This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe grinding my machine down [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good afternoon,

Yesterday, I was hit by XP Security 2012. I received help via the phone from Microsoft to get rid of it. I guess I have a residual problem. It seems that whenever I try to use Google, the whole system grinds almost to a stop. Task manager shows 100% CPU usage. Processes show that ping.exe is running. When the PC is first started, and any time before using Google, ping.exe is not shown in Task Manager Processes and everything runs normally.

The following Hijack This log was produced before triggering the ping.exe problem.

You people helped me once before, several years ago. I certainly appreciate it.

Steve




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:53:07 PM, on 12/21/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Simple Reminder\Simple Reminder.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Eudora\Eudora.exe
C:\WINDOWS\System32\ping.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Temp\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Simple Reminder] C:\Program Files\Simple Reminder\Simple Reminder.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233596122437
O16 - DPF: {79D1DBE2-A317-4D67-891D-9849D17F0531} (MapEdge) - http://www.parcelquest.com/download/MapEdge.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9b63e6aca8b7a) (gupdate1c9b63e6aca8b7a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: Roxio UPnP Renderer 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe
O23 - Service: Roxio Upnp Server 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe
O23 - Service: LiveShare P2P Server 11 (RoxLiveShare11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe
O23 - Service: RoxMediaDB11 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe
O23 - Service: Roxio Hard Drive Watcher 11 (RoxWatch11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

–
End of file - 9313 bytes
Hi Steve,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Hi NoodleTech: I followed your instructions, but neither DDS.scr nor aswMBR.exe returned anything other than text. (no separate files for attachment). Additionally, the text returned by DDS.scr was binary, and it created a huge file, rejected by WTT Forum, due to its size. So I have pasted only the text for aswMBR.exe below. I use MS Security Essentials and have unchecked Real Time Protection. If it will help you at all, I have noted these behaviors in my system since the trouble began: 1. Although I changed my Firefox 9.0 home page from Google to Yahoo, I am still frequently redirected to other sites (like "Nutrition and Wise Living"). 2. I have, on several occasions, seen a pop-up window, stating that "TCP/IP Ping Command…. TCP/IP Command has encountered a problem and needs to close….. " 3. Yesterday before posting my problem, I downloaded and ran MS Malicious Software Removal Tool/December 2011 and ran it. It reported no infections. 4. I also ran MS Security Essentials and it reported no infections. 5. However, yesterday when Googling, I received several pop-up warnings from MS S.E. of threats. The two threats were identified as Exploit:Win32/PDFjsc.YN and TrojanDownloader:Java/Comesis.A. I used MS S.E. to remove both. Okay, that's about it. Here are the text results from aswMBR.exe. If you want me to try another way to obtain attachable files, let me know how. Oh, again, thanks! aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-22 10:20:57 —————————– 10:20:57.296 OS Version: Windows 5.1.2600 Service Pack 2 10:20:57.296 Number of processors: 2 586 0x401 10:20:57.296 ComputerName: STEVE UserName: 10:20:58.140 Initialize success 10:21:09.765 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 10:21:09.781 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3 10:21:09.781 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1 10:21:09.781 Disk 1 Vendor: WDC_WD16 10.0 Size: 152587MB BusType: 3 10:21:09.796 Disk 0 MBR read successfully 10:21:09.796 Disk 0 MBR scan 10:21:09.796 Disk 0 unknown MBR code 10:21:09.796 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 298 MB offset 63 10:21:09.812 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 454526 MB offset 610470 10:21:09.828 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 22112 MB offset 931480830 10:21:09.828 Disk 0 scanning sectors +976768065 10:21:09.875 Disk 0 scanning C:\WINDOWS\system32\drivers 10:21:13.796 File: C:\WINDOWS\system32\drivers\c2scsi.sys **SUSPICIOUS** 10:21:17.859 Service scanning 10:21:18.281 Service MpKsl89e4ccdd c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F499D171-E1DD-4FE1-9684-32A2B6E96D10}\MpKsl89e4ccdd.sys **LOCKED** 32 10:21:19.000 Modules scanning 10:21:20.937 Module: C:\WINDOWS\System32\Drivers\c2scsi.SYS **SUSPICIOUS** 10:21:24.625 Module: C:\WINDOWS\system32\dla\tfsndres.sys **SUSPICIOUS** 10:21:25.781 Disk 0 trace - called modules: 10:21:25.796 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a0c4f10]<< 10:21:25.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aaf1668] 10:21:25.796 3 CLASSPNP.SYS[ba16905b] -> nt!IofCallDriver -> [0x8a390470] 10:21:25.812 \Driver\00000819[0x8a3a65f8] -> IRP_MJ_CREATE -> 0x8a0c4f10 10:21:25.812 Scan finished successfully 10:22:00.359 Disk 0 MBR has been saved successfully to "C:\TEMP VIRUS REMOVAL\MBR.dat" 10:22:00.375 The log file has been saved successfully to "C:\TEMP VIRUS REMOVAL\aswMBR.txt"
Hi Steve,

No problem!

I followed your instructions, but neither DDS.scr nor aswMBR.exe returned anything other than text. (no separate files for attachment). Additionally, the text returned by DDS.scr was binary, and it created a huge file, rejected by WTT Forum, due to its size. So I have pasted only the text for aswMBR.exe below.

Whoa… DDS is supposed to produce two text logs, not binary. Can you try downloading a fresh copy of DDS and running the scans again? The aswMBR log you provided is fine. :thumbup:

I use MS Security Essentials and have unchecked Real Time Protection.

Good.

If it will help you at all, I have noted these behaviors in my system since the trouble began:

This is very helpful, thank you.

1. Although I changed my Firefox 9.0 home page from Google to Yahoo, I am still frequently redirected to other sites (like "Nutrition and Wise Living")

You have some sort of rootkit infection, either a variant of TDSS/TDL or ZeroAccess. That is why you are getting redirected. Ping.exe is a telltale sign.

2. I have, on several occasions, seen a pop-up window, stating that "TCP/IP Ping Command…. TCP/IP Command has encountered a problem and needs to close….. "

Not 100% sure about this.

3. Yesterday before posting my problem, I downloaded and ran MS Malicious Software Removal Tool/December 2011 and ran it. It reported no infections.

It's only designed to remove specific infections.

4. I also ran MS Security Essentials and it reported no infections.

We need special tools to detect and remove the rootkit(s).

5. However, yesterday when Googling, I received several pop-up warnings from MS S.E. of threats. The two threats were identified as Exploit:Win32/PDFjsc.YN and TrojanDownloader:Java/Comesis.A. I used MS S.E. to remove both.

Good call.
Hi NoodleTech, Okay, I went back and tried again. This time, I used DDS.pif instead of DDS.scr. The log is below, and I have attached the zipped file, "Attach.txt". Also, the file, MBR.dat is attached. Thanks, Steve . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 13:22:02 on 2011-12-22 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2558.2067 [GMT -8:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Simple Reminder\Simple Reminder.exe svchost.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe C:\WINDOWS\system32\fxssvc.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Simple Reminder] c:\program files\simple reminder\Simple Reminder.exe mRun: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: mswsock.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233596122437 DPF: {79D1DBE2-A317-4D67-891D-9849D17F0531} - hxxp://www.parcelquest.com/download/MapEdge.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{C8BA5A59-22FB-42E1-9988-70B13FE66006} : DhcpNameServer = [removed] [removed] SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\eudora\EuShlExt.dll LSA: Authentication Packages = msv1_0 relog_ap LSA: Notification Packages = scecli . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\steve hullibarger\application data\mozilla\firefox\profiles\vqbjk8m2.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R1 c2scsi;c2scsi;c:\windows\system32\drivers\c2scsi.sys [2009-6-10 244608] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165648] R1 MpKsl602e369e;MpKsl602e369e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f324dc5-4ddc-48d3-981a-b5808a250035}\MpKsl602e369e.sys [2011-12-22 29904] R2 NProtectService;Norton Unerase Protection;c:\progra~1\norton~1\norton~2\NPROTECT.EXE [2003-11-24 81920] R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2009-3-9 585728] R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-5-16 102400] S0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys –> c:\windows\system32\drivers\avgarkt.sys [?] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\avgarcln.sys –> c:\windows\system32\drivers\AvgArCln.sys [?] S1 MpKsl77d9a056;MpKsl77d9a056;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c52f0162-c7dd-4cdb-832b-ca07df29be1e}\mpksl77d9a056.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c52f0162-c7dd-4cdb-832b-ca07df29be1e}\MpKsl77d9a056.sys [?] S2 gupdate1c9b63e6aca8b7a;Google Update Service (gupdate1c9b63e6aca8b7a);c:\program files\google\update\GoogleUpdate.exe [2009-4-5 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\AAWService.exe [?] S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\roxio creator 2009\digital home 11\RoxioUpnpService11.exe [2008-8-14 367088] S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxLiveShare11.exe [2008-8-14 309744] S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxWatch11.exe [2008-8-14 170480] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-4-5 133104] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064] S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\roxio creator 2009\digital home 11\RoxioUPnPRenderer11.exe [2008-8-14 313840] S3 RoxMediaDB11;RoxMediaDB11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxMediaDB11.exe [2009-3-3 1122304] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-8-27 10112] S3 XLoader;PLEXTOR EZ-USB FX2 FIRMWARE LOADER (XLoader.sys);c:\windows\system32\drivers\XLoader.sys [2004-9-3 13184] . =============== File Associations =============== . .cmd=VisualCADD.Alias.4 .scr=DWGTrueViewScriptFile . =============== Created Last 30 ================ . 2011-12-22 21:20:51 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f324dc5-4ddc-48d3-981a-b5808a250035}\MpKsl602e369e.sys 2011-12-22 21:20:48 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f324dc5-4ddc-48d3-981a-b5808a250035}\offreg.dll 2011-12-22 21:14:15 607017 ——r- c:\temp\dds.pif 2011-12-22 20:02:27 6823496 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0f324dc5-4ddc-48d3-981a-b5808a250035}\mpengine.dll 2011-12-22 00:12:49 ——– d—–w- C:\TEMP VIRUS REMOVAL 2011-12-21 01:12:27 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2011-12-21 01:12:27 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2011-12-21 01:12:27 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2011-12-21 01:12:27 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll 2011-12-20 23:03:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-12-20 22:58:40 ——– d—–w- c:\documents and settings\steve hullibarger\application data\Malwarebytes 2011-12-20 22:58:21 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-20 22:40:47 ——– d—–w- c:\documents and settings\steve hullibarger\local settings\application data\LogMeIn Rescue Applet 2011-12-20 22:40:09 ——– d—–w- c:\documents and settings\steve hullibarger\local settings\application data\Deployment 2011-12-20 18:54:52 ——– d—–w- C:\TEMP LL Pix for KPS 2011-12-10 19:42:46 899414 —-a-w- c:\temp\SetupDVDDecrypter_3.5.4.0.exe 2011-11-30 23:51:13 ——– d—–w- C:\TEMP ACROBAT OCR 2011-11-26 01:50:36 ——– d—–w- C:\Temp November Pix 2011-11-22 23:48:14 ——– d—–w- C:\TEMP PIX . ==================== Find3M ==================== . . ============= FINISH: 13:22:48.12 ===============

Attachments:

Hi Steve,

I figured out why you were getting binary when you tried running DDS.scr. The .scr extension was being handled by DWGTrueViewScriptFile.

I need you to do the following.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Well, it looks like it found a Rootkit. Here's the Kaspersky log: 13:54:02.0890 0668 TDSS rootkit removing tool 2.6.24.0 Dec 22 2011 18:21:27 13:54:03.0531 0668 ============================================================ 13:54:03.0531 0668 Current date / time: 2011/12/22 13:54:03.0531 13:54:03.0531 0668 SystemInfo: 13:54:03.0531 0668 13:54:03.0531 0668 OS Version: 5.1.2600 ServicePack: 2.0 13:54:03.0531 0668 Product type: Workstation 13:54:03.0531 0668 ComputerName: STEVE 13:54:03.0531 0668 UserName: Steve Hullibarger 13:54:03.0531 0668 Windows directory: C:\WINDOWS 13:54:03.0531 0668 System windows directory: C:\WINDOWS 13:54:03.0531 0668 Processor architecture: Intel x86 13:54:03.0531 0668 Number of processors: 2 13:54:03.0531 0668 Page size: 0x1000 13:54:03.0531 0668 Boot type: Normal boot 13:54:03.0531 0668 ============================================================ 13:54:04.0046 0668 Initialize success 13:54:10.0468 1876 ============================================================ 13:54:10.0468 1876 Scan started 13:54:10.0468 1876 Mode: Manual; 13:54:10.0468 1876 ============================================================ 13:54:10.0734 1876 61883 (86d7b1e70661d754685b9ac6d749aae5) C:\WINDOWS\system32\DRIVERS\61883.sys 13:54:10.0734 1876 61883 - ok 13:54:10.0750 1876 Abiosdsk - ok 13:54:10.0796 1876 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 13:54:10.0796 1876 abp480n5 - ok 13:54:10.0812 1876 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:54:10.0812 1876 ACPI - ok 13:54:10.0859 1876 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 13:54:10.0859 1876 ACPIEC - ok 13:54:10.0875 1876 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 13:54:10.0875 1876 adpu160m - ok 13:54:10.0906 1876 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 13:54:10.0906 1876 aec - ok 13:54:10.0953 1876 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 13:54:10.0953 1876 AFD - ok 13:54:10.0984 1876 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 13:54:10.0984 1876 agp440 - ok 13:54:11.0000 1876 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 13:54:11.0000 1876 agpCPQ - ok 13:54:11.0015 1876 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 13:54:11.0015 1876 Aha154x - ok 13:54:11.0046 1876 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 13:54:11.0062 1876 aic78u2 - ok 13:54:11.0062 1876 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 13:54:11.0062 1876 aic78xx - ok 13:54:11.0093 1876 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 13:54:11.0093 1876 AliIde - ok 13:54:11.0109 1876 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys 13:54:11.0125 1876 alim1541 - ok 13:54:11.0125 1876 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys 13:54:11.0140 1876 amdagp - ok 13:54:11.0140 1876 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 13:54:11.0140 1876 amsint - ok 13:54:11.0171 1876 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 13:54:11.0171 1876 Arp1394 - ok 13:54:11.0187 1876 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 13:54:11.0187 1876 asc - ok 13:54:11.0203 1876 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 13:54:11.0203 1876 asc3350p - ok 13:54:11.0203 1876 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 13:54:11.0218 1876 asc3550 - ok 13:54:11.0234 1876 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 13:54:11.0234 1876 ASCTRM - ok 13:54:11.0281 1876 Aspi32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys 13:54:11.0281 1876 Aspi32 - ok 13:54:11.0312 1876 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:54:11.0312 1876 AsyncMac - ok 13:54:11.0328 1876 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 13:54:11.0328 1876 atapi - ok 13:54:11.0343 1876 Atdisk - ok 13:54:11.0375 1876 ati2mtag (f0d0b0cdec0be32d775f404cac2604bf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 13:54:11.0390 1876 ati2mtag - ok 13:54:11.0421 1876 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 13:54:11.0421 1876 Atmarpc - ok 13:54:11.0453 1876 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 13:54:11.0453 1876 audstub - ok 13:54:11.0500 1876 Avc (87c223adb8f7596b31caae3c67b16ddd) C:\WINDOWS\system32\DRIVERS\avc.sys 13:54:11.0500 1876 Avc - ok 13:54:11.0515 1876 AVG Anti-Rootkit - ok 13:54:11.0515 1876 AvgArCln - ok 13:54:11.0546 1876 b57w2k (4826fcf97c47b361a2e2f68cd487a19e) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 13:54:11.0546 1876 b57w2k - ok 13:54:11.0578 1876 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 13:54:11.0578 1876 Beep - ok 13:54:11.0593 1876 bvrp_pci - ok 13:54:11.0656 1876 c2scsi (5cd60ec44e23ef61d7353a090747b850) C:\WINDOWS\system32\drivers\c2scsi.sys 13:54:11.0656 1876 Suspicious file (Forged): C:\WINDOWS\system32\drivers\c2scsi.sys. Real md5: 5cd60ec44e23ef61d7353a090747b850, Fake md5: 56247d46756b399725c2a386f4fc3cc3 13:54:11.0656 1876 c2scsi ( Rootkit.Win32.ZAccess.aml ) - infected 13:54:11.0656 1876 c2scsi - detected Rootkit.Win32.ZAccess.aml (0) 13:54:11.0671 1876 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 13:54:11.0671 1876 cbidf - ok 13:54:11.0687 1876 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 13:54:11.0687 1876 cbidf2k - ok 13:54:11.0718 1876 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 13:54:11.0718 1876 CCDECODE - ok 13:54:11.0734 1876 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 13:54:11.0734 1876 cd20xrnt - ok 13:54:11.0750 1876 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 13:54:11.0750 1876 Cdaudio - ok 13:54:11.0765 1876 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 13:54:11.0765 1876 Cdfs - ok 13:54:11.0812 1876 cdrbsdrv (351735695e9ead93de6af85d8beb1ca8) C:\WINDOWS\system32\drivers\cdrbsdrv.sys 13:54:11.0812 1876 cdrbsdrv - ok 13:54:11.0828 1876 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 13:54:11.0828 1876 Cdrom - ok 13:54:11.0828 1876 Changer - ok 13:54:11.0859 1876 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 13:54:11.0859 1876 CmdIde - ok 13:54:11.0875 1876 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 13:54:11.0875 1876 Cpqarray - ok 13:54:11.0906 1876 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 13:54:11.0906 1876 dac2w2k - ok 13:54:11.0921 1876 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 13:54:11.0921 1876 dac960nt - ok 13:54:11.0953 1876 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 13:54:11.0953 1876 Disk - ok 13:54:12.0000 1876 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 13:54:12.0015 1876 dmboot - ok 13:54:12.0046 1876 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 13:54:12.0046 1876 dmio - ok 13:54:12.0078 1876 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 13:54:12.0078 1876 dmload - ok 13:54:12.0109 1876 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 13:54:12.0109 1876 DMusic - ok 13:54:12.0140 1876 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 13:54:12.0140 1876 dpti2o - ok 13:54:12.0156 1876 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 13:54:12.0171 1876 drmkaud - ok 13:54:12.0187 1876 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys 13:54:12.0187 1876 drvmcdb - ok 13:54:12.0203 1876 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys 13:54:12.0203 1876 drvnddm - ok 13:54:12.0265 1876 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 13:54:12.0281 1876 DSproct - ok 13:54:12.0312 1876 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 13:54:12.0312 1876 dsunidrv - ok 13:54:12.0343 1876 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 13:54:12.0343 1876 E100B - ok 13:54:12.0359 1876 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 13:54:12.0359 1876 Fastfat - ok 13:54:12.0390 1876 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 13:54:12.0390 1876 Fdc - ok 13:54:12.0421 1876 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 13:54:12.0421 1876 Fips - ok 13:54:12.0437 1876 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 13:54:12.0437 1876 Flpydisk - ok 13:54:12.0453 1876 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 13:54:12.0453 1876 FltMgr - ok 13:54:12.0468 1876 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:54:12.0468 1876 Fs_Rec - ok 13:54:12.0500 1876 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 13:54:12.0500 1876 Ftdisk - ok 13:54:12.0515 1876 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 13:54:12.0515 1876 GEARAspiWDM - ok 13:54:12.0546 1876 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 13:54:12.0546 1876 Gpc - ok 13:54:12.0578 1876 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 13:54:12.0578 1876 HidUsb - ok 13:54:12.0593 1876 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 13:54:12.0593 1876 hpn - ok 13:54:12.0625 1876 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 13:54:12.0625 1876 HSFHWBS2 - ok 13:54:12.0703 1876 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 13:54:12.0718 1876 HSF_DP - ok 13:54:12.0781 1876 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 13:54:12.0781 1876 HTTP - ok 13:54:12.0796 1876 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys 13:54:12.0812 1876 i2omgmt - ok 13:54:12.0843 1876 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys 13:54:12.0843 1876 i2omp - ok 13:54:12.0859 1876 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 13:54:12.0859 1876 i8042prt - ok 13:54:12.0875 1876 iaStor (d7731536e183b4397402ca6f9e1d52f7) C:\WINDOWS\system32\drivers\iaStor.sys 13:54:12.0890 1876 iaStor - ok 13:54:12.0906 1876 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 13:54:12.0921 1876 Imapi - ok 13:54:12.0953 1876 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 13:54:12.0953 1876 ini910u - ok 13:54:12.0984 1876 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 13:54:12.0984 1876 IntelIde - ok 13:54:13.0000 1876 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 13:54:13.0000 1876 intelppm - ok 13:54:13.0031 1876 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 13:54:13.0031 1876 Ip6Fw - ok 13:54:13.0046 1876 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:54:13.0046 1876 IpFilterDriver - ok 13:54:13.0062 1876 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 13:54:13.0062 1876 IpInIp - ok 13:54:13.0093 1876 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 13:54:13.0093 1876 IpNat - ok 13:54:13.0109 1876 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 13:54:13.0109 1876 IPSec - ok 13:54:13.0140 1876 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 13:54:13.0140 1876 IRENUM - ok 13:54:13.0156 1876 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 13:54:13.0156 1876 isapnp - ok 13:54:13.0171 1876 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 13:54:13.0171 1876 Kbdclass - ok 13:54:13.0203 1876 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 13:54:13.0203 1876 kmixer - ok 13:54:13.0234 1876 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys 13:54:13.0234 1876 KSecDD - ok 13:54:13.0250 1876 Lbd - ok 13:54:13.0265 1876 lbrtfdc - ok 13:54:13.0312 1876 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 13:54:13.0312 1876 mdmxsdk - ok 13:54:13.0343 1876 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 13:54:13.0343 1876 mnmdd - ok 13:54:13.0375 1876 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 13:54:13.0375 1876 Modem - ok 13:54:13.0390 1876 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 13:54:13.0390 1876 MODEMCSA - ok 13:54:13.0406 1876 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 13:54:13.0406 1876 Mouclass - ok 13:54:13.0453 1876 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 13:54:13.0453 1876 mouhid - ok 13:54:13.0468 1876 MountMgr (af814611a3b40cd282634c71f8f34fc3) C:\WINDOWS\system32\drivers\MountMgr.sys 13:54:13.0468 1876 MountMgr - ok 13:54:13.0515 1876 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 13:54:13.0515 1876 MpFilter - ok 13:54:13.0609 1876 MpKsl77d9a056 - ok 13:54:13.0625 1876 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 13:54:13.0625 1876 mraid35x - ok 13:54:13.0640 1876 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 13:54:13.0640 1876 MRxDAV - ok 13:54:13.0687 1876 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:54:13.0703 1876 MRxSmb - ok 13:54:13.0734 1876 MSDV (6dd721dfd2648f3f6d5808b5ba6cb095) C:\WINDOWS\system32\DRIVERS\msdv.sys 13:54:13.0734 1876 MSDV - ok 13:54:13.0750 1876 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 13:54:13.0750 1876 Msfs - ok 13:54:13.0796 1876 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 13:54:13.0796 1876 MSKSSRV - ok 13:54:13.0828 1876 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 13:54:13.0828 1876 MSPCLOCK - ok 13:54:13.0843 1876 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 13:54:13.0843 1876 MSPQM - ok 13:54:13.0859 1876 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 13:54:13.0859 1876 mssmbios - ok 13:54:13.0890 1876 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 13:54:13.0890 1876 MSTEE - ok 13:54:13.0906 1876 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 13:54:13.0906 1876 Mup - ok 13:54:13.0921 1876 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 13:54:13.0921 1876 NABTSFEC - ok 13:54:13.0968 1876 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 13:54:13.0968 1876 NDIS - ok 13:54:14.0000 1876 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 13:54:14.0000 1876 NdisIP - ok 13:54:14.0031 1876 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 13:54:14.0031 1876 NdisTapi - ok 13:54:14.0046 1876 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 13:54:14.0046 1876 Ndisuio - ok 13:54:14.0062 1876 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:54:14.0062 1876 NdisWan - ok 13:54:14.0078 1876 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 13:54:14.0078 1876 NDProxy - ok 13:54:14.0093 1876 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 13:54:14.0093 1876 NetBIOS - ok 13:54:14.0140 1876 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 13:54:14.0140 1876 NetBT - ok 13:54:14.0171 1876 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 13:54:14.0171 1876 NIC1394 - ok 13:54:14.0203 1876 nm (60cf8c7192b3614f240838ddbaa4a245) C:\WINDOWS\system32\DRIVERS\NMnt.sys 13:54:14.0203 1876 nm - ok 13:54:14.0265 1876 NPDriver (542e08a61dcd3ff07bf092f1ab1fa5a8) C:\WINDOWS\system32\Drivers\NPDRIVER.SYS 13:54:14.0281 1876 NPDriver - ok 13:54:14.0312 1876 NPF (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys 13:54:14.0312 1876 NPF - ok 13:54:14.0328 1876 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 13:54:14.0328 1876 Npfs - ok 13:54:14.0390 1876 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 13:54:14.0390 1876 Ntfs - ok 13:54:14.0421 1876 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 13:54:14.0421 1876 Null - ok 13:54:14.0484 1876 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 13:54:14.0515 1876 nv - ok 13:54:14.0531 1876 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 13:54:14.0531 1876 NwlnkFlt - ok 13:54:14.0546 1876 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 13:54:14.0546 1876 NwlnkFwd - ok 13:54:14.0578 1876 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 13:54:14.0578 1876 ohci1394 - ok 13:54:14.0593 1876 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys 13:54:14.0593 1876 omci - ok 13:54:14.0640 1876 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 13:54:14.0640 1876 Parport - ok 13:54:14.0687 1876 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 13:54:14.0687 1876 PartMgr - ok 13:54:14.0703 1876 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 13:54:14.0703 1876 ParVdm - ok 13:54:14.0718 1876 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 13:54:14.0718 1876 PCI - ok 13:54:14.0734 1876 PCIDump - ok 13:54:14.0750 1876 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 13:54:14.0765 1876 PCIIde - ok 13:54:14.0781 1876 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 13:54:14.0781 1876 Pcmcia - ok 13:54:14.0796 1876 PDCOMP - ok 13:54:14.0796 1876 PDFRAME - ok 13:54:14.0812 1876 PDRELI - ok 13:54:14.0828 1876 PDRFRAME - ok 13:54:14.0843 1876 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 13:54:14.0843 1876 perc2 - ok 13:54:14.0859 1876 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 13:54:14.0859 1876 perc2hib - ok 13:54:14.0890 1876 Pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys 13:54:14.0890 1876 Pfc - ok 13:54:14.0921 1876 PMEM (2b85237f904c5bdf7ad386f0ede19bd3) C:\WINDOWS\system32\drivers\pmemnt.sys 13:54:14.0921 1876 PMEM - ok 13:54:14.0968 1876 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 13:54:14.0968 1876 PptpMiniport - ok 13:54:15.0015 1876 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 13:54:15.0015 1876 PSched - ok 13:54:15.0031 1876 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 13:54:15.0031 1876 Ptilink - ok 13:54:15.0046 1876 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 13:54:15.0046 1876 PxHelp20 - ok 13:54:15.0062 1876 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 13:54:15.0062 1876 ql1080 - ok 13:54:15.0078 1876 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 13:54:15.0078 1876 Ql10wnt - ok 13:54:15.0093 1876 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 13:54:15.0093 1876 ql12160 - ok 13:54:15.0109 1876 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 13:54:15.0109 1876 ql1240 - ok 13:54:15.0125 1876 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 13:54:15.0125 1876 ql1280 - ok 13:54:15.0156 1876 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 13:54:15.0156 1876 RasAcd - ok 13:54:15.0171 1876 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 13:54:15.0171 1876 Rasl2tp - ok 13:54:15.0187 1876 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 13:54:15.0187 1876 RasPppoe - ok 13:54:15.0203 1876 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 13:54:15.0203 1876 Raspti - ok 13:54:15.0218 1876 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 13:54:15.0218 1876 Rdbss - ok 13:54:15.0234 1876 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 13:54:15.0234 1876 RDPCDD - ok 13:54:15.0265 1876 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 13:54:15.0281 1876 rdpdr - ok 13:54:15.0296 1876 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 13:54:15.0296 1876 RDPWD - ok 13:54:15.0328 1876 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 13:54:15.0328 1876 redbook - ok 13:54:15.0406 1876 RxFilter (0501074a2f29250932e34ca4a844a0f5) C:\WINDOWS\system32\DRIVERS\RxFilter.sys 13:54:15.0406 1876 RxFilter - ok 13:54:15.0421 1876 sbp2port (3e2c3b180872be4120f246d85560b734) C:\WINDOWS\system32\DRIVERS\sbp2port.sys 13:54:15.0437 1876 sbp2port - ok 13:54:15.0468 1876 SDdriver (f6a78ee51674f62d30f606b27e53d846) C:\WINDOWS\system32\Drivers\sddriver.sys 13:54:15.0468 1876 SDdriver - ok 13:54:15.0484 1876 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 13:54:15.0484 1876 Secdrv - ok 13:54:15.0531 1876 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys 13:54:15.0546 1876 senfilt - ok 13:54:15.0578 1876 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 13:54:15.0578 1876 serenum - ok 13:54:15.0593 1876 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 13:54:15.0593 1876 Serial - ok 13:54:15.0640 1876 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 13:54:15.0640 1876 Sfloppy - ok 13:54:15.0687 1876 Simbad - ok 13:54:15.0687 1876 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys 13:54:15.0703 1876 sisagp - ok 13:54:15.0734 1876 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 13:54:15.0734 1876 SLIP - ok 13:54:15.0765 1876 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys 13:54:15.0765 1876 smwdm - ok 13:54:15.0812 1876 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\WINDOWS\system32\DRIVERS\snapman.sys 13:54:15.0812 1876 snapman - ok 13:54:15.0859 1876 sonypvs1 (dfadfc2c86662f40759bf02add27d569) C:\WINDOWS\system32\DRIVERS\sonypvs1.sys 13:54:15.0859 1876 sonypvs1 - ok 13:54:15.0875 1876 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 13:54:15.0875 1876 SONYPVU1 - ok 13:54:15.0906 1876 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 13:54:15.0906 1876 Sparrow - ok 13:54:15.0937 1876 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 13:54:15.0937 1876 splitter - ok 13:54:15.0968 1876 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 13:54:15.0968 1876 sr - ok 13:54:16.0000 1876 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 13:54:16.0000 1876 Srv - ok 13:54:16.0015 1876 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 13:54:16.0015 1876 sscdbhk5 - ok 13:54:16.0031 1876 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 13:54:16.0031 1876 ssrtln - ok 13:54:16.0046 1876 StarOpen (e57b778208c783d8debab320c16a1b82) C:\WINDOWS\system32\drivers\StarOpen.sys 13:54:16.0046 1876 StarOpen - ok 13:54:16.0062 1876 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 13:54:16.0062 1876 streamip - ok 13:54:16.0093 1876 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 13:54:16.0093 1876 swenum - ok 13:54:16.0109 1876 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 13:54:16.0125 1876 swmidi - ok 13:54:16.0140 1876 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 13:54:16.0140 1876 symc810 - ok 13:54:16.0156 1876 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 13:54:16.0156 1876 symc8xx - ok 13:54:16.0250 1876 SymEvent (05d9613efe7809e384c10da26958dfa4) C:\Program Files\Symantec\SYMEVENT.SYS 13:54:16.0265 1876 SymEvent - ok 13:54:16.0265 1876 SYMREDRV - ok 13:54:16.0281 1876 SYMTDI - ok 13:54:16.0296 1876 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 13:54:16.0296 1876 sym_hi - ok 13:54:16.0312 1876 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 13:54:16.0312 1876 sym_u3 - ok 13:54:16.0343 1876 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 13:54:16.0343 1876 sysaudio - ok 13:54:16.0359 1876 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 13:54:16.0375 1876 Tcpip - ok 13:54:16.0390 1876 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 13:54:16.0406 1876 TDPIPE - ok 13:54:16.0437 1876 tdrpman (eb53ec341458256deae2ad58822c4a17) C:\WINDOWS\system32\DRIVERS\tdrpman.sys 13:54:16.0453 1876 tdrpman - ok 13:54:16.0484 1876 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 13:54:16.0484 1876 TDTCP - ok 13:54:16.0515 1876 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 13:54:16.0515 1876 TermDD - ok 13:54:16.0531 1876 tfsnboio (75b30b9ea32fe7d8bbc332d3b944ad46) C:\WINDOWS\system32\dla\tfsnboio.sys 13:54:16.0531 1876 tfsnboio - ok 13:54:16.0546 1876 tfsncofs (b811a431b14694d88eb5befaa55b4501) C:\WINDOWS\system32\dla\tfsncofs.sys 13:54:16.0546 1876 tfsncofs - ok 13:54:16.0562 1876 tfsndrct (f5e2cf2144f1fe51dadd6e9063d311eb) C:\WINDOWS\system32\dla\tfsndrct.sys 13:54:16.0562 1876 tfsndrct - ok 13:54:16.0578 1876 tfsndres (e32b32045b6b914fd4caae8be6ca7e8a) C:\WINDOWS\system32\dla\tfsndres.sys 13:54:16.0578 1876 tfsndres - ok 13:54:16.0593 1876 tfsnifs (43034b10a94d1c6f13a1a0e848f51226) C:\WINDOWS\system32\dla\tfsnifs.sys 13:54:16.0593 1876 tfsnifs - ok 13:54:16.0593 1876 tfsnopio (f5ee0faafde37326ea35acbfa5defd3d) C:\WINDOWS\system32\dla\tfsnopio.sys 13:54:16.0609 1876 tfsnopio - ok 13:54:16.0609 1876 tfsnpool (597348eb65b3e19709e9a45ca2b30b61) C:\WINDOWS\system32\dla\tfsnpool.sys 13:54:16.0609 1876 tfsnpool - ok 13:54:16.0640 1876 tfsnudf (767affd52432a0f7e7d39f6ff64401f4) C:\WINDOWS\system32\dla\tfsnudf.sys 13:54:16.0640 1876 tfsnudf - ok 13:54:16.0656 1876 tfsnudfa (2806b2fd00263ccd90cc0638c6139eb0) C:\WINDOWS\system32\dla\tfsnudfa.sys 13:54:16.0656 1876 tfsnudfa - ok 13:54:16.0703 1876 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 13:54:16.0703 1876 tifsfilter - ok 13:54:16.0734 1876 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\WINDOWS\system32\DRIVERS\timntr.sys 13:54:16.0734 1876 timounter - ok 13:54:16.0750 1876 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 13:54:16.0750 1876 TosIde - ok 13:54:16.0781 1876 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 13:54:16.0781 1876 Udfs - ok 13:54:16.0796 1876 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 13:54:16.0796 1876 ultra - ok 13:54:16.0812 1876 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys 13:54:16.0828 1876 Update - ok 13:54:16.0875 1876 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys 13:54:16.0875 1876 USBAAPL - ok 13:54:16.0906 1876 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys 13:54:16.0906 1876 usbaudio - ok 13:54:16.0921 1876 usbbus (d9f3bb7c292f194f3b053ce295754eb8) C:\WINDOWS\system32\DRIVERS\lgusbbus.sys 13:54:16.0921 1876 usbbus - ok 13:54:16.0937 1876 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 13:54:16.0953 1876 usbccgp - ok 13:54:16.0968 1876 UsbDiag (c4f77da649f99fad116ea585376fc164) C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys 13:54:16.0968 1876 UsbDiag - ok 13:54:17.0000 1876 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 13:54:17.0000 1876 usbehci - ok 13:54:17.0015 1876 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 13:54:17.0015 1876 usbhub - ok 13:54:17.0031 1876 USBModem (c0613ce45e617bc671de8ebb1b30d175) C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys 13:54:17.0031 1876 USBModem - ok 13:54:17.0078 1876 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 13:54:17.0078 1876 usbprint - ok 13:54:17.0093 1876 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 13:54:17.0093 1876 usbscan - ok 13:54:17.0109 1876 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 13:54:17.0109 1876 USBSTOR - ok 13:54:17.0156 1876 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 13:54:17.0156 1876 usbuhci - ok 13:54:17.0171 1876 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 13:54:17.0171 1876 VgaSave - ok 13:54:17.0187 1876 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys 13:54:17.0187 1876 viaagp - ok 13:54:17.0218 1876 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 13:54:17.0218 1876 ViaIde - ok 13:54:17.0234 1876 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 13:54:17.0234 1876 VolSnap - ok 13:54:17.0265 1876 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:54:17.0265 1876 Wanarp - ok 13:54:17.0281 1876 wanatw - ok 13:54:17.0312 1876 WDC_SAM (011e8a3e13dd7007353edbee4b180b50) C:\WINDOWS\system32\DRIVERS\wdcsam.sys 13:54:17.0312 1876 WDC_SAM - ok 13:54:17.0328 1876 WDICA - ok 13:54:17.0359 1876 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 13:54:17.0359 1876 wdmaud - ok 13:54:17.0421 1876 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 13:54:17.0437 1876 winachsf - ok 13:54:17.0500 1876 WISTechVIDCAP (d631e5ce1e789cf8ecd277df3e969057) C:\WINDOWS\system32\drivers\Xstream.sys 13:54:17.0500 1876 WISTechVIDCAP - ok 13:54:17.0531 1876 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 13:54:17.0531 1876 WSTCODEC - ok 13:54:17.0562 1876 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 13:54:17.0562 1876 WudfPf - ok 13:54:17.0578 1876 XLoader (e54d59202747147f6d2501d32c43e35e) C:\WINDOWS\system32\Drivers\XLoader.sys 13:54:17.0578 1876 XLoader - ok 13:54:17.0609 1876 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0 13:54:17.0609 1876 \Device\Harddisk0\DR0 - ok 13:54:17.0609 1876 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1 13:54:18.0343 1876 \Device\Harddisk1\DR1 - ok 13:54:18.0343 1876 Boot (0x1200) (2709fff81818b673feba43ef4151596a) \Device\Harddisk0\DR0\Partition0 13:54:18.0343 1876 \Device\Harddisk0\DR0\Partition0 - ok 13:54:18.0359 1876 Boot (0x1200) (6debf3fda9535e5ce6cf69bea10928da) \Device\Harddisk1\DR1\Partition0 13:54:18.0359 1876 \Device\Harddisk1\DR1\Partition0 - ok 13:54:18.0359 1876 ============================================================ 13:54:18.0359 1876 Scan finished 13:54:18.0359 1876 ============================================================ 13:54:18.0375 1916 Detected object count: 1 13:54:18.0375 1916 Actual detected object count: 1 13:54:38.0343 1916 c2scsi ( Rootkit.Win32.ZAccess.aml ) - skipped by user 13:54:38.0343 1916 c2scsi ( Rootkit.Win32.ZAccess.aml ) - User select action: Skip 13:56:57.0500 3532 Deinitialize success
Hi Steve,

Yes, it found the ZeroAccess rootkit which is one of the nastiest ones out there. Run TDSSKiller again and have it Cure the infected objects, then post the new log.
Looks like a fine assassination job! Follow up steps? 14:14:56.0750 0460 TDSS rootkit removing tool [removed] Dec 22 2011 18:21:27 14:14:57.0375 0460 ============================================================ 14:14:57.0375 0460 Current date / time: 2011/12/22 14:14:57.0375 14:14:57.0375 0460 SystemInfo: 14:14:57.0375 0460 14:14:57.0375 0460 OS Version: 5.1.2600 ServicePack: 2.0 14:14:57.0375 0460 Product type: Workstation 14:14:57.0375 0460 ComputerName: STEVE 14:14:57.0375 0460 UserName: Steve Hullibarger 14:14:57.0375 0460 Windows directory: C:\WINDOWS 14:14:57.0375 0460 System windows directory: C:\WINDOWS 14:14:57.0375 0460 Processor architecture: Intel x86 14:14:57.0375 0460 Number of processors: 2 14:14:57.0375 0460 Page size: 0x1000 14:14:57.0375 0460 Boot type: Normal boot 14:14:57.0375 0460 ============================================================ 14:15:03.0750 0460 Initialize success 14:15:07.0750 1944 ============================================================ 14:15:07.0750 1944 Scan started 14:15:07.0750 1944 Mode: Manual; 14:15:07.0750 1944 ============================================================ 14:15:08.0000 1944 61883 (86d7b1e70661d754685b9ac6d749aae5) C:\WINDOWS\system32\DRIVERS\61883.sys 14:15:08.0000 1944 61883 - ok 14:15:08.0000 1944 Abiosdsk - ok 14:15:08.0046 1944 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 14:15:08.0062 1944 abp480n5 - ok 14:15:08.0078 1944 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 14:15:08.0078 1944 ACPI - ok 14:15:08.0109 1944 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 14:15:08.0125 1944 ACPIEC - ok 14:15:08.0140 1944 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 14:15:08.0140 1944 adpu160m - ok 14:15:08.0171 1944 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 14:15:08.0171 1944 aec - ok 14:15:08.0218 1944 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 14:15:08.0218 1944 AFD - ok 14:15:08.0250 1944 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 14:15:08.0250 1944 agp440 - ok 14:15:08.0265 1944 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 14:15:08.0265 1944 agpCPQ - ok 14:15:08.0281 1944 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 14:15:08.0281 1944 Aha154x - ok 14:15:08.0312 1944 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 14:15:08.0328 1944 aic78u2 - ok 14:15:08.0328 1944 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 14:15:08.0343 1944 aic78xx - ok 14:15:08.0359 1944 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 14:15:08.0359 1944 AliIde - ok 14:15:08.0375 1944 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys 14:15:08.0390 1944 alim1541 - ok 14:15:08.0390 1944 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys 14:15:08.0406 1944 amdagp - ok 14:15:08.0406 1944 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 14:15:08.0406 1944 amsint - ok 14:15:08.0453 1944 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 14:15:08.0453 1944 Arp1394 - ok 14:15:08.0468 1944 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 14:15:08.0468 1944 asc - ok 14:15:08.0484 1944 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 14:15:08.0484 1944 asc3350p - ok 14:15:08.0500 1944 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 14:15:08.0500 1944 asc3550 - ok 14:15:08.0531 1944 ASCTRM (d880831279ed91f9a4190a2db9539ea9) C:\WINDOWS\system32\drivers\ASCTRM.sys 14:15:08.0531 1944 ASCTRM - ok 14:15:08.0562 1944 Aspi32 (54ab078660e536da72b21a27f56b035b) C:\WINDOWS\system32\drivers\aspi32.sys 14:15:08.0562 1944 Aspi32 - ok 14:15:08.0593 1944 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 14:15:08.0593 1944 AsyncMac - ok 14:15:08.0609 1944 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 14:15:08.0609 1944 atapi - ok 14:15:08.0640 1944 Atdisk - ok 14:15:08.0718 1944 ati2mtag (f0d0b0cdec0be32d775f404cac2604bf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 14:15:08.0718 1944 ati2mtag - ok 14:15:08.0765 1944 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 14:15:08.0765 1944 Atmarpc - ok 14:15:08.0796 1944 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 14:15:08.0796 1944 audstub - ok 14:15:08.0828 1944 Avc (87c223adb8f7596b31caae3c67b16ddd) C:\WINDOWS\system32\DRIVERS\avc.sys 14:15:08.0828 1944 Avc - ok 14:15:08.0828 1944 AVG Anti-Rootkit - ok 14:15:08.0843 1944 AvgArCln - ok 14:15:08.0859 1944 b57w2k (4826fcf97c47b361a2e2f68cd487a19e) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 14:15:08.0875 1944 b57w2k - ok 14:15:08.0921 1944 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 14:15:08.0921 1944 Beep - ok 14:15:08.0937 1944 bvrp_pci - ok 14:15:09.0000 1944 c2scsi (5cd60ec44e23ef61d7353a090747b850) C:\WINDOWS\system32\drivers\c2scsi.sys 14:15:09.0000 1944 Suspicious file (Forged): C:\WINDOWS\system32\drivers\c2scsi.sys. Real md5: 5cd60ec44e23ef61d7353a090747b850, Fake md5: 56247d46756b399725c2a386f4fc3cc3 14:15:09.0015 1944 c2scsi ( Rootkit.Win32.ZAccess.aml ) - infected 14:15:09.0015 1944 c2scsi - detected Rootkit.Win32.ZAccess.aml (0) 14:15:09.0015 1944 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 14:15:09.0015 1944 cbidf - ok 14:15:09.0031 1944 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 14:15:09.0031 1944 cbidf2k - ok 14:15:09.0093 1944 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 14:15:09.0093 1944 CCDECODE - ok 14:15:09.0109 1944 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 14:15:09.0109 1944 cd20xrnt - ok 14:15:09.0109 1944 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 14:15:09.0125 1944 Cdaudio - ok 14:15:09.0125 1944 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 14:15:09.0140 1944 Cdfs - ok 14:15:09.0187 1944 cdrbsdrv (351735695e9ead93de6af85d8beb1ca8) C:\WINDOWS\system32\drivers\cdrbsdrv.sys 14:15:09.0187 1944 cdrbsdrv - ok 14:15:09.0203 1944 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 14:15:09.0203 1944 Cdrom - ok 14:15:09.0218 1944 Changer - ok 14:15:09.0234 1944 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 14:15:09.0234 1944 CmdIde - ok 14:15:09.0265 1944 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 14:15:09.0265 1944 Cpqarray - ok 14:15:09.0296 1944 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 14:15:09.0296 1944 dac2w2k - ok 14:15:09.0312 1944 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 14:15:09.0312 1944 dac960nt - ok 14:15:09.0343 1944 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 14:15:09.0343 1944 Disk - ok 14:15:09.0406 1944 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 14:15:09.0421 1944 dmboot - ok 14:15:09.0453 1944 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 14:15:09.0453 1944 dmio - ok 14:15:09.0468 1944 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 14:15:09.0468 1944 dmload - ok 14:15:09.0500 1944 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 14:15:09.0515 1944 DMusic - ok 14:15:09.0531 1944 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 14:15:09.0531 1944 dpti2o - ok 14:15:09.0546 1944 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 14:15:09.0562 1944 drmkaud - ok 14:15:09.0593 1944 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys 14:15:09.0593 1944 drvmcdb - ok 14:15:09.0609 1944 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys 14:15:09.0609 1944 drvnddm - ok 14:15:09.0687 1944 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 14:15:09.0687 1944 DSproct - ok 14:15:09.0718 1944 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 14:15:09.0718 1944 dsunidrv - ok 14:15:09.0750 1944 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 14:15:09.0750 1944 E100B - ok 14:15:09.0765 1944 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 14:15:09.0765 1944 Fastfat - ok 14:15:09.0812 1944 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 14:15:09.0812 1944 Fdc - ok 14:15:09.0843 1944 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 14:15:09.0843 1944 Fips - ok 14:15:09.0875 1944 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 14:15:09.0875 1944 Flpydisk - ok 14:15:09.0890 1944 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 14:15:09.0890 1944 FltMgr - ok 14:15:09.0921 1944 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 14:15:09.0937 1944 Fs_Rec - ok 14:15:09.0953 1944 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 14:15:09.0953 1944 Ftdisk - ok 14:15:09.0968 1944 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 14:15:09.0968 1944 GEARAspiWDM - ok 14:15:10.0031 1944 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 14:15:10.0031 1944 Gpc - ok 14:15:10.0109 1944 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 14:15:10.0109 1944 HidUsb - ok 14:15:10.0125 1944 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 14:15:10.0125 1944 hpn - ok 14:15:10.0171 1944 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 14:15:10.0187 1944 HSFHWBS2 - ok 14:15:10.0218 1944 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 14:15:10.0234 1944 HSF_DP - ok 14:15:10.0296 1944 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 14:15:10.0296 1944 HTTP - ok 14:15:10.0312 1944 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys 14:15:10.0312 1944 i2omgmt - ok 14:15:10.0343 1944 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys 14:15:10.0343 1944 i2omp - ok 14:15:10.0375 1944 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 14:15:10.0375 1944 i8042prt - ok 14:15:10.0406 1944 iaStor (d7731536e183b4397402ca6f9e1d52f7) C:\WINDOWS\system32\drivers\iaStor.sys 14:15:10.0421 1944 iaStor - ok 14:15:10.0453 1944 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 14:15:10.0453 1944 Imapi - ok 14:15:10.0468 1944 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 14:15:10.0468 1944 ini910u - ok 14:15:10.0484 1944 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 14:15:10.0484 1944 IntelIde - ok 14:15:10.0500 1944 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 14:15:10.0500 1944 intelppm - ok 14:15:10.0531 1944 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 14:15:10.0546 1944 Ip6Fw - ok 14:15:10.0562 1944 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 14:15:10.0562 1944 IpFilterDriver - ok 14:15:10.0578 1944 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 14:15:10.0578 1944 IpInIp - ok 14:15:10.0625 1944 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 14:15:10.0625 1944 IpNat - ok 14:15:10.0640 1944 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 14:15:10.0640 1944 IPSec - ok 14:15:10.0671 1944 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 14:15:10.0671 1944 IRENUM - ok 14:15:10.0687 1944 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 14:15:10.0687 1944 isapnp - ok 14:15:10.0718 1944 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 14:15:10.0718 1944 Kbdclass - ok 14:15:10.0750 1944 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 14:15:10.0750 1944 kmixer - ok 14:15:10.0765 1944 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys 14:15:10.0781 1944 KSecDD - ok 14:15:10.0812 1944 Lbd - ok 14:15:10.0828 1944 lbrtfdc - ok 14:15:10.0859 1944 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 14:15:10.0859 1944 mdmxsdk - ok 14:15:10.0890 1944 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 14:15:10.0890 1944 mnmdd - ok 14:15:10.0921 1944 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 14:15:10.0921 1944 Modem - ok 14:15:10.0937 1944 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 14:15:10.0937 1944 MODEMCSA - ok 14:15:10.0953 1944 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 14:15:10.0953 1944 Mouclass - ok 14:15:10.0984 1944 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 14:15:10.0984 1944 mouhid - ok 14:15:11.0000 1944 MountMgr (af814611a3b40cd282634c71f8f34fc3) C:\WINDOWS\system32\drivers\MountMgr.sys 14:15:11.0000 1944 MountMgr - ok 14:15:11.0046 1944 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 14:15:11.0046 1944 MpFilter - ok 14:15:11.0140 1944 MpKsl77d9a056 - ok 14:15:11.0156 1944 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 14:15:11.0156 1944 mraid35x - ok 14:15:11.0171 1944 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 14:15:11.0187 1944 MRxDAV - ok 14:15:11.0218 1944 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 14:15:11.0234 1944 MRxSmb - ok 14:15:11.0265 1944 MSDV (6dd721dfd2648f3f6d5808b5ba6cb095) C:\WINDOWS\system32\DRIVERS\msdv.sys 14:15:11.0265 1944 MSDV - ok 14:15:11.0281 1944 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 14:15:11.0281 1944 Msfs - ok 14:15:11.0312 1944 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:15:11.0312 1944 MSKSSRV - ok 14:15:11.0328 1944 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:15:11.0328 1944 MSPCLOCK - ok 14:15:11.0328 1944 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 14:15:11.0343 1944 MSPQM - ok 14:15:11.0359 1944 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:15:11.0359 1944 mssmbios - ok 14:15:11.0390 1944 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 14:15:11.0390 1944 MSTEE - ok 14:15:11.0406 1944 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 14:15:11.0406 1944 Mup - ok 14:15:11.0421 1944 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 14:15:11.0421 1944 NABTSFEC - ok 14:15:11.0468 1944 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 14:15:11.0468 1944 NDIS - ok 14:15:11.0500 1944 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 14:15:11.0500 1944 NdisIP - ok 14:15:11.0531 1944 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:15:11.0531 1944 NdisTapi - ok 14:15:11.0546 1944 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:15:11.0546 1944 Ndisuio - ok 14:15:11.0593 1944 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:15:11.0593 1944 NdisWan - ok 14:15:11.0625 1944 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 14:15:11.0625 1944 NDProxy - ok 14:15:11.0640 1944 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 14:15:11.0640 1944 NetBIOS - ok 14:15:11.0687 1944 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 14:15:11.0703 1944 NetBT - ok 14:15:11.0734 1944 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 14:15:11.0734 1944 NIC1394 - ok 14:15:11.0765 1944 nm (60cf8c7192b3614f240838ddbaa4a245) C:\WINDOWS\system32\DRIVERS\NMnt.sys 14:15:11.0765 1944 nm - ok 14:15:11.0859 1944 NPDriver (542e08a61dcd3ff07bf092f1ab1fa5a8) C:\WINDOWS\system32\Drivers\NPDRIVER.SYS 14:15:11.0859 1944 NPDriver - ok 14:15:11.0890 1944 NPF (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys 14:15:11.0890 1944 NPF - ok 14:15:11.0906 1944 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 14:15:11.0906 1944 Npfs - ok 14:15:11.0968 1944 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 14:15:11.0984 1944 Ntfs - ok 14:15:12.0031 1944 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 14:15:12.0031 1944 Null - ok 14:15:12.0093 1944 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 14:15:12.0125 1944 nv - ok 14:15:12.0171 1944 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:15:12.0171 1944 NwlnkFlt - ok 14:15:12.0187 1944 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:15:12.0187 1944 NwlnkFwd - ok 14:15:12.0203 1944 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 14:15:12.0203 1944 ohci1394 - ok 14:15:12.0250 1944 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys 14:15:12.0250 1944 omci - ok 14:15:12.0296 1944 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 14:15:12.0296 1944 Parport - ok 14:15:12.0328 1944 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 14:15:12.0328 1944 PartMgr - ok 14:15:12.0343 1944 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 14:15:12.0343 1944 ParVdm - ok 14:15:12.0375 1944 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 14:15:12.0375 1944 PCI - ok 14:15:12.0390 1944 PCIDump - ok 14:15:12.0406 1944 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 14:15:12.0406 1944 PCIIde - ok 14:15:12.0421 1944 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 14:15:12.0437 1944 Pcmcia - ok 14:15:12.0437 1944 PDCOMP - ok 14:15:12.0453 1944 PDFRAME - ok 14:15:12.0468 1944 PDRELI - ok 14:15:12.0484 1944 PDRFRAME - ok 14:15:12.0484 1944 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 14:15:12.0500 1944 perc2 - ok 14:15:12.0500 1944 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 14:15:12.0500 1944 perc2hib - ok 14:15:12.0531 1944 Pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys 14:15:12.0531 1944 Pfc - ok 14:15:12.0578 1944 PMEM (2b85237f904c5bdf7ad386f0ede19bd3) C:\WINDOWS\system32\drivers\pmemnt.sys 14:15:12.0578 1944 PMEM - ok 14:15:12.0640 1944 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:15:12.0656 1944 PptpMiniport - ok 14:15:12.0687 1944 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 14:15:12.0687 1944 PSched - ok 14:15:12.0718 1944 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:15:12.0718 1944 Ptilink - ok 14:15:12.0734 1944 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 14:15:12.0734 1944 PxHelp20 - ok 14:15:12.0750 1944 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 14:15:12.0750 1944 ql1080 - ok 14:15:12.0765 1944 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 14:15:12.0765 1944 Ql10wnt - ok 14:15:12.0781 1944 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 14:15:12.0781 1944 ql12160 - ok 14:15:12.0796 1944 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 14:15:12.0796 1944 ql1240 - ok 14:15:12.0812 1944 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 14:15:12.0812 1944 ql1280 - ok 14:15:12.0843 1944 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:15:12.0843 1944 RasAcd - ok 14:15:12.0859 1944 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:15:12.0859 1944 Rasl2tp - ok 14:15:12.0875 1944 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:15:12.0875 1944 RasPppoe - ok 14:15:12.0890 1944 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 14:15:12.0890 1944 Raspti - ok 14:15:12.0921 1944 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:15:12.0921 1944 Rdbss - ok 14:15:12.0937 1944 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:15:12.0937 1944 RDPCDD - ok 14:15:12.0968 1944 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 14:15:12.0968 1944 rdpdr - ok 14:15:13.0000 1944 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 14:15:13.0015 1944 RDPWD - ok 14:15:13.0031 1944 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 14:15:13.0031 1944 redbook - ok 14:15:13.0125 1944 RxFilter (0501074a2f29250932e34ca4a844a0f5) C:\WINDOWS\system32\DRIVERS\RxFilter.sys 14:15:13.0125 1944 RxFilter - ok 14:15:13.0171 1944 sbp2port (3e2c3b180872be4120f246d85560b734) C:\WINDOWS\system32\DRIVERS\sbp2port.sys 14:15:13.0171 1944 sbp2port - ok 14:15:13.0203 1944 SDdriver (f6a78ee51674f62d30f606b27e53d846) C:\WINDOWS\system32\Drivers\sddriver.sys 14:15:13.0203 1944 SDdriver - ok 14:15:13.0234 1944 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:15:13.0234 1944 Secdrv - ok 14:15:13.0281 1944 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys 14:15:13.0296 1944 senfilt - ok 14:15:13.0328 1944 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 14:15:13.0328 1944 serenum - ok 14:15:13.0343 1944 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 14:15:13.0343 1944 Serial - ok 14:15:13.0390 1944 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 14:15:13.0390 1944 Sfloppy - ok 14:15:13.0406 1944 Simbad - ok 14:15:13.0437 1944 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys 14:15:13.0437 1944 sisagp - ok 14:15:13.0468 1944 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 14:15:13.0468 1944 SLIP - ok 14:15:13.0500 1944 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys 14:15:13.0500 1944 smwdm - ok 14:15:13.0531 1944 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\WINDOWS\system32\DRIVERS\snapman.sys 14:15:13.0546 1944 snapman - ok 14:15:13.0593 1944 sonypvs1 (dfadfc2c86662f40759bf02add27d569) C:\WINDOWS\system32\DRIVERS\sonypvs1.sys 14:15:13.0593 1944 sonypvs1 - ok 14:15:13.0640 1944 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 14:15:13.0640 1944 SONYPVU1 - ok 14:15:13.0656 1944 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 14:15:13.0671 1944 Sparrow - ok 14:15:13.0703 1944 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 14:15:13.0703 1944 splitter - ok 14:15:13.0750 1944 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 14:15:13.0750 1944 sr - ok 14:15:13.0812 1944 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 14:15:13.0828 1944 Srv - ok 14:15:13.0828 1944 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 14:15:13.0843 1944 sscdbhk5 - ok 14:15:13.0859 1944 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 14:15:13.0859 1944 ssrtln - ok 14:15:13.0875 1944 StarOpen (e57b778208c783d8debab320c16a1b82) C:\WINDOWS\system32\drivers\StarOpen.sys 14:15:13.0875 1944 StarOpen - ok 14:15:13.0890 1944 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 14:15:13.0890 1944 streamip - ok 14:15:13.0906 1944 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 14:15:13.0906 1944 swenum - ok 14:15:13.0937 1944 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 14:15:13.0937 1944 swmidi - ok 14:15:13.0953 1944 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 14:15:13.0953 1944 symc810 - ok 14:15:13.0968 1944 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 14:15:13.0968 1944 symc8xx - ok 14:15:14.0078 1944 SymEvent (05d9613efe7809e384c10da26958dfa4) C:\Program Files\Symantec\SYMEVENT.SYS 14:15:14.0078 1944 SymEvent - ok 14:15:14.0078 1944 SYMREDRV - ok 14:15:14.0093 1944 SYMTDI - ok 14:15:14.0109 1944 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 14:15:14.0109 1944 sym_hi - ok 14:15:14.0125 1944 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 14:15:14.0125 1944 sym_u3 - ok 14:15:14.0140 1944 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 14:15:14.0140 1944 sysaudio - ok 14:15:14.0187 1944 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:15:14.0187 1944 Tcpip - ok 14:15:14.0218 1944 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 14:15:14.0218 1944 TDPIPE - ok 14:15:14.0265 1944 tdrpman (eb53ec341458256deae2ad58822c4a17) C:\WINDOWS\system32\DRIVERS\tdrpman.sys 14:15:14.0265 1944 tdrpman - ok 14:15:14.0296 1944 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 14:15:14.0296 1944 TDTCP - ok 14:15:14.0328 1944 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 14:15:14.0328 1944 TermDD - ok 14:15:14.0375 1944 tfsnboio (75b30b9ea32fe7d8bbc332d3b944ad46) C:\WINDOWS\system32\dla\tfsnboio.sys 14:15:14.0375 1944 tfsnboio - ok 14:15:14.0390 1944 tfsncofs (b811a431b14694d88eb5befaa55b4501) C:\WINDOWS\system32\dla\tfsncofs.sys 14:15:14.0390 1944 tfsncofs - ok 14:15:14.0406 1944 tfsndrct (f5e2cf2144f1fe51dadd6e9063d311eb) C:\WINDOWS\system32\dla\tfsndrct.sys 14:15:14.0406 1944 tfsndrct - ok 14:15:14.0421 1944 tfsndres (e32b32045b6b914fd4caae8be6ca7e8a) C:\WINDOWS\system32\dla\tfsndres.sys 14:15:14.0421 1944 tfsndres - ok 14:15:14.0421 1944 tfsnifs (43034b10a94d1c6f13a1a0e848f51226) C:\WINDOWS\system32\dla\tfsnifs.sys 14:15:14.0437 1944 tfsnifs - ok 14:15:14.0437 1944 tfsnopio (f5ee0faafde37326ea35acbfa5defd3d) C:\WINDOWS\system32\dla\tfsnopio.sys 14:15:14.0437 1944 tfsnopio - ok 14:15:14.0453 1944 tfsnpool (597348eb65b3e19709e9a45ca2b30b61) C:\WINDOWS\system32\dla\tfsnpool.sys 14:15:14.0453 1944 tfsnpool - ok 14:15:14.0468 1944 tfsnudf (767affd52432a0f7e7d39f6ff64401f4) C:\WINDOWS\system32\dla\tfsnudf.sys 14:15:14.0468 1944 tfsnudf - ok 14:15:14.0484 1944 tfsnudfa (2806b2fd00263ccd90cc0638c6139eb0) C:\WINDOWS\system32\dla\tfsnudfa.sys 14:15:14.0484 1944 tfsnudfa - ok 14:15:14.0515 1944 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 14:15:14.0515 1944 tifsfilter - ok 14:15:14.0546 1944 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\WINDOWS\system32\DRIVERS\timntr.sys 14:15:14.0546 1944 timounter - ok 14:15:14.0562 1944 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 14:15:14.0562 1944 TosIde - ok 14:15:14.0593 1944 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 14:15:14.0593 1944 Udfs - ok 14:15:14.0609 1944 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 14:15:14.0609 1944 ultra - ok 14:15:14.0625 1944 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys 14:15:14.0625 1944 Update - ok 14:15:14.0671 1944 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys 14:15:14.0687 1944 USBAAPL - ok 14:15:14.0718 1944 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys 14:15:14.0718 1944 usbaudio - ok 14:15:14.0734 1944 usbbus (d9f3bb7c292f194f3b053ce295754eb8) C:\WINDOWS\system32\DRIVERS\lgusbbus.sys 14:15:14.0734 1944 usbbus - ok 14:15:14.0781 1944 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 14:15:14.0781 1944 usbccgp - ok 14:15:14.0796 1944 UsbDiag (c4f77da649f99fad116ea585376fc164) C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys 14:15:14.0796 1944 UsbDiag - ok 14:15:14.0828 1944 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 14:15:14.0828 1944 usbehci - ok 14:15:14.0859 1944 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:15:14.0859 1944 usbhub - ok 14:15:14.0875 1944 USBModem (c0613ce45e617bc671de8ebb1b30d175) C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys 14:15:14.0875 1944 USBModem - ok 14:15:14.0921 1944 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 14:15:14.0921 1944 usbprint - ok 14:15:14.0937 1944 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 14:15:14.0937 1944 usbscan - ok 14:15:14.0937 1944 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:15:14.0953 1944 USBSTOR - ok 14:15:15.0000 1944 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 14:15:15.0000 1944 usbuhci - ok 14:15:15.0015 1944 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 14:15:15.0015 1944 VgaSave - ok 14:15:15.0015 1944 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys 14:15:15.0031 1944 viaagp - ok 14:15:15.0078 1944 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 14:15:15.0078 1944 ViaIde - ok 14:15:15.0078 1944 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 14:15:15.0093 1944 VolSnap - ok 14:15:15.0125 1944 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:15:15.0125 1944 Wanarp - ok 14:15:15.0140 1944 wanatw - ok 14:15:15.0187 1944 WDC_SAM (011e8a3e13dd7007353edbee4b180b50) C:\WINDOWS\system32\DRIVERS\wdcsam.sys 14:15:15.0187 1944 WDC_SAM - ok 14:15:15.0187 1944 WDICA - ok 14:15:15.0234 1944 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 14:15:15.0234 1944 wdmaud - ok 14:15:15.0296 1944 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 14:15:15.0312 1944 winachsf - ok 14:15:15.0375 1944 WISTechVIDCAP (d631e5ce1e789cf8ecd277df3e969057) C:\WINDOWS\system32\drivers\Xstream.sys 14:15:15.0375 1944 WISTechVIDCAP - ok 14:15:15.0421 1944 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 14:15:15.0421 1944 WSTCODEC - ok 14:15:15.0437 1944 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:15:15.0437 1944 WudfPf - ok 14:15:15.0468 1944 XLoader (e54d59202747147f6d2501d32c43e35e) C:\WINDOWS\system32\Drivers\XLoader.sys 14:15:15.0468 1944 XLoader - ok 14:15:15.0484 1944 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0 14:15:15.0500 1944 \Device\Harddisk0\DR0 - ok 14:15:15.0500 1944 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1 14:15:16.0218 1944 \Device\Harddisk1\DR1 - ok 14:15:16.0234 1944 Boot (0x1200) (2709fff81818b673feba43ef4151596a) \Device\Harddisk0\DR0\Partition0 14:15:16.0234 1944 \Device\Harddisk0\DR0\Partition0 - ok 14:15:16.0250 1944 Boot (0x1200) (6debf3fda9535e5ce6cf69bea10928da) \Device\Harddisk1\DR1\Partition0 14:15:16.0250 1944 \Device\Harddisk1\DR1\Partition0 - ok 14:15:16.0250 1944 ============================================================ 14:15:16.0250 1944 Scan finished 14:15:16.0250 1944 ============================================================ 14:15:16.0265 1804 Detected object count: 1 14:15:16.0265 1804 Actual detected object count: 1 14:15:23.0359 1804 Backup copy not found, trying to cure infected file.. 14:15:23.0453 1804 Cure success, using it.. 14:15:23.0468 1804 C:\WINDOWS\system32\drivers\c2scsi.sys - will be cured on reboot 14:15:24.0609 1804 c2scsi ( Rootkit.Win32.ZAccess.aml ) - User select action: Cure 14:15:27.0828 0364 Deinitialize success
Excellent! Now we bring in the big guns :D

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi NoodleTech: Clarification on "Disable your Antivirus…" I only use MS Security Essentials. Is it sufficient that Real Time Protection remain unchecked during the ComboFix process? Or do I need to go further with SE? Steve
Okay, NoodleTech, ComboFix has finished. Here's the log:

ComboFix 11-12-22.04 - Steve Hullibarger 12/22/2011 14:49:19.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2558.2088 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Start Menu\Programs\Internet Explorer.lnk
c:\documents and settings\Steve Hullibarger\WINDOWS
c:\windows\$NtUninstallKB51600$
c:\windows\$NtUninstallKB51600$\1664980073
c:\windows\$NtUninstallKB51600$\1970126077\@
c:\windows\$NtUninstallKB51600$\1970126077\bckfg.tmp
c:\windows\$NtUninstallKB51600$\1970126077\cfg.ini
c:\windows\$NtUninstallKB51600$\1970126077\Desktop.ini
c:\windows\$NtUninstallKB51600$\1970126077\keywords
c:\windows\$NtUninstallKB51600$\1970126077\kwrd.dll
c:\windows\$NtUninstallKB51600$\1970126077\L\odetmngk
c:\windows\$NtUninstallKB51600$\1970126077\lsflt7.ver
c:\windows\$NtUninstallKB51600$\1970126077\U\00000001.@
c:\windows\$NtUninstallKB51600$\1970126077\U\00000002.@
c:\windows\$NtUninstallKB51600$\1970126077\U\00000004.@
c:\windows\$NtUninstallKB51600$\1970126077\U\80000000.@
c:\windows\$NtUninstallKB51600$\1970126077\U\80000004.@
c:\windows\$NtUninstallKB51600$\1970126077\U\80000032.@
c:\windows\Downloaded Installations\BMP
c:\windows\Downloaded Installations\BMP\{EA2E6144-0834-4704-915A-AF9FDB0D73CA}\0x0409.ini
c:\windows\Downloaded Installations\BMP\{EA2E6144-0834-4704-915A-AF9FDB0D73CA}\1033.MST
c:\windows\Downloaded Installations\BMP\{EA2E6144-0834-4704-915A-AF9FDB0D73CA}\BACS.msi
c:\windows\system32\ndisapi.dll
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ISPCNERR.HTM
c:\windows\system32\oobe\isperror\ISPDTONE.HTM
c:\windows\system32\oobe\isperror\ISPHDSHK.HTM
c:\windows\system32\oobe\isperror\ISPINS.HTM
c:\windows\system32\oobe\isperror\ISPNOANW.HTM
c:\windows\system32\oobe\isperror\ISPPBERR.HTM
c:\windows\system32\oobe\isperror\ISPPHBSY.HTM
c:\windows\system32\oobe\isperror\ISPSBUSY.HTM
c:\windows\system32\regobj.dll
c:\windows\system32\SET151.tmp
c:\windows\system32\SET154.tmp
c:\windows\system32\SET205.tmp
c:\windows\system32\SET20A.tmp
c:\windows\system32\SET211.tmp
c:\windows\system32\SET21A.tmp
c:\windows\system32\SET21B.tmp
c:\windows\system32\SET21C.tmp
c:\windows\system32\SET21E.tmp
c:\windows\system32\SET21F.tmp
c:\windows\winhelp.ini
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\i386\USERINIT.EXE
.
.
((((((((((((((((((((((((( Files Created from 2011-11-22 to 2011-12-22 )))))))))))))))))))))))))))))))
.
.
2011-12-22 20:02 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0F324DC5-4DDC-48D3-981A-B5808A250035}\mpengine.dll
2011-12-22 00:12 . 2011-12-22 22:17 ——– d—–w- C:\TEMP VIRUS REMOVAL
2011-12-21 01:12 . 2011-12-21 01:12 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2011-12-21 01:12 . 2011-12-21 01:12 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2011-12-21 01:12 . 2011-12-21 01:12 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2011-12-21 01:12 . 2011-12-21 01:12 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-20 23:03 . 2011-12-21 00:43 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-20 22:58 . 2011-12-20 22:58 ——– d—–w- c:\documents and settings\Steve Hullibarger\Application Data\Malwarebytes
2011-12-20 22:58 . 2011-12-20 22:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-20 22:40 . 2011-12-21 17:47 ——– d—–w- c:\documents and settings\Steve Hullibarger\Local Settings\Application Data\LogMeIn Rescue Applet
2011-12-20 22:40 . 2011-12-20 22:40 ——– d—–w- c:\documents and settings\Steve Hullibarger\Local Settings\Application Data\Deployment
2011-12-20 20:08 . 2011-12-20 20:08 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-12-20 18:54 . 2011-12-20 19:28 ——– d—–w- C:\TEMP LL Pix for KPS
2011-11-30 23:51 . 2011-12-06 00:22 ——– d—–w- C:\TEMP ACROBAT OCR
2011-11-26 01:50 . 2011-12-22 00:15 ——– d—–w- C:\Temp November Pix
2011-11-22 23:48 . 2011-11-26 21:39 ——– d—–w- C:\TEMP PIX
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 22:15 . 2009-06-10 16:49 244608 —-a-w- c:\windows\system32\drivers\c2scsi.sys
2011-11-21 10:47 . 2010-04-16 17:06 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-12-21 01:12 . 2011-11-13 18:24 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Simple Reminder"="c:\program files\Simple Reminder\Simple Reminder.exe" [2006-02-25 851968]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 106544]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-14 54472]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Eudora\EuShlExt.dll" [2005-06-08 86016]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Steve Hullibarger^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\Steve Hullibarger\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-06-17 00:20 624056 —-a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-10-31 03:07 140568 —-a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-10-31 03:11 909208 —-a-w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-08-25 17:52 339968 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-04 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPMonitor]
2009-04-20 15:10 84464 —-a-w- c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 10:00 15360 ——w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 18:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-04-12 22:46 1135912 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-11-16 09:05 127035 ——w- c:\windows\SYSTEM32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 21:54 57344 ——w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 05:34 49152 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2004-06-29 16:23 135168 —-a-w- c:\program files\Intel\Intel Application Accelerator\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2006-03-21 00:34 213936 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-03-21 00:34 213936 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2008-10-24 16:14 79136 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 04:21 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2004-09-14 13:50 53248 —-a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2004-09-14 13:50 131072 —-a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 –sh–w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
1998-10-13 02:13 44032 —-a-w- c:\program files\OmniPage\OPware32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2005-10-06 08:37 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2008-08-14 08:23 240112 —-a-w- c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 19:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2003-11-19 22:48 32881 —-a-w- c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-11-11 23:03 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-10-31 03:06 2595616 —-a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]
2000-06-18 21:03 106544 ——w- c:\windows\SYSTEM32\TWEAKUI.CPL
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Drive Manager]
2008-05-17 00:12 430080 —-a-w- c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Roxio Creator 2009\\Creator Classic 11\\Creator11.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery
.
R1 c2scsi;c2scsi;c:\windows\SYSTEM32\DRIVERS\c2scsi.sys [6/10/2009 8:49 AM 244608]
R2 NProtectService;Norton Unerase Protection;c:\progra~1\NORTON~1\NORTON~2\NPROTECT.EXE [11/24/2003 11:49 AM 81920]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 4:12 PM 102400]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 MpKsl77d9a056;MpKsl77d9a056;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C52F0162-C7DD-4CDB-832B-CA07DF29BE1E}\MpKsl77d9a056.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C52F0162-C7DD-4CDB-832B-CA07DF29BE1E}\MpKsl77d9a056.sys [?]
S2 gupdate1c9b63e6aca8b7a;Google Update Service (gupdate1c9b63e6aca8b7a);c:\program files\Google\Update\GoogleUpdate.exe [4/5/2009 2:32 PM 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" –> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [8/14/2008 12:25 AM 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [8/14/2008 12:24 AM 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [8/14/2008 12:24 AM 170480]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/5/2009 2:32 PM 133104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [11/6/2007 12:22 PM 34064]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [8/14/2008 12:25 AM 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [3/3/2009 6:58 PM 1122304]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\SYSTEM32\DRIVERS\wdcsam.sys [8/27/2008 12:13 PM 10112]
S3 XLoader;PLEXTOR EZ-USB FX2 FIRMWARE LOADER (XLoader.sys);c:\windows\SYSTEM32\DRIVERS\XLoader.sys [9/3/2004 10:42 PM 13184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-11 22:36]
.
2011-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-05 22:32]
.
2011-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-05 22:32]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = [removed] [removed]
DPF: {79D1DBE2-A317-4D67-891D-9849D17F0531} - hxxp://www.parcelquest.com/download/MapEdge.cab
FF - ProfilePath - c:\documents and settings\Steve Hullibarger\Application Data\Mozilla\Firefox\Profiles\vqbjk8m2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
.
.
——- File Associations ——-
.
.scr=DWGTrueViewScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Notify-dimsntfy - (no file)
SafeBoot-76802736.sys
MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-22 15:00
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(920)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(812)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Digital Vault\StompFDBNS3.dll
c:\program files\Digital Vault\Vault.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Application Accelerator\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\progra~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\fxssvc.exe
.
**************************************************************************
.
Completion time: 2011-12-22 15:05:01 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-22 23:04
.
Pre-Run: 268,205,604,864 bytes free
Post-Run: 268,550,672,384 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C309D21D0DAFE5F0E3A498BC40E7AA46
Hi Steve,

Your computer is looking good! How is it running now? I see you have Malwarebytes Antimalware installed. Can you please open it, update it, then run a quick scan and post the log?

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 2.
  • Click on jre-7u2-windows-i586.exe if you are running 32-bit Windows or jre-7u2-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Flash Player is out of date
  • Outdated versions of Flash are vulnerable to malware infections.
  • Please uninstall old versions of Flash Player by following the instructions here.
  • Next, click here to download the latest version of Flash Player.
  • Uncheck "Yes, install Google Toolbar - optional" if you do not want to install Google Toolbar.
  • Click Download Now then double click on the setup file to start the installation.
Hey NoodleTech, The computer is running great. No problems so far. I ran Malwarebytes. Here's the log. While you're reviewing it, I'll get going on the Java and Flash Player updates. Steve Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122205 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 12/22/2011 3:34:16 PM mbam-log-2011-12-22 (15-34-16).txt Scan type: Quick scan Objects scanned: 190381 Time elapsed: 1 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI