This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blue Screen/Power Off on Reboots, Running extremely slow [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My computer is running extremely slow. Scripts errors while surfing the net, sites unable to load or load extremely slow. Having difficulty starting computer. Computer will automatically shut off on reboot numerous times even after trying to load on safe mode or last known good configuration. I have to try multiple times in order for it to boot properly. Please help. Thank you.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:47:38 AM, on 3/27/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\DOCUME~1\BIGH~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Nuance\dgnsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\WINDOWS\PLFSet.dll,PLFDefSetting
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking11\Ereg.ini
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpeedUpMyPC] "C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe" -d 20000
O4 - HKCU\..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Dragon Service (DragonSvc) - Nuance Communications, Inc. - C:\Program Files\Common Files\Nuance\dgnsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 13245 bytes


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Run by [removed] at 0:25:29 on 2012-03-27
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.1925 [GMT -7:00]
.
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\DOCUME~1\BIGH~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Nuance\dgnsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Big H\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = http=;ftp=;https=;
BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Google Update] "c:\documents and settings\big h\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [SpeedUpMyPC] "c:\program files\uniblue\speedupmypc\launcher.exe" -d 20000
uRun: [ISUSPM] c:\documents and settings\all users\application data\flexnet\connect\11\ISUSPM.exe -scheduler
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AzMixerSel] c:\program files\realtek\installshield\AzMixerSel.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [PLFSet] rundll32.exe c:\windows\PLFSet.dll,PLFDefSetting
mRun: [AtiPTA] atiptaxx.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking11\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\naturallyspeaking11\Ereg.ini
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.11.1
TCP: Interfaces\{6689B8DC-36F6-4D61-8A96-6916AC313ED4} : DhcpNameServer = 192.168.11.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 74.208.10.249 gs.apple.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\big h\application data\mozilla\firefox\profiles\fxcip6ed.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\big h\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\big h\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\big h\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
.
============= SERVICES / DRIVERS ===============
.
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2010-12-22 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2010-12-22 35712]
R1 atitray;atitray;c:\program files\radeon omega drivers\v4.8.442\ati tray tools\atitray.sys [2010-12-22 17952]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-10-31 232512]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2012-3-12 104456]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-4-8 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-4-8 161392]
R2 DragonSvc;Dragon Service;c:\program files\common files\nuance\dgnsvc.exe [2010-7-23 296808]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-4-17 1706176]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20120322.003\naveng.sys [2012-3-23 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20120322.003\navex15.sys [2012-3-23 1576312]
S2 Micro Niche Finder Background Download Service;Micro Niche Finder Background Download Service; [x]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-1-31 158856]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-4-8 83568]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; [x]
.
=============== Created Last 30 ================
.
2012-03-22 21:09:24 592824 —-a-w- c:\program files\mozilla firefox\gkmedias.dll
2012-03-22 21:09:24 44472 —-a-w- c:\program files\mozilla firefox\mozglue.dll
2012-03-22 04:12:21 ——– d—–w- c:\program files\JDownloader
2012-03-16 22:25:57 ——– d—–w- c:\documents and settings\big h\application data\IDM
2012-03-16 22:25:34 ——– d—–w- c:\program files\Internet Download Manager
2012-03-14 21:01:23 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-03-13 04:05:09 ——– d—–w- c:\documents and settings\big h\application data\redsn0w
2012-03-13 03:26:16 ——– d—–w- c:\documents and settings\big h\.shsh
2012-03-12 23:55:38 ——– d—–w- c:\documents and settings\big h\application data\PlatinumHideIP
2012-03-12 23:55:38 ——– d—–w- c:\documents and settings\all users\application data\PlatinumHideIP
2012-03-12 23:49:17 ——– d—–w- c:\program files\PlatinumHideIP
2012-03-12 15:36:23 104456 —-a-w- c:\windows\system32\drivers\idmtdi.sys
2012-03-10 07:27:14 ——– d—–w- c:\program files\Battle for Wesnoth 1.10.1
2012-03-06 02:55:07 ——– d—–w- c:\documents and settings\big h\application data\SuperHideIP
2012-03-06 02:55:07 ——– d—–w- c:\documents and settings\all users\application data\SuperHideIP
2012-03-06 02:53:54 ——– d—–w- c:\documents and settings\big h\local settings\application data\APN
2012-03-06 01:41:18 ——– d—–w- c:\program files\Quick Hide IP
2012-03-06 01:34:45 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2012-03-06 01:34:44 ——– d—–w- c:\documents and settings\big h\application data\PPStream
2012-02-28 07:41:39 ——– d—–w- c:\program files\Square Soft, Inc
.
==================== Find3M ====================
.
2012-03-26 21:41:51 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-14 21:01:06 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-02-03 09:22:18 1860096 —-a-w- c:\windows\system32\win32k.sys
2012-01-11 19:06:47 3072 ——w- c:\windows\system32\iacenc.dll
2012-01-09 16:20:25 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-01-04 07:13:55 94208 —-a-w- c:\windows\DUMPc6f9.tmp
.
============= FINISH: 0:26:35.81 ===============

Attachments:

Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • If Malicious objects are found then ensure Cure is selected
    • If TDLFS File System is found then ensure Delete is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
during the scan, norton antivirus poppped up and reported a trojan.gen virus that was quaratined… 13:59:36.0062 2440 TDSS rootkit removing tool [removed] Mar 26 2012 13:40:18 13:59:36.0687 2440 ============================================================ 13:59:36.0687 2440 Current date / time: 2012/04/01 13:59:36.0687 13:59:36.0687 2440 SystemInfo: 13:59:36.0687 2440 13:59:36.0687 2440 OS Version: 5.1.2600 ServicePack: 3.0 13:59:36.0687 2440 Product type: Workstation 13:59:36.0687 2440 ComputerName: HYDRO 13:59:36.0687 2440 UserName: Big H 13:59:36.0687 2440 Windows directory: C:\WINDOWS 13:59:36.0687 2440 System windows directory: C:\WINDOWS 13:59:36.0687 2440 Processor architecture: Intel x86 13:59:36.0687 2440 Number of processors: 2 13:59:36.0687 2440 Page size: 0x1000 13:59:36.0687 2440 Boot type: Normal boot 13:59:36.0687 2440 ============================================================ 13:59:39.0562 2440 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 13:59:39.0562 2440 \Device\Harddisk0\DR0: 13:59:39.0562 2440 MBR used 13:59:39.0562 2440 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xDF8F8C1 13:59:39.0609 2440 Initialize success 13:59:39.0609 2440 ============================================================ 13:59:59.0359 5040 ============================================================ 13:59:59.0359 5040 Scan started 13:59:59.0359 5040 Mode: Manual; TDLFS; 13:59:59.0359 5040 ============================================================ 13:59:59.0671 5040 !SASCORE (c0393eb99a6c72c6bef9bfc4a72b33a6) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE 13:59:59.0703 5040 !SASCORE - ok 13:59:59.0812 5040 Abiosdsk - ok 13:59:59.0812 5040 abp480n5 - ok 13:59:59.0875 5040 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:59:59.0875 5040 ACPI - ok 13:59:59.0921 5040 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 13:59:59.0921 5040 ACPIEC - ok 13:59:59.0937 5040 adpu160m - ok 13:59:59.0984 5040 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 14:00:00.0000 5040 aec - ok 14:00:00.0046 5040 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 14:00:00.0046 5040 AFD - ok 14:00:00.0187 5040 AgereModemAudio (39e435c90c9c4f780fa0ed05ca3c3a1b) C:\WINDOWS\system32\agrsmsvc.exe 14:00:00.0218 5040 AgereModemAudio - ok 14:00:00.0328 5040 AgereSoftModem (d31d1a92479bd8c0d050a6ffbdd410d9) C:\WINDOWS\system32\DRIVERS\AGRSM.sys 14:00:00.0359 5040 AgereSoftModem - ok 14:00:00.0453 5040 Aha154x - ok 14:00:00.0468 5040 aic78u2 - ok 14:00:00.0468 5040 aic78xx - ok 14:00:00.0515 5040 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll 14:00:00.0531 5040 Alerter - ok 14:00:00.0562 5040 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe 14:00:00.0562 5040 ALG - ok 14:00:00.0578 5040 AliIde - ok 14:00:00.0609 5040 AmdK8 (efbb0956baed786e137351b5ca272aef) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 14:00:00.0625 5040 AmdK8 - ok 14:00:00.0625 5040 amsint - ok 14:00:00.0734 5040 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 14:00:00.0765 5040 Apple Mobile Device - ok 14:00:00.0906 5040 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll 14:00:00.0921 5040 AppMgmt - ok 14:00:00.0937 5040 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 14:00:00.0953 5040 Arp1394 - ok 14:00:00.0968 5040 asc - ok 14:00:00.0968 5040 asc3350p - ok 14:00:00.0984 5040 asc3550 - ok 14:00:01.0125 5040 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 14:00:01.0218 5040 aspnet_state - ok 14:00:01.0234 5040 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 14:00:01.0250 5040 AsyncMac - ok 14:00:01.0359 5040 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 14:00:01.0359 5040 atapi - ok 14:00:01.0375 5040 Atdisk - ok 14:00:01.0437 5040 Ati HotKey Poller (471087b5e1e01cc82604e81ea14781d8) C:\WINDOWS\system32\Ati2evxx.exe 14:00:01.0468 5040 Ati HotKey Poller - ok 14:00:01.0609 5040 ATI Smart (b979ba0120b6db757196a8e2e873fe3c) C:\WINDOWS\system32\ati2sgag.exe 14:00:01.0640 5040 ATI Smart - ok 14:00:01.0796 5040 ati2mtag (c0b86ecb324e50f6bbd529f9d5c6b24b) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 14:00:01.0937 5040 ati2mtag - ok 14:00:02.0093 5040 atitray (6e51838f65c4f5264af489773a53d678) C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys 14:00:02.0093 5040 atitray - ok 14:00:02.0218 5040 atksgt (70f72c50d39f5afa76c17f86223a7c4f) C:\WINDOWS\system32\DRIVERS\atksgt.sys 14:00:02.0234 5040 atksgt - ok 14:00:02.0281 5040 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 14:00:02.0296 5040 Atmarpc - ok 14:00:02.0343 5040 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll 14:00:02.0343 5040 AudioSrv - ok 14:00:02.0421 5040 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 14:00:02.0421 5040 audstub - ok 14:00:02.0531 5040 BCM43XX (e9ea635b8432d68f0005b3f6cebab837) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 14:00:02.0562 5040 BCM43XX - ok 14:00:02.0625 5040 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 14:00:02.0625 5040 Beep - ok 14:00:02.0718 5040 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll 14:00:02.0796 5040 BITS - ok 14:00:02.0906 5040 Bonjour Service (1c87705ccb2f60172b0fc86b5d82f00d) C:\Program Files\Bonjour\mDNSResponder.exe 14:00:02.0937 5040 Bonjour Service - ok 14:00:03.0031 5040 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll 14:00:03.0046 5040 Browser - ok 14:00:03.0078 5040 catchme - ok 14:00:03.0109 5040 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 14:00:03.0125 5040 cbidf2k - ok 14:00:03.0171 5040 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 14:00:03.0171 5040 CCDECODE - ok 14:00:03.0312 5040 ccEvtMgr (83053d67f40cd00d5fb3baa2c4d6f9ec) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe 14:00:03.0328 5040 ccEvtMgr - ok 14:00:03.0359 5040 ccPwdSvc (ac60ad2fca93f0d0180c9610403782ef) C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe 14:00:03.0375 5040 ccPwdSvc - ok 14:00:03.0421 5040 ccSetMgr (2013a368106f5eb9aa6f492369f8063c) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe 14:00:03.0437 5040 ccSetMgr - ok 14:00:03.0546 5040 cd20xrnt - ok 14:00:03.0578 5040 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 14:00:03.0593 5040 Cdaudio - ok 14:00:03.0640 5040 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 14:00:03.0640 5040 Cdfs - ok 14:00:03.0656 5040 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 14:00:03.0687 5040 Cdrom - ok 14:00:03.0687 5040 Changer - ok 14:00:03.0718 5040 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe 14:00:03.0718 5040 CiSvc - ok 14:00:03.0750 5040 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe 14:00:03.0765 5040 ClipSrv - ok 14:00:03.0906 5040 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:00:03.0984 5040 clr_optimization_v2.0.50727_32 - ok 14:00:04.0109 5040 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 14:00:04.0109 5040 CmBatt - ok 14:00:04.0125 5040 CmdIde - ok 14:00:04.0281 5040 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 14:00:04.0281 5040 Compbatt - ok 14:00:04.0328 5040 COMSysApp - ok 14:00:04.0343 5040 Cpqarray - ok 14:00:04.0375 5040 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll 14:00:04.0390 5040 CryptSvc - ok 14:00:04.0390 5040 dac2w2k - ok 14:00:04.0406 5040 dac960nt - ok 14:00:04.0468 5040 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 14:00:04.0468 5040 DcomLaunch - ok 14:00:04.0593 5040 DefWatch (955924c3532efb803b0661b6aa516126) C:\Program Files\Symantec AntiVirus\DefWatch.exe 14:00:04.0593 5040 DefWatch - ok 14:00:04.0703 5040 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll 14:00:04.0703 5040 Dhcp - ok 14:00:04.0750 5040 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 14:00:04.0750 5040 Disk - ok 14:00:04.0765 5040 dmadmin - ok 14:00:04.0828 5040 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 14:00:04.0859 5040 dmboot - ok 14:00:04.0937 5040 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 14:00:04.0937 5040 dmio - ok 14:00:04.0984 5040 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 14:00:04.0984 5040 dmload - ok 14:00:05.0015 5040 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll 14:00:05.0031 5040 dmserver - ok 14:00:05.0078 5040 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 14:00:05.0078 5040 DMusic - ok 14:00:05.0140 5040 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll 14:00:05.0140 5040 Dnscache - ok 14:00:05.0187 5040 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll 14:00:05.0203 5040 Dot3svc - ok 14:00:05.0265 5040 dpti2o - ok 14:00:05.0359 5040 DragonSvc (f7bda38afbda04f0a89deba767eeda79) C:\Program Files\Common Files\Nuance\dgnsvc.exe 14:00:05.0406 5040 DragonSvc - ok 14:00:05.0453 5040 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 14:00:05.0468 5040 drmkaud - ok 14:00:05.0500 5040 dtsoftbus01 (c0c7ceccb6c85994c2bc92d58e52d3f2) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys 14:00:05.0515 5040 dtsoftbus01 - ok 14:00:05.0578 5040 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll 14:00:05.0578 5040 EapHost - ok 14:00:05.0656 5040 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 14:00:05.0671 5040 eeCtrl - ok 14:00:05.0734 5040 EraserUtilDrv11122 (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11122.sys 14:00:05.0750 5040 EraserUtilDrv11122 - ok 14:00:05.0875 5040 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll 14:00:05.0875 5040 ERSvc - ok 14:00:05.0921 5040 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 14:00:05.0937 5040 Eventlog - ok 14:00:05.0984 5040 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll 14:00:05.0984 5040 EventSystem - ok 14:00:06.0015 5040 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 14:00:06.0015 5040 Fastfat - ok 14:00:06.0078 5040 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:00:06.0078 5040 FastUserSwitchingCompatibility - ok 14:00:06.0218 5040 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 14:00:06.0218 5040 Fdc - ok 14:00:06.0265 5040 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 14:00:06.0281 5040 Fips - ok 14:00:06.0328 5040 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 14:00:06.0328 5040 Flpydisk - ok 14:00:06.0390 5040 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 14:00:06.0390 5040 FltMgr - ok 14:00:06.0500 5040 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 14:00:06.0515 5040 FontCache3.0.0.0 - ok 14:00:06.0640 5040 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 14:00:06.0656 5040 Fs_Rec - ok 14:00:06.0703 5040 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 14:00:06.0718 5040 Ftdisk - ok 14:00:06.0734 5040 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 14:00:06.0750 5040 GEARAspiWDM - ok 14:00:06.0796 5040 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 14:00:06.0812 5040 Gpc - ok 14:00:06.0859 5040 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 14:00:06.0875 5040 HDAudBus - ok 14:00:06.0953 5040 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 14:00:06.0968 5040 helpsvc - ok 14:00:07.0062 5040 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll 14:00:07.0078 5040 HidServ - ok 14:00:07.0125 5040 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 14:00:07.0140 5040 HidUsb - ok 14:00:07.0187 5040 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll 14:00:07.0203 5040 hkmsvc - ok 14:00:07.0218 5040 hpn - ok 14:00:07.0281 5040 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 14:00:07.0281 5040 HTTP - ok 14:00:07.0421 5040 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll 14:00:07.0421 5040 HTTPFilter - ok 14:00:07.0437 5040 i2omgmt - ok 14:00:07.0453 5040 i2omp - ok 14:00:07.0500 5040 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 14:00:07.0515 5040 i8042prt - ok 14:00:07.0578 5040 IDMTDI (eb5a63adbf35314465cfbc33558cdaf7) C:\WINDOWS\system32\DRIVERS\idmtdi.sys 14:00:07.0578 5040 IDMTDI - ok 14:00:07.0750 5040 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 14:00:07.0796 5040 idsvc - ok 14:00:07.0921 5040 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 14:00:07.0937 5040 Imapi - ok 14:00:07.0968 5040 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe 14:00:07.0968 5040 ImapiService - ok 14:00:07.0984 5040 ini910u - ok 14:00:08.0203 5040 IntcAzAudAddService (b45a576ad280dd4f605f58b24cdaafe1) C:\WINDOWS\system32\drivers\RtkHDAud.sys 14:00:08.0390 5040 IntcAzAudAddService - ok 14:00:08.0484 5040 IntelIde - ok 14:00:08.0531 5040 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 14:00:08.0546 5040 Ip6Fw - ok 14:00:08.0609 5040 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 14:00:08.0625 5040 IpFilterDriver - ok 14:00:08.0656 5040 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 14:00:08.0671 5040 IpInIp - ok 14:00:08.0687 5040 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 14:00:08.0718 5040 IpNat - ok 14:00:08.0828 5040 iPod Service (f62c69376a95795fe7cdb1c778edaca4) C:\Program Files\iPod\bin\iPodService.exe 14:00:08.0843 5040 iPod Service - ok 14:00:08.0984 5040 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 14:00:09.0000 5040 IPSec - ok 14:00:09.0046 5040 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys 14:00:09.0062 5040 irda - ok 14:00:09.0109 5040 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 14:00:09.0109 5040 IRENUM - ok 14:00:09.0140 5040 Irmon (49cc4533ce897cb2e93c1e84a818fde5) C:\WINDOWS\System32\irmon.dll 14:00:09.0140 5040 Irmon - ok 14:00:09.0234 5040 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 14:00:09.0234 5040 isapnp - ok 14:00:09.0296 5040 JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Program Files\Java\jre6\bin\jqs.exe 14:00:09.0328 5040 JavaQuickStarterService - ok 14:00:09.0359 5040 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 14:00:09.0359 5040 Kbdclass - ok 14:00:09.0421 5040 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 14:00:09.0437 5040 kmixer - ok 14:00:09.0515 5040 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 14:00:09.0515 5040 KSecDD - ok 14:00:09.0593 5040 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll 14:00:09.0593 5040 LanmanServer - ok 14:00:09.0640 5040 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll 14:00:09.0656 5040 lanmanworkstation - ok 14:00:09.0656 5040 lbrtfdc - ok 14:00:09.0718 5040 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\WINDOWS\system32\DRIVERS\lirsgt.sys 14:00:09.0734 5040 lirsgt - ok 14:00:09.0796 5040 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll 14:00:09.0812 5040 LmHosts - ok 14:00:09.0890 5040 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys 14:00:09.0890 5040 mcdbus - ok 14:00:09.0937 5040 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll 14:00:09.0953 5040 Messenger - ok 14:00:09.0984 5040 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 14:00:10.0000 5040 mnmdd - ok 14:00:10.0046 5040 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe 14:00:10.0062 5040 mnmsrvc - ok 14:00:10.0109 5040 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 14:00:10.0125 5040 Modem - ok 14:00:10.0234 5040 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 14:00:10.0250 5040 Mouclass - ok 14:00:10.0296 5040 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 14:00:10.0312 5040 MountMgr - ok 14:00:10.0312 5040 mraid35x - ok 14:00:10.0328 5040 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 14:00:10.0328 5040 MRxDAV - ok 14:00:10.0390 5040 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 14:00:10.0406 5040 MRxSmb - ok 14:00:10.0500 5040 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe 14:00:10.0515 5040 MSDTC - ok 14:00:10.0578 5040 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 14:00:10.0578 5040 Msfs - ok 14:00:10.0593 5040 MSIServer - ok 14:00:10.0656 5040 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:00:10.0656 5040 MSKSSRV - ok 14:00:10.0703 5040 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:00:10.0703 5040 MSPCLOCK - ok 14:00:10.0750 5040 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 14:00:10.0750 5040 MSPQM - ok 14:00:10.0796 5040 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:00:10.0796 5040 mssmbios - ok 14:00:10.0875 5040 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 14:00:10.0875 5040 MSTEE - ok 14:00:10.0953 5040 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 14:00:10.0953 5040 Mup - ok 14:00:10.0968 5040 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 14:00:10.0984 5040 NABTSFEC - ok 14:00:11.0046 5040 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll 14:00:11.0062 5040 napagent - ok 14:00:11.0250 5040 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120330.002\naveng.sys 14:00:11.0250 5040 NAVENG - ok 14:00:11.0328 5040 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20120330.002\navex15.sys 14:00:11.0343 5040 NAVEX15 - ok 14:00:11.0484 5040 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 14:00:11.0484 5040 NDIS - ok 14:00:11.0531 5040 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 14:00:11.0531 5040 NdisIP - ok 14:00:11.0593 5040 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:00:11.0593 5040 NdisTapi - ok 14:00:11.0609 5040 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:00:11.0625 5040 Ndisuio - ok 14:00:11.0671 5040 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:00:11.0687 5040 NdisWan - ok 14:00:11.0718 5040 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 14:00:11.0718 5040 NDProxy - ok 14:00:11.0843 5040 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 14:00:11.0843 5040 NetBIOS - ok 14:00:11.0875 5040 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 14:00:11.0890 5040 NetBT - ok 14:00:11.0921 5040 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 14:00:11.0937 5040 NetDDE - ok 14:00:11.0953 5040 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 14:00:11.0953 5040 NetDDEdsdm - ok 14:00:12.0000 5040 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:00:12.0000 5040 Netlogon - ok 14:00:12.0031 5040 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll 14:00:12.0031 5040 Netman - ok 14:00:12.0171 5040 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:00:12.0187 5040 NetTcpPortSharing - ok 14:00:12.0328 5040 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 14:00:12.0343 5040 NIC1394 - ok 14:00:12.0406 5040 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll 14:00:12.0406 5040 Nla - ok 14:00:12.0437 5040 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 14:00:12.0437 5040 Npfs - ok 14:00:12.0453 5040 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys 14:00:12.0468 5040 NSCIRDA - ok 14:00:12.0531 5040 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 14:00:12.0546 5040 Ntfs - ok 14:00:12.0687 5040 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:00:12.0687 5040 NtLmSsp - ok 14:00:12.0750 5040 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll 14:00:12.0781 5040 NtmsSvc - ok 14:00:12.0812 5040 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 14:00:12.0812 5040 Null - ok 14:00:12.0843 5040 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:00:12.0843 5040 NwlnkFlt - ok 14:00:12.0890 5040 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:00:12.0906 5040 NwlnkFwd - ok 14:00:13.0000 5040 o2flash (d955d5de998db2476bf0892be3a96c26) C:\Program Files\O2Micro Oz128 Driver\o2flash.exe 14:00:13.0015 5040 o2flash - ok 14:00:13.0125 5040 O2MDRDR (36ed541ff0ad27d7f1c1e8f86f026309) C:\WINDOWS\system32\DRIVERS\o2media.sys 14:00:13.0125 5040 O2MDRDR - ok 14:00:13.0140 5040 O2SDRDR (f3d467025d365a96b5e51c6229562716) C:\WINDOWS\system32\DRIVERS\o2sd.sys 14:00:13.0140 5040 O2SDRDR - ok 14:00:13.0265 5040 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 14:00:13.0328 5040 odserv - ok 14:00:13.0359 5040 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 14:00:13.0359 5040 ohci1394 - ok 14:00:13.0406 5040 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:00:13.0500 5040 ose - ok 14:00:13.0671 5040 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 14:00:13.0687 5040 Parport - ok 14:00:13.0703 5040 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 14:00:13.0703 5040 PartMgr - ok 14:00:13.0750 5040 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 14:00:13.0750 5040 ParVdm - ok 14:00:13.0796 5040 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 14:00:13.0796 5040 PCI - ok 14:00:13.0812 5040 PCIDump - ok 14:00:13.0859 5040 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 14:00:13.0859 5040 PCIIde - ok 14:00:13.0875 5040 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 14:00:13.0875 5040 Pcmcia - ok 14:00:13.0875 5040 PDCOMP - ok 14:00:13.0890 5040 PDFRAME - ok 14:00:13.0906 5040 PDRELI - ok 14:00:13.0921 5040 PDRFRAME - ok 14:00:13.0937 5040 perc2 - ok 14:00:13.0937 5040 perc2hib - ok 14:00:13.0984 5040 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 14:00:13.0984 5040 PlugPlay - ok 14:00:14.0125 5040 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:00:14.0140 5040 PolicyAgent - ok 14:00:14.0187 5040 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:00:14.0203 5040 PptpMiniport - ok 14:00:14.0250 5040 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 14:00:14.0250 5040 Processor - ok 14:00:14.0265 5040 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:00:14.0265 5040 ProtectedStorage - ok 14:00:14.0281 5040 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 14:00:14.0281 5040 PSched - ok 14:00:14.0328 5040 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:00:14.0328 5040 Ptilink - ok 14:00:14.0343 5040 ql1080 - ok 14:00:14.0359 5040 Ql10wnt - ok 14:00:14.0359 5040 ql12160 - ok 14:00:14.0375 5040 ql1240 - ok 14:00:14.0390 5040 ql1280 - ok 14:00:14.0421 5040 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:00:14.0437 5040 RasAcd - ok 14:00:14.0453 5040 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll 14:00:14.0468 5040 RasAuto - ok 14:00:14.0500 5040 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 14:00:14.0500 5040 Rasirda - ok 14:00:14.0625 5040 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:00:14.0640 5040 Rasl2tp - ok 14:00:14.0656 5040 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll 14:00:14.0671 5040 RasMan - ok 14:00:14.0703 5040 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:00:14.0703 5040 RasPppoe - ok 14:00:14.0765 5040 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 14:00:14.0765 5040 Raspti - ok 14:00:14.0781 5040 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:00:14.0796 5040 Rdbss - ok 14:00:14.0812 5040 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:00:14.0828 5040 RDPCDD - ok 14:00:14.0968 5040 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 14:00:14.0984 5040 rdpdr - ok 14:00:15.0015 5040 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys 14:00:15.0031 5040 RDPWD - ok 14:00:15.0046 5040 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe 14:00:15.0062 5040 RDSessMgr - ok 14:00:15.0093 5040 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 14:00:15.0109 5040 redbook - ok 14:00:15.0156 5040 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll 14:00:15.0156 5040 RemoteAccess - ok 14:00:15.0296 5040 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll 14:00:15.0312 5040 RemoteRegistry - ok 14:00:15.0328 5040 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe 14:00:15.0343 5040 RpcLocator - ok 14:00:15.0406 5040 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll 14:00:15.0421 5040 RpcSs - ok 14:00:15.0468 5040 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 14:00:15.0500 5040 RSVP - ok 14:00:15.0546 5040 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 14:00:15.0546 5040 SamSs - ok 14:00:15.0625 5040 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 14:00:15.0625 5040 SASDIFSV - ok 14:00:15.0640 5040 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 14:00:15.0656 5040 SASKUTIL - ok 14:00:15.0703 5040 SavRoam (778f31aa8685426ca2d0d38b423c2512) C:\Program Files\Symantec AntiVirus\SavRoam.exe 14:00:15.0718 5040 SavRoam - ok 14:00:15.0765 5040 SAVRT (a00d5aa4748a1002590f08aa00fc660d) C:\Program Files\Symantec AntiVirus\savrt.sys 14:00:15.0781 5040 SAVRT - ok 14:00:15.0781 5040 SAVRTPEL (1e805005583be1c1568a3fce259c81e3) C:\Program Files\Symantec AntiVirus\Savrtpel.sys 14:00:15.0796 5040 SAVRTPEL - ok 14:00:15.0921 5040 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe 14:00:15.0937 5040 SCardSvr - ok 14:00:15.0984 5040 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll 14:00:16.0000 5040 Schedule - ok 14:00:16.0125 5040 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 14:00:16.0125 5040 sdbus - ok 14:00:16.0171 5040 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:00:16.0187 5040 Secdrv - ok 14:00:16.0218 5040 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll 14:00:16.0234 5040 seclogon - ok 14:00:16.0250 5040 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll 14:00:16.0265 5040 SENS - ok 14:00:16.0437 5040 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 14:00:16.0437 5040 Serial - ok 14:00:16.0484 5040 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 14:00:16.0500 5040 Sfloppy - ok 14:00:16.0578 5040 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll 14:00:16.0593 5040 SharedAccess - ok 14:00:16.0656 5040 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:00:16.0656 5040 ShellHWDetection - ok 14:00:16.0750 5040 Simbad - ok 14:00:16.0843 5040 SkypeUpdate (17eab7852ff9f15fbaab4e95efc0b812) C:\Program Files\Skype\Updater\Updater.exe 14:00:17.0078 5040 SkypeUpdate - ok 14:00:17.0218 5040 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 14:00:17.0218 5040 SLIP - ok 14:00:17.0312 5040 SNDSrvc (443e397643965e08c5ab6a6caa732b97) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe 14:00:17.0328 5040 SNDSrvc - ok 14:00:17.0453 5040 SNP2UVC (1c550748f896e53b7b0fe7717845132b) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys 14:00:17.0500 5040 SNP2UVC - ok 14:00:17.0578 5040 Sparrow - ok 14:00:17.0734 5040 SPBBCDrv (c30fa11923892a4dbd1c747db8492e8f) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 14:00:17.0750 5040 SPBBCDrv - ok 14:00:17.0812 5040 SPBBCSvc (ea07435c72a8534c3a8e02d87246e546) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe 14:00:17.0843 5040 SPBBCSvc - ok 14:00:17.0984 5040 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 14:00:17.0984 5040 splitter - ok 14:00:18.0046 5040 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe 14:00:18.0046 5040 Spooler - ok 14:00:18.0093 5040 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 14:00:18.0093 5040 sr - ok 14:00:18.0125 5040 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll 14:00:18.0140 5040 srservice - ok 14:00:18.0203 5040 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 14:00:18.0203 5040 Srv - ok 14:00:18.0250 5040 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll 14:00:18.0265 5040 SSDPSRV - ok 14:00:18.0421 5040 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll 14:00:18.0437 5040 stisvc - ok 14:00:18.0484 5040 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 14:00:18.0500 5040 streamip - ok 14:00:18.0500 5040 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 14:00:18.0515 5040 swenum - ok 14:00:18.0562 5040 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 14:00:18.0578 5040 swmidi - ok 14:00:18.0593 5040 SwPrv - ok 14:00:18.0812 5040 Symantec AntiVirus (bc59bc3b68d45eb1716cc95e567a3b69) C:\Program Files\Symantec AntiVirus\Rtvscan.exe 14:00:18.0859 5040 Symantec AntiVirus - ok 14:00:18.0968 5040 symc810 - ok 14:00:18.0984 5040 symc8xx - ok 14:00:19.0093 5040 SymEvent (b3f8b9eab2ebe205c0fe053fba951d8c) C:\Program Files\Symantec\SYMEVENT.SYS 14:00:19.0109 5040 SymEvent - ok 14:00:19.0171 5040 SYMREDRV (7c73b65f1bdfab9052a5076c0ca622de) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 14:00:19.0187 5040 SYMREDRV - ok 14:00:19.0234 5040 SYMTDI (b4562798891dca27ed67ca07acbadbd9) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 14:00:19.0250 5040 SYMTDI - ok 14:00:19.0265 5040 sym_hi - ok 14:00:19.0265 5040 sym_u3 - ok 14:00:19.0328 5040 SynTP (cc5da243cfdac58fc0408f7ce24084c5) C:\WINDOWS\system32\DRIVERS\SynTP.sys 14:00:19.0343 5040 SynTP - ok 14:00:19.0484 5040 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 14:00:19.0500 5040 sysaudio - ok 14:00:19.0562 5040 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe 14:00:19.0578 5040 SysmonLog - ok 14:00:19.0609 5040 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll 14:00:19.0625 5040 TapiSrv - ok 14:00:19.0687 5040 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:00:19.0703 5040 Tcpip - ok 14:00:19.0828 5040 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 14:00:19.0843 5040 TDPIPE - ok 14:00:19.0859 5040 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 14:00:19.0875 5040 TDTCP - ok 14:00:19.0890 5040 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 14:00:19.0906 5040 TermDD - ok 14:00:19.0937 5040 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll 14:00:19.0968 5040 TermService - ok 14:00:20.0015 5040 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 14:00:20.0015 5040 Themes - ok 14:00:20.0156 5040 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe 14:00:20.0171 5040 TlntSvr - ok 14:00:20.0187 5040 TosIde - ok 14:00:20.0218 5040 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll 14:00:20.0218 5040 TrkWks - ok 14:00:20.0265 5040 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 14:00:20.0265 5040 Udfs - ok 14:00:20.0281 5040 ultra - ok 14:00:20.0343 5040 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 14:00:20.0359 5040 Update - ok 14:00:20.0390 5040 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll 14:00:20.0390 5040 upnphost - ok 14:00:20.0531 5040 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe 14:00:20.0531 5040 UPS - ok 14:00:20.0578 5040 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 14:00:20.0593 5040 USBAAPL - ok 14:00:20.0625 5040 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 14:00:20.0625 5040 usbaudio - ok 14:00:20.0687 5040 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 14:00:20.0687 5040 usbccgp - ok 14:00:20.0718 5040 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 14:00:20.0718 5040 usbehci - ok 14:00:20.0750 5040 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:00:20.0765 5040 usbhub - ok 14:00:20.0875 5040 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 14:00:20.0890 5040 usbohci - ok 14:00:20.0906 5040 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 14:00:20.0921 5040 usbprint - ok 14:00:20.0968 5040 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 14:00:20.0984 5040 usbscan - ok 14:00:21.0031 5040 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:00:21.0031 5040 USBSTOR - ok 14:00:21.0078 5040 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 14:00:21.0093 5040 usbvideo - ok 14:00:21.0265 5040 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 14:00:21.0265 5040 VgaSave - ok 14:00:21.0390 5040 ViaIde - ok 14:00:21.0453 5040 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 14:00:21.0453 5040 VolSnap - ok 14:00:21.0500 5040 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe 14:00:21.0531 5040 VSS - ok 14:00:21.0578 5040 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll 14:00:21.0593 5040 W32Time - ok 14:00:21.0625 5040 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:00:21.0625 5040 Wanarp - ok 14:00:21.0640 5040 WDICA - ok 14:00:21.0687 5040 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 14:00:21.0703 5040 wdmaud - ok 14:00:21.0750 5040 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll 14:00:21.0750 5040 WebClient - ok 14:00:21.0875 5040 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll 14:00:21.0890 5040 winmgmt - ok 14:00:21.0953 5040 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll 14:00:21.0953 5040 WmdmPmSN - ok 14:00:22.0046 5040 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll 14:00:22.0046 5040 Wmi - ok 14:00:22.0140 5040 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 14:00:22.0140 5040 WmiAcpi - ok 14:00:22.0234 5040 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe 14:00:22.0250 5040 WmiApSrv - ok 14:00:22.0406 5040 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe 14:00:22.0453 5040 WMPNetworkSvc - ok 14:00:22.0593 5040 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 14:00:22.0609 5040 WS2IFSL - ok 14:00:22.0671 5040 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll 14:00:22.0671 5040 wscsvc - ok 14:00:22.0718 5040 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 14:00:22.0734 5040 WSTCODEC - ok 14:00:22.0765 5040 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll 14:00:22.0796 5040 wuauserv - ok 14:00:22.0843 5040 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:00:22.0859 5040 WudfPf - ok 14:00:22.0968 5040 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 14:00:22.0984 5040 WudfRd - ok 14:00:23.0031 5040 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll 14:00:23.0031 5040 WudfSvc - ok 14:00:23.0093 5040 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll 14:00:23.0109 5040 WZCSVC - ok 14:00:23.0265 5040 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll 14:00:23.0296 5040 xmlprov - ok 14:00:23.0359 5040 yukonwxp (f20fc720f74a2533d70cea1f4458f3c8) C:\WINDOWS\system32\DRIVERS\yk51x86.sys 14:00:23.0375 5040 yukonwxp - ok 14:00:23.0421 5040 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 14:00:23.0609 5040 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 14:00:23.0609 5040 \Device\Harddisk0\DR0 - detected TDSS File System (1) 14:00:23.0609 5040 Boot (0x1200) (927980a18157eb24ef552ba60485eac7) \Device\Harddisk0\DR0\Partition0 14:00:23.0609 5040 \Device\Harddisk0\DR0\Partition0 - ok 14:00:23.0609 5040 ============================================================ 14:00:23.0609 5040 Scan finished 14:00:23.0609 5040 ============================================================ 14:00:23.0625 3016 Detected object count: 1 14:00:23.0625 3016 Actual detected object count: 1 14:01:15.0375 3016 \Device\Harddisk0\DR0\TDLFS\cfg.ini - copied to quarantine 14:01:15.0375 3016 \Device\Harddisk0\DR0\TDLFS\mbr - copied to quarantine 14:01:15.0406 3016 \Device\Harddisk0\DR0\TDLFS\bckfg.tmp - copied to quarantine 14:01:15.0453 3016 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 14:01:15.0812 3016 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 14:01:15.0828 3016 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 14:01:15.0843 3016 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 14:01:15.0890 3016 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 14:01:15.0906 3016 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 14:01:15.0937 3016 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 14:01:15.0953 3016 \Device\Harddisk0\DR0\TDLFS\keywords - copied to quarantine 14:01:15.0953 3016 \Device\Harddisk0\DR0\TDLFS - deleted 14:01:15.0953 3016 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
after running tddskiller, was unable to reboot normally. it automatically shutoff during reboot and had to restart using "last known good configuration"


ComboFix 12-04-01.01 - Big H 04/01/2012 14:18:49.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2302 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Big H\Application Data\FFSJ
c:\documents and settings\Big H\Application Data\FFSJ\FFSJ.cfg
c:\documents and settings\Big H\WINDOWS
C:\install.exe
c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-01 to 2012-04-01 )))))))))))))))))))))))))))))))
.
.
2012-04-01 21:01 . 2012-04-01 21:01 ——– d—–w- C:\TDSSKiller_Quarantine
2012-03-29 02:54 . 2012-04-01 21:11 ——– d—–w- c:\documents and settings\Big H\Application Data\Dropbox
2012-03-28 07:31 . 2012-03-28 07:31 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2012-03-28 07:10 . 2012-03-28 23:27 ——– d—–w- c:\documents and settings\Big H\Local Settings\Application Data\1Click DVD Copy Pro
2012-03-28 07:09 . 2012-03-28 23:28 ——– d—–w- c:\documents and settings\All Users\Application Data\1click dvd copy pro
2012-03-28 07:07 . 2012-03-28 07:07 ——– d—–w- c:\documents and settings\All Users\Application Data\LGSI
2012-03-28 07:07 . 2012-03-28 07:07 ——– d—–w- c:\program files\LG Software Innovations
2012-03-27 08:45 . 2012-03-27 08:45 388096 —-a-r- c:\documents and settings\Big H\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-27 08:45 . 2012-03-27 08:45 ——– d—–w- c:\program files\Trend Micro
2012-03-22 21:09 . 2012-03-22 21:09 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-22 21:09 . 2012-03-22 21:09 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-03-22 04:12 . 2012-03-22 06:57 ——– d—–w- c:\program files\JDownloader
2012-03-16 22:25 . 2012-04-01 02:14 ——– d—–w- c:\documents and settings\Big H\Application Data\IDM
2012-03-16 22:25 . 2012-03-16 22:25 ——– d—–w- c:\program files\Internet Download Manager
2012-03-14 22:17 . 2012-03-14 22:17 ——– d—–w- c:\program files\Common Files\Java
2012-03-14 21:01 . 2012-03-14 21:01 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-03-14 21:01 . 2012-03-14 21:01 ——– d—–w- c:\program files\Java
2012-03-13 04:05 . 2012-03-13 04:59 ——– d—–w- c:\documents and settings\Big H\Application Data\redsn0w
2012-03-13 03:26 . 2012-03-13 03:34 ——– d—–w- c:\documents and settings\Big H\.shsh
2012-03-12 23:55 . 2012-03-12 23:55 ——– d—–w- c:\documents and settings\Big H\Application Data\PlatinumHideIP
2012-03-12 23:55 . 2012-03-12 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\PlatinumHideIP
2012-03-12 23:49 . 2012-03-12 23:49 ——– d—–w- c:\program files\PlatinumHideIP
2012-03-12 15:36 . 2012-02-08 01:13 104456 —-a-w- c:\windows\system32\drivers\idmtdi.sys
2012-03-06 02:55 . 2012-03-06 02:55 ——– d—–w- c:\documents and settings\Big H\Application Data\SuperHideIP
2012-03-06 02:55 . 2012-03-06 02:55 ——– d—–w- c:\documents and settings\All Users\Application Data\SuperHideIP
2012-03-06 02:53 . 2012-03-06 02:53 ——– d—–w- c:\documents and settings\Big H\Local Settings\Application Data\APN
2012-03-06 01:41 . 2012-03-06 03:06 ——– d—–w- c:\program files\Quick Hide IP
2012-03-06 01:34 . 2010-12-24 03:00 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2012-03-06 01:34 . 2012-03-06 10:44 ——– d—–w- c:\documents and settings\Big H\Application Data\PPStream
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-26 21:41 . 2011-10-10 04:15 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-14 21:01 . 2011-12-30 03:30 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-02-03 09:22 . 2008-04-14 08:00 1860096 —-a-w- c:\windows\system32\win32k.sys
2012-01-11 19:06 . 2012-02-16 00:02 3072 ——w- c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2010-12-22 08:56 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-01-04 07:13 . 2012-01-04 07:12 94208 —-a-w- c:\windows\DUMPc6f9.tmp
2012-03-22 21:09 . 2011-10-10 04:10 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-09-05 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 —-a-w- c:\documents and settings\Big H\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 —-a-w- c:\documents and settings\Big H\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 —-a-w- c:\documents and settings\Big H\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 —-a-w- c:\documents and settings\Big H\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2012-02-08 00:49 22376 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"ISUSPM"="c:\documents and settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe" [2010-07-23 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 16132608]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2010-12-22 102400]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"AtiPTA"="atiptaxx.exe" [2006-02-22 344064]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-12-09 1226608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-06 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-16 499608]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-09-05 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-09-05 2904984]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\documents and settings\Big H\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Big H\Application Data\Dropbox\bin\Dropbox.exe [2012-2-14 24246216]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BDARemote.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BDARemote.lnk
backup=c:\windows\pss\BDARemote.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Big H^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Big H\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Big H\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Big H\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Big H\\Desktop\\Downloads\\iPhone Games\\tinyumbrella-5.10.07.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Big H\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"51001:TCP"= 51001:TCP:Dragon Smart Phone Server
.
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [12/22/2010 2:15 AM 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [12/22/2010 2:15 AM 35712]
R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [12/22/2010 3:36 AM 17952]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [10/31/2011 3:38 PM 232512]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [3/12/2012 8:36 AM 104456]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 4:38 PM 116608]
R2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [7/23/2010 1:24 PM 296808]
R3 EraserUtilDrv11122;EraserUtilDrv11122;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11122.sys [3/30/2012 8:04 PM 106104]
S2 Micro Niche Finder Background Download Service;Micro Niche Finder Background Download Service; [x]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [1/31/2012 4:09 PM 158856]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [4/17/2005 1:30 PM 124608]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; [x]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-562591055-1801674531-1003Core.job
- c:\documents and settings\Big H\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-22 10:09]
.
2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-562591055-1801674531-1003UA.job
- c:\documents and settings\Big H\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-22 10:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.11.1
FF - ProfilePath - c:\documents and settings\Big H\Application Data\Mozilla\Firefox\Profiles\fxcip6ed.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-SpeedUpMyPC - c:\program files\Uniblue\SpeedUpMyPC\launcher.exe
MSConfigStartUp-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
MSConfigStartUp-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
MSConfigStartUp-SSBkgdUpdate - c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\standard_1.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-01 14:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-583907252-562591055-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:bf,c0,c9,a6,9b,69,5e,d1,5f,ad,e1,5b,2a,a9,32,5c,e2,31,45,9f,f3,
4e,d0,ec,4c,24,d1,d6,89,6e,ce,99,84,ae,a5,ec,c1,5a,90,91,09,20,12,cc,16,1f,\
"rkeysecu"=hex:01,0a,02,14,5c,bb,eb,a2,15,a6,27,35,c9,83,df,62
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{543ffede-0b91-4249-b812-ece1738d1aeb}]
@Denied: (Full) (Everyone)
"Model"=dword:00000056
"Therad"=dword:0000001d
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):a1,45,ce,76,a3,01,a0,c4,73,fc,d5,43,11,70,95,80,a2,fe,c7,f6,dd,
62,54,93,b0,0b,95,0a,5f,07,8a,dd,54,ec,c0,4e,8d,ba,ad,b0,00,00,00,00,00,00,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1036)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-04-01 14:28:00
ComboFix-quarantined-files.txt 2012-04-01 21:27
.
Pre-Run: 31,554,433,024 bytes free
Post-Run: 31,953,448,960 bytes free
.
- - End Of File - - 61B4BD93E145E5B43EDA88391FAD1732
Hi,

Please run the following:

  • Click Start > Run… then type in CMD and click on OK.
  • At the Command Prompt C:\ > type the following: chkdsk c: /r and hit the Enter/Return key.
    Note: chkdsk c: /r presumes that the disk upon which you wish to run Error Checking is your C: Drive (most often)
  • When prompted with:

CHKDSK cannot run because the volume is in use by another process
Would you like to schedule this volume to be checked next time the system
restarts (Y/N)

  • Hit the Y key then at the Command Prompt C:\ >
  • Type in EXIT and and hit the Enter/Return key.
  • Now Reboot(Restart) your computer.
Note: Upon Reboot(Restart), CHKDSK will start and carry out the repairs required.


NEXT



Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.04.02.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Big H :: HYDRO [administrator] 4/1/2012 6:16:44 PM mbam-log-2012-04-01 (18-16-44).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 227561 Time elapsed: 6 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
esetscan.txt C:\System Volume Information\_restore{31E217E4-C6BB-49FC-85EA-11675B3EEF5F}\RP289\A0078360.exe a variant of MSIL/Solimba.B application
OK, That detection is in an old restore point, which we will be cleaning out shortly, How is the computer running now? Are there any outstanding issues?
Ok,

we just have some housekeeping to do, please do the following:


You can delete the TDSSKiller logs and program from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI