Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Slow Computer - Recent Trojan Google Redirect


  • Please log in to reply

#1
micknmark

micknmark

    Member

  • Member
  • PipPip
  • 10 posts
Hi guys
Last week I started having trouble with my laptop when I realised that Trend hadn't updated for some days. I tried to do an automatic update but got an error message (I can't remember the exact wording). I went online and downloaded the manual updater and the latest version of Trend. I was able to update manually but even with the upgraded version still not automatically. I ran Malware and Trojan remover and found that I had a trojan which was changing my IP addresses (I believe). I was getting the redirect from Google too. I did some online research and considered that it was possible my router had been hijacked. I logged in and changed the password. I also ran MWAB and Trojan Remover several times which seemed to help. Whilst my system was slow it seemed to be functioning okay until the past couple of days.

Logging on today my browser locks my whole computer up so that I need to reboot it. In fact, even starting up Outlook Express seems to lock up the computer. It won't allow me to access the Taskmanager when in this situation. Even disconnecting the network at this point doesn't unlock the system. Another laptop on the same network works fine (I'm using it right now).

Since last week, on booting to the desktop, Vista has been showing some services 'blocked' on startup. I've had a look at the blocked services but not game to change anything.

I've following the instructions in the cleaning guide and post logs as requested.

Thanks in advance, I hope I've done everything required to this point. I look forward to hearing from someone soon!

Cheers
Michelle

OTL logfile created on: 24/06/2010 5:02:15 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\The Farmer Family\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.88 Gb Total Space | 70.84 Gb Free Space | 49.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THEFARMERFAMILY
Current User Name: The Farmer Family
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/06/24 17:01:40 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
PRC - [2009/12/15 11:24:48 | 000,293,376 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\Temp\Rar$EX00.850\gmer.exe
PRC - [2009/07/25 09:06:46 | 000,329,040 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe
PRC - [2009/07/25 09:02:47 | 000,185,680 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
PRC - [2009/04/11 14:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/06/24 17:01:40 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
MOD - [2009/04/11 14:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 10:25:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (LexBceS)
SRV - File not found [On_Demand | Stopped] -- -- (HitmanPro35Crusader)
SRV - [2010/06/16 18:53:56 | 000,689,416 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe -- (TmProxy)
SRV - [2010/06/16 18:53:56 | 000,497,008 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe -- (TmPfw)
SRV - [2010/06/16 18:53:56 | 000,345,352 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/01/26 15:39:46 | 000,715,368 | ---- | M] (Trend Micro Inc.) [Auto | Stopped] -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe -- (SfCtlCom)
SRV - [2009/12/01 15:59:30 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/09/25 09:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2008/11/24 21:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/11/05 18:58:42 | 000,049,152 | ---- | M] (AuthenTec Inc.) [Disabled | Stopped] -- C:\Windows\System32\TAMSvr.exe -- (Authentec memory manager)
SRV - [2008/09/16 12:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
SRV - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/21 10:23:59 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/26 05:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Stopped] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/22 09:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/09/29 08:05:16 | 000,128,360 | ---- | M] (TOSHIBA CORPORATION) [Auto | Stopped] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006/10/05 12:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)


========== Driver Services (SafeList) ==========

DRV - [2010/06/16 18:54:02 | 000,283,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmwfp.sys -- (tmwfp)
DRV - [2010/06/16 18:54:02 | 000,158,224 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/06/16 18:54:02 | 000,146,448 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmlwf.sys -- (tmlwf)
DRV - [2010/06/16 18:54:02 | 000,089,872 | ---- | M] (Trend Micro Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2010/06/16 18:54:02 | 000,059,920 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2010/06/16 18:54:02 | 000,050,704 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2009/12/20 02:22:01 | 000,104,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2009/12/18 06:25:12 | 000,026,024 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2009/12/05 00:39:06 | 000,230,928 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmxpflt.sys -- (tmxpflt)
DRV - [2009/12/05 00:38:18 | 000,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmpreflt.sys -- (tmpreflt)
DRV - [2009/12/05 00:05:06 | 001,322,680 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\vsapint.sys -- (vsapint)
DRV - [2009/11/16 03:13:14 | 000,216,576 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/10/02 07:41:44 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2009/07/02 04:30:08 | 000,168,808 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009/06/01 06:58:52 | 000,009,728 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009/05/09 01:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2009/01/26 13:39:48 | 000,146,944 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®
DRV - [2008/08/14 10:40:40 | 000,203,312 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008/03/14 14:18:34 | 000,042,608 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\AlfaFF.sys -- (AlfaFF)
DRV - [2008/01/30 11:34:20 | 002,058,528 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/21 14:42:24 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tos_sps32.sys -- (tos_sps32)
DRV - [2008/01/21 10:23:51 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 10:23:51 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 10:23:51 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 10:23:51 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 10:23:51 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 10:23:50 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 10:23:50 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 10:23:50 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 10:23:49 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 10:23:49 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2008/01/21 10:23:49 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 10:23:48 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 10:23:48 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 10:23:48 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 10:23:47 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 10:23:47 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 10:23:47 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 10:23:46 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 10:23:45 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel®
DRV - [2008/01/21 10:23:45 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 10:23:45 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 10:23:45 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 10:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 10:23:26 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 10:23:26 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 10:23:26 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/12/17 10:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/11/30 08:47:36 | 000,074,240 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2007/11/30 01:45:44 | 000,036,608 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2007/11/09 13:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/10/19 06:25:00 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007/10/03 03:43:22 | 000,064,128 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2007/09/30 15:03:12 | 000,308,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2007/09/26 06:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel®
DRV - [2007/09/13 14:23:50 | 001,925,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2007/04/03 12:57:54 | 000,099,080 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116unic.sys -- (s116unic) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM)
DRV - [2007/04/03 12:57:52 | 000,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116obex.sys -- (s116obex)
DRV - [2007/04/03 12:57:50 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mgmt.sys -- (s116mgmt) Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/03 12:57:48 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdm.sys -- (s116mdm)
DRV - [2007/04/03 12:57:48 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdfl.sys -- (s116mdfl)
DRV - [2007/04/03 12:57:42 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116bus.sys -- (s116bus) Sony Ericsson Device 116 driver (WDM)
DRV - [2007/03/22 14:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/02/25 06:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/24 08:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/28 15:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/21 06:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/02 17:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 17:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 17:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 17:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 17:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 17:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 17:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 17:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 17:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 17:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 17:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 16:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 16:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 16:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 16:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 16:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 16:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 15:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/11/02 15:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/10/19 03:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/10/11 11:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2005/07/12 10:58:00 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2005/01/07 21:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/06/16 18:57:45 | 000,000,000 | ---D | M]

[2009/07/15 21:10:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Mozilla\Extensions
[2009/07/15 21:10:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2010/02/16 17:22:29 | 000,378,956 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 13057 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TrendSecure Remote File Lock] C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe (Trend Micro Inc.)
O4 - Startup: C:\Users\The Farmer Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2009/12/01 16:55:06 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\The Farmer Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hiro-Media Client.lnk = C:\Program Files\Hiro-Media\HiroClient\HiroClient.exe (Hiro Media)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} http://www.facebook....ls/contactx.dll (ContactExtractor Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\hiro {50BA1131-168F-4c08-A69B-4012273F222E} - C:\Program Files\Hiro-Media\HiroClient\HiroProtocolHandler.dll (TODO: <Company name>)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\The Farmer Family\Pictures\Farmer Family\Laura and Zac - Feb 09 (4).JPG
O24 - Desktop BackupWallPaper: C:\Users\The Farmer Family\Pictures\Farmer Family\Laura and Zac - Feb 09 (4).JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 05:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 10:35:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: aux - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.imaadpcm - C:\Windows\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IYUV - C:\Windows\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\Windows\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 90 Days ==========

[2010/06/24 17:01:37 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
[2010/06/24 16:57:11 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\The Farmer Family\Desktop\erunt_setup.exe
[2010/06/17 07:58:22 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/06/17 07:57:41 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/06/16 21:14:06 | 001,322,680 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\vsapint.sys
[2010/06/16 21:14:05 | 000,230,928 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmxpflt.sys
[2010/06/16 21:14:05 | 000,036,368 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmpreflt.sys
[2010/06/16 20:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/06/16 20:49:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Simply Super Software
[2010/06/16 20:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2010/06/16 20:48:48 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Simply Super Software
[2010/06/16 20:48:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2010/06/16 18:55:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Trend Micro
[2010/06/16 18:55:09 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/06/16 18:54:02 | 000,283,152 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/06/16 18:54:02 | 000,158,224 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/06/16 18:54:02 | 000,146,448 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/06/16 18:54:02 | 000,089,872 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/06/16 18:54:02 | 000,059,920 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/06/16 18:54:02 | 000,050,704 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/06/16 18:53:54 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\Desktop\TISPro_Download32bit
[2010/06/15 16:08:18 | 000,287,608 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\Tmfilter.sys
[2010/06/15 15:52:00 | 000,709,896 | ---- | C] (Trend Micro Incorporated) -- C:\Users\The Farmer Family\Desktop\Update_Tool.exe
[2010/06/10 16:27:06 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit Software
[2010/05/24 19:40:00 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\Desktop\Wordpress_Magazine
[2010/05/06 17:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/06 17:47:02 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/06 17:42:06 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/04/12 07:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/04/01 17:13:25 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/01 17:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/04/01 16:57:23 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010/04/01 15:29:37 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Facebook

========== Files - Modified Within 90 Days ==========

[2010/06/24 17:02:34 | 008,650,752 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat
[2010/06/24 17:01:40 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
[2010/06/24 16:58:20 | 000,000,725 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\ERUNT.lnk
[2010/06/24 16:57:36 | 000,284,915 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\gmer.zip
[2010/06/24 16:57:15 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\The Farmer Family\Desktop\erunt_setup.exe
[2010/06/24 16:55:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/24 16:45:32 | 000,000,442 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8A415B25-380B-42B8-AD69-30FDD51BD09A}.job
[2010/06/24 16:42:15 | 000,000,103 | ---- | M] () -- C:\Users\The Farmer Family\HiroConfig.dat
[2010/06/24 16:41:03 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/24 16:40:59 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/24 16:40:59 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/24 16:40:55 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/24 16:13:21 | 000,524,288 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{f91cf0fe-d285-11de-bc7e-00037aaeb154}.TMContainer00000000000000000001.regtrans-ms
[2010/06/24 16:13:21 | 000,065,536 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{f91cf0fe-d285-11de-bc7e-00037aaeb154}.TM.blf
[2010/06/24 15:52:11 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/22 17:08:14 | 000,002,255 | ---- | M] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/06/22 17:07:02 | 000,000,419 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2010/06/22 17:07:02 | 000,000,027 | ---- | M] () -- C:\Windows\BRPP2KA.INI
[2010/06/21 07:33:01 | 000,694,964 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/21 07:33:01 | 000,603,282 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/21 07:33:01 | 000,106,696 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/06/21 07:32:00 | 000,029,184 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/20 13:05:50 | 000,155,110 | ---- | M] () -- C:\Users\Public\Documents\franies.docx
[2010/06/20 12:29:38 | 000,171,427 | ---- | M] () -- C:\Users\Public\Documents\patrics day.docx
[2010/06/18 20:08:43 | 000,023,572 | ---- | M] () -- C:\Users\Public\Documents\DECEMBER.docx
[2010/06/18 16:31:37 | 000,361,868 | ---- | M] () -- C:\Users\Public\Documents\Presentation1.pptx
[2010/06/18 12:23:39 | 000,134,466 | ---- | M] () -- C:\Users\Public\Documents\CGU - Travel Claim.xlsx
[2010/06/17 19:41:23 | 000,014,324 | ---- | M] () -- C:\Users\Public\Documents\callender.docx
[2010/06/17 03:26:24 | 000,403,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/06/16 20:48:55 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2010/06/16 18:56:13 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/06/16 18:54:02 | 000,283,152 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/06/16 18:54:02 | 000,158,224 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/06/16 18:54:02 | 000,146,448 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/06/16 18:54:02 | 000,089,872 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/06/16 18:54:02 | 000,059,920 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/06/16 18:54:02 | 000,050,704 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/06/16 18:04:17 | 000,000,036 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\housecall.guid.cache
[2010/06/16 17:57:35 | 000,001,718 | ---- | M] () -- C:\Appdata.re
[2010/06/15 15:52:04 | 000,709,896 | ---- | M] (Trend Micro Incorporated) -- C:\Users\The Farmer Family\Desktop\Update_Tool.exe
[2010/06/11 10:10:40 | 000,015,944 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010/06/10 16:33:14 | 000,034,308 | ---- | M] () -- C:\Windows\System32\BASSMOD.dll
[2010/06/05 08:52:42 | 000,218,552 | ---- | M] () -- C:\Users\Public\Documents\rubber ducks.docx
[2010/05/31 21:39:36 | 000,001,681 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\CCleaner.lnk
[2010/05/25 19:34:59 | 000,162,304 | ---- | M] () -- C:\Users\Public\Documents\timetable.doc
[2010/05/25 19:24:15 | 000,034,498 | ---- | M] () -- C:\Users\Public\Documents\timetable.docx
[2010/05/21 20:27:23 | 000,000,205 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\Perth - TV Guide.url
[2010/05/08 09:43:33 | 000,002,084 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010/05/06 17:47:58 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/24 13:39:27 | 000,002,305 | ---- | M] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/04/03 19:36:13 | 000,000,600 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\PUTTY.RND
[2010/04/03 19:25:30 | 000,001,796 | ---- | M] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2010/04/03 15:51:15 | 000,195,820 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
[2010/04/01 17:08:40 | 000,001,737 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/01 16:57:36 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2010/03/28 21:45:56 | 000,983,824 | ---- | M] () -- C:\Users\Public\Documents\Managing Your Own Rental Property Made Easy.docx

========== Files Created - No Company Name ==========

[2010/06/24 16:58:20 | 000,000,725 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\ERUNT.lnk
[2010/06/24 16:57:31 | 000,284,915 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\gmer.zip
[2010/06/20 13:05:46 | 000,155,110 | ---- | C] () -- C:\Users\Public\Documents\franies.docx
[2010/06/20 12:29:33 | 000,171,427 | ---- | C] () -- C:\Users\Public\Documents\patrics day.docx
[2010/06/18 20:08:42 | 000,023,572 | ---- | C] () -- C:\Users\Public\Documents\DECEMBER.docx
[2010/06/17 20:30:19 | 000,361,868 | ---- | C] () -- C:\Users\Public\Documents\Presentation1.pptx
[2010/06/17 19:41:22 | 000,014,324 | ---- | C] () -- C:\Users\Public\Documents\callender.docx
[2010/06/16 20:56:29 | 000,102,400 | RHS- | C] () -- C:\Windows\System32\TR2468.dll
[2010/06/16 20:48:55 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2010/06/16 20:48:51 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll
[2010/06/16 20:48:51 | 000,153,088 | ---- | C] () -- C:\Windows\System32\UNRAR3.dll
[2010/06/16 20:48:51 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll
[2010/06/16 20:48:51 | 000,075,264 | ---- | C] () -- C:\Windows\System32\unacev2.dll
[2010/06/16 18:56:13 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/06/16 17:59:05 | 000,000,036 | ---- | C] () -- C:\Users\The Farmer Family\AppData\Local\housecall.guid.cache
[2010/06/16 17:56:14 | 000,001,718 | ---- | C] () -- C:\Appdata.re
[2010/06/10 16:33:14 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2010/06/05 08:52:38 | 000,218,552 | ---- | C] () -- C:\Users\Public\Documents\rubber ducks.docx
[2010/05/25 19:34:51 | 000,162,304 | ---- | C] () -- C:\Users\Public\Documents\timetable.doc
[2010/05/25 19:24:13 | 000,034,498 | ---- | C] () -- C:\Users\Public\Documents\timetable.docx
[2010/05/13 08:45:04 | 000,002,255 | ---- | C] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/05/08 09:43:33 | 000,002,084 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010/05/08 09:41:50 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/08 09:41:50 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/06 17:47:58 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/03 19:35:42 | 000,000,600 | ---- | C] () -- C:\Users\The Farmer Family\AppData\Local\PUTTY.RND
[2010/04/03 15:51:15 | 000,195,820 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/04/01 17:08:40 | 000,001,737 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/01 16:57:36 | 000,002,305 | ---- | C] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/04/01 16:57:36 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2010/03/28 20:06:24 | 000,983,824 | ---- | C] () -- C:\Users\Public\Documents\Managing Your Own Rental Property Made Easy.docx
[2010/02/21 21:43:19 | 000,015,944 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010/02/15 06:56:51 | 000,102,400 | ---- | C] () -- C:\Windows\System32\bitsperfc.dll.vir
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/06/11 11:34:04 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/03/24 15:35:17 | 000,000,985 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2009/03/24 15:35:17 | 000,000,173 | ---- | C] () -- C:\Windows\brpcfx.ini
[2009/03/24 15:34:00 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/03/24 15:34:00 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2009/03/05 06:54:58 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2008/11/09 17:38:28 | 000,036,864 | ---- | C] () -- C:\Windows\System32\LXBRPMON.DLL
[2008/11/09 17:38:28 | 000,020,480 | ---- | C] () -- C:\Windows\System32\LXBRPMUI.DLL
[2008/11/09 17:37:47 | 000,000,400 | ---- | C] () -- C:\Windows\Lexstat.ini
[2008/11/07 15:00:52 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/11/07 15:00:52 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/11/07 15:00:52 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/11/07 15:00:52 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/11/07 15:00:52 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/11/07 15:00:52 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/11/07 14:45:21 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2008/11/07 14:45:21 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2008/11/07 14:45:21 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2008/11/07 14:45:21 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2008/10/23 01:58:00 | 033,793,272 | ---- | C] () -- C:\Windows\System32\TrueAccessCoInst.dll
[2008/02/12 09:59:36 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/02/12 09:03:27 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/02/12 08:46:10 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/02/12 08:44:39 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/02/12 08:44:39 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2008/02/12 08:44:39 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/02/12 08:44:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2007/12/22 08:46:32 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2007/11/15 01:42:27 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2007/11/09 19:01:59 | 000,000,164 | ---- | C] () -- C:\Windows\System32\psyswin32.dll
[2006/11/02 15:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/07/23 13:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll

========== LOP Check ==========

[2008/11/09 20:08:58 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\4200Series
[2008/11/11 09:12:27 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\ABIG
[2009/12/16 19:42:19 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/04/01 15:29:38 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Facebook
[2010/05/24 22:19:55 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\FileZilla
[2008/11/27 14:35:36 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit
[2010/06/10 16:27:06 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit Software
[2009/01/08 11:29:35 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Leadertech
[2009/07/16 00:20:57 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\LimeWire
[2010/01/11 12:59:27 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\PC-FAX TX
[2008/11/09 20:38:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\PeerNetworking
[2009/07/25 16:02:13 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Publish Providers
[2010/06/16 20:48:48 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Simply Super Software
[2009/07/25 16:29:32 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Sony
[2008/11/07 19:01:51 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\SPAMfighter
[2009/07/23 16:59:36 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Thunderbird
[2009/01/21 08:01:04 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\toshiba
[2008/11/09 20:50:23 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\TransMemory_Secure
[2008/11/09 22:22:14 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Ulead Systems
[2010/06/24 16:17:18 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\uTorrent
[2010/06/24 03:16:41 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/24 16:45:32 | 000,000,442 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{8A415B25-380B-42B8-AD69-30FDD51BD09A}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/06/16 17:57:35 | 000,001,718 | ---- | M] () -- C:\Appdata.re
[2006/09/19 05:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/04/11 14:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008/02/12 08:19:42 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/19 05:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2009/04/16 15:49:26 | 000,000,560 | ---- | M] () -- C:\InstallHelper.log
[2008/02/12 08:29:51 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/03/24 15:49:22 | 000,000,078 | ---- | M] () -- C:\lxbm.log
[2008/02/12 08:29:51 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/06/24 16:55:37 | 3524,489,216 | -HS- | M] () -- C:\pagefile.sys
[2010/06/17 08:40:58 | 000,061,438 | ---- | M] () -- C:\TDSSKiller.2.3.2.0_17.06.2010_08.39.57_log.txt
[2010/06/24 15:44:39 | 000,001,647 | ---- | M] () -- C:\VundoFix.txt

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2006/11/02 20:36:30 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 19:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll
[2009/03/08 19:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/21 11:20:25 | 017,223,680 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 11:20:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 11:20:25 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 18:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 18:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 14:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\System32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/21 10:25:16 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\System32\ws2_32.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 48 bytes -> C:\Windows:D2F9AAA03D24C7ED
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CB0AACC9
< End of report >

OTL Extras logfile created on: 24/06/2010 5:02:15 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\The Farmer Family\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.88 Gb Total Space | 70.84 Gb Free Space | 49.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THEFARMERFAMILY
Current User Name: The Farmer Family
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02FAC6E7-A04C-41A4-A82A-949EE8F58508}" = rport=138 | protocol=17 | dir=out | app=system |
"{074FF035-726E-43D2-A8E4-4ADEC7F66C40}" = rport=10243 | protocol=6 | dir=out | app=system |
"{0944D159-FD5A-44D0-A456-F505F723582F}" = lport=139 | protocol=6 | dir=in | app=system |
"{0F0AAAAB-92EC-4189-B793-41FFDC3ADE5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{102DEAEB-52B1-485C-9B57-5BDDC31D24FF}" = lport=138 | protocol=17 | dir=in | app=system |
"{13423317-8C94-4088-A151-B0C769287185}" = rport=445 | protocol=6 | dir=out | app=system |
"{251532EE-95A6-4005-9E67-D3A59CFBE86D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2A22C588-A097-4440-B12E-7F3A144CEE10}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{2A4B6DEA-62A6-461E-9D28-EA334C048821}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{32BBFC5F-08FE-4FA9-B0B9-10F8FF1D71B1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{42285119-EE7B-4D1D-95E7-2FDBAB25370B}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{5CEDF4AB-E3E9-4040-BDF3-A8883C724E73}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{651205B6-57AD-460D-AAF0-7DDA4649C253}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{7A09507A-02CD-464B-AFF1-FBC2ECBD6230}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7E5136A1-A7E7-4BC4-81C8-4217D6A526D2}" = lport=445 | protocol=6 | dir=in | app=system |
"{86516A4C-3CAA-4AB6-A795-C13B3E969ABB}" = rport=139 | protocol=6 | dir=out | app=system |
"{92AD214C-D374-40E4-B8B6-F71944855EAA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{93B36B17-851B-4A4C-9999-3831EA3C0876}" = lport=137 | protocol=17 | dir=in | app=system |
"{9B8DC2DB-F367-4FAD-8C76-A57514A28375}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{9D569999-035E-4035-8E5E-5748D0776906}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A00EC612-1784-4B8B-A8C1-5A643DA65CB1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AAE6E079-E66D-4023-8F5E-1F73456AE76D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C0C8F958-F74E-47FB-9343-B5EBF56FC85F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C1B93B09-F8BB-4653-8626-25798ABAC700}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C8EA1B00-7F60-4754-8DD2-5D8CD8838BA0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{D64E8E4F-C04F-49EE-9E8A-6EB093A315F3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7DDE457-97CE-4E79-A653-668020F883AD}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{DF6C8DA4-D107-4A83-A214-A8949F5D943A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F4281385-F4C5-490B-BDCA-62783939D7AF}" = lport=10243 | protocol=6 | dir=in | app=system |
"{FF2CDB75-9E3D-463B-9DCD-A1368598C1BF}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{031CBE73-20CB-4F24-ACD4-0424D493FE29}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0E1741DD-12CC-447A-981D-3ED5C117FED4}" = protocol=17 | dir=in | app=c:\windows\system32\lxbmcoms.exe |
"{101A8EA4-E89D-4BA5-B5F9-2CAA338FB1F7}" = protocol=6 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{10E54A17-97EE-408A-B632-EC2AF3107099}" = protocol=6 | dir=in | app=c:\windows\system32\lxbmcoms.exe |
"{169F576A-40C1-47B7-908B-25E11D8D515D}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{1AB5B846-5520-4406-8380-3B590CB499C6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{23C61DAA-C03E-43B7-AED6-2587B078115C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{243AC066-DF28-4D60-86BC-9DDA9C13E819}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{2AD71051-62D9-4CEE-B538-AD0343744774}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2BF10DF4-FB81-4B3A-851D-4C68181001FE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3FB6C28E-0B35-4CBB-9F8F-20DF259F0A77}" = protocol=1 | dir=out | [email protected],-28544 |
"{4D6F3C30-6DAE-4DBB-A0D2-AB135CC2018F}" = protocol=58 | dir=out | [email protected],-28546 |
"{50AED980-56A1-4DC0-9288-B96EE5D78BEA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{50BE55BA-2CAA-4043-B6DD-CC64DFE3E345}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5229428E-4FEC-4B97-B370-67EAA755BBF3}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{56424878-C4B2-429A-8380-8474322694BD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5B43453D-8080-4A17-A1EC-B7BD7E6D2904}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{5BF9BD47-DB5B-4FCC-A9C1-BF2F6A3A5502}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5E179966-38E6-43EC-B945-E6B016B7AE2E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5E948E98-5060-41AB-B5AE-EA6E4710AAE3}" = protocol=1 | dir=in | [email protected],-28543 |
"{71E2307F-0E2B-4A6B-B972-89C9A00D1003}" = protocol=58 | dir=in | [email protected],-28545 |
"{76FF0152-DE98-4D65-BCBF-923B1679D9F8}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{7BA2400E-9184-477F-B75A-7FF75EFB569E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{91DD28CB-7267-49FC-B658-3AB53DF3B884}" = protocol=6 | dir=out | app=system |
"{9D46F6AF-2D2E-4CB6-84BE-0899301A8504}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{A6E9606D-33EC-49F6-BAAD-D5370F0FEB6B}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{AEC0F629-F2D7-4B33-AA6A-AC491D330F01}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbmpswx.exe |
"{B3892F4D-B35A-41C5-B45D-5FD2A8391612}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbmpswx.exe |
"{B57C2B07-956E-4A4A-8259-D2221F55CA4B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BA136931-2C1A-4479-9260-C626BA283C5D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BA9902FE-0F0D-41E3-8A80-1ACADFFDD008}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C827EE95-C59B-438E-9A67-2C28B1214740}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E40C70C8-1645-4615-AD28-A2911E03C8AD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E530599F-9FFB-4D76-9AF1-FE21D219D7CA}" = protocol=17 | dir=in | app=c:\windows\system32\spoolsv.exe |
"{FFA23431-7E6A-4D17-A8EC-3D78534D2DEC}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{E1370674-B4FE-4A80-ABDE-03FB90A3F081}C:\windows\system32\wfs.exe" = protocol=6 | dir=in | app=c:\windows\system32\wfs.exe |
"UDP Query User{344277AF-8E38-427F-B59A-F295455B6528}C:\windows\system32\wfs.exe" = protocol=17 | dir=in | app=c:\windows\system32\wfs.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{11F66E7E-4865-4070-B289-A0DB052979E1}" = HIRO Client
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 20
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}" = Brother MFL-Pro Suite MFC-290C
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{919F3D91-8374-410F-932B-A126F2C85426}" = e-tax 2009
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95264530-5A22-8E7E-FE9D-D63A927BCAEA}" = Adobe Media Player
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security Pro
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A67BB21E-D419-45BB-AB86-7D87D14BBCE2}" = Safari
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DA29D017-6E24-481D-BC7C-2B69335A0B3A}" = TrueSuite Access Manager
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"AnyDVD" = AnyDVD
"CCleaner" = CCleaner
"CloneDVD2" = CloneDVD2
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ERUNT_is1" = ERUNT 1.1j
"FileZilla Client" = FileZilla Client 3.3.2.1
"Foxit Creator" = Foxit Creator
"Foxit Reader" = Foxit Reader
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{69640730-B830-4C24-BB5C-222DA1260548}" = Turbo Lister 2
"InstallShield_{DA29D017-6E24-481D-BC7C-2B69335A0B3A}" = TrueSuite Access Manager
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MarkAble2_is1" = MarkAble 2.2.4
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Scholastic's I SPY Treasure Hunt" = Scholastic's I SPY Treasure Hunt
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Trojan Remover_is1" = Trojan Remover 6.8.1
"uTorrent" = µTorrent
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 388: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 396: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 400: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 404: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 408: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 412: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 416: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 2:49:26 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = 420: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 19/06/2010 8:10:23 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 19/06/2010 8:10:23 AM | Computer Name = TheFarmerFamily | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1077

[ System Events ]
Error - 24/06/2010 4:42:39 AM | Computer Name = TheFarmerFamily | Source = Service Control Manager | ID = 7009
Description =

Error - 24/06/2010 4:42:39 AM | Computer Name = TheFarmerFamily | Source = Service Control Manager | ID = 7000
Description =

Error - 24/06/2010 4:44:01 AM | Computer Name = TheFarmerFamily | Source = Service Control Manager | ID = 7031
Description =

Error - 24/06/2010 4:55:58 AM | Computer Name = TheFarmerFamily | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:49:45 PM on 24/06/2010 was unexpected.

Error - 24/06/2010 4:56:08 AM | Computer Name = TheFarmerFamily | Source = DCOM | ID = 10005
Description =

Error - 24/06/2010 4:56:17 AM | Computer Name = TheFarmerFamily | Source = DCOM | ID = 10005
Description =

Error - 24/06/2010 4:56:20 AM | Computer Name = TheFarmerFamily | Source = DCOM | ID = 10005
Description =

Error - 24/06/2010 4:57:15 AM | Computer Name = TheFarmerFamily | Source = Service Control Manager | ID = 7001
Description =

Error - 24/06/2010 4:57:15 AM | Computer Name = TheFarmerFamily | Source = Service Control Manager | ID = 7026
Description =

Error - 24/06/2010 5:01:13 AM | Computer Name = TheFarmerFamily | Source = DCOM | ID = 10005
Description =


< End of report >


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-24 17:05:20
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\THEFAR~1\AppData\Local\Temp\aflcipoc.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8AB53000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8AB9C000, 0x510, 0x40000040]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!SetWindowsHookExW 76F487AD 5 Bytes JMP 709F9AC9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!CallNextHookEx 76F48E3B 5 Bytes JMP 709ED0ED C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!UnhookWindowsHookEx 76F498DB 5 Bytes JMP 7096467C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!CreateWindowExW 76F51305 5 Bytes JMP 709FDB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!DialogBoxParamW 76F710B0 5 Bytes JMP 709254C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!DialogBoxIndirectParamW 76F72EF5 5 Bytes JMP 70AF480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!DialogBoxParamA 76F88152 5 Bytes JMP 70AF47AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!DialogBoxIndirectParamA 76F8847D 5 Bytes JMP 70AF4872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!MessageBoxIndirectA 76F9D4D9 5 Bytes JMP 70AF4741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!MessageBoxIndirectW 76F9D5D3 5 Bytes JMP 70AF46D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!MessageBoxExA 76F9D639 5 Bytes JMP 70AF4674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] USER32.dll!MessageBoxExW 76F9D65D 5 Bytes JMP 70AF4612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] ole32.dll!OleLoadFromStream 75F81E12 5 Bytes JMP 70AF4B77 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[224] ole32.dll!CoCreateInstance 75FB9EA6 5 Bytes JMP 709FDB78 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!CreateWindowExW 76F51305 5 Bytes JMP 709FDB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxParamW 76F710B0 5 Bytes JMP 709254C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxIndirectParamW 76F72EF5 5 Bytes JMP 70AF480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxParamA 76F88152 5 Bytes JMP 70AF47AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!DialogBoxIndirectParamA 76F8847D 5 Bytes JMP 70AF4872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxIndirectA 76F9D4D9 5 Bytes JMP 70AF4741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxIndirectW 76F9D5D3 5 Bytes JMP 70AF46D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxExA 76F9D639 5 Bytes JMP 70AF4674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2024] USER32.dll!MessageBoxExW 76F9D65D 5 Bytes JMP 70AF4612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4204

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18928

24/06/2010 4:08:01 PM
mbam-log-2010-06-24 (16-08-01).txt

Scan type: Quick scan
Objects scanned: 129351
Time elapsed: 5 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Edited by micknmark, 24 June 2010 - 04:12 AM.

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
When you changed the password on the router did you first reset it to factory default? I've seen them put in static routes and also use malware DNS servers and changing hte password wouldn't remove them.


Copy the text between the lines of stars by highlighting and Ctrl + c
********************************************************************************

:OTL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - No CLSID value found.
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe (Simply Super Software)
[2010/06/16 20:56:29 | 000,102,400 | RHS- | C] () -- C:\Windows\System32\TR2468.dll
[2010/06/16 20:48:55 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk

:Files
C:\Windows\System32\TR2468.dll
C:\Windows\System32\bitsperfc.dll.vir

:Commands
[purity]
[emptytemp]
[Reboot]

:Commands
[purity]
[emptytemp]
[Reboot]

*******************************************************************

then Rightclick on OTL and select Run As Administrator to start. Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the RUN FIX button (NOT THE QUICK SCAN button!) at the top
Let the program run unhindered, OTL will reboot the PC when it is done.

Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Rightclick on Malwarebytes' Anti-Malware and select Run As Administrator to start.

* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.



Download but do not yet run ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Rename this file -- (call it george.exe ) to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on george and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Re-activate your anti-virus program at this time :!:

Reboot now, please :!:

Post Back (copy/paste the .txt files, do not use attachments)
After following the above, post back with:

OTL Log
MBAM log
Combofix log
Also post the TDSSKiller log at C:\TDSSKiller.2.3.2.0_17.06.2010_08.39.57_log.txt

Ron

Edited by RKinner, 26 June 2010 - 12:37 AM.

  • 0

#3
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hi Ron,
Since my first email my computer has been freezing after booting up to Vista within only five to 10 minutes. I can get it to run and stay open so far in safe mode. I've used System Recovery to wind back about a week but still getting the same problem with freezing. The mouse works okay during this time but I can't get to the Task Manager (screen halts or goes black) and then I have to hard shut-down.

I'll do as you've asked with OTL, etc.

To answer your first question, no I didn't reset to factory default because I had trouble in the past getting it all set-up again after a firmware upgrade (and I wasn't confident that I could get it happening again!).

Back soon ...
Cheers
Michelle
  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
In that case, let's also check the router as follows:

Start, Programs, Accessories, right click on Command Prompt, Run As Administrator. Type (with an Enter after each line in the code box:

nslookup  google.com  >  junk.txt

tracert  -d  google.com  >>  junk.txt

notepad  junk.txt

(I use two spaces to show where one goes.)

Copy the text from notepad and paste it in a reply.

Ron
  • 0

#5
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hi Ron
Okay, the router test is as follows:



Tracing route to google.com [203.59.140.157]

over a maximum of 30 hops:



1 1 ms 1 ms 1 ms 192.168.1.1

2 * * * Request timed out.

3 19 ms 18 ms 17 ms 203.215.5.244

4 17 ms 18 ms 19 ms 203.215.4.18

5 19 ms 18 ms 18 ms 203.215.4.23

6 20 ms 18 ms 17 ms 203.59.140.157



Trace complete.


OTL is as follows:

OTL logfile created on: 26/06/2010 3:13:05 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\The Farmer Family\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 86.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.88 Gb Total Space | 69.36 Gb Free Space | 48.89% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 149.05 Gb Total Space | 68.75 Gb Free Space | 46.13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: THEFARMERFAMILY
Current User Name: The Farmer Family
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/06/26 14:59:20 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
PRC - [2009/04/11 14:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/06/26 14:59:20 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
MOD - [2009/04/11 14:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 10:25:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (LexBceS)
SRV - File not found [On_Demand | Stopped] -- -- (HitmanPro35Crusader)
SRV - [2010/06/16 18:53:56 | 000,689,416 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe -- (TmProxy)
SRV - [2010/06/16 18:53:56 | 000,497,008 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe -- (TmPfw)
SRV - [2010/06/16 18:53:56 | 000,345,352 | ---- | M] (Trend Micro Inc.) [On_Demand | Stopped] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/01/26 15:39:46 | 000,715,368 | ---- | M] (Trend Micro Inc.) [Auto | Stopped] -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe -- (SfCtlCom)
SRV - [2009/12/01 15:59:30 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/09/25 09:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2008/11/24 21:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/11/05 18:58:42 | 000,049,152 | ---- | M] (AuthenTec Inc.) [Disabled | Stopped] -- C:\Windows\System32\TAMSvr.exe -- (Authentec memory manager)
SRV - [2008/09/16 12:03:18 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0)
SRV - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/21 10:23:59 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/26 05:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Stopped] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/22 09:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/09/29 08:05:16 | 000,128,360 | ---- | M] (TOSHIBA CORPORATION) [Auto | Stopped] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006/10/05 12:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)


========== Driver Services (SafeList) ==========

DRV - [2010/06/16 18:54:02 | 000,283,152 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmwfp.sys -- (tmwfp)
DRV - [2010/06/16 18:54:02 | 000,158,224 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2010/06/16 18:54:02 | 000,146,448 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tmlwf.sys -- (tmlwf)
DRV - [2010/06/16 18:54:02 | 000,089,872 | ---- | M] (Trend Micro Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2010/06/16 18:54:02 | 000,059,920 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2010/06/16 18:54:02 | 000,050,704 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2009/12/05 00:39:06 | 000,230,928 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmxpflt.sys -- (tmxpflt)
DRV - [2009/12/05 00:38:18 | 000,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\tmpreflt.sys -- (tmpreflt)
DRV - [2009/12/05 00:05:06 | 001,322,680 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\vsapint.sys -- (vsapint)
DRV - [2009/11/16 03:13:14 | 000,216,576 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/10/02 07:41:44 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2009/07/02 04:30:08 | 000,168,808 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009/06/01 06:58:52 | 000,009,728 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009/05/09 01:14:20 | 000,014,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nuidfltr.sys -- (NuidFltr)
DRV - [2009/01/26 13:39:48 | 000,146,944 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®
DRV - [2008/08/14 10:40:40 | 000,203,312 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008/03/14 14:18:34 | 000,042,608 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\AlfaFF.sys -- (AlfaFF)
DRV - [2008/01/30 11:34:20 | 002,058,528 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/21 14:42:24 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tos_sps32.sys -- (tos_sps32)
DRV - [2008/01/21 10:23:51 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 10:23:51 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 10:23:51 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 10:23:51 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 10:23:51 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 10:23:50 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 10:23:50 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 10:23:50 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 10:23:49 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 10:23:49 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2008/01/21 10:23:49 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 10:23:48 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 10:23:48 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 10:23:48 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 10:23:47 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 10:23:47 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 10:23:47 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 10:23:46 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 10:23:45 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel®
DRV - [2008/01/21 10:23:45 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 10:23:45 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 10:23:45 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 10:23:45 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 10:23:26 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 10:23:26 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 10:23:26 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/12/17 10:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/11/30 08:47:36 | 000,074,240 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2007/11/30 01:45:44 | 000,036,608 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2007/11/09 13:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/10/19 06:25:00 | 000,041,856 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2007/10/03 03:43:22 | 000,064,128 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2007/09/30 15:03:12 | 000,308,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2007/09/26 06:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel®
DRV - [2007/09/13 14:23:50 | 001,925,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2007/04/03 12:57:54 | 000,099,080 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116unic.sys -- (s116unic) Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM)
DRV - [2007/04/03 12:57:52 | 000,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116obex.sys -- (s116obex)
DRV - [2007/04/03 12:57:50 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mgmt.sys -- (s116mgmt) Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/03 12:57:48 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdm.sys -- (s116mdm)
DRV - [2007/04/03 12:57:48 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116mdfl.sys -- (s116mdfl)
DRV - [2007/04/03 12:57:42 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s116bus.sys -- (s116bus) Sony Ericsson Device 116 driver (WDM)
DRV - [2007/03/22 14:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/02/25 06:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/24 08:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/28 15:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/21 06:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/02 17:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 17:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 17:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 17:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 17:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 17:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 17:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 17:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 17:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 17:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 17:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 16:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 16:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 16:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 16:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 16:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 16:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 15:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/11/02 15:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/10/19 03:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/10/11 11:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2005/07/12 10:58:00 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Toshidpt.sys -- (toshidpt)
DRV - [2005/01/07 21:42:00 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/06/16 18:57:45 | 000,000,000 | ---D | M]

[2009/07/15 21:10:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Mozilla\Extensions
[2009/07/15 21:10:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2010/02/16 17:22:29 | 000,378,956 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 13057 more lines...
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\The Farmer Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2009/12/01 16:55:06 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\The Farmer Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hiro-Media Client.lnk = C:\Program Files\Hiro-Media\HiroClient\HiroClient.exe (Hiro Media)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} http://www.facebook....ls/contactx.dll (ContactExtractor Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\hiro {50BA1131-168F-4c08-A69B-4012273F222E} - C:\Program Files\Hiro-Media\HiroClient\HiroProtocolHandler.dll (TODO: <Company name>)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\The Farmer Family\Pictures\Farmer Family\Laura and Zac - Feb 09 (4).JPG
O24 - Desktop BackupWallPaper: C:\Users\The Farmer Family\Pictures\Farmer Family\Laura and Zac - Feb 09 (4).JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 05:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/26 15:03:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/06/26 14:59:15 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
[2010/06/26 14:19:03 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Simply Super Software
[2010/06/26 14:19:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2010/06/26 10:33:54 | 000,000,000 | -HSD | C] -- C:\found.001
[2010/06/25 19:24:50 | 000,000,000 | -HSD | C] -- C:\found.002
[2010/06/25 15:45:36 | 000,000,000 | -HSD | C] -- C:\found.000
[2010/06/25 15:21:39 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010/06/17 07:58:22 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/06/17 07:57:41 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/06/17 07:56:35 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\The Farmer Family\Desktop\erunt-setup.exe
[2010/06/17 07:55:02 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\TFC.exe
[2010/06/16 21:14:06 | 001,322,680 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\vsapint.sys
[2010/06/16 21:14:05 | 000,230,928 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmxpflt.sys
[2010/06/16 21:14:05 | 000,036,368 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmpreflt.sys
[2010/06/16 20:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/06/16 20:49:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Simply Super Software
[2010/06/16 20:48:48 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2010/06/16 18:55:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Trend Micro
[2010/06/16 18:55:09 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/06/16 18:54:02 | 000,283,152 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/06/16 18:54:02 | 000,158,224 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/06/16 18:54:02 | 000,146,448 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/06/16 18:54:02 | 000,089,872 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/06/16 18:54:02 | 000,059,920 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/06/16 18:54:02 | 000,050,704 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/06/16 18:53:54 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\Desktop\TISPro_Download32bit
[2010/06/16 18:52:27 | 106,967,720 | ---- | C] (Trend Micro Inc.) -- C:\Users\The Farmer Family\Desktop\TISPro_Download32bit.exe
[2010/06/15 16:08:18 | 000,287,608 | ---- | C] (Trend Micro Inc.) -- C:\Windows\System32\drivers\Tmfilter.sys
[2010/06/15 15:52:00 | 000,709,896 | ---- | C] (Trend Micro Incorporated) -- C:\Users\The Farmer Family\Desktop\Update_Tool.exe
[2010/06/10 16:27:06 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit Software
[2010/05/24 19:40:00 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\Desktop\Wordpress_Magazine
[2010/05/06 17:47:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/06 17:47:02 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/06 17:42:06 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/04/12 07:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/04/01 17:13:25 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/01 17:08:16 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/04/01 16:57:23 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2010/04/01 15:29:37 | 000,000,000 | ---D | C] -- C:\Users\The Farmer Family\AppData\Roaming\Facebook

========== Files - Modified Within 90 Days ==========

[2010/06/26 15:15:59 | 003,720,783 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\george.exe
[2010/06/26 15:12:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/26 15:09:30 | 008,650,752 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat
[2010/06/26 15:07:08 | 000,000,103 | ---- | M] () -- C:\Users\The Farmer Family\HiroConfig.dat
[2010/06/26 15:06:18 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/26 15:06:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/26 15:06:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/26 15:06:12 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/26 15:05:21 | 000,524,288 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000001.regtrans-ms
[2010/06/26 15:05:21 | 000,065,536 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TM.blf
[2010/06/26 14:59:20 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\OTL.exe
[2010/06/26 14:50:29 | 000,000,442 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8A415B25-380B-42B8-AD69-30FDD51BD09A}.job
[2010/06/26 14:37:01 | 000,000,680 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\d3d9caps.dat
[2010/06/26 13:52:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/24 20:14:44 | 000,000,419 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2010/06/24 20:14:44 | 000,000,027 | ---- | M] () -- C:\Windows\BRPP2KA.INI
[2010/06/24 20:06:18 | 000,524,288 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000002.regtrans-ms
[2010/06/24 19:59:41 | 000,524,288 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{f91cf0fe-d285-11de-bc7e-00037aaeb154}.TMContainer00000000000000000001.regtrans-ms
[2010/06/24 19:59:41 | 000,065,536 | -HS- | M] () -- C:\Users\The Farmer Family\ntuser.dat{f91cf0fe-d285-11de-bc7e-00037aaeb154}.TM.blf
[2010/06/24 16:57:36 | 000,284,915 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\gmer.zip
[2010/06/20 13:05:50 | 000,155,110 | ---- | M] () -- C:\Users\Public\Documents\franies.docx
[2010/06/20 12:29:38 | 000,171,427 | ---- | M] () -- C:\Users\Public\Documents\patrics day.docx
[2010/06/18 20:08:43 | 000,023,572 | ---- | M] () -- C:\Users\Public\Documents\DECEMBER.docx
[2010/06/18 16:31:37 | 000,361,868 | ---- | M] () -- C:\Users\Public\Documents\Presentation1.pptx
[2010/06/18 12:23:39 | 000,134,466 | ---- | M] () -- C:\Users\Public\Documents\CGU - Travel Claim.xlsx
[2010/06/17 19:41:23 | 000,014,324 | ---- | M] () -- C:\Users\Public\Documents\callender.docx
[2010/06/17 07:57:42 | 000,694,964 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/17 07:57:42 | 000,603,282 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/17 07:57:42 | 000,106,696 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/06/17 07:57:42 | 000,000,744 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\NTREGOPT.lnk
[2010/06/17 07:57:42 | 000,000,725 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\ERUNT.lnk
[2010/06/17 07:56:41 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\The Farmer Family\Desktop\erunt-setup.exe
[2010/06/17 07:55:10 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Users\The Farmer Family\Desktop\TFC.exe
[2010/06/17 03:26:24 | 000,403,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/06/16 18:56:13 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/06/16 18:54:02 | 000,283,152 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmwfp.sys
[2010/06/16 18:54:02 | 000,158,224 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmcomm.sys
[2010/06/16 18:54:02 | 000,146,448 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmlwf.sys
[2010/06/16 18:54:02 | 000,089,872 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmtdi.sys
[2010/06/16 18:54:02 | 000,059,920 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmactmon.sys
[2010/06/16 18:54:02 | 000,050,704 | ---- | M] (Trend Micro Inc.) -- C:\Windows\System32\drivers\tmevtmgr.sys
[2010/06/16 18:52:35 | 106,967,720 | ---- | M] (Trend Micro Inc.) -- C:\Users\The Farmer Family\Desktop\TISPro_Download32bit.exe
[2010/06/16 18:04:17 | 000,000,036 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\housecall.guid.cache
[2010/06/16 17:57:35 | 000,001,718 | ---- | M] () -- C:\Appdata.re
[2010/06/15 15:52:04 | 000,709,896 | ---- | M] (Trend Micro Incorporated) -- C:\Users\The Farmer Family\Desktop\Update_Tool.exe
[2010/06/15 15:26:21 | 000,002,255 | ---- | M] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/06/11 10:10:40 | 000,015,944 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2010/06/10 16:33:14 | 000,034,308 | ---- | M] () -- C:\Windows\System32\BASSMOD.dll
[2010/06/05 08:52:42 | 000,218,552 | ---- | M] () -- C:\Users\Public\Documents\rubber ducks.docx
[2010/05/31 21:39:36 | 000,001,681 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\CCleaner.lnk
[2010/05/25 19:34:59 | 000,162,304 | ---- | M] () -- C:\Users\Public\Documents\timetable.doc
[2010/05/25 19:24:15 | 000,034,498 | ---- | M] () -- C:\Users\Public\Documents\timetable.docx
[2010/05/21 20:27:23 | 000,000,205 | ---- | M] () -- C:\Users\The Farmer Family\Desktop\Perth - TV Guide.url
[2010/05/06 17:47:58 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/24 13:39:27 | 000,002,305 | ---- | M] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/04/03 19:36:13 | 000,000,600 | ---- | M] () -- C:\Users\The Farmer Family\AppData\Local\PUTTY.RND
[2010/04/03 19:25:30 | 000,001,796 | ---- | M] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2010/04/03 15:51:15 | 000,195,820 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
[2010/04/01 17:08:40 | 000,001,737 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/01 16:57:36 | 000,001,854 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2010/03/28 21:45:56 | 000,983,824 | ---- | M] () -- C:\Users\Public\Documents\Managing Your Own Rental Property Made Easy.docx

========== Files Created - No Company Name ==========

[2010/06/26 15:15:59 | 003,720,783 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\ComboFix.exe
[2010/06/24 20:06:18 | 000,524,288 | -HS- | C] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000002.regtrans-ms
[2010/06/24 20:06:17 | 000,524,288 | -HS- | C] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000001.regtrans-ms
[2010/06/24 20:06:17 | 000,065,536 | -HS- | C] () -- C:\Users\The Farmer Family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TM.blf
[2010/06/24 16:57:31 | 000,284,915 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\gmer.zip
[2010/06/20 13:05:46 | 000,155,110 | ---- | C] () -- C:\Users\Public\Documents\franies.docx
[2010/06/20 12:29:33 | 000,171,427 | ---- | C] () -- C:\Users\Public\Documents\patrics day.docx
[2010/06/18 20:08:42 | 000,023,572 | ---- | C] () -- C:\Users\Public\Documents\DECEMBER.docx
[2010/06/17 20:30:19 | 000,361,868 | ---- | C] () -- C:\Users\Public\Documents\Presentation1.pptx
[2010/06/17 19:41:22 | 000,014,324 | ---- | C] () -- C:\Users\Public\Documents\callender.docx
[2010/06/17 07:57:42 | 000,000,744 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\NTREGOPT.lnk
[2010/06/17 07:57:42 | 000,000,725 | ---- | C] () -- C:\Users\The Farmer Family\Desktop\ERUNT.lnk
[2010/06/16 20:48:51 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll
[2010/06/16 20:48:51 | 000,153,088 | ---- | C] () -- C:\Windows\System32\UNRAR3.dll
[2010/06/16 20:48:51 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll
[2010/06/16 20:48:51 | 000,075,264 | ---- | C] () -- C:\Windows\System32\unacev2.dll
[2010/06/16 18:56:13 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Trend Micro Internet Security Pro.lnk
[2010/06/16 17:59:05 | 000,000,036 | ---- | C] () -- C:\Users\The Farmer Family\AppData\Local\housecall.guid.cache
[2010/06/16 17:56:14 | 000,001,718 | ---- | C] () -- C:\Appdata.re
[2010/06/10 16:33:14 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2010/06/05 08:52:38 | 000,218,552 | ---- | C] () -- C:\Users\Public\Documents\rubber ducks.docx
[2010/05/25 19:34:51 | 000,162,304 | ---- | C] () -- C:\Users\Public\Documents\timetable.doc
[2010/05/25 19:24:13 | 000,034,498 | ---- | C] () -- C:\Users\Public\Documents\timetable.docx
[2010/05/13 08:45:04 | 000,002,255 | ---- | C] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/05/08 09:41:50 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/08 09:41:50 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/06 17:47:58 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/04/03 19:35:42 | 000,000,600 | ---- | C] () -- C:\Users\The Farmer Family\AppData\Local\PUTTY.RND
[2010/04/03 15:51:15 | 000,195,820 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/04/01 17:08:40 | 000,001,737 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/01 16:57:36 | 000,002,305 | ---- | C] () -- C:\Users\The Farmer Family\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/04/01 16:57:36 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2010/03/28 20:06:24 | 000,983,824 | ---- | C] () -- C:\Users\Public\Documents\Managing Your Own Rental Property Made Easy.docx
[2010/02/21 21:43:19 | 000,015,944 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/06/11 11:34:04 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/03/24 15:35:17 | 000,000,985 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2009/03/24 15:35:17 | 000,000,173 | ---- | C] () -- C:\Windows\brpcfx.ini
[2009/03/24 15:34:00 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/03/24 15:34:00 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2009/03/05 06:54:58 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
[2008/11/09 17:38:28 | 000,036,864 | ---- | C] () -- C:\Windows\System32\LXBRPMON.DLL
[2008/11/09 17:38:28 | 000,020,480 | ---- | C] () -- C:\Windows\System32\LXBRPMUI.DLL
[2008/11/09 17:37:47 | 000,000,400 | ---- | C] () -- C:\Windows\Lexstat.ini
[2008/11/07 15:00:52 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/11/07 15:00:52 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/11/07 15:00:52 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/11/07 15:00:52 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/11/07 15:00:52 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/11/07 15:00:52 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/11/07 14:45:21 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2008/11/07 14:45:21 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2008/11/07 14:45:21 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2008/11/07 14:45:21 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2008/10/23 01:58:00 | 033,793,272 | ---- | C] () -- C:\Windows\System32\TrueAccessCoInst.dll
[2008/02/12 09:59:36 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/02/12 09:03:27 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/02/12 08:46:10 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/02/12 08:44:39 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/02/12 08:44:39 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2008/02/12 08:44:39 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/02/12 08:44:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2007/12/22 08:46:32 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2007/11/15 01:42:27 | 000,237,568 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2007/11/09 19:01:59 | 000,000,164 | ---- | C] () -- C:\Windows\System32\psyswin32.dll
[2006/11/02 15:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/07/23 13:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll

========== LOP Check ==========

[2008/11/09 20:08:58 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\4200Series
[2008/11/11 09:12:27 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\ABIG
[2009/12/16 19:42:19 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/04/01 15:29:38 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Facebook
[2010/05/24 22:19:55 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\FileZilla
[2008/11/27 14:35:36 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit
[2010/06/10 16:27:06 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Foxit Software
[2009/01/08 11:29:35 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Leadertech
[2009/07/16 00:20:57 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\LimeWire
[2010/01/11 12:59:27 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\PC-FAX TX
[2008/11/09 20:38:47 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\PeerNetworking
[2009/07/25 16:02:13 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Publish Providers
[2010/06/26 14:19:03 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Simply Super Software
[2009/07/25 16:29:32 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Sony
[2008/11/07 19:01:51 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\SPAMfighter
[2009/07/23 16:59:36 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Thunderbird
[2009/01/21 08:01:04 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\toshiba
[2008/11/09 20:50:23 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\TransMemory_Secure
[2008/11/09 22:22:14 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\Ulead Systems
[2010/06/24 20:04:03 | 000,000,000 | ---D | M] -- C:\Users\The Farmer Family\AppData\Roaming\uTorrent
[2010/06/24 20:59:35 | 000,032,584 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/26 14:50:29 | 000,000,442 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{8A415B25-380B-42B8-AD69-30FDD51BD09A}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 48 bytes -> C:\Windows:D2F9AAA03D24C7ED
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:CB0AACC9
< End of report >

MBAM as follows:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4204

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18928

26/06/2010 4:15:35 PM
mbam-log-2010-06-26 (16-15-35).txt

Scan type: Full scan (C:\|)
Objects scanned: 295345
Time elapsed: 57 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


TDSSKiller log:

08:39:57:142 2212 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
08:39:57:142 2212 ================================================================================
08:39:57:142 2212 SystemInfo:

08:39:57:142 2212 OS Version: 6.0.6002 ServicePack: 2.0
08:39:57:142 2212 Product type: Workstation
08:39:57:142 2212 ComputerName: THEFARMERFAMILY
08:39:57:142 2212 UserName: The Farmer Family
08:39:57:142 2212 Windows directory: C:\Windows
08:39:57:142 2212 Processor architecture: Intel x86
08:39:57:142 2212 Number of processors: 2
08:39:57:142 2212 Page size: 0x1000
08:39:57:158 2212 Boot type: Normal boot
08:39:57:158 2212 ================================================================================
08:39:58:294 2212 Initialize success
08:39:58:295 2212
08:39:58:295 2212 Scanning Services ...
08:40:00:734 2212 Raw services enum returned 470 services
08:40:00:750 2212
08:40:00:751 2212 Scanning Drivers ...
08:40:02:391 2212 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
08:40:02:648 2212 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
08:40:02:819 2212 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
08:40:02:877 2212 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
08:40:03:069 2212 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
08:40:03:330 2212 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
08:40:03:749 2212 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys
08:40:04:125 2212 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
08:40:04:486 2212 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
08:40:04:624 2212 AlfaFF (4490b8bdf38750458eb9b24835fda8fe) C:\Windows\system32\drivers\AlfaFF.sys
08:40:04:719 2212 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
08:40:04:941 2212 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
08:40:05:305 2212 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
08:40:05:505 2212 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
08:40:05:587 2212 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
08:40:05:799 2212 AnyDVD (b8f9d3ae038810c6ea08e123cada765e) C:\Windows\system32\Drivers\AnyDVD.sys
08:40:06:077 2212 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
08:40:06:295 2212 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
08:40:06:519 2212 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
08:40:06:704 2212 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
08:40:06:736 2212 ATSWPDRV (7ceaaa478bd100ecbb1a2fc38f8f03de) C:\Windows\system32\DRIVERS\ATSwpDrv.sys
08:40:06:898 2212 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
08:40:06:928 2212 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
08:40:07:141 2212 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
08:40:07:383 2212 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
08:40:07:645 2212 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
08:40:07:832 2212 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
08:40:07:883 2212 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
08:40:08:177 2212 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
08:40:08:319 2212 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
08:40:08:539 2212 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
08:40:08:743 2212 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
08:40:08:959 2212 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
08:40:09:250 2212 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
08:40:09:547 2212 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
08:40:09:763 2212 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
08:40:09:824 2212 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
08:40:10:019 2212 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
08:40:10:090 2212 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
08:40:10:377 2212 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
08:40:10:585 2212 CSC (9bdb2e89be8d0ef37b1f25c3d3fc192c) C:\Windows\system32\drivers\csc.sys
08:40:10:826 2212 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
08:40:10:882 2212 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
08:40:11:079 2212 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
08:40:11:335 2212 DXGKrnl (5c7e2097b91d689ded7a6ff90f0f3a25) C:\Windows\System32\drivers\dxgkrnl.sys
08:40:11:426 2212 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
08:40:11:523 2212 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
08:40:11:602 2212 ElbyCDIO (44996a2addd2db7454f2ca40b67d8941) C:\Windows\system32\Drivers\ElbyCDIO.sys
08:40:11:778 2212 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
08:40:12:033 2212 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
08:40:12:304 2212 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
08:40:12:461 2212 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
08:40:12:603 2212 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
08:40:12:690 2212 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
08:40:12:882 2212 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
08:40:13:003 2212 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
08:40:13:074 2212 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
08:40:13:184 2212 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
08:40:13:260 2212 FwLnk (cbc22823628544735625b280665e434e) C:\Windows\system32\DRIVERS\FwLnk.sys
08:40:13:329 2212 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
08:40:13:459 2212 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:40:13:542 2212 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
08:40:13:659 2212 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
08:40:13:794 2212 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
08:40:13:863 2212 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
08:40:13:924 2212 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
08:40:13:977 2212 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
08:40:14:190 2212 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
08:40:14:429 2212 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
08:40:14:630 2212 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
08:40:14:747 2212 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\DRIVERS\iaStor.sys
08:40:15:056 2212 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
08:40:15:686 2212 igfx (038815297078d236d8cc064c295a74c6) C:\Windows\system32\DRIVERS\igdkmd32.sys
08:40:16:066 2212 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
08:40:16:464 2212 IntcAzAudAddService (8a4341616976e47712b60f18c7049dcc) C:\Windows\system32\drivers\RTKVHDA.sys
08:40:16:732 2212 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
08:40:16:774 2212 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
08:40:16:933 2212 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:40:17:186 2212 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
08:40:17:372 2212 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
08:40:17:574 2212 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
08:40:17:731 2212 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
08:40:17:841 2212 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
08:40:18:049 2212 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
08:40:18:114 2212 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
08:40:18:189 2212 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
08:40:18:265 2212 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
08:40:18:339 2212 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\Windows\system32\drivers\klmd.sys
08:40:18:405 2212 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
08:40:18:514 2212 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
08:40:18:602 2212 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
08:40:18:637 2212 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
08:40:18:742 2212 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
08:40:18:787 2212 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
08:40:18:860 2212 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
08:40:18:910 2212 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
08:40:19:049 2212 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
08:40:19:107 2212 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
08:40:19:128 2212 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
08:40:19:224 2212 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
08:40:19:288 2212 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
08:40:19:349 2212 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
08:40:19:464 2212 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
08:40:19:528 2212 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
08:40:19:591 2212 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
08:40:19:652 2212 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:40:19:794 2212 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:40:19:981 2212 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:40:20:115 2212 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
08:40:20:190 2212 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
08:40:20:238 2212 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
08:40:20:285 2212 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
08:40:20:335 2212 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
08:40:20:533 2212 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
08:40:20:787 2212 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
08:40:21:062 2212 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
08:40:21:288 2212 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
08:40:21:533 2212 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
08:40:21:760 2212 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
08:40:21:960 2212 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
08:40:22:078 2212 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
08:40:22:294 2212 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
08:40:22:633 2212 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
08:40:22:835 2212 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
08:40:23:085 2212 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
08:40:23:300 2212 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
08:40:23:549 2212 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
08:40:24:128 2212 NETw3v32 (35d5458d9a1b26b2005abffbf4c1c5e7) C:\Windows\system32\DRIVERS\NETw3v32.sys
08:40:24:681 2212 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys
08:40:25:399 2212 NETw5v32 (8de67bd902095a13329fd82c85a1fa09) C:\Windows\system32\DRIVERS\NETw5v32.sys
08:40:25:774 2212 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
08:40:25:994 2212 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
08:40:26:177 2212 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
08:40:26:610 2212 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
08:40:26:947 2212 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
08:40:27:248 2212 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
08:40:27:794 2212 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
08:40:28:417 2212 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
08:40:28:729 2212 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
08:40:28:870 2212 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
08:40:29:010 2212 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
08:40:29:188 2212 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
08:40:29:452 2212 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
08:40:29:731 2212 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
08:40:29:964 2212 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
08:40:30:249 2212 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
08:40:30:517 2212 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
08:40:30:834 2212 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
08:40:31:071 2212 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
08:40:31:142 2212 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
08:40:31:296 2212 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
08:40:31:356 2212 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
08:40:31:678 2212 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
08:40:32:103 2212 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
08:40:32:538 2212 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
08:40:32:767 2212 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
08:40:32:973 2212 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:40:33:333 2212 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
08:40:33:742 2212 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
08:40:33:907 2212 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
08:40:34:142 2212 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:40:34:412 2212 rdpdr (943b18305eae3935598a9b4a3d560b4c) C:\Windows\system32\DRIVERS\rdpdr.sys
08:40:34:621 2212 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
08:40:34:702 2212 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
08:40:34:862 2212 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
08:40:35:245 2212 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
08:40:35:411 2212 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
08:40:35:482 2212 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys
08:40:35:745 2212 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
08:40:36:066 2212 RTL8169 (bc83e99d5dfad89d4589545a43498acc) C:\Windows\system32\DRIVERS\Rtlh86.sys
08:40:36:306 2212 s116bus (815445f4676cc96bc9aeec303c727e19) C:\Windows\system32\DRIVERS\s116bus.sys
08:40:36:721 2212 s116mdfl (333d1e0743e6de1779c3c418ac601c3a) C:\Windows\system32\DRIVERS\s116mdfl.sys
08:40:36:862 2212 s116mdm (50d6e5b021e9ec7553ab8a3553cc1b6b) C:\Windows\system32\DRIVERS\s116mdm.sys
08:40:37:142 2212 s116mgmt (1589aa53e43f8d193a7d4d580d3ffa95) C:\Windows\system32\DRIVERS\s116mgmt.sys
08:40:37:440 2212 s116obex (ec32601f04a5a5de89315d0f55e73d66) C:\Windows\system32\DRIVERS\s116obex.sys
08:40:37:694 2212 s116unic (32e3ecb4b2b5887426eaf241a8149cde) C:\Windows\system32\DRIVERS\s116unic.sys
08:40:37:998 2212 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
08:40:38:121 2212 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
08:40:38:232 2212 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
08:40:38:361 2212 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
08:40:38:476 2212 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
08:40:38:738 2212 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
08:40:39:318 2212 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
08:40:39:532 2212 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
08:40:39:754 2212 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
08:40:39:829 2212 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
08:40:40:234 2212 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
08:40:40:654 2212 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
08:40:41:122 2212 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
08:40:41:481 2212 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
08:40:41:605 2212 smserial (c8a58fc905c9184fa70e37f71060c64d) C:\Windows\system32\DRIVERS\smserial.sys
08:40:41:961 2212 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
08:40:42:334 2212 srv (0debafcc0e3591fca34f077cab62f7f7) C:\Windows\system32\DRIVERS\srv.sys
08:40:42:586 2212 srv2 (6b6f3658e0a58c6c50c5f7fbdf3df633) C:\Windows\system32\DRIVERS\srv2.sys
08:40:42:689 2212 srvnet (0c5ab1892ae0fa504218db094bf6d041) C:\Windows\system32\DRIVERS\srvnet.sys
08:40:42:861 2212 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
08:40:42:915 2212 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
08:40:43:481 2212 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
08:40:43:837 2212 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
08:40:44:112 2212 SynTP (70534d1e4f9ac990536d5fb5b550b3de) C:\Windows\system32\DRIVERS\SynTP.sys
08:40:44:504 2212 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\Windows\system32\DRIVERS\taphss.sys
08:40:44:965 2212 Tcpip (48cbe6d53632d0067c2d6b20f90d84ca) C:\Windows\system32\drivers\tcpip.sys
08:40:45:405 2212 Tcpip6 (48cbe6d53632d0067c2d6b20f90d84ca) C:\Windows\system32\DRIVERS\tcpip.sys
08:40:45:840 2212 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
08:40:45:948 2212 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys
08:40:46:151 2212 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
08:40:47:648 2212 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
08:40:47:824 2212 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
08:40:48:031 2212 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
08:40:48:215 2212 tmactmon (582f43830daa5d9aad7aa514843d8905) C:\Windows\system32\DRIVERS\tmactmon.sys
08:40:48:483 2212 tmcomm (949ef0df929a71d6cc77494dfcb1ddeb) C:\Windows\system32\DRIVERS\tmcomm.sys
08:40:48:852 2212 tmevtmgr (9d38ac83d56f9b5274a65d2666da9779) C:\Windows\system32\DRIVERS\tmevtmgr.sys
08:40:49:041 2212 tmlwf (4e87d02e56e9b1af831c5d521597d629) C:\Windows\system32\DRIVERS\tmlwf.sys
08:40:49:246 2212 tmpreflt (c7c7959ec0940e0eddfc881fed8ec214) C:\Windows\system32\DRIVERS\tmpreflt.sys
08:40:49:539 2212 tmtdi (44c262c1b2412ded35078b6166d2acc2) C:\Windows\system32\DRIVERS\tmtdi.sys
08:40:49:737 2212 tmwfp (d9882fd91b7c4c35acaa8498d1f3cd68) C:\Windows\system32\DRIVERS\tmwfp.sys
08:40:49:860 2212 tmxpflt (3e615f370f0c7db414b6bcd1c18399d4) C:\Windows\system32\DRIVERS\tmxpflt.sys
08:40:49:962 2212 toshidpt (e362d54fd394999c4178936396664e57) C:\Windows\system32\drivers\Toshidpt.sys
08:40:50:345 2212 tosporte (8d624d3bd1f2d78bd1c01a2d4e954b4e) C:\Windows\system32\DRIVERS\tosporte.sys
08:40:50:495 2212 tosrfbd (eaeddb6c8bbe3e1b753753c2e847fecb) C:\Windows\system32\DRIVERS\tosrfbd.sys
08:40:50:573 2212 tosrfbnp (181e217a7a326817d97946d045b3cb46) C:\Windows\system32\Drivers\tosrfbnp.sys
08:40:50:908 2212 Tosrfcom (e90ace3b4fa7a85f992bc21eb779c407) C:\Windows\system32\Drivers\tosrfcom.sys
08:40:51:183 2212 tosrfec (c063b8e2db85420438ebce3fc8d2752e) C:\Windows\system32\DRIVERS\tosrfec.sys
08:40:51:250 2212 Tosrfhid (87700714f25131ed21901d617b8b321f) C:\Windows\system32\DRIVERS\Tosrfhid.sys
08:40:51:406 2212 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\Windows\system32\DRIVERS\tosrfnds.sys
08:40:51:453 2212 Tosrfusb (98c04a6432ce9c2ad328f57b9384d348) C:\Windows\system32\DRIVERS\tosrfusb.sys
08:40:51:594 2212 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys
08:40:51:662 2212 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:40:51:723 2212 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
08:40:52:201 2212 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
08:40:52:254 2212 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
08:40:52:310 2212 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
08:40:52:432 2212 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
08:40:52:480 2212 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
08:40:52:635 2212 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
08:40:52:706 2212 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
08:40:52:854 2212 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
08:40:53:144 2212 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
08:40:53:890 2212 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\Windows\system32\Drivers\usbaapl.sys
08:40:54:088 2212 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
08:40:54:633 2212 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
08:40:54:876 2212 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
08:40:55:069 2212 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
08:40:55:318 2212 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
08:40:55:510 2212 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
08:40:55:694 2212 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
08:40:55:767 2212 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:40:55:938 2212 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
08:40:56:004 2212 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
08:40:56:305 2212 UVCFTR (8c5094a8ab24de7496c7c19942f2df04) C:\Windows\system32\Drivers\UVCFTR_S.SYS
08:40:56:380 2212 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
08:40:56:643 2212 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
08:40:56:875 2212 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
08:40:56:930 2212 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
08:40:57:012 2212 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
08:40:57:202 2212 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
08:40:57:377 2212 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
08:40:57:522 2212 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
08:40:57:746 2212 vsapint (60dfbc34228ca36221b03460789f5d4e) C:\Windows\system32\DRIVERS\vsapint.sys
08:40:57:932 2212 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
08:40:57:970 2212 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
08:40:58:015 2212 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
08:40:58:021 2212 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
08:40:58:203 2212 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
08:40:58:254 2212 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
08:40:58:582 2212 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
08:40:58:747 2212 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
08:40:58:794 2212 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
08:40:58:833 2212 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:40:58:838 2212
08:40:58:839 2212 Completed
08:40:58:839 2212
08:40:58:839 2212 Results:
08:40:58:840 2212 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
08:40:58:840 2212 File objects infected / cured / cured on reboot: 0 / 0 / 0
08:40:58:841 2212
08:40:58:849 2212 KLMD(ARK) unloaded successfully

Combofix:

I followed the instructions and ran combofix as requested. I went for a walk while it ran and when I came back 30 mins later, the screen was black and locked up. I had to hard shut-down again and power up in safe mode with networking. There is no record of combofix.txt and I didn't want to run it again (as mentioned in your instructions).

A couple of points I have noted whilst the system has been playing up:

1. pagefile.sys is 3,441,884kb in size after the last reboot. Is this normal?

2. Whilst running some of the services you've requested, I got an error message in the bottom taskbar saying I had a corrupt file PEV.cfxxe, c:\programdata\adobe\ISO-19770

3. The hard drive light goes out when the system freezes but the mouse and capslock still work. I've run Toshiba diagnostics on the hard drive and memory and haven't found any errors.

4. My other laptop on the same network is not having any problems

5. Since last week, when the system boots up, there is a windows message saying that programs have been blocked from starting. There are a LOT of services in the blocked programs screen.

Cheers
Michelle
  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
You left out a > in the second line so it overwrote the first one so I can't be sure you are going to google. It goes to

inetnum: 203.59.0.0 - 203.59.255.255
netname: IINET-AU
descr: iiNet Limited
descr: Level 6, Durack Centre
descr: 263 Adelaide Terrace
descr: Perth WA 6000
country: AU

which might be google.com.au but I have no way of knowing if that is the right address. When I do it I just get the us google which starts with 74.

Your hard drive is having problems. I see three folders

[2010/06/26 10:33:54 | 000,000,000 | -HSD | C] -- C:\found.001
[2010/06/25 19:24:50 | 000,000,000 | -HSD | C] -- C:\found.002
[2010/06/25 15:45:36 | 000,000,000 | -HSD | C] -- C:\found.000

with different times indicating that you (or it) have run the disk check three times in two days and each time it found something. This may be why so many services are not working. You should backup your data now as I think it's going to die.

The pev error usually indicates that the anti-virus got in the way tho it may be your hard drive. Try downloading it again. Make sure your anti-virus is off when you do. This time save it to george2.exe.

Ron
  • 0

#7
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hi Ron
I've re-run the router request which is as follows:
Server: UnKnown
Address: 192.168.1.1

Name: google.com
Addresses: 203.59.140.157
203.59.140.158
203.59.140.156



Tracing route to google.com [203.59.140.156]

over a maximum of 30 hops:



1 1 ms 1 ms 1 ms 192.168.1.1

2 * * * Request timed out.

3 20 ms 19 ms 18 ms 203.215.5.244

4 20 ms 18 ms 19 ms 203.215.4.36

5 24 ms 19 ms 19 ms 203.215.4.25

6 18 ms 19 ms 19 ms 203.59.140.156



Trace complete.

IInet is my ISP, it and I are based in Perth, Western Australia.

I ran combofix but had to do it again in Safe mode. I got the same error with PEV again (in a different location with the Adobe folder). I've attached the txt file which I did locate after rebooting. I checked to see that my AV program, Trend, wasn't running but in Safe mode it didn't boot up.

ComboFix 10-06-26.02 - The Farmer Family 27/06/2010 9:19:33.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.61.1033.18.3061.2573 [GMT 8:00]
Running from: C:\Users\The Farmer Family\Desktop\george2.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Windows\system32\service\02012009_TIS17_SfFniAU.log
C:\Windows\system32\service\07062010_TIS17_SfFniAU.log
C:\Windows\system32\service\08122009_TIS17_SfFniAU.log
C:\Windows\system32\service\09012009_TIS17_SfFniAU.log
C:\Windows\system32\service\14012009_TIS17_SfFniAU.log
C:\Windows\system32\service\14052009_TIS17_SfFniAU.log
C:\Windows\system32\service\15022010_TIS17_SfFniAU.log
C:\Windows\system32\service\15062010_TIS17_SfFniAU.log
C:\Windows\system32\service\16032009_TIS17_SfFniAU.log
C:\Windows\system32\service\16042010_TIS17_SfFniAU.log
C:\Windows\system32\service\16062010_TIS17_SfFniAU.log
C:\Windows\system32\service\18022009_TIS17_SfFniAU.log
C:\Windows\system32\service\22012009_TIS17_SfFniAU.log
C:\Windows\system32\service\22042010_TIS17_SfFniAU.log
C:\Windows\system32\service\26122008_TIS17_SfFniAU.log

.

As for the chkdsk issue. I've had to hard boot many times over the past few days and the chkdsk has run on several of these occasion automatically. I forced a check again this morning which took several hours with my system booting up normally and running okay for now ... well, it hasn't locked up for the past few minutes anyway! I take anything as positive at the moment ...

I've been trying to backup my system for the past few days but because of the stalling problem, I don't get very far and I realise how important it is right now ... given the possible hdd problem. I'm going to try again now but not sure how to do it if I have to go into Safe mode. Can you give me some pointers please?

I'm also concerned that the latest upgrade of Trend may be causing some conflicts so considering whether to uninstall and downgrade back to my previous version. Your thoughts?

Thanks, Ron, will wait to hear back from you.
Cheers
Michelle
  • 0

#8
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hi Ron
The laptop froze again before I could complete the backup. Any advice on how to backup in safe mode?
Cheers
Michelle
  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
It's probably google.com.au since you get more than one but you might ask a friend to run nslookup google.com.au and see what they get.

I'm not real fond of Trend. I use the free Avast! which I think is just as good or better.
http://www.avast.com...avast-home.html
Might be worth uninstalling Trend and trying Avast!

The combofix log is just a fragment. See if you can get dds to run:
Please download DDS from http://download.blee...om/sUBs/dds.com or http://download.blee...om/sUBs/dds.scr
and save it to your desktop.

* Disable any script blocking protection
* Right click dds.com or .scr and Run As Administrator to run the tool.
* When done, two DDS.txt's will open.
* Save both reports to your desktop.

---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

Start. Programs. Accessories, then right click on Command Prompt and Run As Administrator.

msconfig

under Startup, uncheck everything. Under Services first check Hide Microsoft Services then uncheck everything.

OK and reboot into regular mode and see if it will run without freezing.

Start. Programs. Accessories, then right click on Command Prompt and Run As Administrator.

sfc /scannow

SPACE after sfc. This will check your critical system files. If it asks for a CD and you don't have one or it doesn't like your CD just tell it to SKIP.

sigverif

Press Start. This will check your drivers. If you just get a few when it finishes tell me what they are. If you get a lot just look for those with newish dates (since about the time the problem started.)

cd \
dir /a found.001 > junk.txt
dir /a found.002 >> junk.txt
dir /a found.000 >> junk.txt
mbr >> junk.txt
notepad junk.txt

copy and paste the text from notepad.

Try and run the BitDefender scan:

http://www.bitdefend...nline/free.html


Get SIW

http://www.snapfiles.com/get/siw.html

Run it (right click and Run As Administrator) and under Hardware look for Sensors. Click on Sensors and look in the right pane there should be some temperature readings. What are they? Watch a video or run a scan for a little bit then look again. Are the temps going up?

1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right click VEW.exe and Run As Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Ron
  • 0

#10
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Just a quickie, can you tell me how to 'Disable any script blocking protection'
Cheers
Michelle
  • 0

#11
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Right, I have run DDS, with reports as follows:


DDS (Ver_10-03-17.01) - NTFSx86
Run by The Farmer Family at 15:42:55.17 on Sun 27/06/2010
Internet Explorer: 8.0.6001.18928
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.61.1033.18.3061.1598 [GMT 8:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TrueSuite Access Manager\usbnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TrueSuite Access Manager\FpNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Hiro-Media\HiroClient\HiroClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\The Farmer Family\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [TOSCDSPD] TOSCDSPD.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [UsbMonitor] c:\program files\truesuite access manager\usbnotify.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [FingerPrintNotifer] c:\program files\truesuite access manager\FpNotifier.exe
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\users\thefar~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\hiro-m~1.lnk - c:\program files\hiro-media\hiroclient\HiroClient.exe
StartupFolder: c:\users\thefar~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\autoru~1\pmbmed~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: hiro - {50BA1131-168F-4c08-A69B-4012273F222E} - c:\program files\hiro-media\hiroclient\HiroProtocolHandler.dll
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R0 AlfaFF;AlfaFF;c:\windows\system32\drivers\AlfaFF.sys [2008-3-14 42608]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-26 40960]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-2-12 7168]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-8 136176]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
S3 HitmanPro35Crusader;Hitman Pro 3.5 Crusader;"c:\users\the farmer family\desktop\hitmanpro35.exe" /crusader --> c:\users\the farmer family\desktop\HitmanPro35.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 Authentec memory manager;Authentec memory manager service;system32\TAMSvr.exe --> system32\TAMSvr.exe [?]

=============== Created Last 30 ================

2010-06-27 07:33:13 1048576 --sha-w- c:\users\the farmer family\ntuser.dat{75784367-7f87-11df-ac10-001e333b3685}.TxR.2.regtrans-ms
2010-06-27 07:33:13 1048576 --sha-w- c:\users\the farmer family\ntuser.dat{75784367-7f87-11df-ac10-001e333b3685}.TxR.1.regtrans-ms
2010-06-27 07:33:12 65536 --sha-w- c:\users\the farmer family\ntuser.dat{75784367-7f87-11df-ac10-001e333b3685}.TxR.blf
2010-06-27 07:33:12 1048576 --sha-w- c:\users\the farmer family\ntuser.dat{75784367-7f87-11df-ac10-001e333b3685}.TxR.0.regtrans-ms
2010-06-27 06:02:53 0 ----a-w- c:\windows\ToDisc.INI
2010-06-27 01:49:49 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-27 01:49:49 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-27 01:49:49 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-27 01:49:49 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-27 01:49:49 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-27 01:32:36 0 d-sh--w- C:\$RECYCLE.BIN
2010-06-27 01:18:19 0 d-----w- C:\george2
2010-06-26 08:38:58 98816 ----a-w- c:\windows\sed.exe
2010-06-26 08:38:58 77312 ----a-w- c:\windows\MBR.exe
2010-06-26 08:38:58 256512 ----a-w- c:\windows\PEV.exe
2010-06-26 08:38:58 161792 ----a-w- c:\windows\SWREG.exe
2010-06-26 08:38:53 0 d-----w- C:\george
2010-06-26 07:03:56 0 d-----w- C:\_OTL
2010-06-26 06:19:03 0 d-----w- c:\users\thefar~1\appdata\roaming\Simply Super Software
2010-06-26 06:19:03 0 d-----w- c:\programdata\Simply Super Software
2010-06-26 02:33:54 0 d-----w- C:\found.001
2010-06-26 00:54:24 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-26 00:54:24 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-25 11:24:50 0 d-----w- C:\found.002
2010-06-25 07:45:36 0 d-----w- C:\found.000
2010-06-25 07:21:39 0 d-----w- c:\windows\pss
2010-06-24 12:06:18 524288 --sha-w- c:\users\the farmer family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000002.regtrans-ms
2010-06-24 12:06:17 65536 --sha-w- c:\users\the farmer family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TM.blf
2010-06-24 12:06:17 524288 --sha-w- c:\users\the farmer family\ntuser.dat{75784368-7f87-11df-ac10-001e333b3685}.TMContainer00000000000000000001.regtrans-ms
2010-06-16 13:23:38 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-16 12:54:04 0 d---a-w- c:\programdata\TEMP
2010-06-16 12:48:51 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-06-16 12:48:51 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-06-16 12:48:51 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-06-16 12:48:51 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-06-16 12:48:51 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-06-16 12:48:48 0 d-----w- c:\program files\Trojan Remover
2010-06-16 10:55:57 0 d-----w- c:\programdata\Trend Micro
2010-06-16 10:55:09 0 d-----w- c:\program files\Trend Micro
2010-06-16 09:56:14 1718 ----a-w- C:\Appdata.re
2010-06-15 08:08:18 287608 ----a-w- c:\windows\system32\drivers\Tmfilter.sys
2010-06-10 08:27:06 0 d-----w- c:\users\thefar~1\appdata\roaming\Foxit Software

==================== Find3M ====================

2010-06-27 07:38:49 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-27 07:38:49 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-27 07:38:49 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-27 07:35:20 103 ----a-w- c:\users\the farmer family\HiroConfig.dat
2010-06-11 02:10:40 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-05-26 17:06:41 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47:41 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 05:59:21 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55:42 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55:42 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:13:48 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 07:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 07:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-12 09:29:19 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-08 05:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 05:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-03 07:51:15 195820 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-17 19:19:09 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:58 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:07 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:07 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:07 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:07 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-10-17 05:19:33 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 15:45:02.75 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume2
Install Date: 8/11/2008 8:34:07 AM
System Uptime: 27/06/2010 3:28:30 PM (0 hours ago)

Motherboard: Intel Corp. | | Base Board Product Name
Processor: Intel® Core™2 Duo CPU T5750 @ 2.00GHz | CPU | 2000/667mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 142 GiB total, 64.897 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

Acrobat.com
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Dreamweaver CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop Elements 7.0
Adobe Reader 9.3.1
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Shockwave Player 11.5
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe XMP Panels CS4
Apple Application Support
Apple Mobile Device Support
Apple Software Update
µTorrent
Bluetooth Stack for Windows by Toshiba
Bonjour
Brother MFL-Pro Suite MFC-290C
Camera Assistant Software for Toshiba
CCleaner
CD/DVD Drive Acoustic Silencer
Connect
DHTML Editing Component
DVD MovieFactory for TOSHIBA
e-tax 2009
ERUNT 1.1j
Facebook Plug-In
FileZilla Client 3.3.2.1
Foxit Creator
Google Toolbar for Internet Explorer
Google Update Helper
HIRO Client
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java Auto Updater
Java™ 6 Update 20
Java™ 6 Update 3
kuler
Malwarebytes' Anti-Malware
MarkAble 2.2.4
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft XML Parser
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
OGA Notifier 2.0.0048.0
Photoshop Camera Raw
Primo
QuickTime
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
Runtime
Safari
Scholastic's I SPY Treasure Hunt
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Suite Shared Configuration CS4
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA Recovery Disc Creator
TOSHIBA SD Memory Utilities
TOSHIBA Software Modem
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
Trojan Remover 6.8.1
TrueSuite Access Manager
Turbo Lister 2
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Vegas Movie Studio Platinum 9.0
Windows Media Encoder 9 Series
WinRAR archiver

==== End Of File ===========================

On with the rest ... Michelle
  • 0

#12
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
The results of junk.txt:

Volume in drive C is S3A6537D005
Volume Serial Number is E845-49BD

Directory of C:\found.001

26/06/2010 10:33 AM <DIR> .
26/06/2010 10:33 AM <DIR> ..
26/06/2010 10:33 AM <DIR> dir0000.chk
0 File(s) 0 bytes
3 Dir(s) 69,712,224,256 bytes free
Volume in drive C is S3A6537D005
Volume Serial Number is E845-49BD

Directory of C:\found.002

25/06/2010 07:24 PM <DIR> .
25/06/2010 07:24 PM <DIR> ..
25/06/2010 07:13 PM 2,902 file0000.chk
02/10/2009 11:55 AM 6,358 file0001.chk
2 File(s) 9,260 bytes
2 Dir(s) 69,712,093,184 bytes free
Volume in drive C is S3A6537D005
Volume Serial Number is E845-49BD

Directory of C:\found.000

25/06/2010 03:45 PM <DIR> .
25/06/2010 03:45 PM <DIR> ..
24/06/2010 03:57 PM 65,536 file0000.chk
1 File(s) 65,536 bytes
2 Dir(s) 69,711,863,808 bytes free
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK


I also ran sfc /scannow, as follows:

Microsoft Windows [Version 6.0.6002]
Copyright © 2006 Microsoft Corporation. All rights reserved.

C:\Windows\system32>sfc /scannow

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.
Verification 100% complete.

Windows Resource Protection did not find any integrity violations.

C:\Windows\system32>sigverif

C:\Windows\system32>sigverif

C:\Windows\system32>cd \

C:\>dir /a found.001 > junk.txt

C:\>dir /a found.002 >> junk.txt

C:\>dir /a found.000 >> junk.txt

C:\>mbr >> junk.txt

C:\>notepad junk.txt

C:\>



Sigverify said all drivers were confirmed digitally signed. I also deleted Trend and have rebooted ... no freezing yet. I haven't obtained the previous version yet, nor have I requested Avast. I will do this shortly.

On with SIW and the Event Viewer ...
Cheers
Michelle
  • 0

#13
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Event Viewer Tool results:

System

Vino's Event Viewer v01c run on Windows Vista in English
Report run at 27/06/2010 4:29:17 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 27/06/2010 8:28:20 AM
Type: Error Category: 0
Event: 6008 Source: EventLog
The previous system shutdown at 4:25:35 PM on 27/06/2010 was unexpected.

Log: 'System' Date/Time: 27/06/2010 8:23:16 AM
Type: Error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: yvxnxek

Log: 'System' Date/Time: 27/06/2010 8:23:16 AM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).

Log: 'System' Date/Time: 27/06/2010 8:21:42 AM
Type: Error Category: 0
Event: 6008 Source: EventLog
The previous system shutdown at 4:16:52 PM on 27/06/2010 was unexpected.

Log: 'System' Date/Time: 27/06/2010 7:53:38 AM
Type: Error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: yvxnxek

Log: 'System' Date/Time: 27/06/2010 7:53:38 AM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).

Log: 'System' Date/Time: 27/06/2010 7:39:53 AM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user THEFARMERFAMILY\The Farmer Family SID (S-1-5-21-64711756-4049480942-3407641261-1003) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 27/06/2010 7:33:48 AM
Type: Error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: yvxnxek

Log: 'System' Date/Time: 27/06/2010 7:33:48 AM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).

Log: 'System' Date/Time: 27/06/2010 7:33:01 AM
Type: Error Category: 0
Event: 6008 Source: EventLog
The previous system shutdown at 3:17:33 PM on 27/06/2010 was unexpected.

Log: 'System' Date/Time: 27/06/2010 6:46:53 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:46:27 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register with DCOM within the required timeout.

Log: 'System' Date/Time: 27/06/2010 6:45:35 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:45:13 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:44:51 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:44:51 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:44:47 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.

Log: 'System' Date/Time: 27/06/2010 6:44:06 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:44:05 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

Log: 'System' Date/Time: 27/06/2010 6:44:05 AM
Type: Error Category: 2
Event: 55 Source: Ntfs
The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume S3A6537D005.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 27/06/2010 8:28:08 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 8:21:32 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 7:51:48 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 7:50:56 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.

Log: 'System' Date/Time: 27/06/2010 7:32:05 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 6:44:33 AM
Type: Warning Category: 0
Event: 130 Source: Ntfs
The file system structure on volume C: has now been repaired.

Log: 'System' Date/Time: 27/06/2010 6:44:15 AM
Type: Warning Category: 0
Event: 130 Source: Ntfs
The file system structure on volume C: has now been repaired.

Log: 'System' Date/Time: 27/06/2010 6:09:14 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 6:08:35 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.

Log: 'System' Date/Time: 27/06/2010 5:22:31 AM
Type: Warning Category: 0
Event: 263 Source: PlugPlayManager
The service 'TabletInputService' may not have unregistered for device event notifications before it was stopped.

Log: 'System' Date/Time: 27/06/2010 5:22:07 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 5:00:48 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 4:26:39 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 3:50:28 AM
Type: Warning Category: 0
Event: 1 Source: RTL8169
Realtek PCIe GBE Family Controller is disconnected from network.

Log: 'System' Date/Time: 27/06/2010 1:58:06 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.

Log: 'System' Date/Time: 27/06/2010 1:55:59 AM
Type: Warning Category: 0
Event: 4376 Source: Microsoft-Windows-Servicing
Servicing has required reboot to complete the operation of setting package KB982519(Update) into Install Requested(Install Requested) state

Log: 'System' Date/Time: 27/06/2010 1:55:59 AM
Type: Warning Category: 0
Event: 4376 Source: Microsoft-Windows-Servicing
Servicing has required reboot to complete the operation of setting package KB982519(Update) into Install Requested(Install Requested) state

Log: 'System' Date/Time: 27/06/2010 1:55:59 AM
Type: Warning Category: 0
Event: 4376 Source: Microsoft-Windows-Servicing
Servicing has required reboot to complete the operation of setting package KB982519(Update) into Install Requested(Install Requested) state

Log: 'System' Date/Time: 27/06/2010 1:55:59 AM
Type: Warning Category: 0
Event: 4376 Source: Microsoft-Windows-Servicing
Servicing has required reboot to complete the operation of setting package KB982519(Update) into Install Requested(Install Requested) state

Log: 'System' Date/Time: 27/06/2010 1:55:59 AM
Type: Warning Category: 0
Event: 4376 Source: Microsoft-Windows-Servicing
Servicing has required reboot to complete the operation of setting package KB982519(Update) into Install Requested(Install Requested) state


Vino's Event Viewer v01c run on Windows Vista in English
Report run at 27/06/2010 4:30:36 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 27/06/2010 8:29:54 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 8:23:15 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 8:15:49 AM
Type: Error Category: 0
Event: 1017 Source: Microsoft-Windows-Perflib
Disabled performance counter data collection from the "PolicyAgent" service because the performance counter library for that service has generated one or more errors. The errors that forced this action have been written to the application event log. Correct the errors before enabling the performance counters for this service.

Log: 'Application' Date/Time: 27/06/2010 8:15:49 AM
Type: Error Category: 0
Event: 1005 Source: Microsoft-Windows-Perflib
Unable to locate the open procedure "OpenIPSecPerformanceData" in DLL "C:\Windows\System32\ipsecsvc.dll" for the "PolicyAgent" service. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Log: 'Application' Date/Time: 27/06/2010 8:15:49 AM
Type: Error Category: 0
Event: 1008 Source: Microsoft-Windows-Perflib
The Open Procedure for service "PNRPsvc" in DLL "C:\Windows\system32\pnrpperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.

Log: 'Application' Date/Time: 27/06/2010 8:15:47 AM
Type: Error Category: 0
Event: 1010 Source: Microsoft-Windows-Perflib
The Collect Procedure for the "EmdCache" service in DLL "C:\Windows\system32\emdmgmt.dll" generated an exception or returned an invalid status. The performance data returned by the counter DLL will not be returned in the Perf Data Block. The first four bytes (DWORD) of the Data section contains the exception code or status code.

Log: 'Application' Date/Time: 27/06/2010 7:53:38 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 7:33:44 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 6:45:50 AM
Type: Error Category: 3
Event: 3084 Source: Microsoft-Windows-Search
Failed to load protocol handler Search.CscHandler.1. Error description: Access is denied. .


Log: 'Application' Date/Time: 27/06/2010 6:44:11 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application svchost.exe_CscService, version 6.0.6001.18000, time stamp 0x47918b89, faulting module cscsvc.dll, version 6.0.6002.18005, time stamp 0x49e03830, exception code 0x80000004, fault offset 0x0001634a, process id 0x564, application start time 0x01cb15bf508b2d40.

Log: 'Application' Date/Time: 27/06/2010 6:44:11 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application svchost.exe_Winmgmt, version 6.0.6001.18000, time stamp 0x47918b89, faulting module wmisvc.dll, version 6.0.6002.18005, time stamp 0x49e038a4, exception code 0xc0000005, fault offset 0x0000905d, process id 0x578, application start time 0x01cb15bf508d8ea1.

Log: 'Application' Date/Time: 27/06/2010 6:44:09 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application svchost.exe_DPS, version 6.0.6001.18000, time stamp 0x47918b89, faulting module diagperf.dll, version 6.0.6002.18005, time stamp 0x49e03713, exception code 0xc0000096, fault offset 0x00002297, process id 0x148, application start time 0x01cb15bf5195fe5a.

Log: 'Application' Date/Time: 27/06/2010 6:10:13 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 5:23:51 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 5:22:49 AM
Type: Error Category: 16
Event: 4609 Source: Microsoft-Windows-EventSystem
The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043c from line 45 of d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Log: 'Application' Date/Time: 27/06/2010 5:01:55 AM
Type: Error Category: 0
Event: 10 Source: Microsoft-Windows-WMI
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Log: 'Application' Date/Time: 27/06/2010 5:01:44 AM
Type: Error Category: 3
Event: 3058 Source: Microsoft-Windows-Search
The application cannot be initialized.

Context: Windows Application

Details:
The content index metadata cannot be read. (0xc0041801)


Log: 'Application' Date/Time: 27/06/2010 5:01:44 AM
Type: Error Category: 3
Event: 3028 Source: Microsoft-Windows-Search
The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
The content index metadata cannot be read. (0xc0041801)


Log: 'Application' Date/Time: 27/06/2010 5:01:44 AM
Type: Error Category: 3
Event: 3029 Source: Microsoft-Windows-Search
The plug-in in <Search.TripoliIndexer> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
Element not found. (0x80070490)


Log: 'Application' Date/Time: 27/06/2010 5:01:41 AM
Type: Error Category: 3
Event: 3029 Source: Microsoft-Windows-Search
The plug-in in <Search.JetPropStore> cannot be initialized.

Context: Windows Application, SystemIndex Catalog

Details:
The content index metadata cannot be read. (0xc0041801)


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 27/06/2010 6:45:50 AM
Type: Warning Category: 0
Event: 6001 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <Sens> failed a notification event.

Log: 'Application' Date/Time: 27/06/2010 6:44:33 AM
Type: Warning Category: 0
Event: 12289 Source: Microsoft-Windows-Defrag
Volume C: was not defragmented. Reason: The volume is marked as dirty. you must run chkdsk on the volume to correct any problems before you attempt to defragment it again.

Log: 'Application' Date/Time: 27/06/2010 6:44:03 AM
Type: Warning Category: 7
Event: 510 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 1138688 (0x0000000000116000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (1417 seconds) to be serviced by the OS. In addition, 0 other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 1080 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:44:03 AM
Type: Warning Category: 7
Event: 510 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 1114112 (0x0000000000110000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (338 seconds) to be serviced by the OS. In addition, 23 other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 351 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:44:03 AM
Type: Warning Category: 7
Event: 510 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" at offset 129536 (0x000000000001fa00) for 1024 (0x00000400) bytes succeeded, but took an abnormally long time (351 seconds) to be serviced by the OS. In addition, 0 other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 540 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:20:11 AM
Type: Warning Category: 7
Event: 510 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 1146880 (0x0000000000118000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (465 seconds) to be serviced by the OS. In addition, 0 other I/O requests to this file have also taken an abnormally long time to be serviced since the last message regarding this problem was posted 188 seconds ago. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:20:11 AM
Type: Warning Category: 7
Event: 508 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 32768 (0x0000000000008000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (293 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:20:11 AM
Type: Warning Category: 7
Event: 508 Source: ESENT
Windows (3296) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" at offset 122368 (0x000000000001de00) for 7168 (0x00001c00) bytes succeeded, but took an abnormally long time (289 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 27/06/2010 6:08:34 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 6:08:34 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 5:22:40 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 5:02:24 AM
Type: Warning Category: 1
Event: 1008 Source: Microsoft-Windows-Search
The Windows Search Service is attempting to remove the old catalog.


Log: 'Application' Date/Time: 27/06/2010 5:01:44 AM
Type: Warning Category: 1
Event: 1008 Source: Microsoft-Windows-Search
The Windows Search Service is attempting to remove the old catalog.


Log: 'Application' Date/Time: 27/06/2010 1:32:51 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 1:32:50 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 1:32:35 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 1:32:28 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 1:32:28 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 27/06/2010 1:16:00 AM
Type: Warning Category: 0
Event: 1015 Source: MsiInstaller
Failed to connect to server. Error: 0x8007043C

Log: 'Application' Date/Time: 27/06/2010 1:04:11 AM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.


I didn't notice much if any difference in the temperature sensors whilst running a video. Temps are around:

41C for Core #0 and 45C for Core #1, Hard Drive 42C

LMK if you need anything else.
Cheers
Michelle
  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Log: 'System' Date/Time: 27/06/2010 7:33:48 AM
Type: Error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: yvxnxek

Looks like a malware driver but luckily it's broken. Let's see if we can find it.

Start, Programs, Accessories, then right click on Command Prompt and Run As Administrator.

mmc devmgmt.msc

(Space after mmc)

The Device Manager should open (You may have to do a Continue first). Do View, Show Hidden Devices. Then look for Non-Plug and Play Drivers. Under it should be yvxnxek. Right click on it and UNINSTALL. You will need to Reboot but first look through the driver lists for anything that has a yellow or red mark. Do you see anything?


The rest of the log entries are mostly dealing with a failing hard drive tho I do see that Windows Search is causing problems. We can turn it off since we don't really need it:

Right click on Computer and select Manage. Continue. Services and Applications, Services. Standard, find Windows Search and right click and select Properties. Change Startup Type to Disabled Apply. STOP the service. close the services window.

WMI is also messed up probably because of the hard rrive but we can try to fix it.

Click Start, Run and type CMD.EXE

Note: In Windows Vista, you need to open an elevated Command Prompt window. To do so, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.

Type this command and press Enter:

net stop winmgmt

Using Windows Explorer, rename the folder %windir%\System32\Wbem\Repository. (For example, %windir%\System32\Wbem\Repository_bad). %windir% represents the path to the Windows directory, which is typically C:\Windows.

Switch to Command Prompt window, and type the following and press ENTER after each line:

net start winmgmt

EXIT

What I would do about the hard drive is order a new one immediately. You will also need a USB 2.0 to IDE / SATA Converter Cable. You can get both from amazon.com

Don't know which drive you need but the cable is:

http://www.amazon.co..._pr_product_top

If you run SIW under Hardware, Storage Devices your hard drive will be the first one. It should give you the part number. Google the part number and you will find out what it is. Probably a SATA 2.5" of some capacity 40 G or higher. The maker doesn't have to be the same. I would get a bigger one than the original since the price difference is only about $10.

If you can connect up the new drive as an external usb drive then you can use the disk maker's software to clone the old drive. Then it's just a matter of removing the old drive and installing the new which usually just takes a small phillips screwdriver.

Ron
  • 0

#15
micknmark

micknmark

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Thanks Ron, I tried most of the stuff you last mentioned but didn't get far when the system froze again. I'm going to take the laptop to the shop today to organise a new hard drive. Thanks for all your help so far, very much appreciated.
Cheers
Michelle
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP