This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus still present after full system restore (Trojan:Dos/Alureon.E) [

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Everyone, Long story short…I was directed here by helpers from the Windows area of this forum. I had been experiencing a blue screen of death that occurred during a previous virus removal attempt at the Spybot forums. (My Spybot helper then suggested that I come here to the Windows forum for help.) The Windows helpers here helped me restore my Dell laptop using the CTRL + F11 which allowed me to at least get back on track. (http://forums.whatthetech.com/index.php?showtopic=122379) Everything seemed to be back to normal but Microsoft Security Essentials found a virus during its first scan: Trojan:DOS/Alureon.E boot:\\PHYSICALDRIVE0\Partition3 (Type 17) The Windows helpers told me this rootkit wouldn't have been removed by the system restore because it infects the Master Boot Record. I would be extremely appreciative is someone here could help me get rid of this nasty virus. I understand that it could be difficult to remove so I'll be patient during the process. Thanks very much for your help! :thumbup:
Almost forgot…Here are my OTL and Extras from the OTL scan:

OTL logfile created on: 2/29/2012 11:00:31 AM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Russell\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.10% Memory free
3.85 Gb Paging File | 3.49 Gb Available in Paging File | 90.71% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 87.05 Gb Total Space | 69.19 Gb Free Space | 79.48% Space Free | Partition Type: NTFS

Computer Name: BASESTATION | User Name: Russell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Russell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
PRC - C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Modules (No Company Name) ==========

MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_c3f6dbb1\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_273780c2\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4314e828\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_41d007e8\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_43a77e74\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
MOD - C:\WINDOWS\system32\TosBtHcrpAPI.dll ()
MOD - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (Bluetooth Hid Switch Service) – C:\Program Files\BlueTooth\HidSwitchService\HidSw.exe (Cambridge Silicon Radio)


========== Driver Services (SafeList) ==========

DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/?fr=yfp-t-403"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/23 01:22:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/02/23 01:23:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Extensions
[2012/02/26 15:58:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\5nb0ik0f.default\extensions
[2012/02/23 01:41:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/23 01:41:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/02/23 01:41:28 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/16 09:40:42 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/16 05:42:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/16 05:42:53 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/10 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DellHelp] C:\Dell\DellHelp\DellHelp.exe (Dell Inc)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [ShowLOMControl] Reg Error: Invalid data type. File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1329975759726 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1329978404062 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BFFF9B8-868B-4C05-9A5A-613F6B79DD18}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/29 10:47:17 | 000,607,260 | —- | C] (Swearware) – C:\Documents and Settings\Russell\Desktop\dds.scr
[2012/02/29 10:46:53 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/29 10:45:54 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/29 04:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/02/28 05:09:08 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Videos
[2012/02/27 04:07:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2012/02/27 04:07:17 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2012/02/27 04:07:04 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2012/02/27 04:06:36 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2012/02/27 04:06:36 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2012/02/27 04:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2012/02/27 04:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2012/02/27 04:06:35 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2012/02/27 04:06:35 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2012/02/27 04:06:34 | 000,000,000 | —D | C] – C:\59e129738cb8df114e94
[2012/02/26 15:30:41 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IECompatCache
[2012/02/26 15:29:09 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\PrivacIE
[2012/02/26 15:22:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/02/26 15:10:51 | 016,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 05:55:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2012/02/26 05:54:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Google
[2012/02/26 05:54:36 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/02/26 05:52:02 | 014,886,760 | —- | C] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/26 00:56:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\AdobeUM
[2012/02/26 00:56:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Adobe
[2012/02/26 00:56:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\My eBooks
[2012/02/26 00:55:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/02/25 23:32:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel Photo Album
[2012/02/25 23:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Corel Photo Album
[2012/02/25 21:59:03 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2012/02/25 21:59:02 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/02/25 21:52:18 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IETldCache
[2012/02/23 16:23:38 | 004,448,256 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/02/23 03:32:16 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2012/02/23 03:32:02 | 011,082,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2012/02/23 03:32:02 | 002,000,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2012/02/23 03:32:02 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/02/23 03:32:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/02/23 03:32:01 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/02/23 03:31:47 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/02/23 03:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Macromedia
[2012/02/23 03:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Adobe
[2012/02/23 03:13:30 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 03:11:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\Downloads
[2012/02/23 03:03:12 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2012/02/23 02:10:03 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2012/02/23 02:08:19 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2012/02/23 02:08:19 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2012/02/23 02:07:38 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2012/02/23 02:07:24 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2012/02/23 02:05:55 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2012/02/23 02:05:18 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2012/02/23 02:05:18 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2012/02/23 02:04:03 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2012/02/23 01:58:54 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2012/02/23 01:58:43 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012/02/23 01:58:04 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2012/02/23 01:57:58 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2012/02/23 01:57:58 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2012/02/23 01:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2012/02/23 01:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2012/02/23 01:57:57 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2012/02/23 01:57:56 | 001,025,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browseui.dll
[2012/02/23 01:57:33 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2012/02/23 01:55:15 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2012/02/23 01:53:40 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2012/02/23 01:53:30 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2012/02/23 01:51:46 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012/02/23 01:47:48 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2012/02/23 01:47:23 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2012/02/23 01:46:48 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012/02/23 01:46:43 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2012/02/23 01:42:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2012/02/23 01:42:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/02/23 01:41:41 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 01:41:41 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 01:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 01:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 01:41:41 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 01:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Mozilla
[2012/02/23 01:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Mozilla
[2012/02/23 01:22:32 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/02/23 00:56:53 | 000,237,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/02/23 00:49:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/02/23 00:46:04 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oakley.dll
[2012/02/23 00:46:03 | 001,212,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2012/02/23 00:46:03 | 000,916,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2012/02/23 00:46:02 | 001,510,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shdocvw.dll
[2012/02/23 00:46:01 | 005,979,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2012/02/23 00:45:28 | 000,343,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspaint.exe
[2012/02/23 00:44:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2012/02/23 00:44:45 | 002,334,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMVCore.dll
[2012/02/23 00:43:10 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/02/23 00:43:10 | 000,021,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/02/23 00:43:09 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/02/23 00:43:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2012/02/23 00:35:56 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russell\UserData
[2012/02/22 23:38:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2012/02/22 23:37:51 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012/02/22 23:31:12 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2012/02/22 23:31:11 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2012/02/22 23:31:11 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2012/02/22 23:31:03 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2012/02/22 23:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2012/02/22 23:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2012/02/22 23:31:01 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2012/02/22 23:31:01 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2012/02/22 23:31:01 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2012/02/22 23:31:01 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2012/02/22 23:31:01 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2012/02/22 23:31:01 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2012/02/22 23:31:01 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2012/02/22 23:31:00 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2012/02/22 23:31:00 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2012/02/22 23:31:00 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2012/02/22 23:31:00 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2012/02/22 23:31:00 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2012/02/22 23:31:00 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2012/02/22 23:31:00 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2012/02/22 23:31:00 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2012/02/22 23:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2012/02/22 23:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2012/02/22 23:31:00 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2012/02/22 23:30:59 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2012/02/22 23:30:58 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2012/02/22 23:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2012/02/22 23:30:57 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2012/02/22 23:30:57 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2012/02/22 23:30:57 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2012/02/22 23:30:57 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2012/02/22 23:30:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2012/02/22 23:30:57 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2012/02/22 23:30:57 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2012/02/22 23:30:57 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2012/02/22 23:30:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2012/02/22 23:30:57 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2012/02/22 23:30:56 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2012/02/22 23:30:56 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2012/02/22 23:30:56 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2012/02/22 23:30:56 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2012/02/22 23:30:56 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2012/02/22 23:30:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2012/02/22 23:30:56 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2012/02/22 23:30:56 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2012/02/22 23:30:56 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2012/02/22 23:30:56 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2012/02/22 23:30:56 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2012/02/22 23:30:55 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2012/02/22 23:30:55 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2012/02/22 23:30:55 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2012/02/22 23:30:55 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2012/02/22 23:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2012/02/22 23:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2012/02/22 23:30:53 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2012/02/22 23:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2012/02/22 23:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-us
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2012/02/22 23:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2012/02/22 23:28:50 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2012/02/22 23:26:27 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2012/02/22 23:26:27 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2012/02/22 23:26:27 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2012/02/22 23:26:27 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2012/02/22 23:26:27 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2012/02/22 23:26:27 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2012/02/22 23:26:27 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2012/02/22 23:26:27 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2012/02/22 23:26:27 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2012/02/22 23:26:27 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2012/02/22 23:26:27 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2012/02/22 23:26:27 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2012/02/22 23:26:27 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2012/02/22 23:26:27 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2012/02/22 23:26:27 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2012/02/22 23:26:27 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2012/02/22 23:26:27 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2012/02/22 23:26:27 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2012/02/22 23:26:27 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2012/02/22 23:26:27 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2012/02/22 23:26:27 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2012/02/22 23:26:27 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2012/02/22 23:26:26 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2012/02/22 23:26:26 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2012/02/22 23:26:26 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2012/02/22 23:26:26 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2012/02/22 23:26:26 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2012/02/22 23:26:26 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2012/02/22 23:26:26 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2012/02/22 23:26:26 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2012/02/22 23:26:26 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2012/02/22 23:26:26 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2012/02/22 23:26:26 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2012/02/22 23:26:26 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2012/02/22 23:26:26 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2012/02/22 23:26:26 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2012/02/22 23:26:25 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2012/02/22 23:26:25 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2012/02/22 23:26:25 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2012/02/22 23:26:25 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2012/02/22 23:26:25 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2012/02/22 23:26:25 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2012/02/22 23:26:24 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2012/02/22 23:26:24 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2012/02/22 23:26:24 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2012/02/22 23:26:24 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2012/02/22 23:26:24 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2012/02/22 23:26:24 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2012/02/22 23:26:24 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2012/02/22 23:26:24 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2012/02/22 23:26:24 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2012/02/22 23:26:24 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2012/02/22 23:26:24 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2012/02/22 23:26:23 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2012/02/22 23:26:23 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2012/02/22 23:26:23 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2012/02/22 23:26:23 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2012/02/22 23:25:28 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/02/22 23:22:05 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2012/02/22 23:17:48 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/22 23:17:37 | 331,805,736 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe
[2012/02/22 23:08:08 | 000,000,000 | RH-D | C] – C:\MSOCache
[2012/02/19 23:45:21 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2012/02/19 21:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\McAfee.com Personal Firewall
[2012/02/19 21:03:15 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russell\Application Data\Microsoft
[2012/02/19 21:03:15 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Application Data
[2012/02/19 21:03:15 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Favorites
[2012/02/19 21:03:15 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\Cookies
[2012/02/19 21:03:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Local Settings
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Wildtangent
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Sun
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Musicmatch
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Microsoft
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Intel
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Identities
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Gtek
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\BVRP Software
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ATI
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\ATI
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ApplicationHistory
[2012/02/19 21:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2012/02/19 21:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\SendTo
[2012/02/19 21:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Recent
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Startup
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Pictures
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Music
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents
[2012/02/19 21:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Accessories
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Templates
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\PrintHood
[2012/02/19 21:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\NetHood
[2012/02/19 21:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell Accessories
[2012/02/19 21:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/29 10:47:21 | 000,607,260 | —- | M] (Swearware) – C:\Documents and Settings\Russell\Desktop\dds.scr
[2012/02/29 10:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/29 10:45:58 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/29 09:46:10 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/29 09:40:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/29 09:40:56 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/02/29 03:27:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/28 05:16:22 | 000,443,034 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/28 05:16:22 | 000,072,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/28 05:09:03 | 000,000,804 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/02/28 05:09:03 | 000,000,786 | —- | M] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/02/27 04:21:14 | 000,135,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/27 03:49:12 | 000,102,176 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 03:47:43 | 000,039,426 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 16:49:58 | 000,068,829 | —- | M] () – C:\Documents and Settings\Russell\Desktop\15162_x800.jpg
[2012/02/26 15:46:05 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/02/26 15:28:09 | 000,000,815 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/26 15:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 05:57:49 | 000,003,766 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/26 05:57:48 | 000,000,088 | RHS- | M] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/26 05:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/26 02:06:56 | 000,033,388 | —- | M] () – C:\Documents and Settings\Russell\Desktop\BlueT10_02.jpg
[2012/02/26 01:55:42 | 000,031,125 | —- | M] () – C:\Documents and Settings\Russell\Desktop\A4.jpg
[2012/02/26 01:55:31 | 000,025,906 | —- | M] () – C:\Documents and Settings\Russell\Desktop\A1.jpg
[2012/02/25 23:36:03 | 000,030,307 | —- | M] () – C:\Documents and Settings\Russell\Desktop\453718271_o.jpg
[2012/02/25 23:31:37 | 000,209,908 | —- | M] () – C:\Documents and Settings\Russell\Desktop\amber_lights.jpg
[2012/02/23 16:23:38 | 004,448,256 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/02/23 03:13:30 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 01:41:26 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 01:41:26 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 01:41:26 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 01:41:25 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 01:41:25 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 01:22:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 00:50:50 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/02/22 23:39:31 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/02/22 23:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/22 23:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/02/22 19:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/22 19:01:32 | 331,805,736 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe
[2012/02/22 18:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 21:20:37 | 000,031,648 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2012/02/19 21:11:34 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2012/02/19 21:03:37 | 000,000,130 | —- | M] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 21:03:22 | 000,001,478 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 21:03:00 | 000,000,448 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012/02/19 21:02:55 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2012/02/19 20:54:36 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/28 05:09:03 | 000,000,804 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/02/27 03:49:12 | 000,102,176 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 03:47:43 | 000,039,426 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 16:49:58 | 000,068,829 | —- | C] () – C:\Documents and Settings\Russell\Desktop\15162_x800.jpg
[2012/02/26 02:06:56 | 000,033,388 | —- | C] () – C:\Documents and Settings\Russell\Desktop\BlueT10_02.jpg
[2012/02/26 01:55:42 | 000,031,125 | —- | C] () – C:\Documents and Settings\Russell\Desktop\A4.jpg
[2012/02/26 01:55:31 | 000,025,906 | —- | C] () – C:\Documents and Settings\Russell\Desktop\A1.jpg
[2012/02/25 23:36:03 | 000,030,307 | —- | C] () – C:\Documents and Settings\Russell\Desktop\453718271_o.jpg
[2012/02/25 23:31:48 | 000,003,766 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/25 23:31:48 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/25 23:31:36 | 000,209,908 | —- | C] () – C:\Documents and Settings\Russell\Desktop\amber_lights.jpg
[2012/02/23 01:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/23 01:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/23 01:22:39 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 00:55:35 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/23 00:50:50 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2012/02/23 00:50:24 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/23 00:45:58 | 001,292,288 | —- | C] () – C:\WINDOWS\System32\dllcache\quartz.dll
[2012/02/22 23:26:26 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012/02/22 23:26:26 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2012/02/22 23:26:25 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2012/02/22 23:25:14 | 000,004,128 | —- | C] () – C:\INFCACHE.1
[2012/02/22 23:17:58 | 001,359,824 | —- | C] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 21:11:34 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/02/19 21:03:23 | 000,000,786 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/02/19 21:03:16 | 000,002,007 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2012/02/19 21:03:16 | 000,001,824 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk
[2012/02/19 21:03:16 | 000,001,769 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk
[2012/02/19 21:03:16 | 000,001,478 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 21:03:16 | 000,001,298 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Media Center.lnk
[2012/02/19 21:03:16 | 000,000,815 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/19 21:03:16 | 000,000,742 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2012/02/19 21:03:16 | 000,000,130 | —- | C] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 21:03:16 | 000,000,079 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/02/19 21:03:15 | 000,001,503 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Remote Assistance.lnk
[2012/02/19 21:03:15 | 000,000,803 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Internet Explorer.lnk
[2012/02/19 21:03:15 | 000,000,792 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Windows Media Player.lnk
[2012/02/19 21:03:15 | 000,000,738 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Outlook Express.lnk
[2012/02/19 20:54:36 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD

========== LOP Check ==========

[2006/04/22 10:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/02/29 09:46:10 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/08/16 04:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/02/19 21:02:55 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/08/16 04:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/22 10:05:26 | 000,006,905 | RH– | M] () – C:\dell.sdr
[2012/02/29 09:40:56 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/02/22 23:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 04:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/22 10:35:52 | 000,000,829 | -H– | M] () – C:\IPH.PH
[2005/08/16 04:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2012/02/22 23:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/29 09:40:55 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/04/22 10:36:01 | 000,000,071 | —- | M] () – C:\SystemInfo.ini

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 04:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 04:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 04:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 04:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/06/09 11:33:42 | 000,027,648 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\3 Months Free NetZero.exe
[2012/02/22 23:31:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/22 23:38:33 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 04:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/02/29 10:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/26 15:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/22 19:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/29 10:45:58 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/22 18:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/26 05:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/22 19:01:32 | 331,805,736 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-28 10:19:48

< End of report >


Extras:

OTL Extras logfile created on: 2/29/2012 11:00:31 AM - Run 1
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Russell\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 74.10% Memory free
3.85 Gb Paging File | 3.49 Gb Available in Paging File | 90.71% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 87.05 Gb Total Space | 69.19 Gb Free Space | 79.48% Space Free | Partition Type: NTFS

Computer Name: BASESTATION | User Name: Russell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0D251F37-10CB-46DF-BFA0-4702218DB0B6}" = ATI Catalyst Control Center
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{1F528948-0E80-4C96-B455-DE4167CB1DF7}" = Internal Network Card Power Management
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E8C06CB3-5DB2-4689-B1DC-4A0220DEA96C}" = Consumer Complete Care Services Agreement
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/23/2012 2:18:42 AM | Computer Name = BASESTATION | Source = Microsoft Security Client | ID = 5000
Description =

Error - 2/23/2012 2:19:22 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.

Error - 2/23/2012 2:33:55 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.

Error - 2/23/2012 2:34:28 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.

Error - 2/23/2012 2:34:47 AM | Computer Name = BASESTATION | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5626, fault address 0x000721e2.

Error - 2/26/2012 3:25:17 AM | Computer Name = BASESTATION | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 2/26/2012 4:16:05 PM | Computer Name = BASESTATION | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 2/23/2012 12:12:42 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/23/2012 12:12:42 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 2/23/2012 12:55:43 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 2/23/2012 12:55:43 AM | Computer Name = BASESTATION | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 2/23/2012 2:12:12 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952

Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%815 User:
BASESTATION\Russell Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0

Error - 2/23/2012 2:18:26 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952

Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
BASESTATION\Russell Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0

Error - 2/23/2012 2:54:39 AM | Computer Name = BASESTATION | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=370…atid=2147650952

Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition3
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
NT AUTHORITY\SYSTEM Process Name: Unknown Action: %%808 Action Status: To finish
removing malware and other potentially unwanted software, restart the computer.
To see how to finish removing malware and other potentially unwanted software, see
the support article on the Microsoft Security website. Error Code: 0x800704ec Error
description: Windows cannot open this program because it has been prevented by
a software restriction policy. For more information, open Event Viewer or contact
your system administrator. Signature Version: AV: 1.121.227.0, AS: 1.121.227.0,
NIS: 0.0.0.0 Engine Version: AM: 1.1.8101.0, NIS: 0.0.0.0


< End of report >
Hello JoshProto22 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

Lets take a look at your MBR with the following scan:

  • aswMBR


  • Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the "Scan" button to start scan.

[external image: Posted Image]

  • On completion of the scan click save log, save it to your desktop and post in your next reply.

[external image: Posted Image]

Please post the aswMBR log in your next reply.
Hello JoshProto22

Can you also tell me the exact symptoms that are being dislayed by the machine.

When you connect to the net are you being redirected when you browse? <==== Important.

Please let me know :)
Hi,

Thanks very much for helping me. I've posted my aswMBR log below.

You asked about the symptoms that are being displayed by the machine. Actually, I haven't observed any obvious symptoms after the full system restore was performed. At first I thought I had some search redirects but I think I may have just entered a web address wrong and was taken to a fake website. The only thing odd I've seen is that sometimes the icons on my desktop will flicker for no apparent reason but that may be normal.

Before the full system restore, my computer had every conceivable symptom. Among other things I had google redirects and the computer would slow to a crawl after a few minutes to the point I would have to do a hard restart.

A Spybot forum helper was trying to help get rid of all of the viruses but we hit a wall when my machine wouldn't reboot after we tried combofix. Before this happened, he did say that there was a hidden partition infection and multiple trojan viruses.

Please let me know if you need any other information. Thanks again.

—————————–


aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-01 05:44:25
—————————–
05:44:25.687 OS Version: Windows 5.1.2600 Service Pack 3
05:44:25.687 Number of processors: 2 586 0xE08
05:44:25.687 ComputerName: BASESTATION UserName: Russell
05:44:26.265 Initialize success
05:44:33.468 AVAST engine defs: 12030100
05:44:39.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
05:44:39.484 Disk 0 Vendor: TOSHIBA_MK1032GSX AS022D Size: 93958MB BusType: 3
05:44:39.515 Disk 0 MBR read successfully
05:44:39.515 Disk 0 MBR scan
05:44:39.578 Disk 0 unknown MBR code
05:44:39.578 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63
05:44:39.624 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 89141 MB offset 96390
05:44:39.656 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 182675115
05:44:39.687 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 7 MB offset 192410505
05:44:39.749 Disk 0 scanning sectors +192426554
05:44:39.874 Disk 0 scanning C:\WINDOWS\system32\drivers
05:45:14.609 Service scanning
05:45:26.999 Service MpKsl8b310159 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE66DCAC-0B02-460A-AF45-780EC2A6B328}\MpKsl8b310159.sys **LOCKED** 32
05:45:40.265 Modules scanning
05:46:01.687 Disk 0 trace - called modules:
05:46:01.718 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
05:46:01.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a6daab8]
05:46:01.734 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a745940]
05:46:02.140 AVAST engine scan C:\
08:19:35.828 Scan finished successfully
08:51:01.578 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Russell\Desktop\MBR.dat"
08:51:01.765 The log file has been saved successfully to "C:\Documents and Settings\Russell\Desktop\aswMBR.txt"
Hello JoshProto22

Thank you for the log.

A Spybot forum helper was trying to help get rid of all of the viruses / he did say that there was a hidden partition infection and multiple trojan viruses

I see that you were being assisted by ken545 (you were in very good hands).

At first I thought I had some search redirects but I think I may have just entered a web address wrong and was taken to a fake website.

It is very important that we know for certain if you are being redirected or not, since this can sometimes provide important clues as to exactly what is going on.

Please open your browser of choice and vist a trusted site to confirm if the redirects are still occurring (repeat the process with a google search) and let me know the outcome.


When you ran aswMBR, a file called MBR.dat was placed on your desktop (full path to file is C:\Documents and Settings\Russell\Desktop\MBR.dat).

Please attach the MBR.dat file and post it in your next reply.

Once attached and posted, please work your way through the steps below:


  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O4 - HKLM..\Run: [] File not found
      O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
      O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
      [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.


    I would also like to see a log from the following tool. If any malicious items are identified you will be given the option to cure them. At this time, please select skip rather than cure so I can review the log before we proceed.

  • TDSS Killer


    • Please read carefully and follow these steps.
    • Download TDSSKiller and save it to your Desktop.
    • Extract its contents to your desktop.
    • Open TDSSKiller.
    • When the window opens, click on "Change Parameters".
    • Under "Additional options", put a check mark in the box next to "Detect TDLFS File System".
    • click OK and then "Start scan".
    • If an infected file is detected, the default action will be Cure, please select Skip at this time.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

    Please post the attached MBR.dat, the OTL log and the TDSSKiller log in your next reply along with letting me know about the redirects :)
Hi,

I can say with 100% certainty that I'm not experiencing redirects. This was definitely a problem before my system was restored but not now.

I just tried to upload the MBR.dat file from my desktop and I received this message:

Upload failed. You are not permitted to upload this type of file

Do you know what's causing me to receive this message? I'll go ahead a start working on the other procedures and come back to the MBR.dat upload. Maybe it will work later.
(I'm still not able upload the MBR.dat file. The message says I'm not permitted to upload this type of file.)

Here are the OTL scan results:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\musicmatch.com\online\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found.
File E:\setup.exe not found.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\002854_.tmp deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 96844 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Russell
->Temp folder emptied: 104294563 bytes
->Temporary Internet Files folder emptied: 103843912 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 72175013 bytes
->Flash cache emptied: 845 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9215086 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 108793088 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 4730880 bytes

Total Files Cleaned = 385.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Russell
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.33.2 log created on 03022012_052118

Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp\TMP000000017946E0CBD1BF53BB not found!

Registry entries deleted on Reboot…



And here are the TDS Killer scan results:

05:26:41.0250 2288 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
05:26:41.0703 2288 ============================================================
05:26:41.0703 2288 Current date / time: 2012/03/02 05:26:41.0703
05:26:41.0703 2288 SystemInfo:
05:26:41.0703 2288
05:26:41.0703 2288 OS Version: 5.1.2600 ServicePack: 3.0
05:26:41.0703 2288 Product type: Workstation
05:26:41.0703 2288 ComputerName: BASESTATION
05:26:41.0703 2288 UserName: Russell
05:26:41.0703 2288 Windows directory: C:\WINDOWS
05:26:41.0703 2288 System windows directory: C:\WINDOWS
05:26:41.0703 2288 Processor architecture: Intel x86
05:26:41.0703 2288 Number of processors: 2
05:26:41.0703 2288 Page size: 0x1000
05:26:41.0703 2288 Boot type: Normal boot
05:26:41.0703 2288 ============================================================
05:26:44.0250 2288 Drive \Device\Harddisk0\DR0 - Size: 0x16F0649400 (91.76 Gb), SectorSize: 0x200, Cylinders: 0x2ECA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
05:26:44.0265 2288 \Device\Harddisk0\DR0:
05:26:44.0265 2288 MBR used
05:26:44.0265 2288 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0xAE1AF64
05:26:44.0312 2288 Initialize success
05:26:44.0312 2288 ============================================================
05:27:24.0046 1820 ============================================================
05:27:24.0046 1820 Scan started
05:27:24.0046 1820 Mode: Manual; TDLFS;
05:27:24.0046 1820 ============================================================
05:27:24.0296 1820 Abiosdsk - ok
05:27:24.0343 1820 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
05:27:24.0343 1820 abp480n5 - ok
05:27:24.0421 1820 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
05:27:24.0421 1820 ACPI - ok
05:27:24.0468 1820 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
05:27:24.0468 1820 ACPIEC - ok
05:27:24.0515 1820 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
05:27:24.0515 1820 adpu160m - ok
05:27:24.0562 1820 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
05:27:24.0562 1820 aec - ok
05:27:24.0609 1820 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
05:27:24.0640 1820 AegisP - ok
05:27:24.0703 1820 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
05:27:24.0703 1820 AFD - ok
05:27:24.0765 1820 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
05:27:24.0765 1820 agp440 - ok
05:27:24.0796 1820 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
05:27:24.0796 1820 agpCPQ - ok
05:27:24.0812 1820 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
05:27:24.0812 1820 Aha154x - ok
05:27:24.0843 1820 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
05:27:24.0843 1820 aic78u2 - ok
05:27:24.0875 1820 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
05:27:24.0875 1820 aic78xx - ok
05:27:24.0906 1820 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
05:27:24.0906 1820 AliIde - ok
05:27:24.0937 1820 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
05:27:24.0937 1820 alim1541 - ok
05:27:24.0953 1820 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
05:27:24.0953 1820 amdagp - ok
05:27:24.0968 1820 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
05:27:24.0968 1820 amsint - ok
05:27:25.0015 1820 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
05:27:25.0015 1820 APPDRV - ok
05:27:25.0046 1820 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
05:27:25.0046 1820 Arp1394 - ok
05:27:25.0093 1820 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
05:27:25.0093 1820 asc - ok
05:27:25.0140 1820 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
05:27:25.0140 1820 asc3350p - ok
05:27:25.0187 1820 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
05:27:25.0187 1820 asc3550 - ok
05:27:25.0234 1820 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
05:27:25.0234 1820 AsyncMac - ok
05:27:25.0281 1820 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
05:27:25.0281 1820 atapi - ok
05:27:25.0296 1820 Atdisk - ok
05:27:25.0390 1820 ati2mtag (bebeb471617782d138b6f92e7c3fab1c) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
05:27:25.0406 1820 ati2mtag - ok
05:27:25.0453 1820 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
05:27:25.0453 1820 Atmarpc - ok
05:27:25.0484 1820 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
05:27:25.0484 1820 audstub - ok
05:27:25.0515 1820 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
05:27:25.0515 1820 bcm4sbxp - ok
05:27:25.0531 1820 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
05:27:25.0531 1820 Beep - ok
05:27:25.0562 1820 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
05:27:25.0562 1820 cbidf - ok
05:27:25.0578 1820 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
05:27:25.0578 1820 cbidf2k - ok
05:27:25.0593 1820 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
05:27:25.0593 1820 cd20xrnt - ok
05:27:25.0609 1820 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
05:27:25.0609 1820 Cdaudio - ok
05:27:25.0625 1820 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
05:27:25.0625 1820 Cdfs - ok
05:27:25.0656 1820 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
05:27:25.0656 1820 Cdrom - ok
05:27:25.0671 1820 Changer - ok
05:27:25.0703 1820 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
05:27:25.0703 1820 CmBatt - ok
05:27:25.0734 1820 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
05:27:25.0734 1820 CmdIde - ok
05:27:25.0750 1820 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
05:27:25.0750 1820 Compbatt - ok
05:27:25.0796 1820 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
05:27:25.0796 1820 Cpqarray - ok
05:27:25.0859 1820 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
05:27:25.0859 1820 dac2w2k - ok
05:27:25.0875 1820 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
05:27:25.0875 1820 dac960nt - ok
05:27:25.0890 1820 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
05:27:25.0890 1820 Disk - ok
05:27:25.0968 1820 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
05:27:25.0984 1820 dmboot - ok
05:27:26.0109 1820 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
05:27:26.0109 1820 dmio - ok
05:27:26.0140 1820 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
05:27:26.0140 1820 dmload - ok
05:27:26.0171 1820 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
05:27:26.0171 1820 DMusic - ok
05:27:26.0234 1820 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
05:27:26.0234 1820 dpti2o - ok
05:27:26.0281 1820 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
05:27:26.0281 1820 drmkaud - ok
05:27:26.0312 1820 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
05:27:26.0343 1820 drvmcdb - ok
05:27:26.0359 1820 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
05:27:26.0953 1820 drvnddm - ok
05:27:27.0093 1820 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
05:27:27.0093 1820 E100B - ok
05:27:27.0156 1820 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
05:27:27.0156 1820 Fastfat - ok
05:27:27.0171 1820 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
05:27:27.0171 1820 Fdc - ok
05:27:27.0203 1820 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
05:27:27.0203 1820 Fips - ok
05:27:27.0234 1820 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
05:27:27.0234 1820 Flpydisk - ok
05:27:27.0281 1820 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
05:27:27.0281 1820 FltMgr - ok
05:27:27.0328 1820 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
05:27:27.0328 1820 Fs_Rec - ok
05:27:27.0343 1820 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
05:27:27.0343 1820 Ftdisk - ok
05:27:27.0406 1820 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
05:27:27.0406 1820 Gpc - ok
05:27:27.0421 1820 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
05:27:27.0421 1820 HDAudBus - ok
05:27:27.0453 1820 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
05:27:27.0453 1820 HidUsb - ok
05:27:27.0468 1820 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
05:27:27.0468 1820 hpn - ok
05:27:27.0531 1820 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
05:27:27.0531 1820 HSFHWAZL - ok
05:27:27.0593 1820 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
05:27:27.0625 1820 HSF_DPV - ok
05:27:27.0687 1820 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
05:27:27.0687 1820 HTTP - ok
05:27:27.0718 1820 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
05:27:27.0718 1820 i2omgmt - ok
05:27:27.0734 1820 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
05:27:27.0734 1820 i2omp - ok
05:27:27.0765 1820 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
05:27:27.0765 1820 i8042prt - ok
05:27:27.0843 1820 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
05:27:27.0843 1820 Imapi - ok
05:27:27.0890 1820 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
05:27:27.0890 1820 ini910u - ok
05:27:27.0937 1820 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
05:27:27.0937 1820 IntelIde - ok
05:27:27.0953 1820 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
05:27:27.0968 1820 intelppm - ok
05:27:27.0984 1820 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
05:27:27.0984 1820 Ip6Fw - ok
05:27:28.0015 1820 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
05:27:28.0015 1820 IpFilterDriver - ok
05:27:28.0046 1820 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
05:27:28.0046 1820 IpInIp - ok
05:27:28.0109 1820 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
05:27:28.0109 1820 IpNat - ok
05:27:28.0156 1820 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
05:27:28.0156 1820 IPSec - ok
05:27:28.0187 1820 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
05:27:28.0187 1820 IRENUM - ok
05:27:28.0218 1820 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
05:27:28.0218 1820 isapnp - ok
05:27:28.0234 1820 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
05:27:28.0250 1820 Kbdclass - ok
05:27:28.0281 1820 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
05:27:28.0281 1820 kmixer - ok
05:27:28.0312 1820 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
05:27:28.0312 1820 KSecDD - ok
05:27:28.0328 1820 lbrtfdc - ok
05:27:28.0406 1820 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
05:27:28.0406 1820 mdmxsdk - ok
05:27:28.0437 1820 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
05:27:28.0437 1820 MHNDRV - ok
05:27:28.0453 1820 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
05:27:28.0453 1820 mnmdd - ok
05:27:28.0484 1820 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
05:27:28.0484 1820 Modem - ok
05:27:28.0500 1820 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
05:27:28.0500 1820 Mouclass - ok
05:27:28.0531 1820 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
05:27:28.0546 1820 mouhid - ok
05:27:28.0562 1820 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
05:27:28.0562 1820 MountMgr - ok
05:27:28.0625 1820 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
05:27:28.0625 1820 MpFilter - ok
05:27:28.0718 1820 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
05:27:28.0718 1820 mraid35x - ok
05:27:28.0734 1820 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
05:27:28.0734 1820 MRxDAV - ok
05:27:28.0796 1820 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
05:27:28.0812 1820 MRxSmb - ok
05:27:28.0828 1820 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
05:27:28.0828 1820 Msfs - ok
05:27:28.0859 1820 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
05:27:28.0859 1820 MSKSSRV - ok
05:27:28.0875 1820 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
05:27:28.0875 1820 MSPCLOCK - ok
05:27:28.0906 1820 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
05:27:28.0906 1820 MSPQM - ok
05:27:28.0937 1820 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
05:27:28.0953 1820 mssmbios - ok
05:27:29.0000 1820 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
05:27:29.0000 1820 Mup - ok
05:27:29.0062 1820 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
05:27:29.0062 1820 NDIS - ok
05:27:29.0109 1820 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
05:27:29.0109 1820 NdisTapi - ok
05:27:29.0125 1820 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
05:27:29.0125 1820 Ndisuio - ok
05:27:29.0140 1820 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
05:27:29.0140 1820 NdisWan - ok
05:27:29.0171 1820 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
05:27:29.0171 1820 NDProxy - ok
05:27:29.0187 1820 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
05:27:29.0187 1820 NetBIOS - ok
05:27:29.0234 1820 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
05:27:29.0234 1820 NetBT - ok
05:27:29.0265 1820 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
05:27:29.0265 1820 NIC1394 - ok
05:27:29.0296 1820 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
05:27:29.0296 1820 Npfs - ok
05:27:29.0343 1820 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
05:27:29.0359 1820 Ntfs - ok
05:27:29.0390 1820 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
05:27:29.0390 1820 Null - ok
05:27:29.0484 1820 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
05:27:29.0531 1820 nv - ok
05:27:29.0609 1820 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
05:27:29.0625 1820 NwlnkFlt - ok
05:27:29.0625 1820 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
05:27:29.0640 1820 NwlnkFwd - ok
05:27:29.0640 1820 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
05:27:29.0656 1820 ohci1394 - ok
05:27:29.0671 1820 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
05:27:29.0718 1820 omci - ok
05:27:29.0781 1820 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
05:27:29.0781 1820 Parport - ok
05:27:29.0812 1820 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
05:27:29.0812 1820 PartMgr - ok
05:27:29.0843 1820 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
05:27:29.0843 1820 ParVdm - ok
05:27:29.0890 1820 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
05:27:29.0890 1820 PCI - ok
05:27:29.0906 1820 PCIDump - ok
05:27:29.0921 1820 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
05:27:29.0921 1820 PCIIde - ok
05:27:29.0968 1820 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
05:27:29.0968 1820 Pcmcia - ok
05:27:29.0984 1820 PDCOMP - ok
05:27:30.0000 1820 PDFRAME - ok
05:27:30.0015 1820 PDRELI - ok
05:27:30.0031 1820 PDRFRAME - ok
05:27:30.0062 1820 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
05:27:30.0062 1820 perc2 - ok
05:27:30.0078 1820 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
05:27:30.0078 1820 perc2hib - ok
05:27:30.0140 1820 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
05:27:30.0140 1820 PptpMiniport - ok
05:27:30.0156 1820 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
05:27:30.0156 1820 PSched - ok
05:27:30.0171 1820 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
05:27:30.0171 1820 Ptilink - ok
05:27:30.0203 1820 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
05:27:30.0203 1820 PxHelp20 - ok
05:27:30.0234 1820 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
05:27:30.0234 1820 ql1080 - ok
05:27:30.0250 1820 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
05:27:30.0250 1820 Ql10wnt - ok
05:27:30.0281 1820 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
05:27:30.0281 1820 ql12160 - ok
05:27:30.0296 1820 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
05:27:30.0296 1820 ql1240 - ok
05:27:30.0312 1820 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
05:27:30.0312 1820 ql1280 - ok
05:27:30.0343 1820 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
05:27:30.0343 1820 RasAcd - ok
05:27:30.0375 1820 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
05:27:30.0390 1820 Rasl2tp - ok
05:27:30.0406 1820 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
05:27:30.0406 1820 RasPppoe - ok
05:27:30.0421 1820 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
05:27:30.0421 1820 Raspti - ok
05:27:30.0437 1820 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
05:27:30.0453 1820 Rdbss - ok
05:27:30.0468 1820 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
05:27:30.0468 1820 RDPCDD - ok
05:27:30.0500 1820 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
05:27:30.0500 1820 rdpdr - ok
05:27:30.0562 1820 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
05:27:30.0562 1820 RDPWD - ok
05:27:30.0656 1820 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
05:27:30.0656 1820 redbook - ok
05:27:30.0687 1820 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
05:27:30.0687 1820 rimmptsk - ok
05:27:30.0687 1820 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
05:27:30.0703 1820 rimsptsk - ok
05:27:30.0718 1820 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
05:27:30.0718 1820 rismxdp - ok
05:27:30.0781 1820 s24trans (2e4e912ce95f5ef4d4a5079f6ce367fc) C:\WINDOWS\system32\DRIVERS\s24trans.sys
05:27:30.0796 1820 s24trans - ok
05:27:30.0843 1820 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
05:27:30.0859 1820 sdbus - ok
05:27:30.0890 1820 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
05:27:30.0890 1820 Secdrv - ok
05:27:30.0906 1820 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
05:27:30.0906 1820 serenum - ok
05:27:30.0937 1820 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
05:27:30.0937 1820 Serial - ok
05:27:30.0968 1820 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
05:27:30.0968 1820 Sfloppy - ok
05:27:30.0984 1820 Simbad - ok
05:27:31.0015 1820 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
05:27:31.0015 1820 sisagp - ok
05:27:31.0062 1820 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
05:27:31.0062 1820 Sparrow - ok
05:27:31.0093 1820 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
05:27:31.0093 1820 splitter - ok
05:27:31.0109 1820 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
05:27:31.0125 1820 sr - ok
05:27:31.0187 1820 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
05:27:31.0187 1820 Srv - ok
05:27:31.0218 1820 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
05:27:31.0234 1820 sscdbhk5 - ok
05:27:31.0250 1820 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
05:27:31.0281 1820 ssrtln - ok
05:27:31.0359 1820 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys
05:27:31.0375 1820 STHDA - ok
05:27:31.0421 1820 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
05:27:31.0421 1820 swenum - ok
05:27:31.0453 1820 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
05:27:31.0453 1820 swmidi - ok
05:27:31.0546 1820 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
05:27:31.0546 1820 symc810 - ok
05:27:31.0562 1820 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
05:27:31.0562 1820 symc8xx - ok
05:27:31.0578 1820 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
05:27:31.0578 1820 sym_hi - ok
05:27:31.0593 1820 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
05:27:31.0593 1820 sym_u3 - ok
05:27:31.0640 1820 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys
05:27:31.0656 1820 SynTP - ok
05:27:31.0687 1820 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
05:27:31.0687 1820 sysaudio - ok
05:27:31.0750 1820 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
05:27:31.0750 1820 Tcpip - ok
05:27:31.0781 1820 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
05:27:31.0781 1820 TDPIPE - ok
05:27:31.0796 1820 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
05:27:31.0796 1820 TDTCP - ok
05:27:31.0812 1820 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
05:27:31.0812 1820 TermDD - ok
05:27:31.0843 1820 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
05:27:31.0859 1820 tfsnboio - ok
05:27:31.0875 1820 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
05:27:31.0906 1820 tfsncofs - ok
05:27:31.0906 1820 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
05:27:31.0921 1820 tfsndrct - ok
05:27:31.0937 1820 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
05:27:31.0953 1820 tfsndres - ok
05:27:31.0968 1820 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
05:27:32.0015 1820 tfsnifs - ok
05:27:32.0031 1820 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
05:27:32.0046 1820 tfsnopio - ok
05:27:32.0062 1820 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
05:27:32.0078 1820 tfsnpool - ok
05:27:32.0093 1820 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
05:27:32.0140 1820 tfsnudf - ok
05:27:32.0156 1820 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
05:27:32.0203 1820 tfsnudfa - ok
05:27:32.0250 1820 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
05:27:32.0250 1820 TosIde - ok
05:27:32.0296 1820 Tosrfbd (37a7d0d105110aafac6e982a2c49b8b6) C:\WINDOWS\system32\Drivers\tosrfbd.sys
05:27:32.0328 1820 Tosrfbd - ok
05:27:32.0375 1820 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\drivers\Tosrfcom.sys
05:27:32.0437 1820 Tosrfcom - ok
05:27:32.0453 1820 Tosrfhid (f4e4795528d17ff8d1d6d98ebbb92655) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
05:27:32.0500 1820 Tosrfhid - ok
05:27:32.0515 1820 Tosrfusb (1d19323d5bc7309d9df65dad5635005c) C:\WINDOWS\system32\Drivers\tosrfusb.sys
05:27:32.0546 1820 Tosrfusb - ok
05:27:32.0578 1820 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
05:27:32.0578 1820 Udfs - ok
05:27:32.0625 1820 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
05:27:32.0625 1820 ultra - ok
05:27:32.0671 1820 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
05:27:32.0671 1820 Update - ok
05:27:32.0765 1820 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
05:27:32.0765 1820 usbccgp - ok
05:27:32.0781 1820 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
05:27:32.0796 1820 usbehci - ok
05:27:32.0812 1820 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
05:27:32.0812 1820 usbhub - ok
05:27:32.0875 1820 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
05:27:32.0875 1820 usbuhci - ok
05:27:32.0890 1820 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
05:27:32.0890 1820 VgaSave - ok
05:27:32.0921 1820 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
05:27:32.0937 1820 viaagp - ok
05:27:32.0953 1820 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
05:27:32.0953 1820 ViaIde - ok
05:27:32.0984 1820 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
05:27:32.0984 1820 VolSnap - ok
05:27:33.0078 1820 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
05:27:33.0109 1820 w39n51 - ok
05:27:33.0140 1820 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
05:27:33.0140 1820 Wanarp - ok
05:27:33.0156 1820 wanatw - ok
05:27:33.0171 1820 WDICA - ok
05:27:33.0187 1820 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
05:27:33.0187 1820 wdmaud - ok
05:27:33.0265 1820 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
05:27:33.0281 1820 winachsf - ok
05:27:33.0328 1820 MBR (0x1B8) (2ba3e330828ad649a40ef55575d98871) \Device\Harddisk0\DR0
05:27:33.0359 1820 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
05:27:33.0359 1820 \Device\Harddisk0\DR0 - detected TDSS File System (1)
05:27:33.0406 1820 Boot (0x1200) (64e75b0b5a6b9362f974df70553b240c) \Device\Harddisk0\DR0\Partition0
05:27:33.0406 1820 \Device\Harddisk0\DR0\Partition0 - ok
05:27:33.0406 1820 ============================================================
05:27:33.0406 1820 Scan finished
05:27:33.0406 1820 ============================================================
05:27:33.0421 3244 Detected object count: 1
05:27:33.0421 3244 Actual detected object count: 1
05:28:07.0656 3244 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
05:28:07.0656 3244 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Hello JoshProto22

Thank you for the logs and information about the redirects :thumbup:

Lets see if we can get the file attached before we continue.

Please Right click on the file (MBR.dat) and select Send to > Compressed (zipped folder). The file will be placed in a zipped folder on your desktop. See if you can attach the zipped folder in your next reply :)
Hello JoshProto22

Good job getting that file attached :thumbup:

Lets proceed as follows:

Run TDSSKiller again as you did before, but this time, when the following is identified in the scan

05:27:33.0359 1820 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
05:27:33.0359 1820 \Device\Harddisk0\DR0 - detected TDSS File System (1)

Please select delete.

Once the scan has completed please post the log in your next reply.
Hi, I just followed the new TDSSKiller procedure and selected "delete" as you suggested. It seems like it doesn't see the threat anymore. However, I'm seeing that Microsoft Security Essentials is still warning me about Trojan:Dos/Alureon.E., boot:\\PHYSICALDRIVE0\Partition 3 (Type 17). Just let me know where we go from here. Thanks for the help. Here's the TDSSKiller log: 02:49:34.0718 2164 TDSS rootkit removing tool [removed] Mar 2 2012 09:40:07 02:49:35.0218 2164 ============================================================ 02:49:35.0218 2164 Current date / time: 2012/03/03 02:49:35.0218 02:49:35.0218 2164 SystemInfo: 02:49:35.0218 2164 02:49:35.0218 2164 OS Version: 5.1.2600 ServicePack: 3.0 02:49:35.0218 2164 Product type: Workstation 02:49:35.0218 2164 ComputerName: BASESTATION 02:49:35.0218 2164 UserName: Russell 02:49:35.0218 2164 Windows directory: C:\WINDOWS 02:49:35.0218 2164 System windows directory: C:\WINDOWS 02:49:35.0218 2164 Processor architecture: Intel x86 02:49:35.0218 2164 Number of processors: 2 02:49:35.0218 2164 Page size: 0x1000 02:49:35.0218 2164 Boot type: Normal boot 02:49:35.0218 2164 ============================================================ 02:49:37.0312 2164 Drive \Device\Harddisk0\DR0 - Size: 0x16F0649400 (91.76 Gb), SectorSize: 0x200, Cylinders: 0x2ECA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 02:49:37.0312 2164 \Device\Harddisk0\DR0: 02:49:37.0312 2164 MBR used 02:49:37.0312 2164 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0xAE1AF64 02:49:37.0609 2164 Initialize success 02:49:37.0609 2164 ============================================================ 02:49:45.0921 2008 ============================================================ 02:49:45.0921 2008 Scan started 02:49:45.0921 2008 Mode: Manual; TDLFS; 02:49:45.0921 2008 ============================================================ 02:49:46.0218 2008 Abiosdsk - ok 02:49:46.0281 2008 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 02:49:46.0281 2008 abp480n5 - ok 02:49:46.0328 2008 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 02:49:46.0343 2008 ACPI - ok 02:49:46.0375 2008 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 02:49:46.0375 2008 ACPIEC - ok 02:49:46.0390 2008 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 02:49:46.0406 2008 adpu160m - ok 02:49:46.0437 2008 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 02:49:46.0437 2008 aec - ok 02:49:46.0500 2008 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys 02:49:46.0531 2008 AegisP - ok 02:49:46.0578 2008 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 02:49:46.0625 2008 AFD - ok 02:49:46.0656 2008 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 02:49:46.0656 2008 agp440 - ok 02:49:46.0703 2008 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 02:49:46.0703 2008 agpCPQ - ok 02:49:46.0703 2008 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 02:49:46.0718 2008 Aha154x - ok 02:49:46.0734 2008 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 02:49:46.0750 2008 aic78u2 - ok 02:49:46.0781 2008 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 02:49:46.0781 2008 aic78xx - ok 02:49:46.0796 2008 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 02:49:46.0796 2008 AliIde - ok 02:49:46.0828 2008 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 02:49:46.0828 2008 alim1541 - ok 02:49:46.0843 2008 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 02:49:46.0843 2008 amdagp - ok 02:49:46.0859 2008 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 02:49:46.0859 2008 amsint - ok 02:49:46.0906 2008 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 02:49:46.0906 2008 APPDRV - ok 02:49:46.0937 2008 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 02:49:46.0937 2008 Arp1394 - ok 02:49:46.0968 2008 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 02:49:46.0968 2008 asc - ok 02:49:47.0031 2008 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 02:49:47.0046 2008 asc3350p - ok 02:49:47.0046 2008 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 02:49:47.0046 2008 asc3550 - ok 02:49:47.0093 2008 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 02:49:47.0093 2008 AsyncMac - ok 02:49:47.0109 2008 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 02:49:47.0109 2008 atapi - ok 02:49:47.0125 2008 Atdisk - ok 02:49:47.0218 2008 ati2mtag (bebeb471617782d138b6f92e7c3fab1c) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 02:49:47.0234 2008 ati2mtag - ok 02:49:47.0296 2008 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 02:49:47.0312 2008 Atmarpc - ok 02:49:47.0359 2008 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 02:49:47.0359 2008 audstub - ok 02:49:47.0375 2008 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 02:49:47.0406 2008 bcm4sbxp - ok 02:49:47.0437 2008 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 02:49:47.0437 2008 Beep - ok 02:49:47.0500 2008 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 02:49:47.0500 2008 cbidf - ok 02:49:47.0609 2008 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 02:49:47.0609 2008 cbidf2k - ok 02:49:47.0859 2008 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 02:49:47.0859 2008 cd20xrnt - ok 02:49:47.0968 2008 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 02:49:47.0984 2008 Cdaudio - ok 02:49:48.0015 2008 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 02:49:48.0015 2008 Cdfs - ok 02:49:48.0046 2008 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 02:49:48.0062 2008 Cdrom - ok 02:49:48.0062 2008 Changer - ok 02:49:48.0093 2008 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 02:49:48.0093 2008 CmBatt - ok 02:49:48.0109 2008 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 02:49:48.0109 2008 CmdIde - ok 02:49:48.0125 2008 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 02:49:48.0125 2008 Compbatt - ok 02:49:48.0203 2008 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 02:49:48.0203 2008 Cpqarray - ok 02:49:48.0296 2008 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 02:49:48.0296 2008 dac2w2k - ok 02:49:48.0312 2008 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 02:49:48.0312 2008 dac960nt - ok 02:49:48.0328 2008 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 02:49:48.0343 2008 Disk - ok 02:49:48.0421 2008 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 02:49:48.0437 2008 dmboot - ok 02:49:48.0453 2008 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 02:49:48.0468 2008 dmio - ok 02:49:48.0484 2008 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 02:49:48.0484 2008 dmload - ok 02:49:48.0546 2008 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 02:49:48.0546 2008 DMusic - ok 02:49:48.0625 2008 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 02:49:48.0625 2008 dpti2o - ok 02:49:48.0640 2008 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 02:49:48.0640 2008 drmkaud - ok 02:49:48.0687 2008 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys 02:49:48.0718 2008 drvmcdb - ok 02:49:48.0734 2008 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys 02:49:49.0328 2008 drvnddm - ok 02:49:49.0468 2008 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 02:49:49.0468 2008 E100B - ok 02:49:49.0531 2008 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 02:49:49.0531 2008 Fastfat - ok 02:49:49.0562 2008 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 02:49:49.0578 2008 Fdc - ok 02:49:49.0593 2008 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 02:49:49.0593 2008 Fips - ok 02:49:49.0625 2008 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 02:49:49.0625 2008 Flpydisk - ok 02:49:49.0671 2008 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 02:49:49.0671 2008 FltMgr - ok 02:49:49.0718 2008 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 02:49:49.0718 2008 Fs_Rec - ok 02:49:49.0734 2008 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 02:49:49.0734 2008 Ftdisk - ok 02:49:49.0812 2008 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 02:49:49.0812 2008 Gpc - ok 02:49:49.0859 2008 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 02:49:49.0859 2008 HDAudBus - ok 02:49:49.0906 2008 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 02:49:49.0906 2008 HidUsb - ok 02:49:49.0937 2008 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 02:49:49.0937 2008 hpn - ok 02:49:50.0000 2008 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 02:49:50.0000 2008 HSFHWAZL - ok 02:49:50.0062 2008 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 02:49:50.0093 2008 HSF_DPV - ok 02:49:50.0156 2008 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 02:49:50.0156 2008 HTTP - ok 02:49:50.0187 2008 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 02:49:50.0187 2008 i2omgmt - ok 02:49:50.0218 2008 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 02:49:50.0218 2008 i2omp - ok 02:49:50.0281 2008 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 02:49:50.0281 2008 i8042prt - ok 02:49:50.0296 2008 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 02:49:50.0296 2008 Imapi - ok 02:49:50.0343 2008 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 02:49:50.0343 2008 ini910u - ok 02:49:50.0375 2008 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 02:49:50.0375 2008 IntelIde - ok 02:49:50.0406 2008 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 02:49:50.0406 2008 intelppm - ok 02:49:50.0437 2008 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 02:49:50.0437 2008 Ip6Fw - ok 02:49:50.0468 2008 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 02:49:50.0468 2008 IpFilterDriver - ok 02:49:50.0500 2008 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 02:49:50.0500 2008 IpInIp - ok 02:49:50.0531 2008 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 02:49:50.0531 2008 IpNat - ok 02:49:50.0578 2008 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 02:49:50.0578 2008 IPSec - ok 02:49:50.0609 2008 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 02:49:50.0609 2008 IRENUM - ok 02:49:50.0640 2008 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 02:49:50.0640 2008 isapnp - ok 02:49:50.0656 2008 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 02:49:50.0656 2008 Kbdclass - ok 02:49:50.0687 2008 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 02:49:50.0703 2008 kmixer - ok 02:49:50.0734 2008 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 02:49:50.0796 2008 KSecDD - ok 02:49:50.0812 2008 lbrtfdc - ok 02:49:50.0875 2008 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 02:49:50.0875 2008 mdmxsdk - ok 02:49:50.0921 2008 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 02:49:50.0921 2008 MHNDRV - ok 02:49:50.0953 2008 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 02:49:50.0953 2008 mnmdd - ok 02:49:51.0000 2008 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 02:49:51.0000 2008 Modem - ok 02:49:51.0015 2008 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 02:49:51.0015 2008 Mouclass - ok 02:49:51.0046 2008 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 02:49:51.0046 2008 mouhid - ok 02:49:51.0140 2008 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 02:49:51.0140 2008 MountMgr - ok 02:49:51.0187 2008 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 02:49:51.0187 2008 MpFilter - ok 02:49:51.0203 2008 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 02:49:51.0203 2008 mraid35x - ok 02:49:51.0218 2008 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 02:49:51.0234 2008 MRxDAV - ok 02:49:51.0296 2008 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 02:49:51.0359 2008 MRxSmb - ok 02:49:51.0375 2008 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 02:49:51.0375 2008 Msfs - ok 02:49:51.0421 2008 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 02:49:51.0421 2008 MSKSSRV - ok 02:49:51.0437 2008 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 02:49:51.0437 2008 MSPCLOCK - ok 02:49:51.0453 2008 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 02:49:51.0453 2008 MSPQM - ok 02:49:51.0500 2008 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 02:49:51.0500 2008 mssmbios - ok 02:49:51.0546 2008 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 02:49:51.0578 2008 Mup - ok 02:49:51.0640 2008 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 02:49:51.0640 2008 NDIS - ok 02:49:51.0687 2008 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 02:49:51.0703 2008 NdisTapi - ok 02:49:51.0718 2008 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 02:49:51.0734 2008 Ndisuio - ok 02:49:51.0734 2008 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 02:49:51.0750 2008 NdisWan - ok 02:49:51.0781 2008 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 02:49:51.0812 2008 NDProxy - ok 02:49:51.0828 2008 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 02:49:51.0828 2008 NetBIOS - ok 02:49:51.0875 2008 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 02:49:51.0875 2008 NetBT - ok 02:49:51.0906 2008 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 02:49:51.0906 2008 NIC1394 - ok 02:49:51.0937 2008 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 02:49:51.0937 2008 Npfs - ok 02:49:51.0984 2008 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 02:49:52.0000 2008 Ntfs - ok 02:49:52.0031 2008 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 02:49:52.0031 2008 Null - ok 02:49:52.0187 2008 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 02:49:52.0234 2008 nv - ok 02:49:52.0281 2008 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 02:49:52.0281 2008 NwlnkFlt - ok 02:49:52.0296 2008 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 02:49:52.0296 2008 NwlnkFwd - ok 02:49:52.0312 2008 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 02:49:52.0312 2008 ohci1394 - ok 02:49:52.0359 2008 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys 02:49:52.0390 2008 omci - ok 02:49:52.0453 2008 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 02:49:52.0453 2008 Parport - ok 02:49:52.0484 2008 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 02:49:52.0484 2008 PartMgr - ok 02:49:52.0515 2008 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 02:49:52.0515 2008 ParVdm - ok 02:49:52.0531 2008 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 02:49:52.0531 2008 PCI - ok 02:49:52.0546 2008 PCIDump - ok 02:49:52.0546 2008 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 02:49:52.0562 2008 PCIIde - ok 02:49:52.0609 2008 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 02:49:52.0609 2008 Pcmcia - ok 02:49:52.0625 2008 PDCOMP - ok 02:49:52.0625 2008 PDFRAME - ok 02:49:52.0640 2008 PDRELI - ok 02:49:52.0656 2008 PDRFRAME - ok 02:49:52.0687 2008 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 02:49:52.0703 2008 perc2 - ok 02:49:52.0718 2008 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 02:49:52.0718 2008 perc2hib - ok 02:49:52.0765 2008 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 02:49:52.0765 2008 PptpMiniport - ok 02:49:52.0781 2008 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 02:49:52.0796 2008 PSched - ok 02:49:52.0796 2008 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 02:49:52.0812 2008 Ptilink - ok 02:49:52.0843 2008 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 02:49:52.0843 2008 PxHelp20 - ok 02:49:52.0890 2008 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 02:49:52.0890 2008 ql1080 - ok 02:49:52.0906 2008 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 02:49:52.0906 2008 Ql10wnt - ok 02:49:52.0937 2008 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 02:49:52.0937 2008 ql12160 - ok 02:49:53.0031 2008 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 02:49:53.0031 2008 ql1240 - ok 02:49:53.0046 2008 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 02:49:53.0046 2008 ql1280 - ok 02:49:53.0156 2008 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 02:49:53.0156 2008 RasAcd - ok 02:49:53.0312 2008 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 02:49:53.0312 2008 Rasl2tp - ok 02:49:53.0468 2008 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 02:49:53.0468 2008 RasPppoe - ok 02:49:53.0718 2008 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 02:49:53.0718 2008 Raspti - ok 02:49:53.0921 2008 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 02:49:53.0953 2008 Rdbss - ok 02:49:53.0968 2008 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 02:49:53.0968 2008 RDPCDD - ok 02:49:54.0015 2008 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 02:49:54.0015 2008 rdpdr - ok 02:49:54.0078 2008 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 02:49:54.0078 2008 RDPWD - ok 02:49:54.0125 2008 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 02:49:54.0125 2008 redbook - ok 02:49:54.0156 2008 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 02:49:54.0156 2008 rimmptsk - ok 02:49:54.0171 2008 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 02:49:54.0171 2008 rimsptsk - ok 02:49:54.0203 2008 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 02:49:54.0203 2008 rismxdp - ok 02:49:54.0265 2008 s24trans (2e4e912ce95f5ef4d4a5079f6ce367fc) C:\WINDOWS\system32\DRIVERS\s24trans.sys 02:49:54.0296 2008 s24trans - ok 02:49:54.0359 2008 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 02:49:54.0359 2008 sdbus - ok 02:49:54.0406 2008 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 02:49:54.0421 2008 Secdrv - ok 02:49:54.0437 2008 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 02:49:54.0453 2008 serenum - ok 02:49:54.0468 2008 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 02:49:54.0484 2008 Serial - ok 02:49:54.0515 2008 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 02:49:54.0515 2008 Sfloppy - ok 02:49:54.0578 2008 Simbad - ok 02:49:54.0609 2008 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 02:49:54.0609 2008 sisagp - ok 02:49:54.0671 2008 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 02:49:54.0671 2008 Sparrow - ok 02:49:54.0718 2008 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 02:49:54.0718 2008 splitter - ok 02:49:54.0734 2008 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 02:49:54.0750 2008 sr - ok 02:49:54.0843 2008 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 02:49:54.0890 2008 Srv - ok 02:49:54.0921 2008 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 02:49:54.0953 2008 sscdbhk5 - ok 02:49:54.0968 2008 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 02:49:55.0015 2008 ssrtln - ok 02:49:55.0093 2008 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys 02:49:55.0109 2008 STHDA - ok 02:49:55.0140 2008 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 02:49:55.0140 2008 swenum - ok 02:49:55.0156 2008 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 02:49:55.0156 2008 swmidi - ok 02:49:55.0218 2008 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 02:49:55.0218 2008 symc810 - ok 02:49:55.0234 2008 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 02:49:55.0234 2008 symc8xx - ok 02:49:55.0250 2008 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 02:49:55.0250 2008 sym_hi - ok 02:49:55.0265 2008 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 02:49:55.0265 2008 sym_u3 - ok 02:49:55.0312 2008 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys 02:49:55.0328 2008 SynTP - ok 02:49:55.0343 2008 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 02:49:55.0343 2008 sysaudio - ok 02:49:55.0406 2008 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 02:49:55.0468 2008 Tcpip - ok 02:49:55.0515 2008 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 02:49:55.0515 2008 TDPIPE - ok 02:49:55.0531 2008 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 02:49:55.0531 2008 TDTCP - ok 02:49:55.0546 2008 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 02:49:55.0546 2008 TermDD - ok 02:49:55.0578 2008 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys 02:49:55.0609 2008 tfsnboio - ok 02:49:55.0625 2008 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys 02:49:55.0656 2008 tfsncofs - ok 02:49:55.0671 2008 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys 02:49:55.0687 2008 tfsndrct - ok 02:49:55.0703 2008 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys 02:49:55.0734 2008 tfsndres - ok 02:49:55.0750 2008 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys 02:49:55.0812 2008 tfsnifs - ok 02:49:55.0828 2008 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys 02:49:55.0859 2008 tfsnopio - ok 02:49:55.0875 2008 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys 02:49:55.0875 2008 tfsnpool - ok 02:49:55.0890 2008 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys 02:49:55.0937 2008 tfsnudf - ok 02:49:55.0984 2008 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys 02:49:56.0015 2008 tfsnudfa - ok 02:49:56.0062 2008 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 02:49:56.0062 2008 TosIde - ok 02:49:56.0156 2008 Tosrfbd (37a7d0d105110aafac6e982a2c49b8b6) C:\WINDOWS\system32\Drivers\tosrfbd.sys 02:49:56.0203 2008 Tosrfbd - ok 02:49:56.0250 2008 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\drivers\Tosrfcom.sys 02:49:56.0296 2008 Tosrfcom - ok 02:49:56.0296 2008 Tosrfhid (f4e4795528d17ff8d1d6d98ebbb92655) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys 02:49:56.0343 2008 Tosrfhid - ok 02:49:56.0359 2008 Tosrfusb (1d19323d5bc7309d9df65dad5635005c) C:\WINDOWS\system32\Drivers\tosrfusb.sys 02:49:56.0406 2008 Tosrfusb - ok 02:49:56.0437 2008 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 02:49:56.0437 2008 Udfs - ok 02:49:56.0468 2008 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 02:49:56.0468 2008 ultra - ok 02:49:56.0531 2008 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 02:49:56.0546 2008 Update - ok 02:49:56.0562 2008 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 02:49:56.0578 2008 usbccgp - ok 02:49:56.0593 2008 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 02:49:56.0593 2008 usbehci - ok 02:49:56.0640 2008 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 02:49:56.0640 2008 usbhub - ok 02:49:56.0671 2008 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 02:49:56.0671 2008 usbuhci - ok 02:49:56.0687 2008 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 02:49:56.0687 2008 VgaSave - ok 02:49:56.0734 2008 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 02:49:56.0734 2008 viaagp - ok 02:49:56.0781 2008 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 02:49:56.0781 2008 ViaIde - ok 02:49:56.0812 2008 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 02:49:56.0812 2008 VolSnap - ok 02:49:56.0906 2008 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys 02:49:56.0937 2008 w39n51 - ok 02:49:57.0000 2008 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 02:49:57.0000 2008 Wanarp - ok 02:49:57.0046 2008 wanatw - ok 02:49:57.0062 2008 WDICA - ok 02:49:57.0093 2008 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 02:49:57.0109 2008 wdmaud - ok 02:49:57.0187 2008 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 02:49:57.0203 2008 winachsf - ok 02:49:57.0265 2008 MBR (0x1B8) (2ba3e330828ad649a40ef55575d98871) \Device\Harddisk0\DR0 02:49:57.0375 2008 \Device\Harddisk0\DR0 - ok 02:49:57.0406 2008 Boot (0x1200) (64e75b0b5a6b9362f974df70553b240c) \Device\Harddisk0\DR0\Partition0 02:49:57.0406 2008 \Device\Harddisk0\DR0\Partition0 - ok 02:49:57.0406 2008 ============================================================ 02:49:57.0406 2008 Scan finished 02:49:57.0406 2008 ============================================================ 02:49:57.0421 2984 Detected object count: 0 02:49:57.0421 2984 Actual detected object count: 0 02:50:33.0421 2392 Deinitialize success
Hello JoshProto22

Thank you for the log.

It seems like it doesn't see the threat anymore

Thats good :)

However, I'm seeing that Microsoft Security Essentials is still warning me about Trojan:Dos/Alureon.E., boot:\\PHYSICALDRIVE0\Partition 3 (Type 17).

It may be that it is being detected from TDSSKiller quarantine. Did MSE tell you exactly where the threat was located?

Please post a new aswMBR scan log in your next reply :)
Hi, MSE doesn't give an exact location of the infection. It just says that it is on a hidden partition and is attaching itself to the Master Boot Record. Alerts continue to popup from time to time telling me to take action to remove the threat but it's unable to remove it. Well, actually it tells me that I must restart in order to finish the cleanup but the virus is still there after the restart. I saw on the Microsoft help site where they said the hidden partition must be deleted in order to get rid of Trojan:Dos/Alureon.E, which is what I guess TDSSKkiller tried to do. Of course it may have just quarantined it as you mentioned. Microsoft also seemed to imply that they were still working on ways to fully combat this particular virus. This is just what I found with a quick search. I haven't really started researching it yet because I'm hoping our efforts here get rid of the problem. Here's my new aswMBR log: aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-03-03 10:32:11 —————————– 10:32:11.093 OS Version: Windows 5.1.2600 Service Pack 3 10:32:11.093 Number of processors: 2 586 0xE08 10:32:11.093 ComputerName: BASESTATION UserName: Russell 10:32:11.812 Initialize success 10:43:16.968 AVAST engine defs: 12030300 10:44:10.640 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 10:44:10.640 Disk 0 Vendor: TOSHIBA_MK1032GSX AS022D Size: 93958MB BusType: 3 10:44:10.640 Disk 0 MBR read successfully 10:44:10.640 Disk 0 MBR scan 10:44:10.734 Disk 0 unknown MBR code 10:44:10.734 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 10:44:10.781 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 89141 MB offset 96390 10:44:10.812 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 182675115 10:44:10.843 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 7 MB offset 192410505 10:44:10.921 Disk 0 scanning sectors +192426554 10:44:11.078 Disk 0 scanning C:\WINDOWS\system32\drivers 10:44:32.875 Service scanning 10:44:45.718 Service MpKsl9f72bccd c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{846F6D28-9D25-4F3C-836B-6B838BB554A8}\MpKsl9f72bccd.sys **LOCKED** 32 10:45:00.031 Modules scanning 10:45:05.359 Disk 0 trace - called modules: 10:45:05.375 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 10:45:05.390 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a716ab8] 10:45:05.390 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a748940] 10:45:05.953 AVAST engine scan C:\WINDOWS 10:45:24.078 AVAST engine scan C:\WINDOWS\system32 10:49:42.453 AVAST engine scan C:\WINDOWS\system32\drivers 10:50:06.984 AVAST engine scan C:\Documents and Settings\Russell 10:51:10.796 AVAST engine scan C:\Documents and Settings\All Users 10:51:47.796 Scan finished successfully 10:52:01.000 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Russell\Desktop\MBR.dat" 10:52:01.015 The log file has been saved successfully to "C:\Documents and Settings\Russell\Desktop\aswMBR.txt"
Hello JoshProto22

which is what I guess TDSSKkiller tried to do

According to the latest TDSSKiller log the partition has been removed….

Please run TDSSKiller again exactly as you did in post number 6 (making sure that Detect TDLFS File System is selected) and post the log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI