This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Since last week, my pc has been running extremely slow. I decided to go into task manager to see what was causing the high CPU/mem usage. The highest item was a svchost.exe process. I am not sure if this is a virus/malware. Is there any way to get rid of this to make my pc faster? Below is my HighjackThis Log. Thank you for your help in advance. I greatly appreciate it.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:24:30 PM, on 12/22/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: UserZoomBHO - {246E2928-34B8-48D9-BE73-38BA37241E5B} - C:\WINDOWS\Downloaded Program Files\UserZoom.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10n_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Harry\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - https://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo1.walgreens.com/WalgreensActivia.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - http://picasaweb.google.com/s/v/19.13/uploader2.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applicatio…torLauncher.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} - http://download.sopcast.com/download/SOPCORE.CAB
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileopen.com/current/FileOpen.CAB
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.cric7.com/vjocx-en-black.cab
O16 - DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} (Invoke Solutions Participant Control(MR)) - http://online.invokesolutions.com/events/b…1445/MILive.cab
O16 - DPF: {D9944C1C-C6BB-4E90-8E37-55F9FFABC6B8} (CUZControl Object) - https://server.userzoom.com/uz/UserZoom.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup163.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: AnyDiscHelp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - file:///C:/Documents%20and%20Settings/Harry/Desktop/1.jpg

–
End of file - 15314 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!





HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt






Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Thank you for your quick reply. I am pasting the DDS and Attach text files first and then the log from Kaspersky. Kaspersky found 1 threat, and as you mentioned, I did not cure it. I am sure you can tell all this from the logs. Thank you again for all your help.

DDS:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_19
Run by [removed] at 13:25:36 on 2011-12-23
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.89 [GMT -6:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
mDefault_Page_URL = hxxp://yahoo.sbc.com/dsl
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: UserZoomBHO Class: {246e2928-34b8-48d9-be73-38ba37241e5b} - c:\windows\downloaded program files\UserZoom.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {40D41A8B-D79B-43D7-99A7-9EE0F344C385} - No File
TB: {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\Harry\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YahooMessenger.exe" -quiet
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: &AIM Search
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Harry\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: bankofamerica.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo1.walgreens.com/WalgreensActivia.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/19.13/uploader2.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} - hxxp://download.sopcast.com/download/SOPCORE.CAB
DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} - hxxps://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} - hxxp://plugin.fileopen.com/current/FileOpen.CAB
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://www.cric7.com/vjocx-en-black.cab
DPF: {D8AA889B-2C65-47C3-8C16-3DCD4EF76A47} - hxxp://online.invokesolutions.com/events/bin/6.0.0.1445/MILive.cab
DPF: {D9944C1C-C6BB-4E90-8E37-55F9FFABC6B8} - hxxps://server.userzoom.com/uz/UserZoom.cab
DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - hxxp://download.abacast.com/download/files/abasetup163.cab
DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{31D92F1A-7EE4-4508-A5D6-64824A6F966F} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{BD732DB4-8F57-4001-91AA-D8DB59F1CE23} : DhcpNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
Notify: WRNotifier - WRLogonNTF.dll
AppInit_DLLs: AnyDiscHelp.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\Harry\application data\mozilla\firefox\profiles\x0t12j16.profilename\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - plugin: c:\documents and settings\Harry\application data\move networks\plugins\071802000001\npqmp071802000001.dll
FF - plugin: c:\documents and settings\Harry\application data\move networks\plugins\npqmp071705000014.dll
FF - plugin: c:\documents and settings\Harry\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Harry\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\Harry\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.67\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.68\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\quicktime\plugins\npqtplugin8.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
.
—- FIREFOX POLICIES —-
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: signon.rememberSignons - false
FF - user.js: update_notifications.enabled - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
============= SERVICES / DRIVERS ===============
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-2-22 114984]
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;c:\program files\belkin\belkin wireless network utility\WLService.exe [2005-4-8 49152]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2010-2-22 810120]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\sync\FreeAgentService.exe [2009-1-16 161064]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-6-1 34064]
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\system32\drivers\rt2500usb.sys [2005-4-8 140416]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-21 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-21 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys –> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-1-11 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys –> c:\windows\system32\drivers\motport.sys [?]
S3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\drivers\procexp151.sys –> c:\windows\system32\drivers\PROCEXP151.SYS [?]
S3 vidcap;vidcap;c:\windows\system32\drivers\vidcap.sys –> c:\windows\system32\drivers\vidcap.sys [?]
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-12-23 05:43:34 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{111fae77-7791-483b-8418-e57bea2e0652}\offreg.dll
2011-12-23 04:19:30 388096 —-a-r- c:\documents and settings\Harry\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-23 04:19:11 ——– d—–w- c:\program files\Trend Micro
2011-12-20 01:46:22 6823496 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{111fae77-7791-483b-8418-e57bea2e0652}\mpengine.dll
2011-12-20 00:29:14 1266056 —-a-w- C:\WindowsXP-KB927891-v3-x86-ENU.exe
2011-12-20 00:27:23 6216032 —-a-w- C:\windowsupdateagent30-x86.exe
2011-12-08 03:46:57 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-12-08 03:46:56 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-12-08 03:46:55 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-12-08 03:46:54 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-12-08 03:46:54 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-12-08 03:46:54 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-12-08 03:46:53 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-12-08 03:46:52 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
.
==================== Find3M ====================
.
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33:08 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:03 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2007-12-16 01:46:45 779312 —-a-w- c:\program files\MoveMediaPlayer_07074039.exe
2005-05-06 02:17:14 2656568 —-a-w- c:\program files\ica32t.exe
2010-04-29 04:57:12 4608 –sha-r- c:\windows\system32\AnyDiscHelp.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD800BB-75FJA1 rev.14.03G14 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82B8149F]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82b88738]; MOV EAX, [0x82b888ac]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x83352AB8]
3 CLASSPNP[0xF8838FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x8334C0D8]
\Driver\atapi[0x82E06550] -> IRP_MJ_CREATE -> 0x82B8149F
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { CLI ; MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62f; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x82B812C6
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 13:36:23.54 ===============

Attach:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 10/10/2004 1:22:00 PM
System Uptime: 12/23/2011 11:53:11 AM (2 hours ago)
.
Motherboard: Dell Computer Corp. | | 0F4491
Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/533mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 71 GiB total, 10.836 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP2053: 9/16/2011 10:30:50 PM - Software Distribution Service 3.0
RP2054: 9/17/2011 11:47:17 AM - Software Distribution Service 3.0
RP2055: 9/18/2011 12:36:57 PM - System Checkpoint
RP2056: 9/23/2011 8:25:39 PM - Software Distribution Service 3.0
RP2057: 9/25/2011 12:13:41 PM - System Checkpoint
RP2058: 9/27/2011 10:05:17 PM - Software Distribution Service 3.0
RP2059: 9/28/2011 12:02:42 AM - Software Distribution Service 3.0
RP2060: 9/30/2011 9:20:12 PM - Software Distribution Service 3.0
RP2061: 10/2/2011 11:49:14 AM - System Checkpoint
RP2062: 10/3/2011 7:21:03 PM - System Checkpoint
RP2063: 10/4/2011 9:02:17 PM - Software Distribution Service 3.0
RP2064: 10/5/2011 11:03:17 PM - System Checkpoint
RP2065: 10/7/2011 11:24:22 PM - Software Distribution Service 3.0
RP2066: 10/12/2011 8:56:15 PM - Software Distribution Service 3.0
RP2067: 10/13/2011 12:59:53 AM - Software Distribution Service 3.0
RP2068: 10/14/2011 8:30:51 PM - Software Distribution Service 3.0
RP2069: 10/16/2011 12:35:11 PM - System Checkpoint
RP2070: 10/17/2011 10:05:07 PM - System Checkpoint
RP2071: 10/19/2011 8:17:42 PM - Software Distribution Service 3.0
RP2072: 10/21/2011 9:49:48 PM - Software Distribution Service 3.0
RP2073: 10/23/2011 7:52:48 PM - System Checkpoint
RP2074: 10/26/2011 7:46:47 PM - Software Distribution Service 3.0
RP2075: 10/29/2011 2:26:24 PM - Software Distribution Service 3.0
RP2076: 11/1/2011 8:51:03 PM - Software Distribution Service 3.0
RP2077: 11/5/2011 1:16:27 PM - Software Distribution Service 3.0
RP2078: 11/6/2011 10:51:40 PM - System Checkpoint
RP2079: 11/8/2011 8:34:06 PM - Software Distribution Service 3.0
RP2080: 11/10/2011 1:01:00 AM - Software Distribution Service 3.0
RP2081: 11/12/2011 8:32:28 AM - Software Distribution Service 3.0
RP2082: 11/12/2011 11:11:50 AM - Software Distribution Service 3.0
RP2083: 11/15/2011 7:53:14 PM - Software Distribution Service 3.0
RP2084: 11/16/2011 9:21:50 PM - System Checkpoint
RP2085: 11/17/2011 9:33:30 PM - System Checkpoint
RP2086: 11/30/2011 7:55:26 PM - Software Distribution Service 3.0
RP2087: 12/3/2011 10:28:20 AM - Software Distribution Service 3.0
RP2088: 12/4/2011 3:27:00 PM - System Checkpoint
RP2089: 12/7/2011 8:23:29 PM - Software Distribution Service 3.0
RP2090: 12/8/2011 8:13:38 PM - Software Distribution Service 3.0
RP2091: 12/9/2011 8:25:53 PM - Software Distribution Service 3.0
RP2092: 12/12/2011 7:31:03 PM - System Checkpoint
RP2093: 12/14/2011 8:33:26 PM - System Checkpoint
RP2094: 12/18/2011 11:30:08 AM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
.
Adobe Acrobat 8 Professional - English, Français, Deutsch
Adobe Acrobat 8.1.3 Professional
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.3
AIM 7
AnswerWorks 5.0 English Runtime
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
Apollo DivX to DVD Creator 1.2.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Banctec Service Agreement
Belkin 54g USB Network Adapter
Biz Plan Builder 10
BlackBerry Desktop Software 5.0
BlackBerry Desktop Software 6.0
Canon MP Navigator EX 2.1
Canon MX330 series MP Drivers
Canon MX330 series User Registration
Canon Utilities My Printer
Canon Utilities Solution Menu
CCleaner
Choice Guard
CLIE MS SCSI Driver
Coupon Printer for Windows
Dell Digital Jukebox Driver
Dell Media Experience
Dell Networking Guide
Dell Solution Center
DellSupport
DING!
Documents To Go Desktop for iPhone
Download Updater (AOL LLC)
DVDFab 8
ESET Smart Security
FileOpen Plug-in for Adobe Acrobat® and Acrobat Reader®
FileOpen Plug-in for Adobe Acrobat® and Adobe Reader®
Get High Speed Internet!
Google Earth Plug-in
Google Talk Plugin
Google Update Helper
Google Video Player
Help and Support Customization
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
iCamSource
Image Transfer
Intel® 537EP V9x DF PCI Modem
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet
InterActual Player
Internet Explorer Default Page
Invoke Solutions Participant 6.0.0.1445
iPod movie Converter 3
iTunes
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Java Auto Updater
Java™ 6 Update 19
Keynote Connector
Lexmark X73
LimeWire PRO 4.13.0
Logitech QuickCam Express
Macromedia Shockwave Player
Malwarebytes' Anti-Malware version 1.51.2.1300
MediaFACE 4.0
MetaFrame Presentation Server Web Client for Win32
MGI PhotoSuite 8.1 (Remove Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Application Error Reporting
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft MPEG-4 VKI Video Codec V1/V2/V3
Microsoft NetShow Tools 2.0
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MIDAS
Modem Event Monitor
Modem Helper
Modem On Hold
Motorola Driver Installation 3.2.0
Motorola Phone Tools
Move Media Player
Mozilla Firefox 8.0.1 (x86 en-US)
MSN Music Assistant
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My DSC
Nokia Connectivity Cable Driver
Palm Desktop
PowerDVD 5.1
PrintKey-Pro v1.05
Quicken WillMaker Plus 2009
QuickTime
RealPlayer
Riva FLV Encoder 2.0
Roxio Media Manager
SBC Yahoo! Applications
Seagate Manager Installer
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Groove 2007 (KB2552997)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Microsoft Windows (KB2564958)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2416400)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2482017)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2497640)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2530548)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544521)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2559049)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2586448)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2618444)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982802)
Segoe UI
Shockwave
SmartSound Quicktracks Plugin
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sony USB Driver
T-Mobile Shadow™ User Manual
Tansee iPhone Transfer Contact
Total Video Converter 3.70 100621
TurboTax 2008
TurboTax 2008 wiliper
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax 2009
TurboTax 2009 wiliper
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wrapper
TurboTax 2010
TurboTax 2010 wiliper
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
Ulead DVD Workshop 2 Trial
Unix Utilities for Yahoo! Widgets
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Outlook 2007 Junk Email Filter (KB2596560)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Virtual DJ - Atomix Productions
WebFldrs XP
WexTech AnswerWorks
Windows Defender
Windows Defender Signatures
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Safety Scanner
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB894476
Windows XP Service Pack 3
winpcap-nmap 4.02
WinRAR archiver
WordPerfect Office 12
Xvid 1.1.2 final uninstall
XviD MPEG-4 Video Codec
Yahoo! Software Update
Yahoo! Widgets
.
==== Event Viewer Messages From Past Week ========
.
12/23/2011 12:23:03 AM, error: Service Control Manager [7034] - The Automatic Updates service terminated unexpectedly. It has done this 1 time(s).
12/23/2011 11:58:27 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
12/23/2011 11:58:27 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/23/2011 1:36:30 PM, error: Service Control Manager [7034] - The Themes service terminated unexpectedly. It has done this 3 time(s).
12/23/2011 1:36:30 PM, error: Service Control Manager [7034] - The System Event Notification service terminated unexpectedly. It has done this 3 time(s).
12/23/2011 1:25:15 AM, error: Service Control Manager [7034] - The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s).
12/23/2011 1:15:55 AM, error: Service Control Manager [7034] - The COM+ Event System service terminated unexpectedly. It has done this 2 time(s).
12/23/2011 1:15:55 AM, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
12/23/2011 1:13:20 AM, error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s).
12/23/2011 1:13:20 AM, error: Service Control Manager [7034] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s).
12/23/2011 1:13:20 AM, error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/22/2011 9:15:15 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: agp440
12/22/2011 9:15:13 PM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
12/22/2011 9:10:53 PM, error: Print [19] - Sharing printer failed + 1722, Printer Lexmark X73 (Copy 1) share name Printer2.
12/22/2011 10:27:49 PM, error: Service Control Manager [7034] - The Automatic Updates service terminated unexpectedly. It has done this 2 time(s).
12/19/2011 7:03:37 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
12/19/2011 7:00:45 PM, error: Service Control Manager [7000] - The MBAMSwissArmy service failed to start due to the following error: The system cannot find the file specified.
12/19/2011 6:39:17 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/19/2011 6:37:22 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/19/2011 6:37:12 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/19/2011 6:36:25 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD ehdrv ElbyCDIO epfwtdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The Fax service depends on the Print Spooler service which failed to start because of the following error: The dependency service or group failed to start.
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/19/2011 6:36:25 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/19/2011 5:48:02 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Fax service to connect.
12/19/2011 5:48:02 PM, error: Service Control Manager [7000] - The Fax service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/19/2011 5:47:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect.
12/19/2011 5:47:38 PM, error: Service Control Manager [7000] - The Lexmark X73 MFP Scanner service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
12/18/2011 9:52:34 PM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/18/2011 9:52:32 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
12/18/2011 7:26:47 PM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
12/18/2011 11:51:08 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the FLEXnet Licensing Service service to connect.
12/18/2011 11:51:08 AM, error: Service Control Manager [7000] - The FLEXnet Licensing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/18/2011 11:32:54 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
12/18/2011 11:26:09 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0011504C7890. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
.
==== End Of File ===========================

Log from Kaspersky:

13:40:14.0093 3316 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
13:40:15.0281 3316 ============================================================
13:40:15.0281 3316 Current date / time: 2011/12/23 13:40:15.0281
13:40:15.0281 3316 SystemInfo:
13:40:15.0281 3316
13:40:15.0281 3316 OS Version: 5.1.2600 ServicePack: 3.0
13:40:15.0281 3316 Product type: Workstation
13:40:15.0281 3316 ComputerName: HMelzer
13:40:15.0281 3316 UserName: Harry
13:40:15.0281 3316 Windows directory: C:\WINDOWS
13:40:15.0281 3316 System windows directory: C:\WINDOWS
13:40:15.0281 3316 Processor architecture: Intel x86
13:40:15.0281 3316 Number of processors: 1
13:40:15.0281 3316 Page size: 0x1000
13:40:15.0281 3316 Boot type: Normal boot
13:40:15.0281 3316 ============================================================
13:40:19.0500 3316 Initialize success
13:40:28.0328 0624 ============================================================
13:40:28.0328 0624 Scan started
13:40:28.0328 0624 Mode: Manual;
13:40:28.0328 0624 ============================================================
13:40:30.0734 0624 Abiosdsk - ok
13:40:30.0828 0624 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
13:40:30.0859 0624 abp480n5 - ok
13:40:31.0078 0624 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
13:40:31.0078 0624 ACPI - ok
13:40:31.0265 0624 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
13:40:31.0312 0624 ACPIEC - ok
13:40:31.0515 0624 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
13:40:31.0625 0624 adpu160m - ok
13:40:31.0812 0624 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
13:40:31.0828 0624 aeaudio - ok
13:40:32.0031 0624 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
13:40:32.0046 0624 aec - ok
13:40:32.0218 0624 AegisP (4b66e250c94c92522c33a759d5d273cb) C:\WINDOWS\system32\DRIVERS\AegisP.sys
13:40:32.0250 0624 AegisP - ok
13:40:32.0375 0624 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
13:40:32.0406 0624 AFD - ok
13:40:32.0546 0624 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys
13:40:32.0593 0624 agp440 - ok
13:40:32.0765 0624 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
13:40:32.0812 0624 agpCPQ - ok
13:40:33.0015 0624 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
13:40:33.0046 0624 Aha154x - ok
13:40:33.0250 0624 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
13:40:33.0281 0624 aic78u2 - ok
13:40:33.0421 0624 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
13:40:33.0468 0624 aic78xx - ok
13:40:33.0640 0624 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
13:40:33.0687 0624 AliIde - ok
13:40:33.0812 0624 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
13:40:33.0828 0624 alim1541 - ok
13:40:34.0031 0624 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
13:40:34.0078 0624 amdagp - ok
13:40:34.0265 0624 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
13:40:34.0281 0624 amsint - ok
13:40:34.0500 0624 AnyDVD (82ce157ff3701ab50769b2654d0b0215) C:\WINDOWS\system32\Drivers\AnyDVD.sys
13:40:34.0500 0624 AnyDVD - ok
13:40:34.0718 0624 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
13:40:34.0796 0624 asc - ok
13:40:34.0984 0624 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
13:40:35.0000 0624 asc3350p - ok
13:40:35.0140 0624 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
13:40:35.0187 0624 asc3550 - ok
13:40:35.0375 0624 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
13:40:35.0437 0624 AsyncMac - ok
13:40:35.0625 0624 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
13:40:35.0625 0624 atapi - ok
13:40:35.0781 0624 Atdisk - ok
13:40:35.0875 0624 ati2mtag (8759322ffc1a50569c1e5528ee8026b7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
13:40:36.0015 0624 ati2mtag - ok
13:40:36.0218 0624 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
13:40:36.0234 0624 Atmarpc - ok
13:40:36.0390 0624 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
13:40:36.0421 0624 audstub - ok
13:40:36.0578 0624 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
13:40:36.0609 0624 Beep - ok
13:40:36.0734 0624 bkn50USB (6d39682a1051a5be7437ec99f1bf9921) C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
13:40:36.0828 0624 bkn50USB - ok
13:40:36.0984 0624 bvrp_pci - ok
13:40:37.0078 0624 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
13:40:37.0109 0624 cbidf - ok
13:40:37.0281 0624 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
13:40:37.0281 0624 cbidf2k - ok
13:40:37.0375 0624 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
13:40:37.0406 0624 CCDECODE - ok
13:40:37.0593 0624 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
13:40:37.0640 0624 cd20xrnt - ok
13:40:37.0796 0624 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
13:40:37.0828 0624 Cdaudio - ok
13:40:38.0015 0624 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
13:40:38.0078 0624 Cdfs - ok
13:40:38.0546 0624 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
13:40:38.0578 0624 Cdrom - ok
13:40:38.0718 0624 Changer - ok
13:40:38.0875 0624 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys
13:40:38.0890 0624 CmdIde - ok
13:40:39.0078 0624 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
13:40:39.0093 0624 Cpqarray - ok
13:40:39.0296 0624 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
13:40:39.0328 0624 dac2w2k - ok
13:40:39.0515 0624 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
13:40:39.0546 0624 dac960nt - ok
13:40:39.0718 0624 DCamUSBSQTECH (41a2586f3d54efbc1aa8d29748e26634) C:\WINDOWS\system32\Drivers\SQcaptur.sys
13:40:39.0734 0624 DCamUSBSQTECH - ok
13:40:39.0953 0624 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
13:40:39.0953 0624 Disk - ok
13:40:40.0343 0624 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
13:40:40.0468 0624 dmboot - ok
13:40:40.0656 0624 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
13:40:40.0687 0624 dmio - ok
13:40:40.0859 0624 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
13:40:40.0906 0624 dmload - ok
13:40:41.0093 0624 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
13:40:41.0140 0624 DMusic - ok
13:40:41.0328 0624 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
13:40:41.0359 0624 dpti2o - ok
13:40:41.0546 0624 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
13:40:41.0593 0624 drmkaud - ok
13:40:41.0703 0624 drvmcdb (049177996e5e33b5faf40cad2b82098c) C:\WINDOWS\system32\drivers\drvmcdb.sys
13:40:41.0750 0624 drvmcdb - ok
13:40:41.0890 0624 drvnddm (2f4134d073f972575c174e3d621f0107) C:\WINDOWS\system32\drivers\drvnddm.sys
13:40:42.0000 0624 drvnddm - ok
13:40:42.0218 0624 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
13:40:42.0234 0624 DSproct - ok
13:40:42.0406 0624 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
13:40:42.0437 0624 dsunidrv - ok
13:40:42.0640 0624 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
13:40:42.0640 0624 E100B - ok
13:40:42.0812 0624 eamon (55e754e04c09daf19fc0054e72713d80) C:\WINDOWS\system32\DRIVERS\eamon.sys
13:40:42.0875 0624 eamon - ok
13:40:43.0046 0624 ehdrv (6f2441c26d74bde88c25e240a2720eeb) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
13:40:43.0093 0624 ehdrv - ok
13:40:43.0359 0624 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
13:40:43.0359 0624 EL90XBC - ok
13:40:43.0500 0624 ElbyCDIO (309ac30471a0f1c3a89dee1c81230576) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
13:40:43.0531 0624 ElbyCDIO - ok
13:40:43.0671 0624 EntDrv51 - ok
13:40:43.0765 0624 epfw (93aa9cef77315a0866f8307195de416d) C:\WINDOWS\system32\DRIVERS\epfw.sys
13:40:43.0812 0624 epfw - ok
13:40:44.0015 0624 Epfwndis (7946b41daeb3e610742ff01a6d2d61b2) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
13:40:44.0078 0624 Epfwndis - ok
13:40:44.0234 0624 epfwtdi (f38059a07393a8c56bae8ff7ee0c3128) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
13:40:44.0296 0624 epfwtdi - ok
13:40:44.0468 0624 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
13:40:44.0531 0624 Fastfat - ok
13:40:44.0703 0624 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
13:40:44.0765 0624 Fdc - ok
13:40:44.0953 0624 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
13:40:45.0015 0624 Fips - ok
13:40:45.0203 0624 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
13:40:45.0234 0624 Flpydisk - ok
13:40:45.0468 0624 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
13:40:45.0500 0624 FltMgr - ok
13:40:45.0593 0624 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
13:40:45.0609 0624 Fs_Rec - ok
13:40:45.0750 0624 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
13:40:45.0781 0624 Ftdisk - ok
13:40:45.0906 0624 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
13:40:45.0937 0624 GEARAspiWDM - ok
13:40:46.0125 0624 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
13:40:46.0140 0624 Gpc - ok
13:40:46.0312 0624 GTNDIS5 (fc80052194d5708254a346568f0e77c0) C:\WINDOWS\system32\GTNDIS5.SYS
13:40:46.0406 0624 GTNDIS5 - ok
13:40:46.0578 0624 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
13:40:46.0593 0624 HidUsb - ok
13:40:46.0718 0624 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
13:40:46.0781 0624 hpn - ok
13:40:46.0921 0624 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
13:40:46.0937 0624 HTTP - ok
13:40:47.0125 0624 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
13:40:47.0156 0624 i2omgmt - ok
13:40:47.0281 0624 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
13:40:47.0296 0624 i2omp - ok
13:40:47.0468 0624 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
13:40:47.0515 0624 i8042prt - ok
13:40:47.0625 0624 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
13:40:47.0671 0624 i81x - ok
13:40:47.0843 0624 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
13:40:47.0875 0624 iAimFP0 - ok
13:40:48.0062 0624 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
13:40:48.0062 0624 iAimFP1 - ok
13:40:48.0250 0624 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
13:40:48.0250 0624 iAimFP2 - ok
13:40:48.0343 0624 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
13:40:48.0375 0624 iAimFP3 - ok
13:40:48.0625 0624 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
13:40:48.0656 0624 iAimFP4 - ok
13:40:48.0796 0624 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
13:40:48.0859 0624 iAimTV0 - ok
13:40:49.0046 0624 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
13:40:49.0062 0624 iAimTV1 - ok
13:40:49.0187 0624 iAimTV2 - ok
13:40:49.0328 0624 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
13:40:49.0390 0624 iAimTV3 - ok
13:40:49.0625 0624 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
13:40:49.0671 0624 iAimTV4 - ok
13:40:49.0890 0624 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
13:40:49.0968 0624 ialm - ok
13:40:50.0187 0624 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
13:40:50.0218 0624 Imapi - ok
13:40:50.0406 0624 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
13:40:50.0437 0624 ini910u - ok
13:40:50.0656 0624 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
13:40:50.0765 0624 IntelC51 - ok
13:40:50.0968 0624 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
13:40:51.0062 0624 IntelC52 - ok
13:40:51.0265 0624 IntelC53 (de2686c0e012e6ae24acd6e79eb7ff5d) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
13:40:51.0281 0624 IntelC53 - ok
13:40:51.0406 0624 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
13:40:51.0468 0624 IntelIde - ok
13:40:51.0671 0624 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
13:40:51.0703 0624 intelppm - ok
13:40:51.0906 0624 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
13:40:51.0984 0624 ip6fw - ok
13:40:52.0171 0624 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
13:40:52.0218 0624 IpFilterDriver - ok
13:40:52.0328 0624 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
13:40:52.0343 0624 IpInIp - ok
13:40:52.0515 0624 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
13:40:52.0515 0624 IpNat - ok
13:40:52.0703 0624 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
13:40:52.0734 0624 IPSec - ok
13:40:52.0921 0624 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
13:40:52.0953 0624 IRENUM - ok
13:40:53.0078 0624 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
13:40:53.0093 0624 isapnp - ok
13:40:53.0281 0624 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
13:40:53.0343 0624 Kbdclass - ok
13:40:53.0531 0624 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
13:40:53.0546 0624 kmixer - ok
13:40:53.0734 0624 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
13:40:53.0765 0624 KSecDD - ok
13:40:53.0906 0624 lbrtfdc - ok
13:40:54.0015 0624 LXARScan (e8d15acd2f65a2e8756768353e08a9a0) C:\WINDOWS\system32\Drivers\Lxarscan.sys
13:40:54.0031 0624 LXARScan - ok
13:40:54.0187 0624 MBAMSwissArmy - ok
13:40:54.0296 0624 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
13:40:54.0312 0624 mnmdd - ok
13:40:54.0484 0624 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
13:40:54.0500 0624 Modem - ok
13:40:54.0718 0624 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
13:40:54.0734 0624 MODEMCSA - ok
13:40:54.0828 0624 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
13:40:54.0828 0624 mohfilt - ok
13:40:54.0921 0624 motccgp - ok
13:40:55.0109 0624 motccgpfl (aad6191a4daa519f04ab12b2af73e356) C:\WINDOWS\system32\DRIVERS\motccgpfl.sys
13:40:55.0109 0624 motccgpfl - ok
13:40:55.0218 0624 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\WINDOWS\system32\DRIVERS\motmodem.sys
13:40:55.0296 0624 motmodem - ok
13:40:55.0453 0624 motport - ok
13:40:55.0515 0624 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
13:40:55.0546 0624 Mouclass - ok
13:40:55.0781 0624 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
13:40:55.0828 0624 mouhid - ok
13:40:56.0015 0624 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
13:40:56.0062 0624 MountMgr - ok
13:40:56.0234 0624 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
13:40:56.0281 0624 mraid35x - ok
13:40:56.0421 0624 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
13:40:56.0468 0624 MRxDAV - ok
13:40:56.0734 0624 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
13:40:56.0828 0624 MRxSmb - ok
13:40:57.0015 0624 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
13:40:57.0031 0624 Msfs - ok
13:40:57.0156 0624 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
13:40:57.0187 0624 MSKSSRV - ok
13:40:57.0343 0624 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
13:40:57.0375 0624 MSPCLOCK - ok
13:40:57.0468 0624 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
13:40:57.0515 0624 MSPQM - ok
13:40:57.0687 0624 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
13:40:57.0687 0624 mssmbios - ok
13:40:57.0937 0624 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
13:40:57.0968 0624 MSTEE - ok
13:40:58.0062 0624 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
13:40:58.0093 0624 Mup - ok
13:40:58.0281 0624 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
13:40:58.0296 0624 NABTSFEC - ok
13:40:58.0390 0624 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
13:40:58.0421 0624 NDIS - ok
13:40:58.0640 0624 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
13:40:58.0687 0624 NdisIP - ok
13:40:58.0953 0624 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
13:40:58.0984 0624 NdisTapi - ok
13:40:59.0078 0624 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
13:40:59.0109 0624 Ndisuio - ok
13:40:59.0265 0624 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
13:40:59.0281 0624 NdisWan - ok
13:40:59.0421 0624 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
13:40:59.0453 0624 NDProxy - ok
13:40:59.0593 0624 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
13:40:59.0625 0624 NetBIOS - ok
13:40:59.0843 0624 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
13:40:59.0906 0624 NetBT - ok
13:41:00.0156 0624 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
13:41:00.0187 0624 nm - ok
13:41:00.0406 0624 nmwcd (c82f4cc10ad315b6d6bcb14d0a7cad66) C:\WINDOWS\system32\drivers\ccdcmb.sys
13:41:00.0421 0624 nmwcd - ok
13:41:00.0515 0624 nmwcdc (60ef5f5621d7832f00a3f190a0c905e2) C:\WINDOWS\system32\drivers\ccdcmbo.sys
13:41:00.0515 0624 nmwcdc - ok
13:41:00.0671 0624 npf (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys
13:41:00.0671 0624 npf - ok
13:41:00.0796 0624 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
13:41:00.0859 0624 Npfs - ok
13:41:01.0078 0624 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
13:41:01.0156 0624 Ntfs - ok
13:41:01.0359 0624 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
13:41:01.0375 0624 Null - ok
13:41:01.0546 0624 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
13:41:01.0671 0624 nv - ok
13:41:01.0843 0624 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
13:41:01.0859 0624 NwlnkFlt - ok
13:41:01.0953 0624 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
13:41:01.0968 0624 NwlnkFwd - ok
13:41:02.0171 0624 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
13:41:02.0171 0624 omci - ok
13:41:02.0296 0624 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
13:41:02.0328 0624 P3 - ok
13:41:02.0500 0624 PalmUSBD (7238442742146a64fac40fa0f9afd491) C:\WINDOWS\system32\drivers\PalmUSBD.sys
13:41:02.0515 0624 PalmUSBD - ok
13:41:02.0625 0624 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
13:41:02.0656 0624 Parport - ok
13:41:02.0921 0624 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
13:41:02.0953 0624 PartMgr - ok
13:41:03.0093 0624 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
13:41:03.0140 0624 ParVdm - ok
13:41:03.0312 0624 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
13:41:03.0343 0624 PCI - ok
13:41:03.0500 0624 PCIDump - ok
13:41:03.0578 0624 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
13:41:03.0625 0624 PCIIde - ok
13:41:03.0812 0624 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
13:41:03.0843 0624 Pcmcia - ok
13:41:04.0078 0624 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
13:41:04.0109 0624 pcouffin - ok
13:41:04.0203 0624 PDCOMP - ok
13:41:04.0296 0624 PDFRAME - ok
13:41:04.0375 0624 PDRELI - ok
13:41:04.0421 0624 PDRFRAME - ok
13:41:04.0546 0624 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
13:41:04.0578 0624 perc2 - ok
13:41:04.0671 0624 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
13:41:04.0687 0624 perc2hib - ok
13:41:04.0875 0624 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
13:41:04.0984 0624 PptpMiniport - ok
13:41:05.0156 0624 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
13:41:05.0203 0624 Processor - ok
13:41:05.0375 0624 PROCEXP151 - ok
13:41:05.0468 0624 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
13:41:05.0500 0624 PSched - ok
13:41:05.0656 0624 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
13:41:05.0687 0624 Ptilink - ok
13:41:05.0750 0624 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
13:41:05.0765 0624 PxHelp20 - ok
13:41:05.0953 0624 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys
13:41:06.0000 0624 QCDonner - ok
13:41:06.0171 0624 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
13:41:06.0203 0624 ql1080 - ok
13:41:06.0343 0624 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
13:41:06.0468 0624 Ql10wnt - ok
13:41:06.0640 0624 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
13:41:06.0656 0624 ql12160 - ok
13:41:06.0812 0624 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
13:41:06.0859 0624 ql1240 - ok
13:41:07.0015 0624 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
13:41:07.0046 0624 ql1280 - ok
13:41:07.0218 0624 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
13:41:07.0265 0624 RasAcd - ok
13:41:07.0390 0624 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
13:41:07.0406 0624 Rasl2tp - ok
13:41:07.0546 0624 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
13:41:07.0578 0624 RasPppoe - ok
13:41:07.0718 0624 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
13:41:07.0781 0624 Raspti - ok
13:41:07.0890 0624 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
13:41:07.0968 0624 Rdbss - ok
13:41:08.0187 0624 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
13:41:08.0203 0624 RDPCDD - ok
13:41:08.0406 0624 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
13:41:08.0437 0624 rdpdr - ok
13:41:08.0656 0624 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
13:41:08.0718 0624 RDPWD - ok
13:41:08.0937 0624 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
13:41:08.0968 0624 redbook - ok
13:41:09.0078 0624 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
13:41:09.0125 0624 RimUsb - ok
13:41:09.0359 0624 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
13:41:09.0390 0624 RimVSerPort - ok
13:41:09.0578 0624 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
13:41:09.0609 0624 ROOTMODEM - ok
13:41:09.0859 0624 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
13:41:09.0890 0624 Secdrv - ok
13:41:10.0062 0624 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
13:41:10.0078 0624 serenum - ok
13:41:10.0250 0624 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
13:41:10.0296 0624 Serial - ok
13:41:10.0500 0624 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
13:41:10.0531 0624 Sfloppy - ok
13:41:10.0687 0624 Simbad - ok
13:41:10.0765 0624 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
13:41:10.0796 0624 sisagp - ok
13:41:10.0984 0624 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
13:41:11.0000 0624 SLIP - ok
13:41:11.0312 0624 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
13:41:11.0390 0624 smwdm - ok
13:41:11.0578 0624 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
13:41:11.0609 0624 SONYPVU1 - ok
13:41:11.0843 0624 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
13:41:11.0906 0624 Sparrow - ok
13:41:12.0125 0624 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
13:41:12.0140 0624 splitter - ok
13:41:12.0359 0624 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
13:41:12.0406 0624 sr - ok
13:41:12.0640 0624 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
13:41:12.0671 0624 Srv - ok
13:41:12.0843 0624 sscdbhk5 (7c0c9bdca2d351ff3b4f9b69f99aa995) C:\WINDOWS\system32\drivers\sscdbhk5.sys
13:41:12.0890 0624 sscdbhk5 - ok
13:41:12.0968 0624 ssrtln (31726706d54894d5059f7471111a87bb) C:\WINDOWS\system32\drivers\ssrtln.sys
13:41:13.0031 0624 ssrtln - ok
13:41:13.0250 0624 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
13:41:13.0281 0624 streamip - ok
13:41:13.0406 0624 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
13:41:13.0421 0624 swenum - ok
13:41:13.0546 0624 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
13:41:13.0609 0624 swmidi - ok
13:41:13.0796 0624 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
13:41:13.0828 0624 symc810 - ok
13:41:13.0984 0624 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
13:41:14.0062 0624 symc8xx - ok
13:41:14.0234 0624 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
13:41:14.0250 0624 sym_hi - ok
13:41:14.0421 0624 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
13:41:14.0437 0624 sym_u3 - ok
13:41:14.0921 0624 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
13:41:14.0968 0624 sysaudio - ok
13:41:15.0171 0624 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
13:41:15.0203 0624 Tcpip - ok
13:41:15.0406 0624 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
13:41:15.0437 0624 TDPIPE - ok
13:41:15.0562 0624 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
13:41:15.0578 0624 TDTCP - ok
13:41:15.0718 0624 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
13:41:15.0781 0624 TermDD - ok
13:41:15.0937 0624 tfsnboio (b0d311f33c5b4a5858e4e6c965a79267) C:\WINDOWS\system32\dla\tfsnboio.sys
13:41:15.0984 0624 tfsnboio - ok
13:41:16.0062 0624 tfsncofs (250f74fce5d1eccb29ad9abeb55f35d8) C:\WINDOWS\system32\dla\tfsncofs.sys
13:41:16.0109 0624 tfsncofs - ok
13:41:16.0218 0624 tfsndrct (e23291934c59e1741ba83582e7a209c0) C:\WINDOWS\system32\dla\tfsndrct.sys
13:41:16.0250 0624 tfsndrct - ok
13:41:16.0390 0624 tfsndres (0d863d020633025f1e4ad3e0e325d503) C:\WINDOWS\system32\dla\tfsndres.sys
13:41:16.0406 0624 tfsndres - ok
13:41:16.0562 0624 tfsnifs (e3e10696663e35062851a376299198bd) C:\WINDOWS\system32\dla\tfsnifs.sys
13:41:16.0609 0624 tfsnifs - ok
13:41:16.0750 0624 tfsnopio (00cc366bdcbd8a9a1c95c1c59900dd9b) C:\WINDOWS\system32\dla\tfsnopio.sys
13:41:16.0796 0624 tfsnopio - ok
13:41:16.0953 0624 tfsnpool (84a91d08f49831e8c24e4d25ddefae87) C:\WINDOWS\system32\dla\tfsnpool.sys
13:41:16.0968 0624 tfsnpool - ok
13:41:17.0109 0624 tfsnudf (55b761c6e2d4fcedac3b46b6c0724830) C:\WINDOWS\system32\dla\tfsnudf.sys
13:41:17.0156 0624 tfsnudf - ok
13:41:17.0234 0624 tfsnudfa (64c6e8c217e30ee595120c66f6e783ba) C:\WINDOWS\system32\dla\tfsnudfa.sys
13:41:17.0281 0624 tfsnudfa - ok
13:41:17.0468 0624 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys
13:41:17.0531 0624 TosIde - ok
13:41:17.0734 0624 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
13:41:17.0750 0624 Udfs - ok
13:41:17.0921 0624 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
13:41:17.0968 0624 ultra - ok
13:41:18.0125 0624 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
13:41:18.0218 0624 Update - ok
13:41:18.0421 0624 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
13:41:18.0453 0624 USBAAPL - ok
13:41:18.0625 0624 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
13:41:18.0671 0624 usbaudio - ok
13:41:18.0828 0624 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
13:41:18.0843 0624 usbccgp - ok
13:41:18.0984 0624 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
13:41:19.0000 0624 usbehci - ok
13:41:19.0140 0624 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
13:41:19.0187 0624 usbhub - ok
13:41:19.0406 0624 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
13:41:19.0437 0624 usbprint - ok
13:41:19.0609 0624 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
13:41:19.0640 0624 usbscan - ok
13:41:20.0000 0624 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
13:41:20.0093 0624 usbser - ok
13:41:20.0515 0624 UsbserFilt (e748d50b3b2ec7f40a2ba67fb094cf01) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
13:41:20.0546 0624 UsbserFilt - ok
13:41:20.0859 0624 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:41:20.0906 0624 USBSTOR - ok
13:41:21.0171 0624 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
13:41:21.0203 0624 usbuhci - ok
13:41:21.0625 0624 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
13:41:21.0671 0624 usbvideo - ok
13:41:21.0968 0624 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
13:41:22.0000 0624 VgaSave - ok
13:41:22.0171 0624 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
13:41:22.0250 0624 viaagp - ok
13:41:22.0359 0624 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
13:41:22.0421 0624 ViaIde - ok
13:41:22.0609 0624 vidcap - ok
13:41:22.0750 0624 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
13:41:22.0781 0624 VolSnap - ok
13:41:22.0937 0624 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:41:22.0968 0624 Wanarp - ok
13:41:23.0109 0624 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
13:41:23.0140 0624 wanatw - ok
13:41:23.0328 0624 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
13:41:23.0359 0624 wceusbsh - ok
13:41:23.0625 0624 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
13:41:23.0750 0624 Wdf01000 - ok
13:41:23.0875 0624 WDICA - ok
13:41:23.0953 0624 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
13:41:23.0968 0624 wdmaud - ok
13:41:24.0187 0624 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
13:41:24.0218 0624 WS2IFSL - ok
13:41:24.0390 0624 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
13:41:24.0421 0624 WSTCODEC - ok
13:41:24.0531 0624 MBR (0x1B8) (4bc21aabb8ea83c34000756722b7398b) \Device\Harddisk0\DR0
13:41:24.0562 0624 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
13:41:24.0562 0624 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
13:41:24.0609 0624 Boot (0x1200) (d4830dd8c2293ad9829ff7a40a28c5a7) \Device\Harddisk0\DR0\Partition0
13:41:24.0609 0624 \Device\Harddisk0\DR0\Partition0 - ok
13:41:24.0609 0624 ============================================================
13:41:24.0609 0624 Scan finished
13:41:24.0609 0624 ============================================================
13:41:24.0625 2984 Detected object count: 1
13:41:24.0625 2984 Actual detected object count: 1
13:41:36.0437 2984 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - skipped by user
13:41:36.0437 2984 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Skip
Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hello,

This took about 4 hours to run, and I made it all the way through. However, my PC is still slow. The task manager shows that svchost.exe is still using the most memory usage. Also, when my PC rebooted with the ComboFix, my ESET Smart Security showed a message about some svchost.exe being a trojan and that it cannot be cleaned. Not sure what to do. Please see ComboFix log below. Thanks again for your help.

ComboFix 11-12-23.01 - Harry 12/23/2011 18:58:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.131 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Harry\Application Data\RapidGet
c:\documents and settings\Harry\Application Data\RapidGet\settings.ini
c:\documents and settings\Harry\WINDOWS
c:\documents and settings\Paul\WINDOWS
C:\install.exe
c:\program files\Download Plugin
c:\program files\Download Plugin\DlPlugin-MSIE_1.0.2.2\axdlplug.inf
c:\windows\system32\11f42b0c.dll
c:\windows\system32\5f1e0e12.dll
c:\windows\system32\5fa44cd4.dll
c:\windows\system32\linkinfo(2).dll
c:\windows\system32\Nagasoft
c:\windows\system32\Nagasoft\Codecs\asyncflt.ax
c:\windows\system32\Nagasoft\Codecs\atrc.dll
c:\windows\system32\Nagasoft\Codecs\cook.dll
c:\windows\system32\Nagasoft\Codecs\drvc.dll
c:\windows\system32\Nagasoft\Codecs\raac.dll
c:\windows\system32\Nagasoft\Codecs\RealMediaSplitter.ax
c:\windows\system32\Nagasoft\Codecs\WMFDemux.dll
c:\windows\system32\Nagasoft\GifShower.dll
c:\windows\system32\Nagasoft\vjocx.dll
c:\windows\system32\oobe\isperror
c:\windows\system32\oobe\isperror\ISPCNERR.HTM
c:\windows\system32\oobe\isperror\ISPDTONE.HTM
c:\windows\system32\oobe\isperror\ISPHDSHK.HTM
c:\windows\system32\oobe\isperror\ISPINS.HTM
c:\windows\system32\oobe\isperror\ISPNOANW.HTM
c:\windows\system32\oobe\isperror\ISPPBERR.HTM
c:\windows\system32\oobe\isperror\ISPPHBSY.HTM
c:\windows\system32\oobe\isperror\ISPSBUSY.HTM
c:\windows\system32\SET35E.tmp
c:\windows\system32\SET36A.tmp
c:\windows\system32\SET373.tmp
c:\windows\system32\SET374.tmp
c:\windows\system32\SET375.tmp
c:\windows\system32\SET378.tmp
c:\windows\system32\setb0.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_vvdsvc
——-\Legacy_vvdsvc
——-\Service_vvdsvc
——-\Service_vvdsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-11-24 to 2011-12-24 )))))))))))))))))))))))))))))))
.
.
2011-12-24 00:13 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B0B22001-9CD9-415C-80AB-857BEF9787A2}\mpengine.dll
2011-12-23 04:19 . 2011-12-23 04:19 388096 —-a-r- c:\documents and settings\Harry\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-23 04:19 . 2011-12-23 04:19 ——– d—–w- c:\program files\Trend Micro
2011-12-20 00:29 . 2011-12-20 00:29 1266056 —-a-w- C:\WindowsXP-KB927891-v3-x86-ENU.exe
2011-12-20 00:27 . 2011-12-20 00:27 6216032 —-a-w- C:\windowsupdateagent30-x86.exe
2011-12-18 17:34 . 2011-12-18 17:34 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2011-12-15 03:09 . 2011-12-15 03:09 ——– d-s—w- c:\documents and settings\LocalService\UserData
2011-12-08 03:46 . 2011-12-08 03:46 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-08 03:46 . 2011-12-08 03:46 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-12-08 03:46 . 2011-12-08 03:46 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-12-08 03:46 . 2011-12-08 03:46 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-12-08 03:46 . 2011-12-08 03:46 478168 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-12-08 03:46 . 2011-12-08 03:46 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-12-08 03:46 . 2011-12-08 03:46 1989592 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-12-08 03:46 . 2011-12-08 03:46 801752 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2003-07-15 21:01 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2006-05-07 04:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-01 20:35 . 2004-08-24 01:32 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-08-04 07:56 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35 . 2002-08-29 10:00 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07 . 2004-03-06 02:16 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2004-08-04 05:59 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2002-08-29 10:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 1980-01-01 05:00 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 1980-01-01 05:00 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-08-29 10:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2004-03-02 18:18 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-27 06:12 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2002-08-29 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2002-08-29 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2007-12-16 01:46 . 2007-12-16 01:46 779312 —-a-w- c:\program files\MoveMediaPlayer_07074039.exe
2005-05-06 02:17 . 2005-05-06 02:17 2656568 —-a-w- c:\program files\ica32t.exe
2011-12-08 03:46 . 2011-12-08 03:46 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-04-29 04:57 4608 –sha-r- c:\windows\SYSTEM32\AnyDiscHelp.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2011-08-22 6276408]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-02-22 2140880]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PrintKey-Pro.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
backup=c:\windows\pss\PrintKey-Pro.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=c:\windows\pss\SpySubtract.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Paul^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Paul\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
? [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-10-15 03:38 623992 —-a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 07:04 39792 -c–a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2008-11-11 05:54 2356088 —-a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2010-06-15 14:25 4398016 -c–a-w- c:\program files\AnyDVD\AnyDVDtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2009-07-02 04:12 623960 —-a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 01:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 01:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-08-01 16:11 50520 —-a-w- c:\documents and settings\Harry\Application Data\mjusbsp\cdloader2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTransferAgent]
2007-11-13 21:46 135168 —-a-w- c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-03-15 06:04 122933 -c–a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-04-11 16:43 53248 ——w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116]
1998-11-30 23:04 497376 —-a-w- c:\windows\p_981116.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-10-22 02:00 133104 —-atw- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 19:39 1289000 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 15:36 114688 —-a-w- c:\windows\SYSTEM32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-09-20 15:35 94208 —-a-w- c:\windows\SYSTEM32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 01:12 221184 —-a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 14:14 206112 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 22:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
2001-07-11 18:08 53248 —-a-w- c:\progra~1\LEXMAR~1\AcBtnMgr_X73.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
2001-10-08 22:21 53248 —-a-w- c:\progra~1\LEXMAR~1\ACMonitor_X73.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-01-16 21:31 181544 —-a-w- c:\program files\Seagate\FreeAgent Status\stxmenumgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaFace Integration]
2003-04-11 19:24 53248 —-a-w- c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2011-08-22 06:18 6276408 —-a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-07 00:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-12 01:15 290816 ——w- c:\program files\Dell\Media Experience\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
2001-10-12 13:42 36864 -c–a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\printray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2008-05-09 03:12 214560 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2009-04-11 19:17 236016 —-a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-05-09 03:12 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2003-08-19 06:01 110592 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-11 04:15 111816 —-a-w- c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
2005-04-23 00:49 397312 —-a-w- c:\progra~1\Yahoo!\YOP\yop.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Harry\\Desktop\\EXTRA\\virtualdj.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\VirtualDJ\\virtualdj.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Harry\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Harry\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Harry\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\AIM7\\aim.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14394:TCP"= 14394:TCP:BitComet 14394 TCP
"14394:UDP"= 14394:UDP:BitComet 14394 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 ehdrv;ehdrv;c:\windows\SYSTEM32\DRIVERS\ehdrv.sys [2/22/2010 3:50 PM 114984]
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe [4/8/2005 8:09 PM 49152]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2/22/2010 3:50 PM 810120]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\Sync\FreeAgentService.exe [1/16/2009 3:31 PM 161064]
R2 npf;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [6/1/2008 1:13 AM 34064]
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\rt2500usb.sys [4/8/2005 8:09 PM 140416]
R3 pcouffin;VSO Software pcouffin;c:\windows\SYSTEM32\DRIVERS\pcouffin.sys [8/23/2008 10:27 AM 47360]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/21/2011 12:33 PM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/21/2011 12:33 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys –> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\SYSTEM32\DRIVERS\motccgpfl.sys [1/11/2008 10:18 PM 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys –> c:\windows\system32\DRIVERS\motport.sys [?]
S3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\Drivers\PROCEXP151.SYS –> c:\windows\system32\Drivers\PROCEXP151.SYS [?]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-21 18:33]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-21 18:33]
.
2011-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1433085515-1641961063-1852807976-1007Core.job
- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-22 02:00]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1433085515-1641961063-1852807976-1007UA.job
- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-22 02:00]
.
2004-10-10 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
.
2011-12-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM Search
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Harry\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: bankofamerica.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
TCP: DhcpNameServer = 192.168.1.254
DPF: {D9944C1C-C6BB-4E90-8E37-55F9FFABC6B8} - hxxps://server.userzoom.com/uz/UserZoom.cab
FF - ProfilePath - c:\documents and settings\Harry\Application Data\Mozilla\Firefox\Profiles\x0t12j16.ProfileName\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: signon.rememberSignons - false
FF - user.js: update_notifications.enabled - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-AbacastDistributedOnDemand:11 - c:\documents and settings\Harry\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe
MSConfigStartUp-Cleanup - c:\progra~1\mcafee.com\shared\mcappins.exe
MSConfigStartUp-ddoctorv2 - c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe
MSConfigStartUp-mmtask - c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
AddRemove-AOL Instant Messenger - c:\program files\AIM\uninstll.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-23 20:58
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\TEMP\HTT5D7.tmp 1098 bytes
c:\windows\TEMP\HTT5D8.tmp 1002 bytes
.
scan completed successfully
hidden files: 2
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD800BB-75FJA1 rev.14.03G14 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x82BE72C6
user & kernel MBR OK
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3432)
c:\windows\system32\dla\tfswshx.dll
c:\windows\system32\tfswapi.dll
c:\windows\system32\dla\tfswcres.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Windows Defender\MsMpEng.exe
c:\windows\system32\LEXBCES.EXE
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\windows\system32\DllHost.exe
c:\progra~1\MICROS~4\Office12\OUTLOOK.EXE
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2011-12-23 21:50:39 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-24 03:50
.
Pre-Run: 11,925,176,320 bytes free
Post-Run: 12,782,575,616 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 8EDF910E62C03ED9268EFD36E6C09201
Please read carefully and follow these steps.



Immediately after this I'd like you to run the following Combofix Script. The reason it may have taken so long before is that your ESET antivirus was still enabled and that can also possibly interefere with some of the cleaning. I'd like to go ahead and try running it again this way, and see if we see any any improvement .


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll:


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hello,

Merry Christmas! Both of the logs are below. The first is from TDSSKiller and the second one is from ComboFix. I disabled my ESET Smart Security by reviewing this thread (http://forums.whatthetech.com/index.php?showtopic=96260&hl=disable+eset), but it still does not completely stop according to ComboFix. However, i ran ComboFix all the way through in about 1.5 hours this time. Please let me know what you think.

TDSSkiller:

23:56:58.0718 1828 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
23:57:00.0250 1828 ============================================================
23:57:00.0250 1828 Current date / time: 2011/12/24 23:57:00.0250
23:57:00.0250 1828 SystemInfo:
23:57:00.0250 1828
23:57:00.0250 1828 OS Version: 5.1.2600 ServicePack: 3.0
23:57:00.0250 1828 Product type: Workstation
23:57:00.0250 1828 ComputerName: HMelzer
23:57:00.0265 1828 UserName: Harry
23:57:00.0265 1828 Windows directory: C:\WINDOWS
23:57:00.0265 1828 System windows directory: C:\WINDOWS
23:57:00.0265 1828 Processor architecture: Intel x86
23:57:00.0265 1828 Number of processors: 1
23:57:00.0265 1828 Page size: 0x1000
23:57:00.0265 1828 Boot type: Normal boot
23:57:00.0265 1828 ============================================================
23:57:14.0359 1828 Initialize success
23:57:16.0015 3720 ============================================================
23:57:16.0015 3720 Scan started
23:57:16.0015 3720 Mode: Manual;
23:57:16.0015 3720 ============================================================
23:57:31.0750 3720 Abiosdsk - ok
23:57:32.0500 3720 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
23:57:32.0734 3720 abp480n5 - ok
23:57:33.0828 3720 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:57:33.0921 3720 ACPI - ok
23:57:34.0703 3720 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:57:34.0843 3720 ACPIEC - ok
23:57:35.0734 3720 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
23:57:36.0187 3720 adpu160m - ok
23:57:37.0093 3720 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
23:57:37.0187 3720 aeaudio - ok
23:57:37.0750 3720 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
23:57:37.0984 3720 aec - ok
23:57:39.0406 3720 AegisP (4b66e250c94c92522c33a759d5d273cb) C:\WINDOWS\system32\DRIVERS\AegisP.sys
23:57:39.0781 3720 AegisP - ok
23:57:40.0531 3720 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
23:57:40.0625 3720 AFD - ok
23:57:41.0109 3720 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys
23:57:41.0281 3720 agp440 - ok
23:57:41.0968 3720 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
23:57:42.0031 3720 agpCPQ - ok
23:57:42.0453 3720 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
23:57:42.0562 3720 Aha154x - ok
23:57:43.0078 3720 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
23:57:43.0156 3720 aic78u2 - ok
23:57:43.0750 3720 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
23:57:43.0875 3720 aic78xx - ok
23:57:44.0328 3720 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
23:57:44.0484 3720 AliIde - ok
23:57:44.0656 3720 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
23:57:44.0703 3720 alim1541 - ok
23:57:44.0875 3720 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
23:57:44.0906 3720 amdagp - ok
23:57:45.0218 3720 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
23:57:45.0296 3720 amsint - ok
23:57:45.0625 3720 AnyDVD (82ce157ff3701ab50769b2654d0b0215) C:\WINDOWS\system32\Drivers\AnyDVD.sys
23:57:45.0812 3720 AnyDVD - ok
23:57:46.0109 3720 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
23:57:46.0234 3720 asc - ok
23:57:46.0546 3720 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
23:57:46.0562 3720 asc3350p - ok
23:57:46.0718 3720 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
23:57:46.0765 3720 asc3550 - ok
23:57:46.0984 3720 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:57:47.0109 3720 AsyncMac - ok
23:57:47.0281 3720 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:57:47.0281 3720 atapi - ok
23:57:47.0437 3720 Atdisk - ok
23:57:47.0593 3720 ati2mtag (8759322ffc1a50569c1e5528ee8026b7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
23:57:47.0796 3720 ati2mtag - ok
23:57:47.0968 3720 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:57:47.0984 3720 Atmarpc - ok
23:57:48.0093 3720 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:57:48.0140 3720 audstub - ok
23:57:48.0312 3720 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:57:48.0343 3720 Beep - ok
23:57:48.0500 3720 bkn50USB (6d39682a1051a5be7437ec99f1bf9921) C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
23:57:48.0609 3720 bkn50USB - ok
23:57:48.0750 3720 bvrp_pci - ok
23:57:48.0765 3720 catchme - ok
23:57:48.0890 3720 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
23:57:48.0937 3720 cbidf - ok
23:57:49.0109 3720 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:57:49.0109 3720 cbidf2k - ok
23:57:49.0250 3720 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
23:57:49.0281 3720 CCDECODE - ok
23:57:49.0421 3720 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
23:57:49.0468 3720 cd20xrnt - ok
23:57:49.0640 3720 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:57:49.0703 3720 Cdaudio - ok
23:57:49.0875 3720 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
23:57:49.0921 3720 Cdfs - ok
23:57:50.0062 3720 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:57:50.0125 3720 Cdrom - ok
23:57:50.0281 3720 Changer - ok
23:57:50.0468 3720 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys
23:57:50.0515 3720 CmdIde - ok
23:57:50.0718 3720 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
23:57:50.0750 3720 Cpqarray - ok
23:57:50.0953 3720 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
23:57:51.0046 3720 dac2w2k - ok
23:57:51.0328 3720 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
23:57:51.0375 3720 dac960nt - ok
23:57:51.0546 3720 DCamUSBSQTECH (41a2586f3d54efbc1aa8d29748e26634) C:\WINDOWS\system32\Drivers\SQcaptur.sys
23:57:51.0562 3720 DCamUSBSQTECH - ok
23:57:51.0781 3720 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
23:57:51.0859 3720 Disk - ok
23:57:52.0093 3720 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
23:57:52.0250 3720 dmboot - ok
23:57:52.0437 3720 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
23:57:52.0484 3720 dmio - ok
23:57:52.0671 3720 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:57:52.0734 3720 dmload - ok
23:57:52.0921 3720 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
23:57:52.0937 3720 DMusic - ok
23:57:53.0156 3720 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
23:57:53.0250 3720 dpti2o - ok
23:57:53.0421 3720 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
23:57:53.0484 3720 drmkaud - ok
23:57:53.0656 3720 drvmcdb (049177996e5e33b5faf40cad2b82098c) C:\WINDOWS\system32\drivers\drvmcdb.sys
23:57:53.0703 3720 drvmcdb - ok
23:57:54.0046 3720 drvnddm (2f4134d073f972575c174e3d621f0107) C:\WINDOWS\system32\drivers\drvnddm.sys
23:57:54.0562 3720 drvnddm - ok
23:57:54.0828 3720 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
23:57:54.0875 3720 DSproct - ok
23:57:55.0078 3720 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
23:57:55.0125 3720 dsunidrv - ok
23:57:55.0328 3720 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
23:57:55.0328 3720 E100B - ok
23:57:55.0515 3720 eamon (55e754e04c09daf19fc0054e72713d80) C:\WINDOWS\system32\DRIVERS\eamon.sys
23:57:55.0546 3720 eamon - ok
23:57:55.0781 3720 ehdrv (6f2441c26d74bde88c25e240a2720eeb) C:\WINDOWS\system32\DRIVERS\ehdrv.sys
23:57:55.0859 3720 ehdrv - ok
23:57:56.0468 3720 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
23:57:56.0515 3720 EL90XBC - ok
23:57:57.0062 3720 ElbyCDIO (309ac30471a0f1c3a89dee1c81230576) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
23:57:57.0140 3720 ElbyCDIO - ok
23:57:57.0328 3720 EntDrv51 - ok
23:57:57.0500 3720 epfw (93aa9cef77315a0866f8307195de416d) C:\WINDOWS\system32\DRIVERS\epfw.sys
23:57:57.0562 3720 epfw - ok
23:57:57.0781 3720 Epfwndis (7946b41daeb3e610742ff01a6d2d61b2) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys
23:57:57.0843 3720 Epfwndis - ok
23:57:58.0046 3720 epfwtdi (f38059a07393a8c56bae8ff7ee0c3128) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys
23:57:58.0125 3720 epfwtdi - ok
23:57:58.0343 3720 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
23:57:58.0390 3720 Fastfat - ok
23:57:58.0578 3720 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:57:58.0593 3720 Fdc - ok
23:57:58.0656 3720 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
23:57:58.0703 3720 Fips - ok
23:57:58.0906 3720 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:57:58.0968 3720 Flpydisk - ok
23:57:59.0156 3720 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
23:57:59.0203 3720 FltMgr - ok
23:57:59.0390 3720 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:57:59.0437 3720 Fs_Rec - ok
23:57:59.0640 3720 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:57:59.0656 3720 Ftdisk - ok
23:57:59.0843 3720 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
23:57:59.0968 3720 GEARAspiWDM - ok
23:58:00.0140 3720 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:58:00.0171 3720 Gpc - ok
23:58:00.0343 3720 GTNDIS5 (fc80052194d5708254a346568f0e77c0) C:\WINDOWS\system32\GTNDIS5.SYS
23:58:00.0343 3720 GTNDIS5 - ok
23:58:00.0500 3720 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:58:00.0515 3720 HidUsb - ok
23:58:00.0656 3720 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
23:58:00.0703 3720 hpn - ok
23:58:00.0859 3720 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
23:58:00.0875 3720 HTTP - ok
23:58:01.0046 3720 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
23:58:01.0093 3720 i2omgmt - ok
23:58:01.0281 3720 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
23:58:01.0328 3720 i2omp - ok
23:58:01.0515 3720 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:58:01.0578 3720 i8042prt - ok
23:58:01.0765 3720 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
23:58:01.0812 3720 i81x - ok
23:58:02.0000 3720 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
23:58:02.0062 3720 iAimFP0 - ok
23:58:02.0250 3720 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
23:58:02.0312 3720 iAimFP1 - ok
23:58:02.0484 3720 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
23:58:02.0515 3720 iAimFP2 - ok
23:58:02.0687 3720 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
23:58:02.0703 3720 iAimFP3 - ok
23:58:02.0906 3720 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
23:58:03.0000 3720 iAimFP4 - ok
23:58:03.0203 3720 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
23:58:03.0265 3720 iAimTV0 - ok
23:58:03.0453 3720 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
23:58:03.0468 3720 iAimTV1 - ok
23:58:03.0593 3720 iAimTV2 - ok
23:58:03.0734 3720 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
23:58:03.0796 3720 iAimTV3 - ok
23:58:03.0984 3720 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
23:58:04.0000 3720 iAimTV4 - ok
23:58:04.0203 3720 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23:58:04.0343 3720 ialm - ok
23:58:04.0546 3720 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:58:04.0609 3720 Imapi - ok
23:58:04.0812 3720 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
23:58:04.0859 3720 ini910u - ok
23:58:05.0062 3720 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
23:58:05.0218 3720 IntelC51 - ok
23:58:05.0437 3720 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
23:58:05.0515 3720 IntelC52 - ok
23:58:05.0718 3720 IntelC53 (de2686c0e012e6ae24acd6e79eb7ff5d) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
23:58:05.0781 3720 IntelC53 - ok
23:58:05.0953 3720 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
23:58:06.0000 3720 IntelIde - ok
23:58:06.0187 3720 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:58:06.0234 3720 intelppm - ok
23:58:06.0453 3720 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
23:58:06.0515 3720 ip6fw - ok
23:58:06.0687 3720 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:58:06.0718 3720 IpFilterDriver - ok
23:58:06.0890 3720 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:58:06.0937 3720 IpInIp - ok
23:58:07.0171 3720 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:58:07.0171 3720 IpNat - ok
23:58:07.0281 3720 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:58:07.0312 3720 IPSec - ok
23:58:07.0484 3720 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:58:07.0531 3720 IRENUM - ok
23:58:07.0656 3720 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:58:07.0687 3720 isapnp - ok
23:58:07.0906 3720 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:58:07.0921 3720 Kbdclass - ok
23:58:07.0984 3720 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
23:58:08.0000 3720 kmixer - ok
23:58:08.0234 3720 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
23:58:08.0296 3720 KSecDD - ok
23:58:08.0437 3720 lbrtfdc - ok
23:58:08.0546 3720 LXARScan (e8d15acd2f65a2e8756768353e08a9a0) C:\WINDOWS\system32\Drivers\Lxarscan.sys
23:58:08.0593 3720 LXARScan - ok
23:58:08.0734 3720 MBAMSwissArmy - ok
23:58:08.0890 3720 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:58:08.0953 3720 mnmdd - ok
23:58:09.0078 3720 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
23:58:09.0078 3720 Modem - ok
23:58:09.0281 3720 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
23:58:09.0296 3720 MODEMCSA - ok
23:58:09.0406 3720 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
23:58:09.0406 3720 mohfilt - ok
23:58:09.0500 3720 motccgp - ok
23:58:09.0687 3720 motccgpfl (aad6191a4daa519f04ab12b2af73e356) C:\WINDOWS\system32\DRIVERS\motccgpfl.sys
23:58:09.0687 3720 motccgpfl - ok
23:58:09.0796 3720 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\WINDOWS\system32\DRIVERS\motmodem.sys
23:58:09.0843 3720 motmodem - ok
23:58:09.0984 3720 motport - ok
23:58:10.0203 3720 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:58:10.0343 3720 Mouclass - ok
23:58:10.0671 3720 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:58:10.0718 3720 mouhid - ok
23:58:11.0265 3720 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
23:58:11.0484 3720 MountMgr - ok
23:58:11.0968 3720 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
23:58:12.0140 3720 mraid35x - ok
23:58:12.0687 3720 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:58:12.0734 3720 MRxDAV - ok
23:58:13.0250 3720 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:58:13.0625 3720 MRxSmb - ok
23:58:13.0953 3720 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
23:58:13.0984 3720 Msfs - ok
23:58:14.0593 3720 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:58:14.0625 3720 MSKSSRV - ok
23:58:14.0968 3720 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:58:15.0078 3720 MSPCLOCK - ok
23:58:15.0546 3720 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
23:58:15.0562 3720 MSPQM - ok
23:58:15.0875 3720 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:58:15.0875 3720 mssmbios - ok
23:58:16.0328 3720 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
23:58:16.0375 3720 MSTEE - ok
23:58:16.0734 3720 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
23:58:16.0765 3720 Mup - ok
23:58:17.0140 3720 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
23:58:17.0343 3720 NABTSFEC - ok
23:58:17.0750 3720 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
23:58:17.0890 3720 NDIS - ok
23:58:18.0281 3720 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
23:58:18.0296 3720 NdisIP - ok
23:58:18.0671 3720 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:58:18.0687 3720 NdisTapi - ok
23:58:19.0031 3720 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:58:19.0046 3720 Ndisuio - ok
23:58:19.0468 3720 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:58:19.0515 3720 NdisWan - ok
23:58:19.0906 3720 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
23:58:19.0953 3720 NDProxy - ok
23:58:20.0296 3720 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:58:20.0328 3720 NetBIOS - ok
23:58:20.0703 3720 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:58:20.0890 3720 NetBT - ok
23:58:21.0281 3720 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
23:58:21.0343 3720 nm - ok
23:58:21.0890 3720 nmwcd (c82f4cc10ad315b6d6bcb14d0a7cad66) C:\WINDOWS\system32\drivers\ccdcmb.sys
23:58:21.0953 3720 nmwcd - ok
23:58:22.0359 3720 nmwcdc (60ef5f5621d7832f00a3f190a0c905e2) C:\WINDOWS\system32\drivers\ccdcmbo.sys
23:58:22.0359 3720 nmwcdc - ok
23:58:22.0640 3720 npf (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys
23:58:22.0671 3720 npf - ok
23:58:23.0046 3720 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
23:58:23.0187 3720 Npfs - ok
23:58:23.0687 3720 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
23:58:24.0015 3720 Ntfs - ok
23:58:24.0343 3720 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:58:24.0406 3720 Null - ok
23:58:25.0578 3720 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
23:58:27.0375 3720 nv - ok
23:58:27.0953 3720 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:58:28.0015 3720 NwlnkFlt - ok
23:58:28.0625 3720 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:58:28.0796 3720 NwlnkFwd - ok
23:58:29.0375 3720 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
23:58:29.0468 3720 omci - ok
23:58:30.0062 3720 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
23:58:30.0093 3720 P3 - ok
23:58:30.0750 3720 PalmUSBD (7238442742146a64fac40fa0f9afd491) C:\WINDOWS\system32\drivers\PalmUSBD.sys
23:58:30.0875 3720 PalmUSBD - ok
23:58:31.0812 3720 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
23:58:31.0906 3720 Parport - ok
23:58:32.0968 3720 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
23:58:33.0109 3720 PartMgr - ok
23:58:33.0843 3720 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
23:58:33.0921 3720 ParVdm - ok
23:58:34.0859 3720 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
23:58:34.0906 3720 PCI - ok
23:58:35.0203 3720 PCIDump - ok
23:58:35.0593 3720 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
23:58:35.0781 3720 PCIIde - ok
23:58:36.0296 3720 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:58:36.0421 3720 Pcmcia - ok
23:58:36.0984 3720 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
23:58:37.0046 3720 pcouffin - ok
23:58:37.0453 3720 PDCOMP - ok
23:58:38.0046 3720 PDFRAME - ok
23:58:38.0328 3720 PDRELI - ok
23:58:38.0437 3720 PDRFRAME - ok
23:58:38.0656 3720 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
23:58:38.0703 3720 perc2 - ok
23:58:39.0078 3720 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
23:58:39.0109 3720 perc2hib - ok
23:58:39.0343 3720 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:58:39.0468 3720 PptpMiniport - ok
23:58:39.0765 3720 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
23:58:39.0937 3720 Processor - ok
23:58:40.0468 3720 PROCEXP151 - ok
23:58:41.0109 3720 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
23:58:41.0312 3720 PSched - ok
23:58:42.0437 3720 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:58:42.0750 3720 Ptilink - ok
23:58:43.0953 3720 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
23:58:44.0125 3720 PxHelp20 - ok
23:58:44.0765 3720 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys
23:58:44.0921 3720 QCDonner - ok
23:58:45.0625 3720 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
23:58:45.0750 3720 ql1080 - ok
23:58:46.0656 3720 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
23:58:47.0015 3720 Ql10wnt - ok
23:58:47.0906 3720 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
23:58:48.0000 3720 ql12160 - ok
23:58:48.0687 3720 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
23:58:48.0828 3720 ql1240 - ok
23:58:49.0671 3720 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
23:58:49.0765 3720 ql1280 - ok
23:58:50.0609 3720 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:58:50.0781 3720 RasAcd - ok
23:58:51.0750 3720 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:58:51.0843 3720 Rasl2tp - ok
23:58:53.0078 3720 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:58:53.0234 3720 RasPppoe - ok
23:58:54.0500 3720 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:58:54.0578 3720 Raspti - ok
23:58:55.0156 3720 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:58:55.0562 3720 Rdbss - ok
23:58:56.0515 3720 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:58:56.0640 3720 RDPCDD - ok
23:58:57.0609 3720 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
23:58:57.0953 3720 rdpdr - ok
23:58:59.0187 3720 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
23:58:59.0734 3720 RDPWD - ok
23:59:01.0062 3720 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:59:01.0203 3720 redbook - ok
23:59:02.0281 3720 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
23:59:02.0484 3720 RimUsb - ok
23:59:03.0546 3720 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
23:59:03.0609 3720 RimVSerPort - ok
23:59:04.0625 3720 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
23:59:04.0765 3720 ROOTMODEM - ok
23:59:06.0015 3720 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:59:06.0375 3720 Secdrv - ok
23:59:07.0312 3720 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:59:07.0531 3720 serenum - ok
23:59:08.0609 3720 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
23:59:08.0750 3720 Serial - ok
23:59:09.0703 3720 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:59:09.0875 3720 Sfloppy - ok
23:59:10.0953 3720 Simbad - ok
23:59:12.0531 3720 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
23:59:12.0765 3720 sisagp - ok
23:59:13.0828 3720 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
23:59:13.0875 3720 SLIP - ok
23:59:15.0562 3720 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
23:59:16.0781 3720 smwdm - ok
23:59:18.0046 3720 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
23:59:18.0140 3720 SONYPVU1 - ok
23:59:19.0609 3720 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
23:59:19.0953 3720 Sparrow - ok
23:59:21.0437 3720 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
23:59:21.0703 3720 splitter - ok
23:59:23.0187 3720 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
23:59:23.0640 3720 sr - ok
23:59:25.0109 3720 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
23:59:25.0734 3720 Srv - ok
23:59:26.0734 3720 sscdbhk5 (7c0c9bdca2d351ff3b4f9b69f99aa995) C:\WINDOWS\system32\drivers\sscdbhk5.sys
23:59:26.0921 3720 sscdbhk5 - ok
23:59:27.0640 3720 ssrtln (31726706d54894d5059f7471111a87bb) C:\WINDOWS\system32\drivers\ssrtln.sys
23:59:27.0906 3720 ssrtln - ok
23:59:29.0625 3720 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
23:59:29.0890 3720 streamip - ok
23:59:32.0203 3720 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:59:32.0281 3720 swenum - ok
23:59:33.0593 3720 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
23:59:34.0203 3720 swmidi - ok
23:59:35.0593 3720 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
23:59:35.0718 3720 symc810 - ok
23:59:36.0937 3720 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
23:59:37.0500 3720 symc8xx - ok
23:59:38.0843 3720 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
23:59:39.0046 3720 sym_hi - ok
23:59:40.0203 3720 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
23:59:40.0359 3720 sym_u3 - ok
23:59:41.0156 3720 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
23:59:41.0359 3720 sysaudio - ok
23:59:42.0359 3720 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:59:42.0937 3720 Tcpip - ok
23:59:43.0765 3720 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:59:43.0843 3720 TDPIPE - ok
23:59:44.0796 3720 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
23:59:45.0015 3720 TDTCP - ok
23:59:47.0234 3720 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:59:47.0609 3720 TermDD - ok
23:59:48.0593 3720 tfsnboio (b0d311f33c5b4a5858e4e6c965a79267) C:\WINDOWS\system32\dla\tfsnboio.sys
23:59:48.0796 3720 tfsnboio - ok
23:59:49.0421 3720 tfsncofs (250f74fce5d1eccb29ad9abeb55f35d8) C:\WINDOWS\system32\dla\tfsncofs.sys
23:59:49.0531 3720 tfsncofs - ok
23:59:50.0312 3720 tfsndrct (e23291934c59e1741ba83582e7a209c0) C:\WINDOWS\system32\dla\tfsndrct.sys
23:59:50.0468 3720 tfsndrct - ok
23:59:51.0046 3720 tfsndres (0d863d020633025f1e4ad3e0e325d503) C:\WINDOWS\system32\dla\tfsndres.sys
23:59:51.0109 3720 tfsndres - ok
23:59:52.0000 3720 tfsnifs (e3e10696663e35062851a376299198bd) C:\WINDOWS\system32\dla\tfsnifs.sys
23:59:52.0218 3720 tfsnifs - ok
23:59:53.0062 3720 tfsnopio (00cc366bdcbd8a9a1c95c1c59900dd9b) C:\WINDOWS\system32\dla\tfsnopio.sys
23:59:53.0125 3720 tfsnopio - ok
23:59:53.0593 3720 tfsnpool (84a91d08f49831e8c24e4d25ddefae87) C:\WINDOWS\system32\dla\tfsnpool.sys
23:59:53.0625 3720 tfsnpool - ok
23:59:54.0218 3720 tfsnudf (55b761c6e2d4fcedac3b46b6c0724830) C:\WINDOWS\system32\dla\tfsnudf.sys
23:59:54.0437 3720 tfsnudf - ok
23:59:55.0546 3720 tfsnudfa (64c6e8c217e30ee595120c66f6e783ba) C:\WINDOWS\system32\dla\tfsnudfa.sys
23:59:55.0859 3720 tfsnudfa - ok
23:59:56.0671 3720 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys
23:59:56.0781 3720 TosIde - ok
23:59:58.0187 3720 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
23:59:58.0500 3720 Udfs - ok
23:59:59.0843 3720 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
00:00:00.0078 3720 ultra - ok
00:00:01.0625 3720 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
00:00:02.0562 3720 Update - ok
00:00:04.0343 3720 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
00:00:04.0609 3720 USBAAPL - ok
00:00:05.0703 3720 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
00:00:06.0218 3720 usbaudio - ok
00:00:08.0328 3720 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
00:00:08.0703 3720 usbccgp - ok
00:00:10.0281 3720 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
00:00:10.0546 3720 usbehci - ok
00:00:12.0609 3720 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
00:00:12.0906 3720 usbhub - ok
00:00:14.0906 3720 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
00:00:15.0343 3720 usbprint - ok
00:00:16.0750 3720 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
00:00:17.0015 3720 usbscan - ok
00:00:18.0687 3720 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys
00:00:18.0843 3720 usbser - ok
00:00:20.0578 3720 UsbserFilt (e748d50b3b2ec7f40a2ba67fb094cf01) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
00:00:20.0656 3720 UsbserFilt - ok
00:00:22.0390 3720 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
00:00:22.0609 3720 USBSTOR - ok
00:00:24.0250 3720 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
00:00:24.0453 3720 usbuhci - ok
00:00:25.0437 3720 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
00:00:25.0625 3720 usbvideo - ok
00:00:26.0343 3720 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
00:00:26.0421 3720 VgaSave - ok
00:00:27.0468 3720 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
00:00:27.0765 3720 viaagp - ok
00:00:28.0890 3720 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
00:00:29.0093 3720 ViaIde - ok
00:00:30.0109 3720 vidcap - ok
00:00:31.0703 3720 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
00:00:32.0093 3720 VolSnap - ok
00:00:33.0765 3720 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
00:00:33.0937 3720 Wanarp - ok
00:00:35.0734 3720 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
00:00:36.0093 3720 wanatw - ok
00:00:37.0796 3720 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
00:00:37.0875 3720 wceusbsh - ok
00:00:39.0390 3720 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
00:00:40.0328 3720 Wdf01000 - ok
00:00:41.0296 3720 WDICA - ok
00:00:42.0468 3720 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
00:00:42.0640 3720 wdmaud - ok
00:00:43.0828 3720 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
00:00:44.0062 3720 WS2IFSL - ok
00:00:44.0890 3720 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
00:00:44.0937 3720 WSTCODEC - ok
00:00:45.0281 3720 MBR (0x1B8) (4bc21aabb8ea83c34000756722b7398b) \Device\Harddisk0\DR0
00:00:45.0437 3720 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
00:00:45.0437 3720 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
00:00:45.0562 3720 Boot (0x1200) (d4830dd8c2293ad9829ff7a40a28c5a7) \Device\Harddisk0\DR0\Partition0
00:00:45.0593 3720 \Device\Harddisk0\DR0\Partition0 - ok
00:00:45.0593 3720 ============================================================
00:00:45.0593 3720 Scan finished
00:00:45.0593 3720 ============================================================
00:00:45.0718 0708 Detected object count: 1
00:00:45.0718 0708 Actual detected object count: 1
00:04:21.0921 0708 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
00:04:21.0953 0708 \Device\Harddisk0\DR0 - ok
00:04:21.0953 0708 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
00:04:41.0687 2624 Deinitialize success


ComboFix:

ComboFix 11-12-24.10 - Harry 12/25/2011 0:33.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.310 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Harry\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\MoveMediaPlayer_07074039.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-25 to 2011-12-25 )))))))))))))))))))))))))))))))
.
.
2011-12-25 07:17 . 2011-12-25 07:17 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B0B22001-9CD9-415C-80AB-857BEF9787A2}\offreg.dll
2011-12-24 00:13 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B0B22001-9CD9-415C-80AB-857BEF9787A2}\mpengine.dll
2011-12-23 04:19 . 2011-12-23 04:19 388096 —-a-r- c:\documents and settings\Harry\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-23 04:19 . 2011-12-23 04:19 ——– d—–w- c:\program files\Trend Micro
2011-12-20 00:29 . 2011-12-20 00:29 1266056 —-a-w- C:\WindowsXP-KB927891-v3-x86-ENU.exe
2011-12-20 00:27 . 2011-12-20 00:27 6216032 —-a-w- C:\windowsupdateagent30-x86.exe
2011-12-18 17:34 . 2011-12-18 17:34 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2011-12-15 03:09 . 2011-12-15 03:09 ——– d-s—w- c:\documents and settings\LocalService\UserData
2011-12-08 03:46 . 2011-12-08 03:46 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-08 03:46 . 2011-12-08 03:46 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-12-08 03:46 . 2011-12-08 03:46 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-12-08 03:46 . 2011-12-08 03:46 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-12-08 03:46 . 2011-12-08 03:46 478168 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-12-08 03:46 . 2011-12-08 03:46 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-12-08 03:46 . 2011-12-08 03:46 1989592 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-12-08 03:46 . 2011-12-08 03:46 801752 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2003-07-15 21:01 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2006-05-07 04:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-01 20:35 . 2004-08-24 01:32 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-08-04 07:56 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:35 . 2002-08-29 10:00 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07 . 2004-03-06 02:16 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2004-08-04 05:59 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2002-08-29 10:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:33 . 1980-01-01 05:00 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 1980-01-01 05:00 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2002-08-29 10:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2004-03-02 18:18 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-27 06:12 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2002-08-29 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2002-08-29 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2005-05-06 02:17 . 2005-05-06 02:17 2656568 —-a-w- c:\program files\ica32t.exe
2011-12-08 03:46 . 2011-12-08 03:46 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-04-29 04:57 4608 –sha-r- c:\windows\SYSTEM32\AnyDiscHelp.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-24_03.05.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-25 07:17 . 2011-12-25 07:17 16384 c:\windows\temp\Perflib_Perfdata_740.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2011-08-22 6276408]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-02-22 2140880]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PrintKey-Pro.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
backup=c:\windows\pss\PrintKey-Pro.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=c:\windows\pss\SpySubtract.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Harry^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Harry\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Paul^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Paul\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
? [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-10-15 03:38 623992 —-a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 07:04 39792 -c–a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2008-11-11 05:54 2356088 —-a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2010-06-15 14:25 4398016 -c–a-w- c:\program files\AnyDVD\AnyDVDtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2009-07-02 04:12 623960 —-a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 01:06 1848648 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 01:31 722256 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-08-01 16:11 50520 —-a-w- c:\documents and settings\Harry\Application Data\mjusbsp\cdloader2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTransferAgent]
2007-11-13 21:46 135168 —-a-w- c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-03-15 06:04 122933 -c–a-w- c:\windows\SYSTEM32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-04-11 16:43 53248 ——w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116]
1998-11-30 23:04 497376 —-a-w- c:\windows\p_981116.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-10-22 02:00 133104 —-atw- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 19:39 1289000 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 15:36 114688 —-a-w- c:\windows\SYSTEM32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-09-20 15:35 94208 —-a-w- c:\windows\SYSTEM32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 01:12 221184 —-a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 14:14 206112 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 22:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Manager]
2001-07-11 18:08 53248 —-a-w- c:\progra~1\LEXMAR~1\AcBtnMgr_X73.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X73 Button Monitor]
2001-10-08 22:21 53248 —-a-w- c:\progra~1\LEXMAR~1\ACMonitor_X73.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-01-16 21:31 181544 —-a-w- c:\program files\Seagate\FreeAgent Status\stxmenumgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaFace Integration]
2003-04-11 19:24 53248 —-a-w- c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2011-08-22 06:18 6276408 —-a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-07 00:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-12 01:15 290816 ——w- c:\program files\Dell\Media Experience\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
2001-10-12 13:42 36864 -c–a-w- c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\printray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2008-05-09 03:12 214560 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2009-04-11 19:17 236016 —-a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 -c–a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-05-09 03:12 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2003-08-19 06:01 110592 —-a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-11 04:15 111816 —-a-w- c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
2005-04-23 00:49 397312 —-a-w- c:\progra~1\Yahoo!\YOP\yop.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Harry\\Desktop\\EXTRA\\virtualdj.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\VirtualDJ\\virtualdj.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Harry\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Harry\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Harry\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\AIM7\\aim.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14394:TCP"= 14394:TCP:BitComet 14394 TCP
"14394:UDP"= 14394:UDP:BitComet 14394 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 ehdrv;ehdrv;c:\windows\SYSTEM32\DRIVERS\ehdrv.sys [2/22/2010 3:50 PM 114984]
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe [4/8/2005 8:09 PM 49152]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2/22/2010 3:50 PM 810120]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\Sync\FreeAgentService.exe [1/16/2009 3:31 PM 161064]
R2 npf;NetGroup Packet Filter Driver;c:\windows\SYSTEM32\DRIVERS\npf.sys [6/1/2008 1:13 AM 34064]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/17/2009 10:58 PM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\rt2500usb.sys [4/8/2005 8:09 PM 140416]
R3 pcouffin;VSO Software pcouffin;c:\windows\SYSTEM32\DRIVERS\pcouffin.sys [8/23/2008 10:27 AM 47360]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/21/2011 12:33 PM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8/21/2011 12:33 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys –> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\SYSTEM32\DRIVERS\motccgpfl.sys [1/11/2008 10:18 PM 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys –> c:\windows\system32\DRIVERS\motport.sys [?]
S3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\Drivers\PROCEXP151.SYS –> c:\windows\system32\Drivers\PROCEXP151.SYS [?]
S3 vidcap;vidcap;c:\windows\system32\DRIVERS\vidcap.sys –> c:\windows\system32\DRIVERS\vidcap.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - GTNDIS5
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-12-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-21 18:33]
.
2011-12-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-21 18:33]
.
2011-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1433085515-1641961063-1852807976-1007Core.job
- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-22 02:00]
.
2011-12-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1433085515-1641961063-1852807976-1007UA.job
- c:\documents and settings\Harry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-22 02:00]
.
2004-10-10 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
.
2011-12-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &AIM Search
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Harry\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: bankofamerica.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
TCP: DhcpNameServer = 192.168.1.254
DPF: {D9944C1C-C6BB-4E90-8E37-55F9FFABC6B8} - hxxps://server.userzoom.com/uz/UserZoom.cab
FF - ProfilePath - c:\documents and settings\Harry\Application Data\Mozilla\Firefox\Profiles\x0t12j16.ProfileName\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
FF - user.js: signon.rememberSignons - false
FF - user.js: update_notifications.enabled - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-25 01:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3900)
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Microsoft Silverlight\xapauthenticodesip.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2011-12-25 01:46:56 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-25 07:46
ComboFix2.txt 2011-12-24 03:50
.
Pre-Run: 12,660,514,816 bytes free
Post-Run: 12,816,973,824 bytes free
.
- - End Of File - - 02C08151D1861B79CE2CCFDAE13E7CE1
If you have not done so since running the last set of tools, please reboot the computer. If you have already done so then you don't need to so so again.

I know this seems repetitive, but I need to make sure what we were trying to remove has been taken care of so we can forge ahead.. Also, can you please tell me how the machine is running at this point?


Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.





Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Hello! Thanks for the prompt reply. My computer seems to be running a little faster than before, which is a good sign. Svchost.exe still appears in my task manager, but it is not taking up that much memory as before, which is good. Below is the TDSSKiller log. There were no infected files found. Please let me know the next steps. Thanks for your help!! 10:14:41.0531 3704 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 10:14:42.0140 3704 ============================================================ 10:14:42.0140 3704 Current date / time: 2011/12/25 10:14:42.0140 10:14:42.0140 3704 SystemInfo: 10:14:42.0140 3704 10:14:42.0140 3704 OS Version: 5.1.2600 ServicePack: 3.0 10:14:42.0140 3704 Product type: Workstation 10:14:42.0140 3704 ComputerName: HMelzer 10:14:42.0156 3704 UserName: Harry 10:14:42.0156 3704 Windows directory: C:\WINDOWS 10:14:42.0156 3704 System windows directory: C:\WINDOWS 10:14:42.0156 3704 Processor architecture: Intel x86 10:14:42.0156 3704 Number of processors: 1 10:14:42.0156 3704 Page size: 0x1000 10:14:42.0156 3704 Boot type: Normal boot 10:14:42.0156 3704 ============================================================ 10:14:48.0718 3704 Initialize success 10:14:57.0140 2412 ============================================================ 10:14:57.0140 2412 Scan started 10:14:57.0140 2412 Mode: Manual; 10:14:57.0140 2412 ============================================================ 10:14:59.0312 2412 Abiosdsk - ok 10:14:59.0625 2412 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS 10:14:59.0640 2412 abp480n5 - ok 10:14:59.0765 2412 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 10:14:59.0765 2412 ACPI - ok 10:14:59.0953 2412 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 10:14:59.0968 2412 ACPIEC - ok 10:15:00.0296 2412 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys 10:15:00.0328 2412 adpu160m - ok 10:15:00.0671 2412 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys 10:15:00.0687 2412 aeaudio - ok 10:15:00.0906 2412 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 10:15:00.0921 2412 aec - ok 10:15:01.0109 2412 AegisP (4b66e250c94c92522c33a759d5d273cb) C:\WINDOWS\system32\DRIVERS\AegisP.sys 10:15:01.0140 2412 AegisP - ok 10:15:01.0359 2412 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 10:15:01.0375 2412 AFD - ok 10:15:01.0546 2412 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys 10:15:01.0562 2412 agp440 - ok 10:15:02.0140 2412 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys 10:15:02.0187 2412 agpCPQ - ok 10:15:02.0531 2412 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys 10:15:02.0562 2412 Aha154x - ok 10:15:02.0765 2412 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys 10:15:02.0781 2412 aic78u2 - ok 10:15:02.0875 2412 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys 10:15:02.0921 2412 aic78xx - ok 10:15:03.0156 2412 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys 10:15:03.0187 2412 AliIde - ok 10:15:03.0343 2412 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys 10:15:03.0375 2412 alim1541 - ok 10:15:03.0468 2412 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys 10:15:03.0500 2412 amdagp - ok 10:15:03.0640 2412 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys 10:15:03.0656 2412 amsint - ok 10:15:03.0843 2412 AnyDVD (82ce157ff3701ab50769b2654d0b0215) C:\WINDOWS\system32\Drivers\AnyDVD.sys 10:15:03.0843 2412 AnyDVD - ok 10:15:04.0078 2412 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys 10:15:04.0140 2412 asc - ok 10:15:04.0328 2412 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys 10:15:04.0359 2412 asc3350p - ok 10:15:04.0859 2412 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys 10:15:04.0953 2412 asc3550 - ok 10:15:05.0578 2412 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 10:15:05.0703 2412 AsyncMac - ok 10:15:06.0375 2412 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 10:15:06.0375 2412 atapi - ok 10:15:06.0750 2412 Atdisk - ok 10:15:07.0343 2412 ati2mtag (8759322ffc1a50569c1e5528ee8026b7) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 10:15:07.0468 2412 ati2mtag - ok 10:15:07.0671 2412 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 10:15:07.0718 2412 Atmarpc - ok 10:15:07.0921 2412 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 10:15:07.0953 2412 audstub - ok 10:15:08.0203 2412 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 10:15:08.0234 2412 Beep - ok 10:15:08.0390 2412 bkn50USB (6d39682a1051a5be7437ec99f1bf9921) C:\WINDOWS\system32\DRIVERS\rt2500usb.sys 10:15:08.0484 2412 bkn50USB - ok 10:15:08.0625 2412 bvrp_pci - ok 10:15:08.0640 2412 catchme - ok 10:15:08.0781 2412 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys 10:15:08.0828 2412 cbidf - ok 10:15:09.0000 2412 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 10:15:09.0000 2412 cbidf2k - ok 10:15:09.0281 2412 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 10:15:09.0343 2412 CCDECODE - ok 10:15:09.0812 2412 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys 10:15:09.0859 2412 cd20xrnt - ok 10:15:10.0375 2412 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 10:15:10.0421 2412 Cdaudio - ok 10:15:10.0671 2412 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 10:15:10.0687 2412 Cdfs - ok 10:15:10.0875 2412 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 10:15:10.0906 2412 Cdrom - ok 10:15:11.0031 2412 Changer - ok 10:15:11.0203 2412 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys 10:15:11.0234 2412 CmdIde - ok 10:15:11.0359 2412 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys 10:15:11.0437 2412 Cpqarray - ok 10:15:11.0625 2412 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys 10:15:11.0734 2412 dac2w2k - ok 10:15:11.0921 2412 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys 10:15:11.0953 2412 dac960nt - ok 10:15:12.0156 2412 DCamUSBSQTECH (41a2586f3d54efbc1aa8d29748e26634) C:\WINDOWS\system32\Drivers\SQcaptur.sys 10:15:12.0187 2412 DCamUSBSQTECH - ok 10:15:12.0359 2412 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 10:15:12.0390 2412 Disk - ok 10:15:13.0015 2412 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 10:15:13.0234 2412 dmboot - ok 10:15:13.0562 2412 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 10:15:13.0671 2412 dmio - ok 10:15:13.0937 2412 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 10:15:13.0953 2412 dmload - ok 10:15:14.0343 2412 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 10:15:14.0343 2412 DMusic - ok 10:15:14.0578 2412 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys 10:15:14.0593 2412 dpti2o - ok 10:15:14.0765 2412 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 10:15:14.0781 2412 drmkaud - ok 10:15:14.0953 2412 drvmcdb (049177996e5e33b5faf40cad2b82098c) C:\WINDOWS\system32\drivers\drvmcdb.sys 10:15:15.0015 2412 drvmcdb - ok 10:15:15.0234 2412 drvnddm (2f4134d073f972575c174e3d621f0107) C:\WINDOWS\system32\drivers\drvnddm.sys 10:15:15.0328 2412 drvnddm - ok 10:15:15.0515 2412 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 10:15:15.0562 2412 DSproct - ok 10:15:15.0750 2412 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 10:15:15.0781 2412 dsunidrv - ok 10:15:16.0031 2412 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys 10:15:16.0156 2412 E100B - ok 10:15:16.0843 2412 eamon (55e754e04c09daf19fc0054e72713d80) C:\WINDOWS\system32\DRIVERS\eamon.sys 10:15:16.0890 2412 eamon - ok 10:15:17.0640 2412 ehdrv (6f2441c26d74bde88c25e240a2720eeb) C:\WINDOWS\system32\DRIVERS\ehdrv.sys 10:15:17.0671 2412 ehdrv - ok 10:15:17.0875 2412 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys 10:15:17.0875 2412 EL90XBC - ok 10:15:17.0953 2412 ElbyCDIO (309ac30471a0f1c3a89dee1c81230576) C:\WINDOWS\system32\Drivers\ElbyCDIO.sys 10:15:17.0968 2412 ElbyCDIO - ok 10:15:18.0187 2412 EntDrv51 - ok 10:15:18.0265 2412 epfw (93aa9cef77315a0866f8307195de416d) C:\WINDOWS\system32\DRIVERS\epfw.sys 10:15:18.0312 2412 epfw - ok 10:15:18.0468 2412 Epfwndis (7946b41daeb3e610742ff01a6d2d61b2) C:\WINDOWS\system32\DRIVERS\Epfwndis.sys 10:15:18.0546 2412 Epfwndis - ok 10:15:18.0718 2412 epfwtdi (f38059a07393a8c56bae8ff7ee0c3128) C:\WINDOWS\system32\DRIVERS\epfwtdi.sys 10:15:18.0750 2412 epfwtdi - ok 10:15:18.0937 2412 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 10:15:18.0953 2412 Fastfat - ok 10:15:19.0062 2412 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 10:15:19.0078 2412 Fdc - ok 10:15:19.0281 2412 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 10:15:19.0328 2412 Fips - ok 10:15:19.0593 2412 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 10:15:19.0609 2412 Flpydisk - ok 10:15:20.0046 2412 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 10:15:20.0140 2412 FltMgr - ok 10:15:20.0625 2412 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 10:15:20.0656 2412 Fs_Rec - ok 10:15:20.0812 2412 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 10:15:20.0843 2412 Ftdisk - ok 10:15:21.0062 2412 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 10:15:21.0140 2412 GEARAspiWDM - ok 10:15:21.0437 2412 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 10:15:21.0453 2412 Gpc - ok 10:15:21.0593 2412 GTNDIS5 (fc80052194d5708254a346568f0e77c0) C:\WINDOWS\system32\GTNDIS5.SYS 10:15:21.0625 2412 GTNDIS5 - ok 10:15:21.0828 2412 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 10:15:21.0906 2412 HidUsb - ok 10:15:22.0140 2412 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys 10:15:22.0171 2412 hpn - ok 10:15:22.0281 2412 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 10:15:22.0281 2412 HTTP - ok 10:15:22.0468 2412 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 10:15:22.0500 2412 i2omgmt - ok 10:15:23.0046 2412 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys 10:15:23.0218 2412 i2omp - ok 10:15:23.0734 2412 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 10:15:23.0812 2412 i8042prt - ok 10:15:24.0500 2412 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys 10:15:24.0609 2412 i81x - ok 10:15:24.0765 2412 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys 10:15:24.0765 2412 iAimFP0 - ok 10:15:24.0875 2412 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys 10:15:24.0906 2412 iAimFP1 - ok 10:15:25.0046 2412 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys 10:15:25.0062 2412 iAimFP2 - ok 10:15:25.0296 2412 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys 10:15:25.0328 2412 iAimFP3 - ok 10:15:25.0546 2412 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys 10:15:25.0562 2412 iAimFP4 - ok 10:15:25.0656 2412 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys 10:15:25.0687 2412 iAimTV0 - ok 10:15:25.0843 2412 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys 10:15:25.0906 2412 iAimTV1 - ok 10:15:26.0062 2412 iAimTV2 - ok 10:15:26.0250 2412 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys 10:15:26.0281 2412 iAimTV3 - ok 10:15:26.0671 2412 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys 10:15:26.0734 2412 iAimTV4 - ok 10:15:27.0968 2412 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 10:15:28.0062 2412 ialm - ok 10:15:28.0234 2412 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 10:15:28.0265 2412 Imapi - ok 10:15:28.0781 2412 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys 10:15:28.0906 2412 ini910u - ok 10:15:29.0796 2412 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys 10:15:31.0390 2412 IntelC51 - ok 10:15:32.0593 2412 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys 10:15:33.0187 2412 IntelC52 - ok 10:15:33.0718 2412 IntelC53 (de2686c0e012e6ae24acd6e79eb7ff5d) C:\WINDOWS\system32\DRIVERS\IntelC53.sys 10:15:33.0765 2412 IntelC53 - ok 10:15:34.0328 2412 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys 10:15:34.0375 2412 IntelIde - ok 10:15:35.0109 2412 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 10:15:35.0312 2412 intelppm - ok 10:15:36.0312 2412 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 10:15:36.0390 2412 ip6fw - ok 10:15:36.0921 2412 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 10:15:37.0000 2412 IpFilterDriver - ok 10:15:37.0531 2412 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 10:15:37.0578 2412 IpInIp - ok 10:15:38.0046 2412 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 10:15:38.0078 2412 IpNat - ok 10:15:38.0875 2412 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 10:15:38.0937 2412 IPSec - ok 10:15:39.0953 2412 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 10:15:40.0000 2412 IRENUM - ok 10:15:40.0625 2412 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 10:15:40.0671 2412 isapnp - ok 10:15:41.0109 2412 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 10:15:41.0234 2412 Kbdclass - ok 10:15:41.0781 2412 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 10:15:41.0968 2412 kmixer - ok 10:15:42.0984 2412 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 10:15:43.0265 2412 KSecDD - ok 10:15:43.0890 2412 lbrtfdc - ok 10:15:44.0578 2412 LXARScan (e8d15acd2f65a2e8756768353e08a9a0) C:\WINDOWS\system32\Drivers\Lxarscan.sys 10:15:44.0625 2412 LXARScan - ok 10:15:45.0031 2412 MBAMSwissArmy - ok 10:15:45.0562 2412 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 10:15:45.0609 2412 mnmdd - ok 10:15:46.0078 2412 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 10:15:46.0093 2412 Modem - ok 10:15:47.0000 2412 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 10:15:47.0203 2412 MODEMCSA - ok 10:15:47.0906 2412 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys 10:15:47.0921 2412 mohfilt - ok 10:15:48.0281 2412 motccgp - ok 10:15:48.0843 2412 motccgpfl (aad6191a4daa519f04ab12b2af73e356) C:\WINDOWS\system32\DRIVERS\motccgpfl.sys 10:15:48.0875 2412 motccgpfl - ok 10:15:49.0359 2412 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\WINDOWS\system32\DRIVERS\motmodem.sys 10:15:49.0390 2412 motmodem - ok 10:15:49.0953 2412 motport - ok 10:15:50.0812 2412 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 10:15:50.0984 2412 Mouclass - ok 10:15:51.0546 2412 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 10:15:51.0609 2412 mouhid - ok 10:15:52.0093 2412 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 10:15:52.0203 2412 MountMgr - ok 10:15:52.0687 2412 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys 10:15:52.0734 2412 mraid35x - ok 10:15:53.0296 2412 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 10:15:53.0562 2412 MRxDAV - ok 10:15:54.0468 2412 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 10:15:54.0953 2412 MRxSmb - ok 10:15:55.0625 2412 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 10:15:55.0671 2412 Msfs - ok 10:15:56.0312 2412 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 10:15:56.0359 2412 MSKSSRV - ok 10:15:56.0953 2412 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 10:15:57.0046 2412 MSPCLOCK - ok 10:15:57.0828 2412 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 10:15:57.0937 2412 MSPQM - ok 10:15:58.0796 2412 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 10:15:58.0812 2412 mssmbios - ok 10:15:59.0484 2412 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 10:15:59.0500 2412 MSTEE - ok 10:15:59.0671 2412 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 10:15:59.0687 2412 Mup - ok 10:15:59.0875 2412 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 10:15:59.0890 2412 NABTSFEC - ok 10:16:00.0062 2412 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 10:16:00.0078 2412 NDIS - ok 10:16:00.0359 2412 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 10:16:00.0375 2412 NdisIP - ok 10:16:00.0531 2412 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 10:16:00.0562 2412 NdisTapi - ok 10:16:00.0750 2412 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 10:16:00.0765 2412 Ndisuio - ok 10:16:01.0218 2412 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 10:16:01.0296 2412 NdisWan - ok 10:16:01.0671 2412 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 10:16:01.0703 2412 NDProxy - ok 10:16:02.0281 2412 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 10:16:02.0328 2412 NetBIOS - ok 10:16:02.0578 2412 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 10:16:02.0609 2412 NetBT - ok 10:16:02.0828 2412 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys 10:16:02.0859 2412 nm - ok 10:16:03.0062 2412 nmwcd (c82f4cc10ad315b6d6bcb14d0a7cad66) C:\WINDOWS\system32\drivers\ccdcmb.sys 10:16:03.0078 2412 nmwcd - ok 10:16:03.0359 2412 nmwcdc (60ef5f5621d7832f00a3f190a0c905e2) C:\WINDOWS\system32\drivers\ccdcmbo.sys 10:16:03.0375 2412 nmwcdc - ok 10:16:03.0609 2412 npf (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys 10:16:03.0609 2412 npf - ok 10:16:03.0734 2412 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 10:16:03.0750 2412 Npfs - ok 10:16:03.0921 2412 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 10:16:04.0000 2412 Ntfs - ok 10:16:04.0296 2412 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 10:16:04.0328 2412 Null - ok 10:16:05.0515 2412 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 10:16:06.0375 2412 nv - ok 10:16:06.0640 2412 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 10:16:06.0656 2412 NwlnkFlt - ok 10:16:06.0843 2412 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 10:16:06.0875 2412 NwlnkFwd - ok 10:16:07.0046 2412 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys 10:16:07.0046 2412 omci - ok 10:16:07.0359 2412 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys 10:16:07.0390 2412 P3 - ok 10:16:07.0656 2412 PalmUSBD (7238442742146a64fac40fa0f9afd491) C:\WINDOWS\system32\drivers\PalmUSBD.sys 10:16:07.0671 2412 PalmUSBD - ok 10:16:07.0765 2412 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 10:16:07.0796 2412 Parport - ok 10:16:07.0968 2412 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 10:16:08.0000 2412 PartMgr - ok 10:16:08.0312 2412 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 10:16:08.0328 2412 ParVdm - ok 10:16:08.0703 2412 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 10:16:08.0734 2412 PCI - ok 10:16:08.0953 2412 PCIDump - ok 10:16:09.0109 2412 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 10:16:09.0187 2412 PCIIde - ok 10:16:09.0453 2412 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 10:16:09.0500 2412 Pcmcia - ok 10:16:09.0703 2412 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys 10:16:09.0750 2412 pcouffin - ok 10:16:09.0843 2412 PDCOMP - ok 10:16:09.0921 2412 PDFRAME - ok 10:16:10.0062 2412 PDRELI - ok 10:16:10.0234 2412 PDRFRAME - ok 10:16:10.0296 2412 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys 10:16:10.0312 2412 perc2 - ok 10:16:10.0468 2412 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys 10:16:10.0484 2412 perc2hib - ok 10:16:10.0609 2412 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 10:16:10.0640 2412 PptpMiniport - ok 10:16:10.0828 2412 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 10:16:10.0843 2412 Processor - ok 10:16:10.0921 2412 PROCEXP151 - ok 10:16:11.0234 2412 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 10:16:11.0312 2412 PSched - ok 10:16:11.0703 2412 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 10:16:11.0734 2412 Ptilink - ok 10:16:11.0906 2412 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 10:16:11.0921 2412 PxHelp20 - ok 10:16:12.0093 2412 QCDonner (fddd1aeb9f81ef1e6e48ae1edc2a97d6) C:\WINDOWS\system32\DRIVERS\OVCD.sys 10:16:12.0109 2412 QCDonner - ok 10:16:12.0328 2412 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys 10:16:12.0359 2412 ql1080 - ok 10:16:12.0531 2412 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys 10:16:12.0562 2412 Ql10wnt - ok 10:16:12.0671 2412 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys 10:16:12.0703 2412 ql12160 - ok 10:16:12.0890 2412 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys 10:16:12.0937 2412 ql1240 - ok 10:16:13.0078 2412 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys 10:16:13.0093 2412 ql1280 - ok 10:16:13.0218 2412 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 10:16:13.0234 2412 RasAcd - ok 10:16:13.0421 2412 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 10:16:13.0453 2412 Rasl2tp - ok 10:16:13.0765 2412 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 10:16:13.0812 2412 RasPppoe - ok 10:16:14.0218 2412 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 10:16:14.0250 2412 Raspti - ok 10:16:14.0609 2412 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 10:16:14.0718 2412 Rdbss - ok 10:16:15.0156 2412 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 10:16:15.0218 2412 RDPCDD - ok 10:16:15.0437 2412 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 10:16:15.0453 2412 rdpdr - ok 10:16:15.0640 2412 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 10:16:15.0671 2412 RDPWD - ok 10:16:15.0859 2412 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 10:16:15.0875 2412 redbook - ok 10:16:16.0093 2412 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys 10:16:16.0109 2412 RimUsb - ok 10:16:16.0218 2412 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 10:16:16.0218 2412 RimVSerPort - ok 10:16:16.0406 2412 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 10:16:16.0421 2412 ROOTMODEM - ok 10:16:16.0656 2412 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 10:16:16.0671 2412 Secdrv - ok 10:16:16.0812 2412 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 10:16:16.0843 2412 serenum - ok 10:16:16.0984 2412 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 10:16:17.0031 2412 Serial - ok 10:16:17.0421 2412 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 10:16:17.0453 2412 Sfloppy - ok 10:16:17.0687 2412 Simbad - ok 10:16:17.0890 2412 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys 10:16:17.0921 2412 sisagp - ok 10:16:18.0125 2412 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 10:16:18.0140 2412 SLIP - ok 10:16:18.0359 2412 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys 10:16:18.0531 2412 smwdm - ok 10:16:18.0718 2412 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 10:16:18.0734 2412 SONYPVU1 - ok 10:16:18.0890 2412 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys 10:16:18.0921 2412 Sparrow - ok 10:16:19.0093 2412 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 10:16:19.0125 2412 splitter - ok 10:16:19.0218 2412 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 10:16:19.0234 2412 sr - ok 10:16:19.0453 2412 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 10:16:19.0515 2412 Srv - ok 10:16:19.0687 2412 sscdbhk5 (7c0c9bdca2d351ff3b4f9b69f99aa995) C:\WINDOWS\system32\drivers\sscdbhk5.sys 10:16:19.0718 2412 sscdbhk5 - ok 10:16:20.0000 2412 ssrtln (31726706d54894d5059f7471111a87bb) C:\WINDOWS\system32\drivers\ssrtln.sys 10:16:20.0046 2412 ssrtln - ok 10:16:20.0593 2412 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 10:16:20.0671 2412 streamip - ok 10:16:20.0984 2412 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 10:16:21.0015 2412 swenum - ok 10:16:21.0312 2412 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 10:16:21.0359 2412 swmidi - ok 10:16:21.0562 2412 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys 10:16:21.0593 2412 symc810 - ok 10:16:21.0750 2412 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys 10:16:21.0812 2412 symc8xx - ok 10:16:22.0000 2412 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys 10:16:22.0015 2412 sym_hi - ok 10:16:22.0171 2412 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys 10:16:22.0187 2412 sym_u3 - ok 10:16:22.0343 2412 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 10:16:22.0343 2412 sysaudio - ok 10:16:22.0500 2412 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 10:16:22.0562 2412 Tcpip - ok 10:16:22.0750 2412 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 10:16:22.0765 2412 TDPIPE - ok 10:16:22.0875 2412 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 10:16:22.0906 2412 TDTCP - ok 10:16:23.0046 2412 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 10:16:23.0125 2412 TermDD - ok 10:16:23.0250 2412 tfsnboio (b0d311f33c5b4a5858e4e6c965a79267) C:\WINDOWS\system32\dla\tfsnboio.sys 10:16:23.0328 2412 tfsnboio - ok 10:16:23.0453 2412 tfsncofs (250f74fce5d1eccb29ad9abeb55f35d8) C:\WINDOWS\system32\dla\tfsncofs.sys 10:16:23.0515 2412 tfsncofs - ok 10:16:23.0765 2412 tfsndrct (e23291934c59e1741ba83582e7a209c0) C:\WINDOWS\system32\dla\tfsndrct.sys 10:16:23.0796 2412 tfsndrct - ok 10:16:24.0062 2412 tfsndres (0d863d020633025f1e4ad3e0e325d503) C:\WINDOWS\system32\dla\tfsndres.sys 10:16:24.0062 2412 tfsndres - ok 10:16:24.0406 2412 tfsnifs (e3e10696663e35062851a376299198bd) C:\WINDOWS\system32\dla\tfsnifs.sys 10:16:24.0421 2412 tfsnifs - ok 10:16:24.0593 2412 tfsnopio (00cc366bdcbd8a9a1c95c1c59900dd9b) C:\WINDOWS\system32\dla\tfsnopio.sys 10:16:24.0625 2412 tfsnopio - ok 10:16:24.0703 2412 tfsnpool (84a91d08f49831e8c24e4d25ddefae87) C:\WINDOWS\system32\dla\tfsnpool.sys 10:16:24.0734 2412 tfsnpool - ok 10:16:24.0875 2412 tfsnudf (55b761c6e2d4fcedac3b46b6c0724830) C:\WINDOWS\system32\dla\tfsnudf.sys 10:16:24.0906 2412 tfsnudf - ok 10:16:25.0031 2412 tfsnudfa (64c6e8c217e30ee595120c66f6e783ba) C:\WINDOWS\system32\dla\tfsnudfa.sys 10:16:25.0062 2412 tfsnudfa - ok 10:16:25.0203 2412 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys 10:16:25.0218 2412 TosIde - ok 10:16:25.0359 2412 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 10:16:25.0390 2412 Udfs - ok 10:16:25.0625 2412 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys 10:16:25.0671 2412 ultra - ok 10:16:25.0921 2412 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 10:16:26.0000 2412 Update - ok 10:16:26.0203 2412 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys 10:16:26.0218 2412 USBAAPL - ok 10:16:26.0406 2412 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 10:16:26.0468 2412 usbaudio - ok 10:16:26.0781 2412 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 10:16:26.0828 2412 usbccgp - ok 10:16:27.0171 2412 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 10:16:27.0218 2412 usbehci - ok 10:16:27.0593 2412 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 10:16:27.0640 2412 usbhub - ok 10:16:27.0859 2412 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 10:16:27.0906 2412 usbprint - ok 10:16:28.0093 2412 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 10:16:28.0125 2412 usbscan - ok 10:16:28.0234 2412 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\drivers\usbser.sys 10:16:28.0250 2412 usbser - ok 10:16:28.0421 2412 UsbserFilt (e748d50b3b2ec7f40a2ba67fb094cf01) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys 10:16:28.0453 2412 UsbserFilt - ok 10:16:28.0656 2412 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 10:16:28.0671 2412 USBSTOR - ok 10:16:28.0796 2412 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 10:16:28.0828 2412 usbuhci - ok 10:16:28.0968 2412 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 10:16:28.0984 2412 usbvideo - ok 10:16:29.0156 2412 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 10:16:29.0187 2412 VgaSave - ok 10:16:29.0421 2412 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys 10:16:29.0468 2412 viaagp - ok 10:16:29.0593 2412 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys 10:16:29.0609 2412 ViaIde - ok 10:16:29.0750 2412 vidcap - ok 10:16:30.0000 2412 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 10:16:30.0046 2412 VolSnap - ok 10:16:30.0281 2412 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 10:16:30.0312 2412 Wanarp - ok 10:16:30.0625 2412 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys 10:16:30.0625 2412 wanatw - ok 10:16:30.0828 2412 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys 10:16:30.0828 2412 wceusbsh - ok 10:16:31.0000 2412 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 10:16:31.0093 2412 Wdf01000 - ok 10:16:31.0218 2412 WDICA - ok 10:16:31.0296 2412 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 10:16:31.0328 2412 wdmaud - ok 10:16:31.0578 2412 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 10:16:31.0593 2412 WS2IFSL - ok 10:16:31.0796 2412 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 10:16:31.0828 2412 WSTCODEC - ok 10:16:31.0953 2412 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0 10:16:32.0000 2412 \Device\Harddisk0\DR0 - ok 10:16:32.0031 2412 Boot (0x1200) (d4830dd8c2293ad9829ff7a40a28c5a7) \Device\Harddisk0\DR0\Partition0 10:16:32.0031 2412 \Device\Harddisk0\DR0\Partition0 - ok 10:16:32.0031 2412 ============================================================ 10:16:32.0031 2412 Scan finished 10:16:32.0031 2412 ============================================================ 10:16:32.0062 1104 Detected object count: 0 10:16:32.0062 1104 Actual detected object count: 0
Hello, I have been using my pc a little more since my post a few hours ago. One thing that I noticed was that when the pc freezes/stalls, the task bar at the bottom (where the start menu is) turns gray, like the older version of Microsoft windows. Right now my start menu button is green and the rest of the bar is blue. So all of this turns gray during the stall and then changes back to green/blue. I am not sure if this is normal, but I have not seen this before.
Things are definitely looking better but we still have a bit to do.

It's not unusual when things freeze that the taskbar or system tray area might appear different. Although, if this is something you have never noticed before, it's definitely something we want to keep an eye on.


I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Hello, I ran Malwarebytes' Anti-Malware. There were no issues found. I also ran the online scan from ESET and nothing was found either. Below is the MBAM log. How does it look? Please let me know the next steps. Thank you. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 911122503 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/25/2011 3:27:54 PM mbam-log-2011-12-25 (15-27-53).txt Scan type: Quick scan Objects scanned: 300979 Time elapsed: 38 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Actually, your logs are looking very good at this point, but obviously you are still experiencing lockups. From what I saw in your logs. When you noticed that things were freezing up, were you running several applications at once? Or did you have only one thing open?
Thanks. My computer is indeed running better, but like you said it does freeze up at times. I am guessing this is because my computer is getting old now?? I do not think that I am running a lot of programs. Usually it is just Yahoo Messenger and Mozilla Firefox to check mail/read news. Do you suggest any other cleaning programs for temp files, etc. from an old pc that could cause the freeze up? Thanks.
Older single core processor machines do tend to have trouble keeping up these days :)

I do notice you have a very old version of IE on your machine. I realize that you may use Firefox for your browsing, but I'm betting Windows is constantly trying to update that to a more secure version of Internet Explorer. That could be using up some resources in the background. One thing you might want to do - and it could take some time and does not need to be done in a single sitting, is to go do all your critical and non-critical Windows updates until there are no more to do. That way, Windows isn't trying to do anything in the background. You don't have a lot of resources on this machine, and you sure don't want to waste any of them.


At this point, your issues do not appear to be related to malware and I'd like to refer you to our Windows Forum for additional help. They may be able to help you with some tools to clear off some non-essential start up items, or disabling some services you might not need that might help the performance a wee bit - but I caution you not to expect too much. There really is only so much that can be done.

————————————–


The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.



Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI