This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
It would appear that my system has been infected. The response time is very slow, for instance I could not install OTL or Hijack This. It just so happened I had a previous version installed on my system and the below log file is from this version.

Hopefully someone will be able to assist?


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:51:52, on 04/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17103)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Disk Speedup\DSUDefragSrv.exe
G:\Program Files\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\chic\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\BarLcher.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program Files\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - G:\Program Files\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Xvid] G:\Program Files\XviD\CheckUpdate.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
O23 - Service: DSUDiskOptimizer - Systweak Inc., (www.systweak.com) - C:\Program Files\Disk Speedup\DSUDefragSrv.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - G:\Program Files\bin\jqs.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 9098 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)








Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi Mowman,
Thanks for taking the time to respond, it is appreciated.
Can I first of all say that I have already removed uTorrent (prob. the cause of the infection) using RevoUninstaller and run MalwareBytes (which found 15 infections (12 in the registry)).
The PC is running much better than when I first posted.

Below are the results you requested - I hope they help.

TDSSKiller.

05:38:02.0312 3944 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
05:38:02.0703 3944 ============================================================
05:38:02.0703 3944 Current date / time: 2011/12/06 05:38:02.0703
05:38:02.0703 3944 SystemInfo:
05:38:02.0703 3944
05:38:02.0703 3944 OS Version: 5.1.2600 ServicePack: 3.0
05:38:02.0703 3944 Product type: Workstation
05:38:02.0703 3944 ComputerName: CHICPC
05:38:02.0703 3944 UserName: chic
05:38:02.0703 3944 Windows directory: C:\WINDOWS
05:38:02.0703 3944 System windows directory: C:\WINDOWS
05:38:02.0703 3944 Processor architecture: Intel x86
05:38:02.0703 3944 Number of processors: 2
05:38:02.0703 3944 Page size: 0x1000
05:38:02.0703 3944 Boot type: Normal boot
05:38:02.0703 3944 ============================================================
05:38:04.0656 3944 Initialize success
05:38:30.0953 0552 ============================================================
05:38:30.0953 0552 Scan started
05:38:30.0953 0552 Mode: Manual;
05:38:30.0953 0552 ============================================================
05:38:31.0875 0552 100D - ok
05:38:31.0890 0552 1083 - ok
05:38:31.0906 0552 117F - ok
05:38:31.0921 0552 1202A - ok
05:38:31.0937 0552 12032 - ok
05:38:31.0953 0552 12115 - ok
05:38:31.0968 0552 1484 - ok
05:38:31.0968 0552 148D - ok
05:38:31.0984 0552 16017 - ok
05:38:32.0000 0552 16130 - ok
05:38:32.0015 0552 1613F - ok
05:38:32.0031 0552 1643 - ok
05:38:32.0031 0552 1655 - ok
05:38:32.0046 0552 165D - ok
05:38:32.0062 0552 1703C - ok
05:38:32.0078 0552 1803 - ok
05:38:32.0093 0552 1844 - ok
05:38:32.0109 0552 19310 - ok
05:38:32.0109 0552 19336 - ok
05:38:32.0125 0552 1964 - ok
05:38:32.0140 0552 2004 - ok
05:38:32.0156 0552 2993 - ok
05:38:32.0171 0552 4363 - ok
05:38:32.0187 0552 4481D - ok
05:38:32.0203 0552 48426 - ok
05:38:32.0218 0552 5834 - ok
05:38:32.0218 0552 6064 - ok
05:38:32.0234 0552 6824 - ok
05:38:32.0250 0552 725F - ok
05:38:32.0265 0552 73513 - ok
05:38:32.0281 0552 735E - ok
05:38:32.0296 0552 74636 - ok
05:38:32.0312 0552 78928 - ok
05:38:32.0328 0552 79612 - ok
05:38:32.0328 0552 82311 - ok
05:38:32.0343 0552 Abiosdsk - ok
05:38:32.0390 0552 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
05:38:32.0390 0552 abp480n5 - ok
05:38:32.0453 0552 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
05:38:32.0453 0552 ACPI - ok
05:38:32.0500 0552 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
05:38:32.0500 0552 ACPIEC - ok
05:38:32.0531 0552 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
05:38:32.0531 0552 adpu160m - ok
05:38:32.0593 0552 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
05:38:32.0593 0552 aec - ok
05:38:32.0671 0552 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
05:38:32.0687 0552 AFD - ok
05:38:32.0750 0552 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
05:38:32.0750 0552 agp440 - ok
05:38:32.0765 0552 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
05:38:32.0765 0552 agpCPQ - ok
05:38:32.0843 0552 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
05:38:32.0843 0552 Aha154x - ok
05:38:32.0906 0552 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
05:38:32.0906 0552 aic78u2 - ok
05:38:32.0937 0552 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
05:38:32.0937 0552 aic78xx - ok
05:38:33.0140 0552 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
05:38:33.0156 0552 AliIde - ok
05:38:33.0250 0552 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
05:38:33.0250 0552 alim1541 - ok
05:38:33.0312 0552 ambitucm (accd572170dc70138027ea2d519c77c4) C:\WINDOWS\system32\DRIVERS\ambitucm.sys
05:38:33.0328 0552 ambitucm - ok
05:38:33.0343 0552 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
05:38:33.0343 0552 amdagp - ok
05:38:33.0375 0552 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
05:38:33.0375 0552 amsint - ok
05:38:33.0421 0552 Andbus (3e59df4984fbd6800d6621480b38a34e) C:\WINDOWS\system32\DRIVERS\lgandbus.sys
05:38:33.0437 0552 Andbus - ok
05:38:33.0468 0552 AndDiag (8e0bf6f3b2c9c292bc7ce0de727cdd56) C:\WINDOWS\system32\DRIVERS\lganddiag.sys
05:38:33.0468 0552 AndDiag - ok
05:38:33.0484 0552 AndGps (1d2c90e25483363d54b652898bbc8f2a) C:\WINDOWS\system32\DRIVERS\lgandgps.sys
05:38:33.0484 0552 AndGps - ok
05:38:33.0500 0552 ANDModem (b1b06a95da2cac7fa19832c60c348c85) C:\WINDOWS\system32\DRIVERS\lgandmodem.sys
05:38:33.0500 0552 ANDModem - ok
05:38:33.0531 0552 AndNetDiag (e82d3f882dcb594b100827523c2d5c70) C:\WINDOWS\system32\DRIVERS\lgandnetdiag.sys
05:38:33.0531 0552 AndNetDiag - ok
05:38:33.0578 0552 AndNetGps (88175c5db95eeb6de8f46f8089c5d755) C:\WINDOWS\system32\DRIVERS\lgandnetgps.sys
05:38:33.0578 0552 AndNetGps - ok
05:38:33.0593 0552 ANDNetModem (398222fb93404883f573f8a01241cd25) C:\WINDOWS\system32\DRIVERS\lgandnetmodem.sys
05:38:33.0593 0552 ANDNetModem - ok
05:38:33.0640 0552 andnetndis (05318079baa15f42d889fa90cb39181e) C:\WINDOWS\system32\DRIVERS\lgandnetndis.sys
05:38:33.0640 0552 andnetndis - ok
05:38:33.0687 0552 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
05:38:33.0687 0552 asc - ok
05:38:33.0718 0552 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
05:38:33.0718 0552 asc3350p - ok
05:38:33.0750 0552 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
05:38:33.0750 0552 asc3550 - ok
05:38:33.0812 0552 ASPI (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\System32\DRIVERS\ASPI32.sys
05:38:33.0812 0552 ASPI - ok
05:38:33.0828 0552 ASPI32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys
05:38:33.0828 0552 ASPI32 - ok
05:38:33.0890 0552 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
05:38:33.0890 0552 AsyncMac - ok
05:38:33.0953 0552 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
05:38:33.0953 0552 atapi - ok
05:38:33.0968 0552 Atdisk - ok
05:38:34.0062 0552 ati2mtag (03621f7f968ff63713943405deb777f9) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
05:38:34.0078 0552 ati2mtag - ok
05:38:34.0140 0552 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
05:38:34.0140 0552 Atmarpc - ok
05:38:34.0171 0552 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
05:38:34.0171 0552 audstub - ok
05:38:34.0250 0552 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
05:38:34.0250 0552 Beep - ok
05:38:34.0296 0552 BlueletAudio (04e84c8049ee93614a2ff6d676d1e247) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
05:38:34.0296 0552 BlueletAudio - ok
05:38:34.0359 0552 BT (d1813668a0117ae05bc0b81c874f91d4) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
05:38:34.0375 0552 BT - ok
05:38:34.0406 0552 BTHidEnum (161969d2dd1d39cd2f1edbc60c61fa99) C:\WINDOWS\system32\DRIVERS\vbtenum.sys
05:38:34.0437 0552 BTHidEnum - ok
05:38:34.0468 0552 BTHidMgr (a9164c2a39bd917b9f42ae087560ac3d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
05:38:34.0468 0552 BTHidMgr - ok
05:38:34.0531 0552 Ca536av (2fec2e18aff42ff28189410d244d3f03) C:\WINDOWS\system32\Drivers\Ca536av.sys
05:38:34.0546 0552 Ca536av - ok
05:38:34.0578 0552 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
05:38:34.0578 0552 cbidf - ok
05:38:34.0593 0552 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
05:38:34.0593 0552 cbidf2k - ok
05:38:34.0640 0552 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
05:38:34.0640 0552 CCDECODE - ok
05:38:34.0656 0552 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
05:38:34.0671 0552 cd20xrnt - ok
05:38:34.0671 0552 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
05:38:34.0687 0552 Cdaudio - ok
05:38:34.0703 0552 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
05:38:34.0703 0552 Cdfs - ok
05:38:34.0718 0552 Cdr4_2K - ok
05:38:34.0781 0552 Cdralw2k (2c41cd49d82d5fd85c72d57b6ca25471) C:\WINDOWS\system32\drivers\Cdralw2k.sys
05:38:34.0781 0552 Cdralw2k - ok
05:38:34.0812 0552 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
05:38:34.0812 0552 Cdrom - ok
05:38:34.0828 0552 Changer - ok
05:38:34.0921 0552 cmdGuard (dd530ee7d9efbb0ec42aebe7226b8a93) C:\WINDOWS\system32\DRIVERS\cmdguard.sys
05:38:34.0921 0552 cmdGuard - ok
05:38:34.0937 0552 cmdHlp (07cbbe993ed08a52dafac1e6cf27b6a5) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
05:38:34.0937 0552 cmdHlp - ok
05:38:34.0984 0552 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
05:38:34.0984 0552 CmdIde - ok
05:38:35.0015 0552 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
05:38:35.0015 0552 Cpqarray - ok
05:38:35.0093 0552 ctsfm2k (b459ae4afca570088adddbe55eabbc92) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys
05:38:35.0093 0552 ctsfm2k - ok
05:38:35.0140 0552 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
05:38:35.0140 0552 dac2w2k - ok
05:38:35.0171 0552 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
05:38:35.0171 0552 dac960nt - ok
05:38:35.0234 0552 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
05:38:35.0234 0552 Disk - ok
05:38:35.0296 0552 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
05:38:35.0312 0552 dmboot - ok
05:38:35.0343 0552 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
05:38:35.0343 0552 dmio - ok
05:38:35.0359 0552 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
05:38:35.0359 0552 dmload - ok
05:38:35.0406 0552 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
05:38:35.0421 0552 DMusic - ok
05:38:35.0468 0552 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
05:38:35.0468 0552 dpti2o - ok
05:38:35.0531 0552 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
05:38:35.0531 0552 drmkaud - ok
05:38:35.0593 0552 DTV_Capture_2X0 (5ad19fd45820173e094194c1e6f719ef) C:\WINDOWS\system32\Drivers\DTV_Capture_2X0.sys
05:38:35.0609 0552 DTV_Capture_2X0 - ok
05:38:35.0625 0552 DTV_Loader_2X1 (cca7bad75040e7521597a22e3c95af12) C:\WINDOWS\system32\Drivers\DTV_Loader_2X1.sys
05:38:35.0640 0552 DTV_Loader_2X1 - ok
05:38:35.0703 0552 E100B (d57a8fc800b501ac05b10d00f66d127a) C:\WINDOWS\system32\DRIVERS\e100b325.sys
05:38:35.0703 0552 E100B - ok
05:38:35.0781 0552 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
05:38:35.0781 0552 Fastfat - ok
05:38:35.0828 0552 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
05:38:35.0828 0552 Fdc - ok
05:38:35.0859 0552 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
05:38:35.0875 0552 Fips - ok
05:38:35.0906 0552 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
05:38:35.0906 0552 Flpydisk - ok
05:38:35.0968 0552 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
05:38:35.0968 0552 FltMgr - ok
05:38:36.0031 0552 fssfltr (960f5e5e4e1f720465311ac68a99c2df) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
05:38:36.0031 0552 fssfltr - ok
05:38:36.0093 0552 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS
05:38:36.0125 0552 FsUsbExDisk - ok
05:38:36.0171 0552 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
05:38:36.0171 0552 Fs_Rec - ok
05:38:36.0203 0552 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
05:38:36.0203 0552 Ftdisk - ok
05:38:36.0281 0552 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
05:38:36.0281 0552 GEARAspiWDM - ok
05:38:36.0359 0552 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
05:38:36.0359 0552 Gpc - ok
05:38:36.0437 0552 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
05:38:36.0437 0552 HDAudBus - ok
05:38:36.0515 0552 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
05:38:36.0515 0552 HidUsb - ok
05:38:36.0562 0552 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
05:38:36.0562 0552 hpn - ok
05:38:36.0625 0552 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
05:38:36.0625 0552 HTTP - ok
05:38:36.0656 0552 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
05:38:36.0656 0552 i2omgmt - ok
05:38:36.0687 0552 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
05:38:36.0687 0552 i2omp - ok
05:38:36.0750 0552 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
05:38:36.0750 0552 i8042prt - ok
05:38:36.0796 0552 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
05:38:36.0796 0552 Imapi - ok
05:38:36.0859 0552 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
05:38:36.0859 0552 ini910u - ok
05:38:36.0968 0552 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
05:38:36.0968 0552 IntelC51 - ok
05:38:37.0015 0552 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
05:38:37.0015 0552 IntelC52 - ok
05:38:37.0062 0552 IntelC53 (cf0b937710cec6ef39416edecd803cbb) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
05:38:37.0062 0552 IntelC53 - ok
05:38:37.0093 0552 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
05:38:37.0093 0552 IntelIde - ok
05:38:37.0156 0552 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
05:38:37.0171 0552 intelppm - ok
05:38:37.0234 0552 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
05:38:37.0234 0552 Ip6Fw - ok
05:38:37.0265 0552 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
05:38:37.0265 0552 IpInIp - ok
05:38:37.0359 0552 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
05:38:37.0359 0552 IpNat - ok
05:38:37.0390 0552 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
05:38:37.0390 0552 IPSec - ok
05:38:37.0437 0552 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
05:38:37.0437 0552 IRENUM - ok
05:38:37.0515 0552 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
05:38:37.0515 0552 isapnp - ok
05:38:37.0562 0552 k600bus (53d606019bb0f0c6b3e6ec9d2e0f7622) C:\WINDOWS\system32\DRIVERS\k600bus.sys
05:38:37.0593 0552 k600bus - ok
05:38:37.0609 0552 k600mdfl (c0d81f66557847bbb7f5b9980bc2ea2e) C:\WINDOWS\system32\DRIVERS\k600mdfl.sys
05:38:37.0625 0552 k600mdfl - ok
05:38:37.0671 0552 k600mdm (646900b2921bad4757b427d2d328ec96) C:\WINDOWS\system32\DRIVERS\k600mdm.sys
05:38:37.0718 0552 k600mdm - ok
05:38:37.0765 0552 k600mgmt (3990320cfef38b038c012029257e2300) C:\WINDOWS\system32\DRIVERS\k600mgmt.sys
05:38:37.0796 0552 k600mgmt - ok
05:38:37.0828 0552 k600obex (1578cb8176d08cc4d3dbe094c62fc236) C:\WINDOWS\system32\DRIVERS\k600obex.sys
05:38:37.0875 0552 k600obex - ok
05:38:37.0906 0552 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
05:38:37.0906 0552 Kbdclass - ok
05:38:37.0937 0552 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
05:38:37.0937 0552 kbdhid - ok
05:38:37.0984 0552 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
05:38:37.0984 0552 kmixer - ok
05:38:38.0031 0552 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
05:38:38.0046 0552 KSecDD - ok
05:38:38.0078 0552 lbrtfdc - ok
05:38:38.0140 0552 LgBttPort (4dd47b5af0b24871ebb9efc012a7474e) C:\WINDOWS\system32\DRIVERS\lgbtport.sys
05:38:38.0140 0552 LgBttPort - ok
05:38:38.0171 0552 lgbusenum (1d038ca6c529203087a990e5e97887b4) C:\WINDOWS\system32\DRIVERS\lgbtbus.sys
05:38:38.0187 0552 lgbusenum - ok
05:38:38.0203 0552 LGVMODEM (26f1976a330195d62a6224c76968cf0d) C:\WINDOWS\system32\DRIVERS\lgvmodem.sys
05:38:38.0203 0552 LGVMODEM - ok
05:38:38.0234 0552 ManyCam - ok
05:38:38.0265 0552 MBAMSwissArmy - ok
05:38:38.0312 0552 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
05:38:38.0312 0552 mnmdd - ok
05:38:38.0390 0552 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
05:38:38.0390 0552 Modem - ok
05:38:38.0406 0552 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
05:38:38.0406 0552 MODEMCSA - ok
05:38:38.0453 0552 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
05:38:38.0468 0552 mohfilt - ok
05:38:38.0484 0552 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
05:38:38.0484 0552 Mouclass - ok
05:38:38.0531 0552 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
05:38:38.0546 0552 mouhid - ok
05:38:38.0562 0552 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
05:38:38.0562 0552 MountMgr - ok
05:38:38.0625 0552 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
05:38:38.0625 0552 MpFilter - ok
05:38:38.0718 0552 MpKsl38748af2 - ok
05:38:38.0718 0552 MpKsl6717158e - ok
05:38:38.0734 0552 MpKsl994b83a1 - ok
05:38:38.0750 0552 MpKslc29337be - ok
05:38:38.0765 0552 MpKslc5913634 - ok
05:38:38.0859 0552 MpKslf43d82eb (a69630d039c38018689190234f866d77) C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F605BCDD-58C7-485C-8FD7-2A7E2E15BFE9}\MpKslf43d82eb.sys
05:38:38.0859 0552 MpKslf43d82eb - ok
05:38:38.0890 0552 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
05:38:38.0890 0552 mraid35x - ok
05:38:39.0015 0552 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
05:38:39.0015 0552 MREMP50 - ok
05:38:39.0031 0552 MREMPR5 - ok
05:38:39.0046 0552 MRENDIS5 - ok
05:38:39.0062 0552 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
05:38:39.0062 0552 MRESP50 - ok
05:38:39.0093 0552 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
05:38:39.0109 0552 MRxDAV - ok
05:38:39.0171 0552 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
05:38:39.0187 0552 MRxSmb - ok
05:38:39.0250 0552 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
05:38:39.0265 0552 Msfs - ok
05:38:39.0296 0552 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
05:38:39.0296 0552 MSKSSRV - ok
05:38:39.0328 0552 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
05:38:39.0343 0552 MSPCLOCK - ok
05:38:39.0375 0552 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
05:38:39.0375 0552 MSPQM - ok
05:38:39.0437 0552 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
05:38:39.0437 0552 mssmbios - ok
05:38:39.0484 0552 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
05:38:39.0484 0552 MSTEE - ok
05:38:39.0515 0552 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
05:38:39.0515 0552 Mup - ok
05:38:39.0562 0552 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
05:38:39.0562 0552 NABTSFEC - ok
05:38:39.0625 0552 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
05:38:39.0625 0552 NDIS - ok
05:38:39.0656 0552 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
05:38:39.0656 0552 NdisIP - ok
05:38:39.0734 0552 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
05:38:39.0734 0552 NdisTapi - ok
05:38:39.0812 0552 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
05:38:39.0812 0552 Ndisuio - ok
05:38:39.0828 0552 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
05:38:39.0828 0552 NdisWan - ok
05:38:39.0875 0552 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
05:38:39.0875 0552 NDProxy - ok
05:38:39.0906 0552 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
05:38:39.0906 0552 NetBIOS - ok
05:38:39.0937 0552 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
05:38:39.0953 0552 NetBT - ok
05:38:40.0078 0552 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\WINDOWS\system32\drivers\npf.sys
05:38:44.0375 0552 NPF - ok
05:38:44.0406 0552 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
05:38:44.0406 0552 Npfs - ok
05:38:44.0421 0552 ntcdrdrv - ok
05:38:44.0484 0552 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
05:38:44.0500 0552 Ntfs - ok
05:38:44.0546 0552 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
05:38:44.0546 0552 Null - ok
05:38:44.0656 0552 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
05:38:44.0687 0552 nv - ok
05:38:44.0765 0552 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
05:38:44.0765 0552 NwlnkFlt - ok
05:38:44.0796 0552 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
05:38:44.0796 0552 NwlnkFwd - ok
05:38:44.0890 0552 ossrv (c720c25b2d0c93dc425155f5b6a707f3) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys
05:38:44.0890 0552 ossrv - ok
05:38:44.0953 0552 P17 (3a7290f2c423b80ba95becae015b9b1b) C:\WINDOWS\system32\drivers\P17.sys
05:38:44.0968 0552 P17 - ok
05:38:45.0046 0552 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
05:38:45.0046 0552 Parport - ok
05:38:45.0093 0552 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
05:38:45.0093 0552 PartMgr - ok
05:38:45.0125 0552 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
05:38:45.0125 0552 ParVdm - ok
05:38:45.0203 0552 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
05:38:45.0218 0552 pccsmcfd - ok
05:38:45.0234 0552 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
05:38:45.0234 0552 PCI - ok
05:38:45.0250 0552 PCIDump - ok
05:38:45.0296 0552 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
05:38:45.0296 0552 PCIIde - ok
05:38:45.0343 0552 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
05:38:45.0343 0552 Pcmcia - ok
05:38:45.0406 0552 pcouffin (02aaafb7ba137ce5ddabcdf8090954d9) C:\WINDOWS\system32\Drivers\pcouffin.sys
05:38:45.0406 0552 pcouffin - ok
05:38:45.0421 0552 PDCOMP - ok
05:38:45.0453 0552 PDFRAME - ok
05:38:45.0468 0552 PDRELI - ok
05:38:45.0500 0552 PDRFRAME - ok
05:38:45.0546 0552 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
05:38:45.0546 0552 perc2 - ok
05:38:45.0578 0552 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
05:38:45.0578 0552 perc2hib - ok
05:38:45.0703 0552 PfModNT (c8a2d6ff660ac601b7bb9a9b16a5c25e) C:\WINDOWS\system32\drivers\PfModNT.sys
05:38:45.0703 0552 PfModNT - ok
05:38:45.0765 0552 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
05:38:45.0765 0552 PptpMiniport - ok
05:38:45.0812 0552 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
05:38:45.0812 0552 PSched - ok
05:38:45.0828 0552 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
05:38:45.0828 0552 Ptilink - ok
05:38:45.0875 0552 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
05:38:45.0875 0552 PxHelp20 - ok
05:38:45.0906 0552 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
05:38:45.0921 0552 ql1080 - ok
05:38:45.0937 0552 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
05:38:45.0937 0552 Ql10wnt - ok
05:38:45.0968 0552 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
05:38:45.0968 0552 ql12160 - ok
05:38:46.0000 0552 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
05:38:46.0000 0552 ql1240 - ok
05:38:46.0031 0552 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
05:38:46.0031 0552 ql1280 - ok
05:38:46.0062 0552 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
05:38:46.0078 0552 RasAcd - ok
05:38:46.0109 0552 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
05:38:46.0109 0552 Rasl2tp - ok
05:38:46.0140 0552 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
05:38:46.0140 0552 RasPppoe - ok
05:38:46.0171 0552 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
05:38:46.0171 0552 Raspti - ok
05:38:46.0218 0552 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
05:38:46.0218 0552 Rdbss - ok
05:38:46.0250 0552 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
05:38:46.0250 0552 RDPCDD - ok
05:38:46.0328 0552 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
05:38:46.0343 0552 rdpdr - ok
05:38:46.0406 0552 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
05:38:46.0421 0552 RDPWD - ok
05:38:46.0484 0552 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
05:38:46.0484 0552 redbook - ok
05:38:46.0546 0552 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
05:38:46.0546 0552 ROOTMODEM - ok
05:38:46.0656 0552 s716bus (d7a84ef8f953a2d704580e4e73e00011) C:\WINDOWS\system32\DRIVERS\s716bus.sys
05:38:46.0656 0552 s716bus - ok
05:38:46.0687 0552 s716mdfl (c5b509cdeeb733efafadc2d93bc77712) C:\WINDOWS\system32\DRIVERS\s716mdfl.sys
05:38:46.0687 0552 s716mdfl - ok
05:38:46.0718 0552 s716mdm (dc3dec64860878540b374dc7d15d921f) C:\WINDOWS\system32\DRIVERS\s716mdm.sys
05:38:46.0734 0552 s716mdm - ok
05:38:46.0765 0552 s716mgmt (047fd555d897333ad9f61b1d4cc7c114) C:\WINDOWS\system32\DRIVERS\s716mgmt.sys
05:38:46.0765 0552 s716mgmt - ok
05:38:46.0796 0552 s716nd5 (2858193e91eef964e41b6a032e1e4418) C:\WINDOWS\system32\DRIVERS\s716nd5.sys
05:38:46.0796 0552 s716nd5 - ok
05:38:46.0843 0552 s716obex (cc6c212585891614cc2059ba48d27a86) C:\WINDOWS\system32\DRIVERS\s716obex.sys
05:38:46.0843 0552 s716obex - ok
05:38:46.0875 0552 s716unic (aaaeeba9fa0ecb0de6bba59f955cdefb) C:\WINDOWS\system32\DRIVERS\s716unic.sys
05:38:46.0875 0552 s716unic - ok
05:38:47.0015 0552 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
05:38:47.0015 0552 Secdrv - ok
05:38:47.0093 0552 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
05:38:47.0109 0552 serenum - ok
05:38:47.0156 0552 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
05:38:47.0156 0552 Serial - ok
05:38:47.0250 0552 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
05:38:47.0250 0552 Sfloppy - ok
05:38:47.0296 0552 Simbad - ok
05:38:47.0343 0552 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
05:38:47.0359 0552 sisagp - ok
05:38:47.0406 0552 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
05:38:47.0406 0552 SLIP - ok
05:38:47.0484 0552 SmartDefragDriver (972dea0d8149d73c5b7a2c97b2e749e3) C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys
05:38:47.0484 0552 SmartDefragDriver - ok
05:38:47.0546 0552 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
05:38:47.0546 0552 Sparrow - ok
05:38:47.0609 0552 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
05:38:47.0609 0552 splitter - ok
05:38:47.0703 0552 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys
05:38:47.0718 0552 sptd - ok
05:38:47.0750 0552 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
05:38:47.0765 0552 sr - ok
05:38:47.0828 0552 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
05:38:47.0843 0552 Srv - ok
05:38:47.0906 0552 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
05:38:47.0906 0552 StarOpen - ok
05:38:47.0968 0552 STHDA (352b663a81402be7cd7bd4ea27c9998c) C:\WINDOWS\system32\drivers\sthda.sys
05:38:47.0968 0552 STHDA - ok
05:38:48.0046 0552 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
05:38:48.0046 0552 streamip - ok
05:38:48.0093 0552 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
05:38:48.0093 0552 swenum - ok
05:38:48.0140 0552 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
05:38:48.0140 0552 swmidi - ok
05:38:48.0203 0552 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
05:38:48.0203 0552 symc810 - ok
05:38:48.0234 0552 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
05:38:48.0234 0552 symc8xx - ok
05:38:48.0265 0552 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
05:38:48.0265 0552 sym_hi - ok
05:38:48.0312 0552 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
05:38:48.0312 0552 sym_u3 - ok
05:38:48.0375 0552 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
05:38:48.0375 0552 sysaudio - ok
05:38:48.0484 0552 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
05:38:48.0484 0552 Tcpip - ok
05:38:48.0546 0552 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
05:38:48.0546 0552 TDPIPE - ok
05:38:48.0609 0552 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
05:38:48.0609 0552 TDTCP - ok
05:38:48.0656 0552 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
05:38:48.0656 0552 TermDD - ok
05:38:48.0750 0552 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
05:38:48.0750 0552 TosIde - ok
05:38:48.0843 0552 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
05:38:48.0859 0552 Udfs - ok
05:38:48.0906 0552 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
05:38:48.0921 0552 ultra - ok
05:38:48.0984 0552 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
05:38:49.0000 0552 Update - ok
05:38:49.0062 0552 USBAAPL - ok
05:38:49.0125 0552 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
05:38:49.0125 0552 usbaudio - ok
05:38:49.0218 0552 USBCamera (2038824260efdffa6f78d9bef767622d) C:\WINDOWS\system32\Drivers\Bulk536.sys
05:38:49.0234 0552 USBCamera - ok
05:38:49.0328 0552 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
05:38:49.0328 0552 usbccgp - ok
05:38:49.0390 0552 usbcm (a31c1f4b2448eeeff7c0d4e4d58bd9b3) C:\WINDOWS\system32\DRIVERS\usbcm.sys
05:38:49.0390 0552 usbcm - ok
05:38:49.0453 0552 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
05:38:49.0453 0552 usbehci - ok
05:38:49.0500 0552 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
05:38:49.0500 0552 usbhub - ok
05:38:49.0531 0552 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
05:38:49.0546 0552 usbprint - ok
05:38:49.0578 0552 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
05:38:49.0593 0552 usbscan - ok
05:38:49.0640 0552 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\DRIVERS\usbser.sys
05:38:49.0640 0552 usbser - ok
05:38:49.0703 0552 usbsermptxp (49106ee29074e6a3d3ac9e24c6d791d8) C:\WINDOWS\system32\DRIVERS\usbsermptxp.sys
05:38:49.0703 0552 usbsermptxp - ok
05:38:49.0750 0552 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
05:38:49.0750 0552 USBSTOR - ok
05:38:49.0796 0552 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
05:38:49.0796 0552 usbuhci - ok
05:38:49.0828 0552 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
05:38:49.0828 0552 usb_rndisx - ok
05:38:49.0890 0552 VBus (2f819aa4b3171efc050b648430800dc2) C:\WINDOWS\system32\DRIVERS\NkVBus.sys
05:38:49.0906 0552 VBus - ok
05:38:49.0968 0552 VComm (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys
05:38:49.0968 0552 VComm - ok
05:38:50.0031 0552 VcommMgr (630bbdbf5490f8f57abe650da63661a0) C:\WINDOWS\system32\Drivers\VcommMgr.sys
05:38:50.0046 0552 VcommMgr - ok
05:38:50.0109 0552 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
05:38:50.0109 0552 VgaSave - ok
05:38:50.0187 0552 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
05:38:50.0187 0552 viaagp - ok
05:38:50.0234 0552 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
05:38:50.0234 0552 ViaIde - ok
05:38:50.0296 0552 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
05:38:50.0296 0552 VolSnap - ok
05:38:50.0437 0552 VX1000 (d22c6b9c2f840d403fd387ad207a4b16) C:\WINDOWS\system32\DRIVERS\VX1000.sys
05:38:50.0453 0552 VX1000 - ok
05:38:50.0593 0552 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
05:38:50.0593 0552 Wanarp - ok
05:38:50.0625 0552 wanatw - ok
05:38:50.0640 0552 WDICA - ok
05:38:50.0718 0552 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
05:38:50.0718 0552 wdmaud - ok
05:38:50.0953 0552 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
05:38:50.0968 0552 WpdUsb - ok
05:38:51.0015 0552 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
05:38:51.0015 0552 WS2IFSL - ok
05:38:51.0093 0552 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
05:38:51.0109 0552 WSTCODEC - ok
05:38:51.0187 0552 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
05:38:51.0187 0552 WudfPf - ok
05:38:51.0234 0552 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
05:38:51.0250 0552 WudfRd - ok
05:38:51.0484 0552 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0
05:38:51.0484 0552 \Device\Harddisk0\DR0 - ok
05:38:51.0500 0552 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR3
05:38:51.0500 0552 \Device\Harddisk1\DR3 - ok
05:38:51.0515 0552 Boot (0x1200) (e1e52d834b270ea4f89e50ea4201e261) \Device\Harddisk0\DR0\Partition0
05:38:51.0515 0552 \Device\Harddisk0\DR0\Partition0 - ok
05:38:51.0515 0552 Boot (0x1200) (ab59b05fa41c6d9c15734fee8b39d8da) \Device\Harddisk1\DR3\Partition0
05:38:51.0515 0552 \Device\Harddisk1\DR3\Partition0 - ok
05:38:51.0515 0552 ============================================================
05:38:51.0515 0552 Scan finished
05:38:51.0515 0552 ============================================================
05:38:51.0531 1968 Detected object count: 0
05:38:51.0531 1968 Actual detected object count: 0
05:39:21.0593 0872 Deinitialize success


ComboFix
ComboFix 11-12-05.04 - chic 06/12/2011 5:47.15.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.415 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\system32\UNWISE.EXE
G:\AUTORUN.INF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-06 05:02 . 2011-12-06 05:02 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F605BCDD-58C7-485C-8FD7-2A7E2E15BFE9}\MpKslf43d82eb.sys
2011-12-06 05:02 . 2011-12-06 05:02 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F605BCDD-58C7-485C-8FD7-2A7E2E15BFE9}\offreg.dll
2011-12-05 23:30 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F605BCDD-58C7-485C-8FD7-2A7E2E15BFE9}\mpengine.dll
2011-12-04 18:00 . 2011-12-04 18:00 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-04 17:54 . 2011-12-04 18:33 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\uTorrent
2011-11-19 12:27 . 2011-11-19 12:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Citrix
2011-11-19 12:26 . 2011-11-19 12:26 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\Citrix
2011-11-06 11:52 . 2011-11-06 11:52 ——– d—–w- c:\documents and settings\chic\Local Settings\Application Data\Yahoo!
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-10-03 01:26 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-24 14:29 . 2011-10-24 14:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 14:29 . 2011-10-24 14:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22 . 2004-08-10 13:02 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 05:24 . 2011-10-07 05:24 0 —-a-w- c:\windows\system32\REN73.tmp
2011-10-07 05:24 . 2011-10-07 05:24 0 —-a-w- c:\windows\system32\REN72.tmp
2011-10-07 05:24 . 2011-10-07 05:24 0 —-a-w- c:\windows\system32\REN71.tmp
2011-10-03 05:06 . 2010-07-23 18:19 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 02:37 . 2011-10-07 05:26 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-30 14:37 . 2011-10-20 20:49 17280 —-a-w- c:\windows\system32\roboot.exe
2011-09-29 20:37 . 2011-09-29 20:37 0 —-a-w- c:\windows\system32\RENF2.tmp
2011-09-29 20:37 . 2011-09-29 20:37 0 —-a-w- c:\windows\system32\RENF1.tmp
2011-09-29 20:37 . 2011-09-29 20:37 0 —-a-w- c:\windows\system32\RENF0.tmp
2011-09-28 07:06 . 2004-08-10 12:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2004-08-10 12:51 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2004-08-10 12:51 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-11-21 04:04 . 2011-03-27 13:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Xvid"="g:\program files\XviD\CheckUpdate.exe" [2011-01-17 8192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2011-10-02 08:50 16680 —-a-w- c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2006-11-22 20:10 151552 ——w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2008-05-26 19:13 57344 —-a-w- c:\program files\MarkAny\ContentSafer\MaAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 14:28 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-12-18 14:26 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpBrowser.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpNotifier.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"135:TCP"= 135:TCP:TCP Port 135
"5985:TCP"= 5985:TCP:Windows Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [10/07/2011 10:56 13496]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [04/06/2010 10:55 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [01/06/2010 18:00 27576]
R1 MpKslf43d82eb;MpKslf43d82eb;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F605BCDD-58C7-485C-8FD7-2A7E2E15BFE9}\MpKslf43d82eb.sys [06/12/2011 05:02 29904]
R2 DSUDiskOptimizer;DSUDiskOptimizer;c:\program files\Disk Speedup\DSUDefragSrv.exe [21/10/2011 05:34 668472]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/09/2009 08:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/09/2009 08:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/09/2009 08:11 12928]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [24/07/2008 19:38 47360]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [17/06/2005 11:11 17664]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys –> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 MpKsl38748af2;MpKsl38748af2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{185D89C8-04A0-4C7A-BC3C-9078C575EC46}\MpKsl38748af2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{185D89C8-04A0-4C7A-BC3C-9078C575EC46}\MpKsl38748af2.sys [?]
S1 MpKsl6717158e;MpKsl6717158e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C507BD94-0215-4741-93C3-63A572CF7DD2}\MpKsl6717158e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C507BD94-0215-4741-93C3-63A572CF7DD2}\MpKsl6717158e.sys [?]
S1 MpKsl994b83a1;MpKsl994b83a1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CD7F42D8-E1E8-4FAF-994C-5DCE6D36A2DD}\MpKsl994b83a1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CD7F42D8-E1E8-4FAF-994C-5DCE6D36A2DD}\MpKsl994b83a1.sys [?]
S1 MpKslc29337be;MpKslc29337be;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EF7D89D-7C92-4F0A-B5FF-02524AF5838D}\MpKslc29337be.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EF7D89D-7C92-4F0A-B5FF-02524AF5838D}\MpKslc29337be.sys [?]
S1 MpKslc5913634;MpKslc5913634;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CECC4C36-78D7-4F07-893F-430031FD7B30}\MpKslc5913634.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CECC4C36-78D7-4F07-893F-430031FD7B30}\MpKslc5913634.sys [?]
S2 Ca536av;5.0M MPEG4 DV Video Capture;c:\windows\system32\drivers\Ca536av.sys [19/12/2005 18:02 514155]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 10:07 136176]
S3 ambitucm;Ambit USB Cable Modem NDIS Driver;c:\windows\system32\drivers\ambitucm.sys [24/11/2005 21:38 14974]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [10/05/2011 06:25 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [10/05/2011 06:25 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [10/05/2011 06:25 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [10/05/2011 06:25 25088]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys [10/05/2011 06:25 23168]
S3 AndNetGps;LGE AndroidNet USB GPS NMEA Port;c:\windows\system32\drivers\lgandnetgps.sys [10/05/2011 06:25 22272]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys [10/05/2011 06:25 28032]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys [10/05/2011 06:25 70016]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [30/12/2007 19:16 16512]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 11:42 64000]
S3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\drivers\DTV_Capture_2X0.sys [25/12/2005 10:22 18432]
S3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\drivers\DTV_Loader_2X1.sys [25/12/2005 10:11 19328]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [03/04/2010 09:41 36608]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [18/06/2010 10:07 136176]
S3 k600bus;Sony Ericsson 600i driver (WDM);c:\windows\system32\drivers\k600bus.sys [11/05/2005 13:12 52384]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;c:\windows\system32\drivers\k600mdfl.sys [11/05/2005 13:12 6096]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;c:\windows\system32\drivers\k600mdm.sys [11/05/2005 13:12 87456]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;c:\windows\system32\drivers\k600mgmt.sys [11/05/2005 13:12 79248]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\k600obex.sys [11/05/2005 13:12 77072]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12/06/2011 10:15 31125880]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 17:07 35088]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [10/08/2004 12:51 14336]
S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [03/04/2010 09:41 233472]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31/12/2009 08:33 691696]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 48258803
*NewlyCreated* - MPKSLF43D82EB
*Deregistered* - 48258803
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-06 c:\windows\Tasks\AdobeAAMUpdater-1.0-AMANCHIC-chic.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-19 03:44]
.
2011-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-12-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-12-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-18 19:05]
.
2011-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006Core.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2011-12-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3405850505-2850181533-2126382385-1006UA.job
- c:\documents and settings\chic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 16:52]
.
2011-12-04 c:\windows\Tasks\RegClean Pro_DEFAULT.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2011-10-20 14:37]
.
2011-11-30 c:\windows\Tasks\RegClean Pro_UPDATES.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2011-10-20 14:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.00\MediaManager\grab.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\chic\Application Data\Mozilla\Firefox\Profiles\a8kz582u.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - prefs.js: keyword.URL - hxxp://www.buzqo.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=232&product_id=687&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.1.0&install_country=GB&install_date=20110803&user_guid=F8372C8C2037474E84E361D0C6BED8B6&machine_id=dbf6e3af30735d8ed358a4b06ae7e829&browser=FF&os=win&os_version=5.1-x86-SP3&q=

FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-06 06:00
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(756)
c:\program files\Citrix\GoToAssist\570\G2AWinLogon.dll
.
Completion time: 2011-12-06 06:05:29
ComboFix-quarantined-files.txt 2011-12-06 06:05
.
Pre-Run: 113,717,014,528 bytes free
Post-Run: 115,043,098,624 bytes free
.
- - End Of File - - 1D51363C73B6634FC7122946183C615D
Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean








  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Hi Mowman, Below is the MBAM logfile, unfortunately I fouled up with the ESET scan - it ran ok and found 3 threats in my external hd, which it quarantined and deleted - I didn't see any "details" tab, sorry. The PC itself seems to be running ok, certainly a vast improvement on the other day. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8323 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 06/12/2011 18:16:20 mbam-log-2011-12-06 (18-16-20).txt Scan type: Quick scan Objects scanned: 169008 Time elapsed: 6 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Well if everything is running ok now we can finish up here,nice and quick one that.


Delete tdsskiller and eset.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)








Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Thanks again for your time mowman, it is appreciated. I had been told, on this site, before that MS Essentials would provide comprehensive cover for my PC - not to worry. I will source Firewall software and be more careful in the future - thanks for all the advice. Declan.

I had been told, on this site, before that MS Essentials would provide comprehensive cover for my PC - not to worry.

It is one of the best Antivirus but no AV will protect you from everything out there,


You're welcome,glad we could help :)


Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI