This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Extremely slow computer [Closed]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My old topic

Sorry I was gone for a while and couldn't get back to finishing the issue as posted in the link.


HijackThis log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:34:57 AM, on 9/24/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\homework\HiJackThis(1).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Constant Guard Protection Suite (COM) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe /s
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'Default user')
O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
O4 - Global Startup: Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1311645391250
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GIDLogonXP - GIDLogonXP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CGPS Service (IDVaultSvc) - White Sky, Inc. - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

–
End of file - 6537 bytes



MBAM log:


Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.24.03

Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.6001.18702
Anna :: P-EE951AC334294 [limited]

10/16/2012 8:15:30 PM
mbam-log-2012-10-16 (20-15-30).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286066
Time elapsed: 14 minute(s), 43 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



OTL.txt


OTL logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT

Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120921.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.12.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 04:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_12_1 [2012/10/13 10:59:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/24 05:13:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/08/14 00:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/10/16 04:47:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 01:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 12:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2011/11/19 22:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 04:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/09/01 00:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 02:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/10/11 05:41:29 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/13 10:59:42 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_12_1
[2012/02/16 04:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/09/24 05:13:01 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 05:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/24 05:12:57 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite (COM)) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 23:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2012/10/14 22:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/10/13 10:56:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Tific
[2012/10/13 10:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Symantec
[2012/10/11 00:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Identities
[2012/10/04 07:00:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\Videos
[2012/10/04 06:52:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\150RACH_
[2012/10/04 06:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\149RACH_
[2012/09/24 05:12:53 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/09/23 21:53:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/09/18 08:42:00 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2012/09/18 04:37:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Apple Computer
[2012/09/18 03:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Apple Computer
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/16 04:43:36 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/16 04:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/15 14:49:57 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/15 04:36:10 | 000,000,229 | -HS- | M] () – C:\boot.ini
[2012/10/14 11:55:54 | 000,009,099 | —- | M] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/13 11:01:19 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/10/13 10:59:40 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/10/11 18:34:21 | 000,078,728 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | M] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | M] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | M] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:57 | 000,068,084 | —- | M] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:45 | 000,172,017 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:45 | 000,251,184 | —- | M] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:42 | 007,415,240 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 22:34:34 | 000,013,824 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/08 04:03:40 | 000,026,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:53 | 001,015,501 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:30 | 000,096,473 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:41 | 000,390,682 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:51 | 000,901,150 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/07 05:49:56 | 000,296,448 | —- | M] () – C:\WINDOWS\Xenofex.ini
[2012/10/06 11:28:13 | 000,044,368 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | M] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:09 | 000,300,130 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:16 | 000,158,402 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:25 | 000,121,741 | —- | M] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:57 | 000,126,771 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:07 | 002,265,284 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:43 | 000,147,280 | —- | M] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:44 | 001,021,823 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:47 | 001,001,913 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:40:01 | 000,004,953 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | M] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:23 | 000,062,714 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:27:49 | 000,028,453 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:33 | 000,087,232 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:38 | 000,072,730 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/24 03:03:24 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/09/22 23:00:12 | 000,018,521 | —- | M] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:38 | 000,036,432 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:53 | 000,120,484 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/14 11:55:54 | 000,009,099 | —- | C] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 18:34:21 | 000,078,728 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | C] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | C] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | C] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:56 | 000,068,084 | —- | C] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:44 | 000,172,017 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:44 | 000,251,184 | —- | C] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:40 | 007,415,240 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 04:03:39 | 000,026,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:52 | 001,015,501 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:29 | 000,096,473 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:40 | 000,390,682 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:50 | 000,901,150 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/06 11:28:13 | 000,044,368 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | C] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:08 | 000,300,130 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:15 | 000,158,402 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:24 | 000,121,741 | —- | C] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:56 | 000,126,771 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:06 | 002,265,284 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:42 | 000,147,280 | —- | C] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:43 | 001,021,823 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:46 | 001,001,913 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:39:12 | 000,004,953 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | C] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:22 | 000,062,714 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:19:16 | 000,028,453 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:32 | 000,087,232 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:37 | 000,072,730 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/22 23:00:00 | 000,018,521 | —- | C] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:34 | 000,036,432 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:51 | 000,120,484 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[2012/08/23 01:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 01:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 01:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 03:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 14:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 11:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 11:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 07:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 03:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 11:56:04 | 000,013,824 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 19:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/27 00:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/26 00:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 01:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 01:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 01:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 01:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/25 00:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/25 00:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 23:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 23:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 18:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 18:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 01:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 01:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 01:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/04/01 00:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini

========== ZeroAccess Check ==========

[2011/07/25 01:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/08/23 16:10:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2011/10/15 03:37:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2011/07/25 23:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/07/25 23:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2012/08/23 03:53:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Alien Skin
[2012/08/20 12:07:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Dropbox
[2011/10/15 03:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\HotSync
[2012/09/24 01:26:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\ID Vault
[2011/08/19 22:01:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Leadertech
[2012/08/21 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Oracle
[2012/06/27 08:23:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Philipp Winterberg
[2012/10/13 10:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Tific

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004/08/04 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 08:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

========== Drive Information ==========

Physical Drives
—————

Error accessing drive info (0)
Error accessing drive info (0)

Partitions
—————

Error accessing partition info (0)
Error accessing partition info (0)

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

< End of report >



Extras.txt


OTL Extras logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT

Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1B141C01-6491-45C1-BF2F-3FE6BF1FFE7C}_is1" = Colour Studio 2.0 Demo
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F474DDA-6E88-4176-9411-D22CF54B730B}_is1" = Chromagic version 1.1
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{6022299E-440C-43DA-825F-B58BCCB570B9}_is1" = Fotomatic version 1.4
"{607616CE-076C-49C7-A2E8-E6A6AB21053B}_is1" = Colour Surprise version 1.0
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{839CA7E5-5956-487D-8138-682907C5D576}_is1" = The Works version 3.2
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E1C7EF5E-3A7B-4ED4-A48B-F70F1B36EAB4}" = Corel Paint Shop Pro Photo XI
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alien Skin Exposure 4" = Alien Skin Exposure 4
"CleanUp!" = CleanUp!
"Enable S3 for USB Device" = Enable S3 for USB Device
"ID Vault" = Constant Guard Protection Suite
"ie8" = Windows Internet Explorer 8
"InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"Little Ink Pot's Chalkaholic Plugin_is1" = Chalkaholic Plugin v 1.1
"Little Ink Pot's Thredgeholder Plugin_is1" = Thredgeholder Plugin v 1.1
"Little Ink Pot's Xpose Plugin_is1" = Xpose Plugin v 1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"N360" = Norton Security Suite
"virtualPhotographer_is1" = virtualPhotographer 1.5.6
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"Xenofex 1.0" = Xenofex 1.0

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/11/2012 10:07:21 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning MainModule.FileName; failed Only part
of a ReadProcessMemory or WriteProcessMemory request was completed at System.Diagnostics.NtProcessManager.GetModuleInfos(Int32
processId, Boolean firstModuleOnly) at System.Diagnostics.NtProcessManager.GetFirstModuleInfo(Int32
processId) at System.Diagnostics.Process.get_MainModule() at .?. ()

Error - 9/15/2012 8:21:35 AM | Computer Name = P-EE951AC334294 | Source = .NET Runtime | ID = 1023
Description = .NET Runtime version 2.0.50727.3634 - Fatal Execution Engine Error
(7A0BC6A6) (80131506)

Error - 9/17/2012 5:55:28 PM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)

Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Display Flag Error Call was canceled by the message filter. (Exception
from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))

Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Interaction with the desktop is required. Enable desktop interaction
flag in Properties->Log On.

Error - 9/24/2012 12:58:05 AM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)

Error - 9/29/2012 12:48:01 AM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of C:\Documents and Settings\Anna\Application Data\Sun\Java\jre1.7.0_07\jre1.7.0_07-c.msi
is not permitted due to an error in software restriction policy processing. The
object cannot be trusted.

Error - 10/1/2012 1:08:56 AM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 10/7/2012 6:47:36 PM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 10/16/2012 8:33:13 PM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of E:\homework\HiJackThis.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.

[ System Events ]
Error - 10/16/2012 6:27:27 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2012 6:53:44 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/16/2012 8:10:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/16/2012 8:32:08 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/16/2012 8:32:13 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/16/2012 8:37:17 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 10/16/2012 8:39:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 10/16/2012 8:40:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}


< End of report >


GMER.txt


GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-10-16 20:48:52
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys


—- Kernel code sections - GMER 1.0.15 —-

? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[332] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 001A3D48
.text C:\WINDOWS\System32\svchost.exe[332] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 001A4672
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 001A46D3
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 001A4743
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!IsWindowVisible 7E429E3D 5 Bytes JMP 001A4776
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!MessageBoxIndirectW 7E4664D5 6 Bytes [33, C0, 40, C2, 04, 00] {XOR EAX, EAX; INC EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 001A48DC
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoGetClassObject 77515205 5 Bytes JMP 001A48B2
.text C:\WINDOWS\System32\svchost.exe[332] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 001A45D4

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-4 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T1L0-c 85E642E2
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Hello Saguin,

My name is OCD I was helping you in your previous thread. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

I am reviewing your logs and will be back as soon as possible with instructions.
Hi Saquin,

Can you confirm for me if you have about 50 images (jpg, gif) located on your Desktop, and another 20 in your My Documents folder?

  • Download on the desktop RogueKiller (by tigzy)
  • Quit all programs
  • Double Click the desktop icon to start RogueKiller
  • Wait until Prescan has finished …
  • Click on Scan
  • Click the Report button, save the report to your desktop
In your next post please provide the following:
  • RogueKiller log
  • Information about all the images
Yes, I can confirm all the images that are there.



RogueKiller V8.1.1 [10/01/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode with network support
User : Anna [Admin rights]
Mode : Scan – Date : 10/18/2012 18:00:47

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ Infection : Root.MBR ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
— User —
[MBR] 3a33b5c3bfd5886a8678f64d459b5db7
[BSP] a75b20bb05e18eda5a0213cb968b814a : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152625 Mo
User = LL1 … OK!
User != LL2 … KO!
— LL2 —
[MBR] bc8d4586aa0c6d780968fe1727c6e22f
[BSP] a75b20bb05e18eda5a0213cb968b814a : Windows XP MBR Code
Partition table:
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152625 Mo

+++++ PhysicalDrive1: Kingston DataTraveler 2.0 USB Device +++++
— User —
[MBR] b24c72d06a8ffcc127048ae80a73b708
[BSP] f1a6a8365d3ebae60ca5a197dc1f168b : MBR Code unknown
Partition table:
0 - [XXXXXX] UNKNOWN (0x72) [VISIBLE] Offset (sectors): 778135908 | Size: 557377 Mo
1 - [XXXXXX] UNKNOWN (0x65) [VISIBLE] Offset (sectors): 168689522 | Size: 945326 Mo
2 - [XXXXXX] UNKNOWN (0x79) [VISIBLE] Offset (sectors): 1869881465 | Size: 945326 Mo
3 - [XXXXXX] UNKNOWN (0x0d) [VISIBLE] Offset (sectors): 0 | Size: 1775989 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt
Hi Saquin,

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
In your next post please provide the following:
  • TDSSKiller log
15:55:53.0593 1700 TDSS rootkit removing tool [removed] Oct 12 2012 17:26:47 15:55:53.0953 1700 ============================================================ 15:55:53.0953 1700 Current date / time: 2012/10/20 15:55:53.0953 15:55:53.0953 1700 SystemInfo: 15:55:53.0953 1700 15:55:53.0953 1700 OS Version: 5.1.2600 ServicePack: 3.0 15:55:53.0953 1700 Product type: Workstation 15:55:53.0953 1700 ComputerName: P-EE951AC334294 15:55:53.0953 1700 UserName: Anna 15:55:53.0953 1700 Windows directory: C:\WINDOWS 15:55:53.0953 1700 System windows directory: C:\WINDOWS 15:55:53.0953 1700 Processor architecture: Intel x86 15:55:53.0953 1700 Number of processors: 2 15:55:53.0953 1700 Page size: 0x1000 15:55:53.0953 1700 Boot type: Safe boot with network 15:55:53.0953 1700 ============================================================ 15:55:56.0953 1700 Drive \Device\Harddisk0\DR0 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 15:55:56.0953 1700 Drive \Device\Harddisk1\DR2 - Size: 0x3B940000 (0.93 Gb), SectorSize: 0x200, Cylinders: 0x79, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 15:55:56.0968 1700 ============================================================ 15:55:56.0968 1700 \Device\Harddisk0\DR0: 15:55:56.0968 1700 MBR partitions: 15:55:56.0968 1700 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82 15:55:56.0968 1700 \Device\Harddisk1\DR2: 15:55:56.0968 1700 MBR partitions: 15:55:56.0968 1700 ============================================================ 15:55:56.0968 1700 C: <-> \Device\Harddisk0\DR0\Partition1 15:55:56.0984 1700 ============================================================ 15:55:56.0984 1700 Initialize success 15:55:56.0984 1700 ============================================================ 15:56:02.0750 1900 ============================================================ 15:56:02.0750 1900 Scan started 15:56:02.0750 1900 Mode: Manual; 15:56:02.0750 1900 ============================================================ 15:56:03.0671 1900 ================ Scan system memory ======================== 15:56:03.0671 1900 System memory - ok 15:56:03.0671 1900 ================ Scan services ============================= 15:56:03.0796 1900 Abiosdsk - ok 15:56:03.0812 1900 abp480n5 - ok 15:56:03.0875 1900 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:56:03.0875 1900 ACPI - ok 15:56:03.0937 1900 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 15:56:03.0937 1900 ACPIEC - ok 15:56:03.0937 1900 adpu160m - ok 15:56:03.0984 1900 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 15:56:03.0984 1900 aec - ok 15:56:04.0031 1900 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 15:56:04.0046 1900 AFD - ok 15:56:04.0046 1900 Aha154x - ok 15:56:04.0078 1900 aic78u2 - ok 15:56:04.0093 1900 aic78xx - ok 15:56:04.0140 1900 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 15:56:04.0140 1900 Alerter - ok 15:56:04.0171 1900 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 15:56:04.0171 1900 ALG - ok 15:56:04.0187 1900 AliIde - ok 15:56:04.0296 1900 [ 267FC636801EDC5AB28E14036349E3BE ] Ambfilt C:\WINDOWS\system32\drivers\Ambfilt.sys 15:56:04.0359 1900 Ambfilt - ok 15:56:04.0375 1900 amsint - ok 15:56:04.0406 1900 AppMgmt - ok 15:56:04.0421 1900 asc - ok 15:56:04.0437 1900 asc3350p - ok 15:56:04.0468 1900 asc3550 - ok 15:56:04.0593 1900 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 15:56:04.0593 1900 aspnet_state - ok 15:56:04.0640 1900 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:56:04.0640 1900 AsyncMac - ok 15:56:04.0687 1900 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 15:56:04.0687 1900 atapi - ok 15:56:04.0687 1900 Atdisk - ok 15:56:04.0734 1900 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:56:04.0734 1900 Atmarpc - ok 15:56:04.0781 1900 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 15:56:04.0781 1900 AudioSrv - ok 15:56:04.0828 1900 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 15:56:04.0828 1900 audstub - ok 15:56:04.0906 1900 [ F29D375926E36E3A56AF4805C7749302 ] BCUService C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe 15:56:04.0906 1900 BCUService - ok 15:56:04.0953 1900 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 15:56:04.0953 1900 Beep - ok 15:56:05.0125 1900 [ C364F02969E9A842321DD91BCFF749D4 ] BHDrvx86 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120919.001\BHDrvx86.sys 15:56:05.0203 1900 BHDrvx86 - ok 15:56:05.0250 1900 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 15:56:05.0328 1900 BITS - ok 15:56:05.0359 1900 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 15:56:05.0359 1900 Browser - ok 15:56:05.0406 1900 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 15:56:05.0406 1900 cbidf2k - ok 15:56:05.0437 1900 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 15:56:05.0437 1900 CCDECODE - ok 15:56:05.0453 1900 cd20xrnt - ok 15:56:05.0468 1900 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 15:56:05.0468 1900 Cdaudio - ok 15:56:05.0515 1900 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 15:56:05.0515 1900 Cdfs - ok 15:56:05.0531 1900 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:56:05.0531 1900 Cdrom - ok 15:56:05.0546 1900 Changer - ok 15:56:05.0609 1900 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 15:56:05.0609 1900 CiSvc - ok 15:56:05.0640 1900 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 15:56:05.0640 1900 ClipSrv - ok 15:56:05.0671 1900 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:56:05.0687 1900 clr_optimization_v2.0.50727_32 - ok 15:56:05.0703 1900 CmdIde - ok 15:56:05.0734 1900 COMSysApp - ok 15:56:05.0781 1900 Cpqarray - ok 15:56:05.0828 1900 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 15:56:05.0828 1900 CryptSvc - ok 15:56:05.0843 1900 dac2w2k - ok 15:56:05.0859 1900 dac960nt - ok 15:56:05.0921 1900 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 15:56:05.0937 1900 DcomLaunch - ok 15:56:05.0984 1900 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 15:56:05.0984 1900 Dhcp - ok 15:56:06.0000 1900 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 15:56:06.0000 1900 Disk - ok 15:56:06.0015 1900 dmadmin - ok 15:56:06.0093 1900 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 15:56:06.0125 1900 dmboot - ok 15:56:06.0140 1900 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 15:56:06.0140 1900 dmio - ok 15:56:06.0156 1900 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 15:56:06.0171 1900 dmload - ok 15:56:06.0203 1900 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 15:56:06.0203 1900 dmserver - ok 15:56:06.0250 1900 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 15:56:06.0250 1900 DMusic - ok 15:56:06.0281 1900 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 15:56:06.0281 1900 Dnscache - ok 15:56:06.0328 1900 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 15:56:06.0328 1900 Dot3svc - ok 15:56:06.0343 1900 dpti2o - ok 15:56:06.0375 1900 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 15:56:06.0375 1900 drmkaud - ok 15:56:06.0421 1900 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 15:56:06.0421 1900 EapHost - ok 15:56:06.0515 1900 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 15:56:06.0546 1900 eeCtrl - ok 15:56:06.0625 1900 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 15:56:06.0625 1900 EraserUtilRebootDrv - ok 15:56:06.0656 1900 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 15:56:06.0656 1900 ERSvc - ok 15:56:06.0703 1900 [ B8FA96995726D1FA58476E352C02AD82 ] ES lite Service C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE 15:56:06.0703 1900 ES lite Service - ok 15:56:06.0750 1900 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 15:56:06.0765 1900 Eventlog - ok 15:56:06.0796 1900 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 15:56:06.0812 1900 EventSystem - ok 15:56:06.0875 1900 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 15:56:06.0875 1900 Fastfat - ok 15:56:06.0921 1900 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 15:56:06.0921 1900 FastUserSwitchingCompatibility - ok 15:56:06.0953 1900 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 15:56:06.0953 1900 Fdc - ok 15:56:06.0968 1900 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 15:56:06.0968 1900 Fips - ok 15:56:07.0000 1900 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 15:56:07.0000 1900 Flpydisk - ok 15:56:07.0046 1900 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 15:56:07.0046 1900 FltMgr - ok 15:56:07.0140 1900 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 15:56:07.0140 1900 FontCache3.0.0.0 - ok 15:56:07.0156 1900 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:56:07.0156 1900 Fs_Rec - ok 15:56:07.0218 1900 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:56:07.0218 1900 Ftdisk - ok 15:56:07.0265 1900 [ D556CB79967E92B5CC69686D16C1D846 ] gdrv C:\WINDOWS\gdrv.sys 15:56:07.0750 1900 gdrv - ok 15:56:07.0781 1900 [ 5AE3A887ECE5BBB72CFAB273C2FD1CFA ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 15:56:07.0781 1900 GEARAspiWDM - ok 15:56:07.0843 1900 [ 20F6C49E2C410FCD32D781F521579BF5 ] GIDv2 C:\WINDOWS\system32\drivers\GIDv2.sys 15:56:07.0843 1900 GIDv2 - ok 15:56:07.0890 1900 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:56:07.0890 1900 Gpc - ok 15:56:07.0937 1900 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:56:07.0937 1900 HDAudBus - ok 15:56:08.0015 1900 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 15:56:08.0015 1900 helpsvc - ok 15:56:08.0062 1900 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 15:56:08.0062 1900 HidServ - ok 15:56:08.0109 1900 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:56:08.0109 1900 hidusb - ok 15:56:08.0140 1900 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 15:56:08.0140 1900 hkmsvc - ok 15:56:08.0156 1900 hpn - ok 15:56:08.0218 1900 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 15:56:08.0234 1900 HTTP - ok 15:56:08.0265 1900 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 15:56:08.0281 1900 HTTPFilter - ok 15:56:08.0281 1900 i2omgmt - ok 15:56:08.0312 1900 i2omp - ok 15:56:08.0359 1900 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 15:56:08.0359 1900 i8042prt - ok 15:56:08.0453 1900 [ ED3D980E2D3E15FE179269699D65F5A7 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 15:56:08.0531 1900 ialm - ok 15:56:08.0593 1900 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 15:56:08.0593 1900 IDriverT - ok 15:56:08.0671 1900 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 15:56:08.0718 1900 idsvc - ok 15:56:08.0796 1900 [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120921.001\IDSxpx86.sys 15:56:08.0812 1900 IDSxpx86 - ok 15:56:08.0906 1900 [ 70B0763C05C18B6FA18B18631A74ECDE ] IDVaultSvc C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe 15:56:08.0906 1900 IDVaultSvc - ok 15:56:08.0953 1900 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 15:56:08.0953 1900 Imapi - ok 15:56:09.0000 1900 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 15:56:09.0000 1900 ImapiService - ok 15:56:09.0031 1900 ini910u - ok 15:56:09.0265 1900 [ 1511286A30AC4F74F5E9AAC182BBEFBC ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 15:56:09.0421 1900 IntcAzAudAddService - ok 15:56:09.0437 1900 IntelIde - ok 15:56:09.0500 1900 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:56:09.0500 1900 intelppm - ok 15:56:09.0546 1900 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 15:56:09.0546 1900 Ip6Fw - ok 15:56:09.0578 1900 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:56:09.0593 1900 IpFilterDriver - ok 15:56:09.0593 1900 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:56:09.0593 1900 IpInIp - ok 15:56:09.0640 1900 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:56:09.0640 1900 IpNat - ok 15:56:09.0671 1900 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:56:09.0671 1900 IPSec - ok 15:56:09.0703 1900 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 15:56:09.0703 1900 IRENUM - ok 15:56:09.0765 1900 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:56:09.0765 1900 isapnp - ok 15:56:09.0875 1900 [ 4F2143570D2250CA4C4A4C98553C82CD ] JavaQuickStarterService C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe 15:56:09.0875 1900 JavaQuickStarterService - ok 15:56:09.0906 1900 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:56:09.0906 1900 Kbdclass - ok 15:56:09.0921 1900 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:56:09.0921 1900 kbdhid - ok 15:56:09.0968 1900 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 15:56:09.0968 1900 kmixer - ok 15:56:10.0031 1900 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 15:56:10.0031 1900 KSecDD - ok 15:56:10.0062 1900 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 15:56:10.0062 1900 lanmanserver - ok 15:56:10.0093 1900 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 15:56:10.0093 1900 lanmanworkstation - ok 15:56:10.0109 1900 lbrtfdc - ok 15:56:10.0156 1900 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 15:56:10.0156 1900 LmHosts - ok 15:56:10.0203 1900 [ ED643E777BA3F7151EF3F0FB6BE4F7F0 ] LVRS C:\WINDOWS\system32\DRIVERS\lvrs.sys 15:56:10.0250 1900 LVRS - ok 15:56:10.0406 1900 [ 5BC80451109A8DD7F2DDD35BCE2929A3 ] LVUVC C:\WINDOWS\system32\DRIVERS\lvuvc.sys 15:56:10.0531 1900 LVUVC - ok 15:56:10.0562 1900 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 15:56:10.0578 1900 Messenger - ok 15:56:10.0593 1900 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 15:56:10.0593 1900 mnmdd - ok 15:56:10.0640 1900 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 15:56:10.0640 1900 mnmsrvc - ok 15:56:10.0687 1900 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 15:56:10.0687 1900 Modem - ok 15:56:10.0734 1900 [ C7D9F9717916B34C1B00DD4834AF485C ] Monfilt C:\WINDOWS\system32\drivers\Monfilt.sys 15:56:10.0796 1900 Monfilt - ok 15:56:10.0812 1900 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:56:10.0812 1900 Mouclass - ok 15:56:10.0859 1900 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:56:10.0859 1900 mouhid - ok 15:56:10.0875 1900 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 15:56:10.0890 1900 MountMgr - ok 15:56:10.0968 1900 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 15:56:10.0968 1900 MozillaMaintenance - ok 15:56:10.0984 1900 mraid35x - ok 15:56:11.0031 1900 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:56:11.0046 1900 MRxDAV - ok 15:56:11.0093 1900 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:56:11.0125 1900 MRxSmb - ok 15:56:11.0140 1900 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 15:56:11.0140 1900 MSDTC - ok 15:56:11.0203 1900 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 15:56:11.0203 1900 Msfs - ok 15:56:11.0218 1900 MSIServer - ok 15:56:11.0234 1900 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:56:11.0234 1900 MSKSSRV - ok 15:56:11.0281 1900 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:56:11.0281 1900 MSPCLOCK - ok 15:56:11.0312 1900 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 15:56:11.0312 1900 MSPQM - ok 15:56:11.0328 1900 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:56:11.0328 1900 mssmbios - ok 15:56:11.0359 1900 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 15:56:11.0359 1900 MSTEE - ok 15:56:11.0375 1900 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 15:56:11.0375 1900 Mup - ok 15:56:11.0468 1900 [ E78A365CC3E0FBFC018A33DCE01909F8 ] N360 C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe 15:56:11.0484 1900 N360 - ok 15:56:11.0515 1900 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 15:56:11.0515 1900 NABTSFEC - ok 15:56:11.0562 1900 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 15:56:11.0578 1900 napagent - ok 15:56:11.0671 1900 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVENG.SYS 15:56:11.0671 1900 NAVENG - ok 15:56:11.0781 1900 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVEX15.SYS 15:56:11.0828 1900 NAVEX15 - ok 15:56:11.0859 1900 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 15:56:11.0859 1900 NDIS - ok 15:56:11.0875 1900 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 15:56:11.0875 1900 NdisIP - ok 15:56:11.0921 1900 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:56:11.0921 1900 NdisTapi - ok 15:56:11.0968 1900 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:56:11.0968 1900 Ndisuio - ok 15:56:11.0984 1900 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:56:11.0984 1900 NdisWan - ok 15:56:12.0046 1900 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 15:56:12.0046 1900 NDProxy - ok 15:56:12.0078 1900 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 15:56:12.0078 1900 NetBIOS - ok 15:56:12.0125 1900 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 15:56:12.0125 1900 NetBT - ok 15:56:12.0156 1900 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 15:56:12.0171 1900 NetDDE - ok 15:56:12.0187 1900 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 15:56:12.0187 1900 NetDDEdsdm - ok 15:56:12.0234 1900 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 15:56:12.0234 1900 Netlogon - ok 15:56:12.0265 1900 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 15:56:12.0265 1900 Netman - ok 15:56:12.0296 1900 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 15:56:12.0296 1900 NetTcpPortSharing - ok 15:56:12.0328 1900 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 15:56:12.0343 1900 Nla - ok 15:56:12.0375 1900 [ 46FBEEBEBAED83EB6D774B9138536152 ] nlsX86cc C:\WINDOWS\system32\nlssrv32.exe 15:56:12.0375 1900 nlsX86cc - ok 15:56:12.0390 1900 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 15:56:12.0390 1900 Npfs - ok 15:56:12.0437 1900 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 15:56:12.0453 1900 Ntfs - ok 15:56:12.0468 1900 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 15:56:12.0468 1900 NtLmSsp - ok 15:56:12.0515 1900 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 15:56:12.0531 1900 NtmsSvc - ok 15:56:12.0562 1900 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 15:56:12.0562 1900 Null - ok 15:56:12.0625 1900 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:56:12.0625 1900 NwlnkFlt - ok 15:56:12.0625 1900 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:56:12.0625 1900 NwlnkFwd - ok 15:56:12.0718 1900 [ 240C0D4049A833B16B63B636ACF01672 ] PalmUSBD C:\WINDOWS\system32\drivers\PalmUSBD.sys 15:56:12.0718 1900 PalmUSBD - ok 15:56:12.0750 1900 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 15:56:12.0765 1900 Parport - ok 15:56:12.0765 1900 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 15:56:12.0765 1900 PartMgr - ok 15:56:12.0828 1900 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 15:56:12.0828 1900 ParVdm - ok 15:56:12.0843 1900 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 15:56:12.0843 1900 PCI - ok 15:56:12.0859 1900 PCIDump - ok 15:56:12.0906 1900 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 15:56:12.0906 1900 PCIIde - ok 15:56:12.0937 1900 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 15:56:12.0937 1900 Pcmcia - ok 15:56:12.0953 1900 PDCOMP - ok 15:56:12.0968 1900 PDFRAME - ok 15:56:13.0000 1900 PDRELI - ok 15:56:13.0015 1900 PDRFRAME - ok 15:56:13.0046 1900 perc2 - ok 15:56:13.0062 1900 perc2hib - ok 15:56:13.0125 1900 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 15:56:13.0125 1900 PlugPlay - ok 15:56:13.0140 1900 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 15:56:13.0156 1900 PolicyAgent - ok 15:56:13.0187 1900 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:56:13.0187 1900 PptpMiniport - ok 15:56:13.0203 1900 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 15:56:13.0203 1900 ProtectedStorage - ok 15:56:13.0265 1900 [ 64E413BA0C529AA40C3924BBCC4153DB ] ProtexisLicensing C:\WINDOWS\system32\PSIService.exe 15:56:13.0265 1900 ProtexisLicensing - ok 15:56:13.0281 1900 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 15:56:13.0281 1900 PSched - ok 15:56:13.0296 1900 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:56:13.0296 1900 Ptilink - ok 15:56:13.0328 1900 ql1080 - ok 15:56:13.0343 1900 Ql10wnt - ok 15:56:13.0359 1900 ql12160 - ok 15:56:13.0390 1900 ql1240 - ok 15:56:13.0406 1900 ql1280 - ok 15:56:13.0437 1900 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:56:13.0437 1900 RasAcd - ok 15:56:13.0484 1900 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 15:56:13.0500 1900 RasAuto - ok 15:56:13.0531 1900 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:56:13.0531 1900 Rasl2tp - ok 15:56:13.0578 1900 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 15:56:13.0578 1900 RasMan - ok 15:56:13.0593 1900 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:56:13.0593 1900 RasPppoe - ok 15:56:13.0609 1900 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 15:56:13.0609 1900 Raspti - ok 15:56:13.0656 1900 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:56:13.0656 1900 Rdbss - ok 15:56:13.0671 1900 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:56:13.0671 1900 RDPCDD - ok 15:56:13.0750 1900 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 15:56:13.0750 1900 RDPWD - ok 15:56:13.0781 1900 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 15:56:13.0796 1900 RDSessMgr - ok 15:56:13.0843 1900 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 15:56:13.0843 1900 redbook - ok 15:56:13.0875 1900 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 15:56:13.0875 1900 RemoteAccess - ok 15:56:13.0906 1900 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 15:56:13.0906 1900 RpcLocator - ok 15:56:13.0937 1900 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 15:56:13.0953 1900 RpcSs - ok 15:56:13.0984 1900 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 15:56:13.0984 1900 RSVP - ok 15:56:14.0031 1900 [ B29EEB1EA7971BD83069EB2E2258D224 ] RTL8192su C:\WINDOWS\system32\DRIVERS\RTL8192su.sys 15:56:14.0078 1900 RTL8192su - ok 15:56:14.0125 1900 [ 6FC7DDF3B8D94FBA7AC664452D6478D4 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 15:56:14.0125 1900 RTLE8023xp - ok 15:56:14.0156 1900 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 15:56:14.0156 1900 SamSs - ok 15:56:14.0187 1900 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 15:56:14.0187 1900 SCardSvr - ok 15:56:14.0234 1900 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 15:56:14.0234 1900 Schedule - ok 15:56:14.0265 1900 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:56:14.0265 1900 Secdrv - ok 15:56:14.0296 1900 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 15:56:14.0296 1900 seclogon - ok 15:56:14.0312 1900 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 15:56:14.0328 1900 SENS - ok 15:56:14.0343 1900 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 15:56:14.0343 1900 serenum - ok 15:56:14.0375 1900 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 15:56:14.0375 1900 Serial - ok 15:56:14.0437 1900 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 15:56:14.0437 1900 Sfloppy - ok 15:56:14.0468 1900 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 15:56:14.0531 1900 SharedAccess - ok 15:56:14.0593 1900 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 15:56:14.0593 1900 ShellHWDetection - ok 15:56:14.0609 1900 Simbad - ok 15:56:14.0843 1900 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 15:56:14.0859 1900 SkypeUpdate - ok 15:56:14.0921 1900 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 15:56:14.0921 1900 SLIP - ok 15:56:14.0984 1900 Sparrow - ok 15:56:15.0062 1900 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 15:56:15.0062 1900 splitter - ok 15:56:15.0140 1900 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 15:56:15.0171 1900 Spooler - ok 15:56:15.0265 1900 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 15:56:15.0281 1900 sr - ok 15:56:15.0328 1900 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 15:56:15.0375 1900 srservice - ok 15:56:15.0531 1900 [ 83726CF02ECED69138948083E06B6EAC ] SRTSP C:\WINDOWS\System32\Drivers\N360\0502020.003\SRTSP.SYS 15:56:15.0625 1900 SRTSP - ok 15:56:15.0687 1900 [ 4E7EAB2E5615D39CF1F1DF9C71E5E225 ] SRTSPX C:\WINDOWS\system32\drivers\N360\0502020.003\SRTSPX.SYS 15:56:15.0703 1900 SRTSPX - ok 15:56:15.0765 1900 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 15:56:15.0796 1900 Srv - ok 15:56:15.0843 1900 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 15:56:15.0843 1900 SSDPSRV - ok 15:56:15.0953 1900 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 15:56:16.0015 1900 stisvc - ok 15:56:16.0046 1900 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 15:56:16.0046 1900 streamip - ok 15:56:16.0078 1900 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 15:56:16.0078 1900 swenum - ok 15:56:16.0140 1900 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 15:56:16.0140 1900 swmidi - ok 15:56:16.0156 1900 SwPrv - ok 15:56:16.0187 1900 symc810 - ok 15:56:16.0203 1900 symc8xx - ok 15:56:16.0250 1900 [ 9BBEB8C6258E72D62E7560E6667AAD39 ] SymDS C:\WINDOWS\system32\drivers\N360\0502020.003\SYMDS.SYS 15:56:16.0265 1900 SymDS - ok 15:56:16.0312 1900 [ D5C02629C02A820A7E71BCA3D44294A3 ] SymEFA C:\WINDOWS\system32\drivers\N360\0502020.003\SYMEFA.SYS 15:56:16.0343 1900 SymEFA - ok 15:56:16.0359 1900 [ 98D28D08E68145FB550EE7670B43BAF2 ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 15:56:16.0375 1900 SymEvent - ok 15:56:16.0406 1900 [ A73399804D5D4A8B20BA60FCF70C9F1F ] SymIRON C:\WINDOWS\system32\drivers\N360\0502020.003\Ironx86.SYS 15:56:16.0406 1900 SymIRON - ok 15:56:16.0453 1900 [ 336CACE58F0359D5CBB1AE6B8A2FB205 ] SYMTDI C:\WINDOWS\System32\Drivers\N360\0502020.003\SYMTDI.SYS 15:56:16.0468 1900 SYMTDI - ok 15:56:16.0484 1900 sym_hi - ok 15:56:16.0500 1900 sym_u3 - ok 15:56:16.0546 1900 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 15:56:16.0546 1900 sysaudio - ok 15:56:16.0593 1900 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 15:56:16.0609 1900 SysmonLog - ok 15:56:16.0656 1900 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 15:56:16.0656 1900 TapiSrv - ok 15:56:16.0687 1900 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:56:16.0703 1900 Tcpip - ok 15:56:16.0734 1900 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 15:56:16.0734 1900 TDPIPE - ok 15:56:16.0765 1900 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 15:56:16.0765 1900 TDTCP - ok 15:56:16.0796 1900 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 15:56:16.0796 1900 TermDD - ok 15:56:16.0843 1900 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 15:56:16.0843 1900 TermService - ok 15:56:16.0875 1900 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 15:56:16.0875 1900 Themes - ok 15:56:16.0890 1900 TosIde - ok 15:56:16.0921 1900 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 15:56:16.0937 1900 TrkWks - ok 15:56:16.0968 1900 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 15:56:16.0968 1900 Udfs - ok 15:56:16.0984 1900 ultra - ok 15:56:17.0093 1900 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 15:56:17.0109 1900 UMVPFSrv - ok 15:56:17.0156 1900 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 15:56:17.0171 1900 Update - ok 15:56:17.0203 1900 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 15:56:17.0203 1900 upnphost - ok 15:56:17.0234 1900 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 15:56:17.0234 1900 UPS - ok 15:56:17.0281 1900 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 15:56:17.0281 1900 usbaudio - ok 15:56:17.0312 1900 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:56:17.0312 1900 usbccgp - ok 15:56:17.0343 1900 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:56:17.0343 1900 usbehci - ok 15:56:17.0359 1900 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:56:17.0359 1900 usbhub - ok 15:56:17.0406 1900 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:56:17.0406 1900 usbscan - ok 15:56:17.0437 1900 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:56:17.0437 1900 USBSTOR - ok 15:56:17.0453 1900 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 15:56:17.0453 1900 usbuhci - ok 15:56:17.0484 1900 [ 63BBFCA7F390F4C49ED4B96BFB1633E0 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys 15:56:17.0484 1900 usbvideo - ok 15:56:17.0500 1900 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 15:56:17.0500 1900 VgaSave - ok 15:56:17.0515 1900 ViaIde - ok 15:56:17.0562 1900 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 15:56:17.0562 1900 VolSnap - ok 15:56:17.0593 1900 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 15:56:17.0609 1900 VSS - ok 15:56:17.0625 1900 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 15:56:17.0625 1900 W32Time - ok 15:56:17.0671 1900 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:56:17.0671 1900 Wanarp - ok 15:56:17.0687 1900 WDICA - ok 15:56:17.0718 1900 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 15:56:17.0718 1900 wdmaud - ok 15:56:17.0750 1900 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 15:56:17.0765 1900 WebClient - ok 15:56:17.0843 1900 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 15:56:17.0843 1900 winmgmt - ok 15:56:17.0890 1900 [ C7E39EA41233E9F5B86C8DA3A9F1E4A8 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 15:56:17.0890 1900 WmdmPmSN - ok 15:56:17.0937 1900 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 15:56:17.0937 1900 WmiApSrv - ok 15:56:17.0968 1900 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 15:56:17.0968 1900 wscsvc - ok 15:56:18.0000 1900 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 15:56:18.0000 1900 WSTCODEC - ok 15:56:18.0031 1900 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 15:56:18.0062 1900 wuauserv - ok 15:56:18.0093 1900 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 15:56:18.0109 1900 WZCSVC - ok 15:56:18.0140 1900 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 15:56:18.0156 1900 xmlprov - ok 15:56:18.0187 1900 ================ Scan global =============================== 15:56:18.0218 1900 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 15:56:18.0250 1900 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:56:18.0281 1900 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:56:18.0312 1900 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 15:56:18.0312 1900 [Global] - ok 15:56:18.0312 1900 ================ Scan MBR ================================== 15:56:18.0328 1900 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 15:56:18.0328 1900 Suspicious mbr (Forged): \Device\Harddisk0\DR0 15:56:18.0359 1900 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 15:56:18.0359 1900 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 15:56:18.0375 1900 [ ED8B2CF4CF01D149D81B0323A628726B ] \Device\Harddisk1\DR2 15:56:20.0171 1900 \Device\Harddisk1\DR2 - ok 15:56:20.0171 1900 ================ Scan VBR ================================== 15:56:20.0187 1900 [ C847526A1A9CDE6B8FF76A12765C8FD6 ] \Device\Harddisk0\DR0\Partition1 15:56:20.0187 1900 \Device\Harddisk0\DR0\Partition1 - ok 15:56:20.0203 1900 ============================================================ 15:56:20.0203 1900 Scan finished 15:56:20.0203 1900 ============================================================ 15:56:20.0234 1892 Detected object count: 1 15:56:20.0234 1892 Actual detected object count: 1 15:56:57.0015 1892 \Device\Harddisk0\DR0\# - copied to quarantine 15:56:57.0015 1892 \Device\Harddisk0\DR0 - copied to quarantine 15:56:57.0031 1892 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 15:56:57.0046 1892 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 15:56:57.0046 1892 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 15:56:57.0062 1892 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 15:56:57.0062 1892 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 15:56:57.0062 1892 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 15:56:57.0125 1892 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 15:56:57.0140 1892 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine 15:56:57.0156 1892 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 15:56:57.0156 1892 \Device\Harddisk0\DR0 - ok 15:57:02.0718 1892 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 15:57:09.0500 1512 Deinitialize success
Hi Saquin,

Please attempt to boot into Normal Mode, then run the following scans.
  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
Next

  • Re-run RogueKiller (by tigzy)
  • Quit all programs
  • Double Click the desktop icon to start RogueKiller
  • Wait until Prescan has finished …
  • Click on Scan
  • Click the Report button, save the report to your desktop
In your next post please provide the following:
  • OTL.txt
  • RogueKiller Report
  • Tell me how your computer is running at the moment

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI