This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rootkit and Fake Internet Security pop ups [Solved]

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Fake Internet Security is popping up and I've had my CPU going high for awhile. Spybot found a bunch of stuff. Ifixed it then used ESET to be sure it caught everything. It found stuff too and deleted what it could leaving….target- C:\windows\system32\drivers\serial.sys…..threat-Win32?sirefef.DAtrojan….action- unable to clean. Also, ….target- operating memory,…threat- mulitple threats………….action- there was nothing. Also, ran combo fix at my own risk. It came up with a rootkit.zeroaccess. There was something it said it couldn't delete as well. I don't have a log file for these but I do have a HJT log. Here it goes and thanks.







Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:02:17 PM, on 12/19/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: Xfinity.com Toolbar - {dcc70a83-e184-40a3-906b-779af5e941c4} - C:\Program Files\xfinitytb\xfinitydx.dll
O2 - BHO: Updater For Xfinity.com Toolbar 3.5 - {e6d0b79e-ecac-411b-8bf6-7a574981af30} - C:\Program Files\xfinitytb\auxi\xfinityAu.dll
O3 - Toolbar: Xfinity.com Toolbar - {dcc70a83-e184-40a3-906b-779af5e941c4} - C:\Program Files\xfinitytb\xfinitydx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AsioReg] REGSVR32 /S CTASIO.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [DevconDefaultDB] C:\WINDOWS\READREG /PSCONV={NO}
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://msn.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1264810411350
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1264810395457
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v41/hangman/hangman.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v52/dinerdash/dinerdash.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 11472 bytes
Hi leeleecm, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Have a look at C:\combofix.txt for the combofix log. It may also be at C:\combofix.

what symptoms are you having?
There still seem to be cpu spikes and I don't know if this is related but it seems to be running slower. I guess I just want an experienced eye to take a peek and see if I'm clean.



ComboFix 11-12-19.01 - 12/19/2011 16:02:43.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.696 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB29568$\2212098137\@
c:\windows\$NtUninstallKB29568$\2212098137\bckfg.tmp
c:\windows\$NtUninstallKB29568$\2212098137\cfg.ini
c:\windows\$NtUninstallKB29568$\2212098137\Desktop.ini
c:\windows\$NtUninstallKB29568$\2212098137\keywords
c:\windows\$NtUninstallKB29568$\2212098137\kwrd.dll
c:\windows\$NtUninstallKB29568$\2212098137\L\razfqhxf
c:\windows\$NtUninstallKB29568$\2212098137\lsflt7.ver
c:\windows\$NtUninstallKB29568$\2212098137\U\00000001.@
c:\windows\$NtUninstallKB29568$\2212098137\U\00000002.@
c:\windows\$NtUninstallKB29568$\2212098137\U\00000004.@
c:\windows\$NtUninstallKB29568$\2212098137\U\80000000.@
c:\windows\$NtUninstallKB29568$\2212098137\U\80000004.@
c:\windows\$NtUninstallKB29568$\2212098137\U\80000032.@
c:\windows\$NtUninstallKB29568$\3957543327
c:\windows\$NtUninstallKB29568$ . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-30 15:40 . 2004-08-04 03:15 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-23 13:25 . 2004-08-04 03:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2004-08-04 04:56 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 19:20 . 2004-08-04 04:56 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 04:56 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 11:23 . 2004-08-04 02:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-04 04:56 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 04:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2004-08-04 03:20 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-04 04:56 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2005-03-08 18:12 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 04:56 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 18:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2002-08-29 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2002-08-29 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2005-07-12 18:20 . 2005-07-21 14:08 1445888 —-a-w- c:\program files\WinsockFix.exe
2011-11-30 15:53 . 2005-03-08 19:30 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2011-11-30 15:53 . 2005-03-08 19:30 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2011-11-30 15:53 . 2006-11-17 15:46 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2011-11-30 15:53 . 2006-11-17 15:46 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2011-11-30 15:53 . 2005-03-08 19:30 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-30_17.46.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-30 17:46 . 2011-11-30 17:46 40960 c:\windows\temp\rtdrvmon.exe
+ 2011-12-19 21:15 . 2011-12-19 21:15 40960 c:\windows\temp\rtdrvmon.exe
+ 2007-01-03 23:25 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2007-01-03 23:25 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
+ 2004-08-04 04:56 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
+ 2006-10-27 20:09 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
- 2006-10-27 20:09 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
+ 2010-01-30 14:26 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
- 2010-01-30 14:26 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-04-25 08:41 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-04-25 08:41 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-12-14 07:08 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2007-06-22 19:47 . 2011-12-15 08:13 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2011-05-27 14:53 . 2011-05-27 14:53 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\ViewerPS.dll
+ 2011-05-27 19:52 . 2011-05-27 19:52 40368 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\reader_sl.exe
+ 2011-05-27 14:52 . 2011-05-27 14:52 67016 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\PDFPrevHndlrShim.exe
+ 2011-05-27 14:52 . 2011-05-27 14:52 83376 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\PDFPrevHndlr.dll
+ 2011-05-27 14:01 . 2011-05-27 14:01 95672 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\nppdf32.dll
+ 2011-05-27 14:10 . 2011-05-27 14:10 13752 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroRd32Info.exe
+ 2011-05-27 13:24 . 2011-05-27 13:24 61888 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroIEHelper.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2006-10-27 20:09 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2006-10-27 20:09 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 04:56 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 04:56 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
- 2005-03-08 11:07 . 2011-10-19 13:47 343424 c:\windows\system32\FNTCACHE.DAT
+ 2005-03-08 11:07 . 2011-12-19 15:48 343424 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-04 04:56 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
- 2007-04-25 08:41 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-04-25 08:41 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2010-01-30 14:26 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2010-01-30 14:26 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-06-09 18:25 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-06-09 18:25 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 04:56 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2004-08-04 04:56 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2011-03-09 08:20 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
- 2011-03-09 08:20 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-12-10 01:45 . 2011-12-10 01:45 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A83000000003}\SC_Reader.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2011-05-27 14:06 . 2011-05-27 14:06 372736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\pdfshell.dll
+ 2011-05-27 13:20 . 2011-05-27 13:20 140728 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AdobeUpdateCheck.exe
+ 2011-05-27 14:51 . 2011-05-27 14:51 738776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AdobeCollabSync.exe
+ 2011-05-27 14:42 . 2011-05-27 14:42 112048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroRdIF.dll
+ 2011-05-27 19:52 . 2011-05-27 19:52 345520 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroRd32.exe
+ 2011-05-27 13:24 . 2011-05-27 13:24 632240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroPDF.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-15 08:12 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-15 08:12 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-15 08:12 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-15 08:12 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2011-12-15 08:13 . 2011-12-15 08:13 350080 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
- 2004-08-04 04:56 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 5978112 c:\windows\system32\mshtml.dll
+ 2006-10-17 17:57 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
- 2006-10-17 17:57 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2008-10-15 18:33 . 2011-11-23 13:25 1859584 c:\windows\system32\dllcache\win32k.sys
- 2004-08-04 04:56 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 04:56 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2010-10-16 19:40 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
+ 2009-07-02 00:50 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2009-07-02 00:50 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-07-02 00:50 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-07-02 00:50 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-07 23:02 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-02-07 23:02 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-07-02 00:50 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2009-07-02 00:50 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2004-08-04 04:56 . 2011-11-04 19:20 5978112 c:\windows\system32\dllcache\mshtml.dll
+ 2007-04-25 08:41 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
- 2007-04-25 08:41 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-08-31 05:33 . 2011-08-31 05:33 3550208 c:\windows\Installer\5dfc55.msp
+ 2011-12-10 01:45 . 2011-12-10 01:45 4272128 c:\windows\Installer\5dfbd9.msi
+ 2011-11-01 18:34 . 2011-11-01 18:34 4250112 c:\windows\Installer\1b79f23a.msp
+ 2011-11-01 18:34 . 2011-11-01 18:34 2247168 c:\windows\Installer\1b79f222.msp
+ 2011-11-11 21:14 . 2011-11-11 21:14 9096192 c:\windows\Installer\1b79f20c.msp
+ 2011-11-01 18:34 . 2011-11-01 18:34 4225536 c:\windows\Installer\1b79f1f6.msp
+ 2011-11-01 18:34 . 2011-11-01 18:34 2531840 c:\windows\Installer\1b79f1db.msp
+ 2011-11-11 21:15 . 2011-11-11 21:15 1795584 c:\windows\Installer\1b79f1c5.msp
+ 2011-11-11 21:16 . 2011-11-11 21:16 8458240 c:\windows\Installer\1b79f1af.msp
+ 2007-06-22 19:47 . 2011-12-15 08:13 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2007-06-22 19:47 . 2011-12-15 08:13 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2007-06-22 19:47 . 2011-10-13 07:15 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-05-27 13:22 . 2011-05-27 13:22 1953792 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\rt3d.dll
+ 2009-04-03 01:44 . 2009-04-03 01:44 2532224 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\GRAPH.EXE
+ 2011-12-15 08:12 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-15 08:12 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-15 08:12 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
+ 2009-07-02 00:50 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-07-02 00:50 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-07-02 00:50 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-07-02 00:50 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-07 23:02 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-07 23:02 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-07-02 00:50 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-07-02 00:50 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-07-21 13:57 . 2011-12-15 08:07 52988224 c:\windows\system32\MRT.exe
+ 2006-10-27 20:09 . 2011-11-04 19:20 11081728 c:\windows\system32\ieframe.dll
- 2006-10-27 20:09 . 2011-08-23 21:48 11081728 c:\windows\system32\ieframe.dll
+ 2007-04-25 08:41 . 2011-11-04 19:20 11081728 c:\windows\system32\dllcache\ieframe.dll
- 2007-04-25 08:41 . 2011-08-23 21:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-05-27 19:29 . 2011-05-27 19:29 13338040 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0300000030\8.3.0\AcroRd32.dll
+ 2011-12-15 08:12 . 2011-08-23 21:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dcc70a83-e184-40a3-906b-779af5e941c4}]
2010-11-11 18:55 87512 —-a-w- c:\program files\xfinitytb\xfinitydx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e6d0b79e-ecac-411b-8bf6-7a574981af30}]
2010-12-22 14:31 265176 —-a-w- c:\program files\xfinitytb\auxi\xfinityAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dcc70a83-e184-40a3-906b-779af5e941c4}"= "c:\program files\xfinitytb\xfinitydx.dll" [2010-11-11 87512]
.
[HKEY_CLASSES_ROOT\clsid\{dcc70a83-e184-40a3-906b-779af5e941c4}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-25 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\READREG" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-12-18 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AsioReg"="CTASIO.DLL" [2003-11-13 126976]
"CTHelper"="CTHELPER.EXE" [2004-03-11 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-01-10 5513216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
"TSClientAXDisabler"="c:\windows\Installer\TSClientMsiTrans\tscdsbl.bat" [2008-01-19 2247]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-6 113664]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
.
[HKLM\~\startupfolder\C:^Documents and Settings^Christy^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Christy\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLRebootNeeded]
/s [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ComcastAntispyClient]
2009-08-19 17:25 1589208 —-a-w- c:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
2008-04-24 17:25 202560 —-a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [6/17/2009 12:49 PM 616408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2011 8:00 AM 136176]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [8/27/2006 11:02 AM 20160]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2011 8:00 AM 136176]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/3/2004 11:56 PM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-15 12:59]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-15 12:59]
.
2011-12-19 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: worldwinner.com\www
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\documents and settings\Christy\Application Data\Mozilla\Firefox\Profiles\espu83qj.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.pitt.edu
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-19 16:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(648)
c:\program files\CA\PPRT\bin\CACheck.dll
c:\program files\CA\PPRT\bin\CAHook.dll
c:\program files\CA\PPRT\bin\CAServer.dll
.
- - - - - - - > 'explorer.exe'(3544)
c:\windows\system32\WININET.dll
c:\program files\CA\PPRT\bin\CACheck.dll
c:\program files\CA\PPRT\bin\CAHook.dll
c:\program files\CA\PPRT\bin\CAServer.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\CA\PPRT\bin\ITMRTSVC.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-12-19 16:26:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-19 21:25
ComboFix2.txt 2011-11-30 20:42
ComboFix3.txt 2011-11-30 17:56
ComboFix4.txt 2010-01-19 14:38
ComboFix5.txt 2011-12-19 20:54
.
Pre-Run: 47,879,757,824 bytes free
Post-Run: 47,981,015,040 bytes free
.
- - End Of File - - 47289AF283B9718066927CCAE6206EB4
Hi leeleecm,

If this next tool ask you tp download Avast's definitions, please do so.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-21 16:45:41 —————————– 16:45:41.906 OS Version: Windows 5.1.2600 Service Pack 3 16:45:41.906 Number of processors: 1 586 0x207 16:45:41.906 ComputerName: DELL UserName: 16:45:44.329 Initialize success 16:48:17.570 AVAST engine defs: 11122102 16:49:31.446 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 16:49:31.446 Disk 0 Vendor: WDC_WD800BB-75CAA0 16.06V16 Size: 76293MB BusType: 3 16:49:33.479 Disk 0 MBR read successfully 16:49:33.479 Disk 0 MBR scan 16:49:33.559 Disk 0 Windows XP default MBR code 16:49:33.579 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 16:49:33.589 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325 16:49:33.589 Disk 0 scanning sectors +156232125 16:49:33.659 Disk 0 scanning C:\WINDOWS\system32\drivers 16:49:46.017 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk] 16:49:49.762 Service scanning 16:49:54.008 Modules scanning 16:50:27.847 Disk 0 trace - called modules: 16:50:27.877 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS 16:50:27.887 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x873d5030] 16:50:27.887 3 CLASSPNP.SYS[f7621fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8738fb00] 16:50:29.249 AVAST engine scan C:\WINDOWS 16:50:43.710 AVAST engine scan C:\WINDOWS\system32 16:53:56.116 AVAST engine scan C:\WINDOWS\system32\drivers 16:54:11.278 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk] 16:54:18.308 AVAST engine scan C:\Documents and Settings\Christy 17:00:57.572 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat" 17:00:57.572 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt" aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-21 16:45:41 —————————– 16:45:41.906 OS Version: Windows 5.1.2600 Service Pack 3 16:45:41.906 Number of processors: 1 586 0x207 16:45:41.906 ComputerName: DELL UserName: 16:45:44.329 Initialize success 16:48:17.570 AVAST engine defs: 11122102 16:49:31.446 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 16:49:31.446 Disk 0 Vendor: WDC_WD800BB-75CAA0 16.06V16 Size: 76293MB BusType: 3 16:49:33.479 Disk 0 MBR read successfully 16:49:33.479 Disk 0 MBR scan 16:49:33.559 Disk 0 Windows XP default MBR code 16:49:33.579 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63 16:49:33.589 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325 16:49:33.589 Disk 0 scanning sectors +156232125 16:49:33.659 Disk 0 scanning C:\WINDOWS\system32\drivers 16:49:46.017 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk] 16:49:49.762 Service scanning 16:49:54.008 Modules scanning 16:50:27.847 Disk 0 trace - called modules: 16:50:27.877 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS 16:50:27.887 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x873d5030] 16:50:27.887 3 CLASSPNP.SYS[f7621fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8738fb00] 16:50:29.249 AVAST engine scan C:\WINDOWS 16:50:43.710 AVAST engine scan C:\WINDOWS\system32 16:53:56.116 AVAST engine scan C:\WINDOWS\system32\drivers 16:54:11.278 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk] 16:54:18.308 AVAST engine scan C:\Documents and Settings\Christy 17:00:57.572 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat" 17:00:57.572 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt" 17:09:33.054 AVAST engine scan C:\Documents and Settings\All Users 17:15:30.217 Scan finished successfully 21:28:45.657 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat" 21:28:45.657 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt"

Attachments:

Hi leeleecm,



Please read carefully and follow these steps.
I think I got that all right. 22:42:12.0905 3924 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31 22:42:14.0136 3924 ============================================================ 22:42:14.0136 3924 Current date / time: 2011/12/21 22:42:14.0136 22:42:14.0136 3924 SystemInfo: 22:42:14.0136 3924 22:42:14.0136 3924 OS Version: 5.1.2600 ServicePack: 3.0 22:42:14.0136 3924 Product type: Workstation 22:42:14.0136 3924 ComputerName: DELL 22:42:14.0136 3924 UserName: Christy 22:42:14.0136 3924 Windows directory: C:\WINDOWS 22:42:14.0136 3924 System windows directory: C:\WINDOWS 22:42:14.0136 3924 Processor architecture: Intel x86 22:42:14.0136 3924 Number of processors: 1 22:42:14.0136 3924 Page size: 0x1000 22:42:14.0136 3924 Boot type: Normal boot 22:42:14.0136 3924 ============================================================ 22:42:15.0819 3924 Initialize success 22:42:24.0010 1488 ============================================================ 22:42:24.0010 1488 Scan started 22:42:24.0010 1488 Mode: Manual; 22:42:24.0010 1488 ============================================================ 22:42:24.0822 1488 Abiosdsk - ok 22:42:24.0992 1488 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 22:42:24.0992 1488 abp480n5 - ok 22:42:25.0172 1488 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys 22:42:25.0172 1488 ac97intc - ok 22:42:25.0362 1488 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 22:42:25.0362 1488 ACPI - ok 22:42:25.0543 1488 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 22:42:25.0543 1488 ACPIEC - ok 22:42:25.0723 1488 ADM8511 (b05f2367f62552a2de7e3c352b7b9885) C:\WINDOWS\system32\DRIVERS\ADM8511.SYS 22:42:25.0723 1488 ADM8511 - ok 22:42:25.0893 1488 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 22:42:25.0893 1488 adpu160m - ok 22:42:26.0083 1488 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 22:42:26.0083 1488 aec - ok 22:42:26.0264 1488 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 22:42:26.0274 1488 AFD - ok 22:42:26.0484 1488 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 22:42:26.0484 1488 agp440 - ok 22:42:26.0674 1488 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 22:42:26.0674 1488 agpCPQ - ok 22:42:26.0845 1488 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 22:42:26.0845 1488 Aha154x - ok 22:42:27.0045 1488 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 22:42:27.0045 1488 aic78u2 - ok 22:42:27.0215 1488 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 22:42:27.0215 1488 aic78xx - ok 22:42:27.0425 1488 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 22:42:27.0425 1488 AliIde - ok 22:42:27.0616 1488 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 22:42:27.0616 1488 alim1541 - ok 22:42:27.0796 1488 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 22:42:27.0796 1488 amdagp - ok 22:42:27.0966 1488 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 22:42:27.0976 1488 amsint - ok 22:42:28.0196 1488 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 22:42:28.0196 1488 Arp1394 - ok 22:42:28.0377 1488 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 22:42:28.0377 1488 asc - ok 22:42:28.0567 1488 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 22:42:28.0577 1488 asc3350p - ok 22:42:28.0747 1488 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 22:42:28.0747 1488 asc3550 - ok 22:42:29.0028 1488 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 22:42:29.0028 1488 AsyncMac - ok 22:42:29.0218 1488 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 22:42:29.0218 1488 atapi - ok 22:42:29.0368 1488 Atdisk - ok 22:42:29.0558 1488 ati2mtaa (2d030c2f6b036ca0bc243e1b16d924d1) C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys 22:42:29.0588 1488 ati2mtaa - ok 22:42:29.0839 1488 ati2mtag (8759322ffc1a50569c1e5528ee8026b7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 22:42:29.0869 1488 ati2mtag - ok 22:42:30.0049 1488 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 22:42:30.0049 1488 Atmarpc - ok 22:42:30.0209 1488 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 22:42:30.0209 1488 audstub - ok 22:42:30.0390 1488 b57w2k (48bf91cffbcdd12a710207f2a08fec4d) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 22:42:30.0400 1488 b57w2k - ok 22:42:30.0570 1488 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 22:42:30.0570 1488 Beep - ok 22:42:30.0590 1488 catchme - ok 22:42:30.0800 1488 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 22:42:30.0800 1488 cbidf - ok 22:42:30.0970 1488 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 22:42:30.0970 1488 cbidf2k - ok 22:42:31.0141 1488 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 22:42:31.0141 1488 CCDECODE - ok 22:42:31.0311 1488 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 22:42:31.0311 1488 cd20xrnt - ok 22:42:31.0501 1488 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 22:42:31.0501 1488 Cdaudio - ok 22:42:31.0671 1488 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 22:42:31.0682 1488 Cdfs - ok 22:42:32.0042 1488 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 22:42:32.0052 1488 Cdrom - ok 22:42:32.0212 1488 Changer - ok 22:42:32.0403 1488 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 22:42:32.0403 1488 CmdIde - ok 22:42:32.0583 1488 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 22:42:32.0583 1488 Cpqarray - ok 22:42:32.0783 1488 ctac32k (a5e67327b49e1f4341d470d8bbcbc401) C:\WINDOWS\system32\drivers\ctac32k.sys 22:42:32.0813 1488 ctac32k - ok 22:42:33.0264 1488 ctdvda2k (29f78d59b053cb8778f8426e4e24099c) C:\WINDOWS\system32\drivers\ctdvda2k.sys 22:42:33.0284 1488 ctdvda2k - ok 22:42:33.0514 1488 ctprxy2k (c7fc5d87b06207a5d34697b627826618) C:\WINDOWS\system32\drivers\ctprxy2k.sys 22:42:33.0514 1488 ctprxy2k - ok 22:42:33.0995 1488 ctsfm2k (2c0af71cf0e1224a2dfc2b67e63b02b1) C:\WINDOWS\system32\drivers\ctsfm2k.sys 22:42:33.0995 1488 ctsfm2k - ok 22:42:34.0175 1488 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 22:42:34.0175 1488 dac2w2k - ok 22:42:34.0375 1488 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 22:42:34.0375 1488 dac960nt - ok 22:42:34.0556 1488 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 22:42:34.0556 1488 Disk - ok 22:42:34.0766 1488 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 22:42:34.0796 1488 dmboot - ok 22:42:34.0966 1488 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 22:42:34.0976 1488 dmio - ok 22:42:35.0157 1488 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 22:42:35.0157 1488 dmload - ok 22:42:35.0327 1488 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 22:42:35.0327 1488 DMusic - ok 22:42:35.0507 1488 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 22:42:35.0507 1488 dpti2o - ok 22:42:35.0677 1488 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 22:42:35.0677 1488 drmkaud - ok 22:42:35.0858 1488 E1000 (3573259a15281a670f392f59b1c09f3d) C:\WINDOWS\system32\DRIVERS\e1000325.sys 22:42:35.0868 1488 E1000 - ok 22:42:36.0048 1488 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys 22:42:36.0048 1488 EL90XBC - ok 22:42:36.0228 1488 emupia (091d37e0f5193f708c9006b1f2e23ee4) C:\WINDOWS\system32\drivers\emupia2k.sys 22:42:36.0228 1488 emupia - ok 22:42:36.0428 1488 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys 22:42:36.0428 1488 es1371 - ok 22:42:36.0619 1488 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 22:42:36.0619 1488 Fastfat - ok 22:42:36.0799 1488 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 22:42:36.0799 1488 Fdc - ok 22:42:37.0179 1488 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 22:42:37.0179 1488 Fips - ok 22:42:37.0360 1488 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 22:42:37.0360 1488 Flpydisk - ok 22:42:37.0540 1488 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 22:42:37.0540 1488 FltMgr - ok 22:42:37.0710 1488 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 22:42:37.0710 1488 Fs_Rec - ok 22:42:37.0890 1488 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 22:42:37.0890 1488 Ftdisk - ok 22:42:38.0201 1488 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 22:42:38.0211 1488 GEARAspiWDM - ok 22:42:38.0391 1488 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 22:42:38.0391 1488 Gpc - ok 22:42:38.0631 1488 ha10kx2k (1ad88bcf3d043baa58c15eb262625f9b) C:\WINDOWS\system32\drivers\ha10kx2k.sys 22:42:38.0672 1488 ha10kx2k - ok 22:42:38.0852 1488 hap16v2k (8ff42f63c722a1dd4c91ff6a497fd6b2) C:\WINDOWS\system32\drivers\hap16v2k.sys 22:42:38.0852 1488 hap16v2k - ok 22:42:39.0022 1488 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 22:42:39.0032 1488 HDAudBus - ok 22:42:39.0363 1488 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 22:42:39.0363 1488 HidUsb - ok 22:42:39.0573 1488 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 22:42:39.0573 1488 hpn - ok 22:42:39.0763 1488 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 22:42:39.0763 1488 HTTP - ok 22:42:39.0963 1488 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 22:42:39.0963 1488 i2omgmt - ok 22:42:40.0154 1488 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 22:42:40.0154 1488 i2omp - ok 22:42:40.0324 1488 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 22:42:40.0334 1488 i8042prt - ok 22:42:40.0514 1488 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 22:42:40.0514 1488 Imapi - ok 22:42:40.0694 1488 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 22:42:40.0694 1488 ini910u - ok 22:42:40.0925 1488 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 22:42:40.0925 1488 IntelIde - ok 22:42:41.0105 1488 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 22:42:41.0105 1488 intelppm - ok 22:42:41.0275 1488 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 22:42:41.0275 1488 Ip6Fw - ok 22:42:41.0426 1488 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 22:42:41.0426 1488 IpFilterDriver - ok 22:42:41.0596 1488 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 22:42:41.0596 1488 IpInIp - ok 22:42:41.0766 1488 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 22:42:41.0766 1488 IpNat - ok 22:42:41.0966 1488 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 22:42:41.0966 1488 IPSec - ok 22:42:42.0137 1488 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 22:42:42.0137 1488 IRENUM - ok 22:42:42.0317 1488 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 22:42:42.0317 1488 isapnp - ok 22:42:42.0517 1488 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 22:42:42.0517 1488 Kbdclass - ok 22:42:42.0747 1488 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 22:42:42.0747 1488 kbdhid - ok 22:42:42.0928 1488 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 22:42:42.0928 1488 kmixer - ok 22:42:43.0108 1488 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 22:42:43.0108 1488 KSecDD - ok 22:42:43.0258 1488 lbrtfdc - ok 22:42:43.0388 1488 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 22:42:43.0388 1488 mnmdd - ok 22:42:43.0559 1488 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 22:42:43.0559 1488 Modem - ok 22:42:43.0719 1488 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 22:42:43.0729 1488 Mouclass - ok 22:42:43.0889 1488 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 22:42:43.0889 1488 mouhid - ok 22:42:44.0069 1488 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 22:42:44.0069 1488 MountMgr - ok 22:42:44.0240 1488 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 22:42:44.0250 1488 mraid35x - ok 22:42:44.0430 1488 MRxDAV (e3f17e1ea5256709d4e97ef0da04b3c9) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 22:42:44.0440 1488 MRxDAV - ok 22:42:44.0760 1488 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 22:42:44.0991 1488 MRxSmb - ok 22:42:45.0171 1488 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 22:42:45.0171 1488 Msfs - ok 22:42:45.0351 1488 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 22:42:45.0351 1488 MSKSSRV - ok 22:42:45.0531 1488 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 22:42:45.0531 1488 MSPCLOCK - ok 22:42:45.0702 1488 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 22:42:45.0702 1488 MSPQM - ok 22:42:45.0862 1488 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 22:42:45.0862 1488 mssmbios - ok 22:42:46.0032 1488 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 22:42:46.0032 1488 MSTEE - ok 22:42:46.0192 1488 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 22:42:46.0192 1488 Mup - ok 22:42:46.0373 1488 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 22:42:46.0373 1488 NABTSFEC - ok 22:42:46.0593 1488 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 22:42:46.0603 1488 NDIS - ok 22:42:46.0783 1488 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 22:42:46.0783 1488 NdisIP - ok 22:42:47.0164 1488 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 22:42:47.0244 1488 NdisTapi - ok 22:42:47.0484 1488 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 22:42:47.0484 1488 Ndisuio - ok 22:42:47.0675 1488 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 22:42:47.0685 1488 NdisWan - ok 22:42:47.0925 1488 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 22:42:47.0925 1488 NDProxy - ok 22:42:48.0235 1488 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 22:42:48.0355 1488 NetBIOS - ok 22:42:48.0546 1488 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 22:42:48.0556 1488 NetBT - ok 22:42:48.0766 1488 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 22:42:48.0766 1488 NIC1394 - ok 22:42:48.0936 1488 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 22:42:48.0936 1488 Npfs - ok 22:42:49.0137 1488 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 22:42:49.0157 1488 Ntfs - ok 22:42:49.0347 1488 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 22:42:49.0347 1488 Null - ok 22:42:49.0647 1488 nv (c7993894984c271e49381cc649cdf8bd) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 22:42:49.0747 1488 nv - ok 22:42:49.0918 1488 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 22:42:49.0918 1488 NwlnkFlt - ok 22:42:50.0068 1488 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 22:42:50.0068 1488 NwlnkFwd - ok 22:42:50.0238 1488 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 22:42:50.0238 1488 ohci1394 - ok 22:42:50.0459 1488 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 22:42:50.0469 1488 P3 - ok 22:42:50.0649 1488 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 22:42:50.0649 1488 Parport - ok 22:42:50.0829 1488 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 22:42:50.0829 1488 PartMgr - ok 22:42:51.0029 1488 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 22:42:51.0029 1488 ParVdm - ok 22:42:51.0210 1488 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 22:42:51.0210 1488 PCI - ok 22:42:51.0360 1488 PCIDump - ok 22:42:51.0550 1488 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 22:42:51.0550 1488 PCIIde - ok 22:42:51.0740 1488 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 22:42:51.0740 1488 Pcmcia - ok 22:42:51.0881 1488 PDCOMP - ok 22:42:52.0001 1488 PDFRAME - ok 22:42:52.0061 1488 PDRELI - ok 22:42:52.0131 1488 PDRFRAME - ok 22:42:52.0211 1488 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 22:42:52.0211 1488 perc2 - ok 22:42:52.0391 1488 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 22:42:52.0401 1488 perc2hib - ok 22:42:52.0782 1488 Point32 (e4910ce9d882bf825979fcf4636a9bd8) C:\WINDOWS\system32\DRIVERS\point32.sys 22:42:52.0792 1488 Point32 - ok 22:42:53.0333 1488 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 22:42:53.0333 1488 PptpMiniport - ok 22:42:53.0503 1488 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 22:42:53.0503 1488 Processor - ok 22:42:53.0693 1488 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 22:42:53.0693 1488 PSched - ok 22:42:53.0853 1488 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 22:42:53.0863 1488 Ptilink - ok 22:42:54.0064 1488 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 22:42:54.0064 1488 ql1080 - ok 22:42:54.0234 1488 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 22:42:54.0234 1488 Ql10wnt - ok 22:42:54.0434 1488 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 22:42:54.0434 1488 ql12160 - ok 22:42:54.0604 1488 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 22:42:54.0604 1488 ql1240 - ok 22:42:54.0805 1488 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 22:42:54.0815 1488 ql1280 - ok 22:42:54.0975 1488 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 22:42:54.0975 1488 RasAcd - ok 22:42:55.0155 1488 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 22:42:55.0155 1488 Rasl2tp - ok 22:42:55.0326 1488 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 22:42:55.0326 1488 RasPppoe - ok 22:42:55.0656 1488 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 22:42:55.0656 1488 Raspti - ok 22:42:55.0836 1488 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 22:42:55.0836 1488 Rdbss - ok 22:42:56.0006 1488 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 22:42:56.0016 1488 RDPCDD - ok 22:42:56.0197 1488 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 22:42:56.0207 1488 rdpdr - ok 22:42:56.0407 1488 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 22:42:56.0407 1488 RDPWD - ok 22:42:56.0597 1488 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 22:42:56.0597 1488 redbook - ok 22:42:56.0798 1488 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 22:42:56.0798 1488 rtl8139 - ok 22:42:56.0988 1488 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 22:42:56.0988 1488 Secdrv - ok 22:42:57.0158 1488 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 22:42:57.0158 1488 serenum - ok 22:42:57.0328 1488 Serial (2d542f2eb1c958ee5f687d5aaf95aa23) C:\WINDOWS\system32\DRIVERS\serial.sys 22:42:57.0338 1488 Serial - ok 22:42:57.0529 1488 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 22:42:57.0529 1488 Sfloppy - ok 22:42:57.0679 1488 Simbad - ok 22:42:57.0769 1488 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 22:42:57.0769 1488 sisagp - ok 22:42:57.0939 1488 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 22:42:57.0939 1488 SLIP - ok 22:42:58.0160 1488 smwdm (b911c822922cf62df83ad36d5c9775cc) C:\WINDOWS\system32\drivers\smwdm.sys 22:42:58.0190 1488 smwdm - ok 22:42:58.0360 1488 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 22:42:58.0360 1488 Sparrow - ok 22:42:58.0730 1488 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 22:42:58.0730 1488 splitter - ok 22:42:58.0911 1488 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 22:42:58.0911 1488 sr - ok 22:42:59.0451 1488 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 22:42:59.0461 1488 Srv - ok 22:42:59.0632 1488 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 22:42:59.0632 1488 streamip - ok 22:42:59.0792 1488 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 22:42:59.0792 1488 swenum - ok 22:42:59.0952 1488 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 22:42:59.0962 1488 swmidi - ok 22:43:00.0132 1488 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 22:43:00.0132 1488 symc810 - ok 22:43:00.0303 1488 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 22:43:00.0303 1488 symc8xx - ok 22:43:00.0683 1488 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 22:43:00.0683 1488 sym_hi - ok 22:43:00.0853 1488 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 22:43:00.0853 1488 sym_u3 - ok 22:43:01.0064 1488 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 22:43:01.0074 1488 sysaudio - ok 22:43:01.0274 1488 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 22:43:01.0294 1488 Tcpip - ok 22:43:01.0474 1488 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 22:43:01.0474 1488 TDPIPE - ok 22:43:01.0645 1488 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 22:43:01.0645 1488 TDTCP - ok 22:43:01.0815 1488 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 22:43:01.0815 1488 TermDD - ok 22:43:01.0995 1488 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 22:43:01.0995 1488 TosIde - ok 22:43:02.0175 1488 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 22:43:02.0175 1488 Udfs - ok 22:43:02.0336 1488 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 22:43:02.0336 1488 ultra - ok 22:43:02.0586 1488 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 22:43:02.0606 1488 Update - ok 22:43:02.0776 1488 usb20l (153bd85234f7f1d37dd5fe7df64b528b) C:\WINDOWS\system32\DRIVERS\SMC2209.sys 22:43:02.0776 1488 usb20l - ok 22:43:02.0946 1488 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 22:43:02.0946 1488 usbaudio - ok 22:43:03.0127 1488 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 22:43:03.0127 1488 usbccgp - ok 22:43:03.0297 1488 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 22:43:03.0297 1488 usbehci - ok 22:43:03.0477 1488 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 22:43:03.0477 1488 usbhub - ok 22:43:03.0647 1488 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 22:43:03.0647 1488 usbohci - ok 22:43:03.0808 1488 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 22:43:03.0818 1488 usbprint - ok 22:43:03.0998 1488 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 22:43:03.0998 1488 usbscan - ok 22:43:04.0168 1488 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 22:43:04.0168 1488 USBSTOR - ok 22:43:04.0338 1488 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 22:43:04.0338 1488 usbuhci - ok 22:43:04.0519 1488 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 22:43:04.0519 1488 usbvideo - ok 22:43:04.0689 1488 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 22:43:04.0689 1488 VgaSave - ok 22:43:04.0879 1488 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 22:43:04.0879 1488 viaagp - ok 22:43:05.0070 1488 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 22:43:05.0070 1488 ViaIde - ok 22:43:05.0250 1488 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 22:43:05.0250 1488 VolSnap - ok 22:43:05.0430 1488 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:43:05.0430 1488 Wanarp - ok 22:43:05.0580 1488 WDICA - ok 22:43:05.0761 1488 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 22:43:05.0761 1488 wdmaud - ok 22:43:06.0001 1488 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 22:43:06.0001 1488 WSTCODEC - ok 22:43:06.0161 1488 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 22:43:06.0171 1488 WudfPf - ok 22:43:06.0321 1488 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 22:43:06.0331 1488 WudfRd - ok 22:43:06.0391 1488 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 22:43:06.0512 1488 \Device\Harddisk0\DR0 - ok 22:43:06.0522 1488 Boot (0x1200) (d131577988860e90e96e774e06f4ca19) \Device\Harddisk0\DR0\Partition0 22:43:06.0522 1488 \Device\Harddisk0\DR0\Partition0 - ok 22:43:06.0522 1488 ============================================================ 22:43:06.0522 1488 Scan finished 22:43:06.0522 1488 ============================================================ 22:43:06.0552 2252 Detected object count: 0 22:43:06.0552 2252 Actual detected object count: 0 22:43:25.0038 2180 ============================================================ 22:43:25.0038 2180 Scan started 22:43:25.0038 2180 Mode: Manual; 22:43:25.0038 2180 ============================================================ 22:43:25.0529 2180 Abiosdsk - ok 22:43:25.0709 2180 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 22:43:25.0709 2180 abp480n5 - ok 22:43:25.0889 2180 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys 22:43:25.0889 2180 ac97intc - ok 22:43:26.0060 2180 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 22:43:26.0070 2180 ACPI - ok 22:43:26.0270 2180 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 22:43:26.0270 2180 ACPIEC - ok 22:43:26.0450 2180 ADM8511 (b05f2367f62552a2de7e3c352b7b9885) C:\WINDOWS\system32\DRIVERS\ADM8511.SYS 22:43:26.0450 2180 ADM8511 - ok 22:43:26.0631 2180 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 22:43:26.0631 2180 adpu160m - ok 22:43:26.0831 2180 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 22:43:26.0841 2180 aec - ok 22:43:27.0041 2180 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 22:43:27.0041 2180 AFD - ok 22:43:27.0241 2180 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 22:43:27.0241 2180 agp440 - ok 22:43:27.0412 2180 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 22:43:27.0412 2180 agpCPQ - ok 22:43:27.0602 2180 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 22:43:27.0602 2180 Aha154x - ok 22:43:27.0772 2180 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 22:43:27.0772 2180 aic78u2 - ok 22:43:27.0962 2180 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 22:43:27.0962 2180 aic78xx - ok 22:43:28.0153 2180 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 22:43:28.0153 2180 AliIde - ok 22:43:28.0333 2180 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 22:43:28.0333 2180 alim1541 - ok 22:43:28.0523 2180 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 22:43:28.0523 2180 amdagp - ok 22:43:28.0693 2180 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 22:43:28.0693 2180 amsint - ok 22:43:28.0914 2180 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 22:43:28.0914 2180 Arp1394 - ok 22:43:29.0094 2180 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 22:43:29.0094 2180 asc - ok 22:43:29.0264 2180 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 22:43:29.0264 2180 asc3350p - ok 22:43:29.0435 2180 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 22:43:29.0435 2180 asc3550 - ok 22:43:29.0695 2180 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 22:43:29.0695 2180 AsyncMac - ok 22:43:29.0865 2180 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 22:43:29.0865 2180 atapi - ok 22:43:30.0025 2180 Atdisk - ok 22:43:30.0236 2180 ati2mtaa (2d030c2f6b036ca0bc243e1b16d924d1) C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys 22:43:30.0236 2180 ati2mtaa - ok 22:43:30.0466 2180 ati2mtag (8759322ffc1a50569c1e5528ee8026b7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 22:43:30.0476 2180 ati2mtag - ok 22:43:30.0666 2180 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 22:43:30.0666 2180 Atmarpc - ok 22:43:30.0837 2180 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 22:43:30.0837 2180 audstub - ok 22:43:31.0027 2180 b57w2k (48bf91cffbcdd12a710207f2a08fec4d) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 22:43:31.0027 2180 b57w2k - ok 22:43:31.0217 2180 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 22:43:31.0217 2180 Beep - ok 22:43:31.0277 2180 catchme - ok 22:43:31.0488 2180 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 22:43:31.0488 2180 cbidf - ok 22:43:31.0678 2180 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 22:43:31.0678 2180 cbidf2k - ok 22:43:31.0848 2180 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 22:43:31.0848 2180 CCDECODE - ok 22:43:32.0028 2180 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 22:43:32.0028 2180 cd20xrnt - ok 22:43:32.0229 2180 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 22:43:32.0229 2180 Cdaudio - ok 22:43:32.0419 2180 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 22:43:32.0419 2180 Cdfs - ok 22:43:32.0609 2180 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 22:43:32.0609 2180 Cdrom - ok 22:43:32.0769 2180 Changer - ok 22:43:32.0920 2180 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 22:43:32.0920 2180 CmdIde - ok 22:43:33.0140 2180 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 22:43:33.0150 2180 Cpqarray - ok 22:43:33.0350 2180 ctac32k (a5e67327b49e1f4341d470d8bbcbc401) C:\WINDOWS\system32\drivers\ctac32k.sys 22:43:33.0350 2180 ctac32k - ok 22:43:33.0550 2180 ctdvda2k (29f78d59b053cb8778f8426e4e24099c) C:\WINDOWS\system32\drivers\ctdvda2k.sys 22:43:33.0550 2180 ctdvda2k - ok 22:43:33.0731 2180 ctprxy2k (c7fc5d87b06207a5d34697b627826618) C:\WINDOWS\system32\drivers\ctprxy2k.sys 22:43:33.0731 2180 ctprxy2k - ok 22:43:33.0911 2180 ctsfm2k (2c0af71cf0e1224a2dfc2b67e63b02b1) C:\WINDOWS\system32\drivers\ctsfm2k.sys 22:43:33.0911 2180 ctsfm2k - ok 22:43:34.0091 2180 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 22:43:34.0091 2180 dac2w2k - ok 22:43:34.0272 2180 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 22:43:34.0272 2180 dac960nt - ok 22:43:34.0512 2180 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 22:43:34.0512 2180 Disk - ok 22:43:34.0732 2180 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 22:43:34.0742 2180 dmboot - ok 22:43:34.0932 2180 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 22:43:34.0932 2180 dmio - ok 22:43:35.0103 2180 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 22:43:35.0103 2180 dmload - ok 22:43:35.0303 2180 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 22:43:35.0303 2180 DMusic - ok 22:43:35.0513 2180 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 22:43:35.0513 2180 dpti2o - ok 22:43:35.0724 2180 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 22:43:35.0724 2180 drmkaud - ok 22:43:35.0904 2180 E1000 (3573259a15281a670f392f59b1c09f3d) C:\WINDOWS\system32\DRIVERS\e1000325.sys 22:43:35.0904 2180 E1000 - ok 22:43:36.0134 2180 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys 22:43:36.0134 2180 EL90XBC - ok 22:43:36.0314 2180 emupia (091d37e0f5193f708c9006b1f2e23ee4) C:\WINDOWS\system32\drivers\emupia2k.sys 22:43:36.0314 2180 emupia - ok 22:43:36.0505 2180 es1371 (a55dd7d8ced5d2624a9ee2dda7be0319) C:\WINDOWS\system32\drivers\es1371mp.sys 22:43:36.0505 2180 es1371 - ok 22:43:36.0705 2180 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 22:43:36.0715 2180 Fastfat - ok 22:43:36.0915 2180 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 22:43:36.0915 2180 Fdc - ok 22:43:37.0096 2180 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 22:43:37.0106 2180 Fips - ok 22:43:37.0286 2180 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 22:43:37.0286 2180 Flpydisk - ok 22:43:37.0496 2180 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 22:43:37.0496 2180 FltMgr - ok 22:43:37.0686 2180 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 22:43:37.0686 2180 Fs_Rec - ok 22:43:37.0877 2180 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 22:43:37.0877 2180 Ftdisk - ok 22:43:38.0057 2180 GEARAspiWDM (4ac51459805264affd5f6fdfb9d9235f) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 22:43:38.0057 2180 GEARAspiWDM - ok 22:43:38.0227 2180 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 22:43:38.0227 2180 Gpc - ok 22:43:38.0478 2180 ha10kx2k (1ad88bcf3d043baa58c15eb262625f9b) C:\WINDOWS\system32\drivers\ha10kx2k.sys 22:43:38.0488 2180 ha10kx2k - ok 22:43:38.0648 2180 hap16v2k (8ff42f63c722a1dd4c91ff6a497fd6b2) C:\WINDOWS\system32\drivers\hap16v2k.sys 22:43:38.0648 2180 hap16v2k - ok 22:43:38.0838 2180 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 22:43:38.0838 2180 HDAudBus - ok 22:43:39.0058 2180 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 22:43:39.0058 2180 HidUsb - ok 22:43:39.0249 2180 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 22:43:39.0249 2180 hpn - ok 22:43:39.0439 2180 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 22:43:39.0439 2180 HTTP - ok 22:43:39.0629 2180 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 22:43:39.0629 2180 i2omgmt - ok 22:43:39.0819 2180 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 22:43:39.0819 2180 i2omp - ok 22:43:40.0000 2180 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 22:43:40.0000 2180 i8042prt - ok 22:43:40.0190 2180 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 22:43:40.0190 2180 Imapi - ok 22:43:40.0380 2180 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 22:43:40.0380 2180 ini910u - ok 22:43:40.0591 2180 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 22:43:40.0591 2180 IntelIde - ok 22:43:40.0771 2180 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 22:43:40.0771 2180 intelppm - ok 22:43:40.0951 2180 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 22:43:40.0951 2180 Ip6Fw - ok 22:43:41.0091 2180 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 22:43:41.0091 2180 IpFilterDriver - ok 22:43:41.0272 2180 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 22:43:41.0272 2180 IpInIp - ok 22:43:41.0442 2180 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 22:43:41.0442 2180 IpNat - ok 22:43:41.0642 2180 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 22:43:41.0642 2180 IPSec - ok 22:43:41.0812 2180 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 22:43:41.0812 2180 IRENUM - ok 22:43:41.0983 2180 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 22:43:41.0983 2180 isapnp - ok 22:43:42.0163 2180 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 22:43:42.0173 2180 Kbdclass - ok 22:43:42.0353 2180 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 22:43:42.0353 2180 kbdhid - ok 22:43:42.0543 2180 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 22:43:42.0543 2180 kmixer - ok 22:43:42.0764 2180 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 22:43:42.0764 2180 KSecDD - ok 22:43:42.0934 2180 lbrtfdc - ok 22:43:43.0124 2180 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 22:43:43.0124 2180 mnmdd - ok 22:43:43.0315 2180 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 22:43:43.0315 2180 Modem - ok 22:43:43.0495 2180 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 22:43:43.0495 2180 Mouclass - ok 22:43:43.0685 2180 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 22:43:43.0685 2180 mouhid - ok 22:43:43.0885 2180 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 22:43:43.0885 2180 MountMgr - ok 22:43:44.0066 2180 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 22:43:44.0066 2180 mraid35x - ok 22:43:44.0236 2180 MRxDAV (e3f17e1ea5256709d4e97ef0da04b3c9) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 22:43:44.0236 2180 MRxDAV - ok 22:43:44.0436 2180 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 22:43:44.0446 2180 MRxSmb - ok 22:43:44.0656 2180 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 22:43:44.0656 2180 Msfs - ok 22:43:44.0847 2180 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 22:43:44.0847 2180 MSKSSRV - ok 22:43:45.0037 2180 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 22:43:45.0037 2180 MSPCLOCK - ok 22:43:45.0197 2180 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 22:43:45.0197 2180 MSPQM - ok 22:43:45.0387 2180 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 22:43:45.0387 2180 mssmbios - ok 22:43:45.0558 2180 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 22:43:45.0558 2180 MSTEE - ok 22:43:45.0738 2180 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 22:43:45.0738 2180 Mup - ok 22:43:45.0918 2180 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 22:43:45.0918 2180 NABTSFEC - ok 22:43:46.0129 2180 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 22:43:46.0129 2180 NDIS - ok 22:43:46.0319 2180 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 22:43:46.0319 2180 NdisIP - ok 22:43:46.0489 2180 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 22:43:46.0489 2180 NdisTapi - ok 22:43:46.0679 2180 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 22:43:46.0679 2180 Ndisuio - ok 22:43:46.0870 2180 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 22:43:46.0870 2180 NdisWan - ok 22:43:47.0050 2180 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 22:43:47.0050 2180 NDProxy - ok 22:43:47.0220 2180 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 22:43:47.0220 2180 NetBIOS - ok 22:43:47.0410 2180 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 22:43:47.0410 2180 NetBT - ok 22:43:47.0651 2180 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 22:43:47.0661 2180 NIC1394 - ok 22:43:47.0841 2180 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 22:43:47.0841 2180 Npfs - ok 22:43:48.0041 2180 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 22:43:48.0041 2180 Ntfs - ok 22:43:48.0252 2180 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 22:43:48.0252 2180 Null - ok 22:43:48.0542 2180 nv (c7993894984c271e49381cc649cdf8bd) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 22:43:48.0572 2180 nv - ok 22:43:48.0752 2180 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 22:43:48.0752 2180 NwlnkFlt - ok 22:43:48.0913 2180 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 22:43:48.0913 2180 NwlnkFwd - ok 22:43:49.0083 2180 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 22:43:49.0093 2180 ohci1394 - ok 22:43:49.0293 2180 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 22:43:49.0293 2180 P3 - ok 22:43:49.0473 2180 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 22:43:49.0473 2180 Parport - ok 22:43:49.0654 2180 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 22:43:49.0654 2180 PartMgr - ok 22:43:49.0824 2180 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 22:43:49.0824 2180 ParVdm - ok 22:43:49.0984 2180 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 22:43:49.0984 2180 PCI - ok 22:43:50.0134 2180 PCIDump - ok 22:43:50.0295 2180 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 22:43:50.0295 2180 PCIIde - ok 22:43:50.0475 2180 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 22:43:50.0475 2180 Pcmcia - ok 22:43:50.0615 2180 PDCOMP - ok 22:43:50.0695 2180 PDFRAME - ok 22:43:50.0775 2180 PDRELI - ok 22:43:50.0845 2180 PDRFRAME - ok 22:43:50.0935 2180 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 22:43:50.0945 2180 perc2 - ok 22:43:51.0136 2180 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 22:43:51.0136 2180 perc2hib - ok 22:43:51.0376 2180 Point32 (e4910ce9d882bf825979fcf4636a9bd8) C:\WINDOWS\system32\DRIVERS\point32.sys 22:43:51.0376 2180 Point32 - ok 22:43:51.0556 2180 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 22:43:51.0556 2180 PptpMiniport - ok 22:43:51.0737 2180 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 22:43:51.0737 2180 Processor - ok 22:43:51.0927 2180 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 22:43:51.0927 2180 PSched - ok 22:43:52.0127 2180 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 22:43:52.0127 2180 Ptilink - ok 22:43:52.0297 2180 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 22:43:52.0297 2180 ql1080 - ok 22:43:52.0478 2180 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 22:43:52.0478 2180 Ql10wnt - ok 22:43:52.0648 2180 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 22:43:52.0658 2180 ql12160 - ok 22:43:52.0808 2180 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 22:43:52.0808 2180 ql1240 - ok 22:43:52.0988 2180 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 22:43:52.0988 2180 ql1280 - ok 22:43:53.0169 2180 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 22:43:53.0169 2180 RasAcd - ok 22:43:53.0339 2180 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 22:43:53.0349 2180 Rasl2tp - ok 22:43:53.0539 2180 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 22:43:53.0539 2180 RasPppoe - ok 22:43:53.0699 2180 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 22:43:53.0699 2180 Raspti - ok 22:43:53.0910 2180 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 22:43:53.0910 2180 Rdbss - ok 22:43:54.0090 2180 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 22:43:54.0090 2180 RDPCDD - ok 22:43:54.0280 2180 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 22:43:54.0280 2180 rdpdr - ok 22:43:54.0491 2180 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 22:43:54.0501 2180 RDPWD - ok 22:43:54.0671 2180 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 22:43:54.0671 2180 redbook - ok 22:43:54.0901 2180 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 22:43:54.0901 2180 rtl8139 - ok 22:43:55.0121 2180 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 22:43:55.0121 2180 Secdrv - ok 22:43:55.0322 2180 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 22:43:55.0322 2180 serenum - ok 22:43:55.0512 2180 Serial (2d542f2eb1c958ee5f687d5aaf95aa23) C:\WINDOWS\system32\DRIVERS\serial.sys 22:43:55.0512 2180 Serial - ok 22:43:55.0762 2180 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 22:43:55.0762 2180 Sfloppy - ok 22:43:55.0943 2180 Simbad - ok 22:43:56.0053 2180 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 22:43:56.0053 2180 sisagp - ok 22:43:56.0223 2180 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 22:43:56.0223 2180 SLIP - ok 22:43:56.0433 2180 smwdm (b911c822922cf62df83ad36d5c9775cc) C:\WINDOWS\system32\drivers\smwdm.sys 22:43:56.0443 2180 smwdm - ok 22:43:56.0624 2180 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 22:43:56.0624 2180 Sparrow - ok 22:43:56.0814 2180 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 22:43:56.0814 2180 splitter - ok 22:43:57.0014 2180 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 22:43:57.0014 2180 sr - ok 22:43:57.0225 2180 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 22:43:57.0235 2180 Srv - ok 22:43:57.0435 2180 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 22:43:57.0435 2180 streamip - ok 22:43:57.0605 2180 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 22:43:57.0605 2180 swenum - ok 22:43:57.0795 2180 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 22:43:57.0795 2180 swmidi - ok 22:43:57.0996 2180 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 22:43:57.0996 2180 symc810 - ok 22:43:58.0176 2180 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 22:43:58.0176 2180 symc8xx - ok 22:43:58.0356 2180 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 22:43:58.0356 2180 sym_hi - ok 22:43:58.0536 2180 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 22:43:58.0536 2180 sym_u3 - ok 22:43:58.0727 2180 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 22:43:58.0727 2180 sysaudio - ok 22:43:58.0947 2180 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 22:43:58.0947 2180 Tcpip - ok 22:43:59.0117 2180 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 22:43:59.0117 2180 TDPIPE - ok 22:43:59.0287 2180 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 22:43:59.0287 2180 TDTCP - ok 22:43:59.0478 2180 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 22:43:59.0478 2180 TermDD - ok 22:43:59.0708 2180 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 22:43:59.0708 2180 TosIde - ok 22:43:59.0918 2180 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 22:43:59.0918 2180 Udfs - ok 22:44:00.0119 2180 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 22:44:00.0119 2180 ultra - ok 22:44:00.0319 2180 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 22:44:00.0329 2180 Update - ok 22:44:00.0509 2180 usb20l (153bd85234f7f1d37dd5fe7df64b528b) C:\WINDOWS\system32\DRIVERS\SMC2209.sys 22:44:00.0509 2180 usb20l - ok 22:44:00.0700 2180 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 22:44:00.0700 2180 usbaudio - ok 22:44:00.0860 2180 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 22:44:00.0870 2180 usbccgp - ok 22:44:01.0050 2180 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 22:44:01.0050 2180 usbehci - ok 22:44:01.0240 2180 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 22:44:01.0240 2180 usbhub - ok 22:44:01.0431 2180 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 22:44:01.0431 2180 usbohci - ok 22:44:01.0611 2180 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 22:44:01.0621 2180 usbprint - ok 22:44:01.0801 2180 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 22:44:01.0801 2180 usbscan - ok 22:44:01.0971 2180 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 22:44:01.0971 2180 USBSTOR - ok 22:44:02.0142 2180 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 22:44:02.0142 2180 usbuhci - ok 22:44:02.0332 2180 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 22:44:02.0332 2180 usbvideo - ok 22:44:02.0512 2180 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 22:44:02.0512 2180 VgaSave - ok 22:44:02.0692 2180 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 22:44:02.0692 2180 viaagp - ok 22:44:02.0863 2180 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 22:44:02.0863 2180 ViaIde - ok 22:44:03.0023 2180 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 22:44:03.0023 2180 VolSnap - ok 22:44:03.0273 2180 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:44:03.0273 2180 Wanarp - ok 22:44:03.0423 2180 WDICA - ok 22:44:03.0594 2180 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 22:44:03.0594 2180 wdmaud - ok 22:44:04.0034 2180 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 22:44:04.0044 2180 WSTCODEC - ok 22:44:04.0215 2180 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 22:44:04.0225 2180 WudfPf - ok 22:44:04.0425 2180 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 22:44:04.0425 2180 WudfRd - ok 22:44:04.0585 2180 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 22:44:04.0725 2180 \Device\Harddisk0\DR0 - ok 22:44:04.0745 2180 Boot (0x1200) (d131577988860e90e96e774e06f4ca19) \Device\Harddisk0\DR0\Partition0 22:44:04.0745 2180 \Device\Harddisk0\DR0\Partition0 - ok 22:44:04.0755 2180 ============================================================ 22:44:04.0755 2180 Scan finished 22:44:04.0755 2180 ============================================================ 22:44:04.0805 0216 Detected object count: 0 22:44:04.0805 0216 Actual detected object count: 0
Hi leeleecm,


We will use Virustotal to analys a file.

To submit a file to virustotal, please click on this link VirusTotal

copy and paste the following into the upload a file box (if you can't copy and paste the file path then use the browse button)

C:\WINDOWS\system32\drivers\serial.sys



scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed.




Next


Download OTL to your desktop.

  • Double click on OTL.exe to run it
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following



    /md5start
    serial.*
    consrv.dll
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • VirusTotal results
  • OTL.txt
Thanks
serial.sys
Submission date: 2011-12-22 13:49:25 (UTC)
Current status: queued (#3) queued (#3) analysing finished


Result: 29/ 43 (67.4%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.12.19.03 2011.12.19 Dropper/Win32.Tdss
AntiVir 7.11.19.240 2011.12.22 TR/Rootkit.Gen2
Antiy-AVL 2.0.3.7 2011.12.20 Trojan/win32.agent.gen
Avast 6.0.1289.0 2011.12.22 Win32:Aluroot [Rtk]
AVG 10.0.0.1190 2011.12.20 Hider.OOW
BitDefender 7.2 2011.12.20 Trojan.Generic.KDV.481640
ByteHero 1.0.0.1 2011.12.07 -
CAT-QuickHeal 12.00 2011.12.20 -
ClamAV 0.97.3.0 2011.12.20 -
Commtouch 5.3.2.6 2011.12.20 W32/FakeAlert.RL.gen!Eldorado
Comodo 11025 2011.12.20 UnclassifiedMalware
DrWeb 5.0.2.03300 2011.12.20 -
Emsisoft 5.1.0.11 2011.12.20 Trojan-Dropper.Win32.Sirefef!IK
eSafe 7.0.17.0 2011.12.20 Win32.TRRootkit
eTrust-Vet 37.0.9639 2011.12.22 -
F-Prot 4.6.5.141 2011.12.19 W32/FakeAlert.RL.gen!Eldorado
F-Secure 9.0.16440.0 2011.12.20 Trojan.Generic.KDV.481640
Fortinet 4.3.388.0 2011.12.20 W32/ZAccess.K!tr.rkit
GData 22.312/22.592 2011.12.20 Trojan.Generic.KDV.481640
Ikarus T3.1.1.109.0 2011.12.22 Rootkit.Win32.ZAccess
Jiangmin 13.0.900 2011.12.21 -
K7AntiVirus 9.119.5720 2011.12.19 Riskware
Kaspersky 9.0.0.837 2011.12.22 HEUR:Trojan.Win32.Generic
McAfee 5.400.0.1158 2011.12.20 Generic.dx!bcgq
McAfee-GW-Edition 2010.1E 2011.12.22 Generic.dx!bcgq
Microsoft 1.7903 2011.12.20 -
NOD32 6726 2011.12.20 Win32/Sirefef.DA
Norman 6.07.13 2011.12.22 W32/Suspicious_Gen2.UCIXB
nProtect 2011-12-20.02 2011.12.20 -
Panda 10.0.3.5 2011.12.19 Trj/CI.A
PCTools 8.0.0.5 2011.12.22 Hacktool.Rootkit
Prevx 3.0 2011.12.22 -
Rising 23.89.03.02 2011.12.22 -
Sophos 4.72.0 2011.12.20 Mal/EncPk-AAL
SUPERAntiSpyware 4.40.0.1006 2011.12.22 Trojan.Agent/Gen-Sirefef
Symantec 20111.2.0.82 2011.12.22 Hacktool.Rootkit
TheHacker 6.7.0.1.362 2011.12.22 -
TrendMicro 9.500.0.1008 2011.12.22 RTKT_ZACCESS.H
TrendMicro-HouseCall 9.500.0.1008 2011.12.22 RTKT_ZACCESS.H
VBA32 3.12.16.4 2011.12.22 -
VIPRE 11288 2011.12.22 Trojan.FakeAlert
ViRobot 2011.12.22.4841 2011.12.22 -
VirusBuster 14.1.129.0 2011.12.22 -
Additional informationShow all
MD5 : 2d542f2eb1c958ee5f687d5aaf95aa23
SHA1 : cd6f3145e6a13f29075d7ab72ab950fe50f8cc8b
SHA256: a34489b2b027832c30d84a723256a2a6136733aacedf4a39e2622cc028fec2e9



OTL logfile created on: 12/22/2011 9:04:06 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)

1022.99 Mb Total Physical Memory | 525.12 Mb Available Physical Memory | 51.33% Memory free
2.75 Gb Paging File | 2.33 Gb Available in Paging File | 84.47% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 44.01 Gb Free Space | 59.11% Space Free | Partition Type: NTFS

Computer Name: DELL | .
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========



< MD5 for: SERIAL.SY_ >
[2004/08/03 22:15:54 | 000,030,067 | —- | M] () MD5=56A1F7591D17ECD1C5F60DABD2FA6B61 – C:\cmdcons\SERIAL.SY_

< MD5 for: SERIAL.SYS >
[2008/04/13 23:45:46 | 000,064,512 | —- | M] () MD5=2D542F2EB1C958EE5F687D5AAF95AA23 – C:\WINDOWS\system32\drivers\serial.sys
[2008/04/13 23:45:46 | 000,064,512 | —- | M] (Microsoft Corporation) MD5=CCA207A8896D4C6A0C9CE29A4AE411A7 – C:\WINDOWS\ServicePackFiles\i386\serial.sys
[2004/08/03 22:15:54 | 000,064,896 | —- | M] (Microsoft Corporation) MD5=CD9404D115A00D249F70A371B46D5A26 – C:\WINDOWS\$NtServicePackUninstall$\serial.sys

< End of report >
Hi leeleecm,

We'll use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

FCopy::
C:\WINDOWS\ServicePackFiles\i386\serial.sys | C:\WINDOWS\system32\drivers\serial.sys
C:\WINDOWS\ServicePackFiles\i386\serial.sys | c:\windows\system32\dllcache\serial.sys

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Please post the combofix log.

Next

Please rerun aswMBR.exe again.

Please post back with
  • combofix log
  • aswmbr log
How's the computer?

Thanks
ComboFix 11-12-22.03 - 12/22/2011 12:40:27.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.554 [GMT -5:00]
Running from: c:\documents and settings\\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ispcnerr.htm
c:\windows\system32\oobe\isperror\ispdtone.htm
c:\windows\system32\oobe\isperror\isphdshk.htm
c:\windows\system32\oobe\isperror\ispins.htm
c:\windows\system32\oobe\isperror\ispnoanw.htm
c:\windows\system32\oobe\isperror\isppberr.htm
c:\windows\system32\oobe\isperror\ispphbsy.htm
c:\windows\system32\oobe\isperror\ispsbusy.htm
.
.
————— FCopy —————
.
c:\windows\ServicePackFiles\i386\serial.sys –> c:\windows\system32\drivers\serial.sys
c:\windows\ServicePackFiles\i386\serial.sys –> c:\windows\system32\dllcache\serial.sys
.
((((((((((((((((((((((((( Files Created from 2011-11-22 to 2011-12-22 )))))))))))))))))))))))))))))))
.
.
2011-12-19 22:01 . 2011-12-19 22:01 388096 —-a-r- c:\documents and settings\Christy\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-19 22:01 . 2011-12-19 22:01 ——– d—–w- c:\program files\Trend Micro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-30 15:40 . 2004-08-04 03:15 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-23 13:25 . 2004-08-04 03:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2004-08-04 04:56 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 19:20 . 2004-08-04 04:56 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 04:56 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 11:23 . 2004-08-04 02:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-04 04:56 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 04:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2004-08-04 03:20 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-04 04:56 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2005-03-08 18:12 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 04:56 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 18:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2002-08-29 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2002-08-29 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2005-07-12 18:20 . 2005-07-21 14:08 1445888 —-a-w- c:\program files\WinsockFix.exe
2011-11-30 15:53 . 2005-03-08 19:30 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2011-11-30 15:53 . 2005-03-08 19:30 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2011-11-30 15:53 . 2006-11-17 15:46 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2011-11-30 15:53 . 2006-11-17 15:46 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2011-11-30 15:53 . 2005-03-08 19:30 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-19_21.16.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-03-08 18:20 . 2011-12-21 22:31 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-03-08 18:20 . 2011-11-25 16:31 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-03-08 18:20 . 2011-12-21 22:31 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-03-08 18:20 . 2011-11-25 16:31 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-12-21 22:31 . 2011-12-21 22:31 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-12-19 22:01 . 2011-12-19 22:01 1094656 c:\windows\Installer\2a9fb8.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dcc70a83-e184-40a3-906b-779af5e941c4}]
2010-11-11 18:55 87512 —-a-w- c:\program files\xfinitytb\xfinitydx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e6d0b79e-ecac-411b-8bf6-7a574981af30}]
2010-12-22 14:31 265176 —-a-w- c:\program files\xfinitytb\auxi\xfinityAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{dcc70a83-e184-40a3-906b-779af5e941c4}"= "c:\program files\xfinitytb\xfinitydx.dll" [2010-11-11 87512]
.
[HKEY_CLASSES_ROOT\clsid\{dcc70a83-e184-40a3-906b-779af5e941c4}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-25 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\READREG" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2002-12-18 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AsioReg"="CTASIO.DLL" [2003-11-13 126976]
"CTHelper"="CTHELPER.EXE" [2004-03-11 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-01-10 5513216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
"TSClientAXDisabler"="c:\windows\Installer\TSClientMsiTrans\tscdsbl.bat" [2008-01-19 2247]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-6 113664]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
.
[HKLM\~\startupfolder\C:^Documents and Settings^Christy^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Christy\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLRebootNeeded]
/s [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ComcastAntispyClient]
2009-08-19 17:25 1589208 —-a-w- c:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
2008-04-24 17:25 202560 —-a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
S2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [6/17/2009 12:49 PM 616408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2011 8:00 AM 136176]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [8/27/2006 11:02 AM 20160]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2011 8:00 AM 136176]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/3/2004 11:56 PM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 93545398
*NewlyCreated* - ASWMBR
*Deregistered* - 93545398
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
2011-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-15 12:59]
.
2011-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-15 12:59]
.
2011-12-19 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: worldwinner.com\www
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75
FF - ProfilePath - c:\documents and settings\Christy\Application Data\Mozilla\Firefox\Profiles\espu83qj.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.pitt.edu
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-22 12:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(648)
c:\program files\CA\PPRT\bin\CACheck.dll
c:\program files\CA\PPRT\bin\CAHook.dll
c:\program files\CA\PPRT\bin\CAServer.dll
.
Completion time: 2011-12-22 12:51:56
ComboFix-quarantined-files.txt 2011-12-22 17:51
ComboFix2.txt 2011-12-21 13:45
ComboFix3.txt 2011-11-30 20:42
ComboFix4.txt 2011-11-30 17:56
ComboFix5.txt 2011-12-22 17:39
.
Pre-Run: 47,237,550,080 bytes free
Post-Run: 47,531,700,224 bytes free
.
- - End Of File - - 2773403BA992DE8968FE64D01980E027







aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-21 16:45:41
—————————–
16:45:41.906 OS Version: Windows 5.1.2600 Service Pack 3
16:45:41.906 Number of processors: 1 586 0x207
16:45:41.906 ComputerName: DELL UserName:
16:45:44.329 Initialize success
16:48:17.570 AVAST engine defs: 11122102
16:49:31.446 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:49:31.446 Disk 0 Vendor: WDC_WD800BB-75CAA0 16.06V16 Size: 76293MB BusType: 3
16:49:33.479 Disk 0 MBR read successfully
16:49:33.479 Disk 0 MBR scan
16:49:33.559 Disk 0 Windows XP default MBR code
16:49:33.579 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63
16:49:33.589 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325
16:49:33.589 Disk 0 scanning sectors +156232125
16:49:33.659 Disk 0 scanning C:\WINDOWS\system32\drivers
16:49:46.017 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
16:49:49.762 Service scanning
16:49:54.008 Modules scanning
16:50:27.847 Disk 0 trace - called modules:
16:50:27.877 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
16:50:27.887 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x873d5030]
16:50:27.887 3 CLASSPNP.SYS[f7621fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8738fb00]
16:50:29.249 AVAST engine scan C:\WINDOWS
16:50:43.710 AVAST engine scan C:\WINDOWS\system32
16:53:56.116 AVAST engine scan C:\WINDOWS\system32\drivers
16:54:11.278 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
16:54:18.308 AVAST engine scan C:\Documents and Settings\Christy
17:00:57.572 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat"
17:00:57.572 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-21 16:45:41
—————————–
16:45:41.906 OS Version: Windows 5.1.2600 Service Pack 3
16:45:41.906 Number of processors: 1 586 0x207
16:45:41.906 ComputerName: DELL UserName:
16:45:44.329 Initialize success
16:48:17.570 AVAST engine defs: 11122102
16:49:31.446 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:49:31.446 Disk 0 Vendor: WDC_WD800BB-75CAA0 16.06V16 Size: 76293MB BusType: 3
16:49:33.479 Disk 0 MBR read successfully
16:49:33.479 Disk 0 MBR scan
16:49:33.559 Disk 0 Windows XP default MBR code
16:49:33.579 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63
16:49:33.589 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325
16:49:33.589 Disk 0 scanning sectors +156232125
16:49:33.659 Disk 0 scanning C:\WINDOWS\system32\drivers
16:49:46.017 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
16:49:49.762 Service scanning
16:49:54.008 Modules scanning
16:50:27.847 Disk 0 trace - called modules:
16:50:27.877 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
16:50:27.887 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x873d5030]
16:50:27.887 3 CLASSPNP.SYS[f7621fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8738fb00]
16:50:29.249 AVAST engine scan C:\WINDOWS
16:50:43.710 AVAST engine scan C:\WINDOWS\system32
16:53:56.116 AVAST engine scan C:\WINDOWS\system32\drivers
16:54:11.278 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
16:54:18.308 AVAST engine scan C:\Documents and Settings\Christy
17:00:57.572 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat"
17:00:57.572 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt"
17:09:33.054 AVAST engine scan C:\Documents and Settings\All Users
17:15:30.217 Scan finished successfully
21:28:45.657 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat"
21:28:45.657 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-22 12:57:05
—————————–
12:57:05.039 OS Version: Windows 5.1.2600 Service Pack 3
12:57:05.039 Number of processors: 1 586 0x207
12:57:05.039 ComputerName: DELL UserName:
12:57:05.510 Initialize success
12:57:38.567 AVAST engine defs: 11122200
12:58:49.820 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
12:58:49.820 Disk 0 Vendor: WDC_WD800BB-75CAA0 16.06V16 Size: 76293MB BusType: 3
12:58:51.863 Disk 0 MBR read successfully
12:58:51.863 Disk 0 MBR scan
12:58:51.913 Disk 0 Windows XP default MBR code
12:58:51.923 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 39 MB offset 63
12:58:51.953 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76245 MB offset 80325
12:58:51.953 Disk 0 scanning sectors +156232125
12:58:52.073 Disk 0 scanning C:\WINDOWS\system32\drivers
12:59:18.230 Service scanning
12:59:19.392 Modules scanning
13:00:01.092 Disk 0 trace - called modules:
13:00:01.112 ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
13:00:01.122 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x873d5030]
13:00:01.122 3 CLASSPNP.SYS[f7621fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8738fb00]
13:00:01.593 AVAST engine scan C:\WINDOWS
13:00:19.318 AVAST engine scan C:\WINDOWS\system32
13:04:50.418 AVAST engine scan C:\WINDOWS\system32\drivers
13:05:31.758 AVAST engine scan C:\Documents and Settings\Christy
13:20:02.710 AVAST engine scan C:\Documents and Settings\All Users
13:30:51.092 Scan finished successfully
15:42:28.368 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Christy\Desktop\MBR.dat"
15:42:28.398 The log file has been saved successfully to "C:\Documents and Settings\Christy\Desktop\aswMBR.txt"

Attachments:

Hi leeleecm,

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Next

One more to check our handiwork.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • MBAM log
  • Eset log if there is one
  • Both OTL logs
Any issues?
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122303 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/22/2011 11:09:35 PM mbam-log-2011-12-22 (23-09-35).txt Scan type: Quick scan Objects scanned: 180911 Time elapsed: 7 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\serial.sys.vir Win32/Sirefef.DA trojan C:\System Volume Information\_restore{265147A3-4543-402F-8745-8FEB36371031}\RP1139\A0055626.sys Win32/Sirefef.DA trojan Here are the first two. I still have to run the OTL. Christmas festivities have me tied up and I don't want the thread to be closed. I'll post it asap. Thanks!
OTL logfile created on: 12/27/2011 11:55:43 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Christy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.99 Mb Total Physical Memory | 648.97 Mb Available Physical Memory | 63.44% Memory free
2.69 Gb Paging File | 2.30 Gb Available in Paging File | 85.61% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 44.34 Gb Free Space | 59.55% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: Christy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Christy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MAXA Cookie Manager\Cookie.exe (MAXA Research Int'l Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\MAXA Cookie Manager\sqlite3_engine.dll ()
MOD - C:\Program Files\Lexmark 1200 Series\ConvDIB.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXCZPP5C.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (TermService) – File not found
SRV - (AntiSpywareService) – C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (ITMRTSVC) – C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ati2mtaa) – C:\WINDOWS\system32\drivers\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (emupia) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\HA10KX2K.SYS (Creative Technology Ltd)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\CTDVDA2K.SYS (Creative Technology Ltd)
DRV - (usb20l) – C:\WINDOWS\system32\drivers\SMC2209.sys (SMC Networks)
DRV - (ADM8511) – C:\WINDOWS\system32\drivers\ADM8511.SYS (ADMtek Incorporated)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.pitt.edu"

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/30 10:53:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/09 20:45:36 | 000,000,000 | —D | M]

[2011/11/30 10:28:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Christy\Application Data\Mozilla\Firefox\Profiles\espu83qj.default\extensions
[2009/09/10 08:11:55 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Christy\Application Data\Mozilla\Firefox\Profiles\espu83qj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/30 11:49:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/30 10:53:53 | 000,000,000 | —D | M] (Talkback) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/11/30 10:53:42 | 000,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jar50.dll
[2011/11/30 10:53:42 | 000,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jsd3250.dll
[2011/11/30 10:53:42 | 000,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\myspell.dll
[2011/11/30 10:53:44 | 000,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\spellchk.dll
[2011/11/30 10:53:44 | 000,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\xpinstal.dll
[2007/07/10 08:18:10 | 000,069,632 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npitunes.dll
[2006/11/09 15:20:40 | 002,111,096 | —- | M] () – C:\Program Files\mozilla firefox\plugins\NPSWF32.dll
[2010/10/06 09:51:30 | 000,003,277 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\xfinitylcsearch.xml

O1 HOSTS File: ([2011/12/22 12:48:15 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Xfinity.com Toolbar) - {dcc70a83-e184-40a3-906b-779af5e941c4} - C:\Program Files\xfinitytb\xfinitydx.dll ()
O2 - BHO: (Updater For Xfinity.com Toolbar 3.5) - {e6d0b79e-ecac-411b-8bf6-7a574981af30} - C:\Program Files\xfinitytb\auxi\xfinityAu.dll (Visicom Media)
O3 - HKLM\..\Toolbar: (Xfinity.com Toolbar) - {dcc70a83-e184-40a3-906b-779af5e941c4} - C:\Program Files\xfinitytb\xfinitydx.dll ()
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DevconDefaultDB] C:\WINDOWS\READREG.exe (Creative Technology Limited)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Lexmark 1200 Series] C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: worldwinner.com ([www] https in Trusted sites)
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=48835 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://msn.worldwinner.com/games/v47/share…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1264810411350 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1264810395457 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} http://www.worldwinner.com/games/v41/hangman/hangman.cab (Hangman Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} http://www.worldwinner.com/games/v52/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} http://www.worldwinner.com/games/v43/paint/paint.cab (Paint Control)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FCE62234-DF99-45A7-AB2E-70B096D7893B}: DhcpNameServer = 75.75.76.76 75.75.75.75
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Christy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Christy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/03 13:53:05 | 000,000,007 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 12:57:02 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/22 12:51:58 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/12/22 09:02:18 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Christy\Desktop\OTL.exe
[2011/12/21 22:39:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Christy\Desktop\tdsskiller
[2011/12/21 16:45:17 | 001,917,952 | —- | C] (AVAST Software) – C:\Documents and Settings\Christy\Desktop\aswMBR.exe
[2011/12/19 17:01:46 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/12/19 17:01:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Christy\Start Menu\Programs\HiJackThis
[2011/11/30 11:42:50 | 004,348,831 | R— | C] (Swearware) – C:\Documents and Settings\Christy\Desktop\ComboFix.exe
[2011/11/30 10:31:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/11/30 10:31:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2005/07/21 09:08:02 | 001,445,888 | —- | C] (Option^Explicit Software Solutions) – C:\Program Files\WinsockFix.exe
[2003/03/14 04:33:00 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\KILLAPPS.EXE
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/27 11:31:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/27 01:31:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/23 11:52:41 | 000,000,490 | —- | M] () – C:\WINDOWS\lexstat.ini
[2011/12/22 12:48:15 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/22 12:38:05 | 004,348,831 | R— | M] (Swearware) – C:\Documents and Settings\Christy\Desktop\ComboFix.exe
[2011/12/22 10:59:46 | 000,350,359 | —- | M] () – C:\Documents and Settings\Christy\My Documents\craft.jpg
[2011/12/22 09:02:47 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Christy\Desktop\OTL.exe
[2011/12/21 22:39:51 | 001,557,791 | —- | M] () – C:\Documents and Settings\Christy\Desktop\tdsskiller.zip
[2011/12/21 16:45:24 | 001,917,952 | —- | M] (AVAST Software) – C:\Documents and Settings\Christy\Desktop\aswMBR.exe
[2011/12/20 18:42:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/19 17:02:03 | 000,002,451 | —- | M] () – C:\Documents and Settings\Christy\Desktop\HiJackThis.lnk
[2011/12/19 16:16:09 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/12/19 16:15:43 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/19 16:15:39 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/12/19 16:15:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/19 16:15:29 | 1072,750,592 | -HS- | M] () – C:\hiberfil.sys
[2011/12/19 15:43:47 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/19 13:46:15 | 000,017,722 | -HS- | M] () – C:\Documents and Settings\Christy\Local Settings\Application Data\xkauaw4c4aac1fwy6vnt0t741v2b
[2011/12/19 13:46:15 | 000,017,722 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\xkauaw4c4aac1fwy6vnt0t741v2b
[2011/12/19 10:48:47 | 000,343,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 03:12:57 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/11 15:19:25 | 075,642,628 | —- | M] () – C:\Documents and Settings\Christy\Desktop\TMRN_2011_12_09_clif_high_64kbps.mp3
[2011/12/09 20:45:36 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2011/12/06 16:05:39 | 000,000,104 | —- | M] () – C:\Documents and Settings\Christy\Desktop\Shortcut to Recycle Bin.lnk
[2011/11/30 12:46:25 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20111130-152428.backup
[2011/11/30 12:23:01 | 000,016,248 | -HS- | M] () – C:\Documents and Settings\Christy\Local Settings\Application Data\5v56lj4h22d287
[2011/11/30 12:23:01 | 000,016,248 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\5v56lj4h22d287
[2011/11/30 12:07:28 | 000,000,259 | RHS- | M] () – C:\boot.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/22 10:59:45 | 000,350,359 | —- | C] () – C:\Documents and Settings\Christy\My Documents\craft.jpg
[2011/12/19 14:40:43 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/19 14:12:07 | 1072,750,592 | -HS- | C] () – C:\hiberfil.sys
[2011/12/19 10:35:49 | 000,017,722 | -HS- | C] () – C:\Documents and Settings\Christy\Local Settings\Application Data\xkauaw4c4aac1fwy6vnt0t741v2b
[2011/12/19 10:35:49 | 000,017,722 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\xkauaw4c4aac1fwy6vnt0t741v2b
[2011/12/15 03:02:55 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/12/11 15:19:26 | 075,642,628 | —- | C] () – C:\Documents and Settings\Christy\Desktop\TMRN_2011_12_09_clif_high_64kbps.mp3
[2011/12/09 20:44:40 | 000,002,347 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 8.lnk
[2011/12/09 20:44:40 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2011/12/07 11:54:44 | 003,129,600 | —- | C] () – C:\Documents and Settings\Christy\Desktop\Children's Songs - Disney Movies - The Nightmare Before Christmas; This is Halloween.mp3
[2011/12/06 16:05:39 | 000,000,104 | —- | C] () – C:\Documents and Settings\Christy\Desktop\Shortcut to Recycle Bin.lnk
[2011/11/30 10:19:05 | 000,016,248 | -HS- | C] () – C:\Documents and Settings\Christy\Local Settings\Application Data\5v56lj4h22d287
[2011/11/30 10:19:05 | 000,016,248 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\5v56lj4h22d287
[2010/01/19 09:02:25 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/01/19 09:02:25 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/01/19 09:02:25 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/01/19 09:02:25 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/01/19 09:02:25 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/19 11:58:19 | 000,032,768 | —- | C] () – C:\WINDOWS\unvise32.dll
[2008/09/15 20:41:40 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/02/07 16:22:22 | 000,000,000 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2007/11/14 21:36:18 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\Clifford Uninstall.exe
[2007/11/14 21:36:18 | 000,000,097 | —- | C] () – C:\WINDOWS\CR.ini
[2007/11/07 01:59:45 | 000,000,111 | —- | C] () – C:\WINDOWS\dellstat.ini
[2007/11/07 01:55:30 | 000,000,490 | —- | C] () – C:\WINDOWS\lexstat.ini
[2007/11/07 01:54:56 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxczvs.dll
[2007/11/07 01:54:51 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\LEXPING.EXE
[2007/11/07 01:54:51 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
[2007/11/07 01:54:26 | 000,000,270 | —- | C] () – C:\WINDOWS\System32\lxczcoin.ini
[2007/10/21 10:14:05 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2007/07/19 15:04:46 | 000,015,866 | R— | C] () – C:\WINDOWS\System32\Aud2_Gw.ini
[2007/07/19 15:04:46 | 000,000,029 | R— | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/02/05 13:24:28 | 000,018,271 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2007/02/05 13:24:26 | 000,099,999 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/01/03 10:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 10:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 10:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/10/03 18:06:05 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/07/21 08:44:33 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2005/03/08 16:16:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/03/08 15:10:18 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2005/03/08 15:10:18 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2005/03/08 15:10:18 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2005/03/08 15:10:18 | 000,000,342 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2005/03/08 15:10:18 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\ssprs.dll
[2005/03/08 15:00:35 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/08 14:47:11 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2005/03/08 14:31:16 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/03/08 14:31:07 | 000,107,132 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2005/03/08 14:30:57 | 000,003,428 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/03/08 13:19:24 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/03/08 13:12:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/03/08 06:09:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/03/08 06:07:38 | 000,343,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/04 00:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/02 13:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/11/26 07:29:00 | 000,127,226 | —- | C] () – C:\WINDOWS\System32\CTDLANG.DAT
[2003/11/13 13:21:00 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2003/03/21 12:56:00 | 000,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2002/08/29 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/08/29 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/08/29 07:00:00 | 000,526,720 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/08/29 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/08/29 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/08/29 07:00:00 | 000,096,194 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/08/29 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/08/29 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/08/29 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/06/28 07:05:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE

========== LOP Check ==========

[2007/11/07 02:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/29 02:32:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FunGames
[2008/01/15 03:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2008/01/26 02:53:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/03/15 14:00:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radica
[2008/01/27 11:45:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/07/25 17:10:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/07/02 12:41:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/10/04 11:33:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\Aim
[2011/08/16 09:44:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\CallingID
[2007/11/24 22:05:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\eLanguage
[2008/02/24 17:14:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\iWin
[2007/11/21 23:40:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\Leadertech
[2009/11/11 09:44:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\LimeWire
[2008/01/26 02:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\PlayFirst
[2007/11/07 02:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\Windows Desktop Search
[2011/07/26 18:47:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Christy\Application Data\xfinitytb
[2011/12/19 16:15:39 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



< End of report >






OTL Extras logfile created on: 12/27/2011 11:55:43 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Christy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.99 Mb Total Physical Memory | 648.97 Mb Available Physical Memory | 63.44% Memory free
2.69 Gb Paging File | 2.30 Gb Available in Paging File | 85.61% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 44.34 Gb Free Space | 59.55% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: Christy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = ComFile] – "%1" %*
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2157961D-0507-44A8-BCF2-1EE2D439E8DF}" = Civilization III
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{5B39603F-2A77-40E6-950D-ED7B8307933D}" = Microsoft IntelliPoint 5.3
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{747C231B-062D-4586-8221-8E7870987D5B}" = Dora Lost City
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-1143087}" = Garden Defense
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9357AE3A-B2ED-4138-BB9B-0564352C3F0A}" = iTunes
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{9FCCD9B3-4FC4-4F23-8054-ABCB0FB9FC4E}" = Learn to Speak Spanish 9.5
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34CCD1C-7738-47B9-863D-8E0C478FB8F7}" = Dora the Explorer: Animal Adventures
"{A43B2A2F-1DB5-47F9-A608-F11A4835D7CB}" = Apple Mobile Device Support
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.1
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BE3391FB-FAC9-404A-B530-2A27F9697DAE}" = Blue's Room
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEF7211D-CE3A-44C4-B321-D84A2099AE94}" = Comcast Desktop Software (v1.2.0.9)
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{F05A5232-CE5E-4274-AB27-44EB8105898D}" = CA Pest Patrol Realtime Protection
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Caillou's Preschool" = Caillou's Preschool
"CCleaner" = CCleaner
"Clifford Reading" = Clifford Reading
"Creative Driver" = Creative Driver
"Diner Dash" = Diner Dash
"Diner Dash 2" = Diner Dash 2
"Diner Dash Hometown Hero - Gourmet" = Diner Dash Hometown Hero - Gourmet
"DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"FPFarm" = Fisher-Price® - Discovery Farm
"FrippleTown" = Edmark - FrippleTown (Remove only)
"HijackThis" = HijackThis 1.99.1
"Hijackthis_is1" = Hijackthis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2157961D-0507-44A8-BCF2-1EE2D439E8DF}" = Civilization III
"Lexmark 1200 Series" = Lexmark 1200 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"MAXA Cookie Manager_is1" = MAXA Cookie Manager Pro 4.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mighty Math Zoo Zillions" = Edmark Mighty Math Zoo Zillions
"Millie and Bailey Preschool" = Millie and Bailey Preschool
"Mozilla ActiveX Control v1.7.12" = Mozilla ActiveX Control v1.7.12
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Ethernet Adapter and Software
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"Thinkin' Science" = Edmark - Thinkin' Science
"Toddler" = Fisher-Price® - Toddler
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtools3DLifePlayer" = Virtools 3D Life Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"xfinitytb" = Xfinity.com Toolbar 3.5
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Cake Mania Deluxe" = Cake Mania Deluxe
"ESPN Java Check" = ESPN Java Check

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/14/2011 10:22:08 AM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/14/2011 10:22:10 AM | Computer Name = DELL | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 12/14/2011 10:24:53 AM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/14/2011 1:11:03 PM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/14/2011 7:30:40 PM | Computer Name = DELL | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19154, fault address 0x00067a38.

Error - 12/16/2011 10:31:31 PM | Computer Name = DELL | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00011689.

Error - 12/18/2011 3:52:07 PM | Computer Name = DELL | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module jscript.dll, version 5.8.6001.23141, fault address 0x0001ef50.

Error - 12/19/2011 3:56:21 PM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/21/2011 6:06:56 PM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/26/2011 7:11:35 PM | Computer Name = DELL | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ OSession Events ]
Error - 7/6/2009 10:28:58 AM | Computer Name = DELL | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 12/19/2011 5:16:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%126

Error - 12/19/2011 5:16:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%126

Error - 12/19/2011 5:16:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%126

Error - 12/19/2011 5:16:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%126

Error - 12/19/2011 5:16:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%126

Error - 12/19/2011 5:21:08 PM | Computer Name = DELL | Source = DCOM | ID = 10005
Description = DCOM got error "%1068" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error - 12/19/2011 5:21:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7001
Description = The Windows Search service depends on the Terminal Services service
which failed to start because of the following error: %%126

Error - 12/19/2011 5:21:08 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Terminal Services service terminated with the following error:
%%126

Error - 12/19/2011 10:26:54 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7034
Description = The Comcast AntiSpyware service terminated unexpectedly. It has done
this 1 time(s).

Error - 12/22/2011 12:48:28 PM | Computer Name = DELL | Source = Print | ID = 6161
Description = The document Copy from Lexmark 1200 Series All-In-One owned by Christy
failed to print on printer Lexmark 1200 Series. Data type: RAW. Size of the spool
file in bytes: 965852. Number of bytes printed: 4. Total number of pages in the
document: 0. Number of pages printed: 0. Client machine: \\DELL. Win32 error code
returned by the print processor: 535 (0x217).


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI