This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Suspicions of Malware [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First of all i would like to state that im not a native english speaker,im brazilian and the forum i usually went for help in my native tongue closed its help channels, so if you fail to understand anything i say, please just ask me again so i can explain better.

thank you ;)

Well, after quite some time, my computer started giving me warnings about "insufficient virtual memory" even if i dont open enough things to get to that point, the value of memory load goes up from hour to hour and theres nothing that i can do to lower it, besides closing the browser and the instant messenger, even so the thing keeps going up until the system starts closing the browsers and the messengers(MAN,google talk) by itself and i see no other choice than restart the system and watch the same situation repeat itself.

Here are two printscreens showcasing the current situation.

[external image: Posted Image]

[external image: Posted Image]

The problem went away some weeks ago, returning to its normal 1,gb of memory usage like always was, but after some visits to some torrent sites the problem returned,i suspected hardware first but now, it seems o be malware even if the Avira didnt solved the problem when i did a full scan .:( i need help on solving this.

And yes ive made a log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:22:26, on 25/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Arquivos de programas\Google\Google Talk\googletalk.exe
C:\Arquivos de programas\Winamp\winampa.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\BySoft FreeRAM\FreeRAM.exe
C:\Documents and Settings\Analista\Menu Iniciar\Programas\Inicializar\windate.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Nero\Update\NASvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\Arquivos de programas\Winamp\winamp.exe
C:\Arquivos de programas\Last.fm\LastFM.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\system32\msiexec.exe
C:\Arquivos de programas\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARQUIV~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NBAgent] "C:\Arquivos de programas\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [googletalk] C:\Arquivos de programas\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Analista\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Arquivos de programas\BySoft FreeRAM\FreeRAM.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe
O4 - Startup: windate.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1277205020812
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A824B8E3-34B7-4BA1-9CF5-21BD77E23188}: NameServer = 200.222.145.85 200.165.132.148
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: @C:\Arquivos de programas\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Arquivos de programas\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 10409 bytes


hope you guys can help, sorry if i did something wrong.

thanks.
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post both of the logs made by DDS and the log made by GMER. :)
Jeff Thank you for the attention and politeness here's is the DDS log

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 21:52:17 on 2011-12-27
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.2047.712 [GMT -2:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Arquivos de programas\Google\Google Talk\googletalk.exe
C:\Arquivos de programas\Winamp\winampa.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\BySoft FreeRAM\FreeRAM.exe
C:\Documents and Settings\Analista\Menu Iniciar\Programas\Inicializar\windate.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Nero\Update\NASvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\Last.fm\LastFM.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Winamp\winamp.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.br/
uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\arquivos de programas\winamp toolbar\winamptb.dll
mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\arquivos de programas\winamp toolbar\winamptb.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\arquivos de programas\winamp toolbar\winamptb.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\arquiv~1\micros~2\office14\GROOVEEX.DLL
BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\arquiv~1\micros~2\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\arquivos de programas\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\arquivos de programas\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\arquivos de programas\winamp toolbar\winamptb.dll
uRun: [msnmsgr] "c:\arquivos de programas\windows live\messenger\msnmsgr.exe" /background
uRun: [Google Update] "c:\documents and settings\analista\configurações locais\dados de aplicativos\google\update\GoogleUpdate.exe" /c
uRun: [DAEMON Tools Lite] "c:\arquivos de programas\daemon tools lite\DTLite.exe" -autorun
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Pando Media Booster] c:\arquivos de programas\pando networks\media booster\PMB.exe
uRun: [BySoft FreeRAM] c:\arquivos de programas\bysoft freeram\FreeRAM.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NBAgent] "c:\arquivos de programas\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [googletalk] c:\arquivos de programas\google\google talk\googletalk.exe /autostart
mRun: [WinampAgent] "c:\arquivos de programas\winamp\winampa.exe"
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\arquivos de programas\arquivos comuns\adobe\arm\1.0\AdobeARM.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PlusService] c:\arquivos de programas\yuna software\messenger plus!\PlusService.exe
mRun: [SunJavaUpdateSched] "c:\arquivos de programas\arquivos comuns\java\java update\jusched.exe"
mRun: [avgnt] "c:\arquivos de programas\avira\antivir desktop\avgnt.exe" /min
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\analista\menuin~1\progra~1\inicia~1\adobeg~1.lnk - c:\arquivos de programas\arquivos comuns\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\analista\menuin~1\progra~1\inicia~1\hamachi.lnk - c:\arquivos de programas\hamachi\hamachi.exe
StartupFolder: c:\documents and settings\analista\menu iniciar\programas\inicializar\windate.exe
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: &Enviar para o OneNote - c:\arquiv~1\micros~2\office14\ONBttnIE.dll/105
IE: &Winamp Search - c:\documents and settings\all users\dados de aplicativos\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~2\office14\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\arquivos de programas\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\arquivos de programas\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\arquivos de programas\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1277205020812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
TCP: Interfaces\{A824B8E3-34B7-4BA1-9CF5-21BD77E23188} : NameServer = 200.222.145.85 200.165.132.148
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\arquivos de programas\arquivos comuns\microsoft shared\office14\MSOXMLMF.DLL
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\arquiv~1\micros~2\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\analista\dados de aplicativos\mozilla\firefox\profiles\4kibdxbf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - component: c:\documents and settings\analista\dados de aplicativos\mozilla\firefox\profiles\4kibdxbf.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\arquiv~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\arquiv~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\arquivos de programas\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\arquivos de programas\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\arquivos de programas\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\arquivos de programas\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\arquivos de programas\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\arquivos de programas\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\arquivos de programas\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\documents and settings\analista\configuraã§ãµes locais\dados de aplicativos\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\analista\configuraã§ãµes locais\dados de aplicativos\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\documents and settings\analista\dados de aplicativos\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\analista\dados de aplicativos\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-12-16 36000]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-1-22 218688]
R2 AntiVirSchedulerService;Avira Scheduler;c:\arquivos de programas\avira\antivir desktop\sched.exe [2011-12-16 86224]
R2 AntiVirService;Avira Realtime Protection;c:\arquivos de programas\avira\antivir desktop\avguard.exe [2011-12-16 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-12-16 74640]
R2 NAUpdate;@c:\arquivos de programas\nero\update\nasvc.exe,-200;c:\arquivos de programas\nero\update\NASvc.exe [2010-3-25 490280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 KMService;KMService;c:\windows\system32\srvany.exe [2010-6-22 8192]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\arquivos de programas\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\arquivos comuns\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-25 21:22:10 388096 —-a-r- c:\documents and settings\analista\dados de aplicativos\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-25 21:22:06 ——– d—–w- c:\arquivos de programas\Trend Micro
2011-12-16 07:31:48 ——– d—–w- c:\documents and settings\analista\dados de aplicativos\Avira
2011-12-16 07:31:10 36000 —-a-w- c:\windows\system32\drivers\avkmgr.sys
2011-12-16 07:31:09 74640 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2011-12-16 07:30:52 ——– d—–w- c:\documents and settings\all users\dados de aplicativos\Avira
2011-12-16 07:30:52 ——– d—–w- c:\arquivos de programas\Avira
2011-12-15 22:01:25 134104 —-a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll
.
==================== Find3M ====================
.
2011-11-28 14:01:43 26112 —-a-w- c:\windows\system32\userinit.exe
2011-11-24 16:13:13 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 14:40:14 1859712 —-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:13:20 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13:20 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:13:20 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:25:39 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07:09 1288192 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:56 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-26 10:49:52 2152960 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 10:49:52 2031104 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 18:27:42 101720 —-a-w- c:\windows\system32\drivers\SB
2011-10-12 09:38:10 45056 —-a-w- c:\windows\Ip Changer Updater.exe
2011-10-12 09:38:10 323584 —-a-w- c:\windows\Tibia MULTI-ip changer.exe
2011-10-10 14:22:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 07:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 04:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
.
============= FINISH: 21:53:54,31 ===============

the attach log like instructed will be attached to the post.
Jeff again thaking for your will to help me, i would like to state that i tried to create a log with GMER but the scan ran for so long that it "ran out of time" the memory load hit 5gb and i pushed the system over its edge causing the computer to show me the BSOD and then restart, so im unable to provide you with that log, but that doesnt mean that i gave up trying so if i manage to do it, i will post the log here, i hope those two logs can help you out.

thank you.

Attachments:

Hi Mapple,

If you are not able to get GMER to run through and get a log go ahead and try the following >>

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
just did the scan here's the log:

aswMBR version 0.9.9.1120 Copyright© 2011 AVAST Software
Run date: 2011-12-28 00:51:07
—————————–
00:51:07.515 OS Version: Windows 5.1.2600 Service Pack 3
00:51:07.515 Number of processors: 2 586 0xF0D
00:51:07.515 ComputerName: WIND-C9656CC7B0 UserName: Analista
00:51:10.265 Initialize success
00:51:21.750 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
00:51:21.750 Disk 0 Vendor: SAMSUNG_SP1644N BV900-43 Size: 152626MB BusType: 3
00:51:21.750 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T1L0-19
00:51:21.750 Disk 1 Vendor: SAMSUNG_HD161HJ GF100-07 Size: 152626MB BusType: 3
00:51:21.765 Disk 0 MBR read successfully
00:51:21.765 Disk 0 MBR scan
00:51:21.765 Disk 0 Windows XP default MBR code
00:51:21.765 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152625 MB offset 63
00:51:21.781 Disk 0 scanning sectors +312576705
00:51:21.921 Disk 0 scanning C:\WINDOWS\system32\drivers
00:51:51.562 Service scanning
00:51:54.390 Modules scanning
00:52:25.843 Disk 0 trace - called modules:
00:52:25.859 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
00:52:25.859 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89decab8]
00:52:25.859 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\0000005e[0x89de1f18]
00:52:25.859 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x89de0d98]
00:52:25.859 Scan finished successfully
00:54:03.921 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Analista\Meus documentos\Downloads\MBR.dat"
00:54:03.921 The log file has been saved successfully to "C:\Documents and Settings\Analista\Meus documentos\Downloads\aswMBR.txt"


One thing, after the computer restarted itself, he stood for more than five minutes in the XP screen loading everything, and right now i can notice some slowdowns, specially listening to musics that are saved in my portable drives, theyre playing full of delays like a scratched cd.
Hi Mapple,

Thanks for letting me know. :)
————

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

In your next reply please post the logs created by TDSSKiller and ComboFix. :)
Hello Jeff, im unable to find you the combofix log, everything on combofix operation ran smoothly except when the computer restarted the monitor blacked out and stood unresponsive, it was necessary for me to plug in and out the power several times until it got back to normal, and if i restart the computer again i dont know if the problem will perssist, probably yes.

as for the system spending too much time,(more than 10 minures) in the XP boot screen, yes it still happens.
as for the sound suffering slowdowns it also keeps happening.

maybe its hardware, my hard drive its quite old, as for the system did you noticed something strange?

here is the only log i could find thanks to your clear instructions, the TDSS killer log:

01:39:25.0765 3304 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
01:39:27.0781 3304 ============================================================
01:39:27.0781 3304 Current date / time: 2011/12/29 01:39:27.0781
01:39:27.0781 3304 SystemInfo:
01:39:27.0781 3304
01:39:27.0781 3304 OS Version: 5.1.2600 ServicePack: 3.0
01:39:27.0781 3304 Product type: Workstation
01:39:27.0781 3304 ComputerName: WIND-C9656CC7B0
01:39:27.0781 3304 UserName: Analista
01:39:27.0781 3304 Windows directory: C:\WINDOWS
01:39:27.0781 3304 System windows directory: C:\WINDOWS
01:39:27.0781 3304 Processor architecture: Intel x86
01:39:27.0781 3304 Number of processors: 2
01:39:27.0781 3304 Page size: 0x1000
01:39:27.0781 3304 Boot type: Normal boot
01:39:27.0781 3304 ============================================================
01:39:30.0531 3304 Initialize success
01:39:33.0421 4416 ============================================================
01:39:33.0421 4416 Scan started
01:39:33.0421 4416 Mode: Manual;
01:39:33.0421 4416 ============================================================
01:39:47.0890 4416 Abiosdsk - ok
01:39:48.0203 4416 abp480n5 - ok
01:39:48.0593 4416 ACPI (cfcb02e103e44ac7080ca04c1b5c2d7c) C:\WINDOWS\system32\DRIVERS\ACPI.sys
01:39:48.0656 4416 ACPI - ok
01:39:49.0281 4416 ACPIEC (ebd5cf43ad9526eab9b2a15a54760ea9) C:\WINDOWS\system32\drivers\ACPIEC.sys
01:39:49.0312 4416 ACPIEC - ok
01:39:49.0703 4416 adpu160m - ok
01:39:50.0218 4416 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
01:39:50.0281 4416 aec - ok
01:39:50.0781 4416 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
01:39:50.0828 4416 AFD - ok
01:39:51.0250 4416 Aha154x - ok
01:39:51.0593 4416 aic78u2 - ok
01:39:51.0843 4416 aic78xx - ok
01:39:52.0125 4416 AliIde - ok
01:39:52.0390 4416 amsint - ok
01:39:52.0703 4416 asc - ok
01:39:53.0312 4416 asc3350p - ok
01:39:53.0921 4416 asc3550 - ok
01:39:54.0546 4416 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
01:39:54.0640 4416 AsyncMac - ok
01:39:55.0203 4416 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
01:39:55.0203 4416 atapi - ok
01:39:55.0593 4416 Atdisk - ok
01:39:56.0000 4416 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
01:39:56.0078 4416 Atmarpc - ok
01:39:56.0484 4416 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
01:39:56.0484 4416 audstub - ok
01:39:56.0984 4416 avgntflt (7713e4eb0276702faa08e52a6e23f2a6) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
01:39:57.0015 4416 avgntflt - ok
01:39:57.0515 4416 avipbb (475fbb85956534720858ae72010c0a43) C:\WINDOWS\system32\DRIVERS\avipbb.sys
01:39:57.0562 4416 avipbb - ok
01:39:58.0062 4416 avkmgr (271cfd1a989209b1964e24d969552bf7) C:\WINDOWS\system32\DRIVERS\avkmgr.sys
01:39:58.0078 4416 avkmgr - ok
01:39:58.0515 4416 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
01:39:58.0531 4416 Beep - ok
01:39:59.0000 4416 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
01:39:59.0093 4416 cbidf2k - ok
01:39:59.0531 4416 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
01:39:59.0593 4416 CCDECODE - ok
01:39:59.0984 4416 cd20xrnt - ok
01:40:00.0421 4416 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
01:40:00.0421 4416 Cdaudio - ok
01:40:01.0093 4416 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
01:40:01.0125 4416 Cdfs - ok
01:40:01.0593 4416 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
01:40:01.0609 4416 Cdrom - ok
01:40:02.0015 4416 Changer - ok
01:40:02.0390 4416 CmdIde - ok
01:40:02.0656 4416 Cpqarray - ok
01:40:02.0921 4416 dac2w2k - ok
01:40:03.0203 4416 dac960nt - ok
01:40:03.0515 4416 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
01:40:03.0531 4416 Disk - ok
01:40:04.0296 4416 dmboot (f8002f47101ef7e4fbb4379452d16c91) C:\WINDOWS\system32\drivers\dmboot.sys
01:40:04.0718 4416 dmboot - ok
01:40:05.0218 4416 dmio (fe2c5d52066427c82ee473da3b5065c1) C:\WINDOWS\system32\drivers\dmio.sys
01:40:05.0281 4416 dmio - ok
01:40:05.0687 4416 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
01:40:05.0687 4416 dmload - ok
01:40:06.0187 4416 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
01:40:06.0203 4416 DMusic - ok
01:40:06.0625 4416 dpti2o - ok
01:40:07.0187 4416 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
01:40:07.0187 4416 drmkaud - ok
01:40:07.0718 4416 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
01:40:07.0812 4416 dtsoftbus01 - ok
01:40:08.0312 4416 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
01:40:08.0375 4416 Fastfat - ok
01:40:08.0812 4416 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
01:40:08.0828 4416 Fdc - ok
01:40:09.0265 4416 Fips (a8d31e836ccf2f51009ce7dffecf6d51) C:\WINDOWS\system32\drivers\Fips.sys
01:40:09.0281 4416 Fips - ok
01:40:09.0750 4416 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
01:40:09.0750 4416 Flpydisk - ok
01:40:10.0281 4416 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
01:40:10.0328 4416 FltMgr - ok
01:40:10.0781 4416 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
01:40:10.0796 4416 Fs_Rec - ok
01:40:11.0250 4416 Ftdisk (d24d7839d594b255e1c298245b7ba6a2) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
01:40:11.0296 4416 Ftdisk - ok
01:40:11.0781 4416 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
01:40:11.0796 4416 Gpc - ok
01:40:12.0390 4416 hamachi (7929a161f9951d173ca9900fe7067391) C:\WINDOWS\system32\DRIVERS\hamachi.sys
01:40:12.0406 4416 hamachi - ok
01:40:12.0921 4416 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
01:40:12.0968 4416 HDAudBus - ok
01:40:13.0421 4416 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
01:40:13.0437 4416 hidusb - ok
01:40:13.0828 4416 hpn - ok
01:40:14.0250 4416 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
01:40:14.0359 4416 HTTP - ok
01:40:14.0750 4416 i2omgmt - ok
01:40:15.0109 4416 i2omp - ok
01:40:15.0437 4416 i8042prt (485bc6beb778b5e9702e6aa3d384c0cb) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
01:40:15.0453 4416 i8042prt - ok
01:40:16.0484 4416 ialm (bc1f1ff8d5800398937966cdb0a97fdc) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
01:40:17.0281 4416 ialm - ok
01:40:18.0390 4416 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
01:40:18.0453 4416 Imapi - ok
01:40:19.0218 4416 ini910u - ok
01:40:23.0765 4416 IntcAzAudAddService (08baf30f6de95814f58af9ce7bbc5614) C:\WINDOWS\system32\drivers\RtkHDAud.sys
01:40:28.0390 4416 IntcAzAudAddService - ok
01:40:28.0796 4416 IntelIde - ok
01:40:29.0140 4416 intelppm (7844c7948f40c44cb8012104fca7271b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
01:40:29.0156 4416 intelppm - ok
01:40:29.0625 4416 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
01:40:29.0687 4416 Ip6Fw - ok
01:40:30.0109 4416 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
01:40:30.0156 4416 IpFilterDriver - ok
01:40:30.0593 4416 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
01:40:30.0640 4416 IpInIp - ok
01:40:31.0125 4416 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
01:40:31.0187 4416 IpNat - ok
01:40:31.0687 4416 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
01:40:31.0718 4416 IPSec - ok
01:40:32.0156 4416 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
01:40:32.0343 4416 IRENUM - ok
01:40:32.0796 4416 isapnp (2f61347dc1e20b593f8b66a92d9a46b4) C:\WINDOWS\system32\DRIVERS\isapnp.sys
01:40:32.0812 4416 isapnp - ok
01:40:33.0265 4416 Kbdclass (d3d4832b494cbf9a87cf86d7517013cb) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
01:40:33.0281 4416 Kbdclass - ok
01:40:34.0046 4416 kbdhid (68d9a763447d5488e155579e2990c5ad) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
01:40:34.0078 4416 kbdhid - ok
01:40:35.0171 4416 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
01:40:35.0296 4416 kmixer - ok
01:40:36.0203 4416 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
01:40:36.0312 4416 KSecDD - ok
01:40:37.0000 4416 lbrtfdc - ok
01:40:37.0640 4416 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
01:40:37.0671 4416 mnmdd - ok
01:40:38.0265 4416 Modem (04abc65d1d05aa0b396416b08e51b727) C:\WINDOWS\system32\drivers\Modem.sys
01:40:38.0468 4416 Modem - ok
01:40:38.0921 4416 Mouclass (a23a5edd91db897d1c8f0c2e9458e0b0) C:\WINDOWS\system32\DRIVERS\mouclass.sys
01:40:38.0937 4416 Mouclass - ok
01:40:39.0531 4416 mouhid (53d3dba64871148591bfe21b492c3558) C:\WINDOWS\system32\DRIVERS\mouhid.sys
01:40:39.0531 4416 mouhid - ok
01:40:40.0156 4416 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
01:40:40.0171 4416 MountMgr - ok
01:40:40.0875 4416 mraid35x - ok
01:40:41.0843 4416 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
01:40:41.0984 4416 MRxDAV - ok
01:40:42.0953 4416 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
01:40:43.0156 4416 MRxSmb - ok
01:40:43.0796 4416 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
01:40:43.0812 4416 Msfs - ok
01:40:44.0281 4416 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
01:40:44.0312 4416 MSKSSRV - ok
01:40:45.0000 4416 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
01:40:45.0031 4416 MSPCLOCK - ok
01:40:45.0453 4416 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
01:40:45.0515 4416 MSPQM - ok
01:40:45.0953 4416 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
01:40:45.0968 4416 mssmbios - ok
01:40:46.0406 4416 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
01:40:46.0546 4416 MSTEE - ok
01:40:47.0218 4416 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
01:40:47.0265 4416 Mup - ok
01:40:47.0734 4416 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
01:40:47.0859 4416 NABTSFEC - ok
01:40:48.0375 4416 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
01:40:48.0453 4416 NDIS - ok
01:40:48.0890 4416 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
01:40:48.0906 4416 NdisIP - ok
01:40:49.0312 4416 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
01:40:49.0312 4416 NdisTapi - ok
01:40:49.0765 4416 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
01:40:49.0765 4416 Ndisuio - ok
01:40:50.0250 4416 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
01:40:50.0281 4416 NdisWan - ok
01:40:50.0734 4416 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
01:40:50.0765 4416 NDProxy - ok
01:40:51.0203 4416 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
01:40:51.0218 4416 NetBIOS - ok
01:40:51.0750 4416 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
01:40:51.0859 4416 NetBT - ok
01:40:52.0375 4416 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
01:40:52.0390 4416 Npfs - ok
01:40:53.0187 4416 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
01:40:53.0406 4416 Ntfs - ok
01:40:54.0000 4416 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
01:40:54.0000 4416 Null - ok
01:41:00.0421 4416 nv (ed9816dbaf6689542ea7d022631906a1) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
01:41:10.0484 4416 nv - ok
01:41:11.0078 4416 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
01:41:11.0109 4416 NwlnkFlt - ok
01:41:11.0546 4416 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
01:41:11.0609 4416 NwlnkFwd - ok
01:41:12.0203 4416 PAC7302 (14191c739f2af6f9efeb58697535498f) C:\WINDOWS\system32\DRIVERS\PAC7302.SYS
01:41:12.0500 4416 PAC7302 - ok
01:41:12.0953 4416 Parport (9badee6b698bf1af36e25a1a64a89eab) C:\WINDOWS\system32\DRIVERS\parport.sys
01:41:12.0984 4416 Parport - ok
01:41:13.0468 4416 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
01:41:13.0484 4416 PartMgr - ok
01:41:13.0937 4416 ParVdm (598a4e8249dcee03c4426b1cf3917abd) C:\WINDOWS\system32\drivers\ParVdm.sys
01:41:13.0953 4416 ParVdm - ok
01:41:14.0437 4416 PCI (f97146d1a50500b38ec8d4015e83e0a7) C:\WINDOWS\system32\DRIVERS\pci.sys
01:41:14.0453 4416 PCI - ok
01:41:14.0843 4416 PCIDump - ok
01:41:15.0234 4416 PCIIde (62e28fb2d275059532389c615c04e054) C:\WINDOWS\system32\DRIVERS\pciide.sys
01:41:15.0234 4416 PCIIde - ok
01:41:15.0890 4416 Pcmcia (e5b6489d932d374e2c3cb077b13faa82) C:\WINDOWS\system32\drivers\Pcmcia.sys
01:41:15.0968 4416 Pcmcia - ok
01:41:16.0343 4416 PDCOMP - ok
01:41:16.0656 4416 PDFRAME - ok
01:41:16.0906 4416 PDRELI - ok
01:41:17.0171 4416 PDRFRAME - ok
01:41:17.0421 4416 perc2 - ok
01:41:17.0687 4416 perc2hib - ok
01:41:18.0000 4416 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
01:41:18.0015 4416 PptpMiniport - ok
01:41:18.0484 4416 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
01:41:18.0515 4416 PSched - ok
01:41:18.0953 4416 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
01:41:18.0968 4416 Ptilink - ok
01:41:19.0453 4416 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
01:41:19.0484 4416 PxHelp20 - ok
01:41:19.0859 4416 ql1080 - ok
01:41:20.0234 4416 Ql10wnt - ok
01:41:20.0593 4416 ql12160 - ok
01:41:21.0031 4416 ql1240 - ok
01:41:21.0406 4416 ql1280 - ok
01:41:21.0734 4416 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
01:41:21.0781 4416 RasAcd - ok
01:41:22.0359 4416 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
01:41:22.0390 4416 Rasl2tp - ok
01:41:22.0859 4416 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
01:41:22.0875 4416 RasPppoe - ok
01:41:23.0312 4416 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
01:41:23.0328 4416 Raspti - ok
01:41:23.0875 4416 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
01:41:23.0953 4416 Rdbss - ok
01:41:24.0421 4416 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
01:41:24.0421 4416 RDPCDD - ok
01:41:24.0906 4416 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
01:41:24.0984 4416 rdpdr - ok
01:41:25.0484 4416 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
01:41:25.0562 4416 RDPWD - ok
01:41:25.0984 4416 redbook (68d749b04bfbbd4d4d15cc5185afa4dd) C:\WINDOWS\system32\DRIVERS\redbook.sys
01:41:26.0015 4416 redbook - ok
01:41:26.0484 4416 RTLE8023xp (89619ef503f949fae09252a8b883ee11) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
01:41:26.0531 4416 RTLE8023xp - ok
01:41:27.0125 4416 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
01:41:27.0156 4416 Secdrv - ok
01:41:27.0593 4416 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
01:41:27.0593 4416 serenum - ok
01:41:28.0062 4416 Serial (c681c4804504fb2d799daacab2073c94) C:\WINDOWS\system32\DRIVERS\serial.sys
01:41:28.0078 4416 Serial - ok
01:41:28.0531 4416 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
01:41:28.0546 4416 Sfloppy - ok
01:41:28.0937 4416 Simbad - ok
01:41:29.0250 4416 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
01:41:29.0265 4416 SLIP - ok
01:41:29.0640 4416 Sparrow - ok
01:41:29.0953 4416 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
01:41:29.0953 4416 splitter - ok
01:41:30.0421 4416 sr (d6c5a1a97fe0c533e712652ad9dc00d4) C:\WINDOWS\system32\DRIVERS\sr.sys
01:41:30.0453 4416 sr - ok
01:41:31.0015 4416 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
01:41:31.0171 4416 Srv - ok
01:41:31.0609 4416 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
01:41:31.0625 4416 ssmdrv - ok
01:41:32.0234 4416 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
01:41:32.0281 4416 streamip - ok
01:41:32.0718 4416 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
01:41:32.0906 4416 swenum - ok
01:41:33.0953 4416 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
01:41:33.0984 4416 swmidi - ok
01:41:34.0453 4416 symc810 - ok
01:41:34.0843 4416 symc8xx - ok
01:41:35.0234 4416 sym_hi - ok
01:41:35.0562 4416 sym_u3 - ok
01:41:35.0875 4416 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
01:41:35.0906 4416 sysaudio - ok
01:41:36.0484 4416 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
01:41:36.0656 4416 Tcpip - ok
01:41:37.0125 4416 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
01:41:37.0171 4416 TDPIPE - ok
01:41:37.0625 4416 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
01:41:37.0687 4416 TDTCP - ok
01:41:38.0281 4416 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
01:41:38.0296 4416 TermDD - ok
01:41:38.0718 4416 TosIde - ok
01:41:39.0250 4416 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
01:41:39.0328 4416 Udfs - ok
01:41:39.0890 4416 ultra - ok
01:41:40.0906 4416 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
01:41:41.0296 4416 Update - ok
01:41:42.0265 4416 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
01:41:42.0500 4416 usbaudio - ok
01:41:43.0421 4416 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
01:41:43.0500 4416 usbccgp - ok
01:41:44.0640 4416 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
01:41:44.0703 4416 usbehci - ok
01:41:46.0062 4416 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
01:41:46.0156 4416 usbhub - ok
01:41:47.0421 4416 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
01:41:47.0421 4416 USBSTOR - ok
01:41:48.0484 4416 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
01:41:48.0515 4416 usbuhci - ok
01:41:49.0312 4416 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
01:41:49.0328 4416 VgaSave - ok
01:41:49.0703 4416 ViaIde - ok
01:41:50.0046 4416 VolSnap (eb6b1e2c984d84470ff4fe7ef98cd44a) C:\WINDOWS\system32\drivers\VolSnap.sys
01:41:50.0062 4416 VolSnap - ok
01:41:50.0515 4416 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
01:41:50.0531 4416 Wanarp - ok
01:41:50.0906 4416 WDICA - ok
01:41:51.0265 4416 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
01:41:51.0296 4416 wdmaud - ok
01:41:51.0750 4416 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
01:41:51.0796 4416 WSTCODEC - ok
01:41:51.0859 4416 MBR (0x1B8) (239fc8b1c26d5286165a956f5a98d8d7) \Device\Harddisk0\DR0
01:41:52.0187 4416 \Device\Harddisk0\DR0 - ok
01:41:52.0187 4416 MBR (0x1B8) (239fc8b1c26d5286165a956f5a98d8d7) \Device\Harddisk1\DR1
01:41:52.0203 4416 \Device\Harddisk1\DR1 - ok
01:41:52.0203 4416 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR4
01:41:52.0234 4416 \Device\Harddisk2\DR4 - ok
01:41:52.0593 4416 MBR (0x1B8) (180dbde3af7ea48b3db3ac27b1ddf401) \Device\Harddisk3\DR5
01:41:52.0765 4416 \Device\Harddisk3\DR5 - ok
01:41:52.0765 4416 Boot (0x1200) (b511cbc0f2a4986553f7a35b5764cf97) \Device\Harddisk0\DR0\Partition0
01:41:52.0765 4416 \Device\Harddisk0\DR0\Partition0 - ok
01:41:52.0781 4416 Boot (0x1200) (cc8587676f090b0ac3c037375307af12) \Device\Harddisk1\DR1\Partition0
01:41:52.0781 4416 \Device\Harddisk1\DR1\Partition0 - ok
01:41:52.0781 4416 Boot (0x1200) (e5038d89176368679582bbee54a32539) \Device\Harddisk2\DR4\Partition0
01:41:52.0781 4416 \Device\Harddisk2\DR4\Partition0 - ok
01:41:52.0781 4416 Boot (0x1200) (edb59f85ad02b861c0e2e2326b393265) \Device\Harddisk3\DR5\Partition0
01:41:52.0781 4416 \Device\Harddisk3\DR5\Partition0 - ok
01:41:52.0781 4416 ============================================================
01:41:52.0781 4416 Scan finished
01:41:52.0781 4416 ============================================================
01:41:52.0796 2584 Detected object count: 0
01:41:52.0796 2584 Actual detected object count: 0
01:42:35.0218 5968 Deinitialize success


As you can see, it detected nothing,quite weird since i was expecting to detect a truckload of malware just because im having a truckload of troubles with this computer.

Well, unfortunately i will be kind of unable to keep following your suggestions, since im having problems to making the monitor boot properly, i will continue to post in the topic using a mobile computer at least.

Thanks again :)
Hi Mapple, The ComboFix log could have been created. Lets see if we can find it. Please go to your C:\ folder and see if there is a file name CombFix.txt. If it is there please copy and paste that log into your next reply. :) If the log is not there please look in C:\Qoobox for ComboFix.txt. If you are able to find it there please post in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI