This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Got a spooler subsystem error and now anything usb doesn't work [C

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I tried printing and got a spooler subsystem error. Now there is no printer showing up and all usb devices that are plugged in are recognized but can't be browsed. Saw that it could be a virus so I'm running some virus scans right now.
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
Hi b16d8dd4,

I noticed you said you have been running some virus scans. Please refrain from running any anti-virus/spyware/malware scans of your own until I confirm your computer is all-clean. Until then, please only use the tools as I direct you.

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.

  • DDS

    Please download DDS and save it to your desktop.

    • Disable any script blocking protection.
    • Double click dds.scr to run the tool.
    • When done, DDS.txt will open.
    • Save both reports to your desktop.
    —————————————————

    Please copy / paste the scan results of DDS.txt

    Please attach the second file; Attach.txt. To attach a file, do the following:
    • Under the reply panel is the Attachments Panel
    • Browse for the attachment file you want to upload, then click the green Upload button
    • Once it has uploaded, click the Manage Current Attachments drop down box
    • Click on [external image: Posted Image] to insert the attachment into your post
  • aswMBR

    Please download aswMBR and save it to your desktop.

    • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
    • When prompted to download virus definitions, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
    • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 17:50:27.26 on Sat 02/11/2012 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1480 [GMT -8:00] . AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Disabled* FW: ZoneAlarm Firewall *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\WINDOWS\system32\mfevtps.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Vpskeys\VPSKEYS.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\admin\My Documents\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/ uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20111216172118.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll uRun: [VPSKEYS] c:\program files\vpskeys\VPSKEYS.EXE uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\admin\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\SSMMgr.exe /autorun mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\admin\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\admin\startm~1\programs\startup\coxpch~1.lnk - c:\program files\cox, inc\cox pc healthcheck\DesktopClient.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111t\wlan111t.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {3C34EBD2-038D-4d4f-B081-16D99D8BE2B4} - {361D6100-9833-4ABA-BB50-7015F325BBF0} - c:\windows\downloaded program files\IEPrint.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: IEPrint - hxxp://www.visiontech.ltd.uk/software/download/IEPrint.CAB DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {F9CD2233-6744-47C1-A6AE-00C30A35F73D} - hxxps://myaccount.cox.net/internettools/scripts/Inspector.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\bqo97wwp.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;= FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p;= FF - plugin: c:\documents and settings\admin\local settings\application data\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll FF - plugin: c:\program files\microsoft silverlight\4.0.51204.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPCIG.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 459728] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-12-16 84200] R2 COX CommunicationsMonitoringService;COX Communications Monitoring Service;c:\program files\cox, inc\cox pc healthcheck\PCMonitoringService.exe [2010-11-17 14456] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-12-16 271480] R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-12-16 271480] R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-12-16 271480] R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-12-16 271480] R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-12-16 171168] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-12-16 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-12-16 148520] R3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2011-2-21 816672] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-12-16 56064] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-22 153280] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-12-16 314088] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-12-16 88736] S0 78561617;78561617;c:\windows\system32\drivers\09465183.sys –> c:\windows\system32\drivers\09465183.sys [?] S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys –> c:\windows\system32\drivers\SSPORT.sys [?] S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\drivers\athfmwdl.sys –> c:\windows\system32\drivers\ATHFMWDL.sys [?] S3 cpuz132;cpuz132;\??\c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\admin\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2005-9-9 17149] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-22 52320] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-12-16 88736] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-12-16 84488] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-22 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-22 40552] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-10 14336] . =============== Created Last 30 ================ . 2012-01-17 03:04:37 ——– dcs—w- C:\ComboFix 2012-01-17 01:13:55 73728 —-a-w- c:\windows\system32\javacpl.cpl 2012-01-17 01:13:55 476904 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2012-01-17 01:13:55 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-01-16 00:39:56 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-16 00:39:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-01-15 23:24:32 ——– dcsha-r- C:\cmdcons . ==================== Find3M ==================== . 2011-11-25 21:57:19 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-18 12:35:08 60416 —-a-w- c:\windows\system32\packager.exe 2011-11-16 14:21:44 354816 —-a-w- c:\windows\system32\winhttp.dll 2011-11-16 14:21:44 152064 —-a-w- c:\windows\system32\schannel.dll 1956-09-09 16:26:23 3198976 -c–a-w- c:\program files\ViewSonicregistration.exe . ============= FINISH: 17:51:42.46 =============== 📎Attach.txt aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software Run date: 2012-02-11 17:57:42 —————————– 17:57:42.234 OS Version: Windows 5.1.2600 Service Pack 3 17:57:42.234 Number of processors: 1 586 0x401 17:57:42.234 ComputerName: DDS2M981 UserName: admin 17:57:43.140 Initialize success 18:19:05.281 AVAST engine defs: 12021101 18:25:50.968 The log file has been saved successfully to "C:\Documents and Settings\admin\Desktop\aswMBR.txt"
  • OTL

    Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]TDSSKiller


Please download TDSSKiller.zip

  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • As we are only looking for a log of what is on the machine right now > choose to skip whatever is found
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
OTL logfile created on: 2/12/2012 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\FIx
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.09% Memory free
2.23 Gb Paging File | 1.58 Gb Available in Paging File | 71.13% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 16.27 Gb Free Space | 43.71% Space Free | Partition Type: NTFS

Computer Name: DDS2M981 | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/12 07:24:42 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\FIx\OTL.exe
PRC - [2012/01/19 21:35:36 | 001,047,024 | —- | M] (Google Inc.) – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/09/23 20:46:28 | 001,195,408 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/04/15 07:12:37 | 000,618,496 | —- | M] () – C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
PRC - [2011/04/14 14:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/04/14 14:01:38 | 000,171,168 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/03/13 11:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/11/17 06:56:09 | 000,014,456 | —- | M] (PlumChoice, Inc.) – C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe
PRC - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2006/03/21 13:19:40 | 000,069,632 | —- | M] (ScanSoft, Inc.) – C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
PRC - [2006/01/25 15:49:02 | 000,884,840 | —- | M] (NETGEAR) – C:\Program Files\NETGEAR\WG111T\wlan111t.exe
PRC - [2005/09/11 19:58:45 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2003/03/29 11:52:02 | 000,102,400 | —- | M] (Hoi Chuyen Gia Viet Nam) – C:\Program Files\Vpskeys\VPSKEYS.EXE


========== Modules (No Company Name) ==========

MOD - [2012/01/19 21:35:35 | 000,411,120 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll
MOD - [2012/01/19 21:35:34 | 003,767,792 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
MOD - [2012/01/19 21:34:10 | 000,122,880 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avutil-51.dll
MOD - [2012/01/19 21:34:09 | 000,222,208 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avformat-53.dll
MOD - [2012/01/19 21:34:07 | 001,746,432 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\avcodec-53.dll
MOD - [2012/01/19 18:14:40 | 008,593,056 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
MOD - [2011/12/31 03:10:48 | 011,817,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\62e34cfb5a8b233667c7c5a47a32ad93\System.Web.ni.dll
MOD - [2011/12/31 03:03:28 | 000,372,736 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
MOD - [2011/12/31 03:03:25 | 000,303,104 | —- | M] () – C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2011/10/12 02:21:18 | 000,212,992 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll
MOD - [2011/10/12 02:18:20 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll
MOD - [2011/10/12 02:15:05 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll
MOD - [2011/10/12 02:12:04 | 007,950,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll
MOD - [2011/10/12 02:11:27 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/04/15 07:12:37 | 000,618,496 | —- | M] () – C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
MOD - [2010/11/17 06:56:12 | 000,041,080 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\CLISharedInterfaces.dll
MOD - [2010/11/17 06:46:27 | 000,045,688 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\DetectionExtension.dxt
MOD - [2010/11/17 06:12:34 | 000,247,416 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\OESISCore.dll
MOD - [2010/11/17 06:02:23 | 000,155,648 | —- | M] () – C:\Program Files\Cox, Inc\Cox PC HealthCheck\SmartDisk.dll
MOD - [2003/03/29 12:03:22 | 000,069,632 | —- | M] () – C:\Program Files\Vpskeys\VPSKM32.DLL
MOD - [2003/03/29 11:51:44 | 000,061,440 | —- | M] () – C:\Program Files\Vpskeys\VPSKH32.DLL
MOD - [2003/03/29 11:51:26 | 000,098,304 | —- | M] () – C:\Program Files\Vpskeys\VPSVNL32.DLL
MOD - [2001/09/07 20:53:10 | 000,100,864 | —- | M] () – C:\Program Files\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/04/14 14:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2011/04/14 14:01:38 | 000,171,168 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/03/13 11:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2010/11/17 06:56:09 | 000,014,456 | —- | M] (PlumChoice, Inc.) [Auto | Running] – C:\Program Files\Cox, Inc\Cox PC HealthCheck\PCMonitoringService.exe – (COX CommunicationsMonitoringService)
SRV - [2010/10/07 20:34:28 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/07/26 15:01:58 | 000,066,112 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll – (nosGetPlusHelper) getPlus®
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2010/03/10 10:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2008/11/07 18:55:30 | 000,026,144 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\system32\spupdsvc.exe – (spupdsvc)
SRV - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)
SRV - [2005/04/05 10:17:22 | 000,206,552 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) [Disabled | Stopped] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2003/03/03 10:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - [2011/04/14 14:01:38 | 000,314,088 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/04/14 14:01:38 | 000,153,280 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/04/14 14:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/04/14 14:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/04/14 14:01:38 | 000,084,488 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/04/14 14:01:38 | 000,084,200 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/04/14 14:01:38 | 000,056,064 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/04/14 14:01:38 | 000,052,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/03/13 11:20:10 | 000,459,728 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/03/13 11:20:10 | 000,118,784 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/03/22 22:53:12 | 000,816,672 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AE1000XP.sys – (AE1000)
DRV - [2010/02/17 15:52:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 09:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2006/06/11 17:06:28 | 000,041,984 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\DGIVECP.SYS – (DgiVecp)
DRV - [2005/09/09 18:20:15 | 000,015,890 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2005/09/05 11:21:06 | 000,362,944 | —- | M] (NETGEAR, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WG11TND5.sys – (AR5523)
DRV - [2005/07/28 13:52:18 | 000,123,712 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent)
DRV - [2005/04/05 10:17:02 | 000,267,192 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2005/04/05 10:17:00 | 000,017,976 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2005/04/05 10:16:58 | 000,036,984 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2005/04/05 10:16:56 | 000,047,192 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2005/04/05 10:16:54 | 000,173,208 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2005/04/05 10:16:52 | 000,011,512 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2003/07/24 11:10:34 | 000,017,149 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\DNINDIS5.sys – (DNINDIS5)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:4619

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:4619



IE - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=BABTDF&PC;=BBLN&q;="
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {926a10d2-4ce7-4331-b96f-ca4e22590fac}:[removed]
FF - prefs.js..extensions.enabledItems: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2105: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2163: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1212: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/12/17 17:31:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/27 20:24:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/16 17:13:55 | 000,000,000 | —D | M]

[2010/07/31 13:03:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Extensions
[2011/12/29 07:43:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions
[2010/07/31 14:04:23 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/02 21:46:46 | 000,000,000 | —D | M] (D-Link Toolbar) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{926a10d2-4ce7-4331-b96f-ca4e22590fac}
[2010/08/15 19:10:56 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/12/29 07:43:19 | 000,000,000 | —D | M] (samfind Bookmarks Bar) – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\extensions\[removed]
[2010/07/31 14:04:32 | 000,001,832 | —- | M] () – C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\bqo97wwp.default\searchplugins\bing.xml
[2012/01/16 17:13:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/01/16 17:13:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2011/12/20 23:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll
[2008/06/19 01:16:24 | 000,118,784 | —- | M] (CANON INC.) – C:\Program Files\mozilla firefox\plugins\MyCamera.dll
[2008/06/19 01:16:24 | 000,053,248 | —- | M] (CANON INC.) – C:\Program Files\mozilla firefox\plugins\NPCIG.dll
[2012/01/16 17:13:35 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 20:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/09 05:22:03 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011/12/20 20:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url = http://www.bing.com/search?setmkt=en-US&q;={searchTerms}
CHR - default_search_provider: suggest_url = http://api.bing.com/osjson.aspx?query={sea…uage={language}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Canon Online Photo Plugin Module (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPCIG.dll
CHR - plugin: getPlusPlus for Adobe 16287 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\admin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/16 16:46:21 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111216172118.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006..\Run: [VPSKEYS] C:\Program Files\Vpskeys\VPSKEYS.EXE (Hoi Chuyen Gia Viet Nam)
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\Cox PC HealthCheck.lnk = C:\Program Files\Cox, Inc\Cox PC HealthCheck\DesktopClient.exe (PlumChoice, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111T\wlan111t.exe (NETGEAR)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Fit-width Print - {3C34EBD2-038D-4d4f-B081-16D99D8BE2B4} - C:\WINDOWS\Downloaded Program Files\IEPrint.dll ()
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www.costcophotocenter.com/CostcoActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1005.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F9CD2233-6744-47C1-A6AE-00C30A35F73D} https://myaccount.cox.net/internettools/scr…s/Inspector.cab (CAssessmentCtl Object)
O16 - DPF: IEPrint http://www.visiontech.ltd.uk/software/download/IEPrint.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DD33601-AA8D-4591-81C9-1C1A22964F53}: DhcpNameServer = 192.168.1.1 [removed] [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://www.baby-g.com/resource/images/prod…9R-8_medium.png
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 10:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/11 18:29:21 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\FIx
[2012/02/11 08:54:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/01/16 19:04:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\admin\Recent
[2012/01/16 19:04:37 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/01/16 17:14:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/16 17:12:41 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/01/16 17:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Sun
[2012/01/16 17:04:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2012/01/16 16:56:06 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/01/15 16:39:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/15 16:39:56 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/15 16:39:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/15 15:24:32 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/01/15 12:39:47 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/01/14 08:47:24 | 001,972,528 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\admin\Desktop\TDSSKiller.exe
[2006/10/14 17:17:42 | 003,198,976 | —- | C] (Leader Technologies/ViewSonic) – C:\Program Files\ViewSonicregistration.exe

========== Files - Modified Within 30 Days ==========

[2012/02/12 07:28:03 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006UA.job
[2012/02/12 05:50:57 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{4BC30354-82BA-47A2-B4EF-23DF1DA65451}.job
[2012/02/11 18:28:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1649451728-3284657741-3551875713-1006Core.job
[2012/02/11 08:54:46 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/11 08:54:12 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2012/02/11 08:54:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/11 08:54:05 | 2145,439,744 | -HS- | M] () – C:\hiberfil.sys
[2012/01/24 16:25:13 | 000,002,262 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/24 16:25:12 | 000,002,284 | —- | M] () – C:\Documents and Settings\admin\Desktop\Google Chrome.lnk
[2012/01/16 17:03:32 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/16 16:46:21 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/15 16:39:57 | 000,000,802 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/15 15:24:45 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/01/15 13:46:31 | 000,445,798 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/01/15 13:46:31 | 000,073,004 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/01/13 16:07:33 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/13 15:24:32 | 001,972,528 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\admin\Desktop\TDSSKiller.exe

========== Files Created - No Company Name ==========

[2012/01/16 17:03:32 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/16 17:03:32 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/15 16:39:57 | 000,000,802 | —- | C] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/01/15 15:24:44 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/01/15 15:24:40 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/01/14 07:27:46 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/11/28 09:35:43 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/27 09:53:24 | 000,485,240 | —- | C] () – C:\WINDOWS\ssndii.exe
[2011/11/24 06:37:25 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/11/24 06:37:25 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/05/25 19:01:00 | 000,000,166 | —- | C] () – C:\Documents and Settings\admin\Application Data\burnaware.ini
[2011/02/21 09:50:28 | 000,013,931 | R— | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/02/19 18:24:33 | 000,149,392 | —- | C] () – C:\WINDOWS\System32\drivers\ar5523.bin
[2011/01/24 10:06:13 | 000,385,016 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/06 19:21:22 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2008/05/17 19:57:45 | 000,001,160 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/04/01 15:46:57 | 000,000,048 | -HS- | C] () – C:\Documents and Settings\admin\Application Data\.zreglib
[2007/04/01 15:31:53 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/03/14 19:44:07 | 000,010,569 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2007/03/10 11:35:29 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2007/03/10 11:34:14 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2007/03/10 11:32:33 | 000,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/12/10 15:29:38 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/12/09 16:19:31 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/13 17:30:58 | 000,000,102 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2006/09/24 15:52:35 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/06/20 20:00:21 | 000,023,040 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/14 18:27:02 | 000,000,102 | —- | C] () – C:\WINDOWS\FASTYPE60.INI
[2005/11/05 18:20:46 | 000,001,247 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/10/11 15:35:02 | 000,000,128 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\fusioncache.dat
[2005/10/10 13:56:02 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2005/10/07 15:57:14 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/09/12 18:24:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/09 18:20:06 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/09 18:20:06 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/09/09 18:20:05 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/25 07:35:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/08/25 07:12:10 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005/08/25 07:12:06 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/08/25 07:11:58 | 000,000,371 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 10:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 10:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 10:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 09:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 09:57:15 | 000,137,256 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 09:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 09:51:20 | 000,445,798 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 09:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 09:51:20 | 000,073,004 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 09:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 09:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 09:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 09:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 09:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 09:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 09:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 09:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 14:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2011/01/16 14:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Blackberry Desktop
[2011/01/16 14:29:00 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\C2OutlookExport
[2009/02/27 15:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Canon
[2010/07/06 19:22:51 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\CheckPoint
[2010/08/17 20:46:40 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ElevatedDiagnostics
[2010/07/25 20:45:11 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ESET
[2006/10/13 17:31:17 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Leadertech
[2007/05/08 17:37:40 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\MSNInstaller
[2007/07/20 05:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Musicmatch
[2007/03/10 22:58:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\NewSoft
[2007/03/10 23:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Opera
[2011/01/16 13:45:12 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Research In Motion
[2007/03/10 11:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\ScanSoft
[2007/04/01 15:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\SlySoft
[2007/03/01 16:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Snapfish
[2011/01/02 21:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\VirtualStore
[2011/02/21 09:47:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2010/07/15 22:45:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Inspector
[2010/07/25 20:43:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2006/06/14 18:27:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FasType Software
[2011/01/16 13:42:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2007/03/10 11:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/04/01 15:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/12/06 05:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\SACore
[2012/02/12 05:50:57 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4BC30354-82BA-47A2-B4EF-23DF1DA65451}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2004/08/04 02:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/13 16:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/04 02:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\i386\svchost.exe
[2004/08/04 02:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 02:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\i386\userinit.exe
[2004/08/04 02:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/13 16:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 02:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 02:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2011/12/24 17:50:20 | 000,182,856 | —- | M] () MD5=B382935AB01B27D0E14F267DBF288896 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Files - Unicode (All) ==========
[2010/04/09 12:45:58 | 000,228,864 | —- | M] ()(C:\Documents and Settings\admin\My Documents\R?ng Khóc Gi?a Mùa Xuân.doc) – C:\Documents and Settings\admin\My Documents\Rừng Khóc Giữa Mùa Xuân.doc
[2010/04/09 12:45:58 | 000,228,864 | —- | C] ()(C:\Documents and Settings\admin\My Documents\R?ng Khóc Gi?a Mùa Xuân.doc) – C:\Documents and Settings\admin\My Documents\Rừng Khóc Giữa Mùa Xuân.doc

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

< End of report >


OTL Extras logfile created on: 2/12/2012 7:27:02 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\admin\Desktop\FIx
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.09% Memory free
2.23 Gb Paging File | 1.58 Gb Available in Paging File | 71.13% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 16.27 Gb Free Space | 43.71% Space Free | Partition Type: NTFS

Computer Name: DDS2M981 | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [!ezcddaxa] – "C:\Program Files\Easy CD-DA Extractor 7\convert.exe" "%1" ()
Directory [!ezcddaxb] – "C:\Program Files\Easy CD-DA Extractor 7\burn.exe" "%1"
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4803" = CanoScan 4400F
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{25939878-8BE4-493A-BC68-D6E0AE0FDC72}" = Cox PC HealthCheck
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{307B9D04-A1F4-48EA-809C-DF7FA9C4BB6D}" = Presto! PageManager 7.15.13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51123D42-6B9C-4B93-900C-29F9EC5963C9}" = NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter
"{55A0CB85-F941-11D6-945B-00E09880E9D6}" = FasType Typing Tutorial 6
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B2AE2254-8133-4091-A671-E77BE909766C}" = CodeTwo OutlookExport
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}" = Windows Resource Kit Tools
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"BurnAware Free_is1" = BurnAware Free 3.3
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon CanoScan 4400F User Registration" = Canon CanoScan 4400F User Registration
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"CCleaner" = CCleaner
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 3.5
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.1.7
"EOS Utility" = Canon Utilities EOS Utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"MGI_PHOTOSUITE_SE_V10" = MGI PhotoSuite SE
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoStitch" = Canon Utilities PhotoStitch
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Samsung ML-2510 Series" = Samsung ML-2510 Series
"Text to Speech Maker_is1" = Text to Speech Maker version 1.3.5
"UniKey" = UniKey 4.0 NT
"Vpskeys_is1" = Vpskeys 4.3
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1649451728-3284657741-3551875713-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/28/2012 8:31:25 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:32:04 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:32:19 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:32:35 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:33:14 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:33:41 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 1/28/2012 8:35:49 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application spoolsv.exe, version 5.1.2600.6024, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 2/2/2012 4:33:38 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 2/7/2012 4:46:37 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 2/11/2012 12:54:18 PM | Computer Name = DDS2M981 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 2/2/2012 4:33:32 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058

Error - 2/2/2012 4:33:32 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 2/2/2012 4:34:55 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).

Error - 2/2/2012 4:36:22 PM | Computer Name = DDS2M981 | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 2/7/2012 4:46:35 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058

Error - 2/7/2012 4:46:35 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 2/7/2012 4:48:20 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).

Error - 2/11/2012 12:54:12 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7001
Description = The Windows Service Pack Installer update service service depends
on the Security Accounts Manager service which failed to start because of the following
error: %%1058

Error - 2/11/2012 12:54:12 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 2/11/2012 12:59:21 PM | Computer Name = DDS2M981 | Source = Service Control Manager | ID = 7034
Description = The Print Spooler service terminated unexpectedly. It has done this
1 time(s).


< End of report >

07:43:33.0531 0948 TDSS rootkit removing tool [removed] Feb 9 2012 10:12:57
07:43:34.0109 0948 ============================================================
07:43:34.0109 0948 Current date / time: 2012/02/12 07:43:34.0109
07:43:34.0109 0948 SystemInfo:
07:43:34.0109 0948
07:43:34.0109 0948 OS Version: 5.1.2600 ServicePack: 3.0
07:43:34.0109 0948 Product type: Workstation
07:43:34.0109 0948 ComputerName: DDS2M981
07:43:34.0109 0948 UserName: admin
07:43:34.0109 0948 Windows directory: C:\WINDOWS
07:43:34.0109 0948 System windows directory: C:\WINDOWS
07:43:34.0109 0948 Processor architecture: Intel x86
07:43:34.0109 0948 Number of processors: 1
07:43:34.0109 0948 Page size: 0x1000
07:43:34.0109 0948 Boot type: Normal boot
07:43:34.0109 0948 ============================================================
07:43:36.0078 0948 Drive \Device\Harddisk0\DR0 - Size: 0x9502F9000 (37.25 Gb), SectorSize: 0x200, Cylinders: 0x12FF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
07:43:36.0078 0948 \Device\Harddisk0\DR0:
07:43:36.0078 0948 MBR used
07:43:36.0078 0948 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xFB04, BlocksNum 0x4A6DA7A
07:43:36.0125 0948 Initialize success
07:43:36.0125 0948 ============================================================
07:43:41.0843 3780 ============================================================
07:43:41.0843 3780 Scan started
07:43:41.0843 3780 Mode: Manual; TDLFS;
07:43:41.0843 3780 ============================================================
07:43:42.0234 3780 78561617 - ok
07:43:42.0265 3780 Abiosdsk - ok
07:43:42.0421 3780 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
07:43:42.0421 3780 abp480n5 - ok
07:43:42.0546 3780 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
07:43:42.0546 3780 ACPI - ok
07:43:42.0687 3780 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
07:43:42.0687 3780 ACPIEC - ok
07:43:42.0843 3780 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
07:43:42.0843 3780 adpu160m - ok
07:43:42.0984 3780 AE1000 (678c8fdb9d6094d41f322b7159853c54) C:\WINDOWS\system32\DRIVERS\AE1000XP.sys
07:43:42.0984 3780 AE1000 - ok
07:43:43.0125 3780 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
07:43:43.0125 3780 aeaudio - ok
07:43:43.0281 3780 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
07:43:43.0281 3780 aec - ok
07:43:43.0421 3780 AegisP (2c5c22990156a1063e19ad162191dc1d) C:\WINDOWS\system32\DRIVERS\AegisP.sys
07:43:43.0421 3780 AegisP - ok
07:43:43.0546 3780 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
07:43:43.0562 3780 AFD - ok
07:43:43.0687 3780 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
07:43:43.0687 3780 agp440 - ok
07:43:43.0828 3780 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
07:43:43.0828 3780 agpCPQ - ok
07:43:43.0968 3780 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
07:43:43.0968 3780 Aha154x - ok
07:43:44.0109 3780 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
07:43:44.0109 3780 aic78u2 - ok
07:43:44.0234 3780 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
07:43:44.0234 3780 aic78xx - ok
07:43:44.0375 3780 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
07:43:44.0390 3780 AliIde - ok
07:43:44.0531 3780 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
07:43:44.0531 3780 alim1541 - ok
07:43:44.0656 3780 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
07:43:44.0656 3780 amdagp - ok
07:43:44.0796 3780 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
07:43:44.0796 3780 amsint - ok
07:43:44.0937 3780 AR5523 (92637b97f57c1669d521a54482c4579c) C:\WINDOWS\system32\DRIVERS\wg11tnd5.sys
07:43:44.0953 3780 AR5523 - ok
07:43:45.0078 3780 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
07:43:45.0078 3780 asc - ok
07:43:45.0218 3780 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
07:43:45.0218 3780 asc3350p - ok
07:43:45.0359 3780 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
07:43:45.0359 3780 asc3550 - ok
07:43:45.0515 3780 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
07:43:45.0515 3780 AsyncMac - ok
07:43:45.0640 3780 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
07:43:45.0640 3780 atapi - ok
07:43:45.0734 3780 Atdisk - ok
07:43:45.0812 3780 ATHFMWDL - ok
07:43:45.0937 3780 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
07:43:45.0937 3780 Atmarpc - ok
07:43:46.0078 3780 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
07:43:46.0078 3780 audstub - ok
07:43:46.0140 3780 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
07:43:46.0140 3780 Beep - ok
07:43:46.0171 3780 catchme - ok
07:43:46.0312 3780 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
07:43:46.0312 3780 cbidf - ok
07:43:46.0437 3780 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
07:43:46.0437 3780 cbidf2k - ok
07:43:46.0546 3780 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
07:43:46.0546 3780 cd20xrnt - ok
07:43:46.0625 3780 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
07:43:46.0625 3780 Cdaudio - ok
07:43:46.0718 3780 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
07:43:46.0718 3780 Cdfs - ok
07:43:46.0843 3780 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
07:43:46.0843 3780 Cdrom - ok
07:43:46.0968 3780 cfwids (7fd604cd7a7a0ff8975af61bdf64c577) C:\WINDOWS\system32\drivers\cfwids.sys
07:43:46.0968 3780 cfwids - ok
07:43:47.0078 3780 Changer - ok
07:43:47.0156 3780 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
07:43:47.0156 3780 CmdIde - ok
07:43:47.0281 3780 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
07:43:47.0281 3780 Cpqarray - ok
07:43:47.0421 3780 cpuz132 - ok
07:43:47.0593 3780 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
07:43:47.0593 3780 dac2w2k - ok
07:43:47.0718 3780 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
07:43:47.0718 3780 dac960nt - ok
07:43:47.0812 3780 DgiVecp (770471de2550820feeb7e5d24bf2e273) C:\WINDOWS\system32\Drivers\DgiVecp.sys
07:43:47.0812 3780 DgiVecp - ok
07:43:47.0953 3780 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
07:43:47.0953 3780 Disk - ok
07:43:48.0109 3780 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
07:43:48.0109 3780 dmboot - ok
07:43:48.0265 3780 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
07:43:48.0265 3780 dmio - ok
07:43:48.0375 3780 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
07:43:48.0375 3780 dmload - ok
07:43:48.0515 3780 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
07:43:48.0515 3780 DMusic - ok
07:43:48.0593 3780 DNINDIS5 (d2ee54cdbced01d48f2b18642be79a98) C:\WINDOWS\system32\DNINDIS5.SYS
07:43:48.0593 3780 DNINDIS5 - ok
07:43:48.0765 3780 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
07:43:48.0765 3780 dpti2o - ok
07:43:48.0875 3780 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
07:43:48.0875 3780 drmkaud - ok
07:43:49.0015 3780 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
07:43:49.0015 3780 E100B - ok
07:43:49.0140 3780 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
07:43:49.0140 3780 Fastfat - ok
07:43:49.0281 3780 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
07:43:49.0281 3780 Fdc - ok
07:43:49.0421 3780 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
07:43:49.0421 3780 Fips - ok
07:43:49.0546 3780 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
07:43:49.0546 3780 Flpydisk - ok
07:43:49.0671 3780 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
07:43:49.0671 3780 FltMgr - ok
07:43:49.0843 3780 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
07:43:49.0843 3780 Fs_Rec - ok
07:43:49.0968 3780 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
07:43:49.0968 3780 Ftdisk - ok
07:43:50.0109 3780 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
07:43:50.0109 3780 Gpc - ok
07:43:50.0250 3780 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
07:43:50.0250 3780 HidUsb - ok
07:43:50.0343 3780 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
07:43:50.0343 3780 hpn - ok
07:43:50.0437 3780 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
07:43:50.0437 3780 HPZid412 - ok
07:43:50.0546 3780 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
07:43:50.0546 3780 HPZipr12 - ok
07:43:50.0656 3780 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
07:43:50.0656 3780 HPZius12 - ok
07:43:50.0734 3780 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
07:43:50.0734 3780 HTTP - ok
07:43:50.0890 3780 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
07:43:50.0890 3780 i2omgmt - ok
07:43:51.0046 3780 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
07:43:51.0046 3780 i2omp - ok
07:43:51.0109 3780 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
07:43:51.0109 3780 i8042prt - ok
07:43:51.0296 3780 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
07:43:51.0296 3780 ialm - ok
07:43:51.0421 3780 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
07:43:51.0421 3780 Imapi - ok
07:43:51.0578 3780 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
07:43:51.0578 3780 ini910u - ok
07:43:51.0703 3780 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
07:43:51.0703 3780 IntelIde - ok
07:43:51.0828 3780 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
07:43:51.0828 3780 intelppm - ok
07:43:51.0937 3780 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
07:43:51.0937 3780 Ip6Fw - ok
07:43:52.0078 3780 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
07:43:52.0078 3780 IpFilterDriver - ok
07:43:52.0171 3780 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
07:43:52.0171 3780 IpInIp - ok
07:43:52.0265 3780 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
07:43:52.0265 3780 IpNat - ok
07:43:52.0343 3780 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
07:43:52.0343 3780 IPSec - ok
07:43:52.0484 3780 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
07:43:52.0484 3780 IRENUM - ok
07:43:52.0609 3780 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
07:43:52.0609 3780 isapnp - ok
07:43:52.0734 3780 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
07:43:52.0734 3780 Kbdclass - ok
07:43:52.0843 3780 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
07:43:52.0843 3780 kbdhid - ok
07:43:52.0968 3780 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
07:43:52.0984 3780 kmixer - ok
07:43:53.0109 3780 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
07:43:53.0109 3780 KSecDD - ok
07:43:53.0218 3780 lbrtfdc - ok
07:43:53.0359 3780 MDC8021X (8fee53c104223973ed9919936d9cd156) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys
07:43:53.0359 3780 MDC8021X - ok
07:43:53.0500 3780 mfeapfk (688b626fca708ee9eb161cad1f7363a9) C:\WINDOWS\system32\drivers\mfeapfk.sys
07:43:53.0500 3780 mfeapfk - ok
07:43:53.0625 3780 mfeavfk (dbf6e1b388d5c070d438c61adb990c30) C:\WINDOWS\system32\drivers\mfeavfk.sys
07:43:53.0625 3780 mfeavfk - ok
07:43:53.0734 3780 mfeavfk01 - ok
07:43:53.0781 3780 mfebopk (a528b15e330edb83ea649be318d841d5) C:\WINDOWS\system32\drivers\mfebopk.sys
07:43:53.0781 3780 mfebopk - ok
07:43:53.0921 3780 mfefirek (c7da1b8003c89acedaa13768f7a1c622) C:\WINDOWS\system32\drivers\mfefirek.sys
07:43:53.0921 3780 mfefirek - ok
07:43:54.0062 3780 mfehidk (44184f32392fa2e94d08d056ce750d56) C:\WINDOWS\system32\drivers\mfehidk.sys
07:43:54.0078 3780 mfehidk - ok
07:43:54.0156 3780 mfendisk (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:43:54.0156 3780 mfendisk - ok
07:43:54.0171 3780 mfendiskmp (b1728195877b18ce63cf0cd00b2871eb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:43:54.0171 3780 mfendiskmp - ok
07:43:54.0265 3780 mferkdet (ce1711f7c3f72f6762abd241dcfd5ee1) C:\WINDOWS\system32\drivers\mferkdet.sys
07:43:54.0265 3780 mferkdet - ok
07:43:54.0375 3780 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys
07:43:54.0375 3780 mferkdk - ok
07:43:54.0453 3780 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys
07:43:54.0453 3780 mfesmfk - ok
07:43:54.0578 3780 mfetdi2k (25e12c68b49a64ffc873603dfd578236) C:\WINDOWS\system32\drivers\mfetdi2k.sys
07:43:54.0578 3780 mfetdi2k - ok
07:43:54.0687 3780 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
07:43:54.0687 3780 mnmdd - ok
07:43:54.0828 3780 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
07:43:54.0828 3780 Modem - ok
07:43:55.0187 3780 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
07:43:55.0187 3780 Mouclass - ok
07:43:55.0328 3780 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
07:43:55.0328 3780 mouhid - ok
07:43:55.0484 3780 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
07:43:55.0500 3780 MountMgr - ok
07:43:55.0562 3780 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
07:43:55.0562 3780 mraid35x - ok
07:43:55.0656 3780 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
07:43:55.0656 3780 MRxDAV - ok
07:43:55.0796 3780 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
07:43:55.0796 3780 MRxSmb - ok
07:43:55.0921 3780 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
07:43:55.0937 3780 Msfs - ok
07:43:56.0046 3780 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
07:43:56.0046 3780 MSKSSRV - ok
07:43:56.0203 3780 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
07:43:56.0203 3780 MSPCLOCK - ok
07:43:56.0312 3780 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
07:43:56.0312 3780 MSPQM - ok
07:43:56.0437 3780 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
07:43:56.0437 3780 mssmbios - ok
07:43:56.0562 3780 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
07:43:56.0562 3780 Mup - ok
07:43:56.0703 3780 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
07:43:56.0703 3780 NDIS - ok
07:43:56.0812 3780 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
07:43:56.0812 3780 NdisTapi - ok
07:43:56.0953 3780 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
07:43:56.0968 3780 Ndisuio - ok
07:43:57.0109 3780 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
07:43:57.0109 3780 NdisWan - ok
07:43:57.0187 3780 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
07:43:57.0187 3780 NDProxy - ok
07:43:57.0265 3780 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
07:43:57.0265 3780 NetBIOS - ok
07:43:57.0328 3780 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
07:43:57.0328 3780 NetBT - ok
07:43:57.0453 3780 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
07:43:57.0468 3780 Npfs - ok
07:43:57.0609 3780 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
07:43:57.0609 3780 Ntfs - ok
07:43:57.0718 3780 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
07:43:57.0734 3780 Null - ok
07:43:57.0953 3780 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
07:43:57.0968 3780 nv - ok
07:43:58.0046 3780 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
07:43:58.0046 3780 NwlnkFlt - ok
07:43:58.0125 3780 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
07:43:58.0125 3780 NwlnkFwd - ok
07:43:58.0218 3780 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
07:43:58.0218 3780 Parport - ok
07:43:58.0359 3780 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
07:43:58.0359 3780 PartMgr - ok
07:43:58.0500 3780 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
07:43:58.0500 3780 ParVdm - ok
07:43:58.0562 3780 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
07:43:58.0562 3780 PCI - ok
07:43:58.0687 3780 PCIDump - ok
07:43:58.0796 3780 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
07:43:58.0796 3780 PCIIde - ok
07:43:58.0921 3780 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
07:43:58.0921 3780 Pcmcia - ok
07:43:59.0015 3780 PDCOMP - ok
07:43:59.0078 3780 PDFRAME - ok
07:43:59.0140 3780 PDRELI - ok
07:43:59.0187 3780 PDRFRAME - ok
07:43:59.0250 3780 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
07:43:59.0250 3780 perc2 - ok
07:43:59.0328 3780 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
07:43:59.0328 3780 perc2hib - ok
07:43:59.0437 3780 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
07:43:59.0437 3780 PptpMiniport - ok
07:43:59.0578 3780 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
07:43:59.0578 3780 PSched - ok
07:43:59.0687 3780 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
07:43:59.0687 3780 Ptilink - ok
07:43:59.0828 3780 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
07:43:59.0828 3780 ql1080 - ok
07:43:59.0906 3780 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
07:43:59.0906 3780 Ql10wnt - ok
07:43:59.0984 3780 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
07:43:59.0984 3780 ql12160 - ok
07:44:00.0062 3780 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
07:44:00.0062 3780 ql1240 - ok
07:44:00.0140 3780 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
07:44:00.0140 3780 ql1280 - ok
07:44:00.0187 3780 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
07:44:00.0187 3780 RasAcd - ok
07:44:00.0250 3780 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
07:44:00.0265 3780 Rasl2tp - ok
07:44:00.0421 3780 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
07:44:00.0421 3780 RasPppoe - ok
07:44:00.0546 3780 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
07:44:00.0546 3780 Raspti - ok
07:44:00.0609 3780 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
07:44:00.0609 3780 Rdbss - ok
07:44:00.0718 3780 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
07:44:00.0718 3780 RDPCDD - ok
07:44:00.0875 3780 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
07:44:00.0890 3780 rdpdr - ok
07:44:01.0000 3780 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
07:44:01.0000 3780 RDPWD - ok
07:44:01.0125 3780 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
07:44:01.0125 3780 redbook - ok
07:44:01.0218 3780 RimUsb (92d33f76769a028ddc54a863eb7de4a2) C:\WINDOWS\system32\Drivers\RimUsb.sys
07:44:01.0218 3780 RimUsb - ok
07:44:01.0328 3780 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\WINDOWS\system32\DRIVERS\RimSerial.sys
07:44:01.0328 3780 RimVSerPort - ok
07:44:01.0468 3780 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
07:44:01.0468 3780 ROOTMODEM - ok
07:44:01.0578 3780 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
07:44:01.0578 3780 Secdrv - ok
07:44:01.0703 3780 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
07:44:01.0703 3780 serenum - ok
07:44:01.0796 3780 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
07:44:01.0796 3780 Serial - ok
07:44:01.0921 3780 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
07:44:01.0921 3780 Sfloppy - ok
07:44:02.0000 3780 Simbad - ok
07:44:02.0078 3780 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
07:44:02.0078 3780 sisagp - ok
07:44:02.0187 3780 smwdm (5018a9db5eb62e3edb3110f82f556285) C:\WINDOWS\system32\drivers\smwdm.sys
07:44:02.0187 3780 smwdm - ok
07:44:02.0328 3780 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
07:44:02.0343 3780 Sparrow - ok
07:44:02.0453 3780 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
07:44:02.0453 3780 splitter - ok
07:44:02.0609 3780 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
07:44:02.0609 3780 sr - ok
07:44:02.0750 3780 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
07:44:02.0765 3780 Srv - ok
07:44:02.0859 3780 SSPORT - ok
07:44:02.0953 3780 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
07:44:02.0953 3780 swenum - ok
07:44:03.0078 3780 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
07:44:03.0078 3780 swmidi - ok
07:44:03.0250 3780 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
07:44:03.0250 3780 symc810 - ok
07:44:03.0421 3780 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
07:44:03.0421 3780 symc8xx - ok
07:44:03.0515 3780 SYMDNS (1f0a3f93fecba6e873e75ac34538708b) C:\WINDOWS\System32\Drivers\SYMDNS.SYS
07:44:03.0515 3780 SYMDNS - ok
07:44:03.0640 3780 SymEvent (b6020caf9ea58532dd78490a3f28ead2) C:\Program Files\Symantec\SYMEVENT.SYS
07:44:03.0640 3780 SymEvent - ok
07:44:03.0734 3780 SYMFW (ca212638c07f7a1736667319589f416e) C:\WINDOWS\System32\Drivers\SYMFW.SYS
07:44:03.0734 3780 SYMFW - ok
07:44:03.0828 3780 SYMIDS (83a0415ab669afe9f2b7fccc52f23153) C:\WINDOWS\System32\Drivers\SYMIDS.SYS
07:44:03.0828 3780 SYMIDS - ok
07:44:03.0953 3780 SYMNDIS (2a8ebb694d702d91d8046b31c3da2220) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS
07:44:03.0953 3780 SYMNDIS - ok
07:44:04.0046 3780 SYMREDRV (7c73b65f1bdfab9052a5076c0ca622de) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
07:44:04.0046 3780 SYMREDRV - ok
07:44:04.0187 3780 SYMTDI (b4562798891dca27ed67ca07acbadbd9) C:\WINDOWS\System32\Drivers\SYMTDI.SYS
07:44:04.0187 3780 SYMTDI - ok
07:44:04.0328 3780 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
07:44:04.0328 3780 sym_hi - ok
07:44:04.0437 3780 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
07:44:04.0437 3780 sym_u3 - ok
07:44:04.0515 3780 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
07:44:04.0515 3780 sysaudio - ok
07:44:04.0671 3780 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
07:44:04.0671 3780 Tcpip - ok
07:44:04.0812 3780 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
07:44:04.0812 3780 TDPIPE - ok
07:44:04.0953 3780 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
07:44:04.0953 3780 TDTCP - ok
07:44:05.0078 3780 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
07:44:05.0078 3780 TermDD - ok
07:44:05.0234 3780 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
07:44:05.0234 3780 TosIde - ok
07:44:05.0390 3780 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
07:44:05.0390 3780 Udfs - ok
07:44:05.0515 3780 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
07:44:05.0515 3780 ultra - ok
07:44:05.0656 3780 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
07:44:05.0656 3780 Update - ok
07:44:05.0812 3780 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
07:44:05.0812 3780 usbccgp - ok
07:44:05.0921 3780 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
07:44:05.0921 3780 usbehci - ok
07:44:06.0000 3780 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
07:44:06.0000 3780 usbhub - ok
07:44:06.0125 3780 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
07:44:06.0125 3780 usbprint - ok
07:44:06.0187 3780 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
07:44:06.0187 3780 usbscan - ok
07:44:06.0312 3780 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
07:44:06.0312 3780 USBSTOR - ok
07:44:06.0406 3780 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
07:44:06.0406 3780 usbuhci - ok
07:44:06.0531 3780 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
07:44:06.0531 3780 VgaSave - ok
07:44:06.0625 3780 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
07:44:06.0640 3780 viaagp - ok
07:44:06.0750 3780 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
07:44:06.0750 3780 ViaIde - ok
07:44:06.0859 3780 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
07:44:06.0859 3780 VolSnap - ok
07:44:07.0031 3780 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
07:44:07.0031 3780 Wanarp - ok
07:44:07.0187 3780 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
07:44:07.0203 3780 Wdf01000 - ok
07:44:07.0250 3780 WDICA - ok
07:44:07.0328 3780 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
07:44:07.0328 3780 wdmaud - ok
07:44:07.0546 3780 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
07:44:07.0546 3780 WS2IFSL - ok
07:44:07.0640 3780 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
07:44:07.0640 3780 WudfPf - ok
07:44:07.0750 3780 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
07:44:07.0750 3780 WudfRd - ok
07:44:07.0828 3780 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
07:44:08.0015 3780 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
07:44:08.0015 3780 \Device\Harddisk0\DR0 - detected TDSS File System (1)
07:44:08.0046 3780 Boot (0x1200) (b23db40eceaa734a8b47dd772979f475) \Device\Harddisk0\DR0\Partition0
07:44:08.0046 3780 \Device\Harddisk0\DR0\Partition0 - ok
07:44:08.0046 3780 ============================================================
07:44:08.0046 3780 Scan finished
07:44:08.0046 3780 ============================================================
07:44:08.0078 0808 Detected object count: 1
07:44:08.0078 0808 Actual detected object count: 1
07:44:16.0437 0808 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
07:44:16.0437 0808 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
07:44:38.0187 2736 Deinitialize success
Please download Listparts

Run the tool,
check the "list BCD" box
click "Scan" and post the log (Result.txt) it makes.




NEXT


We need to get a look at things outside of Windows


Please do the following:

You'll need a CD and a USB flashdrive that has some space on it. We will not be changing any of the data on the usb device just using it for a file.

You will also need to use FireFox to download a file as Internet Explorer seems to mangle the download.

If you have any problems with these steps please let me know. It may look complicated but it's fairly straight forward and for the most part automated.


Download GETxPUD.exe to your desktop
  • Run GETxPUD.exe by double clicking it.
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image.
  • Click on Start and follow the prompts to burn the image to your CD

Using FireFox, please download and save dumpit to your usb device.

You may want to print out this part as you will not be able to view these instructions once booted with the CD you just made.
  • Leave the usb device attached to the computer
  • Now boot your computer with the CD you just burned
    • with the CD in the computer, restart the computer
  • The computer must be set to boot from the CD,depending on your computer you can either do this by pressing F12 and selecting the CD as the first boot option or it can be set in the BIOS
  • Once you have the computer set to boot from the CD allow it to boot
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1,or sda2…usually corresponds to your HDD
  • sdb1 is likely your USB
  • Click on the folder that represents your USB drive (sdb1 ?)
    (you will be able to tell if it the right one as the screen will populate with your files)
  • Locate the file you downloaded and saved earlier, dumpit
  • double click it to run it
  • a black window will open, follow the instructions to close the window when it's finished
  • a file called MBR.zip should now be placed in the right hand panel
  • Click the Home icon at top
  • Remove the CD and click Power off
  • Click restart

Once the computer has rebooted open the usb device and attach the MBR.zip file to your next reply.
ListParts by Farbar Ran by [removed] on 12-02-2012 at 10:14:22 Windows XP (X86) Running From: C:\Documents and Settings\[removed]\Desktop\FIx Language: 0409 ************************************************************ ========================= Memory info ====================== Percentage of memory in use: 25% Total physical RAM: 2045.98 MB Available physical RAM: 1532.93 MB Total Pagefile: 2280.33 MB Available Pagefile: 1672.02 MB Total Virtual: 2047.88 MB Available Virtual: 1999.84 MB ======================= Partitions ========================= 2 Drive c: () (Fixed) (Total:37.21 GB) (Free:16.19 GB) NTFS ==>[Drive with boot components (Windows XP)] The disk management services could not complete the operation. Partitions of Disk The disk management services could not complete the operation.: =============== The disk management services could not complete the operation. 'bcdedit' is not recognized as an internal or external command, operable program or batch file. ****** End Of Log ******
Please run aswMBR again using the same instructions from earlier.

I noticed it wasn't able to finish last time. It can take a while for the program to download the virus definitions and finish scanning, so please allow it at least 30 minutes. When it's done, it will say "Scan finished successfully".

Post me the new log it creates.
aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software Run date: 2012-02-11 17:57:42 —————————– 17:57:42.234 OS Version: Windows 5.1.2600 Service Pack 3 17:57:42.234 Number of processors: 1 586 0x401 17:57:42.234 ComputerName: DDS2M981 UserName: admin 17:57:43.140 Initialize success 18:19:05.281 AVAST engine defs: 12021101 18:25:50.968 The log file has been saved successfully to "C:\Documents and Settings\admin\Desktop\aswMBR.txt" aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software Run date: 2012-02-12 11:47:26 —————————– 11:47:26.312 OS Version: Windows 5.1.2600 Service Pack 3 11:47:26.312 Number of processors: 1 586 0x401 11:47:26.312 ComputerName: DDS2M981 UserName: admin 11:47:26.718 Initialize success 11:47:39.515 AVAST engine defs: 12021101 11:48:22.703 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 11:48:22.703 Disk 0 Vendor: ST340014A 8.16 Size: 38146MB BusType: 3 11:48:22.734 Disk 0 MBR read successfully 11:48:22.734 Disk 0 MBR scan 11:48:22.765 Disk 0 Windows XP default MBR code 11:48:22.781 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 31 MB offset 63 11:48:22.781 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 38107 MB offset 64260 11:48:22.796 Disk 0 scanning sectors +78108030 11:48:22.859 Disk 0 scanning C:\WINDOWS\system32\drivers 11:48:39.765 Service scanning 11:48:41.203 Modules scanning 11:48:51.640 Disk 0 trace - called modules: 11:48:51.656 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 11:48:51.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a9adab8] 11:48:51.656 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a994b00] 11:48:52.203 AVAST engine scan C:\WINDOWS 11:48:59.000 AVAST engine scan C:\WINDOWS\system32 11:52:00.531 AVAST engine scan C:\WINDOWS\system32\drivers 11:52:29.140 AVAST engine scan C:\Documents and Settings\admin 11:59:14.500 AVAST engine scan C:\Documents and Settings\All Users 11:59:50.328 Scan finished successfully 12:07:45.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\admin\Desktop\MBR.dat" 12:07:45.937 The log file has been saved successfully to "C:\Documents and Settings\admin\Desktop\aswMBR.txt"

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI