This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desktop Icons Keep Moving After Every Reboot [Solved]

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Last month my computer was hit by ping.exe and I was able to clean it up with Malwarebites by running it in safemode. This is what it found:

Registry Data Items Detected: 2
HKCR\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Bad: (C:\Documents and Settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n.) Good: (%SystemRoot%\system32\shdocvw.dll) -> Quarantined and repaired successfully.
HKCR\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32| (Trojan.Zaccess) -> Bad: (\\.\globalroot\systemroot\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n.) Good: (%systemroot%\system32\wbem\wbemess.dll) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 4
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1187\A0141683.ini (Trojan.0access) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1187\A0141708.ini (Trojan.0access) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\WINDOWS\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\80000000.@ (Trojan.Sirefef) -> Quarantined and deleted successfully.

(end)

Also a few days later:
Files Detected: 1
C:\WINDOWS\assembly\GAC\Desktop.ini (Trojan.0access) -> Quarantined and deleted successfully.


After returning to normal mode, everything seemed fine except my desktop icons will not stay where I leave them and the desktop image will not display. (The icons realign to the left after every reboot or refresh, usually with the recycle bin as the upper left icon and the rest of them fairly randomly arranged after that.) I've tried all the normal fixes and even followed these Microsoft instructions figuring that my profile was corrupted: http://support.microsoft.com/?kbid=811151 When I created the new XP account, everything worked fine, but when I copied over the recommended files, the new account has the same problem with the icons. So I'm wondering if I still have a malware issue.

I had also run Spybot which didn't find anything and SUPERAntiSpyware which I think just deleted a bunch of cookies.



Here is a DDS log:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 4:08:40.76 on Sat 07/21/2012
Internet Explorer: 8.0.6001.18702
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell
uInternet Settings,ProxyOverride = localhost;*.local
mSearchAssistant = hxxp://www.google.com/ie
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [CTSysVol] c:\program files\creative\sbaudigy2\surround mixer\CTSysVol.exe
mRun: [CTDVDDet] c:\program files\creative\sbaudigy2\dvdaudio\CTDVDDet.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [SetDefPrt] c:\program files\brother\brmfl04e\BrStDvPt.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DiscWizardMonitor.exe] c:\program files\seagate\discwizard\DiscWizardMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\seagate\discwizard\TimounterMonitor.exe
mRun: [Seagate Scheduler2 Service] "c:\program files\common files\seagate\schedule2\schedhlp.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\o'toole\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: rexplorer.net
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/ja/downloads/getmodule.aspx?lang=en
DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - hxxp://www.alternatiff.com/install-ie/alttiff.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3BF72F68-72D8-461D-A884-329D936C5581} - hxxp://picwash.com/ImageUploader5.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://emeetings.webex.com/client/T27L10NSP11EP14-emeetings/event/ieatgpc.cab
DPF: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Authentication Packages = msv1_0 relog_ap
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-06-28 07:42:00 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2012-06-28 07:41:53 261480 —-a-w- c:\windows\system32\xactengine2_7.dll
2012-06-28 07:41:28 443752 —-a-w- c:\windows\system32\d3dx10_33.dll
2012-06-28 07:41:28 1123696 —-a-w- c:\windows\system32\D3DCompiler_33.dll
2012-06-28 07:35:44 118520 —-a-w- c:\windows\system32\PxInsI64.exe
2012-06-28 07:35:44 115960 —-a-w- c:\windows\system32\PxCpyI64.exe
2012-06-28 07:35:34 ——– d—–w- c:\program files\Sony
2012-06-28 07:34:21 ——– d—–w- c:\docume~1\alluse~1\applic~1\Sony Corporation
.
==================== Find3M ====================
.
2012-06-13 13:19:59 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 ——w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42:33 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
============= FINISH: 4:09:12.59 ===============


Thanks, I appreciate the help.
:welcome:

What Malwarebytes removed was part of the ZeroAccess Rootkit Lets check further

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Thanks for the help. I downloaded aswMBR and let it update the AVAST definitions. There is a dropdown option on my screen for AV Scan which I left on "quickscan." Here is the log. The fifth one from the bottom is infected: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-22 13:36:55 —————————– 13:36:55.593 OS Version: Windows 5.1.2600 Service Pack 3 13:36:55.593 Number of processors: 2 586 0x403 13:36:55.593 ComputerName: DAN UserName: 13:36:56.609 Initialize success 13:38:02.156 AVAST engine defs: 12072200 13:38:19.343 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 13:38:19.343 Disk 0 Vendor: WDC_WD1600JS-75NCB1 10.02E01 Size: 152587MB BusType: 3 13:38:19.343 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-22 13:38:19.343 Disk 1 Vendor: ST3500413AS JC45 Size: 476940MB BusType: 3 13:38:19.375 Disk 0 MBR read successfully 13:38:19.375 Disk 0 MBR scan 13:38:19.421 Disk 0 Windows XP default MBR code 13:38:19.421 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 13:38:19.453 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152539 MB offset 80325 13:38:19.468 Disk 0 scanning sectors +312480315 13:38:19.500 Disk 0 malicious Win32:MBRoot code @ sector 312480318 ! 13:38:19.500 Disk 0 PE file @ sector 312480340 ! 13:38:19.593 Disk 0 scanning C:\WINDOWS\system32\drivers 13:38:38.093 Service scanning 13:39:03.828 Modules scanning 13:39:12.484 Disk 0 trace - called modules: 13:39:12.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 13:39:12.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x871d4ab8] 13:39:12.515 3 CLASSPNP.SYS[f7592fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x87164d98] 13:39:13.734 AVAST engine scan C:\WINDOWS 13:39:25.953 AVAST engine scan C:\WINDOWS\system32 13:43:11.562 AVAST engine scan C:\WINDOWS\system32\drivers 13:43:44.640 AVAST engine scan C:\Documents and Settings\O'Toole 13:53:06.718 File: C:\Documents and Settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n **INFECTED** Win32:Sirefef-PL [Rtk] 13:59:22.125 AVAST engine scan C:\Documents and Settings\All Users 14:37:48.765 Scan finished successfully 14:38:10.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\MBR.dat" 14:38:10.625 The log file has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\aswMBR.txt"
13:38:19.500 Disk 0 malicious Win32:MBRoot code @ sector 312480318 !
Your Master Boot Record may be infected



Download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003c Kernel Drivers (total 155): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E5000 \WINDOWS\system32\hal.dll 0xF7A52000 \WINDOWS\system32\KDCOM.DLL 0xF7962000 \WINDOWS\system32\BOOTVID.dll 0xF7423000 ACPI.sys 0xF7A54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7412000 pci.sys 0xF7552000 isapnp.sys 0xF7B1A000 pciide.sys 0xF77D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7A56000 intelide.sys 0xF7562000 MountMgr.sys 0xF73F3000 ftdisk.sys 0xF7A58000 dmload.sys 0xF73CD000 dmio.sys 0xF77DA000 PartMgr.sys 0xF7572000 VolSnap.sys 0xF73B5000 atapi.sys 0xF73A3000 AFAmgt.sys 0xF7582000 disk.sys 0xF7592000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7383000 fltmgr.sys 0xF7371000 sr.sys 0xF7349000 MpFilter.sys 0xF7333000 drvmcdb.sys 0xF75A2000 PxHelp20.sys 0xF731C000 KSecDD.sys 0xF728F000 Ntfs.sys 0xF7262000 NDIS.sys 0xF71F7000 timntr.sys 0xF719E000 tdrpman.sys 0xF717F000 snapman.sys 0xF75B2000 ohci1394.sys 0xF75C2000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF7165000 Mup.sys 0xF75E2000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF7742000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF607E000 \SystemRoot\system32\DRIVERS\e1000325.sys 0xF577E000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF576A000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF78D2000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF572B000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF78DA000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF5638000 \SystemRoot\system32\drivers\ctaud2k.sys 0xF55D3000 \SystemRoot\system32\drivers\portcls.sys 0xF65CE000 \SystemRoot\system32\drivers\drmk.sys 0xF54A8000 \SystemRoot\system32\drivers\ks.sys 0xF545A000 \SystemRoot\system32\drivers\ctoss2k.sys 0xF7A84000 \SystemRoot\System32\drivers\ctprxy2k.sys 0xF5305000 \SystemRoot\system32\DRIVERS\parport.sys 0xF7632000 \SystemRoot\system32\DRIVERS\serial.sys 0xF708C000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF7642000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF7902000 \SystemRoot\system32\drivers\Afc.sys 0xF7A8A000 \SystemRoot\system32\drivers\sscdbhk5.sys 0xF7652000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7662000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF792A000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF7A92000 \SystemRoot\system32\DRIVERS\serscan.sys 0xF7C07000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF76E2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7104000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF511F000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7702000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7712000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF795A000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF50D3000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7752000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF780A000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF781A000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF5083000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF7762000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF782A000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7832000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7AAC000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF4F73000 \SystemRoot\system32\DRIVERS\update.sys 0xF70E0000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7772000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF77B2000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7AB6000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF2CA4000 \SystemRoot\System32\drivers\ha10kx2k.sys 0xF2C89000 \SystemRoot\System32\drivers\emupia2k.sys 0xF2C6A000 \SystemRoot\System32\drivers\ctsfm2k.sys 0xF2C4A000 \SystemRoot\System32\drivers\ctac32k.sys 0xF2C2A000 \SystemRoot\System32\drivers\hap16v2k.sys 0xF788A000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF7892000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF51FF000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF660E000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF78CA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF65EE000 \SystemRoot\system32\drivers\lvusbsta.sys 0xF51FB000 \SystemRoot\System32\Drivers\BrUsbScn.sys 0xF7C7A000 \SystemRoot\System32\Drivers\Brfilt.sys 0xF65DE000 \SystemRoot\system32\DRIVERS\mf.sys 0xF709C000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF7098000 \SystemRoot\System32\Drivers\BrUsbMdm.sys 0xF2BEE000 \SystemRoot\System32\Drivers\BrSerWdm.sys 0xF78A2000 \SystemRoot\System32\Drivers\Modem.SYS 0xF7084000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF707C000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF7AE0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C77000 \SystemRoot\System32\Drivers\Null.SYS 0xF7AE2000 \SystemRoot\System32\Drivers\Beep.SYS 0xF78B2000 \SystemRoot\system32\drivers\ssrtln.sys 0xF78BA000 \SystemRoot\System32\drivers\vga.sys 0xF7AE4000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7AEA000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78C2000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78E2000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF70E4000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF2BBB000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF2B62000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF2B3A000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF7672000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF2B18000 \SystemRoot\System32\drivers\afd.sys 0xF7682000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF2AF6000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0xF78F2000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0xF2ACB000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF7692000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xF2A5B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF76A2000 \SystemRoot\System32\Drivers\Fips.SYS 0xF76F2000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF297B000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B04000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF2C1A000 \SystemRoot\System32\drivers\Dxapi.sys 0xF78FA000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7BE6000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xF29DB000 \SystemRoot\system32\drivers\drvnddm.sys 0xF29CB000 \SystemRoot\system32\DRIVERS\tifsfilt.sys 0xF7C76000 \SystemRoot\system32\dla\tfsndres.sys 0xF0BD8000 \SystemRoot\system32\dla\tfsnifs.sys 0xF0C52000 \SystemRoot\system32\dla\tfsnopio.sys 0xF7AAE000 \SystemRoot\system32\dla\tfsnpool.sys 0xF793A000 \SystemRoot\system32\dla\tfsnboio.sys 0xF29BB000 \SystemRoot\system32\dla\tfsncofs.sys 0xF7C78000 \SystemRoot\system32\dla\tfsndrct.sys 0xF0B97000 \SystemRoot\system32\dla\tfsnudf.sys 0xF0B7E000 \SystemRoot\system32\dla\tfsnudfa.sys 0xF0BCC000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF0921000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7862000 \SystemRoot\System32\drivers\BrPar.sys 0xF081C000 \SystemRoot\system32\drivers\wdmaud.sys 0xF0996000 \SystemRoot\system32\drivers\sysaudio.sys 0xF787A000 \??\C:\WINDOWS\system32\drivers\AsfAlrt.sys 0xF04C6000 \SystemRoot\system32\DRIVERS\srv.sys 0xF0526000 \??\C:\WINDOWS\system32\drivers\PfModNT.sys 0xEF3F2000 \SystemRoot\System32\Drivers\HTTP.sys 0xEFFAE000 \??\C:\DOCUME~1\O'Toole\LOCALS~1\Temp\aswMBR.sys 0xEEC8E000 \SystemRoot\system32\drivers\kmixer.sys 0xBF3A4000 \SystemRoot\System32\ATMFD.DLL 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 58): 0 System Idle Process 4 System 796 C:\WINDOWS\system32\smss.exe 844 csrss.exe 868 C:\WINDOWS\system32\winlogon.exe 916 C:\WINDOWS\system32\services.exe 928 C:\WINDOWS\system32\lsass.exe 1136 C:\WINDOWS\system32\svchost.exe 1228 svchost.exe 1328 C:\WINDOWS\system32\svchost.exe 1456 svchost.exe 1536 svchost.exe 1724 C:\WINDOWS\system32\spoolsv.exe 1864 svchost.exe 1900 C:\Program Files\SUPERAntiSpyware\SASCore.exe 356 C:\WINDOWS\explorer.exe 424 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 440 C:\Program Files\Intel\ASF Agent\ASFAgent.exe 456 C:\Program Files\Bonjour\mDNSResponder.exe 556 C:\WINDOWS\system32\Brmfrmps.exe 572 C:\WINDOWS\system32\CTSVCCDA.EXE 664 C:\Program Files\Java\jre6\bin\jqs.exe 756 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 1384 C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe 1436 C:\WINDOWS\system32\nvsvc32.exe 1484 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe 1492 C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe 1500 C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe 1520 C:\WINDOWS\system32\CTHELPER.EXE 1680 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe 1948 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe 1984 C:\Program Files\Dell\RAID Storage Manager\StorServ.exe 1996 C:\WINDOWS\system32\dla\tfswctrl.exe 1628 C:\WINDOWS\system32\LVCOMSX.EXE 320 C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe 724 C:\Program Files\Logitech\Video\LogiTray.exe 892 C:\WINDOWS\system32\ctfmon.exe 1812 C:\Program Files\iTunes\iTunesHelper.exe 2128 C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe 2144 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 2276 C:\WINDOWS\system32\svchost.exe 2336 C:\WINDOWS\system32\MsPMSPSv.exe 2472 C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe 2708 C:\Program Files\Logitech\Video\FxSvr2.exe 2780 C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe 2916 C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe 3008 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3072 C:\Program Files\Microsoft Security Client\msseces.exe 3252 C:\WINDOWS\system32\BrmfRsmg.exe 3392 C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe 3616 C:\Program Files\iPod\bin\iPodService.exe 1452 C:\WINDOWS\system32\svchost.exe 3836 C:\Program Files\Internet Explorer\iexplore.exe 3852 C:\Program Files\Internet Explorer\iexplore.exe 2200 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe 2900 C:\WINDOWS\system32\WISPTIS.EXE 1816 C:\Program Files\Internet Explorer\iexplore.exe 2628 C:\Documents and Settings\O'Toole\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS) \\.\F: –> \\.\PhysicalDrive1 at offset 0x00000000`007e0000 (NTFS) PhysicalDrive0 Model Number: WDCWD1600JS-75NCB1, Rev: 10.02E01 PhysicalDrive1 Model Number: ST3500413AS, Rev: JC45 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 465 GB \\.\PhysicalDrive1 Unknown MBR code SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Looks like it may be infected but before we attempt to fix it lets see if this will do. Sometimes this program can fix it

I need you to run TDSSKiller, post the log, then run aswMBR again and post the NEW log please


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
16:03:29.0281 3900 TDSS rootkit removing tool [removed] Jul 16 2012 22:10:11 16:03:29.0625 3900 ============================================================ 16:03:29.0625 3900 Current date / time: 2012/07/22 16:03:29.0625 16:03:29.0625 3900 SystemInfo: 16:03:29.0625 3900 16:03:29.0625 3900 OS Version: 5.1.2600 ServicePack: 3.0 16:03:29.0625 3900 Product type: Workstation 16:03:29.0625 3900 ComputerName: DAN 16:03:29.0625 3900 UserName: O'Toole 16:03:29.0625 3900 Windows directory: C:\WINDOWS 16:03:29.0625 3900 System windows directory: C:\WINDOWS 16:03:29.0625 3900 Processor architecture: Intel x86 16:03:29.0625 3900 Number of processors: 2 16:03:29.0625 3900 Page size: 0x1000 16:03:29.0625 3900 Boot type: Normal boot 16:03:29.0625 3900 ============================================================ 16:03:31.0593 3900 Drive \Device\Harddisk0\DR0 - Size: 0x2540BE4000 (149.01 Gb), SectorSize: 0x200, Cylinders: 0x4BFC, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 16:03:31.0593 3900 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 16:03:31.0609 3900 ============================================================ 16:03:31.0609 3900 \Device\Harddisk0\DR0: 16:03:31.0609 3900 MBR partitions: 16:03:31.0609 3900 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x129ED876 16:03:31.0609 3900 \Device\Harddisk1\DR1: 16:03:31.0609 3900 MBR partitions: 16:03:31.0625 3900 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x3A380D41 16:03:31.0625 3900 ============================================================ 16:03:31.0656 3900 C: <-> \Device\Harddisk0\DR0\Partition0 16:03:31.0671 3900 F: <-> \Device\Harddisk1\DR1\Partition0 16:03:31.0703 3900 ============================================================ 16:03:31.0703 3900 Initialize success 16:03:31.0703 3900 ============================================================ 16:03:49.0859 2928 ============================================================ 16:03:49.0859 2928 Scan started 16:03:49.0859 2928 Mode: Manual; 16:03:49.0859 2928 ============================================================ 16:03:50.0421 2928 !SASCORE (c0393eb99a6c72c6bef9bfc4a72b33a6) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE 16:03:50.0421 2928 !SASCORE - ok 16:03:50.0578 2928 Abiosdsk - ok 16:03:50.0609 2928 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 16:03:50.0609 2928 abp480n5 - ok 16:03:50.0656 2928 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 16:03:50.0656 2928 ACPI - ok 16:03:50.0703 2928 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 16:03:50.0703 2928 ACPIEC - ok 16:03:50.0718 2928 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 16:03:50.0718 2928 adpu160m - ok 16:03:50.0765 2928 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 16:03:50.0765 2928 aec - ok 16:03:50.0796 2928 AFAmgt (cbda98135d62e40b609ab0cf0dbcefea) C:\WINDOWS\system32\drivers\AFAmgt.sys 16:03:50.0796 2928 AFAmgt - ok 16:03:50.0843 2928 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys 16:03:50.0843 2928 Afc - ok 16:03:50.0890 2928 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 16:03:50.0890 2928 AFD - ok 16:03:50.0953 2928 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 16:03:50.0953 2928 agp440 - ok 16:03:51.0000 2928 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 16:03:51.0000 2928 agpCPQ - ok 16:03:51.0015 2928 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 16:03:51.0015 2928 Aha154x - ok 16:03:51.0031 2928 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 16:03:51.0031 2928 aic78u2 - ok 16:03:51.0046 2928 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 16:03:51.0046 2928 aic78xx - ok 16:03:51.0078 2928 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll 16:03:51.0078 2928 Alerter - ok 16:03:51.0109 2928 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe 16:03:51.0109 2928 ALG - ok 16:03:51.0140 2928 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 16:03:51.0140 2928 AliIde - ok 16:03:51.0187 2928 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 16:03:51.0187 2928 alim1541 - ok 16:03:51.0187 2928 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 16:03:51.0187 2928 amdagp - ok 16:03:51.0234 2928 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 16:03:51.0234 2928 amsint - ok 16:03:51.0375 2928 Apple Mobile Device (4b5ae15e5c73eb4dc8dbec2788230d41) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 16:03:51.0375 2928 Apple Mobile Device - ok 16:03:51.0437 2928 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll 16:03:51.0437 2928 AppMgmt - ok 16:03:51.0468 2928 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 16:03:51.0484 2928 Arp1394 - ok 16:03:51.0515 2928 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 16:03:51.0531 2928 asc - ok 16:03:51.0546 2928 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 16:03:51.0546 2928 asc3350p - ok 16:03:51.0562 2928 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 16:03:51.0562 2928 asc3550 - ok 16:03:51.0640 2928 ASFAgent (378051058f0e9c6668cb6a86d6ffb431) c:\Program Files\Intel\ASF Agent\ASFAgent.exe 16:03:51.0640 2928 ASFAgent - ok 16:03:51.0656 2928 AsfAlrt (e301dd2b6cced65e0537ceaee8f954b6) C:\WINDOWS\system32\drivers\AsfAlrt.sys 16:03:51.0656 2928 AsfAlrt - ok 16:03:51.0828 2928 aspnet_state (e1a1206a4fb19b675e947b29ccd25fba) C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 16:03:51.0828 2928 aspnet_state - ok 16:03:51.0875 2928 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16:03:51.0890 2928 AsyncMac - ok 16:03:51.0906 2928 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 16:03:51.0906 2928 atapi - ok 16:03:51.0921 2928 Atdisk - ok 16:03:51.0953 2928 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 16:03:51.0968 2928 Atmarpc - ok 16:03:52.0031 2928 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll 16:03:52.0031 2928 AudioSrv - ok 16:03:52.0078 2928 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 16:03:52.0078 2928 audstub - ok 16:03:52.0140 2928 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 16:03:52.0140 2928 Beep - ok 16:03:52.0203 2928 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll 16:03:52.0421 2928 BITS - ok 16:03:52.0484 2928 Bonjour Service (3f56903e124e820aeece6d471583c6c1) C:\Program Files\Bonjour\mDNSResponder.exe 16:03:52.0531 2928 Bonjour Service - ok 16:03:52.0593 2928 brfilt (4ba311473e0d8557827e6f2fe33a8095) C:\WINDOWS\system32\Drivers\Brfilt.sys 16:03:52.0593 2928 brfilt - ok 16:03:52.0656 2928 brmfrmps (bb192385661daf7f3d48b586f6e1d166) C:\WINDOWS\system32\Brmfrmps.exe 16:03:52.0656 2928 brmfrmps - ok 16:03:52.0703 2928 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll 16:03:52.0718 2928 Browser - ok 16:03:52.0765 2928 BrPar (2fe6d5be0629f706197b30c0aa05de30) C:\WINDOWS\System32\drivers\BrPar.sys 16:03:52.0765 2928 BrPar - ok 16:03:52.0765 2928 BrSerWDM (791ef93168dcf057715493d607e37983) C:\WINDOWS\system32\Drivers\BrSerWdm.sys 16:03:52.0765 2928 BrSerWDM - ok 16:03:52.0781 2928 BrUsbMdm (37e2d0b12ddf536cd64af6eb3b580ef8) C:\WINDOWS\system32\Drivers\BrUsbMdm.sys 16:03:52.0781 2928 BrUsbMdm - ok 16:03:52.0828 2928 BrUsbScn (1c5f014048e5b2748c1a8ad297c50b6f) C:\WINDOWS\system32\Drivers\BrUsbScn.sys 16:03:52.0828 2928 BrUsbScn - ok 16:03:52.0875 2928 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS 16:03:52.0875 2928 BVRPMPR5 - ok 16:03:52.0906 2928 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 16:03:52.0906 2928 cbidf - ok 16:03:52.0906 2928 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 16:03:52.0906 2928 cbidf2k - ok 16:03:52.0953 2928 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 16:03:52.0953 2928 CCDECODE - ok 16:03:52.0984 2928 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 16:03:52.0984 2928 cd20xrnt - ok 16:03:53.0000 2928 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 16:03:53.0000 2928 Cdaudio - ok 16:03:53.0031 2928 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 16:03:53.0031 2928 Cdfs - ok 16:03:53.0093 2928 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 16:03:53.0093 2928 Cdrom - ok 16:03:53.0093 2928 Changer - ok 16:03:53.0140 2928 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe 16:03:53.0140 2928 CiSvc - ok 16:03:53.0187 2928 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe 16:03:53.0187 2928 ClipSrv - ok 16:03:53.0250 2928 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 16:03:53.0250 2928 CmdIde - ok 16:03:53.0250 2928 COMSysApp - ok 16:03:53.0281 2928 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 16:03:53.0281 2928 Cpqarray - ok 16:03:53.0484 2928 Creative Service for CDROM Access (3c8b6609712f4ff78e521f6dcfc4032b) C:\WINDOWS\system32\CTsvcCDA.exe 16:03:53.0515 2928 Creative Service for CDROM Access - ok 16:03:53.0687 2928 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll 16:03:53.0687 2928 CryptSvc - ok 16:03:53.0750 2928 ctac32k (4c638290979600ae2ae329d1608ad2ec) C:\WINDOWS\system32\drivers\ctac32k.sys 16:03:53.0750 2928 ctac32k - ok 16:03:53.0828 2928 ctaud2k (cf5662375781f741513c169cd4094100) C:\WINDOWS\system32\drivers\ctaud2k.sys 16:03:53.0890 2928 ctaud2k - ok 16:03:53.0921 2928 ctdvda2k (437f2b31ba8b6b264d38b4fe6682faec) C:\WINDOWS\system32\drivers\ctdvda2k.sys 16:03:53.0984 2928 ctdvda2k - ok 16:03:54.0015 2928 ctprxy2k (678849d1af0750f68dbdc185252d5926) C:\WINDOWS\system32\drivers\ctprxy2k.sys 16:03:54.0015 2928 ctprxy2k - ok 16:03:54.0015 2928 ctsfm2k (3a076ebfbbbd6879a78863944980da32) C:\WINDOWS\system32\drivers\ctsfm2k.sys 16:03:54.0031 2928 ctsfm2k - ok 16:03:54.0062 2928 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 16:03:54.0093 2928 dac2w2k - ok 16:03:54.0109 2928 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 16:03:54.0109 2928 dac960nt - ok 16:03:54.0171 2928 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 16:03:54.0218 2928 DcomLaunch - ok 16:03:54.0265 2928 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll 16:03:54.0265 2928 Dhcp - ok 16:03:54.0312 2928 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 16:03:54.0312 2928 Disk - ok 16:03:54.0328 2928 dmadmin - ok 16:03:54.0406 2928 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 16:03:54.0437 2928 dmboot - ok 16:03:54.0468 2928 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 16:03:54.0468 2928 dmio - ok 16:03:54.0500 2928 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 16:03:54.0500 2928 dmload - ok 16:03:54.0546 2928 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll 16:03:54.0562 2928 dmserver - ok 16:03:54.0578 2928 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 16:03:54.0578 2928 DMusic - ok 16:03:54.0625 2928 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll 16:03:54.0640 2928 Dnscache - ok 16:03:54.0718 2928 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll 16:03:54.0734 2928 Dot3svc - ok 16:03:54.0765 2928 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 16:03:54.0765 2928 dpti2o - ok 16:03:54.0812 2928 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 16:03:54.0812 2928 drmkaud - ok 16:03:54.0843 2928 drvmcdb (96bc8f872f0270c10edc3931f1c03776) C:\WINDOWS\system32\drivers\drvmcdb.sys 16:03:54.0843 2928 drvmcdb - ok 16:03:54.0859 2928 drvnddm (5afbec7a6ac61b211633dfdb1d9e0c89) C:\WINDOWS\system32\drivers\drvnddm.sys 16:03:54.0859 2928 drvnddm - ok 16:03:54.0906 2928 E1000 (bb98a47faf8b6a99202290c1e7d49d36) C:\WINDOWS\system32\DRIVERS\e1000325.sys 16:03:54.0921 2928 E1000 - ok 16:03:54.0953 2928 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 16:03:54.0968 2928 E100B - ok 16:03:55.0031 2928 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll 16:03:55.0031 2928 EapHost - ok 16:03:55.0078 2928 emupia (f7511cf63ef82f7227c03028a3abadb5) C:\WINDOWS\system32\drivers\emupia2k.sys 16:03:55.0078 2928 emupia - ok 16:03:55.0125 2928 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll 16:03:55.0125 2928 ERSvc - ok 16:03:55.0187 2928 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 16:03:55.0218 2928 Eventlog - ok 16:03:55.0296 2928 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll 16:03:55.0343 2928 EventSystem - ok 16:03:55.0375 2928 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 16:03:55.0375 2928 Fastfat - ok 16:03:55.0406 2928 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 16:03:55.0421 2928 FastUserSwitchingCompatibility - ok 16:03:55.0468 2928 Fax (e97d6a8684466df94ff3bc24fb787a07) C:\WINDOWS\system32\fxssvc.exe 16:03:55.0484 2928 Fax - ok 16:03:55.0531 2928 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 16:03:55.0531 2928 Fdc - ok 16:03:55.0562 2928 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 16:03:55.0578 2928 Fips - ok 16:03:55.0734 2928 FLEXnet Licensing Service (8669be94f63944e4f899c3950b520241) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 16:03:55.0765 2928 FLEXnet Licensing Service - ok 16:03:55.0796 2928 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 16:03:55.0812 2928 Flpydisk - ok 16:03:55.0843 2928 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 16:03:55.0843 2928 FltMgr - ok 16:03:55.0906 2928 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 16:03:55.0906 2928 Fs_Rec - ok 16:03:55.0953 2928 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 16:03:55.0953 2928 Ftdisk - ok 16:03:56.0000 2928 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 16:03:56.0000 2928 GEARAspiWDM - ok 16:03:56.0156 2928 GoogleDesktopManager-051210-111108 (9f5f2f0fb0a7f5aa9f16b9a7b6dad89f) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 16:03:56.0156 2928 GoogleDesktopManager-051210-111108 - ok 16:03:56.0203 2928 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 16:03:56.0203 2928 Gpc - ok 16:03:56.0250 2928 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 16:03:56.0250 2928 gusvc - ok 16:03:56.0312 2928 ha10kx2k (f24dd43adc784177b28984043bc022ab) C:\WINDOWS\system32\drivers\ha10kx2k.sys 16:03:56.0328 2928 ha10kx2k - ok 16:03:56.0343 2928 hap16v2k (ff65c807ea641ff7310a61be4dec6479) C:\WINDOWS\system32\drivers\hap16v2k.sys 16:03:56.0343 2928 hap16v2k - ok 16:03:56.0453 2928 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 16:03:56.0453 2928 helpsvc - ok 16:03:56.0500 2928 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll 16:03:56.0500 2928 HidServ - ok 16:03:56.0515 2928 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 16:03:56.0515 2928 HidUsb - ok 16:03:56.0593 2928 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll 16:03:56.0593 2928 hkmsvc - ok 16:03:56.0625 2928 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 16:03:56.0625 2928 hpn - ok 16:03:56.0687 2928 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 16:03:56.0734 2928 HTTP - ok 16:03:56.0796 2928 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll 16:03:56.0796 2928 HTTPFilter - ok 16:03:56.0812 2928 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 16:03:56.0812 2928 i2omgmt - ok 16:03:56.0859 2928 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 16:03:56.0859 2928 i2omp - ok 16:03:56.0906 2928 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 16:03:56.0906 2928 i8042prt - ok 16:03:57.0078 2928 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 16:03:57.0078 2928 IDriverT - ok 16:03:57.0125 2928 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 16:03:57.0125 2928 Imapi - ok 16:03:57.0187 2928 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe 16:03:57.0187 2928 ImapiService - ok 16:03:57.0234 2928 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 16:03:57.0234 2928 ini910u - ok 16:03:57.0281 2928 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 16:03:57.0281 2928 IntelIde - ok 16:03:57.0328 2928 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 16:03:57.0328 2928 intelppm - ok 16:03:57.0359 2928 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 16:03:57.0359 2928 Ip6Fw - ok 16:03:57.0406 2928 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 16:03:57.0406 2928 IpFilterDriver - ok 16:03:57.0437 2928 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 16:03:57.0437 2928 IpInIp - ok 16:03:57.0468 2928 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 16:03:57.0484 2928 IpNat - ok 16:03:57.0546 2928 iPod Service (6e0faea90e71c5f1b9f3bc71b4cca2fa) C:\Program Files\iPod\bin\iPodService.exe 16:03:57.0609 2928 iPod Service - ok 16:03:57.0687 2928 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 16:03:57.0687 2928 IPSec - ok 16:03:57.0718 2928 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 16:03:57.0734 2928 IRENUM - ok 16:03:57.0734 2928 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 16:03:57.0734 2928 isapnp - ok 16:03:57.0906 2928 JavaQuickStarterService (381b25dc8e958d905b33130d500bbf29) C:\Program Files\Java\jre6\bin\jqs.exe 16:03:57.0921 2928 JavaQuickStarterService - ok 16:03:57.0968 2928 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 16:03:57.0968 2928 Kbdclass - ok 16:03:57.0968 2928 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16:03:57.0984 2928 kbdhid - ok 16:03:58.0015 2928 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 16:03:58.0031 2928 kmixer - ok 16:03:58.0062 2928 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 16:03:58.0062 2928 KSecDD - ok 16:03:58.0109 2928 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll 16:03:58.0109 2928 lanmanserver - ok 16:03:58.0187 2928 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll 16:03:58.0203 2928 lanmanworkstation - ok 16:03:58.0203 2928 lbrtfdc - ok 16:03:58.0265 2928 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll 16:03:58.0265 2928 LmHosts - ok 16:03:58.0328 2928 LVUSBSta (a730fc8671a60666d6e877c544dd7cd4) C:\WINDOWS\system32\drivers\lvusbsta.sys 16:03:58.0328 2928 LVUSBSta - ok 16:03:58.0375 2928 MBAMSwissArmy (0db7527db188c7d967a37bb51bbf3963) C:\WINDOWS\system32\drivers\mbamswissarmy.sys 16:03:58.0375 2928 MBAMSwissArmy - ok 16:03:58.0453 2928 MDM (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 16:03:58.0468 2928 MDM - ok 16:03:58.0546 2928 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll 16:03:58.0546 2928 Messenger - ok 16:03:58.0578 2928 mf (a7da20ab18a1bdae28b0f349e57da0d1) C:\WINDOWS\system32\DRIVERS\mf.sys 16:03:58.0578 2928 mf - ok 16:03:58.0593 2928 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 16:03:58.0593 2928 mnmdd - ok 16:03:58.0640 2928 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe 16:03:58.0640 2928 mnmsrvc - ok 16:03:58.0640 2928 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 16:03:58.0640 2928 Modem - ok 16:03:58.0656 2928 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 16:03:58.0656 2928 Mouclass - ok 16:03:58.0718 2928 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 16:03:58.0718 2928 mouhid - ok 16:03:58.0734 2928 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 16:03:58.0734 2928 MountMgr - ok 16:03:58.0781 2928 MpFilter (d993bea500e7382dc4e760bf4f35efcb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 16:03:58.0781 2928 MpFilter - ok 16:03:58.0828 2928 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 16:03:58.0828 2928 mraid35x - ok 16:03:58.0843 2928 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 16:03:58.0843 2928 MRxDAV - ok 16:03:58.0906 2928 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 16:03:58.0968 2928 MRxSmb - ok 16:03:59.0109 2928 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe 16:03:59.0156 2928 MSDTC - ok 16:03:59.0312 2928 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 16:03:59.0312 2928 Msfs - ok 16:03:59.0312 2928 MSIServer - ok 16:03:59.0484 2928 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 16:03:59.0484 2928 MSKSSRV - ok 16:03:59.0531 2928 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 16:03:59.0531 2928 MSPCLOCK - ok 16:03:59.0531 2928 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 16:03:59.0531 2928 MSPQM - ok 16:03:59.0593 2928 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16:03:59.0593 2928 mssmbios - ok 16:03:59.0703 2928 MSSQL$MICROSOFTBCM - ok 16:03:59.0750 2928 MSSQLServerADHelper (cb7524c21727404bd3140dca32deb7de) C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe 16:03:59.0750 2928 MSSQLServerADHelper - ok 16:03:59.0781 2928 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 16:03:59.0781 2928 MSTEE - ok 16:03:59.0812 2928 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 16:03:59.0812 2928 Mup - ok 16:03:59.0843 2928 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 16:03:59.0843 2928 NABTSFEC - ok 16:03:59.0890 2928 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll 16:03:59.0906 2928 napagent - ok 16:03:59.0953 2928 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 16:03:59.0953 2928 NDIS - ok 16:03:59.0984 2928 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 16:03:59.0984 2928 NdisIP - ok 16:04:00.0031 2928 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 16:04:00.0046 2928 NdisTapi - ok 16:04:00.0046 2928 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16:04:00.0046 2928 Ndisuio - ok 16:04:00.0062 2928 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 16:04:00.0062 2928 NdisWan - ok 16:04:00.0109 2928 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 16:04:00.0109 2928 NDProxy - ok 16:04:00.0125 2928 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 16:04:00.0125 2928 NetBIOS - ok 16:04:00.0140 2928 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 16:04:00.0140 2928 NetBT - ok 16:04:00.0218 2928 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 16:04:00.0265 2928 NetDDE - ok 16:04:00.0265 2928 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe 16:04:00.0265 2928 NetDDEdsdm - ok 16:04:00.0312 2928 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 16:04:00.0328 2928 Netlogon - ok 16:04:00.0375 2928 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll 16:04:00.0421 2928 Netman - ok 16:04:00.0562 2928 NetSvc (02d0798f376fcbd0210eda58476d0b1b) c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe 16:04:00.0578 2928 NetSvc - ok 16:04:00.0609 2928 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 16:04:00.0609 2928 NIC1394 - ok 16:04:00.0671 2928 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll 16:04:00.0703 2928 Nla - ok 16:04:00.0750 2928 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 16:04:00.0750 2928 Npfs - ok 16:04:00.0781 2928 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 16:04:00.0828 2928 Ntfs - ok 16:04:00.0859 2928 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 16:04:00.0859 2928 NtLmSsp - ok 16:04:00.0906 2928 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll 16:04:00.0921 2928 NtmsSvc - ok 16:04:00.0968 2928 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 16:04:00.0968 2928 Null - ok 16:04:01.0125 2928 nv (6793e4169cc56db68d8b2a98286ab6e6) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 16:04:01.0218 2928 nv - ok 16:04:01.0406 2928 NVSvc (f2bda24c0cb2573fe96ab09ed247d703) C:\WINDOWS\system32\nvsvc32.exe 16:04:01.0406 2928 NVSvc - ok 16:04:01.0453 2928 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 16:04:01.0453 2928 NwlnkFlt - ok 16:04:01.0468 2928 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 16:04:01.0468 2928 NwlnkFwd - ok 16:04:01.0484 2928 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 16:04:01.0484 2928 ohci1394 - ok 16:04:01.0609 2928 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:04:01.0609 2928 ose - ok 16:04:01.0640 2928 ossrv (f0184fe6069be1541a3d18c02a73d161) C:\WINDOWS\system32\drivers\ctoss2k.sys 16:04:01.0656 2928 ossrv - ok 16:04:01.0656 2928 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 16:04:01.0656 2928 Parport - ok 16:04:01.0687 2928 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 16:04:01.0687 2928 PartMgr - ok 16:04:01.0718 2928 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 16:04:01.0718 2928 ParVdm - ok 16:04:01.0718 2928 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 16:04:01.0734 2928 PCI - ok 16:04:01.0734 2928 PCIDump - ok 16:04:01.0750 2928 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 16:04:01.0750 2928 PCIIde - ok 16:04:01.0781 2928 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 16:04:01.0796 2928 Pcmcia - ok 16:04:01.0796 2928 PDCOMP - ok 16:04:01.0812 2928 PDFRAME - ok 16:04:01.0812 2928 PDRELI - ok 16:04:01.0828 2928 PDRFRAME - ok 16:04:01.0843 2928 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 16:04:01.0843 2928 perc2 - ok 16:04:01.0859 2928 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 16:04:01.0859 2928 perc2hib - ok 16:04:01.0906 2928 PfModNT (c8a2d6ff660ac601b7bb9a9b16a5c25e) C:\WINDOWS\system32\drivers\PfModNT.sys 16:04:01.0906 2928 PfModNT - ok 16:04:01.0953 2928 PID_0928 (5bd2c6d982481d548107c602e7ccfbbc) C:\WINDOWS\system32\DRIVERS\LV561AV.SYS 16:04:02.0000 2928 PID_0928 - ok 16:04:02.0046 2928 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe 16:04:02.0046 2928 PlugPlay - ok 16:04:02.0093 2928 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 16:04:02.0109 2928 PolicyAgent - ok 16:04:02.0156 2928 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 16:04:02.0156 2928 PptpMiniport - ok 16:04:02.0156 2928 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 16:04:02.0156 2928 ProtectedStorage - ok 16:04:02.0171 2928 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 16:04:02.0171 2928 PSched - ok 16:04:02.0171 2928 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 16:04:02.0187 2928 Ptilink - ok 16:04:02.0218 2928 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys 16:04:02.0234 2928 PxHelp20 - ok 16:04:02.0234 2928 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 16:04:02.0234 2928 ql1080 - ok 16:04:02.0250 2928 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 16:04:02.0250 2928 Ql10wnt - ok 16:04:02.0281 2928 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 16:04:02.0281 2928 ql12160 - ok 16:04:02.0312 2928 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 16:04:02.0312 2928 ql1240 - ok 16:04:02.0328 2928 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 16:04:02.0328 2928 ql1280 - ok 16:04:02.0421 2928 RAIDStorAgent (acea07ec18f2ba8d370aa9bd89710c39) c:\Program Files\Dell\RAID Storage Manager\StorServ.exe 16:04:02.0421 2928 RAIDStorAgent - ok 16:04:02.0484 2928 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 16:04:02.0484 2928 RasAcd - ok 16:04:02.0531 2928 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll 16:04:02.0546 2928 RasAuto - ok 16:04:02.0578 2928 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 16:04:02.0578 2928 Rasl2tp - ok 16:04:02.0640 2928 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll 16:04:02.0687 2928 RasMan - ok 16:04:02.0703 2928 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 16:04:02.0703 2928 RasPppoe - ok 16:04:02.0703 2928 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 16:04:02.0703 2928 Raspti - ok 16:04:02.0750 2928 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 16:04:02.0750 2928 Rdbss - ok 16:04:02.0812 2928 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 16:04:02.0812 2928 RDPCDD - ok 16:04:02.0875 2928 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 16:04:02.0921 2928 rdpdr - ok 16:04:02.0984 2928 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys 16:04:02.0984 2928 RDPWD - ok 16:04:03.0031 2928 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe 16:04:03.0046 2928 RDSessMgr - ok 16:04:03.0062 2928 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 16:04:03.0062 2928 redbook - ok 16:04:03.0125 2928 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll 16:04:03.0125 2928 RemoteAccess - ok 16:04:03.0171 2928 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll 16:04:03.0171 2928 RemoteRegistry - ok 16:04:03.0421 2928 RosettaStoneDaemon (7f7ca7deeb68e68fd67870e9a5ec33e2) C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe 16:04:03.0468 2928 RosettaStoneDaemon - ok 16:04:03.0609 2928 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe 16:04:03.0625 2928 RpcLocator - ok 16:04:03.0671 2928 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll 16:04:03.0671 2928 RpcSs - ok 16:04:03.0734 2928 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe 16:04:03.0734 2928 RSVP - ok 16:04:03.0796 2928 SABProcEnum - ok 16:04:03.0843 2928 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe 16:04:03.0843 2928 SamSs - ok 16:04:03.0953 2928 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 16:04:03.0953 2928 SASDIFSV - ok 16:04:03.0968 2928 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 16:04:03.0968 2928 SASKUTIL - ok 16:04:04.0015 2928 SBRE - ok 16:04:04.0015 2928 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe 16:04:04.0031 2928 SCardSvr - ok 16:04:04.0078 2928 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll 16:04:04.0093 2928 Schedule - ok 16:04:04.0156 2928 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 16:04:04.0156 2928 Secdrv - ok 16:04:04.0218 2928 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll 16:04:04.0218 2928 seclogon - ok 16:04:04.0265 2928 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll 16:04:04.0265 2928 SENS - ok 16:04:04.0312 2928 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 16:04:04.0312 2928 serenum - ok 16:04:04.0328 2928 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 16:04:04.0328 2928 Serial - ok 16:04:04.0343 2928 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 16:04:04.0343 2928 Sfloppy - ok 16:04:04.0468 2928 SgtSch2Svc (c240035fb95c2faef99cfc2403edcd46) C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe 16:04:04.0515 2928 SgtSch2Svc - ok 16:04:04.0562 2928 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 16:04:04.0562 2928 ShellHWDetection - ok 16:04:04.0578 2928 Simbad - ok 16:04:04.0609 2928 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 16:04:04.0609 2928 sisagp - ok 16:04:04.0640 2928 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 16:04:04.0640 2928 SLIP - ok 16:04:05.0046 2928 snapman (c3bf55189aa92b8f919108ef9e4accae) C:\WINDOWS\system32\DRIVERS\snapman.sys 16:04:05.0046 2928 snapman - ok 16:04:05.0062 2928 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 16:04:05.0062 2928 Sparrow - ok 16:04:05.0109 2928 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 16:04:05.0109 2928 splitter - ok 16:04:05.0156 2928 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe 16:04:05.0171 2928 Spooler - ok 16:04:05.0234 2928 SQLAgent$MICROSOFTBCM - ok 16:04:05.0281 2928 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 16:04:05.0281 2928 sr - ok 16:04:05.0312 2928 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll 16:04:05.0312 2928 srservice - ok 16:04:05.0359 2928 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 16:04:05.0375 2928 Srv - ok 16:04:05.0406 2928 sscdbhk5 (98625722ad52b40305e74aaa83c93086) C:\WINDOWS\system32\drivers\sscdbhk5.sys 16:04:05.0406 2928 sscdbhk5 - ok 16:04:05.0437 2928 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll 16:04:05.0437 2928 SSDPSRV - ok 16:04:05.0437 2928 ssrtln (d79412e3942c8a257253487536d5a994) C:\WINDOWS\system32\drivers\ssrtln.sys 16:04:05.0437 2928 ssrtln - ok 16:04:05.0500 2928 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 16:04:05.0500 2928 StillCam - ok 16:04:05.0562 2928 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll 16:04:05.0562 2928 stisvc - ok 16:04:05.0609 2928 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 16:04:05.0609 2928 streamip - ok 16:04:05.0640 2928 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 16:04:05.0640 2928 swenum - ok 16:04:05.0703 2928 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 16:04:05.0703 2928 swmidi - ok 16:04:05.0703 2928 SwPrv - ok 16:04:05.0750 2928 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 16:04:05.0750 2928 symc810 - ok 16:04:05.0765 2928 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 16:04:05.0765 2928 symc8xx - ok 16:04:05.0765 2928 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 16:04:05.0765 2928 sym_hi - ok 16:04:05.0781 2928 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 16:04:05.0781 2928 sym_u3 - ok 16:04:05.0828 2928 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 16:04:05.0828 2928 sysaudio - ok 16:04:05.0843 2928 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe 16:04:05.0843 2928 SysmonLog - ok 16:04:05.0906 2928 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll 16:04:05.0953 2928 TapiSrv - ok 16:04:06.0015 2928 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 16:04:06.0031 2928 Tcpip - ok 16:04:06.0078 2928 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 16:04:06.0078 2928 TDPIPE - ok 16:04:06.0140 2928 tdrpman (3b7b6779eb231f731bba8f9fe67aadfc) C:\WINDOWS\system32\DRIVERS\tdrpman.sys 16:04:06.0140 2928 tdrpman - ok 16:04:06.0187 2928 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 16:04:06.0203 2928 TDTCP - ok 16:04:06.0218 2928 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 16:04:06.0218 2928 TermDD - ok 16:04:06.0312 2928 TermService (56f4867bae6fd78e5365a3a7afa59c82) C:\WINDOWS\System32\termsrv32.dll 16:04:06.0328 2928 TermService - ok 16:04:06.0421 2928 tfsnboio (d0177776e11b0b3f272eebd262a69661) C:\WINDOWS\system32\dla\tfsnboio.sys 16:04:06.0421 2928 tfsnboio - ok 16:04:06.0437 2928 tfsncofs (599804bc938b8305a5422319774da871) C:\WINDOWS\system32\dla\tfsncofs.sys 16:04:06.0437 2928 tfsncofs - ok 16:04:06.0484 2928 tfsndrct (a1902c00adc11c4d83f8e3ed947a6a32) C:\WINDOWS\system32\dla\tfsndrct.sys 16:04:06.0484 2928 tfsndrct - ok 16:04:06.0531 2928 tfsndres (d8ddb3f2b1bef15cff6728d89c042c61) C:\WINDOWS\system32\dla\tfsndres.sys 16:04:06.0531 2928 tfsndres - ok 16:04:06.0546 2928 tfsnifs (c4f2dea75300971cdaee311007de138d) C:\WINDOWS\system32\dla\tfsnifs.sys 16:04:06.0546 2928 tfsnifs - ok 16:04:06.0562 2928 tfsnopio (272925be0ea919f08286d2ee6f102b0f) C:\WINDOWS\system32\dla\tfsnopio.sys 16:04:06.0562 2928 tfsnopio - ok 16:04:06.0578 2928 tfsnpool (7b7d955e5cebc2fb88b03ef875d52a2f) C:\WINDOWS\system32\dla\tfsnpool.sys 16:04:06.0578 2928 tfsnpool - ok 16:04:06.0593 2928 tfsnudf (e3d01263109d800c1967c12c10a0b018) C:\WINDOWS\system32\dla\tfsnudf.sys 16:04:06.0593 2928 tfsnudf - ok 16:04:06.0609 2928 tfsnudfa (b9e9c377906e3a65bc74598fff7f7458) C:\WINDOWS\system32\dla\tfsnudfa.sys 16:04:06.0609 2928 tfsnudfa - ok 16:04:06.0687 2928 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll 16:04:06.0703 2928 Themes - ok 16:04:06.0703 2928 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 16:04:06.0703 2928 tifsfilter - ok 16:04:06.0734 2928 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\WINDOWS\system32\DRIVERS\timntr.sys 16:04:06.0734 2928 timounter - ok 16:04:06.0796 2928 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe 16:04:06.0812 2928 TlntSvr - ok 16:04:06.0859 2928 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 16:04:06.0859 2928 TosIde - ok 16:04:06.0890 2928 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll 16:04:06.0906 2928 TrkWks - ok 16:04:06.0937 2928 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 16:04:06.0937 2928 Udfs - ok 16:04:06.0984 2928 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 16:04:06.0984 2928 ultra - ok 16:04:07.0031 2928 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 16:04:07.0078 2928 Update - ok 16:04:07.0140 2928 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll 16:04:07.0187 2928 upnphost - ok 16:04:07.0234 2928 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe 16:04:07.0234 2928 UPS - ok 16:04:07.0281 2928 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 16:04:07.0281 2928 usbaudio - ok 16:04:07.0343 2928 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 16:04:07.0343 2928 usbccgp - ok 16:04:07.0390 2928 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 16:04:07.0390 2928 usbehci - ok 16:04:07.0453 2928 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 16:04:07.0453 2928 usbhub - ok 16:04:07.0468 2928 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 16:04:07.0468 2928 usbprint - ok 16:04:07.0515 2928 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 16:04:07.0515 2928 usbscan - ok 16:04:07.0546 2928 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 16:04:07.0562 2928 USBSTOR - ok 16:04:07.0578 2928 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 16:04:07.0578 2928 usbuhci - ok 16:04:07.0625 2928 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys 16:04:07.0625 2928 usbvideo - ok 16:04:07.0687 2928 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 16:04:07.0687 2928 VgaSave - ok 16:04:07.0718 2928 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 16:04:07.0718 2928 viaagp - ok 16:04:07.0750 2928 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 16:04:07.0750 2928 ViaIde - ok 16:04:07.0781 2928 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 16:04:07.0781 2928 VolSnap - ok 16:04:07.0843 2928 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe 16:04:07.0859 2928 VSS - ok 16:04:07.0921 2928 w32time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll 16:04:07.0953 2928 w32time - ok 16:04:08.0015 2928 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 16:04:08.0015 2928 Wanarp - ok 16:04:08.0015 2928 WDICA - ok 16:04:08.0062 2928 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 16:04:08.0062 2928 wdmaud - ok 16:04:08.0125 2928 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll 16:04:08.0125 2928 WebClient - ok 16:04:08.0234 2928 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll 16:04:08.0234 2928 winmgmt - ok 16:04:08.0281 2928 WMDM PMSP Service (581176f60885aef8f78c6e38dcc3cdf9) C:\WINDOWS\system32\MsPMSPSv.exe 16:04:08.0296 2928 WMDM PMSP Service - ok 16:04:08.0343 2928 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll 16:04:08.0343 2928 WmdmPmSN - ok 16:04:08.0421 2928 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll 16:04:08.0437 2928 Wmi - ok 16:04:08.0484 2928 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe 16:04:08.0500 2928 WmiApSrv - ok 16:04:08.0687 2928 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe 16:04:08.0718 2928 WMPNetworkSvc - ok 16:04:08.0796 2928 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 16:04:08.0796 2928 WSTCODEC - ok 16:04:08.0875 2928 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll 16:04:08.0906 2928 wuauserv - ok 16:04:08.0968 2928 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 16:04:08.0968 2928 WudfPf - ok 16:04:09.0015 2928 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 16:04:09.0015 2928 WudfRd - ok 16:04:09.0078 2928 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll 16:04:09.0109 2928 WudfSvc - ok 16:04:09.0203 2928 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll 16:04:09.0218 2928 WZCSVC - ok 16:04:09.0265 2928 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll 16:04:09.0265 2928 xmlprov - ok 16:04:09.0296 2928 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 16:04:09.0312 2928 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected 16:04:09.0312 2928 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0) 16:04:09.0343 2928 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1 16:04:09.0390 2928 \Device\Harddisk1\DR1 - ok 16:04:09.0406 2928 Boot (0x1200) (a66acd30ee434917578bc167b45a21f7) \Device\Harddisk0\DR0\Partition0 16:04:09.0406 2928 \Device\Harddisk0\DR0\Partition0 - ok 16:04:09.0421 2928 Boot (0x1200) (b989df2146b5498dea9fd5a7010953e7) \Device\Harddisk1\DR1\Partition0 16:04:09.0421 2928 \Device\Harddisk1\DR1\Partition0 - ok 16:04:09.0421 2928 ============================================================ 16:04:09.0421 2928 Scan finished 16:04:09.0421 2928 ============================================================ 16:04:09.0421 1804 Detected object count: 1 16:04:09.0421 1804 Actual detected object count: 1 16:04:37.0218 1804 \Device\Harddisk0\DR0\# - copied to quarantine 16:04:37.0218 1804 \Device\Harddisk0\DR0 - copied to quarantine 16:04:37.0218 1804 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - will be cured on reboot 16:04:37.0265 1804 \Device\Harddisk0\DR0 - ok 16:04:37.0265 1804 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Cure 16:04:42.0312 2584 Deinitialize success
Looks like TDSSkiller didn't get it. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-22 16:14:53 —————————– 16:14:53.234 OS Version: Windows 5.1.2600 Service Pack 3 16:14:53.234 Number of processors: 2 586 0x403 16:14:53.234 ComputerName: DAN UserName: 16:14:54.171 Initialize success 16:15:09.281 AVAST engine defs: 12072200 16:15:13.484 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 16:15:13.484 Disk 0 Vendor: WDC_WD1600JS-75NCB1 10.02E01 Size: 152587MB BusType: 3 16:15:13.484 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-22 16:15:13.484 Disk 1 Vendor: ST3500413AS JC45 Size: 476940MB BusType: 3 16:15:13.515 Disk 0 MBR read successfully 16:15:13.515 Disk 0 MBR scan 16:15:13.546 Disk 0 Windows XP default MBR code 16:15:13.562 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 16:15:13.578 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152539 MB offset 80325 16:15:13.593 Disk 0 scanning sectors +312480315 16:15:13.625 Disk 0 malicious Win32:MBRoot code @ sector 312480318 ! 16:15:13.718 Disk 0 scanning C:\WINDOWS\system32\drivers 16:15:32.812 Service scanning 16:15:58.640 Modules scanning 16:16:09.312 Disk 0 trace - called modules: 16:16:09.328 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 16:16:09.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87153ab8] 16:16:09.343 3 CLASSPNP.SYS[f7592fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x871cbd98] 16:16:10.046 AVAST engine scan C:\WINDOWS 16:16:23.671 AVAST engine scan C:\WINDOWS\system32 16:20:29.781 AVAST engine scan C:\WINDOWS\system32\drivers 16:21:00.234 AVAST engine scan C:\Documents and Settings\O'Toole 16:29:28.734 File: C:\Documents and Settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n **INFECTED** Win32:Sirefef-PL [Rtk] 16:36:52.453 AVAST engine scan C:\Documents and Settings\All Users 17:10:38.718 Scan finished successfully 17:11:13.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\MBR.dat" 17:11:13.546 The log file has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\aswMBR2.txt"
16:15:13.546 Disk 0 Windows XP default MBR code <- this indicates a clean MBR

16:15:13.625 Disk 0 malicious Win32:MBRoot code @ sector 312480318 !<- this indicates a remnant of malicious code after the MBR was fixed


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Ok, before starting combofix, I went to see if I had any av programs running that might interfere. One of things was Windows XP fire wall, so when I went to disable that (start->> Control Panel –> Security Center) I found that the security center had been disabled and I couldn't get it started, even after a reboot.

So I ran Combofix which installed the restore point thing and then went through the rest of the process. I could tell it worked because my icons went back to roughly where they should have been and the desktop background image displayed properly.

Unfortunately, the desktop image then disappeared, the desktop icons re-shifted and when I started internet explorer a warning message popped up stating it wasn't my default browser. I made it my default and another warning message popped up saying that I was about to view pages over a secure connection. It took me to google, but it was https instead of normal http. WhattheTech now has video ads, which I'm pretty sure are not legit. So it looks like I'm infected again, although this is different than what I noticed on the original infection.

I went and deleted the two XP accounts that I had created a few days ago when I thought I just had a corrupted profile. I didn't actually log into them before being reinfected, but decided to get rid of them just in case anything was hiding out.

Processes that occasionally appear in the task manager are :
csrss.exe
crfmon.exe
brmfRsmg.exe
lsass.exe
jqs.exe

Not sure if that helps. Here is the combofix log. What's the next move?



ComboFix 12-07-21.01 - O'Toole 07/22/2012 21:45:55.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.580 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Dano\g2mdlhlpx.exe
c:\documents and settings\HelpAssistant\g2mdlhlpx.exe
c:\documents and settings\O'Toole\g2mdlhlpx.exe
c:\documents and settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}
c:\documents and settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\@
c:\documents and settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\@
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\L\00000004.@
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\L\1afb2d56
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\L\201d3dde
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\00000004.@
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\000000cb.@
c:\windows\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\80000032.@
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-22 20:04 . 2012-07-22 20:04 ——– d—–w- C:\TDSSKiller_Quarantine
2012-07-16 01:16 . 2012-07-23 01:58 ——– d—–w- c:\documents and settings\Dano
2012-06-28 07:47 . 2012-06-28 07:47 ——– d—–w- c:\documents and settings\O'Toole\Application Data\Sony Corporation
2012-06-28 07:42 . 2007-04-04 22:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2012-06-28 07:41 . 2007-04-04 22:55 261480 —-a-w- c:\windows\system32\xactengine2_7.dll
2012-06-28 07:41 . 2007-03-15 20:57 443752 —-a-w- c:\windows\system32\d3dx10_33.dll
2012-06-28 07:41 . 2007-03-12 20:42 1123696 —-a-w- c:\windows\system32\D3DCompiler_33.dll
2012-06-28 07:35 . 2006-11-02 20:57 118520 —-a-w- c:\windows\system32\PxInsI64.exe
2012-06-28 07:35 . 2006-10-18 23:43 115960 —-a-w- c:\windows\system32\PxCpyI64.exe
2012-06-28 07:35 . 2012-06-28 07:35 ——– d—–w- c:\program files\Sony
2012-06-28 07:34 . 2012-06-28 07:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony Corporation
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-17 04:32 . 2012-06-17 04:32 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-06-13 13:19 . 2004-08-11 23:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-08-31 02:11 1372672 ——w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-11 23:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2004-08-11 23:00 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2007-06-18 17:41 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2007-06-18 17:41 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2004-08-11 23:12 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2004-08-11 23:12 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2004-08-11 23:12 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2007-06-18 17:41 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-05-26 08:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2004-08-11 23:12 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2004-08-11 23:12 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2004-08-11 23:00 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2007-06-18 17:41 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2004-08-11 23:12 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2004-08-11 23:12 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2004-08-11 23:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-11 23:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2004-08-11 23:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-08-11 23:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-11 23:00 385024 —-a-w- c:\windows\system32\html.iec
2012-05-08 16:40 . 2012-06-06 20:44 6737808 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A0CBFE-8990-4054-B6FC-98E269ABB17E}\mpengine.dll
2012-05-08 16:40 . 2012-06-05 19:36 6737808 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-04 13:16 . 2004-08-11 23:00 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-04 04:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2004-08-11 23:11 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-02 4616192]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"CTHelper"="CTHELPER.EXE" [2003-02-21 28672]
"AsioReg"="CTASIO.DLL" [2003-02-21 110592]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"SetDefPrt"="c:\program files\Brother\Brmfl04e\BrStDvPt.exe" [2004-05-25 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2009-05-20 3618104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-17 30192]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-10-16 1325936]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2009-10-16 904840]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2009-10-16 136544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\O'Toole\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2012-6-28 385024]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMM Mode Selection]
2011-02-14 13:55 43520 —-a-r- c:\program files\HTC\ModeSelection\VMMModeSelection.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 AFAmgt;AFAmgt;c:\windows\system32\drivers\afamgt.sys [4/1/2005 6:40 PM 92571]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 12:27 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 7:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [2/8/2004 10:02 AM 118784]
R2 AsfAlrt;AsfAlrt;c:\windows\system32\drivers\Asfalrt.sys [12/18/2002 6:31 AM 36064]
R2 RAIDStorAgent;RAID Storage Manager Agent;c:\program files\Dell\RAID Storage Manager\StorServ.exe [7/6/2005 5:55 PM 53248]
R2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\RosettaStoneLtdServices\RosettaStoneDaemon.exe [5/17/2010 3:45 PM 1615176]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [10/16/2009 6:39 PM 431456]
R3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [3/27/2006 1:22 AM 2944]
R3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [3/27/2006 1:21 AM 61952]
R3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [3/27/2006 1:22 AM 11008]
R3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [3/27/2006 1:22 AM 10368]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/18/2009 3:51 AM 30192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/17/2012 12:32 AM 40776]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys –> c:\windows\system32\drivers\SBREdrv.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell
uInternet Settings,ProxyOverride = localhost;*.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: rexplorer.net
TCP: DhcpNameServer = 192.168.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {3BF72F68-72D8-461D-A884-329D936C5581} - hxxp://picwash.com/ImageUploader5.cab
DPF: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-MsMpSvc
MSConfigStartUp-HLBackupScheduler - c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 22:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E4568B1F-886D-9AB5-1E4B01E7F0FA32FF}\{B2981650-D0BF-E14F-9D9AB95C0FC2939B}\{CDC4F2F4-402E-87A1-4EFD68E3BEB8F4B3}*]
"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,
fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(920)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(2696)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\PENUSA.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\BRMFRSMG.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2012-07-22 22:10:06 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-23 02:10
.
Pre-Run: 52,005,036,032 bytes free
Post-Run: 52,195,033,088 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 1ADD45D9E0311B6EF6BC35A0F1B71547
Hi,

If cookies where removed and you went to the WTT homepage, it does show some adds, once you log in there gone.

All or most of what Combofix removed where related to the Zero Access rootkit and I dont see any trace of it on the rest or your log.


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
I'm logged in and I still see ads. ESET found a few items: C:\Qoobox\Quarantine\C\Documents and Settings\O'Toole\Local Settings\Application Data\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n.vir Win32/Sirefef.EV trojan C:\Qoobox\Quarantine\C\WINDOWS\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\n.vir Win32/Sirefef.EV trojan C:\Qoobox\Quarantine\C\WINDOWS\Installer\{d3489641-00fc-8875-180a-0ce3ff378d9a}\U\80000032.@.vir a variant of Win32/Sirefef.FD trojan F:\2011 Black Drive\Lexington RE Computer\gargoyle.exe a variant of Win32/Adware.MarketScore.A application
Those files in Qoobox are backups of what Combofix removed, there harmless where they are and we will deal with them when where done.

gargoyle <– Do you use this program ?

13:38:19.500 Disk 0 malicious Win32:MBRoot code @ sector 312480318 ! <–This is infected but its a backup and cant hurt you but lets try to remove it

Run aswMBR to scan, when the scan is done click on FIX NOT FIXMBR

Important > you need to wait for the tool to report … Infection fixed successfully or MBR fixed successfully"
Do not reboot the machine until it has said so.

When you see the message restart the computer normally.

Then run aswMBR to scan again and post the new log please


What adds are you seeing, are you getting them on any other sites ??????

Then lets see a new DDS log

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
I don't use the gargoyle file. It's an old desktop theme from an old computer that's just on a backup drive. I haven't seen that file in years. I do see ads when logged in to WhatTheTech, but I logged in from my work computer and they're there too. They're AdChoices which seems normal. I guess the other ads are normal too. After I ran combofix yesterday, everything seemed normal for a few minutes. Icons were in their old locations (pre infection), the background image appeared, I could get into Security Center again, etc, then things started acting funny again. All the icons were forcefully shoved to the left (some were piled on top of others and when I dragged them to my other screen they immediately jumped back to the left position), the ads could have been normal, but seemed forced to me, explorer said it wasn't my default browser and almost every time I click a link, it gives me a message about transmitting over a secure connection. Since yesterday, but before I ran aswMBR and hit fix, the icons stay where I put them (but they're not in their pre infection locations like after I ran combofix) the desktop background image is still gone and explorer keeps asking about the secure connection. I know the background image is there because I can see it when I log off, but it's not there during normal use. I just ran aswMBR, hit fix, and rebooted when it told me to. I then ran a new aswMBR scan and a dds scan. These are the logs: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-23 14:29:02 —————————– 14:29:02.265 OS Version: Windows 5.1.2600 Service Pack 3 14:29:02.265 Number of processors: 2 586 0x403 14:29:02.265 ComputerName: DAN UserName: 14:29:02.937 Initialize success 14:29:17.468 AVAST engine defs: 12072301 14:29:25.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 14:29:25.156 Disk 0 Vendor: WDC_WD1600JS-75NCB1 10.02E01 Size: 152587MB BusType: 3 14:29:25.156 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-22 14:29:25.156 Disk 1 Vendor: ST3500413AS JC45 Size: 476940MB BusType: 3 14:29:25.187 Disk 0 MBR read successfully 14:29:25.187 Disk 0 MBR scan 14:29:25.234 Disk 0 Windows XP default MBR code 14:29:25.234 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 14:29:25.265 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152539 MB offset 80325 14:29:25.265 Disk 0 scanning sectors +312480315 14:29:25.390 Disk 0 scanning C:\WINDOWS\system32\drivers 14:29:43.062 Service scanning 14:30:09.078 Modules scanning 14:30:16.406 Disk 0 trace - called modules: 14:30:16.421 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 14:30:16.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8717aab8] 14:30:16.421 3 CLASSPNP.SYS[f7592fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x871c6d98] 14:30:17.109 AVAST engine scan C:\WINDOWS 14:30:31.375 AVAST engine scan C:\WINDOWS\system32 14:33:40.765 AVAST engine scan C:\WINDOWS\system32\drivers 14:34:10.187 AVAST engine scan C:\Documents and Settings\O'Toole 14:48:44.296 AVAST engine scan C:\Documents and Settings\All Users 15:17:53.625 Scan finished successfully 15:19:07.828 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\MBR.dat" 15:19:07.843 The log file has been saved successfully to "C:\Documents and Settings\O'Toole\Desktop\aswMBR5.txt" . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 15:23:00 on 2012-07-23 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.527 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\Program Files\Intel\ASF Agent\ASFAgent.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\Brmfrmps.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe C:\WINDOWS\system32\nvsvc32.exe c:\Program Files\Dell\RAID Storage Manager\StorServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE C:\WINDOWS\system32\CTHELPER.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\BRMFRSMG.EXE C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe C:\Program Files\iPod\bin\iPodService.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell uInternet Settings,ProxyOverride = localhost;*.local BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 10\SnagitBHO.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 10\SnagitIEAddin.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [CTSysVol] c:\program files\creative\sbaudigy2\surround mixer\CTSysVol.exe mRun: [CTDVDDet] c:\program files\creative\sbaudigy2\dvdaudio\CTDVDDet.EXE mRun: [CTHelper] CTHELPER.EXE mRun: [AsioReg] REGSVR32.EXE /S CTASIO.DLL mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe mRun: [SetDefPrt] c:\program files\brother\brmfl04e\BrStDvPt.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [DiscWizardMonitor.exe] c:\program files\seagate\discwizard\DiscWizardMonitor.exe mRun: [AcronisTimounterMonitor] c:\program files\seagate\discwizard\TimounterMonitor.exe mRun: [Seagate Scheduler2 Service] "c:\program files\common files\seagate\schedule2\schedhlp.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\o'toole\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: rexplorer.net DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.caminova.net/ja/downloads/getmodule.aspx?lang=en DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - hxxp://www.alternatiff.com/install-ie/alttiff.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {3BF72F68-72D8-461D-A884-329D936C5581} - hxxp://picwash.com/ImageUploader5.cab DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://emeetings.webex.com/client/T27L10NSP11EP14-emeetings/event/ieatgpc.cab DPF: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{19A05A37-5D3E-44DB-BBC7-925450DF77F1} : DhcpNameServer = 192.168.1.1 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Authentication Packages = msv1_0 relog_ap . ============= SERVICES / DRIVERS =============== . R0 AFAmgt;AFAmgt;c:\windows\system32\drivers\afamgt.sys [2005-4-1 92571] R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 171064] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2004-2-8 118784] R2 AsfAlrt;AsfAlrt;c:\windows\system32\drivers\Asfalrt.sys [2002-12-18 36064] R2 RAIDStorAgent;RAID Storage Manager Agent;c:\program files\dell\raid storage manager\StorServ.exe [2005-7-6 53248] R2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files\rosettastoneltdservices\RosettaStoneDaemon.exe [2010-5-17 1615176] R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\common files\seagate\schedule2\schedul2.exe [2009-10-16 431456] R3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2006-3-27 2944] R3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2006-3-27 61952] R3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2006-3-27 11008] R3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2006-3-27 10368] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-12-18 30192] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-6-17 40776] S3 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys –> c:\windows\system32\drivers\SBREdrv.sys [?] . =============== Created Last 30 ================ . 2012-07-23 08:20:49 ——– d—–w- c:\program files\ESET 2012-07-23 01:39:30 ——– d-sha-r- C:\cmdcons 2012-07-23 01:36:09 98816 —-a-w- c:\windows\sed.exe 2012-07-23 01:36:09 518144 —-a-w- c:\windows\SWREG.exe 2012-07-23 01:36:09 256000 —-a-w- c:\windows\PEV.exe 2012-07-23 01:36:09 208896 —-a-w- c:\windows\MBR.exe 2012-07-22 20:04:36 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-28 07:42:00 81768 —-a-w- c:\windows\system32\xinput1_3.dll 2012-06-28 07:41:53 261480 —-a-w- c:\windows\system32\xactengine2_7.dll 2012-06-28 07:41:28 443752 —-a-w- c:\windows\system32\d3dx10_33.dll 2012-06-28 07:41:28 1123696 —-a-w- c:\windows\system32\D3DCompiler_33.dll 2012-06-28 07:35:44 118520 —-a-w- c:\windows\system32\PxInsI64.exe 2012-06-28 07:35:44 115960 —-a-w- c:\windows\system32\PxCpyI64.exe 2012-06-28 07:35:34 ——– d—–w- c:\program files\Sony 2012-06-28 07:34:21 ——– d—–w- c:\documents and settings\all users\application data\Sony Corporation . ==================== Find3M ==================== . 2012-06-17 04:32:15 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-06-13 13:19:59 1866112 —-a-w- c:\windows\system32\win32k.sys 2012-06-05 15:50:25 1372672 ——w- c:\windows\system32\msxml6.dll 2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll 2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui 2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll 2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll 2012-05-11 14:42:33 43520 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-11 14:42:33 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2012-05-11 11:38:02 385024 —-a-w- c:\windows\system32\html.iec 2012-05-04 13:16:13 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 12:32:19 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-02 13:46:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys . ============= FINISH: 15:24:31.04 ===============

Attachments:

Well, the good news is that your Master Boot Record is not infected and the infected back up copy is gone. DDS looks ok also

Run this scan and post the log, it wont take long



OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI