 bytes [08:00 11/11/2009] [12:26 17/04/2009] B707EA8E261F47B51CAC6FB7AF7770F6 C:\WINDOWS\$NtUninstallKB979559$\win32k.sys —–c- 1850624 bytes [07:11 11/06/2010] [13:21 14/08/2009] 716ED09D8D9A9E1E4A03549B32B68186 C:\WINDOWS\$NtUninstallKB981957$\win32k.sys —–c- 1851904 bytes [07:01 14/10/2010] [13:44 23/06/2010] 2F2D6B7515363E855EE44D88199ADD5F C:\WINDOWS\ServicePackFiles\i386\win32k.sys ——- 1845632 bytes [17:33 03/09/2008] [19:30 13/04/2008] DE01D79A607C7B9AE7FF88E934D0FFB2 C:\WINDOWS\system32\win32k.sys –a—- 1858944 bytes [18:51 10/08/2004] [13:20 06/09/2011] BFE37C3B420D2CA00D83554182130D32 C:\WINDOWS\system32\dllcache\win32k.sys ——- 1858944 bytes [13:23 16/10/2008] [13:20 06/09/2011] BFE37C3B420D2CA00D83554182130D32 -= EOF =-
Again nothing out of the ordinary

You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

C:\WINDOWS\system32\win32k.sys

If the site is busy you can try this one
http://virusscan.jotti.org/en
VirusTotal: 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: win32k.sys Submission date: 2011-12-06 21:26:58 (UTC) Current status: queued (#1) queued analysing finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.12.06.01 2011.12.06 - AntiVir 7.11.19.2 2011.12.06 - Antiy-AVL 2.0.3.7 2011.12.06 - Avast 6.0.1289.0 2011.12.06 - AVG 10.0.0.1190 2011.12.06 - BitDefender 7.2 2011.12.06 - ByteHero 1.0.0.1 2011.11.29 - CAT-QuickHeal 12.00 2011.12.06 - ClamAV 0.97.3.0 2011.12.06 - Commtouch 5.3.2.6 2011.12.06 - Comodo 10859 2011.12.06 - DrWeb 5.0.2.03300 2011.12.06 - Emsisoft 5.1.0.11 2011.12.06 - eSafe 7.0.17.0 2011.12.06 - eTrust-Vet 37.0.9607 2011.12.06 - F-Prot 4.6.5.141 2011.11.29 - F-Secure 9.0.16440.0 2011.12.06 - Fortinet 4.3.388.0 2011.12.06 - GData 22 2011.12.06 - Ikarus T3.1.1.109.0 2011.12.06 - Jiangmin 13.0.900 2011.12.06 - K7AntiVirus 9.119.5608 2011.12.06 - Kaspersky 9.0.0.837 2011.12.06 - McAfee 5.400.0.1158 2011.12.06 - McAfee-GW-Edition 2010.1D 2011.12.06 - Microsoft 1.7903 2011.12.06 - NOD32 6681 2011.12.04 - Norman 6.07.13 2011.12.06 - nProtect 2011-12-06.01 2011.12.06 - Panda 10.0.3.5 2011.12.06 - PCTools 8.0.0.5 2011.12.06 - Prevx 3.0 2011.12.06 - Rising 23.87.01.02 2011.12.06 - Sophos 4.71.0 2011.12.06 - SUPERAntiSpyware 4.40.0.1006 2011.12.06 - Symantec 20111.2.0.82 2011.12.06 - TheHacker 6.7.0.1.352 2011.12.01 - TrendMicro 9.500.0.1008 2011.12.06 - TrendMicro-HouseCall 9.500.0.1008 2011.12.06 - VBA32 3.12.16.4 2011.12.06 - VIPRE 11212 2011.12.06 - ViRobot 2011.12.6.4811 2011.12.06 - VirusBuster 14.1.102.0 2011.12.06 - Additional informationShow all MD5 : bfe37c3b420d2ca00d83554182130d32 SHA1 : 0fddb915127172d40885b2c32f44aa998efa8677 SHA256: e810a8ebdd9bae00c30f8f4d5901bc2f88bb1a3f4c994ff3eb69f14ded208af8 ssdeep: 49152:f896PF2yMow0GpfMY8w7atWObVXa3EnZYu:f896PzMEGdn8vkObJciYu File size : 1858944 bytes First seen: 2011-10-11 18:26:19 Last seen : 2011-12-06 21:26:58 TrID: Win64 Executable Generic (87.2%) Win32 Executable Generic (8.6%) Generic Win/DOS Executable (2.0%) DOS Executable Generic (2.0%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. All rights reserved. product……: Microsoft_ Windows_ Operating System description..: Multi-User Win32 Driver original name: win32k.sys internal name: win32k.sys file version.: 5.1.2600.6149 (xpsp_sp3_gdr.110906-1620) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x1B2F7F timedatestamp….: 0x4E661E29 (Tue Sep 06 13:20:41 2011) machinetype……: 0x14c (I386) [[ 8 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x380, 0x18F6C7, 0x18F700, 6.69, 009affc7d980d0693cfa48de5f103f29 .rdata, 0x18FA80, 0xD0A4, 0xD100, 5.73, d40b3ddfe737792c63fec715c9836643 .data, 0x19CB80, 0x128AC, 0x12900, 3.94, 9812f83b4d51d9eaae55f26f52c06099 .kbdfall, 0x1AF480, 0x63C, 0x680, 4.65, b8840bdf2ea50d3b1d3532e7704c65cd .edata, 0x1AFB00, 0x1AE3, 0x1B00, 5.92, 5671976ac83584dd02fccbf50a12a540 INIT, 0x1B1600, 0x5796, 0x5800, 6.69, 9b4e3f1b0030a9ab80ce4ddf34a0c433 .rsrc, 0x1B6E00, 0x2218, 0x2280, 3.51, cb144bba3079cc1b5ef908fcdb431281 .reloc, 0x1B9080, 0xCCB0, 0xCD00, 6.76, 48a9aaa62129060e61190c216d455c9a [[ 4 import(s) ]] Dxapi.sys: _DxApiGetVersion@0 HAL.dll: ExAcquireFastMutex, ExReleaseFastMutex, KeQueryPerformanceCounter ntoskrnl.exe: PsSetProcessWin32Process, PsGetProcessWin32Process, ExAcquireFastMutexUnsafe, KeEnterCriticalRegion, PsGetCurrentProcessId, PsSetThreadWin32Thread, KeTickCount, ExReleaseFastMutexUnsafe, KeLeaveCriticalRegion, ObfDereferenceObject, ObfReferenceObject, RtlNtStatusToDosError, strchr, strncpy, KeAreApcsDisabled, ExAllocatePoolWithTagPriority, RtlRandom, MmIsVerifierEnabled, PsGetCurrentThread, KeBugCheckEx, PsGetCurrentProcess, ProbeForWrite, _except_handler3, ExRaiseAccessViolation, SeReleaseSecurityDescriptor, SeCaptureSecurityDescriptor, RtlInitUnicodeString, swprintf, _wcsicmp, ExRaiseDatatypeMisalignment, ObReferenceObjectByHandle, PsGetProcessSessionId, PsProcessType, ExAcquireResourceExclusiveLite, ExReleaseResourceLite, ExRaiseStatus, ObCloseHandle, InterlockedExchange, RtlAreAnyAccessesGranted, memmove, PsGetJobUIRestrictionsClass, PsGetJobLock, PsJobType, wcsncpy, RtlIntegerToUnicode, RtlIntegerToUnicodeString, PsGetThreadId, PsGetThreadProcessId, PsDereferenceImpersonationToken, PsDereferencePrimaryToken, SeTokenType, SeCreateClientSecurity, wcslen, ObOpenObjectByPointer, ExDesktopObjectType, RtlCopyUnicodeString, KeInitializeEvent, ExFreePoolWithTag, ExInitializeResourceLite, ExAllocatePoolWithTag, ZwCreateDirectoryObject, RtlUnicodeStringToInteger, wcschr, wcsstr, MmMapViewOfSection, MmCreateSection, MmMapViewInSessionSpace, MmUnmapViewInSessionSpace, RtlAllocateHeap, ZwSetSystemInformation, NlsMbCodePageTag, NlsAnsiCodePage, PsGetThreadProcess, PsIsSystemThread, PsGetProcessJob, wcscpy, RtlGetNtGlobalFlags, RtlCheckRegistryKey, ExWindowStationObjectType, PsGetCurrentProcessSessionId, PsGetProcessWin32WindowStation, RtlCompareUnicodeString, ZwQueryDefaultLocale, PsGetProcessPeb, InterlockedPopEntrySList, InterlockedPushEntrySList, PsGetProcessCreateTimeQuadPart, KeQuerySystemTime, KeClearEvent, RtlFreeHeap, PsLookupProcessByProcessId, PsGetThreadSessionId, PsLookupThreadByThreadId, ExDeletePagedLookasideList, ExIsResourceAcquiredExclusiveLite, ExInitializePagedLookasideList, KeWaitForMultipleObjects, KeWaitForSingleObject, _allmul, KeSetEvent, PsIsThreadTerminating, ZwClose, ExEventObjectType, ZwCreateEvent, ObReferenceObjectByPointer, RtlAnsiStringToUnicodeString, RtlInitAnsiString, PsGetProcessImageFileName, PsThreadType, SeQueryAuthenticationIdToken, PsReferencePrimaryToken, PsGetProcessInheritedFromUniqueProcessId, PsSetProcessWindowStation, RtlInitializeBitMap, PsGetProcessId, PsGetProcessExitStatus, PsGetProcessExitProcessCalled, ZwQueryInformationProcess, KeSetKernelStackSwapEnable, SeTokenIsWriteRestricted, PsGetProcessSectionBaseAddress, ZwTerminateProcess, ExRaiseHardError, RtlWalkFrameChain, ExAllocatePoolWithQuotaTag, DbgBreakPoint, DbgPrint, KdDebuggerEnabled, ZwQueryValueKey, ZwOpenKey, RtlDestroyHeap, _wcsnicmp, wcscat, KeDelayExecutionThread, InterlockedDecrement, NtQueryInformationProcess, RtlDestroyAtomTable, ExDeleteResourceLite, KeCancelTimer, KeRemoveSystemServiceTable, KeQueryInterruptTime, MmPageEntireDriver, MmUserProbeAddress, PsEstablishWin32Callouts, KeAddSystemServiceTable, ZwQueryDefaultUILanguage, ZwSetDefaultUILanguage, ZwSetDefaultLocale, ExIsResourceAcquiredSharedLite, ExAcquireResourceSharedLite, RtlQueryRegistryValues, ZwPowerInformation, KeResetEvent, ZwDeviceIoControlFile, IoGetRelatedDeviceObject, KeInitializeTimerEx, PsGetCurrentThreadId, InitSafeBootMode, RtlAreAllAccessesGranted, SeDeleteAccessState, ObCheckObjectAccess, SeCreateAccessState, SeReleaseSubjectContext, SeUnlockSubjectContext, SePrivilegeObjectAuditAlarm, SePrivilegeCheck, SeLockSubjectContext, SeCaptureSubjectContext, RtlCopySid, RtlLengthSid, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlAddAce, RtlCreateAcl, RtlCreateSecurityDescriptor, SeExports, ZwFreeVirtualMemory, ZwAllocateVirtualMemory, ZwQueryInformationToken, RtlEqualUnicodeString, ZwSetInformationObject, ZwQueryObject, ObCreateObject, KeUnstackDetachProcess, KeStackAttachProcess, ZwDuplicateObject, ObFindHandleForObject, RtlClearBits, RtlSetBits, ZwSetSecurityObject, RtlInitializeSid, RtlSubAuthoritySid, RtlLengthRequiredSid, RtlMapGenericMask, ObReleaseObjectSecurity, ObAssignSecurity, ObGetObjectSecurity, ObCheckCreateObjectAccess, MmUnmapViewOfSection, ObOpenObjectByName, PsGetThreadTeb, KeDetachProcess, KeAttachProcess, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, KePulseEvent, ObQueryNameString, ZwOpenEvent, ZwSetInformationThread, RtlPinAtomInAtomTable, RtlAddAtomToAtomTable, RtlCreateAtomTable, ExReleaseRundownProtection, LpcRequestWaitReplyPort, SeDeassignSecurity, ObSetSecurityDescriptorInfo, SeAssignSecurity, ObInsertObject, ZwOpenDirectoryObject, ExAcquireRundownProtection, ZwOpenProcessTokenEx, ZwOpenThreadTokenEx, PsReferenceImpersonationToken, SeQueryInformationToken, SeTokenIsRestricted, PsCreateSystemThread, ObSetHandleAttributes, PsGetProcessDebugPort, ZwYieldExecution, RtlIntegerToChar, RtlUnicodeStringToAnsiString, PsSetProcessPriorityByClass, PsSetProcessPriorityClass, PsGetProcessPriorityClass, KeSetPriorityThread, RtlUnicodeToMultiByteN, SeImpersonateClientEx, MmAdjustWorkingSetSize, KeSetTimer, RtlFreeUnicodeString, RtlFormatCurrentUserKeyPath, ZwQueryKey, ZwEnumerateValueKey, ZwSetValueKey, RtlMultiByteToUnicodeN, RtlFindMessage, wcsrchr, RtlEqualString, strrchr, ExGetSharedWaiterCount, ExGetExclusiveWaiterCount, IoQueryDeviceDescription, ExRundownCompleted, ExWaitForRundownProtectionRelease, ZwSetEvent, PoSetSystemState, PoRequestShutdownEvent, KeInitializeTimer, NlsOemCodePage, RtlLookupAtomInAtomTable, RtlDeleteAtomFromAtomTable, RtlQueryAtomInAtomTable, ZwUnmapViewOfSection, ZwMapViewOfSection, ZwCreateSection, PsGetThreadFreezeCount, InterlockedIncrement, RtlUnicodeToMultiByteSize, RtlMultiByteToUnicodeSize, KeUserModeCallback, MmSystemRangeStart, IoFileObjectType, ZwOpenFile, IofCallDriver, IoBuildSynchronousFsdRequest, IoBuildDeviceIoControlRequest, IoWriteErrorLogEntry, IoAllocateErrorLogEntry, IoGetStackLimits, MmCommitSessionMappedView, RtlCreateHeap, IoUnregisterPlugPlayNotification, IoWMIQuerySingleInstance, IoWMIHandleToInstanceName, IoWMIOpenBlock, ZwCreateFile, ZwCancelIoFile, wcsncmp, IoGetDeviceObjectPointer, IoRegisterPlugPlayNotification, ZwReadFile, ObReferenceObjectByName, IoDriverObjectType, IoCreateDriver, IoPnPDeliverServicePowerNotification, IoInvalidateDeviceRelations, LpcRequestPort, KeIsAttachedProcess, RtlEmptyAtomTable, RtlZeroHeap, _alldiv, _allshr, vsprintf, MmSecureVirtualMemory, KeRestoreFloatingPointState, KeSaveFloatingPointState, ZwQuerySystemInformation, ExSystemTimeToLocalTime, InterlockedCompareExchange, MmUnsecureVirtualMemory, RtlInsertElementGenericTableAvl, RtlDeleteElementGenericTableAvl, RtlLookupElementGenericTableAvl, KeInitializeDpc, ExIsProcessorFeaturePresent, RtlFillMemoryUlong, RtlTimeToTimeFields, MmGrowKernelStack, PsGetCurrentThreadStackBase, ExSystemExceptionFilter, KeReadStateEvent, ZwQueryInformationFile, LdrAccessResource, LdrFindResource_U, RtlUnicodeToCustomCPN, RtlCustomCPToUnicodeN, RtlInitCodePageTable, RtlGetDefaultCodePage, ZwDeleteFile, LdrFindResourceDirectory_U, RtlEqualSid, MmHighestUserAddress, PsRevertToSelf, RtlUnicodeToOemN, ZwCreateKey, RtlFreeAnsiString, RtlImageNtHeader, RtlImageDirectoryEntryToData, _strnicmp, PsSetThreadHardErrorsAreDisabled, PsGetThreadHardErrorsAreDisabled, strncmp, toupper, RtlWriteRegistryValue, ZwEnumerateKey, IoOpenDeviceRegistryKey, wcscmp, IoGetDeviceProperty, ZwDeleteKey, IoOpenDeviceInterfaceRegistryKey, IoGetDeviceInterfaces, IoSynchronousInvalidateDeviceRelations, IoCreateFile, MmSectionObjectType, ZwSetInformationFile, ZwQueryVolumeInformationFile, IoSetThreadHardErrorMode, _alldvrm, _aulldiv, PsGetCurrentThreadPreviousMode, RtlCompareMemory, RtlCreateRegistryKey, MmQuerySystemSize, RtlEnumerateGenericTableAvl, RtlInitializeGenericTableAvl, PsTerminateSystemThread, RtlUpcaseUnicodeString, RtlExtendedLargeIntegerDivide, _aulldvrm, IoQueueThreadIrp, IoBuildAsynchronousFsdRequest, qsort, MmAddVerifierThunks, PsGetThreadWin32Thread watchdog.sys: WdDdiWatchdogDpcCallback, WdResumeDeferredWatch, WdSuspendDeferredWatch, WdAllocateDeferredWatchdog, WdStartDeferredWatch, WdStopDeferredWatch, WdFreeDeferredWatchdog, WdExitMonitoredSection, WdEnterMonitoredSection [[ 225 export(s) ]] BRUSHOBJ_hGetColorTransform, BRUSHOBJ_pvAllocRbrush, BRUSHOBJ_pvGetRbrush, BRUSHOBJ_ulGetBrushColor, CLIPOBJ_bEnum, CLIPOBJ_cEnumStart, CLIPOBJ_ppoGetPath, EngAcquireSemaphore, EngAllocMem, EngAllocPrivateUserMem, EngAllocSectionMem, EngAllocUserMem, EngAlphaBlend, EngAssociateSurface, EngBitBlt, EngBugCheckEx, EngCheckAbort, EngClearEvent, EngComputeGlyphSet, EngControlSprites, EngCopyBits, EngCreateBitmap, EngCreateClip, EngCreateDeviceBitmap, EngCreateDeviceSurface, EngCreateDriverObj, EngCreateEvent, EngCreatePalette, EngCreatePath, EngCreateSemaphore, EngCreateWnd, EngDebugBreak, EngDebugPrint, EngDeleteClip, EngDeleteDriverObj, EngDeleteEvent, EngDeleteFile, EngDeletePalette, EngDeletePath, EngDeleteSafeSemaphore, EngDeleteSemaphore, EngDeleteSurface, EngDeleteWnd, EngDeviceIoControl, EngDitherColor, EngDxIoctl, EngEnumForms, EngEraseSurface, EngFileIoControl, EngFileWrite, EngFillPath, EngFindImageProcAddress, EngFindResource, EngFntCacheAlloc, EngFntCacheFault, EngFntCacheLookUp, EngFreeMem, EngFreeModule, EngFreePrivateUserMem, EngFreeSectionMem, EngFreeUserMem, EngGetCurrentCodePage, EngGetCurrentProcessId, EngGetCurrentThreadId, EngGetDriverName, EngGetFileChangeTime, EngGetFilePath, EngGetForm, EngGetLastError, EngGetPrinter, EngGetPrinterData, EngGetPrinterDataFileName, EngGetPrinterDriver, EngGetProcessHandle, EngGetTickCount, EngGetType1FontList, EngGradientFill, EngHangNotification, EngInitializeSafeSemaphore, EngIsSemaphoreOwned, EngIsSemaphoreOwnedByCurrentThread, EngLineTo, EngLoadImage, EngLoadModule, EngLoadModuleForWrite, EngLockDirectDrawSurface, EngLockDriverObj, EngLockSurface, EngLpkInstalled, EngMapEvent, EngMapFile, EngMapFontFile, EngMapFontFileFD, EngMapModule, EngMapSection, EngMarkBandingSurface, EngModifySurface, EngMovePointer, EngMulDiv, EngMultiByteToUnicodeN, EngMultiByteToWideChar, EngNineGrid, EngPaint, EngPlgBlt, EngProbeForRead, EngProbeForReadAndWrite, EngQueryDeviceAttribute, EngQueryLocalTime, EngQueryPalette, EngQueryPerformanceCounter, EngQueryPerformanceFrequency, EngQuerySystemAttribute, EngReadStateEvent, EngReleaseSemaphore, EngRestoreFloatingPointState, EngSaveFloatingPointState, EngSecureMem, EngSetEvent, EngSetLastError, EngSetPointerShape, EngSetPointerTag, EngSetPrinterData, EngSort, EngStretchBlt, EngStretchBltROP, EngStrokeAndFillPath, EngStrokePath, EngTextOut, EngTransparentBlt, EngUnicodeToMultiByteN, EngUnloadImage, EngUnlockDirectDrawSurface, EngUnlockDriverObj, EngUnlockSurface, EngUnmapEvent, EngUnmapFile, EngUnmapFontFile, EngUnmapFontFileFD, EngUnsecureMem, EngWaitForSingleObject, EngWideCharToMultiByte, EngWritePrinter, FLOATOBJ_Add, FLOATOBJ_AddFloat, FLOATOBJ_AddFloatObj, FLOATOBJ_AddLong, FLOATOBJ_Div, FLOATOBJ_DivFloat, FLOATOBJ_DivFloatObj, FLOATOBJ_DivLong, FLOATOBJ_Equal, FLOATOBJ_EqualLong, FLOATOBJ_GetFloat, FLOATOBJ_GetLong, FLOATOBJ_GreaterThan, FLOATOBJ_GreaterThanLong, FLOATOBJ_LessThan, FLOATOBJ_LessThanLong, FLOATOBJ_Mul, FLOATOBJ_MulFloat, FLOATOBJ_MulFloatObj, FLOATOBJ_MulLong, FLOATOBJ_Neg, FLOATOBJ_SetFloat, FLOATOBJ_SetLong, FLOATOBJ_Sub, FLOATOBJ_SubFloat, FLOATOBJ_SubFloatObj, FLOATOBJ_SubLong, FONTOBJ_cGetAllGlyphHandles, FONTOBJ_cGetGlyphs, FONTOBJ_pQueryGlyphAttrs, FONTOBJ_pfdg, FONTOBJ_pifi, FONTOBJ_pjOpenTypeTablePointer, FONTOBJ_pvTrueTypeFontFile, FONTOBJ_pwszFontFilePaths, FONTOBJ_pxoGetXform, FONTOBJ_vGetInfo, HT_ComputeRGBGammaTable, HT_Get8BPPFormatPalette, HT_Get8BPPMaskPalette, HeapVidMemAllocAligned, PALOBJ_cGetColors, PATHOBJ_bCloseFigure, PATHOBJ_bEnum, PATHOBJ_bEnumClipLines, PATHOBJ_bMoveTo, PATHOBJ_bPolyBezierTo, PATHOBJ_bPolyLineTo, PATHOBJ_vEnumStart, PATHOBJ_vEnumStartClipLines, PATHOBJ_vGetBounds, RtlAnsiCharToUnicodeChar, RtlMultiByteToUnicodeN, RtlRaiseException, RtlUnicodeToMultiByteN, RtlUnicodeToMultiByteSize, RtlUnwind, RtlUpcaseUnicodeChar, RtlUpcaseUnicodeToMultiByteN, STROBJ_bEnum, STROBJ_bEnumPositionsOnly, STROBJ_bGetAdvanceWidths, STROBJ_dwGetCodePage, STROBJ_fxBreakExtra, STROBJ_fxCharacterExtra, STROBJ_vEnumStart, VidMemFree, WNDOBJ_bEnum, WNDOBJ_cEnumStart, WNDOBJ_vSetConsumer, XFORMOBJ_bApplyXform, XFORMOBJ_iGetFloatObjXform, XFORMOBJ_iGetXform, XLATEOBJ_cGetPalette, XLATEOBJ_hGetColorTransform, XLATEOBJ_iXlate, XLATEOBJ_piVector, _abnormal_termination, _except_handler2, _global_unwind2, _itoa, _itow, _local_unwind2 ExifTool: file metadata CharacterSet: Unicode CodeSize: 1658624 CompanyName: Microsoft Corporation EntryPoint: 0x1b2f7f FileDescription: Multi-User Win32 Driver FileFlagsMask: 0x003f FileOS: Windows NT 32-bit FileSize: 1815 kB FileSubtype: 7 FileType: Win32 EXE FileVersion: 5.1.2600.6149 (xpsp_sp3_gdr.110906-1620) FileVersionNumber: 5.1.2600.6149 ImageVersion: 5.1 InitializedDataSize: 199424 InternalName: win32k.sys LanguageCode: English (U.S.) LegalCopyright: Microsoft Corporation. All rights reserved. LinkerVersion: 7.1 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 5.1 ObjectFileType: Driver OriginalFilename: win32k.sys PEType: PE32 ProductName: Microsoft Windows Operating System ProductVersion: 5.1.2600.6149 ProductVersionNumber: 5.1.2600.6149 Subsystem: Native SubsystemVersion: 5.1 TimeStamp: 2011:09:06 15:20:41+02:00 UninitializedDataSize: 0 VT Community 0 This file has never been reviewed by any VT Community member. Be the first one to comment on it! VirusTotal Team
I did the other one too just in case: Filename: win32k.sys Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Fri 28 Oct 2011 23:18:14 (CET) Permalink
That file looks fine, I am sure it was but better to be safe than sorry.

See if you can run this free online virus scanner, you would have to boot to safemode with networking


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
That ESET scan can run in less than an hour on some systems and I have seen it run all afternoon on others. How are things running now, any better, if not explain to me in detail exactly what your experiencing
Well, I can only run the computer in Safe Mode with Networking… When i allow the computer to boot up normally, everything seems to startup fine and my wallpaper shows up but no icons, and then it just stays that way forever. I can move the mouse cursor around, but the rest of windows just never shows up. So really, the computer just wont load up…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI