This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe using 100% cpu and sirefef.da still reported by Nod32 [Solved

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Happy holidays techy people. I have read your site over and over and finally decided to ask for help. I had a sirefef.da virus. Nod32 has removed everything but 2 files from it. Also, ping.exe keeps starting and going to 100% cpu usage. I don't know if these are related or not. I have used Nod32, Malwarebytes and Search and Destroy and cannot get these last bits out. Thank you in advance for any help with this problem. King Here is my DDS report: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 16:44:34 on 2011-12-22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1130 [GMT -8:00] . AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe svchost.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Nero\Update\NASvc.exe C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\NetworkTools\AnalogX\NetStat Live\nsl.exe C:\WINDOWS\stsystra.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://hockey.fantasysports.yahoo.com/hockey/7840 uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NetStat Live] c:\program files\networktools\analogx\netstat live\nsl.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: mswsock.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1305740710296 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1324188737578 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 [removed] TCP: Interfaces\{5DACFE51-D746-461B-B74D-48D216381592} : DhcpNameServer = 192.168.1.1 [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\king\application data\mozilla\firefox\profiles\zd3jzgxo.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\king\application data\mozilla\firefox\profiles\zd3jzgxo.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll FF - plugin: c:\documents and settings\king\application data\mozilla\firefox\profiles\zd3jzgxo.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll FF - plugin: c:\progra~1\common~1\nero\browse~1\npBrowserPlugin.dll FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files\rayv\rayv\plugins\nprayvplugin.dll . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false ============= SERVICES / DRIVERS =============== . R0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\drivers\NBVol.sys [2011-10-31 56496] R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\drivers\NBVolUp.sys [2011-10-31 12464] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-9-29 108792] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-9-29 96408] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/08/12 12:16:50];c:\program files\cyberlink\powerdvd10\navfilter\000.fcl [2010-3-13 87536] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-9-29 735960] R2 NAUpdate;@c:\program files\nero\update\nasvc.exe,-200;c:\program files\nero\update\NASvc.exe [2011-9-23 641832] R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2011-3-31 80896] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-5-25 442656] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-6-24 136176] S3 CAM1690;USB PC Camera;c:\windows\system32\drivers\cam1690.sys [2007-11-21 181888] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-6-24 136176] S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-6-24 23624] S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2011-8-10 24576] S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-22 21248] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-19 50704] S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2010-7-8 20480] S3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\drivers\nwusbmdm_000.sys [2010-7-8 176384] S3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\drivers\nwusbser_000.sys [2010-7-8 176384] S3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\drivers\nwusbser2_000.sys [2010-7-8 176384] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-12-22 22:39:44 ——– d—–w- c:\windows\pss 2011-12-22 07:50:15 ——– d—–w- C:\Files 2011-12-20 09:33:55 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP 2011-12-20 09:33:53 ——– d—–w- c:\program files\common files\Wise Installation Wizard 2011-12-20 07:40:22 ——– d—–w- C:\sh4ldr 2011-12-20 07:40:22 ——– d—–w- c:\program files\Enigma Software Group 2011-12-19 21:56:49 ——– d—–w- c:\documents and settings\king\local settings\application data\ESET 2011-12-19 10:11:26 50704 —-a-w- c:\windows\system32\drivers\npf.sys 2011-12-19 10:11:26 281104 —-a-w- c:\windows\system32\wpcap.dll 2011-12-19 10:11:26 100880 —-a-w- c:\windows\system32\Packet.dll 2011-12-19 09:54:25 ——– d—–w- c:\program files\ESET 2011-12-19 01:32:25 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-12-19 01:32:25 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy 2011-12-18 07:07:27 ——– d—–w- c:\documents and settings\king\application data\Malwarebytes 2011-12-18 07:07:08 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-18 07:07:05 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-18 07:07:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-18 05:29:46 ——– d—–w- C:\thumb drive 2011-11-24 04:59:09 ——– d—–w- C:\Documents%20and%20Settings . ==================== Find3M ==================== . 2011-12-22 22:43:07 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys . ============= FINISH: 16:45:06.73 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

If you have chosen to attempt cleaning, please post the logs created by TDSSKiller and ComboFix into your next reply. :)
Thanks for responding so quickly. I am running TDSSKiller and it is finding one threat, redbook.sys as suspicious object, medium risk and the default action is skip. I do know that Nod32 was detecting that file as one of the 2 it couldnt fix with the sirefef.da virus, so I wasn't sure what action I should take. Thanks again, Jeff, for your help.
Hi, Just go ahead and leave the TDSSKiller entry can be left just the way you did it. Be sure to run ComboFix and then post the log created into your next reply. :)
All done. Here are the logs: 10:35:12.0484 1480 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 10:35:13.0187 1480 ============================================================ 10:35:13.0187 1480 Current date / time: 2011/12/23 10:35:13.0187 10:35:13.0187 1480 SystemInfo: 10:35:13.0187 1480 10:35:13.0187 1480 OS Version: 5.1.2600 ServicePack: 3.0 10:35:13.0187 1480 Product type: Workstation 10:35:13.0187 1480 ComputerName: SMOKEY 10:35:13.0187 1480 UserName: King 10:35:13.0187 1480 Windows directory: C:\WINDOWS 10:35:13.0187 1480 System windows directory: C:\WINDOWS 10:35:13.0187 1480 Processor architecture: Intel x86 10:35:13.0187 1480 Number of processors: 2 10:35:13.0187 1480 Page size: 0x1000 10:35:13.0187 1480 Boot type: Normal boot 10:35:13.0187 1480 ============================================================ 10:35:15.0421 1480 Initialize success 10:35:17.0062 2476 ============================================================ 10:35:17.0062 2476 Scan started 10:35:17.0062 2476 Mode: Manual; 10:35:17.0062 2476 ============================================================ 10:35:19.0000 2476 Abiosdsk - ok 10:35:19.0015 2476 abp480n5 - ok 10:35:19.0078 2476 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:35:19.0125 2476 ACPI - ok 10:35:19.0156 2476 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 10:35:19.0187 2476 ACPIEC - ok 10:35:19.0187 2476 adpu160m - ok 10:35:19.0234 2476 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 10:35:19.0265 2476 aec - ok 10:35:19.0312 2476 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys 10:35:19.0328 2476 AFD - ok 10:35:19.0343 2476 Aha154x - ok 10:35:19.0359 2476 aic78u2 - ok 10:35:19.0359 2476 aic78xx - ok 10:35:19.0390 2476 AliIde - ok 10:35:19.0421 2476 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys 10:35:19.0437 2476 AmdPPM - ok 10:35:19.0453 2476 amsint - ok 10:35:19.0468 2476 asc - ok 10:35:19.0484 2476 asc3350p - ok 10:35:19.0500 2476 asc3550 - ok 10:35:19.0562 2476 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:35:19.0578 2476 AsyncMac - ok 10:35:19.0609 2476 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 10:35:19.0625 2476 atapi - ok 10:35:19.0625 2476 Atdisk - ok 10:35:19.0750 2476 ati2mtag (e78b73eb84c257d0d940e041742d2699) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 10:35:19.0781 2476 ati2mtag - ok 10:35:19.0828 2476 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:35:19.0859 2476 Atmarpc - ok 10:35:19.0906 2476 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 10:35:19.0937 2476 audstub - ok 10:35:19.0984 2476 BCM43XX (b89bcf0a25aeb3b47030ac83287f894a) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 10:35:20.0015 2476 BCM43XX - ok 10:35:20.0281 2476 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 10:35:20.0437 2476 bcm4sbxp - ok 10:35:20.0937 2476 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 10:35:21.0000 2476 Beep - ok 10:35:21.0250 2476 CAM1690 (5502f9b8d627ba0419ae5579424bbb7d) C:\WINDOWS\system32\Drivers\cam1690.sys 10:35:21.0343 2476 CAM1690 - ok 10:35:21.0375 2476 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 10:35:21.0406 2476 cbidf2k - ok 10:35:21.0437 2476 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 10:35:21.0468 2476 CCDECODE - ok 10:35:21.0468 2476 cd20xrnt - ok 10:35:21.0531 2476 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 10:35:21.0562 2476 Cdaudio - ok 10:35:21.0625 2476 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 10:35:21.0796 2476 Cdfs - ok 10:35:21.0968 2476 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:35:22.0031 2476 Cdrom - ok 10:35:22.0062 2476 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 10:35:22.0093 2476 cercsr6 - ok 10:35:22.0093 2476 Changer - ok 10:35:22.0187 2476 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 10:35:22.0203 2476 CmBatt - ok 10:35:22.0218 2476 CmdIde - ok 10:35:22.0234 2476 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 10:35:22.0250 2476 Compbatt - ok 10:35:22.0281 2476 Cpqarray - ok 10:35:22.0296 2476 dac2w2k - ok 10:35:22.0312 2476 dac960nt - ok 10:35:22.0328 2476 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 10:35:22.0359 2476 Disk - ok 10:35:22.0625 2476 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 10:35:22.0671 2476 dmboot - ok 10:35:22.0703 2476 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 10:35:22.0734 2476 dmio - ok 10:35:22.0765 2476 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 10:35:22.0781 2476 dmload - ok 10:35:22.0828 2476 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 10:35:22.0828 2476 DMusic - ok 10:35:22.0843 2476 dpti2o - ok 10:35:22.0875 2476 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 10:35:22.0906 2476 drmkaud - ok 10:35:22.0937 2476 eamon (1b5ca1caffc594bd37dcc8d7ef849e0b) C:\WINDOWS\system32\DRIVERS\eamon.sys 10:35:22.0953 2476 eamon - ok 10:35:23.0000 2476 ehdrv (a4241545ecff3ee97041847d83936e1f) C:\WINDOWS\system32\DRIVERS\ehdrv.sys 10:35:23.0015 2476 ehdrv - ok 10:35:23.0078 2476 epfwtdir (367a97a632ec5e8521f68ffa2c700610) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 10:35:23.0093 2476 epfwtdir - ok 10:35:23.0109 2476 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 10:35:23.0140 2476 Fastfat - ok 10:35:23.0203 2476 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 10:35:23.0218 2476 Fdc - ok 10:35:23.0250 2476 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 10:35:23.0265 2476 Fips - ok 10:35:23.0281 2476 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 10:35:23.0296 2476 Flpydisk - ok 10:35:23.0312 2476 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 10:35:23.0343 2476 FltMgr - ok 10:35:23.0359 2476 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:35:23.0375 2476 Fs_Rec - ok 10:35:23.0390 2476 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:35:23.0421 2476 Ftdisk - ok 10:35:23.0484 2476 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:35:23.0500 2476 Gpc - ok 10:35:23.0562 2476 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 10:35:23.0562 2476 HDAudBus - ok 10:35:23.0593 2476 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:35:23.0625 2476 HidUsb - ok 10:35:23.0671 2476 hitmanpro35 (72472b9ce5d02e443cff49a40355455d) C:\WINDOWS\system32\drivers\hitmanpro35.sys 10:35:23.0687 2476 hitmanpro35 - ok 10:35:23.0703 2476 hpn - ok 10:35:23.0812 2476 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 10:35:23.0828 2476 HSF_DPV - ok 10:35:23.0890 2476 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 10:35:23.0906 2476 HSXHWAZL - ok 10:35:23.0968 2476 HTCAND32 (cbd09ed9cf6822177ee85aea4d8816a2) C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys 10:35:23.0968 2476 HTCAND32 - ok 10:35:24.0046 2476 htcnprot (04e3b3554076b8192a668efe88a682a1) C:\WINDOWS\system32\DRIVERS\htcnprot.sys 10:35:24.0046 2476 htcnprot - ok 10:35:24.0109 2476 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 10:35:24.0171 2476 HTTP - ok 10:35:24.0171 2476 i2omgmt - ok 10:35:24.0187 2476 i2omp - ok 10:35:24.0203 2476 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:35:24.0250 2476 i8042prt - ok 10:35:24.0281 2476 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 10:35:24.0312 2476 Imapi - ok 10:35:24.0328 2476 ini910u - ok 10:35:24.0343 2476 IntelIde - ok 10:35:24.0375 2476 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 10:35:24.0421 2476 Ip6Fw - ok 10:35:24.0453 2476 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:35:24.0500 2476 IpFilterDriver - ok 10:35:24.0562 2476 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:35:24.0609 2476 IpInIp - ok 10:35:24.0656 2476 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:35:24.0671 2476 IpNat - ok 10:35:24.0687 2476 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:35:24.0718 2476 IPSec - ok 10:35:24.0765 2476 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 10:35:24.0781 2476 IRENUM - ok 10:35:24.0828 2476 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:35:24.0843 2476 isapnp - ok 10:35:24.0859 2476 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:35:24.0875 2476 Kbdclass - ok 10:35:24.0937 2476 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 10:35:24.0953 2476 kbdhid - ok 10:35:24.0984 2476 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 10:35:25.0015 2476 kmixer - ok 10:35:25.0046 2476 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 10:35:25.0046 2476 KSecDD - ok 10:35:25.0062 2476 lbrtfdc - ok 10:35:25.0140 2476 LVRS (c4fd8055f421a8e6f49259a0bf59c40d) C:\WINDOWS\system32\DRIVERS\lvrs.sys 10:35:25.0156 2476 LVRS - ok 10:35:25.0375 2476 LVUVC (bab6dba71defbc9d147afc15cdc9563f) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 10:35:25.0484 2476 LVUVC - ok 10:35:25.0500 2476 MBAMSwissArmy - ok 10:35:25.0546 2476 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 10:35:25.0562 2476 mdmxsdk - ok 10:35:25.0625 2476 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 10:35:25.0640 2476 mnmdd - ok 10:35:25.0703 2476 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 10:35:25.0718 2476 Modem - ok 10:35:25.0781 2476 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:35:25.0812 2476 Mouclass - ok 10:35:25.0875 2476 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:35:25.0890 2476 mouhid - ok 10:35:25.0906 2476 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 10:35:25.0921 2476 MountMgr - ok 10:35:25.0921 2476 mraid35x - ok 10:35:25.0968 2476 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:35:26.0000 2476 MRxDAV - ok 10:35:26.0062 2476 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:35:26.0093 2476 MRxSmb - ok 10:35:26.0109 2476 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 10:35:26.0125 2476 Msfs - ok 10:35:26.0171 2476 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:35:26.0187 2476 MSKSSRV - ok 10:35:26.0234 2476 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:35:26.0250 2476 MSPCLOCK - ok 10:35:26.0281 2476 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 10:35:26.0296 2476 MSPQM - ok 10:35:26.0328 2476 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:35:26.0328 2476 mssmbios - ok 10:35:26.0390 2476 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 10:35:26.0406 2476 MSTEE - ok 10:35:26.0437 2476 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 10:35:26.0437 2476 Mup - ok 10:35:26.0484 2476 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 10:35:26.0515 2476 NABTSFEC - ok 10:35:26.0562 2476 NBVol (e240f3204e86b7b6ccf266b2a2ad32b4) C:\WINDOWS\system32\DRIVERS\NBVol.sys 10:35:26.0562 2476 NBVol - ok 10:35:26.0578 2476 NBVolUp (c0cf3cccce3c75f7280c89029ab47866) C:\WINDOWS\system32\DRIVERS\NBVolUp.sys 10:35:26.0578 2476 NBVolUp - ok 10:35:26.0640 2476 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 10:35:26.0640 2476 NDIS - ok 10:35:26.0687 2476 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 10:35:26.0718 2476 NdisIP - ok 10:35:26.0734 2476 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:35:26.0750 2476 NdisTapi - ok 10:35:26.0781 2476 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:35:26.0812 2476 Ndisuio - ok 10:35:26.0843 2476 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:35:26.0875 2476 NdisWan - ok 10:35:26.0921 2476 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 10:35:26.0937 2476 NDProxy - ok 10:35:26.0984 2476 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 10:35:26.0984 2476 NetBIOS - ok 10:35:27.0015 2476 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 10:35:27.0046 2476 NetBT - ok 10:35:27.0125 2476 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 10:35:27.0125 2476 NPF - ok 10:35:27.0156 2476 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 10:35:27.0156 2476 Npfs - ok 10:35:27.0218 2476 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 10:35:27.0250 2476 Ntfs - ok 10:35:27.0281 2476 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 10:35:27.0296 2476 Null - ok 10:35:27.0359 2476 NWADI (c83766c4a147159254ff16f1a6c9dc6e) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys 10:35:27.0390 2476 NWADI - ok 10:35:27.0437 2476 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 10:35:27.0453 2476 NwlnkFlt - ok 10:35:27.0500 2476 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 10:35:27.0515 2476 NwlnkFwd - ok 10:35:27.0546 2476 NWUSBCDFIL (224131778c92aee8c13afac5fbff19ca) C:\WINDOWS\system32\DRIVERS\NwUsbCdFil.sys 10:35:27.0578 2476 NWUSBCDFIL - ok 10:35:27.0625 2476 NWUSBModem_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbmdm_000.sys 10:35:27.0640 2476 NWUSBModem_000 - ok 10:35:27.0687 2476 NWUSBPort2_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbser2_000.sys 10:35:27.0687 2476 NWUSBPort2_000 - ok 10:35:27.0734 2476 NWUSBPort_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbser_000.sys 10:35:27.0750 2476 NWUSBPort_000 - ok 10:35:27.0796 2476 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 10:35:27.0828 2476 Parport - ok 10:35:27.0890 2476 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 10:35:27.0890 2476 PartMgr - ok 10:35:27.0921 2476 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 10:35:27.0953 2476 ParVdm - ok 10:35:27.0968 2476 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 10:35:27.0984 2476 PCI - ok 10:35:28.0000 2476 PCIDump - ok 10:35:28.0031 2476 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 10:35:28.0046 2476 PCIIde - ok 10:35:28.0093 2476 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 10:35:28.0140 2476 Pcmcia - ok 10:35:28.0156 2476 PDCOMP - ok 10:35:28.0171 2476 PDFRAME - ok 10:35:28.0187 2476 PDRELI - ok 10:35:28.0203 2476 PDRFRAME - ok 10:35:28.0203 2476 perc2 - ok 10:35:28.0218 2476 perc2hib - ok 10:35:28.0281 2476 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:35:28.0312 2476 PptpMiniport - ok 10:35:28.0328 2476 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 10:35:28.0359 2476 Processor - ok 10:35:28.0375 2476 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 10:35:28.0421 2476 PSched - ok 10:35:28.0453 2476 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:35:28.0484 2476 Ptilink - ok 10:35:28.0500 2476 PxHelp20 (0c8da0a8b0d227319c285e0eae65defd) C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:35:28.0546 2476 PxHelp20 - ok 10:35:28.0562 2476 ql1080 - ok 10:35:28.0578 2476 Ql10wnt - ok 10:35:28.0578 2476 ql12160 - ok 10:35:28.0625 2476 ql1240 - ok 10:35:28.0640 2476 ql1280 - ok 10:35:28.0687 2476 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:35:28.0718 2476 RasAcd - ok 10:35:28.0734 2476 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:35:28.0765 2476 Rasl2tp - ok 10:35:28.0781 2476 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:35:28.0796 2476 RasPppoe - ok 10:35:28.0812 2476 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 10:35:28.0843 2476 Raspti - ok 10:35:28.0906 2476 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:35:28.0906 2476 Rdbss - ok 10:35:28.0921 2476 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:35:28.0953 2476 RDPCDD - ok 10:35:29.0015 2476 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 10:35:29.0031 2476 rdpdr - ok 10:35:29.0078 2476 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 10:35:29.0125 2476 RDPWD - ok 10:35:29.0171 2476 redbook (55f7fa7c581d3508de96e4adf418d370) C:\WINDOWS\system32\DRIVERS\redbook.sys 10:35:29.0171 2476 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\redbook.sys. md5: 55f7fa7c581d3508de96e4adf418d370 10:35:29.0171 2476 redbook ( LockedFile.Multi.Generic ) - warning 10:35:29.0171 2476 redbook - detected LockedFile.Multi.Generic (1) 10:35:29.0500 2476 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\WINDOWS\system32\Drivers\RimUsb.sys 10:35:29.0546 2476 RimUsb - ok 10:35:29.0578 2476 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 10:35:29.0578 2476 RimVSerPort - ok 10:35:29.0609 2476 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 10:35:29.0640 2476 ROOTMODEM - ok 10:35:29.0718 2476 SCDEmu (20b2751cd4c8f3fd989739ca661b9f30) C:\WINDOWS\system32\drivers\SCDEmu.sys 10:35:29.0765 2476 SCDEmu - ok 10:35:29.0796 2476 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 10:35:29.0875 2476 sdbus - ok 10:35:29.0921 2476 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:35:29.0937 2476 Secdrv - ok 10:35:30.0000 2476 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 10:35:30.0046 2476 Serial - ok 10:35:30.0125 2476 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 10:35:30.0140 2476 Sfloppy - ok 10:35:30.0156 2476 Simbad - ok 10:35:30.0218 2476 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 10:35:30.0234 2476 SLIP - ok 10:35:30.0250 2476 Sparrow - ok 10:35:30.0312 2476 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 10:35:30.0328 2476 splitter - ok 10:35:30.0390 2476 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 10:35:30.0390 2476 sr - ok 10:35:30.0453 2476 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 10:35:30.0484 2476 Srv - ok 10:35:30.0593 2476 STHDA (8990440e4b2a7ca5a56a1833b03741fd) C:\WINDOWS\system32\drivers\sthda.sys 10:35:30.0671 2476 STHDA - ok 10:35:30.0703 2476 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 10:35:30.0734 2476 streamip - ok 10:35:30.0781 2476 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 10:35:30.0796 2476 swenum - ok 10:35:30.0843 2476 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 10:35:30.0890 2476 swmidi - ok 10:35:30.0906 2476 symc810 - ok 10:35:30.0921 2476 symc8xx - ok 10:35:30.0921 2476 sym_hi - ok 10:35:30.0937 2476 sym_u3 - ok 10:35:31.0000 2476 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys 10:35:31.0031 2476 SynTP - ok 10:35:31.0078 2476 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 10:35:31.0093 2476 sysaudio - ok 10:35:31.0203 2476 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:35:31.0234 2476 Tcpip - ok 10:35:31.0265 2476 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 10:35:31.0281 2476 TDPIPE - ok 10:35:31.0328 2476 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 10:35:31.0343 2476 TDTCP - ok 10:35:31.0375 2476 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 10:35:31.0437 2476 TermDD - ok 10:35:31.0468 2476 TosIde - ok 10:35:31.0515 2476 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 10:35:31.0546 2476 Udfs - ok 10:35:31.0562 2476 UIUSys - ok 10:35:31.0578 2476 ultra - ok 10:35:31.0640 2476 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 10:35:31.0703 2476 Update - ok 10:35:31.0765 2476 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 10:35:31.0781 2476 usbaudio - ok 10:35:31.0859 2476 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 10:35:31.0875 2476 usbccgp - ok 10:35:31.0906 2476 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:35:31.0937 2476 usbehci - ok 10:35:31.0968 2476 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:35:32.0000 2476 usbhub - ok 10:35:32.0046 2476 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 10:35:32.0062 2476 usbohci - ok 10:35:32.0109 2476 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 10:35:32.0125 2476 usbprint - ok 10:35:32.0171 2476 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:35:32.0203 2476 USBSTOR - ok 10:35:32.0250 2476 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 10:35:32.0265 2476 usbvideo - ok 10:35:32.0281 2476 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys 10:35:32.0312 2476 usb_rndisx - ok 10:35:32.0359 2476 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 10:35:32.0375 2476 VgaSave - ok 10:35:32.0390 2476 ViaIde - ok 10:35:32.0406 2476 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 10:35:32.0437 2476 VolSnap - ok 10:35:32.0500 2476 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:35:32.0531 2476 Wanarp - ok 10:35:32.0593 2476 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 10:35:32.0609 2476 Wdf01000 - ok 10:35:32.0609 2476 WDICA - ok 10:35:32.0734 2476 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 10:35:32.0750 2476 wdmaud - ok 10:35:32.0843 2476 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 10:35:32.0875 2476 winachsf - ok 10:35:32.0937 2476 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 10:35:32.0953 2476 WmiAcpi - ok 10:35:33.0015 2476 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 10:35:33.0031 2476 WSTCODEC - ok 10:35:33.0078 2476 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 10:35:33.0109 2476 WudfPf - ok 10:35:33.0140 2476 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 10:35:33.0140 2476 WudfRd - ok 10:35:33.0203 2476 xusb21 (a640c90b007762939507c28a021be3b3) C:\WINDOWS\system32\DRIVERS\xusb21.sys 10:35:33.0203 2476 xusb21 - ok 10:35:33.0343 2476 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl 10:35:33.0343 2476 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} - ok 10:35:33.0390 2476 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 10:35:33.0671 2476 \Device\Harddisk0\DR0 - ok 10:35:33.0687 2476 Boot (0x1200) (4bb2c283b065595bc43bac840e3a0cb9) \Device\Harddisk0\DR0\Partition0 10:35:33.0687 2476 \Device\Harddisk0\DR0\Partition0 - ok 10:35:33.0687 2476 ============================================================ 10:35:33.0687 2476 Scan finished 10:35:33.0687 2476 ============================================================ 10:35:33.0703 1788 Detected object count: 1 10:35:33.0703 1788 Actual detected object count: 1 10:35:45.0968 1788 redbook ( LockedFile.Multi.Generic ) - skipped by user 10:35:45.0968 1788 redbook ( LockedFile.Multi.Generic ) - User select action: Skip 10:35:48.0578 3520 Deinitialize success

Attachments:

14:46:33.0984 3584 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 14:46:34.0343 3584 ============================================================ 14:46:34.0343 3584 Current date / time: 2011/12/23 14:46:34.0343 14:46:34.0343 3584 SystemInfo: 14:46:34.0343 3584 14:46:34.0343 3584 OS Version: 5.1.2600 ServicePack: 3.0 14:46:34.0343 3584 Product type: Workstation 14:46:34.0343 3584 ComputerName: SMOKEY 14:46:34.0343 3584 UserName: King 14:46:34.0343 3584 Windows directory: C:\WINDOWS 14:46:34.0343 3584 System windows directory: C:\WINDOWS 14:46:34.0343 3584 Processor architecture: Intel x86 14:46:34.0343 3584 Number of processors: 2 14:46:34.0343 3584 Page size: 0x1000 14:46:34.0343 3584 Boot type: Normal boot 14:46:34.0343 3584 ============================================================ 14:46:36.0656 3584 Initialize success 14:46:38.0546 3236 ============================================================ 14:46:38.0546 3236 Scan started 14:46:38.0546 3236 Mode: Manual; 14:46:38.0546 3236 ============================================================ 14:46:41.0109 3236 Abiosdsk - ok 14:46:41.0140 3236 abp480n5 - ok 14:46:41.0218 3236 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 14:46:41.0218 3236 ACPI - ok 14:46:41.0250 3236 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 14:46:41.0250 3236 ACPIEC - ok 14:46:41.0265 3236 adpu160m - ok 14:46:41.0312 3236 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 14:46:41.0312 3236 aec - ok 14:46:41.0375 3236 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys 14:46:41.0375 3236 AFD - ok 14:46:41.0546 3236 Aha154x - ok 14:46:41.0703 3236 aic78u2 - ok 14:46:41.0718 3236 aic78xx - ok 14:46:41.0734 3236 AliIde - ok 14:46:41.0750 3236 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys 14:46:41.0765 3236 AmdPPM - ok 14:46:41.0781 3236 amsint - ok 14:46:41.0796 3236 asc - ok 14:46:41.0812 3236 asc3350p - ok 14:46:41.0828 3236 asc3550 - ok 14:46:41.0890 3236 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 14:46:41.0921 3236 AsyncMac - ok 14:46:41.0953 3236 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 14:46:41.0953 3236 atapi - ok 14:46:41.0968 3236 Atdisk - ok 14:46:42.0078 3236 ati2mtag (e78b73eb84c257d0d940e041742d2699) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 14:46:42.0093 3236 ati2mtag - ok 14:46:42.0140 3236 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 14:46:42.0156 3236 Atmarpc - ok 14:46:42.0203 3236 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 14:46:42.0218 3236 audstub - ok 14:46:42.0281 3236 BCM43XX (b89bcf0a25aeb3b47030ac83287f894a) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 14:46:42.0281 3236 BCM43XX - ok 14:46:42.0328 3236 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 14:46:42.0343 3236 bcm4sbxp - ok 14:46:42.0375 3236 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 14:46:42.0406 3236 Beep - ok 14:46:42.0500 3236 CAM1690 (5502f9b8d627ba0419ae5579424bbb7d) C:\WINDOWS\system32\Drivers\cam1690.sys 14:46:42.0500 3236 CAM1690 - ok 14:46:42.0500 3236 catchme - ok 14:46:42.0546 3236 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 14:46:42.0578 3236 cbidf2k - ok 14:46:42.0609 3236 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 14:46:42.0640 3236 CCDECODE - ok 14:46:42.0640 3236 cd20xrnt - ok 14:46:42.0703 3236 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 14:46:42.0718 3236 Cdaudio - ok 14:46:42.0796 3236 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 14:46:42.0812 3236 Cdfs - ok 14:46:42.0828 3236 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 14:46:42.0859 3236 Cdrom - ok 14:46:42.0921 3236 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 14:46:42.0937 3236 cercsr6 - ok 14:46:42.0953 3236 Changer - ok 14:46:43.0031 3236 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 14:46:43.0062 3236 CmBatt - ok 14:46:43.0062 3236 CmdIde - ok 14:46:43.0078 3236 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 14:46:43.0109 3236 Compbatt - ok 14:46:43.0125 3236 Cpqarray - ok 14:46:43.0140 3236 dac2w2k - ok 14:46:43.0156 3236 dac960nt - ok 14:46:43.0171 3236 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 14:46:43.0203 3236 Disk - ok 14:46:43.0265 3236 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 14:46:43.0312 3236 dmboot - ok 14:46:43.0343 3236 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 14:46:43.0375 3236 dmio - ok 14:46:43.0375 3236 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 14:46:43.0406 3236 dmload - ok 14:46:43.0437 3236 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 14:46:43.0437 3236 DMusic - ok 14:46:43.0453 3236 dpti2o - ok 14:46:43.0484 3236 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 14:46:43.0500 3236 drmkaud - ok 14:46:43.0546 3236 eamon (1b5ca1caffc594bd37dcc8d7ef849e0b) C:\WINDOWS\system32\DRIVERS\eamon.sys 14:46:43.0546 3236 eamon - ok 14:46:43.0593 3236 ehdrv (a4241545ecff3ee97041847d83936e1f) C:\WINDOWS\system32\DRIVERS\ehdrv.sys 14:46:43.0625 3236 ehdrv - ok 14:46:43.0687 3236 epfwtdir (367a97a632ec5e8521f68ffa2c700610) C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 14:46:43.0687 3236 epfwtdir - ok 14:46:43.0718 3236 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 14:46:43.0734 3236 Fastfat - ok 14:46:43.0796 3236 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 14:46:43.0828 3236 Fdc - ok 14:46:43.0843 3236 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 14:46:43.0859 3236 Fips - ok 14:46:43.0875 3236 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 14:46:43.0890 3236 Flpydisk - ok 14:46:43.0906 3236 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 14:46:43.0937 3236 FltMgr - ok 14:46:43.0953 3236 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 14:46:43.0968 3236 Fs_Rec - ok 14:46:43.0984 3236 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 14:46:44.0015 3236 Ftdisk - ok 14:46:44.0078 3236 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 14:46:44.0093 3236 Gpc - ok 14:46:44.0156 3236 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 14:46:44.0156 3236 HDAudBus - ok 14:46:44.0187 3236 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 14:46:44.0218 3236 HidUsb - ok 14:46:44.0265 3236 hitmanpro35 (72472b9ce5d02e443cff49a40355455d) C:\WINDOWS\system32\drivers\hitmanpro35.sys 14:46:44.0281 3236 hitmanpro35 - ok 14:46:44.0296 3236 hpn - ok 14:46:44.0406 3236 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 14:46:44.0406 3236 HSF_DPV - ok 14:46:44.0437 3236 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys 14:46:44.0468 3236 HSXHWAZL - ok 14:46:44.0531 3236 HTCAND32 (cbd09ed9cf6822177ee85aea4d8816a2) C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys 14:46:44.0531 3236 HTCAND32 - ok 14:46:44.0609 3236 htcnprot (04e3b3554076b8192a668efe88a682a1) C:\WINDOWS\system32\DRIVERS\htcnprot.sys 14:46:44.0609 3236 htcnprot - ok 14:46:44.0671 3236 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 14:46:44.0687 3236 HTTP - ok 14:46:44.0703 3236 i2omgmt - ok 14:46:44.0703 3236 i2omp - ok 14:46:44.0718 3236 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 14:46:44.0765 3236 i8042prt - ok 14:46:44.0828 3236 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 14:46:44.0843 3236 Imapi - ok 14:46:44.0921 3236 ini910u - ok 14:46:44.0953 3236 IntelIde - ok 14:46:44.0984 3236 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 14:46:44.0984 3236 Ip6Fw - ok 14:46:45.0062 3236 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 14:46:45.0109 3236 IpFilterDriver - ok 14:46:45.0203 3236 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 14:46:45.0218 3236 IpInIp - ok 14:46:45.0328 3236 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 14:46:45.0343 3236 IpNat - ok 14:46:45.0468 3236 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 14:46:45.0500 3236 IPSec - ok 14:46:45.0625 3236 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 14:46:45.0640 3236 IRENUM - ok 14:46:45.0687 3236 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 14:46:45.0718 3236 isapnp - ok 14:46:45.0734 3236 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 14:46:45.0734 3236 Kbdclass - ok 14:46:45.0796 3236 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 14:46:45.0812 3236 kbdhid - ok 14:46:45.0843 3236 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 14:46:45.0859 3236 kmixer - ok 14:46:45.0890 3236 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 14:46:45.0890 3236 KSecDD - ok 14:46:45.0906 3236 lbrtfdc - ok 14:46:45.0984 3236 LVRS (c4fd8055f421a8e6f49259a0bf59c40d) C:\WINDOWS\system32\DRIVERS\lvrs.sys 14:46:45.0984 3236 LVRS - ok 14:46:46.0171 3236 LVUVC (bab6dba71defbc9d147afc15cdc9563f) C:\WINDOWS\system32\DRIVERS\lvuvc.sys 14:46:46.0234 3236 LVUVC - ok 14:46:46.0250 3236 MBAMSwissArmy - ok 14:46:46.0312 3236 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 14:46:46.0312 3236 mdmxsdk - ok 14:46:46.0375 3236 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 14:46:46.0390 3236 mnmdd - ok 14:46:46.0453 3236 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 14:46:46.0468 3236 Modem - ok 14:46:46.0531 3236 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 14:46:46.0562 3236 Mouclass - ok 14:46:46.0625 3236 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 14:46:46.0640 3236 mouhid - ok 14:46:46.0656 3236 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 14:46:46.0687 3236 MountMgr - ok 14:46:46.0703 3236 mraid35x - ok 14:46:46.0734 3236 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 14:46:46.0781 3236 MRxDAV - ok 14:46:46.0828 3236 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 14:46:46.0843 3236 MRxSmb - ok 14:46:46.0859 3236 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 14:46:46.0890 3236 Msfs - ok 14:46:46.0921 3236 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:46:46.0953 3236 MSKSSRV - ok 14:46:46.0984 3236 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:46:47.0015 3236 MSPCLOCK - ok 14:46:47.0031 3236 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 14:46:47.0062 3236 MSPQM - ok 14:46:47.0093 3236 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:46:47.0093 3236 mssmbios - ok 14:46:47.0140 3236 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 14:46:47.0171 3236 MSTEE - ok 14:46:47.0203 3236 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 14:46:47.0203 3236 Mup - ok 14:46:47.0250 3236 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 14:46:47.0265 3236 NABTSFEC - ok 14:46:47.0328 3236 NBVol (e240f3204e86b7b6ccf266b2a2ad32b4) C:\WINDOWS\system32\DRIVERS\NBVol.sys 14:46:47.0328 3236 NBVol - ok 14:46:47.0343 3236 NBVolUp (c0cf3cccce3c75f7280c89029ab47866) C:\WINDOWS\system32\DRIVERS\NBVolUp.sys 14:46:47.0343 3236 NBVolUp - ok 14:46:47.0390 3236 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 14:46:47.0406 3236 NDIS - ok 14:46:47.0453 3236 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 14:46:47.0468 3236 NdisIP - ok 14:46:47.0484 3236 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:46:47.0484 3236 NdisTapi - ok 14:46:47.0531 3236 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:46:47.0546 3236 Ndisuio - ok 14:46:47.0578 3236 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:46:47.0609 3236 NdisWan - ok 14:46:47.0656 3236 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 14:46:47.0656 3236 NDProxy - ok 14:46:47.0703 3236 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 14:46:47.0718 3236 NetBIOS - ok 14:46:47.0765 3236 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 14:46:47.0781 3236 NetBT - ok 14:46:47.0843 3236 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 14:46:47.0859 3236 Npfs - ok 14:46:47.0921 3236 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 14:46:47.0953 3236 Ntfs - ok 14:46:47.0984 3236 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 14:46:48.0000 3236 Null - ok 14:46:48.0062 3236 NWADI (c83766c4a147159254ff16f1a6c9dc6e) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys 14:46:48.0062 3236 NWADI - ok 14:46:48.0109 3236 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:46:48.0125 3236 NwlnkFlt - ok 14:46:48.0156 3236 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:46:48.0187 3236 NwlnkFwd - ok 14:46:48.0203 3236 NWUSBCDFIL (224131778c92aee8c13afac5fbff19ca) C:\WINDOWS\system32\DRIVERS\NwUsbCdFil.sys 14:46:48.0234 3236 NWUSBCDFIL - ok 14:46:48.0281 3236 NWUSBModem_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbmdm_000.sys 14:46:48.0296 3236 NWUSBModem_000 - ok 14:46:48.0343 3236 NWUSBPort2_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbser2_000.sys 14:46:48.0343 3236 NWUSBPort2_000 - ok 14:46:48.0390 3236 NWUSBPort_000 (c7fb1635508d0009489a0f7e7743468a) C:\WINDOWS\system32\DRIVERS\nwusbser_000.sys 14:46:48.0390 3236 NWUSBPort_000 - ok 14:46:48.0453 3236 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 14:46:48.0468 3236 Parport - ok 14:46:48.0500 3236 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 14:46:48.0531 3236 PartMgr - ok 14:46:48.0562 3236 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 14:46:48.0578 3236 ParVdm - ok 14:46:48.0593 3236 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 14:46:48.0625 3236 PCI - ok 14:46:48.0640 3236 PCIDump - ok 14:46:48.0671 3236 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 14:46:48.0687 3236 PCIIde - ok 14:46:48.0734 3236 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 14:46:48.0781 3236 Pcmcia - ok 14:46:48.0796 3236 PDCOMP - ok 14:46:48.0812 3236 PDFRAME - ok 14:46:48.0828 3236 PDRELI - ok 14:46:48.0843 3236 PDRFRAME - ok 14:46:48.0843 3236 perc2 - ok 14:46:48.0859 3236 perc2hib - ok 14:46:48.0937 3236 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:46:48.0953 3236 PptpMiniport - ok 14:46:48.0984 3236 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 14:46:49.0000 3236 Processor - ok 14:46:49.0015 3236 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 14:46:49.0062 3236 PSched - ok 14:46:49.0093 3236 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:46:49.0125 3236 Ptilink - ok 14:46:49.0140 3236 PxHelp20 (0c8da0a8b0d227319c285e0eae65defd) C:\WINDOWS\system32\Drivers\PxHelp20.sys 14:46:49.0187 3236 PxHelp20 - ok 14:46:49.0187 3236 ql1080 - ok 14:46:49.0203 3236 Ql10wnt - ok 14:46:49.0218 3236 ql12160 - ok 14:46:49.0234 3236 ql1240 - ok 14:46:49.0250 3236 ql1280 - ok 14:46:49.0281 3236 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:46:49.0312 3236 RasAcd - ok 14:46:49.0328 3236 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:46:49.0359 3236 Rasl2tp - ok 14:46:49.0375 3236 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:46:49.0390 3236 RasPppoe - ok 14:46:49.0406 3236 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 14:46:49.0437 3236 Raspti - ok 14:46:49.0484 3236 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:46:49.0562 3236 Rdbss - ok 14:46:49.0578 3236 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:46:49.0609 3236 RDPCDD - ok 14:46:49.0671 3236 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 14:46:49.0703 3236 rdpdr - ok 14:46:49.0734 3236 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 14:46:49.0734 3236 RDPWD - ok 14:46:49.0781 3236 redbook (55f7fa7c581d3508de96e4adf418d370) C:\WINDOWS\system32\DRIVERS\redbook.sys 14:46:49.0796 3236 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\redbook.sys. md5: 55f7fa7c581d3508de96e4adf418d370 14:46:49.0796 3236 redbook ( LockedFile.Multi.Generic ) - warning 14:46:49.0796 3236 redbook - detected LockedFile.Multi.Generic (1) 14:46:49.0906 3236 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\WINDOWS\system32\Drivers\RimUsb.sys 14:46:49.0953 3236 RimUsb - ok 14:46:50.0156 3236 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 14:46:50.0156 3236 RimVSerPort - ok 14:46:50.0187 3236 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 14:46:50.0203 3236 ROOTMODEM - ok 14:46:50.0296 3236 SCDEmu (20b2751cd4c8f3fd989739ca661b9f30) C:\WINDOWS\system32\drivers\SCDEmu.sys 14:46:50.0343 3236 SCDEmu - ok 14:46:50.0375 3236 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 14:46:50.0437 3236 sdbus - ok 14:46:50.0484 3236 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:46:50.0500 3236 Secdrv - ok 14:46:50.0562 3236 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 14:46:50.0609 3236 Serial - ok 14:46:50.0687 3236 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 14:46:50.0703 3236 Sfloppy - ok 14:46:50.0718 3236 Simbad - ok 14:46:50.0765 3236 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 14:46:50.0796 3236 SLIP - ok 14:46:50.0812 3236 Sparrow - ok 14:46:50.0875 3236 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 14:46:50.0890 3236 splitter - ok 14:46:50.0953 3236 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 14:46:50.0968 3236 sr - ok 14:46:51.0046 3236 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 14:46:51.0046 3236 Srv - ok 14:46:51.0156 3236 STHDA (8990440e4b2a7ca5a56a1833b03741fd) C:\WINDOWS\system32\drivers\sthda.sys 14:46:51.0203 3236 STHDA - ok 14:46:51.0250 3236 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 14:46:51.0281 3236 streamip - ok 14:46:51.0328 3236 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 14:46:51.0343 3236 swenum - ok 14:46:51.0390 3236 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 14:46:51.0437 3236 swmidi - ok 14:46:51.0453 3236 symc810 - ok 14:46:51.0468 3236 symc8xx - ok 14:46:51.0468 3236 sym_hi - ok 14:46:51.0484 3236 sym_u3 - ok 14:46:51.0546 3236 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys 14:46:51.0578 3236 SynTP - ok 14:46:51.0640 3236 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 14:46:51.0640 3236 sysaudio - ok 14:46:51.0718 3236 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:46:51.0734 3236 Tcpip - ok 14:46:51.0765 3236 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 14:46:51.0796 3236 TDPIPE - ok 14:46:51.0828 3236 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 14:46:51.0843 3236 TDTCP - ok 14:46:51.0875 3236 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 14:46:51.0953 3236 TermDD - ok 14:46:51.0968 3236 TosIde - ok 14:46:52.0031 3236 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 14:46:52.0046 3236 Udfs - ok 14:46:52.0062 3236 UIUSys - ok 14:46:52.0078 3236 ultra - ok 14:46:52.0156 3236 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 14:46:52.0203 3236 Update - ok 14:46:52.0265 3236 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 14:46:52.0296 3236 usbaudio - ok 14:46:52.0359 3236 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 14:46:52.0375 3236 usbccgp - ok 14:46:52.0406 3236 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 14:46:52.0421 3236 usbehci - ok 14:46:52.0453 3236 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:46:52.0484 3236 usbhub - ok 14:46:52.0531 3236 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 14:46:52.0546 3236 usbohci - ok 14:46:52.0593 3236 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 14:46:52.0609 3236 usbprint - ok 14:46:52.0656 3236 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:46:52.0687 3236 USBSTOR - ok 14:46:52.0734 3236 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 14:46:52.0734 3236 usbvideo - ok 14:46:52.0765 3236 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys 14:46:52.0781 3236 usb_rndisx - ok 14:46:52.0843 3236 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 14:46:52.0859 3236 VgaSave - ok 14:46:52.0875 3236 ViaIde - ok 14:46:52.0890 3236 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 14:46:52.0921 3236 VolSnap - ok 14:46:52.0984 3236 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:46:53.0015 3236 Wanarp - ok 14:46:53.0062 3236 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 14:46:53.0078 3236 Wdf01000 - ok 14:46:53.0093 3236 WDICA - ok 14:46:53.0125 3236 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 14:46:53.0156 3236 wdmaud - ok 14:46:53.0234 3236 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 14:46:53.0265 3236 winachsf - ok 14:46:53.0328 3236 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 14:46:53.0343 3236 WmiAcpi - ok 14:46:53.0390 3236 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 14:46:53.0421 3236 WSTCODEC - ok 14:46:53.0468 3236 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:46:53.0484 3236 WudfPf - ok 14:46:53.0515 3236 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 14:46:53.0515 3236 WudfRd - ok 14:46:53.0562 3236 xusb21 (a640c90b007762939507c28a021be3b3) C:\WINDOWS\system32\DRIVERS\xusb21.sys 14:46:53.0562 3236 xusb21 - ok 14:46:53.0734 3236 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl 14:46:53.0734 3236 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} - ok 14:46:53.0765 3236 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 14:46:54.0062 3236 \Device\Harddisk0\DR0 - ok 14:46:54.0062 3236 Boot (0x1200) (4bb2c283b065595bc43bac840e3a0cb9) \Device\Harddisk0\DR0\Partition0 14:46:54.0062 3236 \Device\Harddisk0\DR0\Partition0 - ok 14:46:54.0062 3236 ============================================================ 14:46:54.0062 3236 Scan finished 14:46:54.0062 3236 ============================================================ 14:46:54.0078 3232 Detected object count: 1 14:46:54.0078 3232 Actual detected object count: 1 14:59:02.0937 3232 HKLM\SYSTEM\ControlSet001\services\redbook - will be deleted on reboot 14:59:02.0937 3232 HKLM\SYSTEM\ControlSet003\services\redbook - will be deleted on reboot 14:59:02.0937 3232 C:\WINDOWS\system32\DRIVERS\redbook.sys - will be deleted on reboot 14:59:02.0937 3232 redbook ( LockedFile.Multi.Generic ) - User select action: Delete 14:59:08.0671 1472 Deinitialize success
Hi KingSmokey, Great job!! Now I would like for you to delete your copy of ComboFix using right-click >> delete and then download a fresh copy to your Desktop. Once you get the fresh copy on your system, please run a new scan and then post the new log into your next reply. Please just copy and paste the logs into the replies. It helps me to read them more easily. :)
ComboFix 11-12-23.01 - King 12/23/2011 16:55:34.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1235 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-22 07:50 . 2011-12-22 07:50 ——– d—–w- C:\Files
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-12-20 07:40 . 2011-12-20 07:49 ——– d—–w- C:\sh4ldr
2011-12-20 07:40 . 2011-12-20 07:40 ——– d—–w- c:\program files\Enigma Software Group
2011-12-19 21:56 . 2011-12-19 21:56 ——– d—–w- c:\documents and settings\King\Local Settings\Application Data\ESET
2011-12-19 19:41 . 2011-12-19 19:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-19 19:09 . 2011-12-19 19:09 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-12-19 18:57 . 2011-12-19 18:57 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\program files\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2011-12-19 01:32 . 2011-12-19 03:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-12-19 01:32 . 2011-12-19 01:40 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\King\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-18 07:07 . 2011-09-01 01:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 05:29 . 2011-12-18 05:29 ——– d—–w- C:\thumb drive
2011-11-24 04:59 . 2011-11-24 04:59 ——– d—–w- C:\Documents%20and%20Settings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 22:43 . 2011-06-24 19:04 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-09 04:50 . 2011-05-18 17:36 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-23_20.18.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-23 23:05 . 2011-12-23 23:05 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-06-24 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"NetStat Live"="c:\program files\NetworkTools\AnalogX\NetStat Live\nsl.exe" [2011-05-18 184304]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-29 2054360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2011-06-06 19:55 2903448 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-06-06 19:55 36760 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 17:29 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-11-09 01:52 497648 —-a-w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 11:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 21:54 91520 —-a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2010-03-14 03:58 75048 ——w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HitmanPro35]
2011-11-01 03:06 6480192 —-a-w- c:\program files\Hitman Pro 3.5\HitmanPro35.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2011-04-27 00:22 593920 —-a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-03-02 06:14 190808 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
2011-09-20 21:53 1493288 —-a-w- c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RayV]
2011-02-15 14:01 3442552 —-a-w- c:\program files\RayV\RayV\RayV.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
2010-02-03 07:08 87336 ——w- c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 18:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2005-12-06 17:24 163840 —-a-w- c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 19:59 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 20:37 517096 —-a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.dll"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\drivers\NBVol.sys [10/31/2011 7:01 PM 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\drivers\NBVolUp.sys [10/31/2011 7:01 PM 12464]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9/29/2009 1:02 PM 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [9/29/2009 1:05 PM 96408]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/08/12 12:16];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [3/13/2010 11:58 AM 87536]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [9/29/2009 1:03 PM 735960]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [9/23/2011 5:37 PM 641832]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [3/31/2011 3:08 PM 80896]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [5/25/2011 8:05 PM 442656]
S0 87343629;87343629;c:\windows\system32\drivers\39580663.sys –> c:\windows\system32\drivers\39580663.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 CAM1690;USB PC Camera;c:\windows\system32\drivers\cam1690.sys [11/21/2007 4:37 PM 181888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [6/24/2011 11:04 AM 23624]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [8/10/2011 10:19 AM 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [6/22/2010 5:01 PM 21248]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 9:25 AM 30969208]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [7/8/2010 9:52 AM 20480]
S3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\drivers\nwusbmdm_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\drivers\nwusbser_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\drivers\nwusbser2_000.sys [7/8/2010 9:52 AM 176384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 8:37 PM 4640000]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 2:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hockey.fantasysports.yahoo.com/hockey/7840
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\King\Application Data\Mozilla\Firefox\Profiles\zd3jzgxo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-87343629.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-23 17:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1904)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-23 17:06:45
ComboFix-quarantined-files.txt 2011-12-24 01:06
ComboFix2.txt 2011-12-23 20:24
.
Pre-Run: 49,365,823,488 bytes free
Post-Run: 49,371,131,904 bytes free
.
- - End Of File - - CF4BF67F098976E5F30D3C42BC1C7A2B
Hi KingSmokey,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DirLook::
    c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
    
    File::
    c:\windows\system32\drivers\39580663.sys
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"=-
    
    Driver::
    87343629
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 11-12-23.01 - King 12/23/2011 20:15:49.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1212 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-22 07:50 . 2011-12-22 07:50 ——– d—–w- C:\Files
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-12-20 07:40 . 2011-12-20 07:49 ——– d—–w- C:\sh4ldr
2011-12-20 07:40 . 2011-12-20 07:40 ——– d—–w- c:\program files\Enigma Software Group
2011-12-19 21:56 . 2011-12-19 21:56 ——– d—–w- c:\documents and settings\King\Local Settings\Application Data\ESET
2011-12-19 19:41 . 2011-12-19 19:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-19 19:09 . 2011-12-19 19:09 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-12-19 18:57 . 2011-12-19 18:57 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\program files\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2011-12-19 01:32 . 2011-12-19 03:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-12-19 01:32 . 2011-12-19 01:40 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\King\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-18 07:07 . 2011-09-01 01:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 05:29 . 2011-12-18 05:29 ——– d—–w- C:\thumb drive
2011-11-24 04:59 . 2011-11-24 04:59 ——– d—–w- C:\Documents%20and%20Settings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 22:43 . 2011-06-24 19:04 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-09 04:50 . 2011-05-18 17:36 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-23_20.18.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-23 23:05 . 2011-12-23 23:05 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-06-24 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"NetStat Live"="c:\program files\NetworkTools\AnalogX\NetStat Live\nsl.exe" [2011-05-18 184304]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-29 2054360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2011-06-06 19:55 2903448 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-06-06 19:55 36760 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 17:29 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-11-09 01:52 497648 —-a-w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 11:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 21:54 91520 —-a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2010-03-14 03:58 75048 ——w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HitmanPro35]
2011-11-01 03:06 6480192 —-a-w- c:\program files\Hitman Pro 3.5\HitmanPro35.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2011-04-27 00:22 593920 —-a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-03-02 06:14 190808 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
2011-09-20 21:53 1493288 —-a-w- c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RayV]
2011-02-15 14:01 3442552 —-a-w- c:\program files\RayV\RayV\RayV.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
2010-02-03 07:08 87336 ——w- c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 18:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2005-12-06 17:24 163840 —-a-w- c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 19:59 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 20:37 517096 —-a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.dll"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\drivers\NBVol.sys [10/31/2011 7:01 PM 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\drivers\NBVolUp.sys [10/31/2011 7:01 PM 12464]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9/29/2009 1:02 PM 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [9/29/2009 1:05 PM 96408]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/08/12 12:16];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [3/13/2010 11:58 AM 87536]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [9/29/2009 1:03 PM 735960]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [9/23/2011 5:37 PM 641832]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [3/31/2011 3:08 PM 80896]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [5/25/2011 8:05 PM 442656]
S0 87343629;87343629;c:\windows\system32\drivers\39580663.sys –> c:\windows\system32\drivers\39580663.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 CAM1690;USB PC Camera;c:\windows\system32\drivers\cam1690.sys [11/21/2007 4:37 PM 181888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [6/24/2011 11:04 AM 23624]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [8/10/2011 10:19 AM 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [6/22/2010 5:01 PM 21248]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 9:25 AM 30969208]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [7/8/2010 9:52 AM 20480]
S3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\drivers\nwusbmdm_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\drivers\nwusbser_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\drivers\nwusbser2_000.sys [7/8/2010 9:52 AM 176384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 8:37 PM 4640000]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 2:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hockey.fantasysports.yahoo.com/hockey/7840
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\King\Application Data\Mozilla\Firefox\Profiles\zd3jzgxo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-23 20:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2968)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-23 20:21:45
ComboFix-quarantined-files.txt 2011-12-24 04:21
ComboFix2.txt 2011-12-24 01:06
ComboFix3.txt 2011-12-23 20:24
.
Pre-Run: 49,372,213,248 bytes free
Post-Run: 49,358,004,224 bytes free
.
- - End Of File - - 535891FA269CAA13D25093F1A9AC8535
Hi KingSmokey, It looks like something happened with the fix. Please follow the previous set of instructions that I provided and then post the new ComboFix log that is created. If you have any questions or problems don't hesitate to ask.
ComboFix 11-12-24.07 - King 12/24/2011 11:51:04.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1215 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\King\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\windows\system32\drivers\39580663.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_87343629
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-22 07:50 . 2011-12-22 07:50 ——– d—–w- C:\Files
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-12-20 09:33 . 2011-12-20 09:33 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-12-20 07:40 . 2011-12-20 07:49 ——– d—–w- C:\sh4ldr
2011-12-20 07:40 . 2011-12-20 07:40 ——– d—–w- c:\program files\Enigma Software Group
2011-12-19 21:56 . 2011-12-19 21:56 ——– d—–w- c:\documents and settings\King\Local Settings\Application Data\ESET
2011-12-19 19:41 . 2011-12-19 19:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-12-19 19:09 . 2011-12-19 19:09 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-12-19 18:57 . 2011-12-19 18:57 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\program files\ESET
2011-12-19 09:54 . 2011-12-19 09:54 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2011-12-19 01:32 . 2011-12-19 03:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-12-19 01:32 . 2011-12-19 01:40 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\King\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-18 07:07 . 2011-12-18 07:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-18 07:07 . 2011-09-01 01:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 05:29 . 2011-12-18 05:29 ——– d—–w- C:\thumb drive
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 22:43 . 2011-06-24 19:04 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-09 04:50 . 2011-05-18 17:36 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP —-
.
2011-12-20 07:49 . 2011-12-20 07:49 7364 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseData.ini
2011-12-20 07:48 . 2011-12-20 07:48 180382 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla21.dll
2011-12-20 07:48 . 2011-12-20 07:38 180382 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla21.exe
2011-12-20 07:48 . 2011-12-20 07:48 175992 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla20.dll
2011-12-20 07:48 . 2011-12-20 07:48 179340 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla18.exe
2011-12-20 07:48 . 2011-12-20 07:48 176035 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla19.dll
2011-12-20 07:48 . 2011-12-20 07:48 179340 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla.dll
2011-12-20 07:48 . 2011-12-20 07:48 176035 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla2.dll
2011-12-20 07:48 . 2011-12-20 07:48 176545 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCalla17.dll
2011-12-20 07:48 . 2011-12-20 07:48 27499 —-a-w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP\WiseCustomCall.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-23_20.18.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-24 19:58 . 2011-12-24 19:58 16384 c:\windows\Temp\Perflib_Perfdata_6f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-06-24 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"NetStat Live"="c:\program files\NetworkTools\AnalogX\NetStat Live\nsl.exe" [2011-05-18 184304]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-29 2054360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2011-06-06 19:55 2903448 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-06-06 19:55 36760 —-a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 17:29 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-11-09 01:52 497648 —-a-w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 11:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2011-05-03 15:43 4321112 —-a-w- c:\program files\AIM\aim.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 21:54 91520 —-a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2010-03-14 03:58 75048 ——w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HitmanPro35]
2011-11-01 03:06 6480192 —-a-w- c:\program files\Hitman Pro 3.5\HitmanPro35.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTC Sync Loader]
2011-04-27 00:22 593920 —-a-w- c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-03-02 06:14 190808 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
2011-09-20 21:53 1493288 —-a-w- c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RayV]
2011-02-15 14:01 3442552 —-a-w- c:\program files\RayV\RayV\RayV.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
2010-02-03 07:08 87336 ——w- c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 18:47 79192 —-a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2005-12-06 17:24 163840 —-a-w- c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 19:59 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 20:37 517096 —-a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.dll"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
.
R0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\drivers\NBVol.sys [10/31/2011 7:01 PM 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\drivers\NBVolUp.sys [10/31/2011 7:01 PM 12464]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9/29/2009 1:02 PM 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [9/29/2009 1:05 PM 96408]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/08/12 12:16];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [3/13/2010 11:58 AM 87536]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [9/29/2009 1:03 PM 735960]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [9/23/2011 5:37 PM 641832]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [3/31/2011 3:08 PM 80896]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [5/25/2011 8:05 PM 442656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 CAM1690;USB PC Camera;c:\windows\system32\drivers\cam1690.sys [11/21/2007 4:37 PM 181888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [6/24/2011 10:17 AM 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [6/24/2011 11:04 AM 23624]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [8/10/2011 10:19 AM 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [6/22/2010 5:01 PM 21248]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 9:25 AM 30969208]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [7/8/2010 9:52 AM 20480]
S3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\drivers\nwusbmdm_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\drivers\nwusbser_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\drivers\nwusbser2_000.sys [7/8/2010 9:52 AM 176384]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 8:37 PM 4640000]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 2:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-24 18:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hockey.fantasysports.yahoo.com/hockey/7840
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\King\Application Data\Mozilla\Firefox\Profiles\zd3jzgxo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-24 11:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(4048)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\SearchIndexer.exe
c:\windows\System32\bcmwltry.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\windows\stsystra.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Completion time: 2011-12-24 12:07:37 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-24 20:07
ComboFix2.txt 2011-12-24 04:21
ComboFix3.txt 2011-12-24 01:06
ComboFix4.txt 2011-12-23 20:24
.
Pre-Run: 49,369,243,648 bytes free
Post-Run: 49,357,254,656 bytes free
.
- - End Of File - - D662959E486993033FE30B75AE6FB7EB


If something is going wrong and it would help that I remove all previous AV and ASW/AMW programs, I have no problems doing that.

Again, thanks so much for helping.
Hi KingSmokey,

Again, thanks so much for helping.

You are more than welcome. :)
—————

P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.
———

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Please save the log that is created for your next reply.
———-

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET online scan. :)
Heh. Thanks for the concern and I totally know where you are coming from. Actually, I'm a MCSE/MCDBA and I have a network of other database people and programmers across the country that we've known each other for years for writing for websites… Its how we share all our stuff with each other. No worries there. Funny part is, I know exactly when and where this started. It was one of those moments when in your head, you stop for a second and go "uh-oh"!! I normally don't have any anti virus or anti malware programs on this computer and I never (knock on wood) have problems, but I was reading reviews about xbox games and I went to the wrong page and now we are here… :pullhair: Ok… Malwarebytes: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122405 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/24/2011 1:08:18 PM mbam-log-2011-12-24 (13-08-18).txt Scan type: Quick scan Objects scanned: 167105 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESET online scanner…. I must have missed the export button, but it came up with zero threats.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI