OTL logfile created on: 2/12/2012 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\FIx
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.09% Memory free
2.23 Gb Paging File | 1.58 Gb Available in Paging File | 71.13% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 16.27 Gb Free Space | 43.71% Space Free | Partition Type: NTFS
Computer Name: DDS2M981 | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/12 07:24:42 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\FIx\OTL.exe
PRC - [2012/01/19 21:35:36 | 001,047,024 | —- | M] (Google Inc.) – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/09/23 20:46:28 | 001,195,408 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/04/15 07:12:37 | 000,618,496 | —- | M] () – C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2011/04/14 14:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/04/14 14:01:38 | 000,171,168 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/03/13 11:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/11/17 06:56:09 | 000,014,456 | —- | M] (PlumChoice, Inc.) – C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe
PRC - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2006/03/21 13:19:40 | 000,069,632 | —- | M] (ScanSoft, Inc.) – C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
PRC - [2006/01/25 15:49:02 | 000,884,840 | —- | M] (NETGEAR) – C:\Program Files\NETGEAR\WG111T\wlan111t.exe
PRC - [2005/09/11 19:58:45 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2003/03/29 11:52:02 | 000,102,400 | —- | M] (Hoi Chuyen Gia Viet Nam) – C:\Program Files\Vpskeys\VPSKEYS.EXE
========== Modules (No Company Name) ==========
MOD - [2012/01/19 21:35:35 | 000,411,120 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll
MOD - [2012/01/19 21:35:34 | 003,767,792 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
MOD - [2012/01/19 21:34:10 | 000,122,880 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avutil-51.dll
MOD - [2012/01/19 21:34:09 | 000,222,208 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avformat-53.dll
MOD - [2012/01/19 21:34:07 | 001,746,432 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avcodec-53.dll
MOD - [2012/01/19 18:14:40 | 008,593,056 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
MOD - [2011/12/31 03:10:48 | 011,817,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
MOD - [2011/12/31 03:03:28 | 000,372,736 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
MOD - [2011/12/31 03:03:25 | 000,303,104 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2011/10/12 02:21:18 | 000,212,992 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
MOD - [2011/10/12 02:18:20 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
MOD - [2011/10/12 02:15:05 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2011/10/12 02:12:04 | 007,950,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2011/10/12 02:11:27 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/04/15 07:12:37 | 000,618,496 | —- | M] () – C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
MOD - [2010/11/17 06:56:12 | 000,041,080 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\CLISharedInterfaces.dll
MOD - [2010/11/17 06:46:27 | 000,045,688 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\DetectionExtension.dxt
MOD - [2010/11/17 06:12:34 | 000,247,416 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\OESISCore.dll
MOD - [2010/11/17 06:02:23 | 000,155,648 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\SmartDisk.dll
MOD - [2003/03/29 12:03:22 | 000,069,632 | —- | M] () – C:\Program Files\Vpskeys\VPSKM32.DLL
MOD - [2003/03/29 11:51:44 | 000,061,440 | —- | M] () – C:\Program Files\Vpskeys\VPSKH32.DLL
MOD - [2003/03/29 11:51:26 | 000,098,304 | —- | M] () – C:\Program Files\Vpskeys\VPSVNL32.DLL
MOD - [2001/09/07 20:53:10 | 000,100,864 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/04/14 14:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2011/04/14 14:01:38 | 000,171,168 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/03/13 11:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2010/11/17 06:56:09 | 000,014,456 | —- | M] (PlumChoice, Inc.) [Auto | Running] – C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe – (COX CommunicationsMonitoringService)
SRV - [2010/10/07 20:34:28 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/07/26 15:01:58 | 000,066,112 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll – (nosGetPlusHelper) getPlus®
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2008/11/07 18:55:30 | 000,026,144 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\spupdsvc.exe – (spupdsvc)
SRV - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)
SRV - [2005/04/05 10:17:22 | 000,206,552 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) [Disabled | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2003/03/03 10:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
========== Driver Services (SafeList) ==========
DRV - [2011/04/14 14:01:38 | 000,314,088 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/04/14 14:01:38 | 000,153,280 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/04/14 14:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/04/14 14:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/04/14 14:01:38 | 000,084,488 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/04/14 14:01:38 | 000,084,200 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/04/14 14:01:38 | 000,056,064 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/04/14 14:01:38 | 000,052,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/03/13 11:20:10 | 000,459,728 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/03/13 11:20:10 | 000,118,784 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/03/22 22:53:12 | 000,816,672 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AE1000XP.sys – (AE1000)
DRV - [2010/02/17 15:52:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 09:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2006/06/11 17:06:28 | 000,041,984 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\DGIVECP.SYS – (DgiVecp)
DRV - [2005/09/09 18:20:15 | 000,015,890 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2005/09/05 11:21:06 | 000,362,944 | —- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WG11TND5.sys – (AR5523)
DRV - [2005/07/28 13:52:18 | 000,123,712 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent)
DRV - [2005/04/05 10:17:02 | 000,267,192 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2005/04/05 10:17:00 | 000,017,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2005/04/05 10:16:58 | 000,036,984 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2005/04/05 10:16:56 | 000,047,192 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2005/04/05 10:16:54 | 000,173,208 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2005/04/05 10:16:52 | 000,011,512 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2003/07/24 11:10:34 | 000,017,149 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\DNINDIS5.sys – (DNINDIS5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:4619
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:4619
IE - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "
http://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;="
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {926a10d2-4ce7-4331-b96f-ca4e22590fac}:[removed]
FF - prefs.js..extensions.enabledItems: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.0
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2105: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2163: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1212: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/12/17 17:31:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/27 20:24:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/16 17:13:55 | 000,000,000 | —D | M]
[2010/07/31 13:03:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Extensions
[2011/12/29 07:43:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions
[2010/07/31 14:04:23 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/02 21:46:46 | 000,000,000 | —D | M] (D-Link Toolbar) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{926a10d2-4ce7-4331-b96f-ca4e22590fac}
[2010/08/15 19:10:56 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/12/29 07:43:19 | 000,000,000 | —D | M] (samfind Bookmarks Bar) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\[removed]
[2010/07/31 14:04:32 | 000,001,832 | —- | M] () – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\searchplugins\bing.xml
[2012/01/16 17:13:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/01/16 17:13:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2011/12/20 23:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll
[2008/06/19 01:16:24 | 000,118,784 | —- | M] (CANON INC.) – C:\Program Files\mozilla firefox\plugins\MyCamera.dll
[2008/06/19 01:16:24 | 000,053,248 | —- | M] (CANON INC.) – C:\Program Files\mozilla firefox\plugins\NPCIG.dll
[2012/01/16 17:13:35 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 20:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/09 05:22:03 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011/12/20 20:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url =
http://www.bing.com/search?setmkt=en-US&q;={searchTerms}
CHR - default_search_provider: suggest_url =
http://api.bing.com/osjson.aspx?query={sea…uage={language}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Canon Online Photo Plugin Module (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPCIG.dll
CHR - plugin: getPlusPlus for Adobe 16287 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/01/16 16:46:21 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111216172118.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006..\Run: [VPSKEYS] C:\Program Files\Vpskeys\VPSKEYS.EXE (Hoi Chuyen Gia Viet Nam)
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\Cox PC HealthCheck.lnk = C:\Program Files\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe (PlumChoice, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Fit-width Print - {3C34EBD2-038D-4d4f-B081-16D99D8BE2B4} - C:\WINDOWS\Downloaded Program Files\IEPrint.dll ()
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://www.costcophotocenter.com/CostcoActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F9CD2233-6744-47C1-A6AE-00C30A35F73D}
https://myaccount.cox.net/internettools/scr…s/Inspector.cab (CAssessmentCtl Object)
O16 - DPF: IEPrint
http://www.visiontech.ltd.uk/software/download/IEPrint.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DD33601-AA8D-4591-81C9-1C1A22964F53}: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () -
http://www.baby-g.com/resource/images/prod…9R-8_medium.png
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 10:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/11 18:29:21 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\FIx
[2012/02/11 08:54:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/01/16 19:04:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\admin\Recent
[2012/01/16 19:04:37 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/01/16 17:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/16 17:12:41 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/01/16 17:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Sun
[2012/01/16 17:04:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/01/16 16:56:06 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/01/15 16:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/15 16:39:56 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/15 16:39:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/15 15:24:32 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/01/15 12:39:47 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/01/14 08:47:24 | 001,972,528 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\admin\Desktop\TDSSKiller.exe
[2006/10/14 17:17:42 | 003,198,976 | —- | C] (Leader Technologies/ViewSonic) – C:\Program Files\ViewSonicregistration.exe
========== Files - Modified Within 30 Days ==========
[2012/02/12 07:28:03 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006UA.job
[2012/02/12 05:50:57 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{4BC30354-82BA-47A2-B4EF-23DF1DA65451}.job
[2012/02/11 18:28:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006Core.job
[2012/02/11 08:54:46 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/11 08:54:12 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2012/02/11 08:54:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/11 08:54:05 | 2145,439,744 | -HS- | M] () – C:\hiberfil.sys
[2012/01/24 16:25:13 | 000,002,262 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/24 16:25:12 | 000,002,284 | —- | M] () – C:\Documents and Settings\admin\Desktop\Google Chrome.lnk
[2012/01/16 17:03:32 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/16 16:46:21 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/15 16:39:57 | 000,000,802 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/15 15:24:45 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/01/15 13:46:31 | 000,445,798 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/15 13:46:31 | 000,073,004 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/13 16:07:33 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/13 15:24:32 | 001,972,528 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\admin\Desktop\TDSSKiller.exe
========== Files Created - No Company Name ==========
[2012/01/16 17:03:32 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/16 17:03:32 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/15 16:39:57 | 000,000,802 | —- | C] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/15 15:24:44 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/01/15 15:24:40 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/01/14 07:27:46 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/11/28 09:35:43 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/27 09:53:24 | 000,485,240 | —- | C] () – C:\WINDOWS\ssndii.exe
[2011/11/24 06:37:25 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/11/24 06:37:25 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/05/25 19:01:00 | 000,000,166 | —- | C] () – C:\Documents and Settings\admin\Application Data\burnaware.ini
[2011/02/21 09:50:28 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/02/19 18:24:33 | 000,149,392 | —- | C] () – C:\WINDOWS\System32\drivers\ar5523.bin
[2011/01/24 10:06:13 | 000,385,016 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/06 19:21:22 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2008/05/17 19:57:45 | 000,001,160 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/04/01 15:46:57 | 000,000,048 | -HS- | C] () – C:\Documents and Settings\admin\Application Data\.zreglib
[2007/04/01 15:31:53 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/03/14 19:44:07 | 000,010,569 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2007/03/10 11:35:29 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2007/03/10 11:34:14 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2007/03/10 11:32:33 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/12/10 15:29:38 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/12/09 16:19:31 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/13 17:30:58 | 000,000,102 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2006/09/24 15:52:35 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/06/20 20:00:21 | 000,023,040 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/14 18:27:02 | 000,000,102 | —- | C] () – C:\WINDOWS\FASTYPE60.INI
[2005/11/05 18:20:46 | 000,001,247 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/10/11 15:35:02 | 000,000,128 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\fusioncache.dat
[2005/10/10 13:56:02 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2005/10/07 15:57:14 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/09/12 18:24:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/09 18:20:06 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/09 18:20:06 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/09/09 18:20:05 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/25 07:35:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/08/25 07:12:10 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/08/25 07:12:06 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/08/25 07:11:58 | 000,000,371 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 10:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 10:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 10:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 09:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 09:57:15 | 000,137,256 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 09:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 09:51:20 | 000,445,798 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 09:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 09:51:20 | 000,073,004 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 09:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 09:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 09:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 09:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 09:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 09:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 09:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 09:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 14:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2011/01/16 14:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Blackberry Desktop
[2011/01/16 14:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\C2OutlookExport
[2009/02/27 15:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Canon
[2010/07/06 19:22:51 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\CheckPoint
[2010/08/17 20:46:40 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ElevatedDiagnostics
[2010/07/25 20:45:11 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ESET
[2006/10/13 17:31:17 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Leadertech
[2007/05/08 17:37:40 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\MSNInstaller
[2007/07/20 05:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Musicmatch
[2007/03/10 22:58:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\NewSoft
[2007/03/10 23:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Opera
[2011/01/16 13:45:12 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Research In Motion
[2007/03/10 11:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ScanSoft
[2007/04/01 15:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\SlySoft
[2007/03/01 16:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Snapfish
[2011/01/02 21:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\VirtualStore
[2011/02/21 09:47:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2010/07/15 22:45:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Inspector
[2010/07/25 20:43:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2006/06/14 18:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FasType Software
[2011/01/16 13:42:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2007/03/10 11:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/04/01 15:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/12/06 05:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2012/02/12 05:50:57 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4BC30354-82BA-47A2-B4EF-23DF1DA65451}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2004/08/04 02:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SVCHOST.EXE >
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 02:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\i386\svchost.exe
[2004/08/04 02:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2004/08/04 02:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\i386\userinit.exe
[2004/08/04 02:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/04 02:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 02:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
========== Files - Unicode (All) ==========
[2010/04/09 12:45:58 | 000,228,864 | —- | M] ()(C:\Documents and Settings\admin\My Documents\R?ng Khóc Gi?a Mùa Xuân.doc) – C:\Documents and Settings\admin\My Documents\Rừng Khóc Giữa Mùa Xuân.doc
[2010/04/09 12:45:58 | 000,228,864 | —- | C] ()(C:\Documents and Settings\admin\My Documents\R?ng Khóc Gi?a Mùa Xuân.doc) – C:\Documents and Settings\admin\My Documents\Rừng Khóc Giữa Mùa Xuân.doc
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
< End of report >
OTL Extras logfile created on: 2/12/2012 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\FIx
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.09% Memory free
2.23 Gb Paging File | 1.58 Gb Available in Paging File | 71.13% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 16.27 Gb Free Space | 43.71% Space Free | Partition Type: NTFS
Computer Name: DDS2M981 | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [!ezcddaxa] – "C:\Program Files\Easy CD-DA Extractor 7\convert.exe" "%1" ()
Directory [!ezcddaxb] – "C:\Program Files\Easy CD-DA Extractor 7\burn.exe" "%1"
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4803" = CanoScan 4400F
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{25939878-8BE4-493A-BC68-D6E0AE0FDC72}" = Cox PC HealthCheck
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{307B9D04-A1F4-48EA-809C-DF7FA9C4BB6D}" = Presto! PageManager 7.15.13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51123D42-6B9C-4B93-900C-29F9EC5963C9}" = NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter
"{55A0CB85-F941-11D6-945B-00E09880E9D6}" = FasType Typing Tutorial 6
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B2AE2254-8133-4091-A671-E77BE909766C}" = CodeTwo OutlookExport
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}" = Windows Resource Kit Tools
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"BurnAware Free_is1" = BurnAware Free 3.3
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon CanoScan 4400F User Registration" = Canon CanoScan 4400F User Registration
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"CCleaner" = CCleaner
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 3.5
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.1.7
"EOS Utility" = Canon Utilities EOS Utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"MGI_PHOTOSUITE_SE_V10" = MGI PhotoSuite SE
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoStitch" = Canon Utilities PhotoStitch
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Samsung ML-2510 Series" = Samsung ML-2510 Series
"Text to Speech Maker_is1" = Text to Speech Maker version 1.3.5
"UniKey" = UniKey 4.0 NT
"Vpskeys_is1" = Vpskeys 4.3
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/28/2012 8:31:25 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:32:04 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:32:19 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:32:35 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:33:14 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:33:41 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 1/28/2012 8:35:49 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 2/2/2012 4:33:38 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 2/7/2012 4:46:37 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 2/11/2012 12:54:18 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
[ System Events ]
Error - 2/2/2012 4:33:32 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058
Error - 2/2/2012 4:33:32 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 2/2/2012 4:34:55 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).
Error - 2/2/2012 4:36:22 PM | Computer Name = DDS2M981 | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 2/7/2012 4:46:35 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058
Error - 2/7/2012 4:46:35 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 2/7/2012 4:48:20 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).
Error - 2/11/2012 12:54:12 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058
Error - 2/11/2012 12:54:12 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 2/11/2012 12:59:21 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).
< End of report >
07:43:33.0531 0948 TDSS rootkit removing tool [removed] Feb 9 2012 10:12:57
07:43:34.0109 0948 ============================================================
07:43:34.0109 0948 Current date / time: 2012/02/12 07:43:34.0109
07:43:34.0109 0948 SystemInfo:
07:43:34.0109 0948
07:43:34.0109 0948 OS Version: 5.1.2600 ServicePack: 3.0
07:43:34.0109 0948 Product type: Workstation
07:43:34.0109 0948 ComputerName: DDS2M981
07:43:34.0109 0948 UserName: admin
07:43:34.0109 0948 Windows directory: C:\WINDOWS
07:43:34.0109 0948 System windows directory: C:\WINDOWS
07:43:34.0109 0948 Processor architecture: Intel x86
07:43:34.0109 0948 Number of processors: 1
07:43:34.0109 0948 Page size: 0x1000
07:43:34.0109 0948 Boot type: Normal boot
07:43:34.0109 0948 ============================================================
07:43:36.0078 0948 Drive \Device\Harddisk0\DR0 - Size: 0x9502F9000 (37.25 Gb), SectorSize: 0x200, Cylinders: 0x12FF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
07:43:36.0078 0948 \Device\Harddisk0\DR0:
07:43:36.0078 0948 MBR used
07:43:36.0078 0948 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xFB04, BlocksNum 0x4A6DA7A
07:43:36.0125 0948 Initialize success
07:43:36.0125 0948 ============================================================
07:43:41.0843 3780 ============================================================
07:43:41.0843 3780 Scan started
07:43:41.0843 3780 Mode: Manual; TDLFS;
07:43:41.0843 3780 ============================================================
07:43:42.0234 3780 78561617 - ok
07:43:42.0265 3780 Abiosdsk - ok
07:43:42.0421 3780 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
07:43:42.0421 3780 abp480n5 - ok
07:43:42.0546 3780 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
07:43:42.0546 3780 ACPI - ok
07:43:42.0687 3780 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
07:43:42.0687 3780 ACPIEC - ok
07:43:42.0843 3780 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
07:43:42.0843 3780 adpu160m - ok
07:43:42.0984 3780 AE1000 (678c8fdb9d6094d41f322b7159853c54) C:\WINDOWS\system32\DRIVERS\AE1000XP.sys
07:43:42.0984 3780 AE1000 - ok
07:43:43.0125 3780 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
07:43:43.0125 3780 aeaudio - ok
07:43:43.0281 3780 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
07:43:43.0281 3780 aec - ok
07:43:43.0421 3780 AegisP (2c5c22990156a1063e19ad162191dc1d) C:\WINDOWS\system32\DRIVERS\AegisP.sys
07:43:43.0421 3780 AegisP - ok
07:43:43.0546 3780 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
07:43:43.0562 3780 AFD - ok
07:43:43.0687 3780 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
07:43:43.0687 3780 agp440 - ok
07:43:43.0828 3780 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
07:43:43.0828 3780 agpCPQ - ok
07:43:43.0968 3780 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
07:43:43.0968 3780 Aha154x - ok
07:43:44.0109 3780 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
07:43:44.0109 3780 aic78u2 - ok
07:43:44.0234 3780 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
07:43:44.0234 3780 aic78xx - ok
07:43:44.0375 3780 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
07:43:44.0390 3780 AliIde - ok
07:43:44.0531 3780 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
07:43:44.0531 3780 alim1541 - ok
07:43:44.0656 3780 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
07:43:44.0656 3780 amdagp - ok
07:43:44.0796 3780 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
07:43:44.0796 3780 amsint - ok
07:43:44.0937 3780 AR5523 (92637b97f57c1669d521a54482c4579c) C:\WINDOWS\system32\DRIVERS\wg11tnd5.sys
07:43:44.0953 3780 AR5523 - ok
07:43:45.0078 3780 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
07:43:45.0078 3780 asc - ok
07:43:45.0218 3780 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
07:43:45.0218 3780 asc3350p - ok
07:43:45.0359 3780 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
07:43:45.0359 3780 asc3550 - ok
07:43:45.0515 3780 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
07:43:45.0515 3780 AsyncMac - ok
07:43:45.0640 3780 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
07:43:45.0640 3780 atapi - ok
07:43:45.0734 3780 Atdisk - ok
07:43:45.0812 3780 ATHFMWDL - ok
07:43:45.0937 3780 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
07:43:45.0937 3780 Atmarpc - ok
07:43:46.0078 3780 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
07:43:46.0078 3780 audstub - ok
07:43:46.0140 3780 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
07:43:46.0140 3780 Beep - ok
07:43:46.0171 3780 catchme - ok
07:43:46.0312 3780 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
07:43:46.0312 3780 cbidf - ok
07:43:46.0437 3780 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
07:43:46.0437 3780 cbidf2k - ok
07:43:46.0546 3780 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
07:43:46.0546 3780 cd20xrnt - ok
07:43:46.0625 3780 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
07:43:46.0625 3780 Cdaudio - ok
07:43:46.0718 3780 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
07:43:46.0718 3780 Cdfs - ok
07:43:46.0843 3780 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
07:43:46.0843 3780 Cdrom - ok
07:43:46.0968 3780 cfwids (7fd604cd7a7a0ff8975af61bdf64c577) C:\WINDOWS\system32\drivers\cfwids.sys
07:43:46.0968 3780 cfwids - ok
07:43:47.0078 3780 Changer - ok
07:43:47.0156 3780 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
07:43:47.0156 3780 CmdIde - ok
07:43:47.0281 3780 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
07:43:47.0281 3780 Cpqarray - ok
07:43:47.0421 3780 cpuz132 - ok
07:43:47.0593 3780 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
07:43:47.0593 3780 dac2w2k - ok
07:43:47.0718 3780 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
07:43:47.0718 3780 dac960nt - ok
07:43:47.0812 3780 DgiVecp (770471de2550820feeb7e5d24bf2e273) C:\WINDOWS\system32\Drivers\DgiVecp.sys
07:43:47.0812 3780 DgiVecp - ok
07:43:47.0953 3780 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
07:43:47.0953 3780 Disk - ok
07:43:48.0109 3780 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
07:43:48.0109 3780 dmboot - ok
07:43:48.0265 3780 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
07:43:48.0265 3780 dmio - ok
07:43:48.0375 3780 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
07:43:48.0375 3780 dmload - ok
07:43:48.0515 3780 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
07:43:48.0515 3780 DMusic - ok
07:43:48.0593 3780 DNINDIS5 (d2ee54cdbced01d48f2b18642be79a98) C:\WINDOWS\system32\DNINDIS5.SYS
07:43:48.0593 3780 DNINDIS5 - ok
07:43:48.0765 3780 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
07:43:48.0765 3780 dpti2o - ok
07:43:48.0875 3780 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
07:43:48.0875 3780 drmkaud - ok
07:43:49.0015 3780 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
07:43:49.0015 3780 E100B - ok
07:43:49.0140 3780 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
07:43:49.0140 3780 Fastfat - ok
07:43:49.0281 3780 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
07:43:49.0281 3780 Fdc - ok
07:43:49.0421 3780 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
07:43:49.0421 3780 Fips - ok
07:43:49.0546 3780 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
07:43:49.0546 3780 Flpydisk - ok
07:43:49.0671 3780 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
07:43:49.0671 3780 FltMgr - ok
07:43:49.0843 3780 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
07:43:49.0843 3780 Fs_Rec - ok
07:43:49.0968 3780 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
07:43:49.0968 3780 Ftdisk - ok
07:43:50.0109 3780 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
07:43:50.0109 3780 Gpc - ok
07:43:50.0250 3780 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
07:43:50.0250 3780 HidUsb - ok
07:43:50.0343 3780 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
07:43:50.0343 3780 hpn - ok
07:43:50.0437 3780 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
07:43:50.0437 3780 HPZid412 - ok
07:43:50.0546 3780 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
07:43:50.0546 3780 HPZipr12 - ok
07:43:50.0656 3780 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
07:43:50.0656 3780 HPZius12 - ok
07:43:50.0734 3780 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
07:43:50.0734 3780 HTTP - ok
07:43:50.0890 3780 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
07:43:50.0890 3780 i2omgmt - ok
07:43:51.0046 3780 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
07:43:51.0046 3780 i2omp - ok
07:43:51.0109 3780 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
07:43:51.0109 3780 i8042prt - ok
07:43:51.0296 3780 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
07:43:51.0296 3780 ialm - ok
07:43:51.0421 3780 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
07:43:51.0421 3780 Imapi - ok
07:43:51.0578 3780 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
07:43:51.0578 3780 ini910u - ok
07:43:51.0703 3780 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
07:43:51.0703 3780 IntelIde - ok
07:43:51.0828 3780 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
07:43:51.0828 3780 intelppm - ok
07:43:51.0937 3780 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
07:43:51.0937 3780 Ip6Fw - ok
07:43:52.0078 3780 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
07:43:52.0078 3780 IpFilterDriver - ok
07:43:52.0171 3780 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
07:43:52.0171 3780 IpInIp - ok
07:43:52.0265 3780 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
07:43:52.0265 3780 IpNat - ok
07:43:52.0343 3780 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
07:43:52.0343 3780 IPSec - ok
07:43:52.0484 3780 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
07:43:52.0484 3780 IRENUM - ok
07:43:52.0609 3780 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
07:43:52.0609 3780 isapnp - ok
07:43:52.0734 3780 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
07:43:52.0734 3780 Kbdclass - ok
07:43:52.0843 3780 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
07:43:52.0843 3780 kbdhid - ok
07:43:52.0968 3780 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
07:43:52.0984 3780 kmixer - ok
07:43:53.0109 3780 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
07:43:53.0109 3780 KSecDD - ok
07:43:53.0218 3780 lbrtfdc - ok
07:43:53.0359 3780 MDC8021X (8fee53c104223973ed9919936d9cd156) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys
07:43:53.0359 3780 MDC8021X - ok
07:43:53.0500 3780 mfeapfk (688b626fca708ee9eb161cad1f7363a9) C:\WINDOWS\system32\drivers\mfeapfk.sys
07:43:53.0500 3780 mfeapfk - ok
07:43:53.0625 3780 mfeavfk (dbf6e1b388d5c070d438c61adb990c30) C:\WINDOWS\system32\drivers\mfeavfk.sys
07:43:53.0625 3780 mfeavfk - ok
07:43:53.0734 3780 mfeavfk01 - ok
07:43:53.0781 3780 mfebopk (a528b15e330edb83ea649be318d841d5) C:\WINDOWS\system32\drivers\mfebopk.sys
07:43:53.0781 3780 mfebopk - ok
07:43:53.0921 3780 mfefirek (c7da1b8003c89acedaa13768f7a1c622) C:\WINDOWS\system32\drivers\mfefirek.sys
07:43:53.0921 3780 mfefirek - ok
07:43:54.0062 3780 mfehidk (44184f32392fa2e94d08d056ce750d56) C:\WINDOWS\system32\drivers\mfehidk.sys
07:43:54.0078 3780 mfehidk - ok
07:43:54.0156 3780 mfendisk (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:43:54.0156 3780 mfendisk - ok
07:43:54.0171 3780 mfendiskmp (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:43:54.0171 3780 mfendiskmp - ok
07:43:54.0265 3780 mferkdet (ce1711f7c3f72f6762abd241dcfd5ee1) C:\WINDOWS\system32\drivers\mferkdet.sys
07:43:54.0265 3780 mferkdet - ok
07:43:54.0375 3780 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys
07:43:54.0375 3780 mferkdk - ok
07:43:54.0453 3780 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys
07:43:54.0453 3780 mfesmfk - ok
07:43:54.0578 3780 mfetdi2k (25e12c68b49a64ffc873603dfd578236) C:\WINDOWS\system32\drivers\mfetdi2k.sys
07:43:54.0578 3780 mfetdi2k - ok
07:43:54.0687 3780 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
07:43:54.0687 3780 mnmdd - ok
07:43:54.0828 3780 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
07:43:54.0828 3780 Modem - ok
07:43:55.0187 3780 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
07:43:55.0187 3780 Mouclass - ok
07:43:55.0328 3780 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
07:43:55.0328 3780 mouhid - ok
07:43:55.0484 3780 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
07:43:55.0500 3780 MountMgr - ok
07:43:55.0562 3780 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
07:43:55.0562 3780 mraid35x - ok
07:43:55.0656 3780 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
07:43:55.0656 3780 MRxDAV - ok
07:43:55.0796 3780 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
07:43:55.0796 3780 MRxSmb - ok
07:43:55.0921 3780 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
07:43:55.0937 3780 Msfs - ok
07:43:56.0046 3780 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
07:43:56.0046 3780 MSKSSRV - ok
07:43:56.0203 3780 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
07:43:56.0203 3780 MSPCLOCK - ok
07:43:56.0312 3780 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
07:43:56.0312 3780 MSPQM - ok
07:43:56.0437 3780 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
07:43:56.0437 3780 mssmbios - ok
07:43:56.0562 3780 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
07:43:56.0562 3780 Mup - ok
07:43:56.0703 3780 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
07:43:56.0703 3780 NDIS - ok
07:43:56.0812 3780 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
07:43:56.0812 3780 NdisTapi - ok
07:43:56.0953 3780 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
07:43:56.0968 3780 Ndisuio - ok
07:43:57.0109 3780 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
07:43:57.0109 3780 NdisWan - ok
07:43:57.0187 3780 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
07:43:57.0187 3780 NDProxy - ok
07:43:57.0265 3780 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
07:43:57.0265 3780 NetBIOS - ok
07:43:57.0328 3780 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
07:43:57.0328 3780 NetBT - ok
07:43:57.0453 3780 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
07:43:57.0468 3780 Npfs - ok
07:43:57.0609 3780 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
07:43:57.0609 3780 Ntfs - ok
07:43:57.0718 3780 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
07:43:57.0734 3780 Null - ok
07:43:57.0953 3780 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
07:43:57.0968 3780 nv - ok
07:43:58.0046 3780 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
07:43:58.0046 3780 NwlnkFlt - ok
07:43:58.0125 3780 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
07:43:58.0125 3780 NwlnkFwd - ok
07:43:58.0218 3780 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
07:43:58.0218 3780 Parport - ok
07:43:58.0359 3780 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
07:43:58.0359 3780 PartMgr - ok
07:43:58.0500 3780 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
07:43:58.0500 3780 ParVdm - ok
07:43:58.0562 3780 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
07:43:58.0562 3780 PCI - ok
07:43:58.0687 3780 PCIDump - ok
07:43:58.0796 3780 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
07:43:58.0796 3780 PCIIde - ok
07:43:58.0921 3780 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
07:43:58.0921 3780 Pcmcia - ok
07:43:59.0015 3780 PDCOMP - ok
07:43:59.0078 3780 PDFRAME - ok
07:43:59.0140 3780 PDRELI - ok
07:43:59.0187 3780 PDRFRAME - ok
07:43:59.0250 3780 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
07:43:59.0250 3780 perc2 - ok
07:43:59.0328 3780 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
07:43:59.0328 3780 perc2hib - ok
07:43:59.0437 3780 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
07:43:59.0437 3780 PptpMiniport - ok
07:43:59.0578 3780 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
07:43:59.0578 3780 PSched - ok
07:43:59.0687 3780 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
07:43:59.0687 3780 Ptilink - ok
07:43:59.0828 3780 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
07:43:59.0828 3780 ql1080 - ok
07:43:59.0906 3780 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
07:43:59.0906 3780 Ql10wnt - ok
07:43:59.0984 3780 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
07:43:59.0984 3780 ql12160 - ok
07:44:00.0062 3780 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
07:44:00.0062 3780 ql1240 - ok
07:44:00.0140 3780 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
07:44:00.0140 3780 ql1280 - ok
07:44:00.0187 3780 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
07:44:00.0187 3780 RasAcd - ok
07:44:00.0250 3780 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
07:44:00.0265 3780 Rasl2tp - ok
07:44:00.0421 3780 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
07:44:00.0421 3780 RasPppoe - ok
07:44:00.0546 3780 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
07:44:00.0546 3780 Raspti - ok
07:44:00.0609 3780 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
07:44:00.0609 3780 Rdbss - ok
07:44:00.0718 3780 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
07:44:00.0718 3780 RDPCDD - ok
07:44:00.0875 3780 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
07:44:00.0890 3780 rdpdr - ok
07:44:01.0000 3780 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
07:44:01.0000 3780 RDPWD - ok
07:44:01.0125 3780 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
07:44:01.0125 3780 redbook - ok
07:44:01.0218 3780 RimUsb (92d33f76769a028ddc54a863eb7de4a2) C:\WINDOWS\system32\Drivers\RimUsb.sys
07:44:01.0218 3780 RimUsb - ok
07:44:01.0328 3780 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
07:44:01.0328 3780 RimVSerPort - ok
07:44:01.0468 3780 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
07:44:01.0468 3780 ROOTMODEM - ok
07:44:01.0578 3780 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
07:44:01.0578 3780 Secdrv - ok
07:44:01.0703 3780 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
07:44:01.0703 3780 serenum - ok
07:44:01.0796 3780 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
07:44:01.0796 3780 Serial - ok
07:44:01.0921 3780 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
07:44:01.0921 3780 Sfloppy - ok
07:44:02.0000 3780 Simbad - ok
07:44:02.0078 3780 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
07:44:02.0078 3780 sisagp - ok
07:44:02.0187 3780 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
07:44:02.0187 3780 smwdm - ok
07:44:02.0328 3780 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
07:44:02.0343 3780 Sparrow - ok
07:44:02.0453 3780 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
07:44:02.0453 3780 splitter - ok
07:44:02.0609 3780 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
07:44:02.0609 3780 sr - ok
07:44:02.0750 3780 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
07:44:02.0765 3780 Srv - ok
07:44:02.0859 3780 SSPORT - ok
07:44:02.0953 3780 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
07:44:02.0953 3780 swenum - ok
07:44:03.0078 3780 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
07:44:03.0078 3780 swmidi - ok
07:44:03.0250 3780 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
07:44:03.0250 3780 symc810 - ok
07:44:03.0421 3780 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
07:44:03.0421 3780 symc8xx - ok
07:44:03.0515 3780 SYMDNS (1f0a3f93fecba6e873e75ac34538708b) C:\WINDOWS\System32\Drivers\SYMDNS.SYS
07:44:03.0515 3780 SYMDNS - ok
07:44:03.0640 3780 SymEvent (b6020caf9ea58532dd78490a3f28ead2) C:\Program Files\Symantec\SYMEVENT.SYS
07:44:03.0640 3780 SymEvent - ok
07:44:03.0734 3780 SYMFW (ca212638c07f7a1736667319589f416e) C:\WINDOWS\System32\Drivers\SYMFW.SYS
07:44:03.0734 3780 SYMFW - ok
07:44:03.0828 3780 SYMIDS (83a0415ab669afe9f2b7fccc52f23153) C:\WINDOWS\System32\Drivers\SYMIDS.SYS
07:44:03.0828 3780 SYMIDS - ok
07:44:03.0953 3780 SYMNDIS (2a8ebb694d702d91d8046b31c3da2220) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS
07:44:03.0953 3780 SYMNDIS - ok
07:44:04.0046 3780 SYMREDRV (7c73b65f1bdfab9052a5076c0ca622de) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
07:44:04.0046 3780 SYMREDRV - ok
07:44:04.0187 3780 SYMTDI (b4562798891dca27ed67ca07acbadbd9) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
07:44:04.0187 3780 SYMTDI - ok
07:44:04.0328 3780 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
07:44:04.0328 3780 sym_hi - ok
07:44:04.0437 3780 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
07:44:04.0437 3780 sym_u3 - ok
07:44:04.0515 3780 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
07:44:04.0515 3780 sysaudio - ok
07:44:04.0671 3780 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
07:44:04.0671 3780 Tcpip - ok
07:44:04.0812 3780 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
07:44:04.0812 3780 TDPIPE - ok
07:44:04.0953 3780 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
07:44:04.0953 3780 TDTCP - ok
07:44:05.0078 3780 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
07:44:05.0078 3780 TermDD - ok
07:44:05.0234 3780 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
07:44:05.0234 3780 TosIde - ok
07:44:05.0390 3780 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
07:44:05.0390 3780 Udfs - ok
07:44:05.0515 3780 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
07:44:05.0515 3780 ultra - ok
07:44:05.0656 3780 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
07:44:05.0656 3780 Update - ok
07:44:05.0812 3780 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
07:44:05.0812 3780 usbccgp - ok
07:44:05.0921 3780 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
07:44:05.0921 3780 usbehci - ok
07:44:06.0000 3780 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
07:44:06.0000 3780 usbhub - ok
07:44:06.0125 3780 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
07:44:06.0125 3780 usbprint - ok
07:44:06.0187 3780 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
07:44:06.0187 3780 usbscan - ok
07:44:06.0312 3780 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
07:44:06.0312 3780 USBSTOR - ok
07:44:06.0406 3780 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
07:44:06.0406 3780 usbuhci - ok
07:44:06.0531 3780 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
07:44:06.0531 3780 VgaSave - ok
07:44:06.0625 3780 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
07:44:06.0640 3780 viaagp - ok
07:44:06.0750 3780 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
07:44:06.0750 3780 ViaIde - ok
07:44:06.0859 3780 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
07:44:06.0859 3780 VolSnap - ok
07:44:07.0031 3780 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
07:44:07.0031 3780 Wanarp - ok
07:44:07.0187 3780 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
07:44:07.0203 3780 Wdf01000 - ok
07:44:07.0250 3780 WDICA - ok
07:44:07.0328 3780 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
07:44:07.0328 3780 wdmaud - ok
07:44:07.0546 3780 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
07:44:07.0546 3780 WS2IFSL - ok
07:44:07.0640 3780 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
07:44:07.0640 3780 WudfPf - ok
07:44:07.0750 3780 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
07:44:07.0750 3780 WudfRd - ok
07:44:07.0828 3780 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
07:44:08.0015 3780 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
07:44:08.0015 3780 \Device\Harddisk0\DR0 - detected TDSS File System (1)
07:44:08.0046 3780 Boot (0x1200) (b23db40eceaa734a8b47dd772979f475) \Device\Harddisk0\DR0\Partition0
07:44:08.0046 3780 \Device\Harddisk0\DR0\Partition0 - ok
07:44:08.0046 3780 ============================================================
07:44:08.0046 3780 Scan finished
07:44:08.0046 3780 ============================================================
07:44:08.0078 0808 Detected object count: 1
07:44:08.0078 0808 Actual detected object count: 1
07:44:16.0437 0808 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
07:44:16.0437 0808 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
07:44:38.0187 2736 Deinitialize success