This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ebay Pop Up Window Asking for Credit Card Info [Solved]

48 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Just like the topic title says. I get a pop up window whenever I try to log into Ebay. It asks for credit card info. There is no way to close the window, the only thing you can do is just hit the back button.

HJT Log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:36:45 PM, on 2/16/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark 2500 Series\lxddmon.exe
C:\Program Files\Lexmark 2500 Series\lxddamon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\iRacing\iRacingService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxddcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\brian\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - https://02bfad4.netsolstores.com/admin/File…ger/XUpload.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: iRacing.com Helper Service (iRacingService) - iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730 - C:\Program Files\iRacing\iRacingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe
O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Solver for COSMOSFloWorks 2008 - Unknown owner - C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

–
End of file - 8552 bytes



Thank you for your time,
Brian

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Brian

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

I see you have iRacing installed. I do iRacing as well ;)

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hello Conspire. Thank you for your help. I was able to run the OTL program and produce the required txt files. When I ran the GMER scan, I left home for a while as it was scanning. When I got home, there was an error message, something about unable to save the file, it looked as though my computer had restarted or something and was frozen. I hit the reset switch, and upon startup the computer did some sort of 3 stage CHKDISK operation. Everything seems to be ok. Not sure what I should do now. Should I go ahead and try to run the GMER again? I will post the OTL txt files that I have.

Thanks,
Brian


OTL logfile created on: 2/18/2012 11:19:58 AM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Documents and Settings\brian\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 75.39% Memory free
5.09 Gb Paging File | 4.35 Gb Available in Paging File | 85.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 138.39 Gb Free Space | 46.43% Space Free | Partition Type: NTFS
Drive D: | 702.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: BRIAN-E921DFA8C | User Name: brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\brian\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iRacing\iRacingService.exe (iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Valve\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk)
PRC - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe (Autodesk)
PRC - C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe ()
PRC - C:\Program Files\Lexmark 2500 Series\lxddmon.exe ()
PRC - C:\WINDOWS\system32\lxddcoms.exe ( )
PRC - C:\Program Files\Lexmark 2500 Series\lxddamon.exe ()


========== Modules (No Company Name) ==========

MOD - c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\autodeskdm_services\b2eebf01\564e7b31\App_global.asax.jm3kh6yd.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\11dcb806c92f55111f5fa9f1a90e3bdd\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e9ba004858dcdb5958d86f26f043f85a\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Program Files\Valve\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Valve\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Valve\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files\Valve\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files\Valve\Steam\bin\avutil-50.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
MOD - C:\Program Files\GIGABYTE\EnergySaver\ycc.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzArchive10.tgp ()
MOD - C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe ()
MOD - C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\FwProxy.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\lxddmon.exe ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.Monitor.Core.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.Monitor.Common.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.DevMons.MCMDevMon.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.DevMons.MCMDevMon.AutoPlayUtil.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\lxddamon.exe ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.DevMons.ScanDevMon.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\App4R.DevMons.NetworkCardDevMon.dll ()
MOD - C:\WINDOWS\system32\ztvunrar36.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\lxdddatr.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdddrpp.dll ()
MOD - C:\WINDOWS\system32\lxddcaps.dll ()
MOD - C:\WINDOWS\system32\lxdddrs.dll ()
MOD - C:\Program Files\Lexmark 2500 Series\lxddscw.dll ()
MOD - C:\WINDOWS\system32\lxddcnv4.dll ()
MOD - C:\Program Files\TUGZip\TzShell.dll ()
MOD - C:\Program Files\TUGZip\Plugins\TzImage10.tgp ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (iRacingService) – C:\Program Files\iRacing\iRacingService.exe (iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Autodesk Data Management Job Dispatch) – C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe (Autodesk)
SRV - (Autodesk EDM Server) – C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe (Autodesk)
SRV - (Remote Solver for COSMOSFloWorks 2008) – C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe ()
SRV - (lxddCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe ()
SRV - (lxdd_device) – C:\WINDOWS\System32\lxddcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (xpsec) – File not found
DRV - (xcpip) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (n558) – C:\WINDOWS\system32\drivers\n558.sys ()
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\atl01_xp.sys (Attansic Technology corporation.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (WINIO) – C:\WINDOWS\system32\winio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\brian\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\brian\Application Data\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\brian\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2012/02/03 09:50:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/18 10:45:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/19 19:09:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\brian\Application Data\Move Networks [2010/02/07 14:08:23 | 000,000,000 | —D | M]

[2008/07/16 18:45:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\brian\Application Data\Mozilla\Extensions
[2011/05/17 07:42:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\brian\Application Data\Mozilla\Firefox\Profiles\5v1dmjst.default\extensions
[2010/06/24 01:15:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\brian\Application Data\Mozilla\Firefox\Profiles\5v1dmjst.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/11/29 18:22:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/18 10:45:10 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/01/16 02:28:50 | 000,155,648 | —- | M] (Solidworks Corporation) – C:\Program Files\mozilla firefox\plugins\npEModelPlugin.dll
[2012/02/13 00:17:30 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/13 00:17:30 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2006/02/28 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [lxddamon] C:\Program Files\Lexmark 2500 Series\lxddamon.exe ()
O4 - HKLM..\Run: [lxddmon.exe] C:\Program Files\Lexmark 2500 Series\lxddmon.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\brian\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe (Dassault Systemes)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} https://02bfad4.netsolstores.com/admin/File…ger/XUpload.ocx (Persits Software XUpload)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3F7E54C8-912C-4C2F-A2BD-41F69DE00FFE}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{963E41D1-045F-486B-878F-E6BBF390A476}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC302D95-DCD2-4765-B21D-6466AE193A19}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\brian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\brian\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/07 01:53:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{862e647b-a695-11de-8691-001fd0815f78}\Shell - "" = AutoRun
O33 - MountPoints2\{862e647b-a695-11de-8691-001fd0815f78}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{862e647b-a695-11de-8691-001fd0815f78}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{8e833e39-ec4d-11dc-b0fa-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{8e833e39-ec4d-11dc-b0fa-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8e833e39-ec4d-11dc-b0fa-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.LAGS - C:\WINDOWS\System32\lagarith.dll ( )
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/18 10:53:19 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\brian\Desktop\OTL.exe
[2012/02/16 20:00:30 | 000,000,000 | —D | C] – C:\Documents and Settings\brian\My Documents\Inventor
[2012/02/16 19:36:07 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HiJackThis.exe
[2012/02/16 19:28:53 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HJTInstall.exe
[2012/02/11 17:05:41 | 000,000,000 | —D | C] – C:\Documents and Settings\brian\My Documents\Mechanics of Materials
[2012/01/19 19:04:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/08/22 18:42:19 | 000,216,064 | —- | C] ( ) – C:\WINDOWS\System32\lagarith.dll
[2008/03/25 16:40:39 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxddinpa.dll
[2008/03/25 16:40:39 | 000,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDDhcp.dll
[2008/03/25 16:40:38 | 001,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxddserv.dll
[2008/03/25 16:40:38 | 000,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxddusb1.dll
[2008/03/25 16:40:38 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxddiesc.dll
[2008/03/25 16:40:38 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxddprox.dll
[2008/03/25 16:40:38 | 000,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxddpplc.dll
[2008/03/25 16:40:37 | 000,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxddhbn3.dll
[2008/03/25 16:40:37 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxddpmui.dll
[2008/03/25 16:40:37 | 000,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxddlmpm.dll
[2008/03/25 16:40:37 | 000,385,968 | —- | C] ( ) – C:\WINDOWS\System32\lxddih.exe
[2008/03/25 16:40:36 | 000,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxddcomc.dll
[2008/03/25 16:40:36 | 000,537,520 | —- | C] ( ) – C:\WINDOWS\System32\lxddcoms.exe
[2008/03/25 16:40:36 | 000,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxddcomm.dll
[2008/03/25 16:40:35 | 000,394,160 | —- | C] ( ) – C:\WINDOWS\System32\lxddcfg.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
[11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/18 11:05:39 | 000,000,000 | —- | M] () – C:\Documents and Settings\brian\Local Settings\Application Data\prvlcl.dat
[2012/02/18 10:53:19 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\brian\Desktop\OTL.exe
[2012/02/18 10:47:53 | 089,363,195 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/18 10:42:14 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/02/18 10:39:48 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/18 10:39:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/17 14:09:22 | 000,003,564 | —- | M] () – C:\Documents and Settings\brian\Desktop\91253A546.rpt
[2012/02/17 14:08:55 | 000,617,706 | —- | M] () – C:\Documents and Settings\brian\Desktop\91253A546.IGS
[2012/02/17 12:35:16 | 000,003,234 | —- | M] () – C:\Documents and Settings\brian\Desktop\91259A541.rpt
[2012/02/17 12:34:31 | 002,343,150 | —- | M] () – C:\Documents and Settings\brian\Desktop\91259A541.IGS
[2012/02/17 12:30:26 | 000,003,234 | —- | M] () – C:\Documents and Settings\brian\Desktop\91259A542.rpt
[2012/02/17 12:29:25 | 002,342,822 | —- | M] () – C:\Documents and Settings\brian\Desktop\91259A542.IGS
[2012/02/17 10:28:19 | 000,306,808 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/16 19:36:07 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HiJackThis.exe
[2012/02/16 19:28:53 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HJTInstall.exe
[2012/02/16 03:33:55 | 000,489,228 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/16 03:33:55 | 000,090,152 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/16 03:11:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/02/13 22:36:10 | 000,242,202 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/13 11:08:23 | 000,003,231 | —- | M] () – C:\Documents and Settings\brian\Desktop\60595K730.rpt
[2012/02/13 11:07:24 | 006,600,262 | —- | M] () – C:\Documents and Settings\brian\Desktop\60595K730.IGS
[2012/02/13 00:44:56 | 000,026,077 | —- | M] () – C:\Documents and Settings\brian\Desktop\ben2.jpg
[2012/02/11 02:12:48 | 004,118,252 | —- | M] () – C:\Documents and Settings\brian\Desktop\ComputationalDynamics.pdf
[2012/02/05 10:50:26 | 000,173,568 | —- | M] () – C:\Documents and Settings\brian\Desktop\5909K490.SLDPRT
[2012/02/05 10:30:47 | 000,739,328 | —- | M] () – C:\Documents and Settings\brian\Desktop\5909K360.SLDPRT
[2012/02/05 10:18:37 | 000,392,192 | —- | M] () – C:\Documents and Settings\brian\Desktop\5905K137.SLDPRT
[2012/02/03 19:24:32 | 000,003,368 | —- | M] () – C:\Documents and Settings\brian\Desktop\92510A760.rpt
[2012/02/03 19:23:54 | 000,045,510 | —- | M] () – C:\Documents and Settings\brian\Desktop\92510A760.IGS
[2012/02/03 19:23:16 | 000,193,024 | —- | M] () – C:\Documents and Settings\brian\Desktop\92510A760.SLDPRT
[2012/02/03 12:27:32 | 000,271,872 | —- | M] () – C:\Documents and Settings\brian\Desktop\5905K131.SLDPRT
[2012/02/03 12:26:36 | 000,371,200 | —- | M] () – C:\Documents and Settings\brian\Desktop\5905K280.SLDPRT
[2012/02/02 21:21:17 | 000,201,216 | —- | M] () – C:\Documents and Settings\brian\Desktop\93827A211.SLDPRT
[2012/02/02 21:17:26 | 000,474,112 | —- | M] () – C:\Documents and Settings\brian\Desktop\91257A549.SLDPRT
[2012/01/29 21:00:45 | 000,109,644 | —- | M] () – C:\Documents and Settings\brian\Desktop\singlepulsegenerator.zip
[2012/01/29 18:02:13 | 000,036,361 | —- | M] () – C:\Documents and Settings\brian\Desktop\SuspendedMassSpring.zip
[2012/01/19 19:09:39 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/19 18:38:40 | 000,002,215 | —- | M] () – C:\Documents and Settings\brian\.recently-used.xbel
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
[11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/17 14:09:18 | 000,003,564 | —- | C] () – C:\Documents and Settings\brian\Desktop\91253A546.rpt
[2012/02/17 14:08:54 | 000,617,706 | —- | C] () – C:\Documents and Settings\brian\Desktop\91253A546.IGS
[2012/02/17 12:35:10 | 000,003,234 | —- | C] () – C:\Documents and Settings\brian\Desktop\91259A541.rpt
[2012/02/17 12:34:29 | 002,343,150 | —- | C] () – C:\Documents and Settings\brian\Desktop\91259A541.IGS
[2012/02/17 12:30:20 | 000,003,234 | —- | C] () – C:\Documents and Settings\brian\Desktop\91259A542.rpt
[2012/02/17 12:29:22 | 002,342,822 | —- | C] () – C:\Documents and Settings\brian\Desktop\91259A542.IGS
[2012/02/15 22:10:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/15 22:10:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/13 11:08:08 | 000,003,231 | —- | C] () – C:\Documents and Settings\brian\Desktop\60595K730.rpt
[2012/02/13 11:07:16 | 006,600,262 | —- | C] () – C:\Documents and Settings\brian\Desktop\60595K730.IGS
[2012/02/13 00:44:56 | 000,026,077 | —- | C] () – C:\Documents and Settings\brian\Desktop\ben2.jpg
[2012/02/11 02:12:47 | 004,118,252 | —- | C] () – C:\Documents and Settings\brian\Desktop\ComputationalDynamics.pdf
[2012/02/05 10:50:26 | 000,173,568 | —- | C] () – C:\Documents and Settings\brian\Desktop\5909K490.SLDPRT
[2012/02/05 10:30:47 | 000,739,328 | —- | C] () – C:\Documents and Settings\brian\Desktop\5909K360.SLDPRT
[2012/02/05 10:18:36 | 000,392,192 | —- | C] () – C:\Documents and Settings\brian\Desktop\5905K137.SLDPRT
[2012/02/03 19:24:32 | 000,003,368 | —- | C] () – C:\Documents and Settings\brian\Desktop\92510A760.rpt
[2012/02/03 19:23:54 | 000,045,510 | —- | C] () – C:\Documents and Settings\brian\Desktop\92510A760.IGS
[2012/02/03 19:23:16 | 000,193,024 | —- | C] () – C:\Documents and Settings\brian\Desktop\92510A760.SLDPRT
[2012/02/03 12:27:32 | 000,271,872 | —- | C] () – C:\Documents and Settings\brian\Desktop\5905K131.SLDPRT
[2012/02/03 12:26:36 | 000,371,200 | —- | C] () – C:\Documents and Settings\brian\Desktop\5905K280.SLDPRT
[2012/02/02 21:21:17 | 000,201,216 | —- | C] () – C:\Documents and Settings\brian\Desktop\93827A211.SLDPRT
[2012/02/02 21:17:26 | 000,474,112 | —- | C] () – C:\Documents and Settings\brian\Desktop\91257A549.SLDPRT
[2012/01/29 21:00:45 | 000,109,644 | —- | C] () – C:\Documents and Settings\brian\Desktop\singlepulsegenerator.zip
[2012/01/29 18:02:13 | 000,036,361 | —- | C] () – C:\Documents and Settings\brian\Desktop\SuspendedMassSpring.zip
[2012/01/19 19:09:39 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/19 19:09:39 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/19 18:38:40 | 000,002,215 | —- | C] () – C:\Documents and Settings\brian\.recently-used.xbel
[2011/10/17 09:50:56 | 000,041,324 | —- | C] () – C:\WINDOWS\System32\winio.sys
[2011/10/10 20:12:02 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2011/08/22 18:43:13 | 000,714,526 | —- | C] () – C:\WINDOWS\unins000.exe
[2011/08/22 18:42:19 | 000,003,092 | —- | C] () – C:\WINDOWS\unins000.dat
[2011/07/24 00:09:35 | 000,000,517 | —- | C] () – C:\WINDOWS\ecoqocefuwejataz.dll
[2011/05/09 01:52:04 | 000,000,000 | —- | C] () – C:\Documents and Settings\brian\Local Settings\Application Data\prvlcl.dat
[2010/10/06 13:28:27 | 000,000,263 | —- | C] () – C:\Documents and Settings\brian\Application Data\StvAutoCAD_3D.ini
[2010/04/01 10:26:25 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/12 21:42:15 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\ibfs32.dll
[2010/01/12 21:25:08 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2009/12/20 15:32:52 | 000,000,202 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2009/04/13 22:28:00 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/08/14 18:10:58 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2008/08/14 18:10:58 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2008/07/20 16:34:21 | 000,000,287 | —- | C] () – C:\WINDOWS\game.ini
[2008/05/24 21:48:53 | 000,081,244 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2008/05/24 21:48:53 | 000,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2008/04/10 14:54:17 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/29 15:09:05 | 000,019,288 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/03/25 16:44:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxddvs.dll
[2008/03/25 16:44:27 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxddcoin.dll
[2008/03/25 16:44:11 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdddrs.dll
[2008/03/25 16:44:11 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxddcnv4.dll
[2008/03/25 16:44:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxddcaps.dll
[2008/03/25 16:43:48 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\LXF3PMRC.DLL
[2008/03/25 16:41:18 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxddrwrd.ini
[2008/03/25 16:40:39 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\LXDDinst.dll
[2008/03/25 16:40:36 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxddgrd.dll
[2008/03/23 01:45:44 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2008/03/13 23:34:10 | 000,050,176 | —- | C] () – C:\Documents and Settings\brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/12 16:53:31 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2008/03/12 16:53:31 | 000,012,664 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2008/03/12 16:53:28 | 000,012,096 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2008/03/12 16:53:28 | 000,010,304 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2008/03/12 12:09:34 | 000,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/03/09 15:13:28 | 000,001,690 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/03/07 15:48:29 | 000,000,128 | —- | C] () – C:\Documents and Settings\brian\Local Settings\Application Data\fusioncache.dat
[2008/03/07 15:33:13 | 000,138,608 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/03/07 15:33:12 | 000,022,328 | —- | C] () – C:\Documents and Settings\brian\Application Data\PnkBstrK.sys
[2008/03/07 15:32:37 | 000,669,184 | —- | C] () – C:\WINDOWS\System32\pbsvc.exe
[2008/03/07 15:32:37 | 000,189,800 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/03/07 15:32:37 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2008/03/07 13:20:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/03/07 09:30:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/03/07 09:27:27 | 000,306,808 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/03/07 02:14:08 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2008/03/07 02:04:56 | 000,014,383 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2008/03/07 02:04:40 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/03/07 02:04:38 | 000,014,139 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/07 02:04:29 | 000,010,288 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/03/07 01:55:06 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/03/07 01:51:47 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2007/11/06 19:30:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/11/06 19:30:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/11/06 19:30:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/11/06 19:30:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/11/06 19:30:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/11/06 19:30:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/11/06 19:30:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/11/06 19:30:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/11/06 19:30:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/08/21 20:46:34 | 000,059,160 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2007/08/15 06:27:18 | 000,009,600 | —- | C] () – C:\WINDOWS\System32\drivers\n558.sys
[2006/02/28 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 06:00:00 | 000,489,228 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 06:00:00 | 000,090,152 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 06:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2008/03/07 01:53:52 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/08/21 16:43:26 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/03/07 01:53:52 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/06/06 10:48:45 | 000,000,197 | —- | M] () – C:\csb.log
[2009/05/05 20:03:23 | 000,000,081 | —- | M] () – C:\DVDPATH.TXT
[2008/06/15 18:09:57 | 000,000,424 | —- | M] () – C:\InstallHelper.log
[2008/03/07 01:53:52 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/03/07 01:53:52 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/20 16:43:05 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/18 10:39:44 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/06/06 10:45:03 | 000,000,480 | —- | M] () – C:\RHDSetup.log
[2012/02/18 10:44:22 | 000,000,125 | —- | M] () – C:\service.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/03/07 01:53:37 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/02/26 22:16:25 | 000,103,936 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdddrpp.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/03/07 09:26:39 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/03/07 09:26:39 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/03/07 09:26:38 | 000,909,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/20 16:47:08 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/20 20:52:28 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\brian\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/03/07 01:58:27 | 000,000,079 | —- | M] () – C:\Documents and Settings\brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/02/16 19:36:07 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HiJackThis.exe
[2012/02/16 19:28:53 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\brian\Desktop\HJTInstall.exe
[2012/02/18 10:53:19 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\brian\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-16 09:34:41

========== Alternate Data Streams ==========

@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05D195EC

< End of report >
OTL Extras logfile created on: 2/18/2012 11:19:58 AM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Documents and Settings\brian\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.45 Gb Available Physical Memory | 75.39% Memory free
5.09 Gb Paging File | 4.35 Gb Available in Paging File | 85.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 138.39 Gb Free Space | 46.43% Space Free | Partition Type: NTFS
Drive D: | 702.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: BRIAN-E921DFA8C | User Name: brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with FastStone] – "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Lexmark 2500 Series\app4r.exe" = C:\Program Files\Lexmark 2500 Series\App4R.exe:*:Enabled:Printing Application – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe" = C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32 – (Crytek GmbH)
"C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe" = C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32 – (Crytek GmbH)
"C:\Program Files\GameSpy\Comrade\Comrade.exe" = C:\Program Files\GameSpy\Comrade\Comrade.exe:*:Enabled:Comrade – (IGN Entertainment Inc.)
"C:\WINDOWS\system32\lxddcoms.exe" = C:\WINDOWS\system32\lxddcoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\Program Files\Lexmark 2500 Series\lxddamon.exe" = C:\Program Files\Lexmark 2500 Series\lxddamon.exe:*:Enabled:Lexmark Device Monitor – ()
"C:\Program Files\Lexmark 2500 Series\App4R.exe" = C:\Program Files\Lexmark 2500 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio – ()
"C:\Program Files\Valve\Steam\SteamApps\dirty31\team fortress 2\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\dirty31\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe" = C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2 – ()
"C:\Program Files\MySpace\IM\MySpaceIM.exe" = C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Azureus\Azureus.exe" = C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)
"C:\Program Files\Performance Electronics\peMonitor v3.02.04\peMonitor.exe" = C:\Program Files\Performance Electronics\peMonitor v3.02.04\peMonitor.exe:*:Enabled:peMonitor – (Performance Electronics, Ltd.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Valve\Steam\SteamApps\common\call of duty 4\iw3sp.exe" = C:\Program Files\Valve\Steam\SteamApps\common\call of duty 4\iw3sp.exe:*:Enabled:Call of Duty 4: Modern Warfare – ()
"C:\Program Files\Valve\Steam\SteamApps\common\call of duty 4\iw3mp.exe" = C:\Program Files\Valve\Steam\SteamApps\common\call of duty 4\iw3mp.exe:*:Enabled:Call of Duty 4: Modern Warfare – ()
"C:\Program Files\Valve\Steam\SteamApps\dirty31\gtr evolution - demo\GtrEvo_Demo_Steam.exe" = C:\Program Files\Valve\Steam\SteamApps\dirty31\gtr evolution - demo\GtrEvo_Demo_Steam.exe:*:Enabled:GTR Evolution Demo – (SimBin)
"C:\Program Files\Valve\Steam\SteamApps\dirty31\gtr evolution - demo\Config.exe" = C:\Program Files\Valve\Steam\SteamApps\dirty31\gtr evolution - demo\Config.exe:*:Enabled:GTR Evolution Demo – (Simbin Development Team AB)
"C:\Program Files\Valve\Steam\SteamApps\common\grid\grid.exe" = C:\Program Files\Valve\Steam\SteamApps\common\grid\grid.exe:*:Enabled:GRID – (Codemasters)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Valve\Steam\SteamApps\dirty31\counter-strike source\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\dirty31\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source – ()
"C:\Program Files\Lexmark 2500 Series\lxddmon.exe" = C:\Program Files\Lexmark 2500 Series\lxddmon.exe:*:Enabled: – ()
"C:\Program Files\Valve\Steam\SteamApps\dirty31\day of defeat source\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\dirty31\day of defeat source\hl2.exe:*:Enabled:Day of Defeat: Source – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddpswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddjswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxddtime.exe:*:Enabled: – (Lexmark International, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00020409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Standard
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis®
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam™
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2: Deluxe Edition
"{0C631AC5-3AA0-418F-B132-29F8432F1C19}" = COSMOSWorks 2008 SP03
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F698102-5739-441E-96F0-74F4EA540F06}" = Attansic Ethernet Utility
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{266EB766-9ABB-40D0-AB9F-41EE46D23876}" = SolidWorks 2008 SP03
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 26
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2A4F281E-2161-405B-B090-4487F505BDDE}" = AOEMView 2009
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (AUTODESKVAULT)
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33A9C38A-E3CC-4077-9E24-CBEFCFA76EFA}" = DWGeditor
"{33BAD028-D921-4A9E-8004-89B11E413C6C}" = COSMOSFloWorks 2008 SP03
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5783F2D6-7028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2009
"{5783F2D7-7005-0409-0002-0060B0CE6BBA}" = AutoCAD Mechanical 2009
"{5C9F43C2-7946-4F94-8581-CFEF561E3C32}" = peMonitor v3.02.04 by Performance Electronics, Ltd
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73AA12E1-5FFD-4545-9A28-CE7C318F284E}" = AVG 2011
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.1015.1
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{ABBBD1A8-E4C9-4714-A202-17D5F6AE58AC}" = COSMOSM 2008 (2008/040)
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB8F2869-8598-42D1-BD43-653DB348BE7E}" = peViewer v1.6 by Performance Electronics, Ltd
"{BB9FF67B-1A16-491B-81C5-272B145FEAB7}" = Autodesk Data Management Server 2009
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBBB3C80-76F5-42B5-92A6-C4BF84796DCB}" = iRacing.com Race Simulation
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"{D45EC259-4A19-4656-B588-C2C360DD18EA}" = Half-Life® 2
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E533E637-FB3E-4F28-8B18-449CC9AB7235}" = AVG 2011
"{E69411C0-8D66-4F9C-B6D6-9ED2FB89D0E4}" = eDrawings 2008
"{E7084B89-69E0-46B3-A118-8F99D06988CD}" = Microsoft SQL Server VSS Writer
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{F039B2AE-4D0B-4806-89B6-9645F4DD3FDA}" = SolidWorks Explorer 2008 sp03
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.25)
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.5
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FED8A261-FE64-416D-ADDD-3EA1173D3D2D}" = COSMOSMotion 2008 SP03
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AltoMP3 Gold" = AltoMP3 Gold 5.20
"AOEMView 2009" = AOEMView 2009
"AtcL1" = Attansic L1 Gigabit Ethernet Driver
"AutoCAD Mechanical 2009" = AutoCAD Mechanical 2009
"Autodesk Data Management Server 2009" = Autodesk Data Management Server 2009
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"AVG" = AVG 2011
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 7_is1" = AVS Video Converter 8
"Axum_V6.0{C:/Program Files/axumle/}#1" = Axum 6.0 LE #1 in 'C:\Program Files\axumle\'
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DivX Setup.divx.com" = DivX Setup
"DWG TrueView 2009" = DWG TrueView 2009
"FastStone Image Viewer" = FastStone Image Viewer 3.5
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.8.13.722
"ie8" = Windows Internet Explorer 8
"InstallShield_{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"JAIELangPack" = Japanese Language Support
"Lexmark 2500 Series" = Lexmark 2500 Series
"Mathcad 2000 Professional" = Mathcad 2000 Professional
"MatlabR2008b" = MATLAB R2008b
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Mp3tag" = Mp3tag v2.45a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NIStune ROM Pack_is1" = NIStune ROM Pack 2.2
"NIStune_is1" = NIStune 0.9.14.13
"NVIDIA Drivers" = NVIDIA Drivers
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"SmartSketch" = Intergraph SmartSketch LE
"ST6UNST #1" = Ecu_Monitor
"ST6UNST #2" = Ecu_Monitor (C:\Program Files\Performance Electronics\)
"Steam App 12750" = GRID
"Steam App 300" = Day of Defeat: Source
"Steam App 440" = Team Fortress 2
"Steam App 7940" = Call of Duty 4: Modern Warfare
"Steam App 8720" = GTR Evolution - DEMO
"SystemRequirementsLab" = System Requirements Lab
"TUGZip_is1" = TUGZip 3.5
"VLC media player" = VLC media player 1.1.11
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.8
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Motion in 2D" = Motion in 2D
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/18/2012 1:20:53 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:21:53 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:22:53 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:23:54 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:24:54 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:25:54 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:26:55 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:27:55 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:28:55 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

Error - 2/18/2012 1:29:55 PM | Computer Name = BRIAN-E921DFA8C | Source = Autodesk Web Server | ID = 0
Description = System.AppDomainUnloadedException: The application domain in which
the thread was running has been unloaded. Server stack trace: at System.Threading.Thread.InternalCrossContextCallback(Context
ctx, IntPtr ctxID, Int32 appDomainID, InternalCrossContextDelegate ftnToCall, Object[]
args) at System.Runtime.Remoting.Channels.CrossAppDomainSink.DoTransitionDispatch(Byte[]
reqStmBuff, SmuggledMethodCallMessage smuggledMcm, SmuggledMethodReturnMessage&
smuggledMrm) at System.Runtime.Remoting.Channels.CrossAppDomainSink.SyncProcessMessage(IMessage
reqMsg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at Connectivity.EDMWS.AppDomain.HttpListenerApplication.ProcessRequest()

at Connectivity.EDMWS.AppDomain.HttpListenerController.OnStart()

[ System Events ]
Error - 2/17/2012 12:31:53 PM | Computer Name = BRIAN-E921DFA8C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service NMIndexingService
with arguments "" in order to run the server: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

Error - 2/17/2012 12:32:17 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7022
Description = The Autodesk EDM Server service hung on starting.

Error - 2/17/2012 12:32:21 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.

Error - 2/18/2012 12:41:19 PM | Computer Name = BRIAN-E921DFA8C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service NMIndexingService
with arguments "" in order to run the server: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

Error - 2/18/2012 12:41:22 PM | Computer Name = BRIAN-E921DFA8C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service NMIndexingService
with arguments "" in order to run the server: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

Error - 2/18/2012 12:41:22 PM | Computer Name = BRIAN-E921DFA8C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service NMIndexingService
with arguments "" in order to run the server: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

Error - 2/18/2012 12:42:23 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxddCATSCustConnectService
service to connect.

Error - 2/18/2012 12:42:23 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7000
Description = The lxddCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 2/18/2012 12:43:48 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7022
Description = The Autodesk EDM Server service hung on starting.

Error - 2/18/2012 12:43:53 PM | Computer Name = BRIAN-E921DFA8C | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.


< End of report >
We will try a different scan instead.

Scan With RootKitUnHooker

Please download Rootkit Unhooker and save it to your desktop.
  • Double-click RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close then Yes
  • Copy the entire contents of the report and paste it in your next reply.


Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
RkU Version: 3.8.389.593, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB9271000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 7438336 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 169.21 ) 0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 5775360 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 169.21 ) 0xB6B87000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4919296 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2154496 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2154496 bytes 0x804D7000 RAW 2154496 bytes 0x804D7000 WMIxWDM 2154496 bytes 0xBF800000 Win32k 1863680 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1863680 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xB9E18000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB690D000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB9138000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xB6A87000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xB6254000 C:\WINDOWS\system32\drivers\xcpip.sys 364544 bytes 0xB57B4000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xBF594000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xB6A18000 C:\WINDOWS\system32\DRIVERS\avgtdix.sys 290816 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xB4471000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB68D1000 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB58FC000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9DEB000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB697D000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xB9211000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xB69CA000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xB69F2000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xB5450000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB6B3B000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB9239000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB91BE000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB51FD000 C:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export)) 0xB69A8000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806E5000 ACPI_HAL 134400 bytes 0x806E5000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB5654000 C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 131072 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.) 0xB9EE1000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB91F5000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 114688 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xB9DD1000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB6790000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB9F19000 jraid.sys 98304 bytes (JMicron Technology Corp., JMicron JMB36X RAID Driver) 0xB9F31000 RGRCZ@J@ 98304 bytes 0xB9F01000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB9EB8000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB91A7000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xB5F1F000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB91E1000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB925D000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xB6AE0000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xB9EA5000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xB62AD000 C:\WINDOWS\system32\drivers\xpsec.sys 77824 bytes 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9ECF000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB9196000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xB67A8000 C:\WINDOWS\System32\Drivers\Udfs.SYS 69632 bytes (Microsoft Corporation, UDF File System Driver) 0xB5BA1000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA278000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xBA138000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xBA0B8000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xBA248000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xBA178000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xB99D9000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA288000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xB68B1000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA1C8000 C:\WINDOWS\system32\drivers\usbaudio.sys 61440 bytes (Microsoft Corporation, USB Audio Class Driver) 0xBA148000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xBA0C8000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xBA108000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xBA258000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA298000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xBA0E8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA158000 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xBA2B8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBA198000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA268000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0D8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA2A8000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA308000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xBA2D8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xB452A000 C:\WINDOWS\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver) 0xBA0F8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA1B8000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xBA238000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA2C8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA188000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xBA168000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA450000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA458000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xBA388000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA338000 avgrkx86.sys 28672 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver) 0xBA390000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xBA438000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA480000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver) 0xBA398000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA3B8000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xB5278000 C:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver) 0xBA380000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xBA440000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA490000 C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.) 0xBA498000 C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.) 0xBA428000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xBA448000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA3A8000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA3B0000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA3A0000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA3C0000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xBA4BC000 AVGIDSEH.Sys 16384 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.) 0xBA54C000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB6468000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB9B2D000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xB9B35000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver) 0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB6815000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB46D6000 C:\WINDOWS\gdrv.sys 12288 bytes (Windows ® 2000 DDK provider, GIGABYTE Tools) 0xB9B31000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xB6B7F000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB9B21000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB6B2F000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA5CA000 C:\WINDOWS\system32\drivers\AsIO.sys 8192 bytes 0xBA668000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA5D0000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA666000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA66A000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA65E000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xBA66C000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5FA000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA602000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA69D000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA7A2000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA7FB000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ============================================== 0x8A248B9E Unknown page with executable code, 1122 bytes 0x8A249B52 Unknown page with executable code, 1198 bytes 0x8A233A74 Unknown page with executable code, 1420 bytes 0x8A20498F Unknown page with executable code, 1649 bytes 0x8A24898B Unknown page with executable code, 1653 bytes 0x8A22A8E2 Unknown page with executable code, 1822 bytes 0x8A22A71D Unknown page with executable code, 2275 bytes 0x8A227430 Unknown page with executable code, 3024 bytes 0x8A24B3FE Unknown page with executable code, 3074 bytes 0x8A24814E Unknown page with executable code, 3762 bytes 0x8A228074 Unknown page with executable code, 3980 bytes 0x8A225DFE Unknown page with executable code, 514 bytes 0x8A253C4A Unknown page with executable code, 950 bytes ============================================== >Files ============================================== ============================================== >Hooks ============================================== ntkrnlpa.exe+0x0006ECEE, Type: Inline - RelativeJump 0x80545CEE–>80545CF5 [ntkrnlpa.exe] [1312]explorer.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>5CB77774 [shimeng.dll] [1312]explorer.exe–>crypt32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77A81188–>5CB77774 [shimeng.dll] [1312]explorer.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>5CB77774 [shimeng.dll] [1312]explorer.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x01001268–>5CB77774 [shimeng.dll] [1312]explorer.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>5CB77774 [shimeng.dll] [1312]explorer.exe–>user32.dll–>DisplayExitWindowsWarnings, Type: Inline - RelativeJump 0x7E459F91–>00FE2A93 [unknown_code_page] [1312]explorer.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>5CB77774 [shimeng.dll] [1312]explorer.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D9314B0–>5CB77774 [shimeng.dll] [1312]explorer.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00DC9D85 [unknown_code_page] [1312]explorer.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>5CB77774 [shimeng.dll] [1312]explorer.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00DC9A03 [unknown_code_page] [1312]explorer.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00DC98B1 [unknown_code_page] [1312]explorer.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00DC9C37 [unknown_code_page] [1312]explorer.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00DC9AD6 [unknown_code_page] [1624]lxddmon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B09D85 [unknown_code_page] [1624]lxddmon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B09A03 [unknown_code_page] [1624]lxddmon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B098B1 [unknown_code_page] [1624]lxddmon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B09C37 [unknown_code_page] [1624]lxddmon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B09AD6 [unknown_code_page] [2076]sqlbrowser.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>008A9D85 [unknown_code_page] [2076]sqlbrowser.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>008A9A03 [unknown_code_page] [2076]sqlbrowser.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>008A98B1 [unknown_code_page] [2076]sqlbrowser.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>008A9C37 [unknown_code_page] [2076]sqlbrowser.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>008A9AD6 [unknown_code_page] [2132]sqlwriter.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B89D85 [unknown_code_page] [2132]sqlwriter.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B89A03 [unknown_code_page] [2132]sqlwriter.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B898B1 [unknown_code_page] [2132]sqlwriter.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B89C37 [unknown_code_page] [2132]sqlwriter.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B89AD6 [unknown_code_page] [2160]lxddamon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>01099D85 [unknown_code_page] [2160]lxddamon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>01099A03 [unknown_code_page] [2160]lxddamon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>010998B1 [unknown_code_page] [2160]lxddamon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>01099C37 [unknown_code_page] [2160]lxddamon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>01099AD6 [unknown_code_page] [2344]DivXUpdate.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>016F9D85 [unknown_code_page] [2344]DivXUpdate.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>016F9A03 [unknown_code_page] [2344]DivXUpdate.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>016F98B1 [unknown_code_page] [2344]DivXUpdate.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>016F9C37 [unknown_code_page] [2344]DivXUpdate.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>016F9AD6 [unknown_code_page] [2388]TeaTimer.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>04BC9D85 [unknown_code_page] [2388]TeaTimer.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>04BC9A03 [unknown_code_page] [2388]TeaTimer.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>04BC98B1 [unknown_code_page] [2388]TeaTimer.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>04BC9C37 [unknown_code_page] [2388]TeaTimer.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>04BC9AD6 [unknown_code_page] [2444]msmsgs.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00E69D85 [unknown_code_page] [2444]msmsgs.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00E69A03 [unknown_code_page] [2444]msmsgs.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00E698B1 [unknown_code_page] [2444]msmsgs.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00E69C37 [unknown_code_page] [2444]msmsgs.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00E69AD6 [unknown_code_page] [2716]swBOEngine.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>01259D85 [unknown_code_page] [2716]swBOEngine.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>01259A03 [unknown_code_page] [2716]swBOEngine.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>012598B1 [unknown_code_page] [2716]swBOEngine.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>01259C37 [unknown_code_page] [2716]swBOEngine.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>01259AD6 [unknown_code_page] [3356]Steam.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>0B7F9D85 [unknown_code_page] [3356]Steam.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>0B7F9A03 [unknown_code_page] [3356]Steam.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>0B7F98B1 [unknown_code_page] [3356]Steam.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>0B7F9C37 [unknown_code_page] [3356]Steam.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>0B7F9AD6 [unknown_code_page] [360]StandAloneSlv.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00CB9D85 [unknown_code_page] [360]StandAloneSlv.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00CB9A03 [unknown_code_page] [360]StandAloneSlv.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00CB98B1 [unknown_code_page] [360]StandAloneSlv.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00CB9C37 [unknown_code_page] [360]StandAloneSlv.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00CB9AD6 [unknown_code_page] [3676]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>03559D85 [unknown_code_page] [3676]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>03559A03 [unknown_code_page] [3676]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>035598B1 [unknown_code_page] [3676]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>03559C37 [unknown_code_page] [3676]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>03559AD6 [unknown_code_page] [3728]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00EF9D85 [unknown_code_page] [3728]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00EF9A03 [unknown_code_page] [3728]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00EF98B1 [unknown_code_page] [3728]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00EF9C37 [unknown_code_page] [3728]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00EF9AD6 [unknown_code_page] [3824]iRacingService.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>02FD9D85 [unknown_code_page] [3824]iRacingService.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>02FD9A03 [unknown_code_page] [3824]iRacingService.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>02FD98B1 [unknown_code_page] [3824]iRacingService.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>02FD9C37 [unknown_code_page] [3824]iRacingService.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>02FD9AD6 [unknown_code_page] [3976]lxddcoms.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00DD9D85 [unknown_code_page] [3976]lxddcoms.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00DD9A03 [unknown_code_page] [3976]lxddcoms.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00DD98B1 [unknown_code_page] [3976]lxddcoms.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00DD9C37 [unknown_code_page] [3976]lxddcoms.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00DD9AD6 [unknown_code_page] [4100]SolidWorksLicensing.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00BF9D85 [unknown_code_page] [4100]SolidWorksLicensing.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00BF9A03 [unknown_code_page] [4100]SolidWorksLicensing.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00BF98B1 [unknown_code_page] [4100]SolidWorksLicensing.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00BF9C37 [unknown_code_page] [4100]SolidWorksLicensing.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00BF9AD6 [unknown_code_page] [4800]alg.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B99D85 [unknown_code_page] [4800]alg.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B99A03 [unknown_code_page] [4800]alg.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B998B1 [unknown_code_page] [4800]alg.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B99C37 [unknown_code_page] [4800]alg.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B99AD6 [unknown_code_page] [5448]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>01215B60 [xul.dll]
I ran the RKU again. I had a lot of trouble getting it to work again, it would freeze up. The avg I have installed notified of threats whenever I tried to run the RKU. I have attached the report RkU Version: 3.8.389.593, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB91C1000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 7438336 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 169.21 ) 0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 5775360 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 169.21 ) 0xB6AD7000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4919296 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2154496 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2154496 bytes 0x804D7000 RAW 2154496 bytes 0x804D7000 WMIxWDM 2154496 bytes 0xBF800000 Win32k 1863680 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1863680 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xB9E18000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB685D000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB9088000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xB69D7000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xB6104000 C:\WINDOWS\system32\drivers\xcpip.sys 364544 bytes 0xB4D51000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xBF594000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xB6968000 C:\WINDOWS\system32\DRIVERS\avgtdix.sys 290816 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xB44D6000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB6821000 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB4E21000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9DEB000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB41CA000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xB68CD000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xB9161000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xB691A000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xB6942000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xB4A3D000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB6A8B000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB9189000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB910E000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB483A000 C:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export)) 0xB68F8000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806E5000 ACPI_HAL 134400 bytes 0x806E5000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB4B51000 C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 131072 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.) 0xB9EE1000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB9F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB9145000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 114688 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xB9DD1000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB66E0000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB9F19000 jraid.sys 98304 bytes (JMicron Technology Corp., JMicron JMB36X RAID Driver) 0xB9F31000 RGRCZ@J@ 98304 bytes 0xB9F01000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB9EB8000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB90F7000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xB5E6F000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB9131000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB91AD000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xB6A30000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xB9EA5000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xB615D000 C:\WINDOWS\system32\drivers\xpsec.sys 77824 bytes 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9ECF000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB90E6000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xB66F8000 C:\WINDOWS\System32\Drivers\Udfs.SYS 69632 bytes (Microsoft Corporation, UDF File System Driver) 0xB58C9000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA1A8000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xBA138000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xBA0B8000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xBA178000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xBA2B8000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xBA278000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA1B8000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xB61F0000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA308000 C:\WINDOWS\system32\drivers\usbaudio.sys 61440 bytes (Microsoft Corporation, USB Audio Class Driver) 0xBA238000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xBA0C8000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xBA108000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xBA188000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA1C8000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xBA0E8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA318000 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xBA1E8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBA2D8000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA198000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0D8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA1D8000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA0A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA218000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xBA208000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xB4C29000 C:\WINDOWS\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver) 0xBA0F8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA2F8000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xBA168000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA1F8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA2C8000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xBA2A8000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA3E0000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA3E8000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xBA4A0000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA338000 avgrkx86.sys 28672 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver) 0xBA4A8000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xBA3C8000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA3F0000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver) 0xBA4B0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA390000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xB48C5000 C:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver) 0xBA498000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xBA3D0000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA3B0000 C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.) 0xBA468000 C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 20480 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.) 0xBA3B8000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xBA3D8000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA380000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA388000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA348000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA440000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xBA4BC000 AVGIDSEH.Sys 16384 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.) 0xBA544000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB63B0000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB9B7E000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xB6A77000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver) 0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB6771000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB49F5000 C:\WINDOWS\gdrv.sys 12288 bytes (Windows ® 2000 DDK provider, GIGABYTE Tools) 0xB6A73000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xB9DA5000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB9B72000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB6AB7000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA66A000 C:\WINDOWS\system32\drivers\AsIO.sys 8192 bytes 0xBA632000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA5B2000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA630000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA634000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA640000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xBA636000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5F2000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA5F6000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA6CB000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA7A2000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA7F7000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ============================================== 0x8A2A9B9E Unknown page with executable code, 1122 bytes 0x8A2AAB52 Unknown page with executable code, 1198 bytes 0x8A294A74 Unknown page with executable code, 1420 bytes 0x8A26598F Unknown page with executable code, 1649 bytes 0x8A2A998B Unknown page with executable code, 1653 bytes 0x8A28B8E2 Unknown page with executable code, 1822 bytes 0x8A28B71D Unknown page with executable code, 2275 bytes 0x8A288430 Unknown page with executable code, 3024 bytes 0x8A2AC3FE Unknown page with executable code, 3074 bytes 0x8A2A914E Unknown page with executable code, 3762 bytes 0x8A289074 Unknown page with executable code, 3980 bytes 0x8A286DFE Unknown page with executable code, 514 bytes 0x8A2B4C4A Unknown page with executable code, 950 bytes ============================================== >Files ============================================== ============================================== >Hooks ============================================== ntkrnlpa.exe+0x0006ECEE, Type: Inline - RelativeJump 0x80545CEE–>80545CF5 [ntkrnlpa.exe] [1572]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>03559D85 [unknown_code_page] [1572]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>03559A03 [unknown_code_page] [1572]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>035598B1 [unknown_code_page] [1572]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>03559C37 [unknown_code_page] [1572]Connectivity.WindowsService.JobDispatch.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>03559AD6 [unknown_code_page] [1616]SolidWorksLicensing.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00BF9D85 [unknown_code_page] [1616]SolidWorksLicensing.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00BF9A03 [unknown_code_page] [1616]SolidWorksLicensing.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00BF98B1 [unknown_code_page] [1616]SolidWorksLicensing.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00BF9C37 [unknown_code_page] [1616]SolidWorksLicensing.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00BF9AD6 [unknown_code_page] [1788]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00EF9D85 [unknown_code_page] [1788]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00EF9A03 [unknown_code_page] [1788]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00EF98B1 [unknown_code_page] [1788]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00EF9C37 [unknown_code_page] [1788]Connectivity.EDMWS.Server.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00EF9AD6 [unknown_code_page] [1872]explorer.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>5CB77774 [shimeng.dll] [1872]explorer.exe–>crypt32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77A81188–>5CB77774 [shimeng.dll] [1872]explorer.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>5CB77774 [shimeng.dll] [1872]explorer.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x01001268–>5CB77774 [shimeng.dll] [1872]explorer.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>5CB77774 [shimeng.dll] [1872]explorer.exe–>user32.dll–>DisplayExitWindowsWarnings, Type: Inline - RelativeJump 0x7E459F91–>01A32A93 [unknown_code_page] [1872]explorer.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>5CB77774 [shimeng.dll] [1872]explorer.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D9314B0–>5CB77774 [shimeng.dll] [1872]explorer.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>014A9D85 [unknown_code_page] [1872]explorer.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>5CB77774 [shimeng.dll] [1872]explorer.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>014A9A03 [unknown_code_page] [1872]explorer.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>014A98B1 [unknown_code_page] [1872]explorer.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>014A9C37 [unknown_code_page] [1872]explorer.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>014A9AD6 [unknown_code_page] [2128]iRacingService.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>02BD9D85 [unknown_code_page] [2128]iRacingService.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>02BD9A03 [unknown_code_page] [2128]iRacingService.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>02BD98B1 [unknown_code_page] [2128]iRacingService.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>02BD9C37 [unknown_code_page] [2128]iRacingService.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>02BD9AD6 [unknown_code_page] [2140]lxddmon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B09D85 [unknown_code_page] [2140]lxddmon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B09A03 [unknown_code_page] [2140]lxddmon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B098B1 [unknown_code_page] [2140]lxddmon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B09C37 [unknown_code_page] [2140]lxddmon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B09AD6 [unknown_code_page] [2256]lxddamon.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>01099D85 [unknown_code_page] [2256]lxddamon.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>01099A03 [unknown_code_page] [2256]lxddamon.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>010998B1 [unknown_code_page] [2256]lxddamon.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>01099C37 [unknown_code_page] [2256]lxddamon.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>01099AD6 [unknown_code_page] [2432]lxddcoms.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00E69D85 [unknown_code_page] [2432]lxddcoms.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00E69A03 [unknown_code_page] [2432]lxddcoms.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00E698B1 [unknown_code_page] [2432]lxddcoms.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00E69C37 [unknown_code_page] [2432]lxddcoms.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00E69AD6 [unknown_code_page] [2552]StandAloneSlv.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00CB9D85 [unknown_code_page] [2552]StandAloneSlv.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00CB9A03 [unknown_code_page] [2552]StandAloneSlv.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00CB98B1 [unknown_code_page] [2552]StandAloneSlv.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00CB9C37 [unknown_code_page] [2552]StandAloneSlv.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00CB9AD6 [unknown_code_page] [2588]DivXUpdate.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>016F9D85 [unknown_code_page] [2588]DivXUpdate.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>016F9A03 [unknown_code_page] [2588]DivXUpdate.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>016F98B1 [unknown_code_page] [2588]DivXUpdate.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>016F9C37 [unknown_code_page] [2588]DivXUpdate.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>016F9AD6 [unknown_code_page] [2628]Steam.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>095D9D85 [unknown_code_page] [2628]Steam.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>095D9A03 [unknown_code_page] [2628]Steam.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>095D98B1 [unknown_code_page] [2628]Steam.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>095D9C37 [unknown_code_page] [2628]Steam.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>095D9AD6 [unknown_code_page] [2644]TeaTimer.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>04BC9D85 [unknown_code_page] [2644]TeaTimer.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>04BC9A03 [unknown_code_page] [2644]TeaTimer.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>04BC98B1 [unknown_code_page] [2644]TeaTimer.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>04BC9C37 [unknown_code_page] [2644]TeaTimer.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>04BC9AD6 [unknown_code_page] [2668]msmsgs.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00FA9D85 [unknown_code_page] [2668]msmsgs.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00FA9A03 [unknown_code_page] [2668]msmsgs.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00FA98B1 [unknown_code_page] [2668]msmsgs.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00FA9C37 [unknown_code_page] [2668]msmsgs.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00FA9AD6 [unknown_code_page] [2828]swBOEngine.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>01259D85 [unknown_code_page] [2828]swBOEngine.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>01259A03 [unknown_code_page] [2828]swBOEngine.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>012598B1 [unknown_code_page] [2828]swBOEngine.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>01259C37 [unknown_code_page] [2828]swBOEngine.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>01259AD6 [unknown_code_page] [3276]sqlwriter.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B89D85 [unknown_code_page] [3276]sqlwriter.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B89A03 [unknown_code_page] [3276]sqlwriter.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B898B1 [unknown_code_page] [3276]sqlwriter.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B89C37 [unknown_code_page] [3276]sqlwriter.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B89AD6 [unknown_code_page] [4736]alg.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00B99D85 [unknown_code_page] [4736]alg.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00B99A03 [unknown_code_page] [4736]alg.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00B998B1 [unknown_code_page] [4736]alg.exe–>ws2_32.dll–>WSARecv, Type: Inline - RelativeJump 0x71AB4CB5–>00B99C37 [unknown_code_page] [4736]alg.exe–>ws2_32.dll–>WSASend, Type: Inline - RelativeJump 0x71AB68FA–>00B99AD6 [unknown_code_page]

Attachments:

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Everything seemed to go well. I uninstalled avg before I ran the Combofix, as I didn't think that the 15 minutes deactivation time would be sufficient, and didn't want to take any chances.



ComboFix 12-02-19.02 - brian 02/20/2012 20:41:54.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3326.2762 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\brian\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0000\~de688f.tmp
c:\docume~1\brian\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0000\~df394b.tmp
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\All Users\SPL232.tmp
c:\documents and settings\All Users\SPLAA.tmp
c:\documents and settings\brian\Application Data\Adobe\plugs
c:\documents and settings\brian\Application Data\Adobe\shed
c:\documents and settings\brian\Favorites\Thumbs.db
c:\documents and settings\brian\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0000\~de688f.tmp
c:\documents and settings\brian\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0000\~df394b.tmp
c:\documents and settings\brian\Recent\Thumbs.db
c:\documents and settings\brian\Start Menu\Programs\Zentom System Guard
c:\documents and settings\brian\WINDOWS
c:\windows\dasetup.log
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\system32\2C9B7206.exe
c:\windows\system32\SET1052.tmp
c:\windows\system32\SET1057.tmp
c:\windows\system32\setb3.tmp
c:\windows\system32\setb6.tmp
c:\windows\system32\WinIo.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_xcpip
——-\Legacy_2C9B7206
——-\Legacy_WINIO
——-\Service_2C9B7206
——-\Service_WINIO
.
.
((((((((((((((((((((((((( Files Created from 2012-01-21 to 2012-02-21 )))))))))))))))))))))))))))))))
.
.
2012-02-16 16:44 . 2012-02-16 16:44 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2012-02-16 04:10 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2012-02-16 04:10 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-21 02:52 . 2009-06-06 16:17 16608 —-a-w- c:\windows\gdrv.sys
2012-01-12 16:53 . 2006-02-28 12:00 1859968 —-a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2006-02-28 12:00 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2006-02-28 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2006-02-28 12:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2006-02-28 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-11-25 21:57 . 2006-02-28 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2012-02-18 16:45 . 2011-05-17 13:55 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Valve\Steam\\Steam.exe" [2012-02-19 1242448]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-28 152872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"lxddmon.exe"="c:\program files\Lexmark 2500 Series\lxddmon.exe" [2007-06-11 291760]
"lxddamon"="c:\program files\Lexmark 2500 Series\lxddamon.exe" [2007-04-30 20480]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"nwiz"="nwiz.exe" [2007-12-05 1626112]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1424" [?]
.
c:\documents and settings\brian\Start Menu\Programs\Startup\
SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2008-2-15 488728]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"c:\\WINDOWS\\system32\\lxddcoms.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\dirty31\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Performance Electronics\\peMonitor v3.02.04\\peMonitor.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\call of duty 4\\iw3sp.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\call of duty 4\\iw3mp.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\dirty31\\gtr evolution - demo\\GtrEvo_Demo_Steam.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\dirty31\\gtr evolution - demo\\Config.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\grid\\grid.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\dirty31\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\dirty31\\day of defeat source\\hl2.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddtime.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddmon.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
.
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [6/6/2009 10:39 AM 68136]
R2 iRacingService;iRacing.com Helper Service;c:\program files\iRacing\iRacingService.exe [10/10/2011 8:11 PM 475808]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service –> c:\windows\system32\lxddcoms.exe -service [?]
R2 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe [1/23/2008 6:37 PM 245760]
R3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys –> c:\windows\system32\drivers\xpsec.sys [?]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [3/25/2008 4:44 PM 99248]
S3 51D388AE;51D388AE;c:\windows\system32\51D388AE.exe –> c:\windows\system32\51D388AE.exe [?]
S3 6h9wk8_3.sys;6h9wk8_3.sys;\??\c:\windows\system32\drivers\6h9wk8_3.sys –> c:\windows\system32\drivers\6h9wk8_3.sys [?]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [3/7/2008 2:15 AM 38656]
S3 D6ED8A9C;D6ED8A9C;c:\windows\system32\D6ED8A9C.exe –> c:\windows\system32\D6ED8A9C.exe [?]
S3 EB5D307A;EB5D307A;c:\windows\system32\EB5D307A.exe –> c:\windows\system32\EB5D307A.exe [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - xcpip
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\brian\Application Data\Mozilla\Firefox\Profiles\5v1dmjst.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc6eca3&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q=
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-20 20:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3160)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
c:\program files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxddcoms.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\windows\SOUNDMAN.EXE
c:\docume~1\brian\LOCALS~1\Temp\SolidWorksLicTemp.0001
c:\program files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
.
**************************************************************************
.
Completion time: 2012-02-20 21:02:25 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-21 03:02
.
Pre-Run: 152,559,050,752 bytes free
Post-Run: 153,274,232,832 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 89BDC6DE7884BD3382A71966A224CA66
Hi,

Thank you.

We just want the scan log from TDSSKiller only, no need for cure.

Download TDSSKiller.exe and save it to your desktop
Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt
19:11:38.0406 2380 TDSS rootkit removing tool [removed] Feb 15 2012 19:33:14 19:11:38.0671 2380 ============================================================ 19:11:38.0671 2380 Current date / time: 2012/02/21 19:11:38.0671 19:11:38.0671 2380 SystemInfo: 19:11:38.0671 2380 19:11:38.0671 2380 OS Version: 5.1.2600 ServicePack: 3.0 19:11:38.0671 2380 Product type: Workstation 19:11:38.0671 2380 ComputerName: BRIAN-E921DFA8C 19:11:38.0671 2380 UserName: brian 19:11:38.0671 2380 Windows directory: C:\WINDOWS 19:11:38.0671 2380 System windows directory: C:\WINDOWS 19:11:38.0671 2380 Processor architecture: Intel x86 19:11:38.0671 2380 Number of processors: 2 19:11:38.0671 2380 Page size: 0x1000 19:11:38.0671 2380 Boot type: Normal boot 19:11:38.0671 2380 ============================================================ 19:11:39.0703 2380 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 19:11:39.0703 2380 \Device\Harddisk0\DR0: 19:11:39.0703 2380 MBR used 19:11:39.0703 2380 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x254297C1 19:11:39.0718 2380 Initialize success 19:11:39.0718 2380 ============================================================ 19:12:02.0109 4052 ============================================================ 19:12:02.0109 4052 Scan started 19:12:02.0109 4052 Mode: Manual; 19:12:02.0109 4052 ============================================================ 19:12:02.0531 4052 6h9wk8_3.sys - ok 19:12:02.0531 4052 Abiosdsk - ok 19:12:02.0546 4052 abp480n5 - ok 19:12:02.0578 4052 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 19:12:02.0578 4052 ACPI - ok 19:12:02.0609 4052 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 19:12:02.0609 4052 ACPIEC - ok 19:12:02.0625 4052 adpu160m - ok 19:12:02.0656 4052 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 19:12:02.0656 4052 aec - ok 19:12:02.0687 4052 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 19:12:02.0687 4052 AFD - ok 19:12:02.0703 4052 Aha154x - ok 19:12:02.0703 4052 aic78u2 - ok 19:12:02.0718 4052 aic78xx - ok 19:12:02.0718 4052 AliIde - ok 19:12:02.0734 4052 amsint - ok 19:12:02.0765 4052 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 19:12:02.0765 4052 Arp1394 - ok 19:12:02.0765 4052 asc - ok 19:12:02.0781 4052 asc3350p - ok 19:12:02.0781 4052 asc3550 - ok 19:12:02.0812 4052 AsIO (663f2fb92608073824ee3106886120f3) C:\WINDOWS\system32\drivers\AsIO.sys 19:12:02.0812 4052 AsIO - ok 19:12:02.0828 4052 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 19:12:02.0828 4052 AsyncMac - ok 19:12:02.0859 4052 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 19:12:02.0859 4052 atapi - ok 19:12:02.0875 4052 AtcL001 (19f277bc4ce5689f20f347a6b8aa8c42) C:\WINDOWS\system32\DRIVERS\atl01_xp.sys 19:12:02.0875 4052 AtcL001 - ok 19:12:02.0890 4052 Atdisk - ok 19:12:02.0906 4052 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 19:12:02.0906 4052 Atmarpc - ok 19:12:02.0937 4052 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 19:12:02.0937 4052 audstub - ok 19:12:02.0968 4052 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 19:12:02.0968 4052 Beep - ok 19:12:02.0984 4052 btaudio - ok 19:12:02.0984 4052 BTDriver - ok 19:12:03.0015 4052 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 19:12:03.0015 4052 BthEnum - ok 19:12:03.0031 4052 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 19:12:03.0031 4052 BthPan - ok 19:12:03.0046 4052 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 19:12:03.0046 4052 BTHPORT - ok 19:12:03.0078 4052 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 19:12:03.0078 4052 BTHUSB - ok 19:12:03.0078 4052 BTWDNDIS - ok 19:12:03.0093 4052 btwhid - ok 19:12:03.0093 4052 btwmodem - ok 19:12:03.0109 4052 BTWUSB - ok 19:12:03.0109 4052 catchme - ok 19:12:03.0125 4052 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 19:12:03.0125 4052 cbidf2k - ok 19:12:03.0140 4052 cd20xrnt - ok 19:12:03.0156 4052 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 19:12:03.0156 4052 Cdaudio - ok 19:12:03.0156 4052 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 19:12:03.0156 4052 Cdfs - ok 19:12:03.0171 4052 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 19:12:03.0171 4052 Cdrom - ok 19:12:03.0187 4052 Changer - ok 19:12:03.0187 4052 CmdIde - ok 19:12:03.0203 4052 Cpqarray - ok 19:12:03.0203 4052 dac2w2k - ok 19:12:03.0218 4052 dac960nt - ok 19:12:03.0218 4052 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 19:12:03.0218 4052 Disk - ok 19:12:03.0250 4052 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 19:12:03.0265 4052 dmboot - ok 19:12:03.0265 4052 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 19:12:03.0265 4052 dmio - ok 19:12:03.0296 4052 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 19:12:03.0296 4052 dmload - ok 19:12:03.0312 4052 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 19:12:03.0328 4052 DMusic - ok 19:12:03.0328 4052 dpti2o - ok 19:12:03.0343 4052 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 19:12:03.0343 4052 drmkaud - ok 19:12:03.0375 4052 ENTECH (16ebd8bf1d5090923694cc972c7ce1b4) C:\WINDOWS\system32\DRIVERS\ENTECH.sys 19:12:03.0375 4052 ENTECH - ok 19:12:03.0390 4052 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 19:12:03.0390 4052 Fastfat - ok 19:12:03.0406 4052 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 19:12:03.0406 4052 Fdc - ok 19:12:03.0421 4052 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 19:12:03.0421 4052 Fips - ok 19:12:03.0437 4052 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 19:12:03.0437 4052 Flpydisk - ok 19:12:03.0437 4052 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 19:12:03.0437 4052 FltMgr - ok 19:12:03.0453 4052 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 19:12:03.0453 4052 Fs_Rec - ok 19:12:03.0468 4052 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 19:12:03.0468 4052 Ftdisk - ok 19:12:03.0500 4052 gdrv (c6e3105b8c68c35cc1eb26a00fd1a8c6) C:\WINDOWS\gdrv.sys 19:12:05.0171 4052 gdrv - ok 19:12:05.0265 4052 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 19:12:05.0265 4052 Gpc - ok 19:12:05.0296 4052 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 19:12:05.0296 4052 HDAudBus - ok 19:12:05.0312 4052 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 19:12:05.0312 4052 hidusb - ok 19:12:05.0328 4052 hpn - ok 19:12:05.0343 4052 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 19:12:05.0343 4052 HTTP - ok 19:12:05.0359 4052 i2omgmt - ok 19:12:05.0359 4052 i2omp - ok 19:12:05.0359 4052 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 19:12:05.0359 4052 i8042prt - ok 19:12:05.0375 4052 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 19:12:05.0375 4052 Imapi - ok 19:12:05.0375 4052 ini910u - ok 19:12:05.0500 4052 IntcAzAudAddService (4aaa8312732655f93a254d1fa695eb79) C:\WINDOWS\system32\drivers\RtkHDAud.sys 19:12:05.0531 4052 IntcAzAudAddService - ok 19:12:05.0531 4052 IntelIde - ok 19:12:05.0562 4052 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 19:12:05.0562 4052 intelppm - ok 19:12:05.0562 4052 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 19:12:05.0578 4052 Ip6Fw - ok 19:12:05.0593 4052 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 19:12:05.0593 4052 IpFilterDriver - ok 19:12:05.0609 4052 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 19:12:05.0609 4052 IpInIp - ok 19:12:05.0625 4052 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 19:12:05.0625 4052 IpNat - ok 19:12:05.0640 4052 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 19:12:05.0640 4052 IPSec - ok 19:12:05.0656 4052 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 19:12:05.0656 4052 IRENUM - ok 19:12:05.0687 4052 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 19:12:05.0687 4052 isapnp - ok 19:12:05.0718 4052 JRAID (b07084095f8c03aadb9811c9df14b5e4) C:\WINDOWS\system32\DRIVERS\jraid.sys 19:12:05.0718 4052 JRAID - ok 19:12:05.0718 4052 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 19:12:05.0718 4052 Kbdclass - ok 19:12:05.0750 4052 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 19:12:05.0750 4052 kbdhid - ok 19:12:05.0765 4052 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 19:12:05.0765 4052 kmixer - ok 19:12:05.0796 4052 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 19:12:05.0796 4052 KSecDD - ok 19:12:05.0796 4052 lbrtfdc - ok 19:12:05.0828 4052 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 19:12:05.0828 4052 mnmdd - ok 19:12:05.0843 4052 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 19:12:05.0843 4052 Modem - ok 19:12:05.0875 4052 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 19:12:05.0875 4052 Mouclass - ok 19:12:05.0875 4052 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 19:12:05.0875 4052 mouhid - ok 19:12:05.0906 4052 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 19:12:05.0906 4052 MountMgr - ok 19:12:05.0906 4052 mraid35x - ok 19:12:05.0921 4052 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 19:12:05.0921 4052 MRxDAV - ok 19:12:05.0953 4052 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 19:12:05.0968 4052 MRxSmb - ok 19:12:05.0968 4052 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 19:12:05.0968 4052 Msfs - ok 19:12:05.0984 4052 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 19:12:05.0984 4052 MSKSSRV - ok 19:12:06.0000 4052 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 19:12:06.0000 4052 MSPCLOCK - ok 19:12:06.0015 4052 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 19:12:06.0015 4052 MSPQM - ok 19:12:06.0031 4052 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 19:12:06.0031 4052 mssmbios - ok 19:12:06.0062 4052 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys 19:12:06.0062 4052 MTsensor - ok 19:12:06.0078 4052 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 19:12:06.0078 4052 Mup - ok 19:12:06.0125 4052 n558 (88705dc61b9275b82e48904d53031f5b) C:\WINDOWS\system32\Drivers\n558.sys 19:12:06.0125 4052 n558 - ok 19:12:06.0171 4052 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 19:12:06.0171 4052 NDIS - ok 19:12:06.0187 4052 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 19:12:06.0187 4052 NdisTapi - ok 19:12:06.0218 4052 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 19:12:06.0218 4052 Ndisuio - ok 19:12:06.0250 4052 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 19:12:06.0250 4052 NdisWan - ok 19:12:06.0265 4052 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 19:12:06.0265 4052 NDProxy - ok 19:12:06.0281 4052 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 19:12:06.0281 4052 NetBIOS - ok 19:12:06.0296 4052 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 19:12:06.0296 4052 NetBT - ok 19:12:06.0343 4052 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 19:12:06.0343 4052 NIC1394 - ok 19:12:06.0359 4052 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 19:12:06.0359 4052 Npfs - ok 19:12:06.0375 4052 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 19:12:06.0375 4052 Ntfs - ok 19:12:06.0421 4052 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 19:12:06.0421 4052 Null - ok 19:12:06.0593 4052 nv (8c0456001b6900114bbb1c548bd8aaf5) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 19:12:06.0750 4052 nv - ok 19:12:06.0781 4052 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 19:12:06.0781 4052 NwlnkFlt - ok 19:12:06.0796 4052 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 19:12:06.0796 4052 NwlnkFwd - ok 19:12:06.0812 4052 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 19:12:06.0812 4052 ohci1394 - ok 19:12:06.0812 4052 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 19:12:06.0828 4052 Parport - ok 19:12:06.0828 4052 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 19:12:06.0828 4052 PartMgr - ok 19:12:06.0843 4052 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 19:12:06.0843 4052 ParVdm - ok 19:12:06.0859 4052 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 19:12:06.0859 4052 PCI - ok 19:12:06.0875 4052 PCIDump - ok 19:12:06.0875 4052 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 19:12:06.0875 4052 PCIIde - ok 19:12:06.0890 4052 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 19:12:06.0890 4052 Pcmcia - ok 19:12:06.0906 4052 PDCOMP - ok 19:12:06.0906 4052 PDFRAME - ok 19:12:06.0921 4052 PDRELI - ok 19:12:06.0921 4052 PDRFRAME - ok 19:12:06.0921 4052 perc2 - ok 19:12:06.0937 4052 perc2hib - ok 19:12:06.0953 4052 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 19:12:06.0953 4052 PptpMiniport - ok 19:12:06.0953 4052 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 19:12:06.0953 4052 PSched - ok 19:12:06.0968 4052 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 19:12:06.0968 4052 Ptilink - ok 19:12:06.0984 4052 ql1080 - ok 19:12:06.0984 4052 Ql10wnt - ok 19:12:07.0000 4052 ql12160 - ok 19:12:07.0000 4052 ql1240 - ok 19:12:07.0000 4052 ql1280 - ok 19:12:07.0031 4052 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 19:12:07.0031 4052 RasAcd - ok 19:12:07.0031 4052 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 19:12:07.0031 4052 Rasl2tp - ok 19:12:07.0046 4052 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 19:12:07.0046 4052 RasPppoe - ok 19:12:07.0046 4052 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 19:12:07.0046 4052 Raspti - ok 19:12:07.0062 4052 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 19:12:07.0062 4052 Rdbss - ok 19:12:07.0078 4052 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 19:12:07.0078 4052 RDPCDD - ok 19:12:07.0109 4052 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 19:12:07.0109 4052 RDPWD - ok 19:12:07.0125 4052 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 19:12:07.0125 4052 redbook - ok 19:12:07.0156 4052 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 19:12:07.0156 4052 RFCOMM - ok 19:12:07.0171 4052 RTLE8023xp (f0a21c62b9b835e1c96268eaae31d239) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 19:12:07.0171 4052 RTLE8023xp - ok 19:12:07.0218 4052 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 19:12:07.0218 4052 Secdrv - ok 19:12:07.0218 4052 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 19:12:07.0234 4052 serenum - ok 19:12:07.0234 4052 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 19:12:07.0234 4052 Serial - ok 19:12:07.0250 4052 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 19:12:07.0250 4052 Sfloppy - ok 19:12:07.0250 4052 Simbad - ok 19:12:07.0265 4052 Sparrow - ok 19:12:07.0281 4052 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 19:12:07.0281 4052 splitter - ok 19:12:07.0296 4052 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 19:12:07.0296 4052 sr - ok 19:12:07.0328 4052 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 19:12:07.0328 4052 Srv - ok 19:12:07.0343 4052 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 19:12:07.0343 4052 swenum - ok 19:12:07.0359 4052 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 19:12:07.0359 4052 swmidi - ok 19:12:07.0375 4052 symc810 - ok 19:12:07.0375 4052 symc8xx - ok 19:12:07.0390 4052 sym_hi - ok 19:12:07.0390 4052 sym_u3 - ok 19:12:07.0406 4052 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 19:12:07.0406 4052 sysaudio - ok 19:12:07.0453 4052 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 19:12:07.0453 4052 Tcpip - ok 19:12:07.0468 4052 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 19:12:07.0468 4052 TDPIPE - ok 19:12:07.0484 4052 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 19:12:07.0484 4052 TDTCP - ok 19:12:07.0500 4052 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 19:12:07.0500 4052 TermDD - ok 19:12:07.0500 4052 TosIde - ok 19:12:07.0515 4052 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 19:12:07.0515 4052 Udfs - ok 19:12:07.0515 4052 ultra - ok 19:12:07.0531 4052 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 19:12:07.0531 4052 Update - ok 19:12:07.0546 4052 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 19:12:07.0546 4052 usbaudio - ok 19:12:07.0562 4052 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 19:12:07.0562 4052 usbccgp - ok 19:12:07.0609 4052 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 19:12:07.0609 4052 usbehci - ok 19:12:07.0625 4052 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 19:12:07.0625 4052 usbhub - ok 19:12:07.0625 4052 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 19:12:07.0625 4052 usbprint - ok 19:12:07.0640 4052 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 19:12:07.0640 4052 usbscan - ok 19:12:07.0656 4052 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 19:12:07.0656 4052 USBSTOR - ok 19:12:07.0703 4052 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 19:12:07.0703 4052 usbuhci - ok 19:12:07.0718 4052 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 19:12:07.0718 4052 VgaSave - ok 19:12:07.0718 4052 ViaIde - ok 19:12:07.0734 4052 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 19:12:07.0734 4052 VolSnap - ok 19:12:07.0750 4052 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 19:12:07.0750 4052 Wanarp - ok 19:12:07.0796 4052 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 19:12:07.0796 4052 Wdf01000 - ok 19:12:07.0812 4052 WDICA - ok 19:12:07.0828 4052 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 19:12:07.0828 4052 wdmaud - ok 19:12:07.0875 4052 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 19:12:07.0875 4052 WpdUsb - ok 19:12:07.0906 4052 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 19:12:07.0906 4052 WS2IFSL - ok 19:12:07.0953 4052 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 19:12:07.0953 4052 WudfPf - ok 19:12:07.0984 4052 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 19:12:07.0984 4052 WudfRd - ok 19:12:07.0984 4052 xcpip - ok 19:12:08.0000 4052 xpsec - ok 19:12:08.0046 4052 xusb21 (f5e5f944e63a9b5f6e76c2ebb2ac462f) C:\WINDOWS\system32\DRIVERS\xusb21.sys 19:12:08.0046 4052 xusb21 - ok 19:12:08.0062 4052 MBR (0x1B8) (f381baacfc1778337c007982b0c32d82) \Device\Harddisk0\DR0 19:12:08.0062 4052 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected 19:12:08.0062 4052 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0) 19:12:08.0062 4052 Boot (0x1200) (8507be9d5dceef71561a3fa11832abff) \Device\Harddisk0\DR0\Partition0 19:12:08.0078 4052 \Device\Harddisk0\DR0\Partition0 - ok 19:12:08.0078 4052 ============================================================ 19:12:08.0078 4052 Scan finished 19:12:08.0078 4052 ============================================================ 19:12:08.0078 4064 Detected object count: 1 19:12:08.0078 4064 Actual detected object count: 1 19:12:32.0671 4064 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - skipped by user 19:12:32.0671 4064 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Skip
20:34:31.0890 1708 TDSS rootkit removing tool [removed] Feb 15 2012 19:33:14 20:34:32.0531 1708 ============================================================ 20:34:32.0531 1708 Current date / time: 2012/02/21 20:34:32.0531 20:34:32.0531 1708 SystemInfo: 20:34:32.0531 1708 20:34:32.0531 1708 OS Version: 5.1.2600 ServicePack: 3.0 20:34:32.0531 1708 Product type: Workstation 20:34:32.0531 1708 ComputerName: BRIAN-E921DFA8C 20:34:32.0531 1708 UserName: brian 20:34:32.0531 1708 Windows directory: C:\WINDOWS 20:34:32.0531 1708 System windows directory: C:\WINDOWS 20:34:32.0531 1708 Processor architecture: Intel x86 20:34:32.0531 1708 Number of processors: 2 20:34:32.0531 1708 Page size: 0x1000 20:34:32.0531 1708 Boot type: Normal boot 20:34:32.0531 1708 ============================================================ 20:34:33.0593 1708 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:34:33.0593 1708 \Device\Harddisk0\DR0: 20:34:33.0593 1708 MBR used 20:34:33.0593 1708 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x254297C1 20:34:33.0609 1708 Initialize success 20:34:33.0609 1708 ============================================================ 20:34:35.0812 0952 ============================================================ 20:34:35.0812 0952 Scan started 20:34:35.0812 0952 Mode: Manual; 20:34:35.0812 0952 ============================================================ 20:34:36.0562 0952 6h9wk8_3.sys - ok 20:34:36.0562 0952 Abiosdsk - ok 20:34:36.0578 0952 abp480n5 - ok 20:34:36.0609 0952 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:34:36.0609 0952 ACPI - ok 20:34:36.0640 0952 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 20:34:36.0640 0952 ACPIEC - ok 20:34:36.0656 0952 adpu160m - ok 20:34:36.0687 0952 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 20:34:36.0687 0952 aec - ok 20:34:36.0718 0952 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 20:34:36.0718 0952 AFD - ok 20:34:36.0734 0952 Aha154x - ok 20:34:36.0734 0952 aic78u2 - ok 20:34:36.0750 0952 aic78xx - ok 20:34:36.0750 0952 AliIde - ok 20:34:36.0765 0952 amsint - ok 20:34:36.0796 0952 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 20:34:36.0796 0952 Arp1394 - ok 20:34:36.0796 0952 asc - ok 20:34:36.0812 0952 asc3350p - ok 20:34:36.0812 0952 asc3550 - ok 20:34:36.0828 0952 AsIO (663f2fb92608073824ee3106886120f3) C:\WINDOWS\system32\drivers\AsIO.sys 20:34:36.0828 0952 AsIO - ok 20:34:36.0859 0952 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:34:36.0859 0952 AsyncMac - ok 20:34:36.0875 0952 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 20:34:36.0875 0952 atapi - ok 20:34:36.0906 0952 AtcL001 (19f277bc4ce5689f20f347a6b8aa8c42) C:\WINDOWS\system32\DRIVERS\atl01_xp.sys 20:34:36.0906 0952 AtcL001 - ok 20:34:36.0906 0952 Atdisk - ok 20:34:36.0937 0952 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:34:36.0937 0952 Atmarpc - ok 20:34:36.0968 0952 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 20:34:36.0968 0952 audstub - ok 20:34:37.0015 0952 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 20:34:37.0015 0952 Beep - ok 20:34:37.0015 0952 btaudio - ok 20:34:37.0031 0952 BTDriver - ok 20:34:37.0062 0952 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 20:34:37.0062 0952 BthEnum - ok 20:34:37.0062 0952 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 20:34:37.0062 0952 BthPan - ok 20:34:37.0078 0952 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 20:34:37.0093 0952 BTHPORT - ok 20:34:37.0109 0952 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 20:34:37.0109 0952 BTHUSB - ok 20:34:37.0109 0952 BTWDNDIS - ok 20:34:37.0125 0952 btwhid - ok 20:34:37.0125 0952 btwmodem - ok 20:34:37.0125 0952 BTWUSB - ok 20:34:37.0140 0952 catchme - ok 20:34:37.0171 0952 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 20:34:37.0171 0952 cbidf2k - ok 20:34:37.0171 0952 cd20xrnt - ok 20:34:37.0203 0952 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 20:34:37.0203 0952 Cdaudio - ok 20:34:37.0203 0952 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 20:34:37.0203 0952 Cdfs - ok 20:34:37.0234 0952 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:34:37.0234 0952 Cdrom - ok 20:34:37.0234 0952 Changer - ok 20:34:37.0250 0952 CmdIde - ok 20:34:37.0250 0952 Cpqarray - ok 20:34:37.0265 0952 dac2w2k - ok 20:34:37.0265 0952 dac960nt - ok 20:34:37.0281 0952 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 20:34:37.0281 0952 Disk - ok 20:34:37.0312 0952 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 20:34:37.0312 0952 dmboot - ok 20:34:37.0328 0952 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 20:34:37.0328 0952 dmio - ok 20:34:37.0343 0952 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 20:34:37.0343 0952 dmload - ok 20:34:37.0359 0952 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 20:34:37.0359 0952 DMusic - ok 20:34:37.0375 0952 dpti2o - ok 20:34:37.0375 0952 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 20:34:37.0390 0952 drmkaud - ok 20:34:37.0406 0952 ENTECH (16ebd8bf1d5090923694cc972c7ce1b4) C:\WINDOWS\system32\DRIVERS\ENTECH.sys 20:34:37.0406 0952 ENTECH - ok 20:34:37.0437 0952 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 20:34:37.0437 0952 Fastfat - ok 20:34:37.0453 0952 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 20:34:37.0453 0952 Fdc - ok 20:34:37.0468 0952 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 20:34:37.0468 0952 Fips - ok 20:34:37.0484 0952 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20:34:37.0484 0952 Flpydisk - ok 20:34:37.0484 0952 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 20:34:37.0484 0952 FltMgr - ok 20:34:37.0500 0952 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:34:37.0500 0952 Fs_Rec - ok 20:34:37.0500 0952 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:34:37.0500 0952 Ftdisk - ok 20:34:37.0531 0952 gdrv (c6e3105b8c68c35cc1eb26a00fd1a8c6) C:\WINDOWS\gdrv.sys 20:34:37.0531 0952 gdrv - ok 20:34:37.0531 0952 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:34:37.0531 0952 Gpc - ok 20:34:37.0562 0952 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 20:34:37.0562 0952 HDAudBus - ok 20:34:37.0562 0952 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:34:37.0562 0952 hidusb - ok 20:34:37.0562 0952 hpn - ok 20:34:37.0609 0952 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 20:34:37.0609 0952 HTTP - ok 20:34:37.0609 0952 i2omgmt - ok 20:34:37.0625 0952 i2omp - ok 20:34:37.0625 0952 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 20:34:37.0625 0952 i8042prt - ok 20:34:37.0640 0952 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 20:34:37.0640 0952 Imapi - ok 20:34:37.0640 0952 ini910u - ok 20:34:37.0765 0952 IntcAzAudAddService (4aaa8312732655f93a254d1fa695eb79) C:\WINDOWS\system32\drivers\RtkHDAud.sys 20:34:37.0781 0952 IntcAzAudAddService - ok 20:34:37.0781 0952 IntelIde - ok 20:34:37.0812 0952 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:34:37.0812 0952 intelppm - ok 20:34:37.0812 0952 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 20:34:37.0812 0952 Ip6Fw - ok 20:34:37.0828 0952 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:34:37.0843 0952 IpFilterDriver - ok 20:34:37.0859 0952 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:34:37.0859 0952 IpInIp - ok 20:34:37.0875 0952 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:34:37.0875 0952 IpNat - ok 20:34:37.0890 0952 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:34:37.0890 0952 IPSec - ok 20:34:37.0906 0952 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 20:34:37.0906 0952 IRENUM - ok 20:34:37.0921 0952 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:34:37.0921 0952 isapnp - ok 20:34:37.0937 0952 JRAID (b07084095f8c03aadb9811c9df14b5e4) C:\WINDOWS\system32\DRIVERS\jraid.sys 20:34:37.0937 0952 JRAID - ok 20:34:37.0937 0952 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:34:37.0937 0952 Kbdclass - ok 20:34:37.0984 0952 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 20:34:37.0984 0952 kbdhid - ok 20:34:38.0000 0952 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 20:34:38.0000 0952 kmixer - ok 20:34:38.0015 0952 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 20:34:38.0015 0952 KSecDD - ok 20:34:38.0031 0952 lbrtfdc - ok 20:34:38.0046 0952 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 20:34:38.0046 0952 mnmdd - ok 20:34:38.0062 0952 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 20:34:38.0062 0952 Modem - ok 20:34:38.0093 0952 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:34:38.0093 0952 Mouclass - ok 20:34:38.0093 0952 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 20:34:38.0093 0952 mouhid - ok 20:34:38.0109 0952 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 20:34:38.0109 0952 MountMgr - ok 20:34:38.0109 0952 mraid35x - ok 20:34:38.0125 0952 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:34:38.0125 0952 MRxDAV - ok 20:34:38.0156 0952 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:34:38.0156 0952 MRxSmb - ok 20:34:38.0171 0952 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 20:34:38.0171 0952 Msfs - ok 20:34:38.0171 0952 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:34:38.0171 0952 MSKSSRV - ok 20:34:38.0187 0952 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:34:38.0187 0952 MSPCLOCK - ok 20:34:38.0203 0952 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 20:34:38.0203 0952 MSPQM - ok 20:34:38.0218 0952 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:34:38.0218 0952 mssmbios - ok 20:34:38.0250 0952 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys 20:34:38.0250 0952 MTsensor - ok 20:34:38.0281 0952 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 20:34:38.0281 0952 Mup - ok 20:34:38.0312 0952 n558 (88705dc61b9275b82e48904d53031f5b) C:\WINDOWS\system32\Drivers\n558.sys 20:34:38.0312 0952 n558 - ok 20:34:38.0328 0952 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 20:34:38.0328 0952 NDIS - ok 20:34:38.0375 0952 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:34:38.0375 0952 NdisTapi - ok 20:34:38.0562 0952 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:34:38.0562 0952 Ndisuio - ok 20:34:38.0687 0952 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:34:38.0687 0952 NdisWan - ok 20:34:38.0718 0952 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 20:34:38.0718 0952 NDProxy - ok 20:34:38.0718 0952 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 20:34:38.0718 0952 NetBIOS - ok 20:34:38.0750 0952 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 20:34:38.0750 0952 NetBT - ok 20:34:38.0765 0952 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 20:34:38.0765 0952 NIC1394 - ok 20:34:38.0781 0952 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 20:34:38.0781 0952 Npfs - ok 20:34:38.0796 0952 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 20:34:38.0812 0952 Ntfs - ok 20:34:38.0843 0952 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 20:34:38.0843 0952 Null - ok 20:34:39.0015 0952 nv (8c0456001b6900114bbb1c548bd8aaf5) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 20:34:39.0046 0952 nv - ok 20:34:39.0093 0952 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:34:39.0093 0952 NwlnkFlt - ok 20:34:39.0109 0952 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:34:39.0109 0952 NwlnkFwd - ok 20:34:39.0109 0952 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 20:34:39.0109 0952 ohci1394 - ok 20:34:39.0125 0952 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 20:34:39.0125 0952 Parport - ok 20:34:39.0140 0952 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 20:34:39.0140 0952 PartMgr - ok 20:34:39.0156 0952 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 20:34:39.0156 0952 ParVdm - ok 20:34:39.0171 0952 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 20:34:39.0171 0952 PCI - ok 20:34:39.0171 0952 PCIDump - ok 20:34:39.0187 0952 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 20:34:39.0187 0952 PCIIde - ok 20:34:39.0203 0952 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 20:34:39.0203 0952 Pcmcia - ok 20:34:39.0218 0952 PDCOMP - ok 20:34:39.0218 0952 PDFRAME - ok 20:34:39.0234 0952 PDRELI - ok 20:34:39.0234 0952 PDRFRAME - ok 20:34:39.0250 0952 perc2 - ok 20:34:39.0250 0952 perc2hib - ok 20:34:39.0265 0952 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:34:39.0265 0952 PptpMiniport - ok 20:34:39.0265 0952 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 20:34:39.0265 0952 PSched - ok 20:34:39.0281 0952 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:34:39.0281 0952 Ptilink - ok 20:34:39.0281 0952 ql1080 - ok 20:34:39.0296 0952 Ql10wnt - ok 20:34:39.0296 0952 ql12160 - ok 20:34:39.0312 0952 ql1240 - ok 20:34:39.0312 0952 ql1280 - ok 20:34:39.0328 0952 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:34:39.0328 0952 RasAcd - ok 20:34:39.0343 0952 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:34:39.0343 0952 Rasl2tp - ok 20:34:39.0343 0952 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:34:39.0343 0952 RasPppoe - ok 20:34:39.0359 0952 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 20:34:39.0359 0952 Raspti - ok 20:34:39.0359 0952 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:34:39.0359 0952 Rdbss - ok 20:34:39.0390 0952 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:34:39.0390 0952 RDPCDD - ok 20:34:39.0437 0952 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 20:34:39.0437 0952 RDPWD - ok 20:34:39.0453 0952 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 20:34:39.0453 0952 redbook - ok 20:34:39.0484 0952 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 20:34:39.0484 0952 RFCOMM - ok 20:34:39.0515 0952 RTLE8023xp (f0a21c62b9b835e1c96268eaae31d239) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 20:34:39.0515 0952 RTLE8023xp - ok 20:34:39.0546 0952 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:34:39.0546 0952 Secdrv - ok 20:34:39.0562 0952 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 20:34:39.0562 0952 serenum - ok 20:34:39.0562 0952 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 20:34:39.0562 0952 Serial - ok 20:34:39.0578 0952 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 20:34:39.0578 0952 Sfloppy - ok 20:34:39.0578 0952 Simbad - ok 20:34:39.0593 0952 Sparrow - ok 20:34:39.0609 0952 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 20:34:39.0609 0952 splitter - ok 20:34:39.0609 0952 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 20:34:39.0625 0952 sr - ok 20:34:39.0640 0952 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 20:34:39.0640 0952 Srv - ok 20:34:39.0671 0952 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 20:34:39.0671 0952 swenum - ok 20:34:39.0671 0952 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 20:34:39.0671 0952 swmidi - ok 20:34:39.0687 0952 symc810 - ok 20:34:39.0687 0952 symc8xx - ok 20:34:39.0703 0952 sym_hi - ok 20:34:39.0703 0952 sym_u3 - ok 20:34:39.0734 0952 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 20:34:39.0734 0952 sysaudio - ok 20:34:39.0781 0952 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:34:39.0781 0952 Tcpip - ok 20:34:39.0796 0952 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 20:34:39.0796 0952 TDPIPE - ok 20:34:39.0812 0952 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 20:34:39.0812 0952 TDTCP - ok 20:34:39.0812 0952 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 20:34:39.0812 0952 TermDD - ok 20:34:39.0828 0952 TosIde - ok 20:34:39.0828 0952 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 20:34:39.0828 0952 Udfs - ok 20:34:39.0843 0952 ultra - ok 20:34:39.0859 0952 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 20:34:39.0859 0952 Update - ok 20:34:39.0890 0952 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 20:34:39.0890 0952 usbaudio - ok 20:34:39.0890 0952 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 20:34:39.0906 0952 usbccgp - ok 20:34:39.0937 0952 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:34:39.0937 0952 usbehci - ok 20:34:39.0953 0952 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:34:39.0953 0952 usbhub - ok 20:34:39.0953 0952 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 20:34:39.0968 0952 usbprint - ok 20:34:39.0968 0952 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 20:34:39.0968 0952 usbscan - ok 20:34:39.0984 0952 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:34:39.0984 0952 USBSTOR - ok 20:34:40.0031 0952 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:34:40.0031 0952 usbuhci - ok 20:34:40.0078 0952 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 20:34:40.0078 0952 VgaSave - ok 20:34:40.0078 0952 ViaIde - ok 20:34:40.0093 0952 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 20:34:40.0093 0952 VolSnap - ok 20:34:40.0125 0952 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:34:40.0125 0952 Wanarp - ok 20:34:40.0171 0952 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 20:34:40.0171 0952 Wdf01000 - ok 20:34:40.0187 0952 WDICA - ok 20:34:40.0203 0952 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 20:34:40.0203 0952 wdmaud - ok 20:34:40.0250 0952 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 20:34:40.0250 0952 WpdUsb - ok 20:34:40.0281 0952 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 20:34:40.0281 0952 WS2IFSL - ok 20:34:40.0312 0952 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 20:34:40.0312 0952 WudfPf - ok 20:34:40.0328 0952 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 20:34:40.0328 0952 WudfRd - ok 20:34:40.0343 0952 xcpip - ok 20:34:40.0343 0952 xpsec - ok 20:34:40.0390 0952 xusb21 (f5e5f944e63a9b5f6e76c2ebb2ac462f) C:\WINDOWS\system32\DRIVERS\xusb21.sys 20:34:40.0406 0952 xusb21 - ok 20:34:40.0421 0952 MBR (0x1B8) (f381baacfc1778337c007982b0c32d82) \Device\Harddisk0\DR0 20:34:40.0421 0952 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - infected 20:34:40.0421 0952 \Device\Harddisk0\DR0 - detected Backdoor.Win32.Sinowal.knf (0) 20:34:40.0421 0952 Boot (0x1200) (8507be9d5dceef71561a3fa11832abff) \Device\Harddisk0\DR0\Partition0 20:34:40.0421 0952 \Device\Harddisk0\DR0\Partition0 - ok 20:34:40.0421 0952 ============================================================ 20:34:40.0421 0952 Scan finished 20:34:40.0421 0952 ============================================================ 20:34:40.0421 0432 Detected object count: 1 20:34:40.0421 0432 Actual detected object count: 1 20:34:51.0687 0432 \Device\Harddisk0\DR0\# - copied to quarantine 20:34:51.0687 0432 \Device\Harddisk0\DR0 - copied to quarantine 20:34:51.0703 0432 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - will be cured on reboot 20:34:51.0703 0432 \Device\Harddisk0\DR0 - ok 20:34:51.0703 0432 \Device\Harddisk0\DR0 ( Backdoor.Win32.Sinowal.knf ) - User select action: Cure 20:35:02.0125 3912 Deinitialize success

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI