This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus still present after full system restore (Trojan:Dos/Alureon.E) [

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I just ran TDSSKIller again and it still doesn't see a threat but MSE is still bugging me about it. The MSE scan runs and it finds Trojan:Dos/Alureon.E somehow. I follow MSE's suggestion and select "Remove" from the pulldown menu and restart. Then the process starts over with MSE finding the threat again. I guess maybe now I have a MSE problem instead of a malware/virus problem. If that's the case do you think I should move to a different section of the forum? Just let me know what you think I should do. Thanks very much for your help. Here's my TDSSKiller log: 21:01:26.0421 3948 TDSS rootkit removing tool [removed] Mar 2 2012 09:40:07 21:01:26.0890 3948 ============================================================ 21:01:26.0890 3948 Current date / time: 2012/03/03 21:01:26.0890 21:01:26.0890 3948 SystemInfo: 21:01:26.0890 3948 21:01:26.0890 3948 OS Version: 5.1.2600 ServicePack: 3.0 21:01:26.0890 3948 Product type: Workstation 21:01:26.0890 3948 ComputerName: BASESTATION 21:01:26.0890 3948 UserName: Russell 21:01:26.0890 3948 Windows directory: C:\WINDOWS 21:01:26.0890 3948 System windows directory: C:\WINDOWS 21:01:26.0890 3948 Processor architecture: Intel x86 21:01:26.0890 3948 Number of processors: 2 21:01:26.0890 3948 Page size: 0x1000 21:01:26.0890 3948 Boot type: Normal boot 21:01:26.0890 3948 ============================================================ 21:01:28.0843 3948 Drive \Device\Harddisk0\DR0 - Size: 0x16F0649400 (91.76 Gb), SectorSize: 0x200, Cylinders: 0x2ECA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 21:01:28.0843 3948 \Device\Harddisk0\DR0: 21:01:28.0843 3948 MBR used 21:01:28.0843 3948 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0xAE1AF64 21:01:29.0156 3948 Initialize success 21:01:29.0156 3948 ============================================================ 21:01:37.0953 0676 ============================================================ 21:01:37.0953 0676 Scan started 21:01:37.0953 0676 Mode: Manual; TDLFS; 21:01:37.0953 0676 ============================================================ 21:01:38.0265 0676 Abiosdsk - ok 21:01:38.0312 0676 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 21:01:38.0312 0676 abp480n5 - ok 21:01:38.0359 0676 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 21:01:38.0359 0676 ACPI - ok 21:01:38.0406 0676 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 21:01:38.0406 0676 ACPIEC - ok 21:01:38.0421 0676 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 21:01:38.0421 0676 adpu160m - ok 21:01:38.0468 0676 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 21:01:38.0468 0676 aec - ok 21:01:38.0515 0676 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys 21:01:38.0562 0676 AegisP - ok 21:01:38.0625 0676 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 21:01:38.0656 0676 AFD - ok 21:01:38.0703 0676 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 21:01:38.0718 0676 agp440 - ok 21:01:38.0750 0676 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 21:01:38.0750 0676 agpCPQ - ok 21:01:38.0765 0676 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 21:01:38.0765 0676 Aha154x - ok 21:01:38.0796 0676 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 21:01:38.0796 0676 aic78u2 - ok 21:01:38.0812 0676 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 21:01:38.0812 0676 aic78xx - ok 21:01:38.0843 0676 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 21:01:38.0843 0676 AliIde - ok 21:01:38.0875 0676 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 21:01:38.0875 0676 alim1541 - ok 21:01:38.0890 0676 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 21:01:38.0890 0676 amdagp - ok 21:01:38.0906 0676 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 21:01:38.0906 0676 amsint - ok 21:01:38.0937 0676 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 21:01:38.0937 0676 APPDRV - ok 21:01:38.0953 0676 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 21:01:38.0953 0676 Arp1394 - ok 21:01:39.0000 0676 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 21:01:39.0000 0676 asc - ok 21:01:39.0015 0676 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 21:01:39.0015 0676 asc3350p - ok 21:01:39.0031 0676 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 21:01:39.0031 0676 asc3550 - ok 21:01:39.0062 0676 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 21:01:39.0062 0676 AsyncMac - ok 21:01:39.0093 0676 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 21:01:39.0093 0676 atapi - ok 21:01:39.0156 0676 Atdisk - ok 21:01:39.0234 0676 ati2mtag (bebeb471617782d138b6f92e7c3fab1c) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 21:01:39.0250 0676 ati2mtag - ok 21:01:39.0312 0676 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 21:01:39.0312 0676 Atmarpc - ok 21:01:39.0359 0676 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 21:01:39.0359 0676 audstub - ok 21:01:39.0406 0676 bcm4sbxp (c768c8a463d32c219ce291645a0621a4) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 21:01:39.0406 0676 bcm4sbxp - ok 21:01:39.0437 0676 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 21:01:39.0437 0676 Beep - ok 21:01:39.0468 0676 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 21:01:39.0484 0676 cbidf - ok 21:01:39.0484 0676 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 21:01:39.0484 0676 cbidf2k - ok 21:01:39.0500 0676 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 21:01:39.0500 0676 cd20xrnt - ok 21:01:39.0515 0676 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 21:01:39.0515 0676 Cdaudio - ok 21:01:39.0546 0676 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 21:01:39.0562 0676 Cdfs - ok 21:01:39.0578 0676 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 21:01:39.0578 0676 Cdrom - ok 21:01:39.0593 0676 Changer - ok 21:01:39.0625 0676 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 21:01:39.0625 0676 CmBatt - ok 21:01:39.0640 0676 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 21:01:39.0640 0676 CmdIde - ok 21:01:39.0640 0676 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 21:01:39.0656 0676 Compbatt - ok 21:01:39.0671 0676 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 21:01:39.0671 0676 Cpqarray - ok 21:01:39.0718 0676 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 21:01:39.0718 0676 dac2w2k - ok 21:01:39.0734 0676 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 21:01:39.0734 0676 dac960nt - ok 21:01:39.0750 0676 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 21:01:39.0765 0676 Disk - ok 21:01:39.0843 0676 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 21:01:39.0875 0676 dmboot - ok 21:01:39.0906 0676 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 21:01:39.0906 0676 dmio - ok 21:01:39.0953 0676 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 21:01:39.0953 0676 dmload - ok 21:01:39.0984 0676 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 21:01:39.0984 0676 DMusic - ok 21:01:40.0109 0676 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 21:01:40.0109 0676 dpti2o - ok 21:01:40.0125 0676 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 21:01:40.0125 0676 drmkaud - ok 21:01:40.0140 0676 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys 21:01:40.0171 0676 drvmcdb - ok 21:01:40.0187 0676 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys 21:01:40.0734 0676 drvnddm - ok 21:01:40.0765 0676 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 21:01:40.0765 0676 E100B - ok 21:01:40.0812 0676 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 21:01:40.0812 0676 Fastfat - ok 21:01:40.0859 0676 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 21:01:40.0859 0676 Fdc - ok 21:01:40.0875 0676 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 21:01:40.0890 0676 Fips - ok 21:01:40.0906 0676 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 21:01:40.0906 0676 Flpydisk - ok 21:01:40.0937 0676 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 21:01:40.0937 0676 FltMgr - ok 21:01:40.0968 0676 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 21:01:40.0968 0676 Fs_Rec - ok 21:01:40.0984 0676 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 21:01:41.0000 0676 Ftdisk - ok 21:01:41.0015 0676 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 21:01:41.0015 0676 Gpc - ok 21:01:41.0046 0676 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 21:01:41.0046 0676 HDAudBus - ok 21:01:41.0062 0676 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 21:01:41.0078 0676 HidUsb - ok 21:01:41.0078 0676 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 21:01:41.0093 0676 hpn - ok 21:01:41.0140 0676 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 21:01:41.0140 0676 HSFHWAZL - ok 21:01:41.0203 0676 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 21:01:41.0218 0676 HSF_DPV - ok 21:01:41.0281 0676 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 21:01:41.0281 0676 HTTP - ok 21:01:41.0343 0676 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 21:01:41.0343 0676 i2omgmt - ok 21:01:41.0359 0676 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 21:01:41.0359 0676 i2omp - ok 21:01:41.0453 0676 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 21:01:41.0453 0676 i8042prt - ok 21:01:41.0484 0676 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 21:01:41.0484 0676 Imapi - ok 21:01:41.0531 0676 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 21:01:41.0531 0676 ini910u - ok 21:01:41.0562 0676 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 21:01:41.0562 0676 IntelIde - ok 21:01:41.0593 0676 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 21:01:41.0593 0676 intelppm - ok 21:01:41.0640 0676 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 21:01:41.0640 0676 Ip6Fw - ok 21:01:41.0671 0676 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 21:01:41.0671 0676 IpFilterDriver - ok 21:01:41.0703 0676 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 21:01:41.0718 0676 IpInIp - ok 21:01:41.0750 0676 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 21:01:41.0750 0676 IpNat - ok 21:01:41.0765 0676 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 21:01:41.0765 0676 IPSec - ok 21:01:41.0796 0676 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 21:01:41.0796 0676 IRENUM - ok 21:01:41.0828 0676 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 21:01:41.0828 0676 isapnp - ok 21:01:41.0843 0676 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 21:01:41.0843 0676 Kbdclass - ok 21:01:41.0890 0676 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 21:01:41.0890 0676 kmixer - ok 21:01:41.0921 0676 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 21:01:41.0984 0676 KSecDD - ok 21:01:42.0015 0676 lbrtfdc - ok 21:01:42.0062 0676 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 21:01:42.0062 0676 mdmxsdk - ok 21:01:42.0109 0676 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys 21:01:42.0109 0676 MHNDRV - ok 21:01:42.0125 0676 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 21:01:42.0125 0676 mnmdd - ok 21:01:42.0156 0676 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 21:01:42.0156 0676 Modem - ok 21:01:42.0171 0676 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 21:01:42.0171 0676 Mouclass - ok 21:01:42.0218 0676 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 21:01:42.0218 0676 mouhid - ok 21:01:42.0250 0676 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 21:01:42.0250 0676 MountMgr - ok 21:01:42.0359 0676 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 21:01:42.0359 0676 MpFilter - ok 21:01:42.0468 0676 MpKslf4d71e66 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{846F6D28-9D25-4F3C-836B-6B838BB554A8}\MpKslf4d71e66.sys 21:01:42.0468 0676 MpKslf4d71e66 - ok 21:01:42.0484 0676 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 21:01:42.0484 0676 mraid35x - ok 21:01:42.0500 0676 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 21:01:42.0515 0676 MRxDAV - ok 21:01:42.0578 0676 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 21:01:42.0640 0676 MRxSmb - ok 21:01:42.0671 0676 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 21:01:42.0671 0676 Msfs - ok 21:01:42.0703 0676 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 21:01:42.0703 0676 MSKSSRV - ok 21:01:42.0718 0676 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 21:01:42.0718 0676 MSPCLOCK - ok 21:01:42.0734 0676 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 21:01:42.0734 0676 MSPQM - ok 21:01:42.0765 0676 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 21:01:42.0765 0676 mssmbios - ok 21:01:42.0812 0676 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 21:01:42.0859 0676 Mup - ok 21:01:42.0890 0676 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 21:01:42.0890 0676 NDIS - ok 21:01:42.0937 0676 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 21:01:42.0968 0676 NdisTapi - ok 21:01:42.0984 0676 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 21:01:42.0984 0676 Ndisuio - ok 21:01:43.0000 0676 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 21:01:43.0000 0676 NdisWan - ok 21:01:43.0031 0676 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 21:01:43.0078 0676 NDProxy - ok 21:01:43.0093 0676 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 21:01:43.0093 0676 NetBIOS - ok 21:01:43.0125 0676 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 21:01:43.0140 0676 NetBT - ok 21:01:43.0171 0676 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 21:01:43.0187 0676 NIC1394 - ok 21:01:43.0203 0676 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 21:01:43.0203 0676 Npfs - ok 21:01:43.0250 0676 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 21:01:43.0265 0676 Ntfs - ok 21:01:43.0375 0676 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 21:01:43.0375 0676 Null - ok 21:01:43.0500 0676 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 21:01:43.0546 0676 nv - ok 21:01:43.0562 0676 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 21:01:43.0578 0676 NwlnkFlt - ok 21:01:43.0578 0676 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 21:01:43.0593 0676 NwlnkFwd - ok 21:01:43.0609 0676 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 21:01:43.0609 0676 ohci1394 - ok 21:01:43.0656 0676 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys 21:01:43.0687 0676 omci - ok 21:01:43.0734 0676 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 21:01:43.0734 0676 Parport - ok 21:01:43.0750 0676 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 21:01:43.0750 0676 PartMgr - ok 21:01:43.0781 0676 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 21:01:43.0781 0676 ParVdm - ok 21:01:43.0812 0676 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 21:01:43.0828 0676 PCI - ok 21:01:43.0828 0676 PCIDump - ok 21:01:43.0843 0676 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 21:01:43.0843 0676 PCIIde - ok 21:01:43.0890 0676 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 21:01:43.0906 0676 Pcmcia - ok 21:01:43.0906 0676 PDCOMP - ok 21:01:43.0921 0676 PDFRAME - ok 21:01:43.0937 0676 PDRELI - ok 21:01:43.0953 0676 PDRFRAME - ok 21:01:43.0984 0676 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 21:01:43.0984 0676 perc2 - ok 21:01:44.0015 0676 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 21:01:44.0015 0676 perc2hib - ok 21:01:44.0062 0676 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 21:01:44.0062 0676 PptpMiniport - ok 21:01:44.0078 0676 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 21:01:44.0078 0676 PSched - ok 21:01:44.0093 0676 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 21:01:44.0093 0676 Ptilink - ok 21:01:44.0109 0676 PxHelp20 (86724469cd077901706854974cd13c3e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 21:01:44.0109 0676 PxHelp20 - ok 21:01:44.0125 0676 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 21:01:44.0125 0676 ql1080 - ok 21:01:44.0140 0676 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 21:01:44.0140 0676 Ql10wnt - ok 21:01:44.0187 0676 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 21:01:44.0187 0676 ql12160 - ok 21:01:44.0203 0676 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 21:01:44.0203 0676 ql1240 - ok 21:01:44.0218 0676 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 21:01:44.0218 0676 ql1280 - ok 21:01:44.0234 0676 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 21:01:44.0234 0676 RasAcd - ok 21:01:44.0265 0676 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 21:01:44.0265 0676 Rasl2tp - ok 21:01:44.0328 0676 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 21:01:44.0328 0676 RasPppoe - ok 21:01:44.0359 0676 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 21:01:44.0359 0676 Raspti - ok 21:01:44.0406 0676 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 21:01:44.0406 0676 Rdbss - ok 21:01:44.0453 0676 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 21:01:44.0453 0676 RDPCDD - ok 21:01:44.0484 0676 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 21:01:44.0484 0676 rdpdr - ok 21:01:44.0546 0676 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 21:01:44.0562 0676 RDPWD - ok 21:01:44.0578 0676 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 21:01:44.0578 0676 redbook - ok 21:01:44.0640 0676 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 21:01:44.0640 0676 rimmptsk - ok 21:01:44.0656 0676 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 21:01:44.0656 0676 rimsptsk - ok 21:01:44.0687 0676 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 21:01:44.0703 0676 rismxdp - ok 21:01:44.0765 0676 s24trans (2e4e912ce95f5ef4d4a5079f6ce367fc) C:\WINDOWS\system32\DRIVERS\s24trans.sys 21:01:44.0796 0676 s24trans - ok 21:01:44.0828 0676 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 21:01:44.0843 0676 sdbus - ok 21:01:44.0890 0676 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 21:01:44.0890 0676 Secdrv - ok 21:01:44.0921 0676 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 21:01:44.0921 0676 serenum - ok 21:01:44.0953 0676 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 21:01:44.0953 0676 Serial - ok 21:01:44.0984 0676 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 21:01:44.0984 0676 Sfloppy - ok 21:01:45.0000 0676 Simbad - ok 21:01:45.0031 0676 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 21:01:45.0031 0676 sisagp - ok 21:01:45.0062 0676 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 21:01:45.0062 0676 Sparrow - ok 21:01:45.0093 0676 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 21:01:45.0093 0676 splitter - ok 21:01:45.0125 0676 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 21:01:45.0125 0676 sr - ok 21:01:45.0187 0676 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 21:01:45.0250 0676 Srv - ok 21:01:45.0343 0676 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 21:01:45.0375 0676 sscdbhk5 - ok 21:01:45.0500 0676 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 21:01:45.0546 0676 ssrtln - ok 21:01:45.0625 0676 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys 21:01:45.0640 0676 STHDA - ok 21:01:45.0703 0676 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 21:01:45.0703 0676 swenum - ok 21:01:45.0750 0676 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 21:01:45.0750 0676 swmidi - ok 21:01:45.0781 0676 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 21:01:45.0781 0676 symc810 - ok 21:01:45.0796 0676 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 21:01:45.0796 0676 symc8xx - ok 21:01:45.0812 0676 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 21:01:45.0812 0676 sym_hi - ok 21:01:45.0828 0676 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 21:01:45.0843 0676 sym_u3 - ok 21:01:45.0890 0676 SynTP (35d5b3632e0bcebe27b391157de05996) C:\WINDOWS\system32\DRIVERS\SynTP.sys 21:01:45.0890 0676 SynTP - ok 21:01:45.0906 0676 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 21:01:45.0906 0676 sysaudio - ok 21:01:45.0984 0676 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 21:01:46.0031 0676 Tcpip - ok 21:01:46.0078 0676 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 21:01:46.0078 0676 TDPIPE - ok 21:01:46.0093 0676 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 21:01:46.0093 0676 TDTCP - ok 21:01:46.0109 0676 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 21:01:46.0109 0676 TermDD - ok 21:01:46.0140 0676 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys 21:01:46.0171 0676 tfsnboio - ok 21:01:46.0187 0676 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys 21:01:46.0218 0676 tfsncofs - ok 21:01:46.0234 0676 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys 21:01:46.0250 0676 tfsndrct - ok 21:01:46.0265 0676 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys 21:01:46.0296 0676 tfsndres - ok 21:01:46.0312 0676 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys 21:01:46.0375 0676 tfsnifs - ok 21:01:46.0390 0676 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys 21:01:46.0421 0676 tfsnopio - ok 21:01:46.0421 0676 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys 21:01:46.0437 0676 tfsnpool - ok 21:01:46.0453 0676 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys 21:01:46.0500 0676 tfsnudf - ok 21:01:46.0531 0676 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys 21:01:46.0578 0676 tfsnudfa - ok 21:01:46.0625 0676 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 21:01:46.0625 0676 TosIde - ok 21:01:46.0671 0676 Tosrfbd (37a7d0d105110aafac6e982a2c49b8b6) C:\WINDOWS\system32\Drivers\tosrfbd.sys 21:01:46.0687 0676 Tosrfbd - ok 21:01:46.0718 0676 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\drivers\Tosrfcom.sys 21:01:46.0765 0676 Tosrfcom - ok 21:01:46.0859 0676 Tosrfhid (f4e4795528d17ff8d1d6d98ebbb92655) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys 21:01:46.0906 0676 Tosrfhid - ok 21:01:46.0921 0676 Tosrfusb (1d19323d5bc7309d9df65dad5635005c) C:\WINDOWS\system32\Drivers\tosrfusb.sys 21:01:46.0953 0676 Tosrfusb - ok 21:01:46.0984 0676 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 21:01:47.0000 0676 Udfs - ok 21:01:47.0031 0676 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 21:01:47.0046 0676 ultra - ok 21:01:47.0093 0676 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 21:01:47.0109 0676 Update - ok 21:01:47.0140 0676 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 21:01:47.0140 0676 usbccgp - ok 21:01:47.0156 0676 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 21:01:47.0156 0676 usbehci - ok 21:01:47.0171 0676 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 21:01:47.0171 0676 usbhub - ok 21:01:47.0218 0676 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 21:01:47.0250 0676 USBSTOR - ok 21:01:47.0265 0676 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 21:01:47.0265 0676 usbuhci - ok 21:01:47.0281 0676 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 21:01:47.0281 0676 VgaSave - ok 21:01:47.0312 0676 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 21:01:47.0312 0676 viaagp - ok 21:01:47.0343 0676 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 21:01:47.0343 0676 ViaIde - ok 21:01:47.0390 0676 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 21:01:47.0390 0676 VolSnap - ok 21:01:47.0515 0676 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys 21:01:47.0531 0676 w39n51 - ok 21:01:47.0562 0676 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 21:01:47.0562 0676 Wanarp - ok 21:01:47.0656 0676 wanatw - ok 21:01:47.0671 0676 WDICA - ok 21:01:47.0703 0676 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 21:01:47.0703 0676 wdmaud - ok 21:01:47.0781 0676 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 21:01:47.0796 0676 winachsf - ok 21:01:47.0859 0676 MBR (0x1B8) (2ba3e330828ad649a40ef55575d98871) \Device\Harddisk0\DR0 21:01:47.0968 0676 \Device\Harddisk0\DR0 - ok 21:01:48.0000 0676 Boot (0x1200) (64e75b0b5a6b9362f974df70553b240c) \Device\Harddisk0\DR0\Partition0 21:01:48.0000 0676 \Device\Harddisk0\DR0\Partition0 - ok 21:01:48.0000 0676 ============================================================ 21:01:48.0000 0676 Scan finished 21:01:48.0000 0676 ============================================================ 21:01:48.0015 0572 Detected object count: 0 21:01:48.0015 0572 Actual detected object count: 0
Hello JoshProto22

Before we go any further I think it would be prudent to take a closer look at the system MBR.

When you were being helped before you created an MBR dump from outside of the normal windows loading environment.

I would like you to perform the same procedure again and attach the MBR dump details to your reply.

Please work through the steps below:

  • xPUD

    We will need a USB stick and access to an uninfected machine.

    We need to prepare the USB stick. It is not absolutely essential that it is formatted, but it may help if it is:

  • Insert your USB drive ino the uninfected machine.
  • Click on Start > My Computer > right click your USB drive > choose Format > Quick format.

Next

  • Please use Firefox to download each required tool (Internet Explorer can sometimes encounter problems).
  • Download both http://sourceforge.net/projects/unetbootin…87.exe/download and http://noahdfear.net/downloads/bootable/xPUD/xpud-0.9.2.iso to the desktop of the uninfected machine.
  • Make sure you have the formatted USB stick in the uninfected system.
  • Double click on the unetbootin-xpud-windows-387.exe that you just downloaded.
  • Press Run and then OK.
  • Select the DiskImage option then click the browse button located on the right side of the textbox field.
  • Browse to and select the xpud-0.9.2.iso file you downloaded.
  • Verify the correct drive letter is selected for your USB device then click OK.
  • It will install a little bootable OS on your USB device
  • After it has completed do not choose to reboot the clean computer, simply close the installer.

Next


Next

  • Take the USB to the infected computer and boot with it.
  • The computer must be set to boot from the USB (as soon as BIOS is loaded tap F12 and choose to boot from the USB drive).
  • A Welcome to xPUD screen will appear.
  • Press File.
  • Expand mnt.
  • sda1,2…usually corresponds to your HDD.
  • sdb1 is likely your USB drive.
  • Click on the folder that represents your USB drive (sdb1 ?).
  • Confirm that you see dumpit that you downloaded there.
  • Double click on dumpit.
  • Once completed, a file called mbr.zip will be saved to the USB drive.
  • Take the USB drive back to the uninfected system and attach the mbr.zip in your next reply.
Hi, Sorry for the delay in getting you this mbr.zip file. I had to wait until I had access to a clean computer. Just me know whatever else you need. Thanks again for your help!

Attachments:

Hello JoshProto22

Thank you for the mbr dump.

Lets proceed as follows:

  • tdl_fix.sh


  • Download tdl_fix.sh and save it to the xPUD flash drive.
  • Boot into xPUD then click the File tab.
  • Press File
  • Expand mnt
  • Click on the folder under mnt that represents your USB drive (sdb1 ?)
  • You should see the tdl_fix.sh file in the main window.
  • Select Tool from the Menu
  • Choose Open Terminal
  • Type bash tdl_fix.sh -delete then press Enter.
  • ** Make sure to leave a space to either side of tdl_fix.sh in the command.
  • You should be notified of a hidden partition found and prompted to delete it.
  • Type y then press Enter.
  • The script will complete and prompt you to reboot the computer.
  • Close the Terminal window and restart back into Windows.
  • Post the contents of the tdl_delete.txt file that was created on your flash drive.

Note - in the event there is a problem booting the computer normally after running the script, run the tdl_fix.sh script again using the following command.

bash tdl_fix.sh -restore

Make sure to leave a space to either side of tdl_fix.sh in the command.
This will prompt you to use the file tdl_mbr_sda.bin on drive sda.
Ok the procedure then restart when complete.
Hi JonTom, Just letting you know I'm still here. I had to go out of town for a few days. It will be Monday before I can get back to our removal project. Thanks for your help and continued patience. :thumbup:
Hi JonTom,

I'm back with the results of the tdl_fix.sh process. I'll post the contents of the .txt document below. *I must say I do see a good sign that things are getting better. MSE hasn't prompted me with any sort of warning message since I rebooted. To me, that's real progress. I'm hoping the hidden partition is truly wiped out. Let me know whatever else you think I need to do.


Here's the tdl_delete.txt contents:

2012-03-12-23:06:57

using tdl_delete_sda.bin

Model: ATA TOSHIBA MK1032GS (scsi)
Disk /dev/sda: 98.5GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 49.4MB 49.3MB primary fat16
2 49.4MB 93.5GB 93.5GB primary ntfs boot
3 93.5GB 98.5GB 4985MB primary fat32
4 98.5GB 98.5GB 8217kB primary ntfs hidden

Hidden partition found on sda
sda4 is hidden
Deleting partition 4 on drive sda

Model: ATA TOSHIBA MK1032GS (scsi)
Disk /dev/sda: 98.5GB
Sector size (logical/physical): 512B/512B
Partition Table: msdos

Number Start End Size Type File system Flags
1 32.3kB 49.4MB 49.3MB primary fat16
2 49.4MB 93.5GB 93.5GB primary ntfs boot
3 93.5GB 98.5GB 4985MB primary fat32

No hidden partition on sdb
Hello JoshProto22

Thank you for the log.

To me, that's real progress

Me too :)


I would like to see a new aswMBR scan log.

Please scan the machine with aswMBR as you did before and post the log in your next reply.

I would also like to see a log from the following tool:


  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Hi JonTom,

I just completed the next couple of steps that you recommended. Everything seemed to work OK. Last time someone asked me to run Combofix, my computer crashed and wouldn't reboot.

Here are the aswMBR and the combofix logs:

aswMBR:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-14 04:24:37
—————————–
04:24:37.171 OS Version: Windows 5.1.2600 Service Pack 3
04:24:37.171 Number of processors: 2 586 0xE08
04:24:37.171 ComputerName: BASESTATION UserName: Russell
04:24:37.859 Initialize success
04:24:44.015 AVAST engine defs: 12031301
04:24:49.984 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
04:24:49.984 Disk 0 Vendor: TOSHIBA_MK1032GSX AS022D Size: 93958MB BusType: 3
04:24:50.031 Disk 0 MBR read successfully
04:24:50.031 Disk 0 MBR scan
04:24:50.062 Disk 0 unknown MBR code
04:24:50.078 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63
04:24:50.093 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 89141 MB offset 96390
04:24:50.125 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 182675115
04:24:50.140 Disk 0 scanning sectors +192410505
04:24:50.203 Disk 0 scanning C:\WINDOWS\system32\drivers
04:25:13.718 Service scanning
04:25:31.734 Modules scanning
04:25:51.250 Disk 0 trace - called modules:
04:25:51.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
04:25:51.265 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a71cab8]
04:25:51.265 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a722940]
04:25:51.968 AVAST engine scan C:\WINDOWS
04:26:12.484 AVAST engine scan C:\WINDOWS\system32
04:30:43.859 AVAST engine scan C:\WINDOWS\system32\drivers
04:31:18.765 AVAST engine scan C:\Documents and Settings\Russell
05:20:07.484 AVAST engine scan C:\Documents and Settings\All Users
05:22:28.562 Scan finished successfully
05:55:28.906 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Russell\Desktop\MBR.dat"
05:55:28.921 The log file has been saved successfully to "C:\Documents and Settings\Russell\Desktop\aswMBR.txt"


combofix log:

ComboFix 12-03-13.01 - Russell 03/14/2012 6:26.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1375 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\EventSystem.log
c:\windows\system32\SET106.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-02-14 to 2012-03-14 )))))))))))))))))))))))))))))))
.
.
2012-03-14 09:56 . 2012-02-08 03:03 6552120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F69E4CE-C7E1-4DAF-ADF6-EE5543B98C44}\mpengine.dll
2012-03-12 12:41 . 2012-03-12 12:41 ——– d—–w- c:\windows\Sun
2012-03-12 02:35 . 2012-03-13 06:26 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
2012-03-12 02:34 . 2008-11-07 22:55 16928 ——w- c:\windows\system32\spmsgXP_2k3.dll
2012-03-12 02:32 . 2011-09-02 06:30 12184 —-a-w- c:\windows\system32\drivers\LBeepKE.sys
2012-03-12 02:32 . 2012-03-12 02:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2012-03-12 02:32 . 2012-03-12 02:32 ——– d—–w- c:\program files\Logitech
2012-03-12 02:31 . 2012-03-12 02:33 ——– d—–w- c:\program files\Common Files\Logishrd
2012-03-11 05:24 . 2012-03-11 05:24 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2012-03-10 12:01 . 2008-04-14 05:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2012-03-10 12:01 . 2008-04-14 05:15 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2012-03-10 12:00 . 2012-03-10 12:00 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2012-03-10 12:00 . 2012-03-10 12:00 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2012-03-10 12:00 . 2012-03-10 12:00 ——– d—–w- c:\program files\ScanSoft
2012-03-10 11:58 . 2012-03-10 11:58 ——– d—–w- c:\program files\Common Files\CANON
2012-03-10 11:57 . 1998-10-29 21:45 306688 —-a-w- c:\windows\IsUninst.exe
2012-03-10 11:57 . 2012-03-10 11:57 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2012-03-10 11:57 . 2006-09-13 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP87.DLL
2012-03-10 11:57 . 2006-09-13 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD87.DLL
2012-03-10 11:57 . 2006-09-13 05:00 197632 —-a-w- c:\windows\system32\CNMLM87.DLL
2012-03-10 11:57 . 2012-03-10 11:57 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2012-03-10 11:56 . 2006-06-29 14:29 106496 —-a-w- c:\windows\system32\cnco600.dll
2012-03-10 11:56 . 2006-07-20 15:51 1298432 —-a-w- c:\windows\system32\CNCC600.DLL
2012-03-10 11:56 . 2006-07-20 15:51 57344 —-a-w- c:\windows\system32\CNCI600.DLL
2012-03-10 11:56 . 2006-05-26 10:54 135168 —-a-w- c:\windows\system32\CNCL600.DLL
2012-03-10 11:55 . 2012-03-10 12:02 ——– d—–w- c:\program files\Canon
2012-03-10 11:53 . 2008-04-14 05:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2012-03-10 11:53 . 2008-04-14 05:17 25856 —-a-w- c:\windows\system32\dllcache\usbprint.sys
2012-03-10 01:32 . 2012-03-10 01:32 4431872 —-a-w- c:\windows\system32\GPhotos.scr
2012-03-06 01:09 . 2012-03-06 01:09 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2012-03-04 06:47 . 2012-03-10 21:20 ——– d—–w- c:\program files\VideoLAN
2012-03-04 06:08 . 2008-04-14 10:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2012-03-04 06:05 . 2012-03-04 06:05 ——– d—–w- c:\program files\Windows Media Connect 2
2012-03-04 06:04 . 2012-03-04 06:04 ——– d—–w- c:\windows\system32\drivers\UMDF
2012-03-04 06:04 . 2012-03-04 06:04 ——– d—–w- c:\windows\system32\LogFiles
2012-03-03 19:36 . 2008-04-14 05:15 26368 —-a-w- c:\windows\system32\dllcache\usbstor.sys
2012-03-03 15:30 . 2012-03-03 15:30 1409 —-a-w- c:\windows\QTFont.for
2012-03-03 07:42 . 2012-03-03 07:42 ——– d—–w- C:\TDSSKiller_Quarantine
2012-03-02 10:21 . 2012-03-02 10:21 ——– d—–w- C:\_OTL
2012-02-29 09:18 . 2012-02-29 09:18 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2012-02-27 09:07 . 2012-02-27 09:07 ——– d—–w- c:\windows\system32\XPSViewer
2012-02-27 09:07 . 2012-02-27 09:07 ——– d—–w- c:\program files\MSBuild
2012-02-27 09:07 . 2012-02-27 09:07 ——– d—–w- c:\program files\Reference Assemblies
2012-02-27 09:06 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2012-02-27 09:06 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2012-02-27 09:06 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2012-02-27 09:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2012-02-27 09:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2012-02-27 09:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2012-02-27 09:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2012-02-27 09:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2012-02-27 09:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2012-02-27 09:06 . 2012-02-27 09:06 ——– d—–w- C:\59e129738cb8df114e94
2012-02-27 08:01 . 2012-02-27 08:01 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2012-02-26 20:22 . 2012-02-26 20:24 ——– dc-h–w- c:\windows\ie8
2012-02-26 10:54 . 2012-02-26 10:54 ——– d—–w- c:\program files\Google
2012-02-26 05:55 . 2012-02-26 05:55 ——– d—–w- c:\program files\Common Files\Adobe
2012-02-26 04:31 . 2012-02-26 10:57 3766 –sha-w- c:\windows\system32\KGyGaAvL.sys
2012-02-26 04:31 . 2012-02-26 10:57 88 –sh–r- c:\windows\system32\CCA7228038.sys
2012-02-26 03:05 . 2012-02-08 03:03 6552120 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-02-26 02:59 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2012-02-23 08:32 . 2011-08-16 10:45 6144 ——w- c:\windows\system32\dllcache\iecompat.dll
2012-02-23 08:32 . 2011-12-18 19:46 11082240 ——w- c:\windows\system32\dllcache\ieframe.dll
2012-02-23 08:32 . 2011-12-17 19:46 602112 ——w- c:\windows\system32\dllcache\msfeeds.dll
2012-02-23 08:32 . 2011-12-17 19:46 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-02-23 08:32 . 2011-12-17 19:46 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2012-02-23 08:32 . 2011-12-17 19:46 2000384 ——w- c:\windows\system32\dllcache\iertutil.dll
2012-02-23 08:32 . 2011-12-17 19:46 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2012-02-23 08:32 . 2011-12-17 19:46 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2012-02-23 08:13 . 2012-02-23 08:13 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-23 08:03 . 2012-02-23 08:03 ——– d—–w- c:\program files\MSXML 4.0
2012-02-23 07:10 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\dllcache\bthport.sys
2012-02-23 07:08 . 2010-09-18 06:53 954368 ——w- c:\windows\system32\dllcache\mfc40.dll
2012-02-23 07:08 . 2010-09-18 06:53 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll
2012-02-23 07:07 . 2011-07-15 13:29 456320 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2012-02-23 07:07 . 2010-08-23 16:12 617472 ——w- c:\windows\system32\dllcache\comctl32.dll
2012-02-23 07:05 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2012-02-23 07:05 . 2010-08-27 08:02 119808 ——w- c:\windows\system32\dllcache\t2embed.dll
2012-02-23 07:05 . 2009-10-15 16:28 81920 ——w- c:\windows\system32\dllcache\fontsub.dll
2012-02-23 07:04 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2012-02-23 07:03 . 2009-03-06 14:22 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2012-02-23 07:03 . 2009-02-09 12:10 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2012-02-23 07:03 . 2009-02-06 10:39 35328 ——w- c:\windows\system32\dllcache\sc.exe
2012-02-23 07:03 . 2009-02-09 12:10 473600 ——w- c:\windows\system32\dllcache\fastprox.dll
2012-02-23 07:03 . 2009-02-09 12:10 453120 ——w- c:\windows\system32\dllcache\wmiprvsd.dll
2012-02-23 07:03 . 2009-02-06 11:11 110592 ——w- c:\windows\system32\dllcache\services.exe
2012-02-23 07:03 . 2009-02-06 10:10 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2012-02-23 07:03 . 2009-02-09 12:10 617472 ——w- c:\windows\system32\dllcache\advapi32.dll
2012-02-23 07:01 . 2009-06-21 21:44 153088 ——w- c:\windows\system32\dllcache\triedit.dll
2012-02-23 06:58 . 2008-05-08 14:02 203136 ——w- c:\windows\system32\dllcache\rmcast.sys
2012-02-23 06:58 . 2012-01-09 16:20 139784 ——w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-23 06:58 . 2010-06-14 07:41 1172480 ——w- c:\windows\system32\dllcache\msxml3.dll
2012-02-23 06:57 . 2011-12-17 19:46 66560 ——w- c:\windows\system32\dllcache\mshtmled.dll
2012-02-23 06:57 . 2011-12-17 19:46 611840 ——w- c:\windows\system32\dllcache\mstime.dll
2012-02-23 06:57 . 2011-12-17 19:46 184320 ——w- c:\windows\system32\dllcache\iepeers.dll
2012-02-23 06:57 . 2011-12-17 19:46 105984 ——w- c:\windows\system32\dllcache\url.dll
2012-02-23 06:57 . 2011-12-19 08:53 1025024 ——w- c:\windows\system32\dllcache\browseui.dll
2012-02-23 06:57 . 2008-05-01 14:33 331776 ——w- c:\windows\system32\dllcache\msadce.dll
2012-02-23 06:55 . 2010-06-18 13:36 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2012-02-23 06:53 . 2008-10-15 16:34 337408 ——w- c:\windows\system32\dllcache\netapi32.dll
2012-02-23 06:53 . 2011-04-30 03:01 758784 —-a-w- c:\windows\system32\dllcache\vgx.dll
2012-02-23 06:52 . 2010-12-09 15:15 718336 ——w- c:\windows\system32\dllcache\ntdll.dll
2012-02-23 06:51 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-23 06:51 . 2010-07-12 12:55 218112 ——w- c:\windows\system32\dllcache\wordpad.exe
2012-02-23 06:50 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2012-02-23 06:50 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\dllcache\iacenc.dll
2012-02-23 06:47 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2012-02-23 06:47 . 2011-02-17 12:32 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2012-02-23 06:47 . 2010-08-16 08:45 590848 ——w- c:\windows\system32\dllcache\rpcrt4.dll
2012-02-23 06:46 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2012-02-23 06:46 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2012-02-23 06:41 . 2012-02-23 06:41 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-02-23 06:41 . 2012-02-23 06:41 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-02-23 05:56 . 2012-01-31 12:44 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-02-23 05:49 . 2012-02-23 05:50 ——– d—–w- c:\program files\Microsoft Security Client
2012-02-23 05:46 . 2009-10-13 10:30 270336 ——w- c:\windows\system32\dllcache\oakley.dll
2012-02-23 05:46 . 2011-12-17 19:46 916992 ——w- c:\windows\system32\dllcache\wininet.dll
2012-02-23 05:46 . 2011-12-17 19:46 1212416 ——w- c:\windows\system32\dllcache\urlmon.dll
2012-02-23 05:46 . 2011-12-19 08:53 1510400 ——w- c:\windows\system32\dllcache\shdocvw.dll
2012-02-23 05:46 . 2011-12-17 19:46 5979136 ——w- c:\windows\system32\dllcache\mshtml.dll
2012-02-23 05:45 . 2011-11-03 15:28 1292288 ——w- c:\windows\system32\dllcache\quartz.dll
2012-02-23 05:45 . 2009-12-16 18:43 343040 ——w- c:\windows\system32\dllcache\mspaint.exe
2012-02-23 05:44 . 2010-04-06 09:52 2462720 ——w- c:\windows\system32\dllcache\WMVCore.dll
2012-02-23 05:43 . 2009-08-07 00:24 21728 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-02-23 05:43 . 2009-08-07 00:24 44768 —-a-w- c:\windows\system32\wups2.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-03 09:22 . 2005-08-16 09:18 1860096 —-a-w- c:\windows\system32\win32k.sys
2012-01-09 16:20 . 2005-08-16 09:37 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-12-17 19:46 . 2005-08-16 09:18 916992 —-a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2005-08-16 09:18 43520 ——w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2005-08-16 09:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2005-08-16 09:18 385024 ——w- c:\windows\system32\html.iec
2012-02-16 14:40 . 2012-02-23 06:22 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-06 839680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-17 1197648]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Russell\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\Logishrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-22 24576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2011-09-27 19:03 66328 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [3/11/2012 10:32 PM 12184]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\documents and settings\Russell\Application Data\Mozilla\Firefox\Profiles\5nb0ik0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/?fr=yfp-t-403
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-14 06:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2012-03-14 06:31:58
ComboFix-quarantined-files.txt 2012-03-14 10:31
.
Pre-Run: 73,508,327,424 bytes free
Post-Run: 73,686,052,864 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C8BA13825A88B8EC569BC6458DE28AE4
Helo JoshProto22

Thank you for the logs.

Did you used to have McAfee installed on this machine? If you no longer use it let me know and I will provide a removal tool for the leftovers.

aswMBR confirms the absence of the malware partition :)

Lets run a couple of general scans to check for anything that may have been missed.


  • Please un-instal Java 2 Runtime Environment, SE v1.4.2_03


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "Java 2 Runtime Environment, SE v1.4.2_03" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Double click the TFC icon to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please run the following scan


    • Note:Internet Explorer is preferred for this scan, although it will run with other browsers.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM log, the ESET log and a new OTL scan log in your next reply.
Hi JonTom,

I've completed all of the last set of steps you wanted me to do. I'll post the logs below. The ESET log was interesting in particular. Just let me know what you think of them and what you think I need to do next. Thanks!

Malwarebytes log:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.15.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Russell :: BASESTATION [administrator]

3/15/2012 3:19:16 AM
mbam-log-2012-03-15 (03-19-16).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191418
Time elapsed: 5 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

ESET Scan log:

C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0001\tsk0006.dta Win64/Olmasco.W trojan
C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0001\tsk0007.dta a variant of Win32/Olmasco.O trojan
C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0001\tsk0010.dta Win64/Olmasco.R trojan
C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0001\tsk0011.dta a variant of Win32/Olmasco.Q trojan
Hello JoshProto22

Thank you for the logs.

MBAM looks good and the ESET scan is flagging items that have been quarantined by TDSSKiller (nothing to worry about).

  • Please open OTL


  • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    :Files
    C:\TDSSKiller_Quarantine
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]
  • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
  • Allow the program to run unhindered.
  • Your machine will re-start itself. This is normal.
  • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

Please post the OTL log that is created after running the above fix in your next reply, along with a new OTL scan log.
OK, Here are the OTL scan results. Seems to be looking pretty good. All processes killed ========== OTL ========== No active process named explorer.exe was found! ========== FILES ========== C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0001 folder moved successfully. C:\TDSSKiller_Quarantine\03.03.2012_02.40.31\tdlfs0000 folder moved successfully. C:\TDSSKiller_Quarantine\03.03.2012_02.40.31 folder moved successfully. C:\TDSSKiller_Quarantine folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 12606 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Russell ->Temp folder emptied: 710508 bytes ->Temporary Internet Files folder emptied: 7713160 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 45413192 bytes ->Flash cache emptied: 470 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 29844 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 25766700 bytes Total Files Cleaned = 76.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User User: LocalService User: NetworkService User: Russell ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.37.1 log created on 03162012_042307 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi JonTom,

Here are the new OTL scan results like you wanted. Just let me know whatever else you think I need to do. I feel like my computer must be getting close to being clean. Again, thanks very much for all of your help.

OTL logfile created on: 3/16/2012 11:21:00 AM - Run 2
OTL by OldTimer - Version 3.2.37.1 Folder = C:\Documents and Settings\Russell\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 76.49% Memory free
3.85 Gb Paging File | 3.50 Gb Available in Paging File | 90.93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 87.05 Gb Total Space | 69.17 Gb Free Space | 79.46% Space Free | Partition Type: NTFS

Computer Name: BASESTATION | User Name: Russell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Russell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
PRC - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Modules (No Company Name) ==========

MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_c3f6dbb1\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_273780c2\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_4314e828\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_41d007e8\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_43a77e74\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll ()
MOD - c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll ()
MOD - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
MOD - C:\WINDOWS\system32\TosBtHcrpAPI.dll ()
MOD - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (Bluetooth Hid Switch Service) – C:\Program Files\BlueTooth\HidSwitchService\HidSw.exe (Cambridge Silicon Radio)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) WAN Miniport (ATW) – system32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\Russell\LOCALS~1\Temp\catchme.sys File not found
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/?fr=yfp-t-403"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/23 02:22:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/02/23 02:23:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Extensions
[2012/03/16 03:21:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\5nb0ik0f.default\extensions
[2012/03/11 22:38:40 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Documents and Settings\Russell\Application Data\Mozilla\Firefox\Profiles\5nb0ik0f.default\extensions\[removed]
[2012/02/23 02:41:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/23 02:41:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\RUSSELL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5NB0IK0F.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2012/02/23 02:41:28 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/16 10:40:42 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/16 06:42:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/16 06:42:53 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/03/14 06:30:08 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [ShowLOMControl] Reg Error: Invalid data type. File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()
O4 - Startup: C:\Documents and Settings\Russell\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/windows…b?1329975759726 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1329978404062 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BFFF9B8-868B-4C05-9A5A-613F6B79DD18}: DhcpNameServer = 75.75.75.75 75.75.76.76
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Russell\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Russell\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/16 11:19:46 | 000,594,944 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/03/16 03:21:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop\DL
[2012/03/16 02:34:33 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2012/03/16 02:34:26 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2012/03/16 02:31:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop\1654754.aspx_files
[2012/03/15 03:48:54 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/03/15 03:17:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Malwarebytes
[2012/03/15 03:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/03/15 03:17:39 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/03/15 03:17:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/15 03:15:48 | 009,502,424 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Russell\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/15 02:56:46 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/03/15 02:48:56 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\TFC.exe
[2012/03/15 02:48:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2012/03/14 06:25:03 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/03/14 06:23:54 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/03/14 06:23:54 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/03/14 06:23:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/03/14 06:23:54 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/03/14 06:23:48 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/03/14 06:23:42 | 000,000,000 | —D | C] – C:\Qoobox
[2012/03/14 06:23:39 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Administrative Tools
[2012/03/14 02:25:02 | 004,434,769 | R— | C] (Swearware) – C:\Documents and Settings\Russell\Desktop\ComboFix.exe
[2012/03/14 02:23:56 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Russell\Desktop\aswMBR.exe
[2012/03/12 08:41:39 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2012/03/11 22:35:07 | 000,016,400 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LNonPnP.sys
[2012/03/11 22:34:57 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsgXP_2k3.dll
[2012/03/11 22:33:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Leadertech
[2012/03/11 22:32:50 | 000,012,184 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LBeepKE.sys
[2012/03/11 22:32:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\LogiShrd
[2012/03/11 22:32:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Logitech
[2012/03/11 22:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2012/03/11 22:32:23 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2012/03/11 22:31:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Logishrd
[2012/03/11 22:29:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Logitech
[2012/03/11 22:29:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Logishrd
[2012/03/11 22:28:43 | 002,414,672 | —- | C] (Logitech Inc.) – C:\Documents and Settings\Russell\Desktop\setpoint632_smart.exe
[2012/03/11 01:24:58 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2012/03/10 12:17:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Scansoft
[2012/03/10 08:02:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP600 User Registration
[2012/03/10 08:01:31 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2012/03/10 08:01:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\ScanSoft
[2012/03/10 08:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4.0
[2012/03/10 08:00:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2012/03/10 08:00:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2012/03/10 08:00:13 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2012/03/10 07:58:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2012/03/10 07:57:53 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUninst.exe
[2012/03/10 07:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2012/03/10 07:57:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP600 Manual
[2012/03/10 07:57:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/03/10 07:57:03 | 000,197,632 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM87.DLL
[2012/03/10 07:57:01 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2012/03/10 07:57:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP600
[2012/03/10 07:56:56 | 000,106,496 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\cnco600.dll
[2012/03/10 07:56:55 | 001,298,432 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNCC600.DLL
[2012/03/10 07:56:55 | 000,135,168 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNCL600.DLL
[2012/03/10 07:56:55 | 000,057,344 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNCI600.DLL
[2012/03/10 07:56:42 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2012/03/10 07:55:36 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012/03/10 07:53:36 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2012/03/09 21:32:32 | 004,431,872 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/03/05 21:09:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/03/04 02:47:19 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2012/03/04 02:06:12 | 000,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/03/04 02:05:51 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Connect 2
[2012/03/04 02:04:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2012/03/04 02:04:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2012/03/03 15:48:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Identities
[2012/03/03 15:42:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop\Car Dump
[2012/03/03 15:36:33 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2012/03/02 06:21:18 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/29 11:46:53 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/29 05:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2012/02/28 06:09:08 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Videos
[2012/02/27 05:07:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2012/02/27 05:07:17 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2012/02/27 05:07:04 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2012/02/27 05:06:36 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2012/02/27 05:06:36 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2012/02/27 05:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2012/02/27 05:06:35 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2012/02/27 05:06:35 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2012/02/27 05:06:35 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2012/02/27 05:06:34 | 000,000,000 | —D | C] – C:\59e129738cb8df114e94
[2012/02/26 16:30:41 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IECompatCache
[2012/02/26 16:29:09 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\PrivacIE
[2012/02/26 16:22:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/02/26 16:10:51 | 016,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 06:55:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2012/02/26 06:54:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Google
[2012/02/26 06:54:36 | 000,000,000 | —D | C] – C:\Program Files\Google
[2012/02/26 06:52:02 | 014,886,760 | —- | C] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/26 01:56:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\AdobeUM
[2012/02/26 01:56:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Adobe
[2012/02/26 01:56:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\My eBooks
[2012/02/26 01:55:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2012/02/26 00:32:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel Photo Album
[2012/02/26 00:32:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Corel Photo Album
[2012/02/25 22:59:03 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2012/02/25 22:59:02 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/02/25 22:52:18 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\IETldCache
[2012/02/23 04:32:16 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2012/02/23 04:32:02 | 011,082,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2012/02/23 04:32:02 | 002,000,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2012/02/23 04:32:02 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/02/23 04:32:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/02/23 04:32:01 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/02/23 04:31:47 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2012/02/23 04:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Macromedia
[2012/02/23 04:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Adobe
[2012/02/23 04:13:30 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 04:11:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\My Documents\Downloads
[2012/02/23 04:03:12 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2012/02/23 03:10:03 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2012/02/23 03:08:19 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2012/02/23 03:08:19 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2012/02/23 03:07:38 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2012/02/23 03:07:24 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2012/02/23 03:05:55 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2012/02/23 03:05:18 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2012/02/23 03:05:18 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2012/02/23 03:04:03 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2012/02/23 02:58:54 | 000,203,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rmcast.sys
[2012/02/23 02:58:43 | 000,139,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012/02/23 02:58:04 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2012/02/23 02:57:58 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2012/02/23 02:57:58 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2012/02/23 02:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2012/02/23 02:57:58 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2012/02/23 02:57:57 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2012/02/23 02:57:56 | 001,025,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browseui.dll
[2012/02/23 02:57:33 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2012/02/23 02:55:15 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2012/02/23 02:53:40 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2012/02/23 02:53:30 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vgx.dll
[2012/02/23 02:51:46 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012/02/23 02:47:48 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2012/02/23 02:47:23 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcrt4.dll
[2012/02/23 02:46:48 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012/02/23 02:46:43 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2012/02/23 02:42:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2012/02/23 02:42:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/02/23 02:41:41 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 02:41:41 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 02:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 02:41:41 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 02:41:41 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 02:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Mozilla
[2012/02/23 02:22:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Mozilla
[2012/02/23 02:22:32 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/02/23 01:56:53 | 000,237,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/02/23 01:49:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/02/23 01:46:04 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oakley.dll
[2012/02/23 01:46:03 | 001,212,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2012/02/23 01:46:03 | 000,916,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2012/02/23 01:46:02 | 001,510,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shdocvw.dll
[2012/02/23 01:46:01 | 005,979,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2012/02/23 01:45:28 | 000,343,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mspaint.exe
[2012/02/23 01:44:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2012/02/23 01:44:45 | 002,462,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\WMVCore.dll
[2012/02/23 01:43:10 | 000,044,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/02/23 01:43:10 | 000,021,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/02/23 01:43:09 | 000,015,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/02/23 01:43:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2012/02/23 01:35:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\UserData
[2012/02/23 00:38:14 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2012/02/23 00:37:51 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012/02/23 00:31:12 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2012/02/23 00:31:11 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2012/02/23 00:31:11 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2012/02/23 00:31:03 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2012/02/23 00:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2012/02/23 00:31:03 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2012/02/23 00:31:01 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2012/02/23 00:31:01 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2012/02/23 00:31:01 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2012/02/23 00:31:01 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2012/02/23 00:31:01 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2012/02/23 00:31:01 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2012/02/23 00:31:01 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2012/02/23 00:31:00 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2012/02/23 00:31:00 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2012/02/23 00:31:00 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2012/02/23 00:31:00 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2012/02/23 00:31:00 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2012/02/23 00:31:00 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2012/02/23 00:31:00 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2012/02/23 00:31:00 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2012/02/23 00:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2012/02/23 00:31:00 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2012/02/23 00:31:00 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2012/02/23 00:30:59 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2012/02/23 00:30:58 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2012/02/23 00:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2012/02/23 00:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2012/02/23 00:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2012/02/23 00:30:58 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2012/02/23 00:30:57 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2012/02/23 00:30:57 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2012/02/23 00:30:57 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2012/02/23 00:30:57 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2012/02/23 00:30:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2012/02/23 00:30:57 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2012/02/23 00:30:57 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2012/02/23 00:30:57 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2012/02/23 00:30:57 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2012/02/23 00:30:57 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2012/02/23 00:30:56 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2012/02/23 00:30:56 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2012/02/23 00:30:56 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2012/02/23 00:30:56 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2012/02/23 00:30:56 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2012/02/23 00:30:56 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2012/02/23 00:30:56 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2012/02/23 00:30:56 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2012/02/23 00:30:56 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2012/02/23 00:30:56 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2012/02/23 00:30:56 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2012/02/23 00:30:55 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2012/02/23 00:30:55 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2012/02/23 00:30:55 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2012/02/23 00:30:55 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2012/02/23 00:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2012/02/23 00:30:55 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2012/02/23 00:30:53 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2012/02/23 00:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2012/02/23 00:30:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-us
[2012/02/23 00:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2012/02/23 00:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2012/02/23 00:30:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2012/02/23 00:28:50 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2012/02/23 00:26:27 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2012/02/23 00:26:27 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2012/02/23 00:26:27 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2012/02/23 00:26:27 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2012/02/23 00:26:27 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2012/02/23 00:26:27 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2012/02/23 00:26:27 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2012/02/23 00:26:27 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2012/02/23 00:26:27 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2012/02/23 00:26:27 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2012/02/23 00:26:27 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2012/02/23 00:26:27 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2012/02/23 00:26:27 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2012/02/23 00:26:27 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2012/02/23 00:26:27 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2012/02/23 00:26:27 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2012/02/23 00:26:27 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2012/02/23 00:26:27 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2012/02/23 00:26:27 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2012/02/23 00:26:27 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2012/02/23 00:26:27 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2012/02/23 00:26:27 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2012/02/23 00:26:26 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2012/02/23 00:26:26 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2012/02/23 00:26:26 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2012/02/23 00:26:26 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2012/02/23 00:26:26 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2012/02/23 00:26:26 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2012/02/23 00:26:26 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2012/02/23 00:26:26 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2012/02/23 00:26:26 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2012/02/23 00:26:26 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2012/02/23 00:26:26 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2012/02/23 00:26:26 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2012/02/23 00:26:26 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2012/02/23 00:26:26 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2012/02/23 00:26:25 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2012/02/23 00:26:25 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2012/02/23 00:26:25 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2012/02/23 00:26:25 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2012/02/23 00:26:25 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2012/02/23 00:26:25 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2012/02/23 00:26:24 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2012/02/23 00:26:24 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2012/02/23 00:26:24 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2012/02/23 00:26:24 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2012/02/23 00:26:24 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2012/02/23 00:26:24 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2012/02/23 00:26:24 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2012/02/23 00:26:24 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2012/02/23 00:26:24 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2012/02/23 00:26:24 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2012/02/23 00:26:24 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2012/02/23 00:26:23 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2012/02/23 00:26:23 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2012/02/23 00:26:23 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2012/02/23 00:26:23 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2012/02/23 00:22:05 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2012/02/23 00:17:48 | 008,068,864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/23 00:08:08 | 000,000,000 | R–D | C] – C:\MSOCache
[2012/02/20 00:45:21 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2012/02/19 22:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\McAfee.com Personal Firewall
[2012/02/19 22:03:15 | 000,000,000 | –SD | C] – C:\Documents and Settings\Russell\Application Data\Microsoft
[2012/02/19 22:03:15 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Application Data
[2012/02/19 22:03:15 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Favorites
[2012/02/19 22:03:15 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Russell\Cookies
[2012/02/19 22:03:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Local Settings
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Wildtangent
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Sun
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Musicmatch
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\Microsoft
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Intel
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Identities
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Gtek
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Desktop
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\Corel
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\BVRP Software
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ATI
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Application Data\ATI
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\ApplicationHistory
[2012/02/19 22:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2012/02/19 22:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\SendTo
[2012/02/19 22:03:14 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Russell\Recent
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Startup
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Pictures
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents\My Music
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\My Documents
[2012/02/19 22:03:14 | 000,000,000 | R–D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Accessories
[2012/02/19 22:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\Templates
[2012/02/19 22:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\PrintHood
[2012/02/19 22:03:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Russell\NetHood
[2012/02/19 22:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell Accessories
[2012/02/19 22:03:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Russell\Start Menu\Programs\Dell

========== Files - Modified Within 30 Days ==========

[2012/03/16 11:22:23 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/16 11:19:53 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/03/16 11:17:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/16 11:17:07 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/03/16 03:56:23 | 000,991,854 | —- | M] () – C:\Documents and Settings\Russell\Desktop\Desktop Background.bmp
[2012/03/16 03:40:54 | 000,009,216 | —- | M] () – C:\Documents and Settings\Russell\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/16 02:31:19 | 000,065,207 | —- | M] () – C:\Documents and Settings\Russell\Desktop\1654754.aspx.htm
[2012/03/15 03:17:45 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/15 03:16:42 | 009,502,424 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Russell\Desktop\mbam-setup-1.60.1.1000.exe
[2012/03/15 02:49:01 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\TFC.exe
[2012/03/14 06:30:08 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/14 06:25:09 | 000,000,325 | RHS- | M] () – C:\boot.ini
[2012/03/14 05:55:28 | 000,000,512 | —- | M] () – C:\Documents and Settings\Russell\Desktop\MBR.dat
[2012/03/14 03:58:55 | 000,135,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/14 03:07:57 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/03/14 02:25:35 | 004,434,769 | R— | M] (Swearware) – C:\Documents and Settings\Russell\Desktop\ComboFix.exe
[2012/03/14 02:25:23 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Russell\Desktop\aswMBR.exe
[2012/03/14 02:03:19 | 000,000,951 | —- | M] () – C:\Documents and Settings\Russell\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2012/03/13 02:45:39 | 000,012,839 | —- | M] () – C:\Documents and Settings\Russell\Desktop\4770529.jpg
[2012/03/13 02:45:28 | 000,013,097 | —- | M] () – C:\Documents and Settings\Russell\Desktop\4770531.jpg
[2012/03/13 02:26:43 | 000,016,400 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LNonPnP.sys
[2012/03/11 23:57:38 | 000,041,689 | —- | M] () – C:\Documents and Settings\Russell\Desktop\535968_52_full.jpg
[2012/03/11 23:57:35 | 000,042,435 | —- | M] () – C:\Documents and Settings\Russell\Desktop\535968_53_full.jpg
[2012/03/11 23:57:31 | 000,048,384 | —- | M] () – C:\Documents and Settings\Russell\Desktop\535968_51_full.jpg
[2012/03/11 23:52:00 | 000,057,929 | —- | M] () – C:\Documents and Settings\Russell\Desktop\orig.jpg
[2012/03/11 23:51:31 | 000,056,816 | —- | M] () – C:\Documents and Settings\Russell\Desktop\DSC01913.jpg
[2012/03/11 23:16:35 | 000,073,674 | —- | M] () – C:\Documents and Settings\Russell\Desktop\armrestbracket.jpg
[2012/03/11 22:35:07 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/11 22:28:57 | 002,414,672 | —- | M] (Logitech Inc.) – C:\Documents and Settings\Russell\Desktop\setpoint632_smart.exe
[2012/03/11 17:34:43 | 000,443,034 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/11 17:34:43 | 000,072,134 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/10 08:02:04 | 000,001,632 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP600 User Registration.LNK
[2012/03/10 08:01:06 | 000,000,416 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2012/03/10 07:58:42 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2012/03/10 07:58:30 | 000,001,698 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
[2012/03/10 07:57:41 | 000,001,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator 3.0.lnk
[2012/03/10 07:57:19 | 000,001,861 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP600 On-screen Manual.lnk
[2012/03/09 21:32:32 | 004,431,872 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/03/04 21:17:10 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012/03/04 21:17:10 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012/03/04 02:08:00 | 000,000,782 | —- | M] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/03/04 02:04:15 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012/03/04 02:03:28 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/03 22:03:18 | 000,000,154 | —- | M] () – C:\Documents and Settings\Russell\Desktop\Network.lnk
[2012/02/29 11:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/27 04:49:12 | 000,102,176 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 04:47:43 | 000,039,426 | —- | M] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 16:28:09 | 000,000,815 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/26 16:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/02/26 06:57:49 | 000,003,766 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/26 06:57:48 | 000,000,088 | RHS- | M] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/26 06:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/02/23 04:13:30 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/23 02:41:26 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/23 02:41:26 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/23 02:41:26 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/23 02:41:25 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/23 02:41:25 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/23 02:22:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 01:50:50 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/02/23 00:39:31 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/02/23 00:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/23 00:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/02/22 20:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/02/22 19:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 22:20:37 | 000,031,648 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2012/02/19 22:11:34 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2012/02/19 22:03:37 | 000,000,130 | —- | M] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 22:03:22 | 000,001,478 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 22:03:00 | 000,000,448 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012/02/19 22:02:55 | 000,000,209 | —- | M] () – C:\Boot.bak
[2012/02/19 21:54:36 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD

========== Files Created - No Company Name ==========

[2012/03/16 05:28:21 | 000,991,854 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Desktop Background.bmp
[2012/03/16 02:31:17 | 000,065,207 | —- | C] () – C:\Documents and Settings\Russell\Desktop\1654754.aspx.htm
[2012/03/15 03:46:33 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/15 03:17:45 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/14 06:25:09 | 000,000,209 | —- | C] () – C:\Boot.bak
[2012/03/14 06:25:06 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/03/14 06:23:54 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/03/14 06:23:54 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/03/14 06:23:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/03/14 06:23:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/03/14 06:23:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/03/14 05:55:28 | 000,000,512 | —- | C] () – C:\Documents and Settings\Russell\Desktop\MBR.dat
[2012/03/14 02:03:19 | 000,000,951 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2012/03/13 02:45:39 | 000,012,839 | —- | C] () – C:\Documents and Settings\Russell\Desktop\4770529.jpg
[2012/03/13 02:45:28 | 000,013,097 | —- | C] () – C:\Documents and Settings\Russell\Desktop\4770531.jpg
[2012/03/11 23:57:38 | 000,041,689 | —- | C] () – C:\Documents and Settings\Russell\Desktop\535968_52_full.jpg
[2012/03/11 23:57:35 | 000,042,435 | —- | C] () – C:\Documents and Settings\Russell\Desktop\535968_53_full.jpg
[2012/03/11 23:57:31 | 000,048,384 | —- | C] () – C:\Documents and Settings\Russell\Desktop\535968_51_full.jpg
[2012/03/11 23:52:00 | 000,057,929 | —- | C] () – C:\Documents and Settings\Russell\Desktop\orig.jpg
[2012/03/11 23:51:31 | 000,056,816 | —- | C] () – C:\Documents and Settings\Russell\Desktop\DSC01913.jpg
[2012/03/11 23:16:35 | 000,073,674 | —- | C] () – C:\Documents and Settings\Russell\Desktop\armrestbracket.jpg
[2012/03/11 22:35:07 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/03/10 08:02:04 | 000,001,632 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP600 User Registration.LNK
[2012/03/10 08:01:06 | 000,000,416 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2012/03/10 07:58:42 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2012/03/10 07:58:30 | 000,001,698 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint.lnk
[2012/03/10 07:57:41 | 000,001,693 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator 3.0.lnk
[2012/03/10 07:57:19 | 000,001,861 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP600 On-screen Manual.lnk
[2012/03/04 02:04:15 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2012/03/03 22:03:18 | 000,000,154 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Network.lnk
[2012/03/03 15:42:14 | 000,009,216 | —- | C] () – C:\Documents and Settings\Russell\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/27 04:49:12 | 000,102,176 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7815.JPG
[2012/02/27 04:47:43 | 000,039,426 | —- | C] () – C:\Documents and Settings\Russell\Desktop\IMG_7790.JPG
[2012/02/26 00:31:48 | 000,003,766 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2012/02/26 00:31:48 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\CCA7228038.sys
[2012/02/23 02:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/23 02:50:39 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/23 02:22:39 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/23 01:50:50 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2012/02/23 01:50:24 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/23 01:45:58 | 001,292,288 | —- | C] () – C:\WINDOWS\System32\dllcache\quartz.dll
[2012/02/23 00:26:26 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012/02/23 00:26:26 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2012/02/23 00:26:25 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2012/02/23 00:25:14 | 000,004,128 | —- | C] () – C:\INFCACHE.1
[2012/02/23 00:17:58 | 001,359,824 | —- | C] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/19 22:11:34 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/02/19 22:03:23 | 000,000,782 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Windows Media Player.lnk
[2012/02/19 22:03:16 | 000,002,007 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2012/02/19 22:03:16 | 000,001,824 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk
[2012/02/19 22:03:16 | 000,001,769 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk
[2012/02/19 22:03:16 | 000,001,478 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/02/19 22:03:16 | 000,001,298 | —- | C] () – C:\Documents and Settings\Russell\Desktop\Media Center.lnk
[2012/02/19 22:03:16 | 000,000,815 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/19 22:03:16 | 000,000,742 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2012/02/19 22:03:16 | 000,000,130 | —- | C] () – C:\Documents and Settings\Russell\Local Settings\Application Data\fusioncache.dat
[2012/02/19 22:03:16 | 000,000,079 | —- | C] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/02/19 22:03:15 | 000,001,503 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Remote Assistance.lnk
[2012/02/19 22:03:15 | 000,000,803 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Internet Explorer.lnk
[2012/02/19 22:03:15 | 000,000,788 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Windows Media Player.lnk
[2012/02/19 22:03:15 | 000,000,738 | —- | C] () – C:\Documents and Settings\Russell\Start Menu\Programs\Outlook Express.lnk
[2012/02/19 21:54:36 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD

========== LOP Check ==========

[2012/03/10 07:57:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/03/10 08:00:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/04/22 11:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/03/11 22:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Russell\Application Data\Leadertech
[2012/03/10 08:01:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Russell\Application Data\ScanSoft
[2012/03/16 11:22:23 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/02/19 22:02:55 | 000,000,209 | —- | M] () – C:\Boot.bak
[2012/03/14 06:25:09 | 000,000,325 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/03/14 06:31:59 | 000,019,038 | —- | M] () – C:\ComboFix.txt
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/22 11:05:26 | 000,006,905 | RH– | M] () – C:\dell.sdr
[2012/03/16 11:17:07 | 2145,845,248 | -HS- | M] () – C:\hiberfil.sys
[2012/02/23 00:25:14 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/22 11:35:52 | 000,000,829 | -H– | M] () – C:\IPH.PH
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2012/02/23 00:26:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/03/16 11:17:06 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/04/22 11:36:01 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2012/03/02 06:43:46 | 000,062,160 | —- | M] () – C:\TDSSKiller.2.7.17.0_02.03.2012_05.26.41_log.txt
[2012/03/03 03:40:09 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.7.17.0_03.03.2012_02.40.04_log.txt
[2012/03/03 03:43:55 | 000,183,868 | —- | M] () – C:\TDSSKiller.2.7.17.0_03.03.2012_02.40.28_log.txt
[2012/03/03 03:48:31 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.7.17.0_03.03.2012_02.48.24_log.txt
[2012/03/03 03:50:33 | 000,061,616 | —- | M] () – C:\TDSSKiller.2.7.18.0_03.03.2012_02.49.34_log.txt
[2012/03/03 22:02:08 | 000,062,446 | —- | M] () – C:\TDSSKiller.2.7.18.0_03.03.2012_21.01.26_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/09/13 01:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD87.DLL
[2006/09/13 01:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP87.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012/02/23 00:31:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/23 00:38:33 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 05:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Russell\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/03/14 02:25:23 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Russell\Desktop\aswMBR.exe
[2012/03/14 02:25:35 | 004,434,769 | R— | M] (Swearware) – C:\Documents and Settings\Russell\Desktop\ComboFix.exe
[2012/02/29 11:46:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Russell\Desktop\HiJackThis.exe
[2012/02/26 16:12:27 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\IE8-WindowsXP-x86-ENU.exe
[2012/03/15 03:16:42 | 009,502,424 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Russell\Desktop\mbam-setup-1.60.1.1000.exe
[2012/02/22 20:23:23 | 008,068,864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Russell\Desktop\mseinstall.exe
[2012/03/16 11:19:53 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\OTL.exe
[2012/02/22 19:54:50 | 001,359,824 | —- | M] () – C:\Documents and Settings\Russell\Desktop\pc-decrapifier-2.2.8.exe
[2012/02/26 06:53:45 | 014,886,760 | —- | M] (Google Inc.) – C:\Documents and Settings\Russell\Desktop\picasa39-setup.exe
[2012/03/11 22:28:57 | 002,414,672 | —- | M] (Logitech Inc.) – C:\Documents and Settings\Russell\Desktop\setpoint632_smart.exe
[2012/03/15 02:49:01 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Russell\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-14 07:07:58

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI