—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 260292608
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 269266944
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 275640320
Downloaded database version: v2013.09.22.03
Downloaded database version: v2013.09.20.01
=======================================
Initializing…
———— Kernel report ————
09/23/2013 07:54:55
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HSFHWBS2.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\HSF_DP.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\e100b325.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\DRIVERS\afw.sys
\SystemRoot\system32\DRIVERS\afwcore.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\sthda.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\MODEMCSA.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\i2omgmt.SYS
\SystemRoot\system32\drivers\BdSpy.sys
\SystemRoot\system32\DRIVERS\NSKernel.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\System32\Drivers\MpFirewall.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\NSNetmon.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\wg111v3.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\system32\DRIVERS\Trufos.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\ipfltdrv.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR7
Upper Device Object: 0xffffffff86845ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff86c6f030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR6
Upper Device Object: 0xffffffff8682e498
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff86c438e0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR5
Upper Device Object: 0xffffffff86815500
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xffffffff86c66ea0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR4
Upper Device Object: 0xffffffff86829ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xffffffff86c64650
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff86f5fab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-17\
Lower Device Object: 0xffffffff86f61d98
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86f60b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86f61d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-17\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E686F016
Partition information:
Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 96327
Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 96390 Numsec = 302664600
Partition file system is NTFS
Partition is bootable
Partition 2 type is Other (0xdb)
Partition is NOT ACTIVE.
Partition starts at LBA: 302760990 Numsec = 9735390
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 160000000000 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-312480000-312500000)…
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86832020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c64650, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86826020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c66ea0, DeviceName: \Device\00000067\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8682e270, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c438e0, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86818020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c6f030, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
———— End ———-
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 383320064
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 382242816
Downloaded database version: v2013.09.24.10
Downloaded database version: v2013.09.23.01
Initializing…
======================
———— Kernel report ————
09/25/2013 22:09:30
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HSFHWBS2.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\HSF_DP.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\e100b325.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\DRIVERS\afw.sys
\SystemRoot\system32\DRIVERS\afwcore.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\sthda.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\MODEMCSA.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\i2omgmt.SYS
\SystemRoot\system32\drivers\BdSpy.sys
\SystemRoot\system32\DRIVERS\NSKernel.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\System32\Drivers\MpFirewall.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\NSNetmon.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\wg111v3.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\system32\DRIVERS\Trufos.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\ipfltdrv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR7
Upper Device Object: 0xffffffff86764ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff8681d810
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR6
Upper Device Object: 0xffffffff86760408
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff8679f030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR5
Upper Device Object: 0xffffffff86765ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xffffffff86765870
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR4
Upper Device Object: 0xffffffff86775600
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xffffffff86794030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff86f6aab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-17\
Lower Device Object: 0xffffffff86f59d98
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff86f6aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86f58b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86f6aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86f59d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-17\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E686F016
Partition information:
Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 96327
Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 96390 Numsec = 302664600
Partition file system is NTFS
Partition is bootable
Partition 2 type is Other (0xdb)
Partition is NOT ACTIVE.
Partition starts at LBA: 302760990 Numsec = 9735390
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 160000000000 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-312480000-312500000)…
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86775600, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8677d690, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86775600, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86794030, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86765ab8, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86765440, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86765ab8, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86765870, DeviceName: \Device\00000067\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff86760408, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86765228, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86760408, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8679f030, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86764ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8677d020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86764ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8681d810, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
———— End ———-
=======================================
**Combo fix had some kind of error when trying to download the recovery console
ComboFix 13-09-24.02 - janell brown 09/26/2013 7:33.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.223 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Services
.
.
((((((((((((((((((((((((( Files Created from 2013-08-26 to 2013-09-26 )))))))))))))))))))))))))))))))
.
.
2013-09-23 19:26 . 2013-09-23 19:28 ——– d—–w- C:\AdwCleaner
2013-09-23 14:54 . 2013-09-26 05:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-09-23 14:54 . 2013-09-26 05:09 105176 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2013-09-23 14:52 . 2013-09-23 14:52 48728 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-09-20 16:56 . 2013-09-20 16:56 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\BullGuard
2013-09-20 15:54 . 2009-02-27 10:42 31640 —-a-w- c:\windows\system32\msonpmon.dll
2013-09-20 15:54 . 2006-10-27 02:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2013-09-20 15:53 . 2013-09-22 19:06 ——– d—–w- c:\program files\Microsoft Works
2013-09-20 15:52 . 2013-09-20 15:52 ——– d—–w- c:\program files\Microsoft.NET
2013-09-20 15:50 . 2013-09-20 15:51 ——– d—–w- c:\windows\SHELLNEW
2013-09-20 15:50 . 2013-09-20 15:50 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Microsoft Help
2013-09-20 15:50 . 2013-09-26 01:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2013-09-20 15:49 . 2013-09-20 15:49 ——– d—–r- C:\MSOCache
2013-09-18 13:59 . 2013-09-18 13:59 ——– d–h–w- c:\documents and settings\LocalService\Application Data\GTek
2013-09-17 18:49 . 2010-11-17 01:11 267112 —-a-r- c:\windows\system32\hpinksts9311LM.dll
2013-09-17 18:49 . 2010-11-17 01:11 232296 —-a-r- c:\windows\system32\hpinksts9311.dll
2013-09-17 18:49 . 2010-11-17 01:11 213864 —-a-r- c:\windows\system32\hpinkcoi9311.dll
2013-09-17 18:34 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-09-17 18:34 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\dllcache\usbprint.sys
2013-09-12 04:10 . 2013-09-12 04:10 ——– d—–w- c:\program files\Microsoft Silverlight
2013-09-12 01:42 . 2013-09-12 01:42 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2013-09-09 02:05 . 2013-09-09 02:05 ——– d—–w- c:\program files\Common Files\Skype
2013-09-09 02:05 . 2013-09-09 02:05 ——– d—–r- c:\program files\Skype
2013-09-09 02:03 . 2013-09-09 02:03 ——– d—–w- c:\program files\Common Files\Java
2013-09-09 02:02 . 2013-09-09 02:02 144896 —-a-w- c:\windows\system32\javacpl.cpl
2013-09-09 02:02 . 2013-09-09 02:02 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-09-09 02:02 . 2013-09-09 02:02 ——– d—–w- c:\program files\Java
2013-09-09 01:25 . 2013-09-09 02:10 ——– d—–w- c:\windows\SxsCaPendDel
2013-09-08 23:45 . 2010-09-18 06:53 954368 ——w- c:\windows\system32\dllcache\mfc40.dll
2013-09-08 23:45 . 2010-09-18 06:53 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll
2013-09-08 23:44 . 2013-08-08 06:05 522240 ——w- c:\windows\system32\dllcache\jsdbgui.dll
2013-09-08 23:40 . 2010-08-23 16:12 617472 ——w- c:\windows\system32\dllcache\comctl32.dll
2013-09-08 23:38 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2013-09-08 23:37 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2013-09-08 23:37 . 2013-02-12 00:32 12928 ——w- c:\windows\system32\dllcache\usb8023x.sys
2013-09-08 23:37 . 2013-02-12 00:32 12928 ——w- c:\windows\system32\dllcache\usb8023.sys
2013-09-08 23:36 . 2012-05-28 18:16 536576 ——w- c:\windows\system32\dllcache\msado15.dll
2013-09-08 23:35 . 2012-07-04 14:05 139784 ——w- c:\windows\system32\dllcache\rdpwd.sys
2013-09-08 23:34 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2013-09-08 23:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-09-08 23:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\dllcache\iacenc.dll
2013-09-08 23:33 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2013-09-08 23:03 . 2012-06-02 22:19 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2013-09-08 21:55 . 2013-09-10 23:55 ——– d—–w- c:\windows\system32\MRT
2013-09-08 20:59 . 2013-08-08 06:05 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2013-09-08 20:59 . 2013-08-08 06:05 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2013-09-08 20:59 . 2013-08-08 06:05 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2013-09-08 20:51 . 2013-09-08 20:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\scripting
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\l2schemas
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\en
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\bits
2013-09-08 20:01 . 2013-09-08 20:01 ——– d—–w- c:\documents and settings\janell brown\Application Data\vlc
2013-09-08 19:53 . 2013-09-08 19:53 ——– d—–w- c:\program files\VideoLAN
2013-09-08 19:22 . 2013-09-08 19:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\BullGuard
2013-09-08 19:22 . 2013-09-20 15:10 ——– d—–w- c:\documents and settings\janell brown\Application Data\BullGuard
2013-09-08 19:22 . 2013-09-26 14:40 ——– d—–w- c:\documents and settings\All Users\Application Data\BullGuard
2013-09-08 19:20 . 2013-09-08 19:20 ——– d—–w- c:\program files\Common Files\BullGuard Ltd
2013-09-08 19:20 . 2013-09-08 19:20 ——– d—–w- c:\program files\BullGuard Ltd
2013-09-08 18:29 . 2013-09-08 18:29 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Logitech® Webcam Software
2013-09-08 03:02 . 2013-09-08 03:02 ——– d-sh–w- c:\documents and settings\janell brown\PrivacIE
2013-09-08 00:05 . 2013-09-08 00:05 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Sun
2013-09-07 23:47 . 2013-09-07 23:47 ——– d—–w- c:\program files\ATI
2013-09-07 23:42 . 2013-09-07 23:42 ——– d—–w- C:\AMD
2013-09-07 23:08 . 2013-09-07 23:08 ——– d-sh–w- c:\documents and settings\janell brown\IETldCache
2013-09-07 23:04 . 2013-09-07 23:05 ——– dc-h–w- c:\windows\ie8
2013-09-07 22:59 . 2013-09-07 22:59 ——– d—–w- c:\program files\FileHippo.com
2013-09-07 22:55 . 2013-09-09 02:02 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-09-07 06:58 . 2013-09-07 07:10 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2013-09-07 06:58 . 2013-09-07 07:10 ——– d—–w- c:\program files\PCPitstop
2013-09-07 06:53 . 2013-09-26 01:42 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-07 06:53 . 2013-09-26 01:42 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-07 05:35 . 2013-09-07 05:35 ——– d—–w- c:\program files\CCleaner
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\documents and settings\janell brown\Application Data\Malwarebytes
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-09-07 03:21 . 2013-04-04 21:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-09-07 03:02 . 2013-09-07 03:02 ——– d—–w- c:\program files\CONEXANT
2013-09-07 00:49 . 2013-09-07 00:49 ——– d—–w- c:\documents and settings\janell brown\Application Data\Helios
2013-09-05 14:04 . 2013-09-05 14:04 209272 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-09 02:02 . 2011-10-26 05:19 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-09-08 19:29 . 2013-05-31 13:19 60256 —-a-w- c:\windows\system32\BGLsp.dll
2013-09-08 19:29 . 2013-05-31 13:19 113088 —-a-w- c:\windows\system32\BgGamingMonitor.dll
2013-08-09 01:56 . 2005-08-16 09:18 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2005-08-16 09:18 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2005-08-16 09:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2005-08-16 09:18 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2005-08-16 09:18 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2005-08-16 09:18 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2005-08-16 09:18 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2005-08-16 09:18 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-01 00:20 . 2005-08-16 09:19 827392 —-a-w- c:\windows\system32\wmvdmod.dll
2013-07-10 10:37 . 2005-08-16 09:18 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 03:03 . 2005-08-16 09:18 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2004-08-04 03:59 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"BullGuard"="c:\program files\bullguard ltd\bullguard\BullGuard.exe" [2013-09-18 858976]
"BullGuardUpdate2"="c:\program files\bullguard ltd\bullguard\BullGuardUpdate2.exe" [2013-09-08 1879392]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-9-12 1527808]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
2010-10-29 20:06 5915480 —-a-w- c:\program files\Logitech\Vid HD\Vid.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-11-11 21:08 205336 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
2005-08-18 22:52 999424 —-a-w- c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
2005-07-12 23:06 110592 —-a-w- c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
2005-08-12 03:02 53248 —-a-w- c:\program files\McAfee.com\VSO\oasclnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 20:33 17418928 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 17:49 163840 —-a-w- c:\progra~1\McAfee.com\VSO\mcvsshld.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
2005-07-08 23:18 151552 —-a-w- c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [3/18/2013 6:24 AM 66160]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [6/26/2012 2:48 AM 789960]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [6/26/2012 2:48 AM 19272]
R2 BsBackup;BullGuard backup service;c:\windows\System32\SvcHost.exe -k BullGuard_Backup [8/16/2005 2:18 AM 14336]
R2 BsBhvScan;BullGuard behavioural detection service;c:\program files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [5/20/2013 1:51 AM 376672]
R2 BsFileScan;BullGuard on-access service;c:\windows\System32\SvcHost.exe -k BullGuard [8/16/2005 2:18 AM 14336]
R2 BsFire;BullGuard firewall service;c:\windows\System32\SvcHost.exe -k BullGuard [8/16/2005 2:18 AM 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\System32\SvcHost.exe -k BullGuard_Proxy [8/16/2005 2:18 AM 14336]
R2 BsMain;BullGuard main service;c:\windows\System32\SvcHost.exe -k BullGuard_Main [8/16/2005 2:18 AM 14336]
R2 BsScanner;BullGuard scanning service;c:\program files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [5/20/2013 1:51 AM 212320]
R2 BsUpdate;BullGuard update service;c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [9/18/2013 3:48 AM 287584]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [9/6/2013 8:21 PM 418376]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/6/2013 8:21 PM 701512]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [11/20/2012 6:11 AM 33888]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [11/20/2012 6:11 AM 284768]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/6/2013 8:21 PM 22856]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [4/23/2007 2:11 PM 224896]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7/13/2012 1:28 PM 160944]
S3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [11/9/2010 7:46 PM 20704]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [9/23/2013 7:52 AM 48728]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [9/23/2013 7:54 AM 105176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan BsFire
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
BullGuard_Backup REG_MULTI_SZ BsBackup
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 19:27 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-07 01:42]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 19:11]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 19:11]
.
2013-09-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (DF8RS5B1-janell brown).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-06-16 23:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-09-26 07:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1392)
c:\progra~1\BULLGU~1\BULLGU~1\BgAgent.dll
.
- - - - - - - > 'lsass.exe'(1468)
c:\progra~1\BULLGU~1\BULLGU~1\BgAgent.dll
c:\windows\system32\BGLsp.dll
.
Completion time: 2013-09-26 07:44:00
ComboFix-quarantined-files.txt 2013-09-26 14:43
.
Pre-Run: 73,147,408,384 bytes free
Post-Run: 73,109,745,664 bytes free
.
- - End Of File - - 18A7C8B933B0BC5EEABA9698252584C7
91722E6BC3A2B40FF00222DCA4A3DB3E
I still have a big problem with the computer. When it starts a box saying 'sonic activation module' needs a cd. I dont know what that is. when i cancel it repeatedly tries to loading/download something and pops up error messages that i need a cd. the comp randomly does after start up too.
sorry it took so long, working a lot.