Virus still present after full system restore (Trojan:Dos/Alureon.E) [
18 min read
OTL logfile created on: 2/29/2012 11:00:31 AM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Russell\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.10% Memory free
3.85 Gb Paging File | 3.49 Gb Available in Paging File | 90.71% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 87.05 Gb Total Space | 69.19 Gb Free Space | 79.48% Space Free | Partition Type: NTFS
Computer Name: BASESTATION | User Name: Russell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Russell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
PRC - C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\NetWaiting\netwaiting.exe ()
========== Modules (No Company Name) ==========
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_c3f6dbb1\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_273780c2\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4314e828\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_41d007e8\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_43a77e74\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
MOD - C:\WINDOWS\system32\TosBtHcrpAPI.dll ()
MOD - C:\Program Files\NetWaiting\netwaiting.exe ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (Bluetooth Hid Switch Service) – C:\Program Files\BlueTooth\HidSwitchService\HidSw.exe (Cambridge Silicon Radio)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/?fr=yfp-t-403"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/23 01:22:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/02/23 01:23:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Extensions
[2012/02/26 15:58:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\5nb0ik0f.default\extensions
[2012/02/23 01:41:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/23 01:41:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/02/23 01:41:28 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/16 09:40:42 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/16 05:42:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/16 05:42:53 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2004/08/10 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DellHelp] C:\Dell\DellHelp\DellHelp.exe (Dell Inc)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShowLOMControl] Reg Error: Invalid data type. File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1329975759726 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1329978404062 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BFFF9B8-868B-4C05-9A5A-613F6B79DD18}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/29 10:47:17 | 000,607,260 | —- | C] (Swearware) – C:\Documents and Settings\Russell\Desktop\dds.scr
[2012/02/29 10:46:53 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/29 10:45:54 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/29 04:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/02/28 05:09:08 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Videos
[2012/02/27 04:07:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2012/02/27 04:07:17 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2012/02/27 04:07:04 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2012/02/27 04:06:36 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2012/02/27 04:06:36 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2012/02/27 04:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2012/02/27 04:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2012/02/27 04:06:35 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2012/02/27 04:06:35 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2012/02/27 04:06:34 | 000,000,000 | —D | C] – C:\59e129738cb8df114e94
[2012/02/26 15:30:41 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IECompatCache
[2012/02/26 15:29:09 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\PrivacIE
[2012/02/26 15:22:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/02/26 15:10:51 | 016,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 05:55:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2012/02/26 05:54:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Google
[2012/02/26 05:54:36 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/02/26 05:52:02 | 014,886,760 | —- | C] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/26 00:56:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\AdobeUM
[2012/02/26 00:56:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Adobe
[2012/02/26 00:56:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\My eBooks
[2012/02/26 00:55:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/02/25 23:32:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel Photo Album
[2012/02/25 23:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Corel Photo Album
[2012/02/25 21:59:03 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2012/02/25 21:59:02 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/02/25 21:52:18 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IETldCache
[2012/02/23 16:23:38 | 004,448,256 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/02/23 03:32:16 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2012/02/23 03:32:02 | 011,082,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2012/02/23 03:32:02 | 002,000,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2012/02/23 03:32:02 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/02/23 03:32:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/02/23 03:32:01 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/02/23 03:31:47 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/02/23 03:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Macromedia
[2012/02/23 03:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Adobe
[2012/02/23 03:13:30 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 03:11:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\Downloads
[2012/02/23 03:03:12 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2012/02/23 02:10:03 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2012/02/23 02:08:19 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2012/02/23 02:08:19 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2012/02/23 02:07:38 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2012/02/23 02:07:24 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2012/02/23 02:05:55 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2012/02/23 02:05:18 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2012/02/23 02:05:18 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2012/02/23 02:04:03 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2012/02/23 01:58:54 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2012/02/23 01:58:43 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012/02/23 01:58:04 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2012/02/23 01:57:58 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2012/02/23 01:57:58 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2012/02/23 01:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2012/02/23 01:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2012/02/23 01:57:57 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2012/02/23 01:57:56 | 001,025,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browseui.dll
[2012/02/23 01:57:33 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2012/02/23 01:55:15 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2012/02/23 01:53:40 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2012/02/23 01:53:30 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2012/02/23 01:51:46 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012/02/23 01:47:48 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2012/02/23 01:47:23 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2012/02/23 01:46:48 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012/02/23 01:46:43 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2012/02/23 01:42:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2012/02/23 01:42:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/02/23 01:41:41 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 01:41:41 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 01:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 01:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 01:41:41 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 01:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Mozilla
[2012/02/23 01:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Mozilla
[2012/02/23 01:22:32 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/02/23 00:56:53 | 000,237,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/02/23 00:49:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/02/23 00:46:04 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oakley.dll
[2012/02/23 00:46:03 | 001,212,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2012/02/23 00:46:03 | 000,916,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2012/02/23 00:46:02 | 001,510,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shdocvw.dll
[2012/02/23 00:46:01 | 005,979,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2012/02/23 00:45:28 | 000,343,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspaint.exe
[2012/02/23 00:44:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2012/02/23 00:44:45 | 002,334,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMVCore.dll
[2012/02/23 00:43:10 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/02/23 00:43:10 | 000,021,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/02/23 00:43:09 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/02/23 00:43:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2012/02/23 00:35:56 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russell\UserData
[2012/02/22 23:38:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2012/02/22 23:37:51 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012/02/22 23:31:12 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2012/02/22 23:31:11 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2012/02/22 23:31:11 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2012/02/22 23:31:03 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2012/02/22 23:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2012/02/22 23:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2012/02/22 23:31:01 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2012/02/22 23:31:01 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2012/02/22 23:31:01 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2012/02/22 23:31:01 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2012/02/22 23:31:01 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2012/02/22 23:31:01 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2012/02/22 23:31:01 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2012/02/22 23:31:00 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2012/02/22 23:31:00 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2012/02/22 23:31:00 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2012/02/22 23:31:00 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2012/02/22 23:31:00 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2012/02/22 23:31:00 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2012/02/22 23:31:00 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2012/02/22 23:31:00 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2012/02/22 23:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2012/02/22 23:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2012/02/22 23:31:00 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2012/02/22 23:30:59 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2012/02/22 23:30:58 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2012/02/22 23:30:57 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2012/02/22 23:30:57 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2012/02/22 23:30:57 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2012/02/22 23:30:57 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2012/02/22 23:30:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2012/02/22 23:30:57 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2012/02/22 23:30:57 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2012/02/22 23:30:57 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2012/02/22 23:30:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2012/02/22 23:30:57 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2012/02/22 23:30:56 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2012/02/22 23:30:56 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2012/02/22 23:30:56 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2012/02/22 23:30:56 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2012/02/22 23:30:56 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2012/02/22 23:30:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2012/02/22 23:30:56 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2012/02/22 23:30:56 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2012/02/22 23:30:56 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2012/02/22 23:30:56 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2012/02/22 23:30:56 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2012/02/22 23:30:55 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2012/02/22 23:30:55 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2012/02/22 23:30:55 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2012/02/22 23:30:55 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2012/02/22 23:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2012/02/22 23:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2012/02/22 23:30:53 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2012/02/22 23:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2012/02/22 23:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-us
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2012/02/22 23:28:50 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2012/02/22 23:26:27 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2012/02/22 23:26:27 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2012/02/22 23:26:27 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2012/02/22 23:26:27 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2012/02/22 23:26:27 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2012/02/22 23:26:27 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2012/02/22 23:26:27 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2012/02/22 23:26:27 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2012/02/22 23:26:27 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2012/02/22 23:26:27 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2012/02/22 23:26:27 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2012/02/22 23:26:27 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2012/02/22 23:26:27 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2012/02/22 23:26:27 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2012/02/22 23:26:27 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2012/02/22 23:26:27 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2012/02/22 23:26:27 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2012/02/22 23:26:27 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2012/02/22 23:26:27 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2012/02/22 23:26:27 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2012/02/22 23:26:27 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2012/02/22 23:26:27 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2012/02/22 23:26:26 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2012/02/22 23:26:26 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2012/02/22 23:26:26 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2012/02/22 23:26:26 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2012/02/22 23:26:26 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2012/02/22 23:26:26 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2012/02/22 23:26:26 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2012/02/22 23:26:26 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2012/02/22 23:26:26 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2012/02/22 23:26:26 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2012/02/22 23:26:26 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2012/02/22 23:26:26 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2012/02/22 23:26:26 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2012/02/22 23:26:26 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2012/02/22 23:26:25 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2012/02/22 23:26:25 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2012/02/22 23:26:25 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2012/02/22 23:26:25 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2012/02/22 23:26:25 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2012/02/22 23:26:25 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2012/02/22 23:26:24 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2012/02/22 23:26:24 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2012/02/22 23:26:24 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2012/02/22 23:26:24 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2012/02/22 23:26:24 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2012/02/22 23:26:24 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2012/02/22 23:26:24 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2012/02/22 23:26:24 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2012/02/22 23:26:24 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2012/02/22 23:26:24 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2012/02/22 23:26:24 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2012/02/22 23:26:23 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2012/02/22 23:26:23 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2012/02/22 23:26:23 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2012/02/22 23:26:23 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2012/02/22 23:25:28 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/02/22 23:22:05 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2012/02/22 23:17:48 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/22 23:17:37 | 331,805,736 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe
[2012/02/22 23:08:08 | 000,000,000 | RH-D | C] – C:\MSOCache
[2012/02/19 23:45:21 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2012/02/19 21:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\McAfee.com Personal Firewall
[2012/02/19 21:03:15 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russell\Application Data\Microsoft
[2012/02/19 21:03:15 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Application Data
[2012/02/19 21:03:15 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Favorites
[2012/02/19 21:03:15 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\Cookies
[2012/02/19 21:03:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Local Settings
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Wildtangent
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Sun
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Musicmatch
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Microsoft
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Intel
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Identities
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Gtek
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\BVRP Software
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ATI
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\ATI
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ApplicationHistory
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2012/02/19 21:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\SendTo
[2012/02/19 21:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Recent
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Startup
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Pictures
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Music
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Accessories
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Templates
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\PrintHood
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\NetHood
[2012/02/19 21:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell Accessories
[2012/02/19 21:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/29 10:47:21 | 000,607,260 | —- | M] (Swearware) – C:\Documents and Settings\Russell\Desktop\dds.scr
[2012/02/29 10:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/29 10:45:58 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/29 09:46:10 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/29 09:40:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/29 09:40:56 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/02/29 03:27:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/28 05:16:22 | 000,443,034 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/28 05:16:22 | 000,072,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/28 05:09:03 | 000,000,804 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/02/28 05:09:03 | 000,000,786 | —- | M] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/02/27 04:21:14 | 000,135,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/27 03:49:12 | 000,102,176 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 03:47:43 | 000,039,426 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 16:49:58 | 000,068,829 | —- | M] () – C:\Documents and Settings\Russell\Desktop\15162_x800.jpg
[2012/02/26 15:46:05 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/02/26 15:28:09 | 000,000,815 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/26 15:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 05:57:49 | 000,003,766 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/26 05:57:48 | 000,000,088 | RHS- | M] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/26 05:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/26 02:06:56 | 000,033,388 | —- | M] () – C:\Documents and Settings\Russell\Desktop\BlueT10_02.jpg
[2012/02/26 01:55:42 | 000,031,125 | —- | M] () – C:\Documents and Settings\Russell\Desktop\A4.jpg
[2012/02/26 01:55:31 | 000,025,906 | —- | M] () – C:\Documents and Settings\Russell\Desktop\A1.jpg
[2012/02/25 23:36:03 | 000,030,307 | —- | M] () – C:\Documents and Settings\Russell\Desktop\453718271_o.jpg
[2012/02/25 23:31:37 | 000,209,908 | —- | M] () – C:\Documents and Settings\Russell\Desktop\amber_lights.jpg
[2012/02/23 16:23:38 | 004,448,256 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/02/23 03:13:30 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 01:41:26 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 01:41:26 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 01:41:26 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 01:41:25 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 01:41:25 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 01:22:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 00:50:50 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/02/22 23:39:31 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/02/22 23:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/22 23:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/02/22 19:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/22 19:01:32 | 331,805,736 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe
[2012/02/22 18:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 21:20:37 | 000,031,648 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2012/02/19 21:11:34 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2012/02/19 21:03:37 | 000,000,130 | —- | M] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 21:03:22 | 000,001,478 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 21:03:00 | 000,000,448 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012/02/19 21:02:55 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2012/02/19 20:54:36 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/28 05:09:03 | 000,000,804 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/02/27 03:49:12 | 000,102,176 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 03:47:43 | 000,039,426 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 16:49:58 | 000,068,829 | —- | C] () – C:\Documents and Settings\Russell\Desktop\15162_x800.jpg
[2012/02/26 02:06:56 | 000,033,388 | —- | C] () – C:\Documents and Settings\Russell\Desktop\BlueT10_02.jpg
[2012/02/26 01:55:42 | 000,031,125 | —- | C] () – C:\Documents and Settings\Russell\Desktop\A4.jpg
[2012/02/26 01:55:31 | 000,025,906 | —- | C] () – C:\Documents and Settings\Russell\Desktop\A1.jpg
[2012/02/25 23:36:03 | 000,030,307 | —- | C] () – C:\Documents and Settings\Russell\Desktop\453718271_o.jpg
[2012/02/25 23:31:48 | 000,003,766 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/25 23:31:48 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/25 23:31:36 | 000,209,908 | —- | C] () – C:\Documents and Settings\Russell\Desktop\amber_lights.jpg
[2012/02/23 01:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/23 01:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/23 01:22:39 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 00:55:35 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/23 00:50:50 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2012/02/23 00:50:24 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/23 00:45:58 | 001,292,288 | —- | C] () – C:\WINDOWS\System32\dllcache\quartz.dll
[2012/02/22 23:26:26 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012/02/22 23:26:26 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2012/02/22 23:26:25 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2012/02/22 23:25:14 | 000,004,128 | —- | C] () – C:\INFCACHE.1
[2012/02/22 23:17:58 | 001,359,824 | —- | C] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 21:11:34 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/02/19 21:03:23 | 000,000,786 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/02/19 21:03:16 | 000,002,007 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2012/02/19 21:03:16 | 000,001,824 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk
[2012/02/19 21:03:16 | 000,001,769 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk
[2012/02/19 21:03:16 | 000,001,478 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 21:03:16 | 000,001,298 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Media Center.lnk
[2012/02/19 21:03:16 | 000,000,815 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/19 21:03:16 | 000,000,742 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2012/02/19 21:03:16 | 000,000,130 | —- | C] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 21:03:16 | 000,000,079 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/02/19 21:03:15 | 000,001,503 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Remote Assistance.lnk
[2012/02/19 21:03:15 | 000,000,803 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Internet Explorer.lnk
[2012/02/19 21:03:15 | 000,000,792 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Windows Media Player.lnk
[2012/02/19 21:03:15 | 000,000,738 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Outlook Express.lnk
[2012/02/19 20:54:36 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
========== LOP Check ==========
[2006/04/22 10:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/02/29 09:46:10 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/08/16 04:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/02/19 21:02:55 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/08/16 04:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/22 10:05:26 | 000,006,905 | RH– | M] () – C:\dell.sdr
[2012/02/29 09:40:56 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/02/22 23:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 04:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/22 10:35:52 | 000,000,829 | -H– | M] () – C:\IPH.PH
[2005/08/16 04:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2012/02/22 23:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/29 09:40:55 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/04/22 10:36:01 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 04:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/08/16 04:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 04:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 04:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/06/09 11:33:42 | 000,027,648 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\3 Months Free NetZero.exe
[2012/02/22 23:31:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/22 23:38:33 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 04:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/02/29 10:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/26 15:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/22 19:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/29 10:45:58 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/22 18:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/26 05:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/22 19:01:32 | 331,805,736 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-28 10:19:48
< End of report >
Extras:
OTL Extras logfile created on: 2/29/2012 11:00:31 AM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Russell\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.10% Memory free
3.85 Gb Paging File | 3.49 Gb Available in Paging File | 90.71% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 87.05 Gb Total Space | 69.19 Gb Free Space | 79.48% Space Free | Partition Type: NTFS
Computer Name: BASESTATION | User Name: Russell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0D251F37-10CB-46DF-BFA0-4702218DB0B6}" = ATI Catalyst Control Center
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E8C06CB3-5DB2-4689-B1DC-4A0220DEA96C}" = Consumer Complete Care Services Agreement
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/23/2012 2:18:42 AM | Computer Name = BASESTATION | Source = Microsoft Security Client | ID = 5000
Description =
Error - 2/23/2012 2:19:22 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.
Error - 2/23/2012 2:33:55 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.
Error - 2/23/2012 2:34:28 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.
Error - 2/23/2012 2:34:47 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.
Error - 2/26/2012 3:25:17 AM | Computer Name = BASESTATION | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.
Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.
[ System Events ]
Error - 2/23/2012 12:12:42 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 2/23/2012 12:12:42 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 2/23/2012 12:55:43 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 2/23/2012 12:55:43 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 2/23/2012 2:12:12 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%815 User:
BASESTATION\Russell Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0
Error - 2/23/2012 2:18:26 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
BASESTATION\Russell Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0
Error - 2/23/2012 2:54:39 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
NT AUTHORITY\SYSTEM Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0
< End of report >
My name is JonTom
- Malware Logs can sometimes take a lot of time to research and interpret.
- Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
- Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
- Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
- PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
Lets take a look at your MBR with the following scan:
- aswMBR
- Download aswMBR.exe to your desktop.
- Double click the aswMBR.exe to run it.
- When asked if you want to download Avast's virus definitions please select Yes.
- Click the "Scan" button to start scan.
[external image: Posted Image]
- On completion of the scan click save log, save it to your desktop and post in your next reply.
[external image: Posted Image]
Please post the aswMBR log in your next reply.
Can you also tell me the exact symptoms that are being dislayed by the machine.
When you connect to the net are you being redirected when you browse? <==== Important.
Please let me know
Thanks very much for helping me. I've posted my aswMBR log below.
You asked about the symptoms that are being displayed by the machine. Actually, I haven't observed any obvious symptoms after the full system restore was performed. At first I thought I had some search redirects but I think I may have just entered a web address wrong and was taken to a fake website. The only thing odd I've seen is that sometimes the icons on my desktop will flicker for no apparent reason but that may be normal.
Before the full system restore, my computer had every conceivable symptom. Among other things I had google redirects and the computer would slow to a crawl after a few minutes to the point I would have to do a hard restart.
A Spybot forum helper was trying to help get rid of all of the viruses but we hit a wall when my machine wouldn't reboot after we tried combofix. Before this happened, he did say that there was a hidden partition infection and multiple trojan viruses.
Please let me know if you need any other information. Thanks again.
—————————–
aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-01 05:44:25
—————————–
05:44:25.687 OS Version: Windows 5.1.2600 Service Pack 3
05:44:25.687 Number of processors: 2 586 0xE08
05:44:25.687 ComputerName: BASESTATION UserName: Russell
05:44:26.265 Initialize success
05:44:33.468 AVAST engine defs: 12030100
05:44:39.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
05:44:39.484 Disk 0 Vendor: TOSHIBA_MK1032GSX AS022D Size: 93958MB BusType: 3
05:44:39.515 Disk 0 MBR read successfully
05:44:39.515 Disk 0 MBR scan
05:44:39.578 Disk 0 unknown MBR code
05:44:39.578 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63
05:44:39.624 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 89141 MB offset 96390
05:44:39.656 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 182675115
05:44:39.687 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 7 MB offset 192410505
05:44:39.749 Disk 0 scanning sectors +192426554
05:44:39.874 Disk 0 scanning C:\WINDOWS\system32\drivers
05:45:14.609 Service scanning
05:45:26.999 Service MpKsl8b310159 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE66DCAC-0B02-460A-AF45-780EC2A6B328}\MpKsl8b310159.sys **LOCKED** 32
05:45:40.265 Modules scanning
05:46:01.687 Disk 0 trace - called modules:
05:46:01.718 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
05:46:01.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a6daab8]
05:46:01.734 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a745940]
05:46:02.140 AVAST engine scan C:\
08:19:35.828 Scan finished successfully
08:51:01.578 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Russell\Desktop\MBR.dat"
08:51:01.765 The log file has been saved successfully to "C:\Documents and Settings\Russell\Desktop\aswMBR.txt"
Thank you for the log.
I see that you were being assisted by ken545 (you were in very good hands).A Spybot forum helper was trying to help get rid of all of the viruses / he did say that there was a hidden partition infection and multiple trojan viruses
It is very important that we know for certain if you are being redirected or not, since this can sometimes provide important clues as to exactly what is going on.At first I thought I had some search redirects but I think I may have just entered a web address wrong and was taken to a fake website.
Please open your browser of choice and vist a trusted site to confirm if the redirects are still occurring (repeat the process with a google search) and let me know the outcome.
When you ran aswMBR, a file called MBR.dat was placed on your desktop (full path to file is C:\Documents and Settings\Russell\Desktop\MBR.dat).
Please attach the MBR.dat file and post it in your next reply.
Once attached and posted, please work your way through the steps below:
- Please open OTL
- Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.
:OTL PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) O4 - HKLM..\Run: [] File not found O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites) O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] :Commands [purity] [emptytemp] [emptyflash] [start explorer] [Reboot] - Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
- Allow the program to run unhindered.
- Your machine will re-start itself. This is normal.
- A log will be created after your machine reboots. Please post the contents of the log in your next reply.
I would also like to see a log from the following tool. If any malicious items are identified you will be given the option to cure them. At this time, please select skip rather than cure so I can review the log before we proceed.
- Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.
- TDSS Killer
- Please read carefully and follow these steps.
- Download TDSSKiller and save it to your Desktop.
- Extract its contents to your desktop.
- Open TDSSKiller.
- When the window opens, click on "Change Parameters".
- Under "Additional options", put a check mark in the box next to "Detect TDLFS File System".
- click OK and then "Start scan".
- If an infected file is detected, the default action will be Cure, please select Skip at this time.
- If a suspicious file is detected, the default action will be Skip, click on Continue.
- It may ask you to reboot the computer to complete the process. Click on Reboot Now.
- If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
- If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Please post the attached MBR.dat, the OTL log and the TDSSKiller log in your next reply along with letting me know about the redirects
I can say with 100% certainty that I'm not experiencing redirects. This was definitely a problem before my system was restored but not now.
I just tried to upload the MBR.dat file from my desktop and I received this message:
Upload failed. You are not permitted to upload this type of file
Do you know what's causing me to receive this message? I'll go ahead a start working on the other procedures and come back to the MBR.dat upload. Maybe it will work later.
Here are the OTL scan results:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\musicmatch.com\online\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
File E:\setup.exe not found.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\002854_.tmp deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 96844 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Russell
->Temp folder emptied: 104294563 bytes
->Temporary Internet Files folder emptied: 103843912 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 72175013 bytes
->Flash cache emptied: 845 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9215086 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 108793088 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 4730880 bytes
Total Files Cleaned = 385.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Russell
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.33.2 log created on 03022012_052118
Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp\TMP000000017946E0CBD1BF53BB not found!
Registry entries deleted on Reboot…
And here are the TDS Killer scan results:
05:26:41.0250 2288 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
05:26:41.0703 2288 ============================================================
05:26:41.0703 2288 Current date / time: 2012/03/02 05:26:41.0703
05:26:41.0703 2288 SystemInfo:
05:26:41.0703 2288
05:26:41.0703 2288 OS Version: 5.1.2600 ServicePack: 3.0
05:26:41.0703 2288 Product type: Workstation
05:26:41.0703 2288 ComputerName: BASESTATION
05:26:41.0703 2288 UserName: Russell
05:26:41.0703 2288 Windows directory: C:\WINDOWS
05:26:41.0703 2288 System windows directory: C:\WINDOWS
05:26:41.0703 2288 Processor architecture: Intel x86
05:26:41.0703 2288 Number of processors: 2
05:26:41.0703 2288 Page size: 0x1000
05:26:41.0703 2288 Boot type: Normal boot
05:26:41.0703 2288 ============================================================
05:26:44.0250 2288 Drive \Device\Harddisk0\DR0 - Size: 0x16F0649400 (91.76 Gb), SectorSize: 0x200, Cylinders: 0x2ECA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
05:26:44.0265 2288 \Device\Harddisk0\DR0:
05:26:44.0265 2288 MBR used
05:26:44.0265 2288 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0xAE1AF64
05:26:44.0312 2288 Initialize success
05:26:44.0312 2288 ============================================================
05:27:24.0046 1820 ============================================================
05:27:24.0046 1820 Scan started
05:27:24.0046 1820 Mode: Manual; TDLFS;
05:27:24.0046 1820 ============================================================
05:27:24.0296 1820 Abiosdsk - ok
05:27:24.0343 1820 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
05:27:24.0343 1820 abp480n5 - ok
05:27:24.0421 1820 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
05:27:24.0421 1820 ACPI - ok
05:27:24.0468 1820 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
05:27:24.0468 1820 ACPIEC - ok
05:27:24.0515 1820 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
05:27:24.0515 1820 adpu160m - ok
05:27:24.0562 1820 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
05:27:24.0562 1820 aec - ok
05:27:24.0609 1820 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
05:27:24.0640 1820 AegisP - ok
05:27:24.0703 1820 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
05:27:24.0703 1820 AFD - ok
05:27:24.0765 1820 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
05:27:24.0765 1820 agp440 - ok
05:27:24.0796 1820 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
05:27:24.0796 1820 agpCPQ - ok
05:27:24.0812 1820 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
05:27:24.0812 1820 Aha154x - ok
05:27:24.0843 1820 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
05:27:24.0843 1820 aic78u2 - ok
05:27:24.0875 1820 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
05:27:24.0875 1820 aic78xx - ok
05:27:24.0906 1820 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
05:27:24.0906 1820 AliIde - ok
05:27:24.0937 1820 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
05:27:24.0937 1820 alim1541 - ok
05:27:24.0953 1820 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
05:27:24.0953 1820 amdagp - ok
05:27:24.0968 1820 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
05:27:24.0968 1820 amsint - ok
05:27:25.0015 1820 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
05:27:25.0015 1820 APPDRV - ok
05:27:25.0046 1820 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
05:27:25.0046 1820 Arp1394 - ok
05:27:25.0093 1820 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
05:27:25.0093 1820 asc - ok
05:27:25.0140 1820 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
05:27:25.0140 1820 asc3350p - ok
05:27:25.0187 1820 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
05:27:25.0187 1820 asc3550 - ok
05:27:25.0234 1820 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
05:27:25.0234 1820 AsyncMac - ok
05:27:25.0281 1820 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
05:27:25.0281 1820 atapi - ok
05:27:25.0296 1820 Atdisk - ok
05:27:25.0390 1820 ati2mtag (bebeb471617782d138b6f92e7c3fab1c) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
05:27:25.0406 1820 ati2mtag - ok
05:27:25.0453 1820 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
05:27:25.0453 1820 Atmarpc - ok
05:27:25.0484 1820 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
05:27:25.0484 1820 audstub - ok
05:27:25.0515 1820 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
05:27:25.0515 1820 bcm4sbxp - ok
05:27:25.0531 1820 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
05:27:25.0531 1820 Beep - ok
05:27:25.0562 1820 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
05:27:25.0562 1820 cbidf - ok
05:27:25.0578 1820 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
05:27:25.0578 1820 cbidf2k - ok
05:27:25.0593 1820 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
05:27:25.0593 1820 cd20xrnt - ok
05:27:25.0609 1820 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
05:27:25.0609 1820 Cdaudio - ok
05:27:25.0625 1820 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
05:27:25.0625 1820 Cdfs - ok
05:27:25.0656 1820 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
05:27:25.0656 1820 Cdrom - ok
05:27:25.0671 1820 Changer - ok
05:27:25.0703 1820 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
05:27:25.0703 1820 CmBatt - ok
05:27:25.0734 1820 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
05:27:25.0734 1820 CmdIde - ok
05:27:25.0750 1820 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
05:27:25.0750 1820 Compbatt - ok
05:27:25.0796 1820 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
05:27:25.0796 1820 Cpqarray - ok
05:27:25.0859 1820 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
05:27:25.0859 1820 dac2w2k - ok
05:27:25.0875 1820 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
05:27:25.0875 1820 dac960nt - ok
05:27:25.0890 1820 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
05:27:25.0890 1820 Disk - ok
05:27:25.0968 1820 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
05:27:25.0984 1820 dmboot - ok
05:27:26.0109 1820 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
05:27:26.0109 1820 dmio - ok
05:27:26.0140 1820 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
05:27:26.0140 1820 dmload - ok
05:27:26.0171 1820 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
05:27:26.0171 1820 DMusic - ok
05:27:26.0234 1820 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
05:27:26.0234 1820 dpti2o - ok
05:27:26.0281 1820 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
05:27:26.0281 1820 drmkaud - ok
05:27:26.0312 1820 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
05:27:26.0343 1820 drvmcdb - ok
05:27:26.0359 1820 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
05:27:26.0953 1820 drvnddm - ok
05:27:27.0093 1820 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
05:27:27.0093 1820 E100B - ok
05:27:27.0156 1820 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
05:27:27.0156 1820 Fastfat - ok
05:27:27.0171 1820 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
05:27:27.0171 1820 Fdc - ok
05:27:27.0203 1820 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
05:27:27.0203 1820 Fips - ok
05:27:27.0234 1820 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
05:27:27.0234 1820 Flpydisk - ok
05:27:27.0281 1820 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
05:27:27.0281 1820 FltMgr - ok
05:27:27.0328 1820 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
05:27:27.0328 1820 Fs_Rec - ok
05:27:27.0343 1820 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
05:27:27.0343 1820 Ftdisk - ok
05:27:27.0406 1820 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
05:27:27.0406 1820 Gpc - ok
05:27:27.0421 1820 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
05:27:27.0421 1820 HDAudBus - ok
05:27:27.0453 1820 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
05:27:27.0453 1820 HidUsb - ok
05:27:27.0468 1820 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
05:27:27.0468 1820 hpn - ok
05:27:27.0531 1820 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
05:27:27.0531 1820 HSFHWAZL - ok
05:27:27.0593 1820 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
05:27:27.0625 1820 HSF_DPV - ok
05:27:27.0687 1820 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
05:27:27.0687 1820 HTTP - ok
05:27:27.0718 1820 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
05:27:27.0718 1820 i2omgmt - ok
05:27:27.0734 1820 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
05:27:27.0734 1820 i2omp - ok
05:27:27.0765 1820 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
05:27:27.0765 1820 i8042prt - ok
05:27:27.0843 1820 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
05:27:27.0843 1820 Imapi - ok
05:27:27.0890 1820 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
05:27:27.0890 1820 ini910u - ok
05:27:27.0937 1820 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
05:27:27.0937 1820 IntelIde - ok
05:27:27.0953 1820 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
05:27:27.0968 1820 intelppm - ok
05:27:27.0984 1820 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
05:27:27.0984 1820 Ip6Fw - ok
05:27:28.0015 1820 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
05:27:28.0015 1820 IpFilterDriver - ok
05:27:28.0046 1820 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
05:27:28.0046 1820 IpInIp - ok
05:27:28.0109 1820 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
05:27:28.0109 1820 IpNat - ok
05:27:28.0156 1820 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
05:27:28.0156 1820 IPSec - ok
05:27:28.0187 1820 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
05:27:28.0187 1820 IRENUM - ok
05:27:28.0218 1820 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
05:27:28.0218 1820 isapnp - ok
05:27:28.0234 1820 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
05:27:28.0250 1820 Kbdclass - ok
05:27:28.0281 1820 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
05:27:28.0281 1820 kmixer - ok
05:27:28.0312 1820 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
05:27:28.0312 1820 KSecDD - ok
05:27:28.0328 1820 lbrtfdc - ok
05:27:28.0406 1820 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
05:27:28.0406 1820 mdmxsdk - ok
05:27:28.0437 1820 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
05:27:28.0437 1820 MHNDRV - ok
05:27:28.0453 1820 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
05:27:28.0453 1820 mnmdd - ok
05:27:28.0484 1820 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
05:27:28.0484 1820 Modem - ok
05:27:28.0500 1820 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
05:27:28.0500 1820 Mouclass - ok
05:27:28.0531 1820 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
05:27:28.0546 1820 mouhid - ok
05:27:28.0562 1820 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
05:27:28.0562 1820 MountMgr - ok
05:27:28.0625 1820 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
05:27:28.0625 1820 MpFilter - ok
05:27:28.0718 1820 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
05:27:28.0718 1820 mraid35x - ok
05:27:28.0734 1820 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
05:27:28.0734 1820 MRxDAV - ok
05:27:28.0796 1820 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
05:27:28.0812 1820 MRxSmb - ok
05:27:28.0828 1820 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
05:27:28.0828 1820 Msfs - ok
05:27:28.0859 1820 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
05:27:28.0859 1820 MSKSSRV - ok
05:27:28.0875 1820 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
05:27:28.0875 1820 MSPCLOCK - ok
05:27:28.0906 1820 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
05:27:28.0906 1820 MSPQM - ok
05:27:28.0937 1820 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
05:27:28.0953 1820 mssmbios - ok
05:27:29.0000 1820 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
05:27:29.0000 1820 Mup - ok
05:27:29.0062 1820 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
05:27:29.0062 1820 NDIS - ok
05:27:29.0109 1820 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
05:27:29.0109 1820 NdisTapi - ok
05:27:29.0125 1820 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
05:27:29.0125 1820 Ndisuio - ok
05:27:29.0140 1820 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
05:27:29.0140 1820 NdisWan - ok
05:27:29.0171 1820 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
05:27:29.0171 1820 NDProxy - ok
05:27:29.0187 1820 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
05:27:29.0187 1820 NetBIOS - ok
05:27:29.0234 1820 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
05:27:29.0234 1820 NetBT - ok
05:27:29.0265 1820 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
05:27:29.0265 1820 NIC1394 - ok
05:27:29.0296 1820 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
05:27:29.0296 1820 Npfs - ok
05:27:29.0343 1820 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
05:27:29.0359 1820 Ntfs - ok
05:27:29.0390 1820 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
05:27:29.0390 1820 Null - ok
05:27:29.0484 1820 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
05:27:29.0531 1820 nv - ok
05:27:29.0609 1820 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
05:27:29.0625 1820 NwlnkFlt - ok
05:27:29.0625 1820 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
05:27:29.0640 1820 NwlnkFwd - ok
05:27:29.0640 1820 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
05:27:29.0656 1820 ohci1394 - ok
05:27:29.0671 1820 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
05:27:29.0718 1820 omci - ok
05:27:29.0781 1820 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
05:27:29.0781 1820 Parport - ok
05:27:29.0812 1820 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
05:27:29.0812 1820 PartMgr - ok
05:27:29.0843 1820 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
05:27:29.0843 1820 ParVdm - ok
05:27:29.0890 1820 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
05:27:29.0890 1820 PCI - ok
05:27:29.0906 1820 PCIDump - ok
05:27:29.0921 1820 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
05:27:29.0921 1820 PCIIde - ok
05:27:29.0968 1820 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
05:27:29.0968 1820 Pcmcia - ok
05:27:29.0984 1820 PDCOMP - ok
05:27:30.0000 1820 PDFRAME - ok
05:27:30.0015 1820 PDRELI - ok
05:27:30.0031 1820 PDRFRAME - ok
05:27:30.0062 1820 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
05:27:30.0062 1820 perc2 - ok
05:27:30.0078 1820 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
05:27:30.0078 1820 perc2hib - ok
05:27:30.0140 1820 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
05:27:30.0140 1820 PptpMiniport - ok
05:27:30.0156 1820 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
05:27:30.0156 1820 PSched - ok
05:27:30.0171 1820 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
05:27:30.0171 1820 Ptilink - ok
05:27:30.0203 1820 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
05:27:30.0203 1820 PxHelp20 - ok
05:27:30.0234 1820 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
05:27:30.0234 1820 ql1080 - ok
05:27:30.0250 1820 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
05:27:30.0250 1820 Ql10wnt - ok
05:27:30.0281 1820 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
05:27:30.0281 1820 ql12160 - ok
05:27:30.0296 1820 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
05:27:30.0296 1820 ql1240 - ok
05:27:30.0312 1820 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
05:27:30.0312 1820 ql1280 - ok
05:27:30.0343 1820 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
05:27:30.0343 1820 RasAcd - ok
05:27:30.0375 1820 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
05:27:30.0390 1820 Rasl2tp - ok
05:27:30.0406 1820 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
05:27:30.0406 1820 RasPppoe - ok
05:27:30.0421 1820 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
05:27:30.0421 1820 Raspti - ok
05:27:30.0437 1820 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
05:27:30.0453 1820 Rdbss - ok
05:27:30.0468 1820 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
05:27:30.0468 1820 RDPCDD - ok
05:27:30.0500 1820 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
05:27:30.0500 1820 rdpdr - ok
05:27:30.0562 1820 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
05:27:30.0562 1820 RDPWD - ok
05:27:30.0656 1820 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
05:27:30.0656 1820 redbook - ok
05:27:30.0687 1820 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
05:27:30.0687 1820 rimmptsk - ok
05:27:30.0687 1820 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
05:27:30.0703 1820 rimsptsk - ok
05:27:30.0718 1820 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
05:27:30.0718 1820 rismxdp - ok
05:27:30.0781 1820 s24trans (2e4e912ce95f5ef4d4a5079f6ce367fc) C:\WINDOWS\system32\DRIVERS\s24trans.sys
05:27:30.0796 1820 s24trans - ok
05:27:30.0843 1820 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
05:27:30.0859 1820 sdbus - ok
05:27:30.0890 1820 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
05:27:30.0890 1820 Secdrv - ok
05:27:30.0906 1820 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
05:27:30.0906 1820 serenum - ok
05:27:30.0937 1820 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
05:27:30.0937 1820 Serial - ok
05:27:30.0968 1820 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
05:27:30.0968 1820 Sfloppy - ok
05:27:30.0984 1820 Simbad - ok
05:27:31.0015 1820 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
05:27:31.0015 1820 sisagp - ok
05:27:31.0062 1820 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
05:27:31.0062 1820 Sparrow - ok
05:27:31.0093 1820 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
05:27:31.0093 1820 splitter - ok
05:27:31.0109 1820 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
05:27:31.0125 1820 sr - ok
05:27:31.0187 1820 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
05:27:31.0187 1820 Srv - ok
05:27:31.0218 1820 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
05:27:31.0234 1820 sscdbhk5 - ok
05:27:31.0250 1820 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
05:27:31.0281 1820 ssrtln - ok
05:27:31.0359 1820 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys
05:27:31.0375 1820 STHDA - ok
05:27:31.0421 1820 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
05:27:31.0421 1820 swenum - ok
05:27:31.0453 1820 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
05:27:31.0453 1820 swmidi - ok
05:27:31.0546 1820 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
05:27:31.0546 1820 symc810 - ok
05:27:31.0562 1820 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
05:27:31.0562 1820 symc8xx - ok
05:27:31.0578 1820 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
05:27:31.0578 1820 sym_hi - ok
05:27:31.0593 1820 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
05:27:31.0593 1820 sym_u3 - ok
05:27:31.0640 1820 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys
05:27:31.0656 1820 SynTP - ok
05:27:31.0687 1820 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
05:27:31.0687 1820 sysaudio - ok
05:27:31.0750 1820 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
05:27:31.0750 1820 Tcpip - ok
05:27:31.0781 1820 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
05:27:31.0781 1820 TDPIPE - ok
05:27:31.0796 1820 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
05:27:31.0796 1820 TDTCP - ok
05:27:31.0812 1820 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
05:27:31.0812 1820 TermDD - ok
05:27:31.0843 1820 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
05:27:31.0859 1820 tfsnboio - ok
05:27:31.0875 1820 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
05:27:31.0906 1820 tfsncofs - ok
05:27:31.0906 1820 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
05:27:31.0921 1820 tfsndrct - ok
05:27:31.0937 1820 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
05:27:31.0953 1820 tfsndres - ok
05:27:31.0968 1820 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
05:27:32.0015 1820 tfsnifs - ok
05:27:32.0031 1820 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
05:27:32.0046 1820 tfsnopio - ok
05:27:32.0062 1820 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
05:27:32.0078 1820 tfsnpool - ok
05:27:32.0093 1820 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
05:27:32.0140 1820 tfsnudf - ok
05:27:32.0156 1820 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
05:27:32.0203 1820 tfsnudfa - ok
05:27:32.0250 1820 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
05:27:32.0250 1820 TosIde - ok
05:27:32.0296 1820 Tosrfbd (37a7d0d105110aafac6e982a2c49b8b6) C:\WINDOWS\system32\Drivers\tosrfbd.sys
05:27:32.0328 1820 Tosrfbd - ok
05:27:32.0375 1820 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\drivers\Tosrfcom.sys
05:27:32.0437 1820 Tosrfcom - ok
05:27:32.0453 1820 Tosrfhid (f4e4795528d17ff8d1d6d98ebbb92655) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
05:27:32.0500 1820 Tosrfhid - ok
05:27:32.0515 1820 Tosrfusb (1d19323d5bc7309d9df65dad5635005c) C:\WINDOWS\system32\Drivers\tosrfusb.sys
05:27:32.0546 1820 Tosrfusb - ok
05:27:32.0578 1820 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
05:27:32.0578 1820 Udfs - ok
05:27:32.0625 1820 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
05:27:32.0625 1820 ultra - ok
05:27:32.0671 1820 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
05:27:32.0671 1820 Update - ok
05:27:32.0765 1820 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
05:27:32.0765 1820 usbccgp - ok
05:27:32.0781 1820 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
05:27:32.0796 1820 usbehci - ok
05:27:32.0812 1820 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
05:27:32.0812 1820 usbhub - ok
05:27:32.0875 1820 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
05:27:32.0875 1820 usbuhci - ok
05:27:32.0890 1820 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
05:27:32.0890 1820 VgaSave - ok
05:27:32.0921 1820 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
05:27:32.0937 1820 viaagp - ok
05:27:32.0953 1820 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
05:27:32.0953 1820 ViaIde - ok
05:27:32.0984 1820 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
05:27:32.0984 1820 VolSnap - ok
05:27:33.0078 1820 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
05:27:33.0109 1820 w39n51 - ok
05:27:33.0140 1820 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
05:27:33.0140 1820 Wanarp - ok
05:27:33.0156 1820 wanatw - ok
05:27:33.0171 1820 WDICA - ok
05:27:33.0187 1820 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
05:27:33.0187 1820 wdmaud - ok
05:27:33.0265 1820 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
05:27:33.0281 1820 winachsf - ok
05:27:33.0328 1820 MBR (0x1B8) (2ba3e330828ad649a40ef55575d98871) \Device\Harddisk0\DR0
05:27:33.0359 1820 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
05:27:33.0359 1820 \Device\Harddisk0\DR0 - detected TDSS File System (1)
05:27:33.0406 1820 Boot (0x1200) (64e75b0b5a6b9362f974df70553b240c) \Device\Harddisk0\DR0\Partition0
05:27:33.0406 1820 \Device\Harddisk0\DR0\Partition0 - ok
05:27:33.0406 1820 ============================================================
05:27:33.0406 1820 Scan finished
05:27:33.0406 1820 ============================================================
05:27:33.0421 3244 Detected object count: 1
05:27:33.0421 3244 Actual detected object count: 1
05:28:07.0656 3244 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
05:28:07.0656 3244 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Thank you for the logs and information about the redirects
Lets see if we can get the file attached before we continue.
Please Right click on the file (MBR.dat) and select Send to > Compressed (zipped folder). The file will be placed in a zipped folder on your desktop. See if you can attach the zipped folder in your next reply
Good job getting that file attached
Lets proceed as follows:
Run TDSSKiller again as you did before, but this time, when the following is identified in the scan
Please select delete.05:27:33.0359 1820 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
05:27:33.0359 1820 \Device\Harddisk0\DR0 - detected TDSS File System (1)
Once the scan has completed please post the log in your next reply.
Thank you for the log.
Thats goodIt seems like it doesn't see the threat anymore
It may be that it is being detected from TDSSKiller quarantine. Did MSE tell you exactly where the threat was located?However, I'm seeing that Microsoft Security Essentials is still warning me about Trojan:Dos/Alureon.E., boot:\\PHYSICALDRIVE0\Partition 3 (Type 17).
Please post a new aswMBR scan log in your next reply
According to the latest TDSSKiller log the partition has been removed….which is what I guess TDSSKkiller tried to do
Please run TDSSKiller again exactly as you did in post number 6 (making sure that Detect TDLFS File System is selected) and post the log in your next reply.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI