This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Recovery Virus -- (attempting to fully recover from !) [So

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I appreciate all patience and any further guidance in advance !
I am definitely a newbie with computers, but I have learned/taught myself lots pretty quickly.
There is a virus going around that has many names i.e. (Windows Recovery, Windows AntiVirus 2012) where all desktop icons are missing, startup menu is empty, administrative tools are empty, desktop background is blue, and constant windows are popping up saying there are 14 or more viruses found, and immediate action needs to be taken, and leads you to nothing but an order form screen…..

I have restored my desktop icons, and most of my startup menu, and administrative tools. System Recovery was not able to load/restore from any of the points chosen (I read this tool is disabled from this virus). I was able copy some of my programs shortcuts to the programs list, but I am still missing several tools/programs. I use Microsoft Security Essentials, and the Windows Malicious Software Removal Tool. Both have ran, and only MSE has came up with several viruses/trojans/etc, and removed them. I read from a previous blog titled "Trojan on my Computer [Solved]" on how to start the malware removal.
I was only able to download and run OTL.exe. The tool aswMBR.exe would download, but would not open. I tried "run as Administrator", disabling anti-virus/firewall, and renaming the application, but nothing would work.
Here are my attached OTL.txt and Extras.txt

OTL logfile created on: 6/30/2012 6:02:55 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Documents and Settings\Dan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.99% Memory free
3.84 Gb Paging File | 3.46 Gb Available in Paging File | 90.01% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.68 Gb Total Space | 19.71 Gb Free Space | 58.52% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DEHAHN | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dan\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NeroMediaHomeService.4) – C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero AG)
SRV - (pdfcDispatcher) – C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (tfsnudfa) – system32\dla\tfsnudfa.sys File not found
DRV - (tfsnudf) – system32\dla\tfsnudf.sys File not found
DRV - (tfsnpool) – system32\dla\tfsnpool.sys File not found
DRV - (tfsnopio) – system32\dla\tfsnopio.sys File not found
DRV - (tfsnifs) – system32\dla\tfsnifs.sys File not found
DRV - (tfsndres) – system32\dla\tfsndres.sys File not found
DRV - (tfsndrct) – system32\dla\tfsndrct.sys File not found
DRV - (tfsncofs) – system32\dla\tfsncofs.sys File not found
DRV - (tfsnboio) – system32\dla\tfsnboio.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MpKsld6d34de9) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{298A0275-4F3A-4DCB-95AE-321EED411A49}\MpKsld6d34de9.sys (Microsoft Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (BANTExt) – C:\WINDOWS\system32\drivers\BANTExt.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Blfp) – C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (cpqdfw) – C:\WINDOWS\system32\drivers\Cpqdfw.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/17 00:24:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/04/25 11:02:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Extensions
[2012/05/01 21:41:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\sc268k5v.default\extensions
[2012/06/13 22:08:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/04/26 23:31:06 | 000,413,408 | —- | M] () (No name found) – C:\DOCUMENTS AND SETTINGS\DAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SC268K5V.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
[2012/04/26 10:05:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/06/17 00:24:22 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/04/20 20:18:25 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/20 20:18:25 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2008/08/21 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DKgPKMxgvSnGH.exe] C:\Documents and Settings\All Users\Application Data\DKgPKMxgvSnGH.exe File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Nero MediaHome 4] C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe ()
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: spywarehelpcenter.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1580818891-1644491937-1003\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{709D542D-75D9-4D22-AB96-42A9DA690C8C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/23 22:54:07 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/30 17:55:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/29 11:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Local Settings\Application Data\Identities
[2012/06/28 20:24:37 | 016,208,824 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/28 12:21:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Apple Software Update
[2012/06/28 12:19:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Analog Devices
[2012/06/28 12:13:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Adobe
[2012/06/28 12:11:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Xvid
[2012/06/28 12:09:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Windows Media Player
[2012/06/28 12:05:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Application Data\Nero
[2012/06/28 12:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\PDF Complete
[2012/06/28 11:54:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Mozilla Firefox
[2012/06/28 11:53:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Movie Maker
[2012/06/28 11:46:22 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Games
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\SoundMAX
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Sonic
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\QuickTime
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Nero
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Silverlight
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Microsoft Office
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\iTunes
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\EPSON
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\Broadcom
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Print Creations
[2012/06/28 11:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Dan\Start Menu\Programs\ArcSoft Connect
[2012/06/27 18:30:21 | 000,000,000 | R–D | C] – C:\Documents and Settings\Dan\Recent
[2012/06/26 20:27:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Local Settings
[2012/06/25 00:00:17 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2012/06/14 12:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/14 12:00:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/12 21:01:52 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012/05/09 01:08:31 | 006,955,968 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.exe
[2012/04/26 10:04:03 | 000,908,576 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 11:35:23 | 006,674,008 | —- | C] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/04/25 10:38:50 | 010,288,512 | —- | C] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe
[2012/06/30 17:15:16 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/06/30 17:04:03 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/06/30 16:58:25 | 000,552,080 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/30 16:58:25 | 000,104,212 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/30 16:54:45 | 000,013,726 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/30 16:53:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/28 20:24:44 | 016,208,824 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Dan\My Documents\Windows-KB890830-V4.9.exe
[2012/06/27 22:24:05 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/27 22:07:04 | 000,000,831 | —- | M] () – C:\WINDOWS\Cpqdiag.ini
[2012/06/26 22:13:25 | 000,196,960 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/23 09:15:13 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/06/23 09:15:13 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/06/21 07:27:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/14 12:02:35 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/12 21:21:42 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/02 15:19:44 | 000,022,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll.mui
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wucltui.dll
[2012/06/02 15:19:38 | 000,329,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wucltui.dll
[2012/06/02 15:19:38 | 000,219,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2012/06/02 15:19:38 | 000,210,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuweb.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cdm.dll
[2012/06/02 15:19:34 | 000,097,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cdm.dll
[2012/06/02 15:19:34 | 000,053,784 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuauclt.exe
[2012/06/02 15:19:34 | 000,045,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups2.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wups.dll
[2012/06/02 15:19:34 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wups.dll
[2012/06/02 15:19:34 | 000,015,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll
[2012/06/02 15:19:24 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuapi.dll
[2012/06/02 15:19:18 | 001,933,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wuaueng.dll
[2012/06/02 15:18:58 | 000,275,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2012/06/02 15:18:58 | 000,017,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/30 16:49:04 | 000,654,920 | —- | C] () – C:\Documents and Settings\Dan\My Documents\mtinst.exe
[2012/06/27 22:23:40 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/06/14 12:02:35 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/05/15 00:21:28 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2012/05/09 09:48:32 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2012/05/09 09:48:32 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2012/05/07 00:05:55 | 000,004,608 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/26 11:34:57 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2012/04/26 11:34:57 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2012/04/26 11:34:57 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2012/04/26 11:34:57 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2012/04/26 11:34:57 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2012/04/26 11:34:57 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2012/04/26 11:34:57 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2012/04/26 11:34:57 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2012/04/26 11:34:57 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2012/04/26 11:34:57 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2012/04/26 11:34:57 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2012/04/26 11:34:57 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2012/04/26 11:34:57 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2012/04/26 11:34:57 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2012/04/26 11:33:26 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSNX400.ini
[2012/04/26 11:01:04 | 000,001,807 | —- | C] () – C:\WINDOWS\ACT_CFG.INI
[2012/04/26 11:00:52 | 000,019,845 | —- | C] () – C:\WINDOWS\System32\drivers\Cpqdfw.sys
[2012/04/26 11:00:52 | 000,000,831 | —- | C] () – C:\WINDOWS\Cpqdiag.ini
[2012/04/26 10:32:30 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2012/04/26 01:41:10 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2012/04/26 01:41:09 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2012/04/26 01:40:23 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2012/04/26 01:40:22 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2012/04/26 01:40:20 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2012/04/25 23:00:25 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2012/04/25 09:47:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/04/24 00:25:07 | 000,000,664 | —- | C] () – C:\Documents and Settings\Dan\Local Settings\Application Data\FASTWiz.html
[2012/04/24 00:11:45 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2012/04/23 22:51:04 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2012/04/23 17:42:32 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2012/04/22 18:44:52 | 000,196,960 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2012/04/26 11:34:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2012/06/30 00:53:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PDFC
[2012/05/07 22:06:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/27 10:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\EPSON
[2012/04/26 11:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Leadertech
[2012/04/26 20:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\SystemRequirementsLab
[2012/04/26 00:10:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Desktop Search
[2012/04/26 00:32:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2012/04/23 22:48:49 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012/04/23 22:54:07 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/04/23 22:54:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/06/30 16:53:50 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2012/04/23 22:53:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2012/04/24 01:03:41 | 000,001,722 | —- | M] () – C:\Documents and Settings\Dan\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2012/04/26 10:04:11 | 000,908,576 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\jxpiinstall.exe
[2012/04/25 10:39:01 | 010,288,512 | —- | M] (Microsoft Corporation) – C:\Program Files\mseinstall.exe
[2012/04/25 11:35:35 | 006,674,008 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Shockwave_Installer_Slim.exe
[2012/05/09 01:08:43 | 006,955,968 | —- | M] (Microsoft Corporation) – C:\Program Files\Silverlight.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2012/04/22 18:42:56 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012/04/22 18:42:56 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012/04/22 18:42:56 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2012/06/30 17:55:45 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Dan\Desktop\aswMBR.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 02:35:31

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp
[2012/06/27 09:50:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\1
[2012/06/27 10:25:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Dan\..\Dan\Local Settings\Temp\smtmp\2

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/08/21 07:00:00 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/06/30 17:25:31 | 000,018,630 | —- | M] () MD5=26F0EE6F9D37AB1D128C88CC21F9A52D – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SCF >
[2008/08/21 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/08/21 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/08/21 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -HS- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.HLP >
[2008/08/21 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/08/21 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\mspaint.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\b57xp32.sys:SummaryInformation

< End of report >

wasn't sure if the following full log would fit into that thread
here is the Extras.txt log from OTL.exe

OTL Extras logfile created on: 6/30/2012 6:02:55 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:Documents and SettingsDanMy DocumentsDownloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.99% Memory free
3.84 Gb Paging File | 3.46 Gb Available in Paging File | 90.01% Paging File free
Paging file location(s): C:pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 33.68 Gb Total Space | 19.71 Gb Free Space | 58.52% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DEHAHN | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERSS-1-5-21-329068152-1580818891-1644491937-1003SOFTWAREClasses]
.html [@ = FirefoxHTML] – C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyDomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyDomainProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyStandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22009
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyDomainProfileAuthorizedApplicationsList]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewall
PolicyStandardProfileAuthorizedApplicationsList]
"C:Program FilesNeroNero MediaHome 4NMMediaServerService.exe" = C:Program FilesNeroNero MediaHome 4NMMediaServerService.exe:*:Enabled:Nero MediaHome 4 – (Nero AG)
"C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe" = C:Program FilesCommon FilesAppleApple Application SupportWebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE" = C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{1881AE03-2BD4-11D4-86BF-00508B10AA88}" = Diagnostics for Windows
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2D62916C-976C-4425-8833-8814D9A7A54D}" = ArcSoft Print Creations
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{69fc3b9a-4149-43db-a557-6ed0c8d8ba44}" = Nero MediaHome 4 Help
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BB045C3-D5E4-4620-B536-DC11AACD5942}" = Broadcom Management Programs
"{7edf3c86-9878-45d4-86d5-1ec5bb73c8f2}" = Nero MediaHome 4 Essentials
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{99ef387e-633e-4cfb-bfa3-ab961b685ddf}" = Nero MediaHome 4
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EEA0E169-D256-4CD4-8F70-30D9B8F900F7}" = HP Client Management Interface Utilities
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0A55445-B637-4CEA-A580-A8FC6954130D}" = HP Client Management Interface Providers
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F5242227-2051-4158-AC42-0F2BAA3CD3D6}" = HP SetRefresh
"{F870B987-18BC-45FC-9BE8-35C02DCDA10F}" = Broadcom NetXtreme Ethernet Controller
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Belarc Advisor" = Belarc Advisor 8.2
"EPSON Scanner" = EPSON Scan
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"PDF Complete" = PDF Complete Special Edition
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid Video Codec 1.3.2" = Xvid Video Codec

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 2:45:04 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module shell32.dll, version 6.0.2900.6072, fault address 0x0002f0ee.
Error - 6/28/2012 2:45:13 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3009

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3009

Error - 6/28/2012 9:32:42 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module iertutil.dll, version 8.0.6001.19258, fault address 0x0011a67c.

Error - 6/28/2012 11:15:20 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/29/2012 10:15:02 AM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/30/2012 6:15:17 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

[ Application Events ]
Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 2:45:04 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module shell32.dll, version 6.0.2900.6072, fault address 0x0002f0ee.
Error - 6/28/2012 2:45:13 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3009

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3009

Error - 6/28/2012 9:32:42 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module iertutil.dll, version 8.0.6001.19258, fault address 0x0011a67c.

Error - 6/28/2012 11:15:20 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/29/2012 10:15:02 AM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/30/2012 6:15:17 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

[ Application Events ]
Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 1:54:25 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 2:45:04 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module shell32.dll, version 6.0.2900.6072, fault address 0x0002f0ee.
Error - 6/28/2012 2:45:13 AM | Computer Name = DEHAHN | Source = Application Error
| ID = 1000

Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 2:52:16 AM | Computer Name = DEHAHN | Source = LoadPerf | ID =
3009

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3013
Description = Unable to update the performance counter strings of the 009 language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 6/28/2012 11:59:27 AM | Computer Name = DEHAHN | Source = LoadPerf | ID = 3009
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3013

Description = Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error - 6/28/2012 12:02:11 PM | Computer Name = DEHAHN | Source = LoadPerf | ID
= 3009

Error - 6/28/2012 9:32:42 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module iertutil.dll, version 8.0.6001.19258, fault address 0x0011a67c.

Error - 6/28/2012 11:15:20 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/29/2012 10:15:02 AM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

Error - 6/30/2012 6:15:17 PM | Computer Name = DEHAHN | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.3.300.262,
faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x000113c0.

[ System Events ]
Error - 6/30/2012 5:00:44 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:00 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:10 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:16 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7034
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 3 time(s).

Error - 6/30/2012 5:20:48 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

Error - 6/30/2012 5:24:37 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:42 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:44 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:50 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7034
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 3 time(s).

Error - 6/30/2012 5:54:40 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

[ System Events ]
Error - 6/30/2012 5:00:44 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:00 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:10 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:01:16 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7034
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 3 time(s).

Error - 6/30/2012 5:20:48 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

Error - 6/30/2012 5:24:37 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:42 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:44 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7031
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 1 milliseconds:
Restart the service.

Error - 6/30/2012 5:24:50 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7034
Description = The Nero MediaHome 4 Service service terminated unexpectedly. It
has done this 3 time(s).

Error - 6/30/2012 5:54:40 PM | Computer Name = DEHAHN | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt


< End of report >

and again, thank you !
Hello, I Am Alander :)

Welcome to the Malware Removal forums.

I would be glad to take a look at your log and help you with solving any malware problems.

Logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Do not make any further changes to your machines (i.e. uninstall a program, run any other tools, attempt a system restore) without a helper instruction as it will hinder the malware removal process
  • Please reply to this thread. Do not start a new topic.
Hello Alander, I look forward to working with you. I appreciate your patience with my inexperience as well, in advance. noob_dan
Step 1
TDSSKiller - Rootkit Removal Tool
Please download the TDSSKiller.exe by Kaspersky… save it to your Desktop. <-Important!!!
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista - W7 users: Right-click and select "Run As Administrator".
    If TDSSKiller does not run… rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com). If you don't see file extensions, please see: How to change the file extension.
  • Click the Start Scan button. Do not use the computer during the scan!
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.
    • Ensure SKIP is selected… DO NOT attempt to FIX anything yet!
    • Now click on Report to open the log file created by TDSSKiller in your root directory C:\
  • A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the root directory. (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

Step 2
Upload File/Files for testing

Please go to Virustotal

Copy/paste this file and path into the white box at the top:

C:\Documents and Settings\All Users\Application Data\DKgPKMxgvSnGH.exe
C:\WINDOWS\System32\msssc.dll
C:\WINDOWS\imsins.BAK

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the permalink (web address) in your next response.
Example of web address :
[external image: Posted Image]
Repeat for each of the files if present, you should come back with 3 perma links, please report back if files are not present
20:40:10.0437 3368 TDSS rootkit removing tool [removed] Jul 2 2012 20:01:08 20:40:10.0812 3368 ============================================================ 20:40:10.0812 3368 Current date / time: 2012/07/05 20:40:10.0812 20:40:10.0812 3368 SystemInfo: 20:40:10.0812 3368 20:40:10.0812 3368 OS Version: 5.1.2600 ServicePack: 3.0 20:40:10.0812 3368 Product type: Workstation 20:40:10.0812 3368 ComputerName: DEHAHN 20:40:10.0812 3368 UserName: Dan 20:40:10.0812 3368 Windows directory: C:\WINDOWS 20:40:10.0812 3368 System windows directory: C:\WINDOWS 20:40:10.0812 3368 Processor architecture: Intel x86 20:40:10.0812 3368 Number of processors: 2 20:40:10.0812 3368 Page size: 0x1000 20:40:10.0812 3368 Boot type: Normal boot 20:40:10.0812 3368 ============================================================ 20:40:14.0687 3368 Drive \Device\Harddisk0\DR0 - Size: 0x9502F9000 (37.25 Gb), SectorSize: 0x200, Cylinders: 0x12FF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:40:14.0687 3368 ============================================================ 20:40:14.0687 3368 \Device\Harddisk0\DR0: 20:40:14.0687 3368 MBR partitions: 20:40:14.0687 3368 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1F608, BlocksNum 0x435D8ED 20:40:14.0687 3368 ============================================================ 20:40:14.0734 3368 C: <-> \Device\Harddisk0\DR0\Partition0 20:40:14.0734 3368 ============================================================ 20:40:14.0734 3368 Initialize success 20:40:14.0734 3368 ============================================================ 20:40:19.0421 1972 ============================================================ 20:40:19.0421 1972 Scan started 20:40:19.0421 1972 Mode: Manual; 20:40:19.0421 1972 ============================================================ 20:40:19.0921 1972 Abiosdsk - ok 20:40:19.0921 1972 abp480n5 - ok 20:40:20.0062 1972 ACDaemon (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 20:40:20.0062 1972 ACDaemon - ok 20:40:20.0140 1972 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:40:20.0156 1972 ACPI - ok 20:40:20.0203 1972 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 20:40:20.0218 1972 ACPIEC - ok 20:40:20.0312 1972 AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 20:40:20.0312 1972 AdobeFlashPlayerUpdateSvc - ok 20:40:20.0328 1972 adpu160m - ok 20:40:20.0375 1972 aeaudio (3cb6ae5435987b1f8c83fd2730479878) C:\WINDOWS\system32\drivers\aeaudio.sys 20:40:20.0421 1972 aeaudio - ok 20:40:20.0453 1972 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 20:40:20.0500 1972 aec - ok 20:40:20.0546 1972 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 20:40:20.0562 1972 AFD - ok 20:40:20.0562 1972 Aha154x - ok 20:40:20.0562 1972 aic78u2 - ok 20:40:20.0578 1972 aic78xx - ok 20:40:20.0593 1972 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll 20:40:20.0625 1972 Alerter - ok 20:40:20.0656 1972 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe 20:40:20.0703 1972 ALG - ok 20:40:20.0703 1972 AliIde - ok 20:40:20.0703 1972 amsint - ok 20:40:20.0781 1972 Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:40:20.0796 1972 Apple Mobile Device - ok 20:40:20.0843 1972 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll 20:40:20.0890 1972 AppMgmt - ok 20:40:20.0890 1972 asc - ok 20:40:20.0890 1972 asc3350p - ok 20:40:20.0890 1972 asc3550 - ok 20:40:21.0031 1972 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 20:40:21.0031 1972 aspnet_state - ok 20:40:21.0062 1972 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:40:21.0093 1972 AsyncMac - ok 20:40:21.0125 1972 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 20:40:21.0125 1972 atapi - ok 20:40:21.0125 1972 Atdisk - ok 20:40:21.0156 1972 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:40:21.0203 1972 Atmarpc - ok 20:40:21.0250 1972 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll 20:40:21.0281 1972 AudioSrv - ok 20:40:21.0328 1972 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 20:40:21.0328 1972 audstub - ok 20:40:21.0406 1972 b57w2k (6f7911f3e674363a91541e097f49b633) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 20:40:21.0500 1972 b57w2k - ok 20:40:21.0546 1972 BANTExt (5d7be7b19e827125e016325334e58ff1) C:\WINDOWS\System32\Drivers\BANTExt.sys 20:40:21.0562 1972 BANTExt - ok 20:40:21.0593 1972 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 20:40:21.0625 1972 Beep - ok 20:40:21.0687 1972 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll 20:40:21.0750 1972 BITS - ok 20:40:21.0812 1972 Blfp (9b53d428de0a2566a03499d7aa48dec4) C:\WINDOWS\system32\DRIVERS\baspxp32.sys 20:40:21.0859 1972 Blfp - ok 20:40:21.0921 1972 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 20:40:21.0953 1972 Bonjour Service - ok 20:40:22.0015 1972 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll 20:40:22.0046 1972 Browser - ok 20:40:22.0078 1972 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 20:40:22.0093 1972 cbidf2k - ok 20:40:22.0093 1972 cd20xrnt - ok 20:40:22.0125 1972 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 20:40:22.0171 1972 Cdaudio - ok 20:40:22.0203 1972 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 20:40:22.0203 1972 Cdfs - ok 20:40:22.0265 1972 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:40:22.0312 1972 Cdrom - ok 20:40:22.0312 1972 Changer - ok 20:40:22.0328 1972 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe 20:40:22.0359 1972 CiSvc - ok 20:40:22.0375 1972 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe 20:40:22.0406 1972 ClipSrv - ok 20:40:22.0546 1972 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:40:22.0546 1972 clr_optimization_v2.0.50727_32 - ok 20:40:22.0625 1972 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:40:22.0640 1972 clr_optimization_v4.0.30319_32 - ok 20:40:22.0640 1972 CmdIde - ok 20:40:22.0640 1972 COMSysApp - ok 20:40:22.0656 1972 Cpqarray - ok 20:40:22.0687 1972 cpqdfw (817bec5f328518290ac42821ec3922cb) C:\WINDOWS\system32\drivers\cpqdfw.sys 20:40:22.0718 1972 cpqdfw - ok 20:40:22.0765 1972 cpudrv (d01f685f8b4598d144b0cce9ff95d8d5) C:\Program Files\SystemRequirementsLab\cpudrv.sys 20:40:22.0796 1972 cpudrv - ok 20:40:22.0796 1972 cqcpu (be43d9c71508cb4116cb56979d1ce820) C:\WINDOWS\system32\drivers\cqcpu.sys 20:40:22.0828 1972 cqcpu - ok 20:40:22.0843 1972 cq_mem (cd6364f3acb9b2094ab60671806a5b9c) C:\WINDOWS\system32\drivers\cq_mem.sys 20:40:22.0859 1972 cq_mem - ok 20:40:22.0890 1972 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll 20:40:22.0921 1972 CryptSvc - ok 20:40:22.0921 1972 dac2w2k - ok 20:40:22.0937 1972 dac960nt - ok 20:40:23.0015 1972 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 20:40:23.0031 1972 DcomLaunch - ok 20:40:23.0078 1972 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll 20:40:23.0078 1972 Dhcp - ok 20:40:23.0125 1972 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 20:40:23.0125 1972 Disk - ok 20:40:23.0125 1972 dmadmin - ok 20:40:23.0218 1972 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 20:40:23.0296 1972 dmboot - ok 20:40:23.0343 1972 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 20:40:23.0343 1972 dmio - ok 20:40:23.0359 1972 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 20:40:23.0359 1972 dmload - ok 20:40:23.0390 1972 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll 20:40:23.0406 1972 dmserver - ok 20:40:23.0453 1972 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 20:40:23.0484 1972 DMusic - ok 20:40:23.0515 1972 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll 20:40:23.0531 1972 Dnscache - ok 20:40:23.0562 1972 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll 20:40:23.0609 1972 Dot3svc - ok 20:40:23.0609 1972 dpti2o - ok 20:40:23.0640 1972 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 20:40:23.0656 1972 drmkaud - ok 20:40:23.0703 1972 drvmcdb (b15f9e526ba511a48b1b1b8537815740) C:\WINDOWS\system32\drivers\drvmcdb.sys 20:40:23.0703 1972 drvmcdb - ok 20:40:23.0703 1972 drvnddm (fa4670cae95ae2bb857c68e535661145) C:\WINDOWS\system32\drivers\drvnddm.sys 20:40:23.0718 1972 drvnddm - ok 20:40:23.0750 1972 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll 20:40:23.0781 1972 EapHost - ok 20:40:23.0812 1972 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll 20:40:23.0828 1972 ERSvc - ok 20:40:23.0875 1972 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 20:40:23.0875 1972 Eventlog - ok 20:40:23.0937 1972 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll 20:40:23.0953 1972 EventSystem - ok 20:40:24.0000 1972 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 20:40:24.0015 1972 Fastfat - ok 20:40:24.0093 1972 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 20:40:24.0093 1972 FastUserSwitchingCompatibility - ok 20:40:24.0125 1972 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 20:40:24.0156 1972 Fdc - ok 20:40:24.0171 1972 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 20:40:24.0203 1972 Fips - ok 20:40:24.0218 1972 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 20:40:24.0234 1972 Flpydisk - ok 20:40:24.0281 1972 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 20:40:24.0281 1972 FltMgr - ok 20:40:24.0437 1972 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 20:40:24.0437 1972 FontCache3.0.0.0 - ok 20:40:24.0468 1972 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:40:24.0484 1972 Fs_Rec - ok 20:40:24.0531 1972 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:40:24.0531 1972 Ftdisk - ok 20:40:24.0578 1972 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 20:40:24.0578 1972 GEARAspiWDM - ok 20:40:24.0578 1972 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:40:24.0609 1972 Gpc - ok 20:40:24.0703 1972 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 20:40:24.0734 1972 helpsvc - ok 20:40:24.0750 1972 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll 20:40:24.0765 1972 HidServ - ok 20:40:24.0796 1972 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:40:24.0812 1972 hidusb - ok 20:40:24.0843 1972 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll 20:40:24.0906 1972 hkmsvc - ok 20:40:24.0906 1972 hpn - ok 20:40:24.0953 1972 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 20:40:24.0953 1972 HTTP - ok 20:40:25.0000 1972 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll 20:40:25.0031 1972 HTTPFilter - ok 20:40:25.0031 1972 i2omgmt - ok 20:40:25.0031 1972 i2omp - ok 20:40:25.0078 1972 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 20:40:25.0109 1972 i8042prt - ok 20:40:25.0250 1972 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 20:40:25.0296 1972 ialm - ok 20:40:25.0515 1972 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 20:40:25.0562 1972 idsvc - ok 20:40:25.0687 1972 IISADMIN (db3c22745c0da4666f3be31f1af36b2f) C:\WINDOWS\system32\inetsrv\inetinfo.exe 20:40:25.0734 1972 IISADMIN - ok 20:40:25.0812 1972 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 20:40:25.0843 1972 Imapi - ok 20:40:25.0890 1972 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe 20:40:25.0890 1972 ImapiService - ok 20:40:25.0906 1972 ini910u - ok 20:40:25.0953 1972 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 20:40:25.0953 1972 IntelIde - ok 20:40:25.0984 1972 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:40:26.0015 1972 intelppm - ok 20:40:26.0031 1972 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 20:40:26.0062 1972 Ip6Fw - ok 20:40:26.0078 1972 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:40:26.0109 1972 IpFilterDriver - ok 20:40:26.0125 1972 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:40:26.0140 1972 IpInIp - ok 20:40:26.0187 1972 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:40:26.0218 1972 IpNat - ok 20:40:26.0359 1972 iPod Service (e6be7a41a28d8f2db174957454d32448) C:\Program Files\iPod\bin\iPodService.exe 20:40:26.0421 1972 iPod Service - ok 20:40:26.0484 1972 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:40:26.0531 1972 IPSec - ok 20:40:26.0546 1972 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 20:40:26.0578 1972 IRENUM - ok 20:40:26.0609 1972 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:40:26.0625 1972 isapnp - ok 20:40:26.0687 1972 JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Program Files\Java\jre6\bin\jqs.exe 20:40:26.0687 1972 JavaQuickStarterService - ok 20:40:26.0703 1972 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:40:26.0734 1972 Kbdclass - ok 20:40:26.0750 1972 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 20:40:26.0765 1972 kbdhid - ok 20:40:26.0812 1972 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 20:40:26.0812 1972 kmixer - ok 20:40:26.0859 1972 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 20:40:26.0859 1972 KSecDD - ok 20:40:26.0906 1972 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll 20:40:26.0921 1972 LanmanServer - ok 20:40:26.0984 1972 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll 20:40:26.0984 1972 lanmanworkstation - ok 20:40:26.0984 1972 lbrtfdc - ok 20:40:27.0031 1972 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll 20:40:27.0046 1972 LmHosts - ok 20:40:27.0078 1972 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll 20:40:27.0109 1972 Messenger - ok 20:40:27.0140 1972 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 20:40:27.0156 1972 mnmdd - ok 20:40:27.0187 1972 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe 20:40:27.0250 1972 mnmsrvc - ok 20:40:27.0265 1972 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 20:40:27.0296 1972 Modem - ok 20:40:27.0312 1972 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:40:27.0343 1972 Mouclass - ok 20:40:27.0375 1972 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 20:40:27.0390 1972 mouhid - ok 20:40:27.0421 1972 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 20:40:27.0421 1972 MountMgr - ok 20:40:27.0484 1972 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 20:40:27.0484 1972 MozillaMaintenance - ok 20:40:27.0531 1972 MpFilter (d993bea500e7382dc4e760bf4f35efcb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 20:40:27.0531 1972 MpFilter - ok 20:40:27.0671 1972 MpKslddfdbd04 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4441669E-CED3-44FA-AFE3-DEC6286A4A08}\MpKslddfdbd04.sys 20:40:27.0671 1972 MpKslddfdbd04 - ok 20:40:27.0687 1972 mraid35x - ok 20:40:27.0718 1972 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:40:27.0734 1972 MRxDAV - ok 20:40:27.0812 1972 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:40:27.0828 1972 MRxSmb - ok 20:40:27.0890 1972 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe 20:40:27.0906 1972 MSDTC - ok 20:40:27.0937 1972 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 20:40:27.0937 1972 Msfs - ok 20:40:27.0953 1972 MSIServer - ok 20:40:27.0984 1972 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:40:28.0000 1972 MSKSSRV - ok 20:40:28.0062 1972 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) c:\Program Files\Microsoft Security Client\MsMpEng.exe 20:40:28.0062 1972 MsMpSvc - ok 20:40:28.0109 1972 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:40:28.0125 1972 MSPCLOCK - ok 20:40:28.0140 1972 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 20:40:28.0156 1972 MSPQM - ok 20:40:28.0187 1972 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:40:28.0218 1972 mssmbios - ok 20:40:28.0265 1972 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 20:40:28.0265 1972 Mup - ok 20:40:28.0328 1972 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll 20:40:28.0390 1972 napagent - ok 20:40:28.0421 1972 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 20:40:28.0421 1972 NDIS - ok 20:40:28.0468 1972 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:40:28.0468 1972 NdisTapi - ok 20:40:28.0531 1972 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:40:28.0546 1972 Ndisuio - ok 20:40:28.0578 1972 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:40:28.0640 1972 NdisWan - ok 20:40:28.0671 1972 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 20:40:28.0671 1972 NDProxy - ok 20:40:28.0765 1972 NeroMediaHomeService.4 (b6eb664bd5e25413e730bcb54cf64272) C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe 20:40:28.0765 1972 NeroMediaHomeService.4 - ok 20:40:28.0812 1972 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 20:40:28.0812 1972 NetBIOS - ok 20:40:28.0828 1972 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 20:40:28.0875 1972 NetBT - ok 20:40:28.0937 1972 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 20:40:29.0015 1972 NetDDE - ok 20:40:29.0015 1972 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 20:40:29.0015 1972 NetDDEdsdm - ok 20:40:29.0046 1972 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 20:40:29.0046 1972 Netlogon - ok 20:40:29.0109 1972 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll 20:40:29.0109 1972 Netman - ok 20:40:29.0265 1972 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 20:40:29.0265 1972 NetTcpPortSharing - ok 20:40:29.0312 1972 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll 20:40:29.0328 1972 Nla - ok 20:40:29.0375 1972 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 20:40:29.0375 1972 Npfs - ok 20:40:29.0468 1972 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 20:40:29.0484 1972 Ntfs - ok 20:40:29.0484 1972 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 20:40:29.0484 1972 NtLmSsp - ok 20:40:29.0546 1972 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll 20:40:29.0625 1972 NtmsSvc - ok 20:40:29.0656 1972 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 20:40:29.0671 1972 Null - ok 20:40:29.0718 1972 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:40:29.0734 1972 NwlnkFlt - ok 20:40:29.0734 1972 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:40:29.0765 1972 NwlnkFwd - ok 20:40:29.0875 1972 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:40:29.0875 1972 ose - ok 20:40:30.0250 1972 osppsvc (358a9cca612c68eb2f07ddad4ce1d8d7) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 20:40:30.0390 1972 osppsvc - ok 20:40:30.0515 1972 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 20:40:30.0578 1972 Parport - ok 20:40:30.0609 1972 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 20:40:30.0609 1972 PartMgr - ok 20:40:30.0656 1972 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 20:40:30.0671 1972 ParVdm - ok 20:40:30.0703 1972 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 20:40:30.0703 1972 PCI - ok 20:40:30.0703 1972 PCIDump - ok 20:40:30.0718 1972 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\drivers\PCIIde.sys 20:40:30.0718 1972 PCIIde - ok 20:40:30.0765 1972 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 20:40:30.0796 1972 Pcmcia - ok 20:40:30.0796 1972 PDCOMP - ok 20:40:30.0859 1972 pdfcDispatcher - ok 20:40:30.0859 1972 PDFRAME - ok 20:40:30.0875 1972 PDRELI - ok 20:40:30.0875 1972 PDRFRAME - ok 20:40:30.0875 1972 perc2 - ok 20:40:30.0890 1972 perc2hib - ok 20:40:30.0937 1972 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 20:40:30.0937 1972 PlugPlay - ok 20:40:30.0953 1972 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 20:40:30.0968 1972 PolicyAgent - ok 20:40:31.0000 1972 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:40:31.0031 1972 PptpMiniport - ok 20:40:31.0031 1972 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 20:40:31.0031 1972 ProtectedStorage - ok 20:40:31.0046 1972 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 20:40:31.0093 1972 PSched - ok 20:40:31.0125 1972 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:40:31.0140 1972 Ptilink - ok 20:40:31.0171 1972 PxHelp20 (30cbae0a34359f1cd19d1576245149ed) C:\WINDOWS\system32\Drivers\PxHelp20.sys 20:40:31.0171 1972 PxHelp20 - ok 20:40:31.0187 1972 ql1080 - ok 20:40:31.0187 1972 Ql10wnt - ok 20:40:31.0187 1972 ql12160 - ok 20:40:31.0203 1972 ql1240 - ok 20:40:31.0203 1972 ql1280 - ok 20:40:31.0218 1972 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:40:31.0218 1972 RasAcd - ok 20:40:31.0250 1972 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll 20:40:31.0281 1972 RasAuto - ok 20:40:31.0312 1972 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:40:31.0343 1972 Rasl2tp - ok 20:40:31.0390 1972 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll 20:40:31.0453 1972 RasMan - ok 20:40:31.0453 1972 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:40:31.0484 1972 RasPppoe - ok 20:40:31.0500 1972 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 20:40:31.0515 1972 Raspti - ok 20:40:31.0562 1972 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:40:31.0562 1972 Rdbss - ok 20:40:31.0562 1972 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:40:31.0578 1972 RDPCDD - ok 20:40:31.0640 1972 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 20:40:31.0640 1972 rdpdr - ok 20:40:31.0687 1972 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys 20:40:31.0687 1972 RDPWD - ok 20:40:31.0750 1972 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe 20:40:31.0812 1972 RDSessMgr - ok 20:40:31.0843 1972 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 20:40:31.0875 1972 redbook - ok 20:40:31.0921 1972 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll 20:40:31.0953 1972 RemoteAccess - ok 20:40:32.0000 1972 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll 20:40:32.0015 1972 RemoteRegistry - ok 20:40:32.0062 1972 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe 20:40:32.0109 1972 RpcLocator - ok 20:40:32.0156 1972 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 20:40:32.0171 1972 RpcSs - ok 20:40:32.0203 1972 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 20:40:32.0250 1972 RSVP - ok 20:40:32.0281 1972 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 20:40:32.0281 1972 SamSs - ok 20:40:32.0328 1972 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe 20:40:32.0375 1972 SCardSvr - ok 20:40:32.0437 1972 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll 20:40:32.0484 1972 Schedule - ok 20:40:32.0500 1972 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:40:32.0531 1972 Secdrv - ok 20:40:32.0562 1972 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll 20:40:32.0593 1972 seclogon - ok 20:40:32.0593 1972 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll 20:40:32.0609 1972 SENS - ok 20:40:32.0671 1972 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 20:40:32.0687 1972 serenum - ok 20:40:32.0703 1972 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 20:40:32.0781 1972 Serial - ok 20:40:32.0828 1972 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 20:40:32.0843 1972 Sfloppy - ok 20:40:32.0921 1972 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll 20:40:33.0000 1972 SharedAccess - ok 20:40:33.0046 1972 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 20:40:33.0046 1972 ShellHWDetection - ok 20:40:33.0062 1972 Simbad - ok 20:40:33.0140 1972 SMTPSVC (db3c22745c0da4666f3be31f1af36b2f) C:\WINDOWS\system32\inetsrv\inetinfo.exe 20:40:33.0140 1972 SMTPSVC - ok 20:40:33.0234 1972 smwdm (86d17b6760dd2b09e932ff101714e0dc) C:\WINDOWS\system32\drivers\smwdm.sys 20:40:33.0250 1972 smwdm - ok 20:40:33.0296 1972 SNMP (60c377be6b3cc83f6a8584934b181d2e) C:\WINDOWS\System32\snmp.exe 20:40:33.0328 1972 SNMP - ok 20:40:33.0343 1972 SNMPTRAP (80a050795a107a76c2b1cd4cfbe010e6) C:\WINDOWS\System32\snmptrap.exe 20:40:33.0468 1972 SNMPTRAP - ok 20:40:33.0562 1972 SoundMAX Agent Service (default) (3978f082274f723ad5a0a8058c2417dd) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 20:40:34.0140 1972 SoundMAX Agent Service (default) - ok 20:40:34.0156 1972 Sparrow - ok 20:40:34.0187 1972 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 20:40:34.0203 1972 splitter - ok 20:40:34.0265 1972 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe 20:40:34.0265 1972 Spooler - ok 20:40:34.0312 1972 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 20:40:34.0312 1972 sr - ok 20:40:34.0375 1972 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll 20:40:34.0406 1972 srservice - ok 20:40:34.0468 1972 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 20:40:34.0484 1972 Srv - ok 20:40:34.0500 1972 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys 20:40:34.0500 1972 sscdbhk5 - ok 20:40:34.0546 1972 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll 20:40:34.0578 1972 SSDPSRV - ok 20:40:34.0609 1972 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys 20:40:34.0609 1972 ssrtln - ok 20:40:34.0687 1972 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll 20:40:34.0750 1972 stisvc - ok 20:40:34.0781 1972 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 20:40:34.0796 1972 swenum - ok 20:40:34.0843 1972 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 20:40:34.0875 1972 swmidi - ok 20:40:34.0875 1972 SwPrv - ok 20:40:34.0890 1972 symc810 - ok 20:40:34.0890 1972 symc8xx - ok 20:40:34.0906 1972 sym_hi - ok 20:40:34.0906 1972 sym_u3 - ok 20:40:34.0921 1972 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 20:40:34.0968 1972 sysaudio - ok 20:40:35.0000 1972 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe 20:40:35.0062 1972 SysmonLog - ok 20:40:35.0125 1972 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll 20:40:35.0156 1972 TapiSrv - ok 20:40:35.0218 1972 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:40:35.0250 1972 Tcpip - ok 20:40:35.0265 1972 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 20:40:35.0265 1972 TDPIPE - ok 20:40:35.0281 1972 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 20:40:35.0281 1972 TDTCP - ok 20:40:35.0343 1972 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 20:40:35.0343 1972 TermDD - ok 20:40:35.0406 1972 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll 20:40:35.0500 1972 TermService - ok 20:40:35.0515 1972 tfsnboio - ok 20:40:35.0515 1972 tfsncofs - ok 20:40:35.0515 1972 tfsndrct - ok 20:40:35.0531 1972 tfsndres - ok 20:40:35.0531 1972 tfsnifs - ok 20:40:35.0531 1972 tfsnopio - ok 20:40:35.0546 1972 tfsnpool - ok 20:40:35.0546 1972 tfsnudf - ok 20:40:35.0562 1972 tfsnudfa - ok 20:40:35.0609 1972 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 20:40:35.0609 1972 Themes - ok 20:40:35.0640 1972 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe 20:40:35.0687 1972 TlntSvr - ok 20:40:35.0687 1972 TosIde - ok 20:40:35.0734 1972 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll 20:40:35.0765 1972 TrkWks - ok 20:40:35.0796 1972 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 20:40:35.0843 1972 Udfs - ok 20:40:35.0843 1972 ultra - ok 20:40:35.0921 1972 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 20:40:35.0968 1972 Update - ok 20:40:36.0031 1972 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll 20:40:36.0078 1972 upnphost - ok 20:40:36.0093 1972 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe 20:40:36.0156 1972 UPS - ok 20:40:36.0187 1972 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\WINDOWS\system32\Drivers\usbaapl.sys 20:40:36.0234 1972 USBAAPL - ok 20:40:36.0281 1972 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 20:40:36.0312 1972 usbccgp - ok 20:40:36.0312 1972 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:40:36.0343 1972 usbehci - ok 20:40:36.0359 1972 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:40:36.0406 1972 usbhub - ok 20:40:36.0531 1972 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 20:40:36.0578 1972 usbprint - ok 20:40:36.0593 1972 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 20:40:36.0656 1972 usbscan - ok 20:40:36.0703 1972 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:40:36.0718 1972 USBSTOR - ok 20:40:36.0750 1972 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:40:36.0781 1972 usbuhci - ok 20:40:36.0812 1972 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 20:40:36.0843 1972 VgaSave - ok 20:40:36.0843 1972 ViaIde - ok 20:40:36.0890 1972 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 20:40:36.0890 1972 VolSnap - ok 20:40:36.0937 1972 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe 20:40:37.0000 1972 VSS - ok 20:40:37.0046 1972 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll 20:40:37.0093 1972 W32Time - ok 20:40:37.0171 1972 W3SVC (db3c22745c0da4666f3be31f1af36b2f) C:\WINDOWS\system32\inetsrv\inetinfo.exe 20:40:37.0171 1972 W3SVC - ok 20:40:37.0203 1972 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:40:37.0250 1972 Wanarp - ok 20:40:37.0265 1972 wceusbsh (4c0b8ef721783f52f8e531fbdc4b1f74) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys 20:40:37.0312 1972 wceusbsh - ok 20:40:37.0312 1972 WDICA - ok 20:40:37.0375 1972 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 20:40:37.0406 1972 wdmaud - ok 20:40:37.0453 1972 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll 20:40:37.0484 1972 WebClient - ok 20:40:37.0578 1972 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll 20:40:37.0625 1972 winmgmt - ok 20:40:37.0750 1972 WinRM (18f347402da544a780949b8fdf83351b) C:\WINDOWS\system32\WsmSvc.dll 20:40:37.0843 1972 WinRM - ok 20:40:37.0890 1972 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll 20:40:37.0906 1972 WmdmPmSN - ok 20:40:38.0015 1972 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll 20:40:38.0015 1972 Wmi - ok 20:40:38.0062 1972 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 20:40:38.0093 1972 WmiAcpi - ok 20:40:38.0187 1972 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe 20:40:38.0250 1972 WmiApSrv - ok 20:40:38.0421 1972 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe 20:40:38.0703 1972 WMPNetworkSvc - ok 20:40:38.0921 1972 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 20:40:38.0953 1972 WPFFontCache_v0400 - ok 20:40:39.0046 1972 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll 20:40:39.0093 1972 wscsvc - ok 20:40:39.0093 1972 WSearch - ok 20:40:39.0140 1972 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll 20:40:39.0171 1972 wuauserv - ok 20:40:39.0234 1972 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 20:40:39.0296 1972 WudfPf - ok 20:40:39.0328 1972 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 20:40:39.0406 1972 WudfRd - ok 20:40:39.0453 1972 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll 20:40:39.0484 1972 WudfSvc - ok 20:40:39.0546 1972 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll 20:40:39.0578 1972 WZCSVC - ok 20:40:39.0625 1972 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll 20:40:39.0656 1972 xmlprov - ok 20:40:39.0703 1972 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 20:40:39.0734 1972 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected 20:40:39.0734 1972 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0) 20:40:39.0750 1972 Boot (0x1200) (5c113494705c17192986e503050e3c20) \Device\Harddisk0\DR0\Partition0 20:40:39.0765 1972 \Device\Harddisk0\DR0\Partition0 - ok 20:40:39.0765 1972 ============================================================ 20:40:39.0765 1972 Scan finished 20:40:39.0765 1972 ============================================================ 20:40:39.0765 1744 Detected object count: 1 20:40:39.0765 1744 Actual detected object count: 1 20:40:59.0125 1744 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - skipped by user 20:40:59.0125 1744 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Skip I am having trouble with the VirusTotal part. The 3 files that you have to be copy/pasted are not found on my computer, so it won't let me browse for those files. Where is says Step 2 Upload File/Files for Testing… maybe I didn't do something. I'm confused at that part, but the TDSS report is attached above. Thanks Alander, noob-dan
Hi, dont worry about the missing files

Rootkit

Your computer has a serious infections, including a Rootkit. A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.

You are strongly advised to do the following:

  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).

DO NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

Due to its rootkit functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS). However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

To help you understand more, please take some time to read the following articles:

How do I respond to a possible identity theft and how do I prevent it
When should do a reformat and reinstallation of my OS
How to backup your files in Windows XP

Should you have any questions please feel free to ask.

Please let us know what you have decided to do in your next post.
Alander, I just did a complete clean install on April 24th. I would like not to have to go through the hassle, I have a pre-installed version, and the disc I was given to do restoring/recovery is scratched kind of badly. Would I be ok to rid this rootkit, and not have to worry about security issues ?? I do not store anything on my main HDD. It is only a 40GB, because the 500GB I had crashed… hence the clean install. If you believe in your expertise that I cannot rid this completely without the re-install, then let me know. Otherwise, lets continue to kill this thing! Should I be using other programs along with Microsoft Security Essentials, on a daily basis ?? Thanks, noob_dan
Hi :)
  • Important!: Run this fix once and once only.
  • First go to Start > Computer > C: and delete the TDSSKiller log that was created there.
  • Next double click on TDSSKiller.exe to launch it.
  • Click on Start Scan, the scan will run.
  • When the scan has finished Ensure Cure ( the default) is selected… then click Continue > Reboot now.
  • When finished re-booting, a log of the cleanup will be found at C:\TDSSKiller._version_.MM.YYYY_HH.MM.SS_log.txt .
  • To find the log go to Start > Computer > C:
  • Post the contents of that log in your next reply please.
Alander, Thanks for all of your assistance. After I wrote my last reply, I decided to go ahead and do a complete clean install of my OS. I didn't want any issues to arise in the future form this infection. I had all the files I needed backed onto an external HDD from the last install. I appreciate your time and efforts ! I will post in the future, I'm sure my computer won't stay safe again for long ! Thanks, noob_dan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI