This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tidserv Activity 2 [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't seem to get a post thru. I have tried sending all the info in 1 post….then I tried in 2 posts and then in 3 posts and it wouldn't go thru. I am trying just my symptoms this time. I am running IE Windows XP sp3 Norton 360 is detecting the Tidserv Activity 2 with a little Norton popup in the lower left corner of my screen. My computer was acting fine except for this popup. I followed the Norton removal instructions and they had me use FixTDSS.exe removal tool which triggered the XP Anti Spyware 2012 Alert. I was then told to use Norton power eraser to rid the XP Anti Spyware 2012 Alert which worked but the Tidserv Activity 2 is still present. Norton then recommended the FixTDSS.exe removal tool again. The tool said it worked and no infection was present but the Norton Tidserv Activity 2 popup came back. I tried the Fix TDSS.exe removal tool several more times with no avail…still comes back. Norton recommended a few forums that could help and I chose you. I have the scan results from OTL but I cant seem to get is thru in a post
Hi redmax1,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Let's try DDS and see if you can post that log.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
. DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 15:59:34 on 2011-12-22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.185 [GMT -5:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Documents and Settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe C:\Program Files\Fighters\SPAMfighter\sfus.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Fighters\FighterSuiteService.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe C:\Program Files\Fighters\SPAMfighter\sfagent.exe C:\Program Files\ATI Multimedia\main\launchpd.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.rr.com/index.cfm uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll TB: {8AE33802-00D3-4F1B-B5C7-6FEE34E402CE} - No File EB: {2AA2FBF8-9C76-4E97-A226-25C5F4AB6358} - No File EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL uRun: [ATI Launchpad] "c:\program files\ati multimedia\main\launchpd.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [ATnotes.exe] c:\program files\atnotes\ATnotes.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [sfagent] c:\program files\fighters\spamfighter\sfagent.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: mswsock.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9} DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{8072E46F-97C6-4CF2-9D15-83E5E1508F7E} : DhcpNameServer = [removed] [removed] Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\larry.max\application data\mozilla\firefox\profiles\8kf06vey.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com/index.cfm FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\symds.sys [2011-5-18 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\symefa.sys [2011-5-18 744568] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20111221.003\BHDrvx86.sys [2011-12-22 819320] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys [2011-5-18 136312] R2 dmsmbios;dmsmbios;c:\windows\system32\dmsmbios.sys [2000-5-2 16480] R2 FreemakeUtilsService;Freemake Service;c:\documents and settings\all users.windows\application data\freemake\freemakeutilsservice\FreemakeUtilsService.exe [2011-9-8 74240] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccsvchst.exe [2011-5-18 130008] R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2011-3-15 428384] R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2011-8-19 215688] R2 Suite Service;Suite Service;c:\program files\fighters\FighterSuiteService.exe [2011-8-19 1302152] R3 ATICXCAP;ATI TV Wonder Pro A/V Capture;c:\windows\system32\drivers\aticxcap.sys [2005-3-30 173824] R3 ATICXTUN;ATI TV Wonder Pro Tuner (Philips 1236 MK3);c:\windows\system32\drivers\aticxtun.sys [2005-3-30 29184] R3 ATICXXBR;ATI TV Wonder Pro A/V Crossbar;c:\windows\system32\drivers\aticxxbr.sys [2005-3-30 9088] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-11-9 106104] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20111221.001\IDSXpx86.sys [2011-12-22 356280] R3 NAVENG;NAVENG;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\virusdefs\20111221.034\NAVENG.SYS [2011-12-22 86136] R3 NAVEX15;NAVEX15;c:\documents and settings\all users.windows\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\virusdefs\20111221.034\NAVEX15.SYS [2011-12-22 1576312] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-12-21 06:01:17 64512 -c–a-w- c:\windows\system32\dllcache\serial.sys 2011-12-21 06:01:17 64512 —-a-w- c:\windows\system32\drivers\serial.sys 2011-12-21 06:00:37 33280 -c–a-w- c:\windows\system32\dllcache\rundll32.exe 2011-12-21 06:00:37 33280 —-a-w- c:\windows\system32\rundll32.exe 2011-12-20 01:13:43 ——– d—–w- c:\documents and settings\larry.max\local settings\application data\NPE . ==================== Find3M ==================== . 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-11 16:10:42 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll 2011-10-11 12:27:53 41 —-a-w- c:\windows\WFXDEL.BAT 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2008-09-09 19:37:35 774144 —-a-w- c:\program files\RngInterstitial.dll . ============= FINISH: 16:00:35.26 ===============

Attachments:

Hi NoodleTech This is the last of the list you gave me to do….Thank you for taking the tim. :notworthy: aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-22 16:17:59 —————————– 16:17:59.500 OS Version: Windows 5.1.2600 Service Pack 3 16:17:59.500 Number of processors: 1 586 0x204 16:17:59.500 ComputerName: MAX UserName: 16:18:00.218 Initialize success 16:19:13.718 The log file has been saved successfully to "C:\Documents and Settings\Larry.MAX\Desktop\Noodle Tech\aswMBR.txt" 16:20:35.453 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0 16:20:35.453 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3 16:20:35.453 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0 16:20:35.453 Disk 1 Vendor: Maxtor_6 YAR4 Size: 194481MB BusType: 3 16:20:35.453 Disk 2 \Device\Harddisk2\DR2 -> \Device\Scsi\ultra1Port2Path0Target1Lun0 16:20:35.453 Disk 2 Vendor: Maxtor_6 YAR4 Size: 117246MB BusType: 3 16:20:35.453 Disk 3 \Device\Harddisk3\DR3 -> \Device\Scsi\SI31121Port3Path0Target0Lun0 16:20:35.453 Disk 3 Vendor: Maxtor_6 YAR5 Size: 239372MB BusType: 1 16:20:35.484 Disk 0 MBR read successfully 16:20:35.484 Disk 0 MBR scan 16:20:35.484 Disk 0 Windows XP default MBR code 16:20:35.484 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 238472 MB offset 63 16:20:35.484 Disk 0 scanning sectors +488392065 16:20:35.578 Disk 0 scanning C:\WINDOWS\system32\drivers 16:20:43.812 Service scanning 16:20:44.968 Modules scanning 16:20:47.109 Module: C:\WINDOWS\system32\DRIVERS\serial.sys **SUSPICIOUS** 16:21:11.343 Disk 0 trace - called modules: 16:21:11.343 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86a4df10]<< 16:21:11.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87359030] 16:21:11.343 3 CLASSPNP.SYS[f76b3fd7] -> nt!IofCallDriver -> [0x86a99c78] 16:21:11.343 \Driver\00001187[0x86a9af38] -> IRP_MJ_CREATE -> 0x86a4df10 16:21:11.343 Scan finished successfully 16:21:20.781 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Larry.MAX\Desktop\Noodle Tech\MBR.dat" 16:21:20.796 The log file has been saved successfully to "C:\Documents and Settings\Larry.MAX\Desktop\Noodle Tech\aswMBR.txt"

Attachments:

Hi redmax1,

No problem :)

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
TDSSKiller scan…….. 16:43:12.0390 1944 TDSS rootkit removing tool [removed] Dec 22 2011 18:21:27 16:43:14.0390 1944 ============================================================ 16:43:14.0390 1944 Current date / time: 2011/12/22 16:43:14.0390 16:43:14.0390 1944 SystemInfo: 16:43:14.0390 1944 16:43:14.0390 1944 OS Version: 5.1.2600 ServicePack: 3.0 16:43:14.0390 1944 Product type: Workstation 16:43:14.0390 1944 ComputerName: MAX 16:43:14.0390 1944 UserName: Larry 16:43:14.0390 1944 Windows directory: C:\WINDOWS 16:43:14.0390 1944 System windows directory: C:\WINDOWS 16:43:14.0390 1944 Processor architecture: Intel x86 16:43:14.0390 1944 Number of processors: 1 16:43:14.0390 1944 Page size: 0x1000 16:43:14.0390 1944 Boot type: Normal boot 16:43:14.0390 1944 ============================================================ 16:43:16.0078 1944 Initialize success 16:43:20.0796 3884 ============================================================ 16:43:20.0796 3884 Scan started 16:43:20.0796 3884 Mode: Manual; 16:43:20.0796 3884 ============================================================ 16:43:21.0281 3884 Abiosdsk - ok 16:43:21.0343 3884 abp480n5 - ok 16:43:21.0406 3884 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:43:21.0421 3884 ACPI - ok 16:43:21.0453 3884 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:43:21.0468 3884 ACPIEC - ok 16:43:21.0484 3884 adpu160m - ok 16:43:21.0546 3884 aeaudio (85c33f7f55042f9034818b96948d94c0) C:\WINDOWS\system32\drivers\aeaudio.sys 16:43:21.0546 3884 aeaudio - ok 16:43:21.0593 3884 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 16:43:21.0609 3884 aec - ok 16:43:21.0656 3884 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 16:43:21.0671 3884 AFD - ok 16:43:21.0718 3884 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 16:43:21.0734 3884 agp440 - ok 16:43:21.0765 3884 Aha154x - ok 16:43:21.0781 3884 aic78u2 - ok 16:43:21.0812 3884 aic78xx - ok 16:43:21.0859 3884 AliIde - ok 16:43:21.0875 3884 amsint - ok 16:43:21.0953 3884 asc - ok 16:43:21.0968 3884 asc3350p - ok 16:43:22.0000 3884 asc3550 - ok 16:43:22.0062 3884 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:43:22.0062 3884 AsyncMac - ok 16:43:22.0125 3884 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:43:22.0125 3884 atapi - ok 16:43:22.0156 3884 Atdisk - ok 16:43:22.0265 3884 ati2mtag (07ac9a98ea70b5a6655a5797174bd282) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 16:43:22.0343 3884 ati2mtag - ok 16:43:22.0390 3884 ATICXCAP (b27b6cc25e81165bb946ded4ec8eea0b) C:\WINDOWS\system32\drivers\aticxcap.sys 16:43:22.0406 3884 ATICXCAP - ok 16:43:22.0453 3884 ATICXTUN (2fd0cdfee26d490b6f8de9a035d522b6) C:\WINDOWS\system32\drivers\aticxtun.sys 16:43:22.0453 3884 ATICXTUN - ok 16:43:22.0484 3884 ATICXXBR (ba877c4698f4477d6a69f9e071337c4b) C:\WINDOWS\system32\drivers\aticxxbr.sys 16:43:22.0484 3884 ATICXXBR - ok 16:43:22.0546 3884 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:43:22.0546 3884 Atmarpc - ok 16:43:22.0609 3884 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:43:22.0609 3884 audstub - ok 16:43:22.0640 3884 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:43:22.0640 3884 Beep - ok 16:43:22.0781 3884 BHDrvx86 (9d14d76e4e7b9b2ead17149011db2b11) C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111221.003\BHDrvx86.sys 16:43:22.0843 3884 BHDrvx86 - ok 16:43:22.0937 3884 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:43:22.0937 3884 cbidf2k - ok 16:43:23.0015 3884 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 16:43:23.0015 3884 CCDECODE - ok 16:43:23.0046 3884 cd20xrnt - ok 16:43:23.0093 3884 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:43:23.0093 3884 Cdaudio - ok 16:43:23.0125 3884 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 16:43:23.0125 3884 Cdfs - ok 16:43:23.0187 3884 Cdr4_xp (b9cff0a9ed63e9bd4931847284a33401) C:\WINDOWS\system32\drivers\Cdr4_xp.sys 16:43:23.0203 3884 Cdr4_xp - ok 16:43:23.0234 3884 Cdralw2k (bf09211c3fb1b6c93ecb58973f84ee23) C:\WINDOWS\system32\drivers\Cdralw2k.sys 16:43:23.0250 3884 Cdralw2k - ok 16:43:23.0281 3884 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:43:23.0281 3884 Cdrom - ok 16:43:23.0312 3884 cdudf_xp (a19f8c660426e02aa99af1ed3d0dcb1c) C:\WINDOWS\system32\drivers\cdudf_xp.sys 16:43:23.0343 3884 cdudf_xp - ok 16:43:23.0359 3884 Changer - ok 16:43:23.0406 3884 CmdIde - ok 16:43:23.0453 3884 Cpqarray - ok 16:43:23.0484 3884 dac2w2k - ok 16:43:23.0500 3884 dac960nt - ok 16:43:23.0546 3884 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 16:43:23.0562 3884 Disk - ok 16:43:23.0625 3884 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 16:43:23.0640 3884 dmboot - ok 16:43:23.0687 3884 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 16:43:23.0687 3884 dmio - ok 16:43:23.0718 3884 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:43:23.0718 3884 dmload - ok 16:43:23.0781 3884 dmsmbios (43cb4f8c4c110f06e5b0a1f15787a081) C:\WINDOWS\system32\dmsmbios.sys 16:43:23.0812 3884 dmsmbios - ok 16:43:23.0843 3884 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 16:43:23.0859 3884 DMusic - ok 16:43:23.0890 3884 dpti2o - ok 16:43:23.0906 3884 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 16:43:23.0921 3884 drmkaud - ok 16:43:23.0984 3884 drvmcdb (d078ee6ab06a6cdd3849d9b93ddf1ca5) C:\WINDOWS\system32\DRIVERS\drvmcdb.sys 16:43:24.0000 3884 drvmcdb - ok 16:43:24.0046 3884 dvd_2K (943873bf94e372b78ab0b0631069ac2b) C:\WINDOWS\system32\drivers\dvd_2K.sys 16:43:24.0062 3884 dvd_2K - ok 16:43:24.0125 3884 E100B (fe9cb643a034285031502d3369e5a869) C:\WINDOWS\system32\DRIVERS\e100b325.sys 16:43:24.0125 3884 E100B - ok 16:43:24.0250 3884 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 16:43:24.0265 3884 eeCtrl - ok 16:43:24.0296 3884 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 16:43:24.0296 3884 EraserUtilRebootDrv - ok 16:43:24.0406 3884 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 16:43:24.0406 3884 Fastfat - ok 16:43:24.0468 3884 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 16:43:24.0468 3884 Fdc - ok 16:43:24.0500 3884 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 16:43:24.0500 3884 Fips - ok 16:43:24.0531 3884 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 16:43:24.0531 3884 Flpydisk - ok 16:43:24.0562 3884 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 16:43:24.0578 3884 FltMgr - ok 16:43:24.0640 3884 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:43:24.0656 3884 Fs_Rec - ok 16:43:24.0703 3884 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:43:24.0703 3884 Ftdisk - ok 16:43:24.0765 3884 GEARAspiWDM (5ae3a887ece5bbb72cfab273c2fd1cfa) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 16:43:24.0796 3884 GEARAspiWDM - ok 16:43:24.0937 3884 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:43:24.0968 3884 Gpc - ok 16:43:25.0078 3884 HCF_MSFT (4236e014632f4163f53ebb717f41594c) C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys 16:43:25.0109 3884 HCF_MSFT - ok 16:43:25.0171 3884 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:43:25.0171 3884 hidusb - ok 16:43:25.0203 3884 hpn - ok 16:43:25.0312 3884 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 16:43:25.0343 3884 HTTP - ok 16:43:25.0375 3884 i2omgmt - ok 16:43:25.0406 3884 i2omp - ok 16:43:25.0437 3884 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:43:25.0453 3884 i8042prt - ok 16:43:25.0500 3884 IdeBusDr (4ec233ef7c2a2c36fa962de2ae5d982a) C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys 16:43:25.0515 3884 IdeBusDr - ok 16:43:25.0546 3884 IdeChnDr (e1b24e6478ab2e5e09c21d2028e2f208) C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys 16:43:25.0546 3884 IdeChnDr - ok 16:43:25.0734 3884 IDSxpx86 (e72d3894d42355e9cd5fd77e1e4fea11) C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111221.001\IDSxpx86.sys 16:43:25.0750 3884 IDSxpx86 - ok 16:43:25.0812 3884 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:43:25.0828 3884 Imapi - ok 16:43:25.0859 3884 ini910u - ok 16:43:25.0890 3884 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:43:25.0890 3884 IntelIde - ok 16:43:25.0921 3884 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 16:43:25.0921 3884 intelppm - ok 16:43:25.0968 3884 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 16:43:25.0968 3884 Ip6Fw - ok 16:43:26.0015 3884 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:43:26.0015 3884 IpFilterDriver - ok 16:43:26.0062 3884 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:43:26.0062 3884 IpInIp - ok 16:43:26.0109 3884 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:43:26.0109 3884 IpNat - ok 16:43:26.0156 3884 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 16:43:26.0171 3884 IPSec - ok 16:43:26.0218 3884 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:43:26.0218 3884 IRENUM - ok 16:43:26.0281 3884 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:43:26.0281 3884 isapnp - ok 16:43:26.0343 3884 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:43:26.0343 3884 Kbdclass - ok 16:43:26.0406 3884 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16:43:26.0406 3884 kbdhid - ok 16:43:26.0453 3884 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 16:43:26.0453 3884 kmixer - ok 16:43:26.0500 3884 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 16:43:26.0500 3884 KSecDD - ok 16:43:26.0546 3884 Lavasoft Kernexplorer - ok 16:43:26.0562 3884 lbrtfdc - ok 16:43:26.0656 3884 mmc_2K (18032034b88c7f9e9068df91ab3ae968) C:\WINDOWS\system32\drivers\mmc_2K.sys 16:43:26.0703 3884 mmc_2K - ok 16:43:26.0859 3884 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:43:27.0781 3884 mnmdd - ok 16:43:27.0968 3884 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 16:43:27.0968 3884 Modem - ok 16:43:28.0031 3884 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:43:28.0031 3884 Mouclass - ok 16:43:28.0109 3884 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 16:43:28.0109 3884 mouhid - ok 16:43:28.0171 3884 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 16:43:28.0171 3884 MountMgr - ok 16:43:28.0203 3884 mraid35x - ok 16:43:28.0265 3884 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:43:28.0265 3884 MRxDAV - ok 16:43:28.0343 3884 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:43:28.0359 3884 MRxSmb - ok 16:43:28.0421 3884 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 16:43:28.0421 3884 Msfs - ok 16:43:28.0468 3884 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:43:28.0468 3884 MSKSSRV - ok 16:43:28.0515 3884 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:43:28.0515 3884 MSPCLOCK - ok 16:43:28.0546 3884 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 16:43:28.0546 3884 MSPQM - ok 16:43:28.0593 3884 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:43:28.0609 3884 mssmbios - ok 16:43:28.0656 3884 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 16:43:28.0656 3884 MSTEE - ok 16:43:28.0703 3884 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 16:43:28.0703 3884 Mup - ok 16:43:28.0812 3884 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 16:43:28.0812 3884 NABTSFEC - ok 16:43:29.0000 3884 NAVENG (862f55824ac81295837b0ab63f91071f) C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111222.002\NAVENG.SYS 16:43:29.0015 3884 NAVENG - ok 16:43:29.0078 3884 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111222.002\NAVEX15.SYS 16:43:29.0140 3884 NAVEX15 - ok 16:43:29.0218 3884 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 16:43:29.0234 3884 NDIS - ok 16:43:29.0281 3884 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 16:43:29.0281 3884 NdisIP - ok 16:43:29.0328 3884 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:43:29.0328 3884 NdisTapi - ok 16:43:29.0390 3884 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:43:29.0390 3884 Ndisuio - ok 16:43:29.0437 3884 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:43:29.0437 3884 NdisWan - ok 16:43:29.0500 3884 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 16:43:29.0500 3884 NDProxy - ok 16:43:29.0562 3884 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:43:29.0562 3884 NetBIOS - ok 16:43:29.0609 3884 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:43:29.0609 3884 NetBT - ok 16:43:29.0687 3884 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 16:43:29.0687 3884 Npfs - ok 16:43:29.0765 3884 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 16:43:29.0796 3884 Ntfs - ok 16:43:29.0890 3884 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:43:29.0890 3884 Null - ok 16:43:29.0953 3884 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:43:29.0953 3884 NwlnkFlt - ok 16:43:29.0984 3884 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:43:30.0015 3884 NwlnkFwd - ok 16:43:30.0078 3884 P1110VID (f1fda9093a04d77063ae84fe3f9a30a0) C:\WINDOWS\system32\DRIVERS\P1110VID.sys 16:43:30.0093 3884 P1110VID - ok 16:43:30.0156 3884 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 16:43:30.0156 3884 Parport - ok 16:43:30.0218 3884 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 16:43:30.0218 3884 PartMgr - ok 16:43:30.0265 3884 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 16:43:30.0265 3884 ParVdm - ok 16:43:30.0312 3884 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 16:43:30.0312 3884 PCI - ok 16:43:30.0343 3884 PCIDump - ok 16:43:30.0359 3884 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 16:43:30.0359 3884 PCIIde - ok 16:43:30.0406 3884 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:43:30.0437 3884 Pcmcia - ok 16:43:30.0468 3884 PDCOMP - ok 16:43:30.0484 3884 PDFRAME - ok 16:43:30.0515 3884 PDRELI - ok 16:43:30.0531 3884 PDRFRAME - ok 16:43:30.0562 3884 perc2 - ok 16:43:30.0593 3884 perc2hib - ok 16:43:30.0640 3884 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys 16:43:30.0656 3884 pfc - ok 16:43:30.0765 3884 Point32 (cf7c1868b90c90a265fc3f60ce46265b) C:\WINDOWS\system32\DRIVERS\point32.sys 16:43:30.0765 3884 Point32 - ok 16:43:30.0828 3884 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:43:30.0843 3884 PptpMiniport - ok 16:43:30.0875 3884 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 16:43:30.0875 3884 PSched - ok 16:43:30.0921 3884 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:43:30.0937 3884 Ptilink - ok 16:43:31.0000 3884 pwd_2k (4f1948a73db89ee4b34feeedd6745ee1) C:\WINDOWS\system32\drivers\pwd_2k.sys 16:43:31.0015 3884 pwd_2k - ok 16:43:31.0078 3884 PxHelp20 (8948c3f19a69808610c39db2a8c5f1c7) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys 16:43:31.0093 3884 PxHelp20 - ok 16:43:31.0109 3884 ql1080 - ok 16:43:31.0140 3884 Ql10wnt - ok 16:43:31.0156 3884 ql12160 - ok 16:43:31.0187 3884 ql1240 - ok 16:43:31.0218 3884 ql1280 - ok 16:43:31.0250 3884 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:43:31.0250 3884 RasAcd - ok 16:43:31.0312 3884 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:43:31.0312 3884 Rasl2tp - ok 16:43:31.0359 3884 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:43:31.0359 3884 RasPppoe - ok 16:43:31.0406 3884 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:43:31.0421 3884 Raspti - ok 16:43:31.0468 3884 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:43:31.0484 3884 Rdbss - ok 16:43:31.0500 3884 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:43:31.0500 3884 RDPCDD - ok 16:43:31.0562 3884 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:43:31.0562 3884 rdpdr - ok 16:43:31.0625 3884 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 16:43:31.0625 3884 RDPWD - ok 16:43:31.0687 3884 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:43:31.0687 3884 redbook - ok 16:43:31.0812 3884 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:43:31.0812 3884 Secdrv - ok 16:43:31.0859 3884 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 16:43:31.0875 3884 serenum - ok 16:43:31.0921 3884 Serial (2d542f2eb1c958ee5f687d5aaf95aa23) C:\WINDOWS\system32\DRIVERS\serial.sys 16:43:31.0921 3884 Serial - ok 16:43:32.0000 3884 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:43:32.0000 3884 Sfloppy - ok 16:43:32.0078 3884 SI3112 (f459dd5ee69d4b68cb6767c9731b5faf) C:\WINDOWS\system32\DRIVERS\SI3112.sys 16:43:32.0078 3884 SI3112 - ok 16:43:32.0093 3884 SiFilter (96b43459e9bd1dad1873a47ddde9bdf4) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys 16:43:32.0109 3884 SiFilter - ok 16:43:32.0125 3884 Simbad - ok 16:43:32.0156 3884 SiRemFil (40f3babe67c1c51fbb3ee64ea9209e1f) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys 16:43:32.0156 3884 SiRemFil - ok 16:43:32.0203 3884 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 16:43:32.0203 3884 SLIP - ok 16:43:32.0281 3884 smwdm (21653671be98f2772da766b74419c725) C:\WINDOWS\system32\drivers\smwdm.sys 16:43:32.0296 3884 smwdm - ok 16:43:32.0343 3884 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 16:43:32.0343 3884 SONYPVU1 - ok 16:43:32.0375 3884 Sparrow - ok 16:43:32.0421 3884 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 16:43:32.0421 3884 splitter - ok 16:43:32.0453 3884 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 16:43:32.0468 3884 sr - ok 16:43:32.0546 3884 SRTSP (83726cf02eced69138948083e06b6eac) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SRTSP.SYS 16:43:32.0562 3884 SRTSP - ok 16:43:32.0593 3884 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\WINDOWS\system32\drivers\N360\0501000.01D\SRTSPX.SYS 16:43:32.0593 3884 SRTSPX - ok 16:43:32.0671 3884 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 16:43:32.0687 3884 Srv - ok 16:43:32.0750 3884 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 16:43:32.0765 3884 streamip - ok 16:43:32.0828 3884 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:43:32.0828 3884 swenum - ok 16:43:32.0890 3884 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 16:43:32.0890 3884 swmidi - ok 16:43:32.0937 3884 symc810 - ok 16:43:32.0953 3884 symc8xx - ok 16:43:33.0031 3884 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMDS.SYS 16:43:33.0062 3884 SymDS - ok 16:43:33.0125 3884 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\WINDOWS\system32\drivers\N360\0501000.01D\SYMEFA.SYS 16:43:33.0140 3884 SymEFA - ok 16:43:33.0203 3884 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 16:43:33.0203 3884 SymEvent - ok 16:43:33.0265 3884 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\WINDOWS\system32\drivers\N360\0501000.01D\Ironx86.SYS 16:43:33.0281 3884 SymIRON - ok 16:43:33.0343 3884 SYMTDI (dec35ccaf7a222df918306cd2fdfbd39) C:\WINDOWS\System32\Drivers\N360\0501000.01D\SYMTDI.SYS 16:43:33.0343 3884 SYMTDI - ok 16:43:33.0375 3884 sym_hi - ok 16:43:33.0406 3884 sym_u3 - ok 16:43:33.0453 3884 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 16:43:33.0453 3884 sysaudio - ok 16:43:33.0531 3884 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:43:33.0546 3884 Tcpip - ok 16:43:33.0593 3884 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:43:33.0609 3884 TDPIPE - ok 16:43:33.0656 3884 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 16:43:33.0656 3884 TDTCP - ok 16:43:33.0703 3884 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:43:33.0703 3884 TermDD - ok 16:43:33.0750 3884 TosIde - ok 16:43:33.0828 3884 UdfReadr_xp (37148e648e0f3a6694040fd9f80941b7) C:\WINDOWS\system32\drivers\UdfReadr_xp.sys 16:43:33.0843 3884 UdfReadr_xp - ok 16:43:33.0906 3884 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 16:43:33.0906 3884 Udfs - ok 16:43:33.0937 3884 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 16:43:33.0953 3884 ultra - ok 16:43:34.0000 3884 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 16:43:34.0015 3884 Update - ok 16:43:34.0078 3884 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 16:43:34.0078 3884 USBAAPL - ok 16:43:34.0125 3884 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:43:34.0125 3884 usbccgp - ok 16:43:34.0171 3884 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:43:34.0171 3884 usbehci - ok 16:43:34.0234 3884 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:43:34.0234 3884 usbhub - ok 16:43:34.0281 3884 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 16:43:34.0281 3884 usbprint - ok 16:43:34.0343 3884 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:43:34.0343 3884 usbscan - ok 16:43:34.0390 3884 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:43:34.0390 3884 usbstor - ok 16:43:34.0437 3884 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:43:34.0437 3884 usbuhci - ok 16:43:34.0484 3884 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 16:43:34.0484 3884 VgaSave - ok 16:43:34.0515 3884 ViaIde - ok 16:43:34.0562 3884 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 16:43:34.0562 3884 VolSnap - ok 16:43:34.0609 3884 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:43:34.0609 3884 Wanarp - ok 16:43:34.0640 3884 WDICA - ok 16:43:34.0687 3884 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 16:43:34.0687 3884 wdmaud - ok 16:43:34.0843 3884 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 16:43:34.0843 3884 WSTCODEC - ok 16:43:34.0890 3884 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:43:34.0890 3884 WudfPf - ok 16:43:34.0953 3884 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2 16:43:34.0953 3884 \Device\Harddisk2\DR2 - ok 16:43:34.0968 3884 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk3\DR3 16:43:35.0328 3884 \Device\Harddisk3\DR3 - ok 16:43:35.0343 3884 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 16:43:35.0500 3884 \Device\Harddisk0\DR0 - ok 16:43:35.0515 3884 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 16:43:35.0515 3884 \Device\Harddisk1\DR1 - ok 16:43:35.0531 3884 Boot (0x1200) (65fe7c5721dbc8448712284a45bd8bdf) \Device\Harddisk2\DR2\Partition0 16:43:35.0531 3884 \Device\Harddisk2\DR2\Partition0 - ok 16:43:35.0546 3884 Boot (0x1200) (c0e18d007f4f800aee837c5c6ffedf6d) \Device\Harddisk0\DR0\Partition0 16:43:35.0546 3884 \Device\Harddisk0\DR0\Partition0 - ok 16:43:35.0562 3884 Boot (0x1200) (6d87910e09aa8e554e16e96d8d7e1822) \Device\Harddisk1\DR1\Partition0 16:43:35.0562 3884 \Device\Harddisk1\DR1\Partition0 - ok 16:43:35.0578 3884 ============================================================ 16:43:35.0578 3884 Scan finished 16:43:35.0578 3884 ============================================================ 16:43:35.0593 3000 Detected object count: 0 16:43:35.0593 3000 Actual detected object count: 0 16:48:18.0203 3868 Deinitialize success
Hi redmax1,

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi NoodleTech,

During the scan a pop up window appeared and said:

Microsoft Windows Recovery Console

This machine does not have the Microsoft Windows Recovery Console installed. Alternately, an existing installation of the recovery console may be present but requires updating. Without it, Combofix shall not attempt the fixing of some serious infections. Click Yes to have Combofix download/install it. Note: This requires an active internet connection.

I clicked on No and the scan continued. I hope this didn't hurt anything, I didn't trust if it was the scan or the virus.

Here is the scan log:

ComboFix 11-12-22.04 - Larry 12/22/2011 17:48:32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.623 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Noodle Tech\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\DragToDiscUserNameI.txt
c:\documents and settings\Larry.MAX\WINDOWS
c:\program files\WebEnhancements
c:\program files\WebEnhancements\uninst000.dat
c:\program files\WebEnhancements\we_uninstall.exe
c:\windows\$NtUninstallKB36702$\2726571482\@
c:\windows\$NtUninstallKB36702$\2726571482\bckfg.tmp
c:\windows\$NtUninstallKB36702$\2726571482\cfg.ini
c:\windows\$NtUninstallKB36702$\2726571482\Desktop.ini
c:\windows\$NtUninstallKB36702$\2726571482\keywords
c:\windows\$NtUninstallKB36702$\2726571482\kwrd.dll
c:\windows\$NtUninstallKB36702$\2726571482\L\ipoeipuw
c:\windows\$NtUninstallKB36702$\2726571482\U\00000001.@
c:\windows\$NtUninstallKB36702$\2726571482\U\00000002.@
c:\windows\$NtUninstallKB36702$\2726571482\U\00000004.@
c:\windows\$NtUninstallKB36702$\2726571482\U\80000000.@
c:\windows\$NtUninstallKB36702$\2726571482\U\80000004.@
c:\windows\$NtUninstallKB36702$\2726571482\U\80000032.@
c:\windows\$NtUninstallKB36702$\512582609
c:\windows\system32\734914
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ispcnerr.htm
c:\windows\system32\oobe\isperror\ispdtone.htm
c:\windows\system32\oobe\isperror\isphdshk.htm
c:\windows\system32\oobe\isperror\ispins.htm
c:\windows\system32\oobe\isperror\ispnoanw.htm
c:\windows\system32\oobe\isperror\isppberr.htm
c:\windows\system32\oobe\isperror\ispphbsy.htm
c:\windows\system32\oobe\isperror\ispsbusy.htm
c:\windows\system32\SET44F.tmp
c:\windows\system32\SET452.tmp
c:\windows\system32\SET456.tmp
c:\windows\system32\SET45E.tmp
c:\windows\system32\SET460.tmp
c:\windows\$NtUninstallKB36702$ . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-11-22 to 2011-12-22 )))))))))))))))))))))))))))))))
.
.
2011-12-21 06:01 . 2008-04-13 20:15 64512 -c–a-w- c:\windows\system32\dllcache\serial.sys
2011-12-21 06:01 . 2008-04-13 20:15 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2011-12-21 06:00 . 2008-04-14 00:12 33280 -c–a-w- c:\windows\system32\dllcache\rundll32.exe
2011-12-21 06:00 . 2008-04-14 00:12 33280 —-a-w- c:\windows\system32\rundll32.exe
2011-12-20 01:13 . 2011-12-20 09:00 ——– d—–w- c:\documents and settings\Larry.MAX\Local Settings\Application Data\NPE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2008-07-08 02:08 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-11 16:10 . 2011-05-14 02:12 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20 . 2008-07-08 02:08 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2008-07-08 02:06 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2008-07-08 02:06 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2008-07-08 02:06 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2008-07-08 02:07 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2008-07-08 02:05 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2008-07-08 02:06 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2008-07-08 02:06 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-11 12:27 . 2008-07-14 18:13 41 —-a-w- c:\windows\WFXDEL.BAT
2011-10-10 14:22 . 2008-07-08 00:46 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-07-08 02:05 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2010-03-18 14:09 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2008-07-08 02:07 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2008-07-08 02:07 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-09 19:37 . 2008-09-09 19:37 774144 —-a-w- c:\program files\RngInterstitial.dll
2011-08-17 15:25 . 2011-04-17 03:02 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2005-06-15 102400]
"ATnotes.exe"="c:\program files\ATnotes\ATnotes.exe" [2005-01-05 1015808]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2011-03-15 650080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-08-19 1197192]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Larry.MAX^Start Menu^Programs^Startup^Norton System Doctor.LNK]
path=c:\documents and settings\Larry.MAX\Start Menu\Programs\Startup\Norton System Doctor.LNK
backup=c:\windows\pss\Norton System Doctor.LNKStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
2005-06-15 01:49 53248 —-a-w- c:\program files\ATI Multimedia\main\atidtct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
2005-06-15 01:53 102400 —-a-w- c:\program files\ATI Multimedia\main\LaunchPd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATnotes.exe]
2005-01-05 20:45 1015808 —-a-w- c:\program files\ATnotes\ATnotes.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-12 22:14 323392 —-a-w- c:\program files\DNA\btdna.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDBitSet]
2002-12-06 22:19 200704 ——w- c:\program files\HP CD-DVD\Umbrella\DVDBitSet.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDTray]
2002-12-18 22:50 53248 ——w- c:\program files\HP CD-DVD\Umbrella\DVDTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2008-06-10 19:56 1406024 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
2003-01-09 13:21 253952 —-a-w- c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2003-01-13 14:19 757760 —-a-w- c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
2003-01-13 18:05 69632 —-a-w- c:\program files\Common Files\Roxio Shared\System\EngUtil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2002-03-19 15:01 90112 —-a-w- c:\program files\Analog Devices\SoundMAX\SMTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WPFFontCache_v0400"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"N360"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"g:\\BitTorrent\\bittorrent.exe"=
"g:\\BitTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\symds.sys [5/18/2011 1:13 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\symefa.sys [5/18/2011 1:13 PM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111221.003\BHDrvx86.sys [12/22/2011 1:36 AM 819320]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\ironx86.sys [5/18/2011 1:12 PM 136312]
R2 dmsmbios;dmsmbios;c:\windows\system32\dmsmbios.sys [5/2/2000 3:42 PM 16480]
R2 FreemakeUtilsService;Freemake Service;c:\documents and settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [9/8/2011 11:31 AM 74240]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccsvchst.exe [5/18/2011 1:12 PM 130008]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [3/15/2011 1:44 PM 428384]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [8/19/2011 3:18 AM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [8/19/2011 3:19 AM 1302152]
R3 ATICXCAP;ATI TV Wonder Pro A/V Capture;c:\windows\system32\drivers\aticxcap.sys [3/30/2005 10:22 AM 173824]
R3 ATICXTUN;ATI TV Wonder Pro Tuner (Philips 1236 MK3);c:\windows\system32\drivers\aticxtun.sys [3/30/2005 10:22 AM 29184]
R3 ATICXXBR;ATI TV Wonder Pro A/V Crossbar;c:\windows\system32\drivers\aticxxbr.sys [3/30/2005 10:22 AM 9088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/9/2011 8:29 PM 106104]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111221.001\IDSXpx86.sys [12/22/2011 1:39 AM 356280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2009-03-05 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 19:56]
.
2011-12-22 c:\windows\Tasks\User_Feed_Synchronization-{CA39505C-B0B6-4CEF-AC1E-AB513ECA8CD1}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rr.com/index.cfm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab
FF - ProfilePath - c:\documents and settings\Larry.MAX\Application Data\Mozilla\Firefox\Profiles\8kf06vey.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com/index.cfm
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
AddRemove-WebEnhancements_is1 - c:\program files\WebEnhancements\we_uninstall.exe
AddRemove-BitTorrent - d:\bittorrent\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-22 18:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-527237240-1547161642-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\L3codeca.acm
.
- - - - - - - > 'explorer.exe'(3156)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2011-12-22 18:07:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-22 23:07
.
Pre-Run: 229,234,987,008 bytes free
Post-Run: 229,306,507,264 bytes free
.
- - End Of File - - F7B76DEC0DB4B09FA8056E1F67AB6988
Hi redmax1,

Sorry for the unclear directions. Not installing the recovery console would not hurt anything right off the bat but it potentially could if let's say removing the infection caused your computer to become unbootable. You should install the recovery console when prompted.

I'm going to have you run ComboFix one more time. This time, make sure you install the recovery console when prompted. Please post the log it generates.

===================================================

Next, please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    serial.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Thank you NoodleTech. I did as you asked and here is the log……. :thumbup:

ComboFix 11-12-22.04 - Larry 12/22/2011 23:34:19.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.373 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Noodle Tech\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-23 to 2011-12-23 )))))))))))))))))))))))))))))))
.
.
2011-12-21 06:01 . 2008-04-13 20:15 64512 -c–a-w- c:\windows\system32\dllcache\serial.sys
2011-12-21 06:01 . 2008-04-13 20:15 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2011-12-21 06:00 . 2008-04-14 00:12 33280 -c–a-w- c:\windows\system32\dllcache\rundll32.exe
2011-12-21 06:00 . 2008-04-14 00:12 33280 —-a-w- c:\windows\system32\rundll32.exe
2011-12-20 01:13 . 2011-12-20 09:00 ——– d—–w- c:\documents and settings\Larry.MAX\Local Settings\Application Data\NPE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2008-07-08 02:08 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-11 16:10 . 2011-05-14 02:12 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20 . 2008-07-08 02:08 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2008-07-08 02:06 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2008-07-08 02:06 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2008-07-08 02:06 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2008-07-08 02:07 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2008-07-08 02:05 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 2008-07-08 02:06 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2008-07-08 02:06 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-11 12:27 . 2008-07-14 18:13 41 —-a-w- c:\windows\WFXDEL.BAT
2011-10-10 14:22 . 2008-07-08 00:46 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-07-08 02:05 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2010-03-18 14:09 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2008-07-08 02:07 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2008-07-08 02:07 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2008-09-09 19:37 . 2008-09-09 19:37 774144 —-a-w- c:\program files\RngInterstitial.dll
2011-08-17 15:25 . 2011-04-17 03:02 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2005-06-15 102400]
"ATnotes.exe"="c:\program files\ATnotes\ATnotes.exe" [2005-01-05 1015808]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2011-03-15 650080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-08-19 1197192]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Larry.MAX^Start Menu^Programs^Startup^Norton System Doctor.LNK]
path=c:\documents and settings\Larry.MAX\Start Menu\Programs\Startup\Norton System Doctor.LNK
backup=c:\windows\pss\Norton System Doctor.LNKStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI DeviceDetect]
2005-06-15 01:49 53248 —-a-w- c:\program files\ATI Multimedia\main\atidtct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
2005-06-15 01:53 102400 —-a-w- c:\program files\ATI Multimedia\main\LaunchPd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATnotes.exe]
2005-01-05 20:45 1015808 —-a-w- c:\program files\ATnotes\ATnotes.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-12 22:14 323392 —-a-w- c:\program files\DNA\btdna.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDBitSet]
2002-12-06 22:19 200704 ——w- c:\program files\HP CD-DVD\Umbrella\DVDBitSet.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDTray]
2002-12-18 22:50 53248 ——w- c:\program files\HP CD-DVD\Umbrella\DVDTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2008-06-10 19:56 1406024 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
2003-01-09 13:21 253952 —-a-w- c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2003-01-13 14:19 757760 —-a-w- c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
2003-01-13 18:05 69632 —-a-w- c:\program files\Common Files\Roxio Shared\System\EngUtil.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2002-03-19 15:01 90112 —-a-w- c:\program files\Analog Devices\SoundMAX\SMTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 19:49 249064 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WPFFontCache_v0400"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"N360"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"g:\\BitTorrent\\bittorrent.exe"=
"g:\\BitTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\symds.sys [5/18/2011 1:13 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\symefa.sys [5/18/2011 1:13 PM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111221.003\BHDrvx86.sys [12/22/2011 1:36 AM 819320]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\ironx86.sys [5/18/2011 1:12 PM 136312]
R2 dmsmbios;dmsmbios;c:\windows\system32\dmsmbios.sys [5/2/2000 3:42 PM 16480]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccsvchst.exe [5/18/2011 1:12 PM 130008]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [3/15/2011 1:44 PM 428384]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [8/19/2011 3:18 AM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [8/19/2011 3:19 AM 1302152]
R3 ATICXCAP;ATI TV Wonder Pro A/V Capture;c:\windows\system32\drivers\aticxcap.sys [3/30/2005 10:22 AM 173824]
R3 ATICXTUN;ATI TV Wonder Pro Tuner (Philips 1236 MK3);c:\windows\system32\drivers\aticxtun.sys [3/30/2005 10:22 AM 29184]
R3 ATICXXBR;ATI TV Wonder Pro A/V Crossbar;c:\windows\system32\drivers\aticxxbr.sys [3/30/2005 10:22 AM 9088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/9/2011 8:29 PM 106104]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111222.001\IDSXpx86.sys [12/22/2011 7:47 PM 356280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 FreemakeUtilsService;Freemake Service;c:\documents and settings\All Users.WINDOWS\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [9/8/2011 11:31 AM 74240]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2009-03-05 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 19:56]
.
2011-12-23 c:\windows\Tasks\User_Feed_Synchronization-{CA39505C-B0B6-4CEF-AC1E-AB513ECA8CD1}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rr.com/index.cfm
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab
FF - ProfilePath - c:\documents and settings\Larry.MAX\Application Data\Mozilla\Firefox\Profiles\8kf06vey.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com/index.cfm
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-22 23:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-527237240-1547161642-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\L3codeca.acm
.
- - - - - - - > 'explorer.exe'(2640)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-22 23:47:45
ComboFix-quarantined-files.txt 2011-12-23 04:47
ComboFix2.txt 2011-12-22 23:07
.
Pre-Run: 229,192,765,440 bytes free
Post-Run: 229,207,056,384 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /bootlog
.
- - End Of File - - 29D840523E5795EAD0DCDE74902A83F8
That was a quick on…sorry Ididn't see to run systemLook before, it's been a long day :blush: My computer is running great again, I know that infection ciould stll be present but things are getting better :clap: SystemLook 30.07.11 by jpshortstuff Log created at 00:27 on 23/12/2011 by Larry Administrator - Elevation successful No Context: filefind No Context: serial.sys -= EOF =-
Hi redmax1,

No worries :) I need you to run SystemLook again. You left out the colon before filefind. Copy the script exactly as you see it in the codebox below.

:filefind
serial.sys

Also, please run aswMBR again and post the log.
:blush: :smack: LOL………….Hope this is better SystemLook 30.07.11 by jpshortstuff Log created at 01:19 on 23/12/2011 by Larry Administrator - Elevation successful ========== filefind ========== Searching for "serial.sys" C:\WINDOWS\$NtServicePackUninstall$\serial.sys —–c- 64896 bytes [15:21 08/07/2008] [12:00 04/08/2004] CD9404D115A00D249F70A371B46D5A26 C:\WINDOWS\ServicePackFiles\i386\serial.sys ——- 64512 bytes [15:11 08/07/2008] [19:15 13/04/2008] CCA207A8896D4C6A0C9CE29A4AE411A7 C:\WINDOWS\system32\dllcache\serial.sys –a–c- 64512 bytes [06:01 21/12/2011] [20:15 13/04/2008] CCA207A8896D4C6A0C9CE29A4AE411A7 C:\WINDOWS\system32\drivers\serial.sys –a—- 64512 bytes [06:01 21/12/2011] [20:15 13/04/2008] 2D542F2EB1C958EE5F687D5AAF95AA23 -= EOF =-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI