Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

sirefef can't connect to internet


  • Please log in to reply

#1
General Field Marshal

General Field Marshal

    Member

  • Member
  • PipPip
  • 71 posts
I am typing this from my roommate's computer. A couple of days ago I started Avast warnings about every five minutes regarding some kind of Sirefef invasion. When I opened my laptop today, I was unable to connect to the internet at all, Avast will not activate. Here is my OTL log, transferred via flash drive:


OTL logfile created on: 11/29/2011 12:25:08 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Primo\Desktop\malware stuff
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 709.00 Mb Available Physical Memory | 69.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.35 Gb Total Space | 6.75 Gb Free Space | 20.25% Space Free | Partition Type: NTFS

Computer Name: DESERT7210 | User Name: Primo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/10 06:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
PRC - [2011/03/16 16:32:59 | 000,325,000 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010/06/02 18:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/01/15 06:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/08/21 06:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/06/24 13:34:38 | 000,126,976 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


========== Modules (SafeList) ==========

MOD - [2011/05/10 06:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2007/03/26 12:03:20 | 000,057,344 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll
MOD - [2003/06/24 13:33:54 | 000,065,536 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [Auto | Stopped] -- -- (IBMPMSVC)
SRV - File not found [Auto | Stopped] -- -- (Bonjour Service)
SRV - File not found [Auto | Stopped] -- -- (Ati HotKey Poller)
SRV - File not found [Auto | Stopped] -- -- (Apple Mobile Device)
SRV - [2011/11/17 19:08:21 | 003,313,752 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_d768ebc.dll -- (Akamai)
SRV - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/01/15 06:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 06:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 06:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 06:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 06:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 05:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 05:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 05:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2007/05/02 07:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007/02/06 21:38:32 | 001,133,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/01/25 16:27:14 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/01/25 16:26:36 | 000,207,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/01/25 16:26:28 | 000,703,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...UGO&form=ZGAPHP
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;<local>

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 15:37:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/21 21:14:44 | 000,000,000 | ---D | M]

[2010/04/21 22:18:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Extensions
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions
[2011/11/10 12:01:37 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/22 19:27:41 | 000,000,000 | ---D | M] (Search Toolbar) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2010/10/27 20:40:11 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2011/06/22 19:27:41 | 000,001,919 | ---- | M] () -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\searchplugins\bing-zugo.xml
[2011/11/09 15:37:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/07 12:51:33 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PRIMO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\37V2W6J0.DEFAULT\EXTENSIONS\{40A1F5D7-AFC2-498F-B264-02668D616FF6}.XPI
[2011/11/09 15:37:31 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/10/04 10:17:50 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 02:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old
[2011/11/09 15:37:31 | 000,002,040 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/05/01 23:24:09 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk = C:\Documents and Settings\Primo\Application Data\Leadertech\PowerRegister\Seagate na02sx8d Product Registration.exe (Leader Technologies/Seagate)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a\X) - C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a\X ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/03 21:00:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\WINDOWS\System32\
[2011/11/28 23:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2011/11/27 22:13:53 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a
[2011/11/07 20:13:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Desktop\lcs_win32_4.04.0
[2011/11/03 18:40:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\Akamai
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\WINDOWS\System32\
[2011/11/29 12:22:51 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/29 12:15:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/28 23:13:34 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/27 22:45:46 | 000,001,313 | ---- | M] () -- C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk
[2011/11/22 01:52:48 | 000,000,285 | ---- | M] () -- C:\Documents and Settings\Primo\Desktop\Shortcut to New Volume (D).lnk
[2011/11/21 20:38:09 | 000,108,544 | ---- | M] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 20:52:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/12 13:06:41 | 000,135,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/10 18:04:35 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/11/10 03:02:37 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/07 10:56:28 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/06 12:42:54 | 000,426,932 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/06 12:42:54 | 000,065,776 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/10 18:04:33 | 000,000,268 | ---- | C] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/05/11 22:34:31 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2011/05/02 01:21:08 | 000,025,380 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/04/02 16:14:58 | 000,108,544 | ---- | C] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/02 19:05:32 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/02/02 19:05:32 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/02/01 18:54:17 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/04/25 02:25:10 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/22 13:15:47 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010/04/21 22:18:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/15 07:56:42 | 000,087,540 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/04/04 12:58:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/04/03 21:03:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/04/03 20:57:28 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/04/03 20:42:01 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/04/03 20:42:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/04/03 20:42:00 | 000,426,932 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/04/03 20:42:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/04/03 20:42:00 | 000,065,776 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/04/03 20:42:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/04/03 20:42:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/04/03 20:41:59 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/04/03 20:41:59 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/04/03 20:41:59 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/04/03 20:41:51 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/04/03 20:41:50 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/04/03 13:51:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/04/03 13:50:44 | 000,135,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/06/24 13:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll

========== LOP Check ==========

[2010/06/08 12:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/05/11 12:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/06/13 01:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2011/06/20 20:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/10/16 20:11:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/10/18 23:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/13 01:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/04/22 22:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/05/02 01:04:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/09/06 19:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\Dropbox
[2010/06/16 22:16:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\Facebook
[2010/10/18 15:33:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\InterVideo
[2011/10/04 00:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\Leadertech
[2011/08/18 13:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\Megaupload
[2011/06/14 20:17:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\Ulead Systems
[2011/05/11 12:09:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Primo\Application Data\WinPatrol
[2011/11/10 18:04:35 | 000,000,268 | ---- | M] () -- C:\WINDOWS\Tasks\prismShakeIcon.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

Thanks!
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Start, Run, eventvwr.msc, OK to bring up the Event Viewer. Right click on System and Clear All Events, No (we don't want to save the old log), OK. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Double-click VEW.exe
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.


Start, All Programs, Accessories, Command Prompt. Type with an Enter after each line in the code box:

ipconfig /flushdns

netsh  winsock  reset catalog


netsh  int ip reset reset.log


(I use two spaces in the code box so you will be sure to see where 1 space goes.)

Reboot and test. If it still won't connect then Copy the next line:

reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters %userprofile%\Desktop\junk.txt

Start, All Programs, Accessories, Command Prompt.

Right click and Paste or Edit then paste. Hit Enter. Close Command Window. This should create a file on your desktop called junk.txt. Attach it to your next post.

ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Doubleclick on ComboFix to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then run it.
Double click on TDSSKiller.exe
Scan.
If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.


Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
uncheck trace disk IO calls
Click the "Scan" button to start scan
On completion of the scan (Note if the Fix button is enabled (not the FixMBR button) and tell me) click save log, save it to your desktop and post in your next reply

Ron
  • 0

#3
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
Luckily, I already had Event Viewer Tool.

System output log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 30/11/2011 4:54:15 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 30/11/2011 4:52:04 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:51:55 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:47:25 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:57 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:38 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:30 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The Network Location Awareness (NLA) service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7024 Source: Service Control Manager
The Background Intelligent Transfer Service service terminated with service-specific error 2147952450 (0x80072742).

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7023 Source: Service Control Manager
The Automatic Updates service terminated with the following error: %%2147952450

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7023 Source: Service Control Manager
The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: A socket operation encountered a dead network.

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Remote Registry service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Remote Registry service to connect.

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7023 Source: Service Control Manager
The IPSEC Services service terminated with the following error: A socket operation encountered a dead network.

Log: 'System' Date/Time: 30/11/2011 4:46:16 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Java Quick Starter service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 30/11/2011 4:46:15 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Bonjour Service service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 30/11/2011 4:46:15 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Apple Mobile Device service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 30/11/2011 4:46:15 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The TCP/IP NetBIOS Helper service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:15 PM
Type: error Category: 0
Event: 7003 Source: Service Control Manager
The DHCP Client service depends on the following nonexistent service: Afd

Log: 'System' Date/Time: 30/11/2011 4:46:15 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Ati HotKey Poller service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 30/11/2011 4:45:58 PM
Type: error Category: 0
Event: 10010 Source: DCOM
The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application output log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 30/11/2011 4:55:18 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Typing what was in the box did not allow me to connect. Typing the next line beginning with "reg export . . . " got me this message:

Error: too many command-line parameters
  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
This looks like a zero access rootkit infection. Some a-v has removed it incorrectly and you no longer have the afd.sys file.

Copy the text in the code box by highlighting and Ctrl + c

/md5start
afd.sys
/md5stop

then run OTL and Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the Run SCAN button at the top
Let the program run unhindered, OTL will reboot the PC when it is done. Save the log and copy and paste it to a reply.

At the bottom of the log it will tell you if it found any afd.sys files. If it did then you can copy the newest one that it found to C:\windows\system32\drivers\ then reboot and it might be able to connect.

Combofix is your best bet to remove the infection. It will work better if it has the Recovery Console installed:

http://www.bleepingc...manual_recovery

You have Windows XP Professional Edition Service Pack 3 so get:

http://www.microsoft...&displaylang=en

and move it over to the sick PC then drag and drop it on the combofix icon on the desktop.
  • 0

#5
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
OTL log:

OTL logfile created on: 12/1/2011 1:27:40 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Primo\Desktop\malware stuff
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 686.00 Mb Available Physical Memory | 67.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.35 Gb Total Space | 6.75 Gb Free Space | 20.26% Space Free | Partition Type: NTFS

Computer Name: DESERT7210 | User Name: Primo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/10 06:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
PRC - [2011/03/16 16:32:59 | 000,325,000 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010/06/02 18:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/01/16 11:02:38 | 000,436,752 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\mcuicnt.exe
PRC - [2010/01/15 06:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/08/21 06:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/06/24 13:34:38 | 000,126,976 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


========== Modules (SafeList) ==========

MOD - [2011/05/10 06:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2007/03/26 12:03:20 | 000,057,344 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll
MOD - [2003/06/24 13:33:54 | 000,065,536 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [Auto | Stopped] -- -- (IBMPMSVC)
SRV - File not found [Auto | Stopped] -- -- (Bonjour Service)
SRV - File not found [Auto | Stopped] -- -- (Ati HotKey Poller)
SRV - File not found [Auto | Stopped] -- -- (Apple Mobile Device)
SRV - [2011/11/17 19:08:21 | 003,313,752 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_d768ebc.dll -- (Akamai)
SRV - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/01/15 06:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)


========== Driver Services (SafeList) ==========

DRV - [2011/05/10 06:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 06:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 06:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 06:02:25 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/05/10 05:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 05:59:37 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/10 05:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2007/05/02 07:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007/02/06 21:38:32 | 001,133,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/01/25 16:27:14 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/01/25 16:26:36 | 000,207,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/01/25 16:26:28 | 000,703,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...UGO&form=ZGAPHP
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;<local>

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 15:37:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/21 21:14:44 | 000,000,000 | ---D | M]

[2010/04/21 22:18:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Extensions
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions
[2011/11/10 12:01:37 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/22 19:27:41 | 000,000,000 | ---D | M] (Search Toolbar) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2010/10/27 20:40:11 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2011/06/22 19:27:41 | 000,001,919 | ---- | M] () -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\searchplugins\bing-zugo.xml
[2011/11/09 15:37:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/07 12:51:33 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PRIMO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\37V2W6J0.DEFAULT\EXTENSIONS\{40A1F5D7-AFC2-498F-B264-02668D616FF6}.XPI
[2011/11/09 15:37:31 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/10/04 10:17:50 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 02:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old
[2011/11/09 15:37:31 | 000,002,040 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/05/01 23:24:09 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk = C:\Documents and Settings\Primo\Application Data\Leadertech\PowerRegister\Seagate na02sx8d Product Registration.exe (Leader Technologies/Seagate)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a\X) - C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a\X ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/03 21:00:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\WINDOWS\System32\
[2011/11/28 23:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2011/11/27 22:13:53 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a
[2011/11/17 14:18:56 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2011/11/07 20:13:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Desktop\lcs_win32_4.04.0
[2011/11/03 18:40:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\Akamai
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\WINDOWS\System32\
[2011/11/30 17:14:40 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/30 17:07:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/28 23:13:34 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/27 22:45:46 | 000,001,313 | ---- | M] () -- C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk
[2011/11/22 01:52:48 | 000,000,285 | ---- | M] () -- C:\Documents and Settings\Primo\Desktop\Shortcut to New Volume (D).lnk
[2011/11/21 20:38:09 | 000,108,544 | ---- | M] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 20:52:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/12 13:06:41 | 000,135,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/10 18:04:35 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/11/10 03:02:37 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/07 10:56:28 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/06 12:42:54 | 000,426,932 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/06 12:42:54 | 000,065,776 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/10 18:04:33 | 000,000,268 | ---- | C] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/05/11 22:34:31 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2011/05/02 01:21:08 | 000,025,380 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/04/02 16:14:58 | 000,108,544 | ---- | C] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/02 19:05:32 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/02/02 19:05:32 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/02/01 18:54:17 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/04/25 02:25:10 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/22 13:15:47 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010/04/21 22:18:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/15 07:56:42 | 000,087,540 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/04/04 12:58:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/04/03 21:03:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/04/03 20:57:28 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/04/03 20:42:01 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/04/03 20:42:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/04/03 20:42:00 | 000,426,932 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/04/03 20:42:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/04/03 20:42:00 | 000,065,776 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/04/03 20:42:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/04/03 20:42:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/04/03 20:41:59 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/04/03 20:41:59 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/04/03 20:41:59 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/04/03 20:41:51 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/04/03 20:41:50 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/04/03 13:51:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/04/03 13:50:44 | 000,135,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/06/24 13:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll

========== Custom Scans ==========



< MD5 for: AFD.SYS >
[2011/08/17 07:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\dllcache\afd.sys
[2011/08/17 07:49:54 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=1E44BC1E83D8FD2305F8D452DB109CF9 -- C:\WINDOWS\system32\drivers\afd.sys
[2008/08/21 06:00:00 | 000,138,112 | ---- | M] (Microsoft Corporation) MD5=322D0E36693D6E24A2398BEE62A268CD -- C:\WINDOWS\$NtUninstallKB951748$\afd.sys
[2011/02/16 07:22:48 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=355556D9E580915118CD7EF736653A89 -- C:\WINDOWS\$NtUninstallKB2592799$\afd.sys
[2008/10/16 09:07:58 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=38D7B715504DA4741DF35E3594FE2099 -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys
[2008/08/14 04:34:26 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=4D43E74F2A1239D53929B82600F1971C -- C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys
[2008/10/16 08:43:01 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7618D5218F2A614672EC61A80D854A37 -- C:\WINDOWS\$NtUninstallKB2503665$\afd.sys
[2008/08/14 04:04:36 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=7E775010EF291DA96AD17CA4B17137D7 -- C:\WINDOWS\$NtUninstallKB2509553$\afd.sys
[2011/02/16 07:25:05 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=8D499B1276012EB907E7A9E0F4D8FDA4 -- C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys
[2008/06/20 05:48:03 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=D6EE6014241D034E63C49A50CB2B442A -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
[2008/06/20 05:40:08 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=E3049B90FE06F3F740B7CFDA44995E2C -- C:\WINDOWS\$NtUninstallKB956803$\afd.sys
[2011/08/17 07:41:46 | 000,138,496 | ---- | M] (Microsoft Corporation) MD5=F6B7B1ECD7B41736BDB6FF4B092BCB79 -- C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

OTL did not automatically reboot the PC when it finished.

Which afd.sys file should I use and where exactly should I put it? I wouldn't want to screw anything up
  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
Appears that the file is there but the service has been deleted. Took me a little while to fire up an ancient XP box someone gave me to fix and pull off the registry entry.

Copy the text in the code box.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD]
"Type"=dword:00000001
"Start"=dword:00000001
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,\
  00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,66,00,64,00,2e,00,73,00,79,00,\
  73,00,00,00
"DisplayName"="AFD Networking Support Environment"
"Group"="TDI"
"Description"="AFD Networking Support Environment"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
  00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
  00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
  05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
  20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
  00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
  00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Enum]
"0"="Root\\LEGACY_AFD\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001



Start, Run, notepad, OK

Ctrl + v or Edit, Paste to paste the text into notepad. File, Save As, to your desktop, "afd.reg" OK. Make sure you type the quotation marks or it will tack on .txt which we don't want.

Close notepad.

On your desktop should be a file called afd.reg. Right click on it and MERGE.

Once it has merged, reboot and see if it is still complaining about afd not running.
  • 0

#7
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
It worked! Thanks! Writing to you from my own computer now. What's next?
  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
Combofix, tdsskiller and aswmbr
  • 0

#9
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
Combofix log:

ComboFix 11-12-01.03 - Primo 12/01/2011 18:51:19.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.716 [GMT -6:00]
Running from: c:\documents and settings\Primo\Desktop\malware stuff\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\searchplugins\bing-zugo.xml
c:\documents and settings\Primo\Application Data\Sun\ddee.dat
c:\documents and settings\Primo\Application Data\Sun\mnj.dat
c:\documents and settings\Primo\Application Data\Sun\ppkk.dat
c:\documents and settings\Primo\Application Data\Sun\uuoo.dat
c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a\U
c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a\U\[email protected]
c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a\U\[email protected]
c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a\U\[email protected]
c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a\X
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\windows\$NtUninstallKB57097$
c:\windows\$NtUninstallKB57097$\2488584639
c:\windows\$NtUninstallKB57097$\3818701674\@
c:\windows\$NtUninstallKB57097$\3818701674\L\mpfafmar
c:\windows\$NtUninstallKB57097$\3818701674\loader.tlb
c:\windows\$NtUninstallKB57097$\3818701674\U\@00000001
c:\windows\$NtUninstallKB57097$\3818701674\U\@000000c0
c:\windows\$NtUninstallKB57097$\3818701674\U\@000000cb
c:\windows\$NtUninstallKB57097$\3818701674\U\@000000cf
c:\windows\$NtUninstallKB57097$\3818701674\U\@80000000
c:\windows\$NtUninstallKB57097$\3818701674\U\@800000c0
c:\windows\$NtUninstallKB57097$\3818701674\U\@800000cb
c:\windows\$NtUninstallKB57097$\3818701674\U\@800000cf
c:\windows\CSC\d6
c:\windows\system32\
c:\windows\system32\c_00946.nls
.
.
((((((((((((((((((((((((( Files Created from 2011-11-02 to 2011-12-02 )))))))))))))))))))))))))))))))
.
.
2011-11-29 16:52 . 2011-11-29 16:52 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-11-28 20:37 . 2011-11-28 20:37 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2011-11-28 05:30 . 2011-11-28 05:30 -------- d-s---w- c:\documents and settings\LocalService\UserData
2011-11-28 04:13 . 2011-12-02 01:35 -------- d-sh--w- c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a
2011-11-17 20:18 . 1998-10-29 22:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-11-04 00:40 . 2011-11-05 07:00 -------- d-----w- c:\documents and settings\Primo\Local Settings\Application Data\Akamai
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-20 08:55 . 2011-08-17 15:52 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2006-04-04 02:58 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2006-04-04 02:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2006-04-04 02:42 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2006-04-04 02:42 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-04-04 02:42 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2006-04-04 02:42 667136 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2006-04-04 02:42 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2006-04-04 02:41 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2006-04-04 02:41 369664 ----a-w- c:\windows\system32\html.iec
2011-11-09 21:37 . 2011-10-04 16:18 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-24 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-24 561152]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-03-16 325000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
c:\documents and settings\Primo\Start Menu\Programs\Startup\
Seagate na02sx8d Product Registration.lnk - c:\documents and settings\Primo\Application Data\Leadertech\PowerRegister\Seagate na02sx8d Product Registration.exe [2011-10-4 1731736]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Primo\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\BillP Studios\\WinPatrol\\WinPatrol.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Program Files\\Common Files\\Java\\Java Update\\jucheck.exe"=
"c:\\Program Files\\McAfee Security Scan\\2.0.181\\mcuicnt.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5/4/2011 1:51 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/8/2010 12:16 PM 307928]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [4/3/2006 8:42 PM 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/8/2010 12:16 PM 19544]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/1/2011 7:22 PM 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-11-11 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2011-05-05 02:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
uInternet Settings,ProxyOverride = ;*.local;<local>
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z039&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
user_pref(security.warn_viewing_mixed,false);
user_pref(security.warn_viewing_mixed.show_once,false);
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
user_pref(security.warn_submit_insecure,false);
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
AddRemove-DVD Shrink_is1 - d:\dvd shrink\unins000.exe
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
AddRemove-_{AA902C31-B49D-4608-BCCF-2519EB77722D} - d:\corel videostudio pro x4\Setup\{AA902C31-B49D-4608-BCCF-2519EB77722D}\SetupARP.exe
AddRemove-{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1 - d:\converthelper\unins000.exe
AddRemove-FoxTab Video To MP3 - d:\uninstall\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-01 19:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_d768ebc.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2928)
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-12-01 20:02:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-02 02:01
ComboFix2.txt 2011-05-04 05:55
.
Pre-Run: 7,099,445,248 bytes free
Post-Run: 10,465,894,400 bytes free
.
- - End Of File - - 2878C999758628FC836DD83D722B7A98


TDSSKiller log:

20:40:33.0763 4092 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
20:40:33.0933 4092 ============================================================
20:40:33.0933 4092 Current date / time: 2011/12/01 20:40:33.0933
20:40:33.0933 4092 SystemInfo:
20:40:33.0933 4092
20:40:33.0933 4092 OS Version: 5.1.2600 ServicePack: 3.0
20:40:33.0933 4092 Product type: Workstation
20:40:33.0933 4092 ComputerName: DESERT7210
20:40:33.0933 4092 UserName: Primo
20:40:33.0933 4092 Windows directory: C:\WINDOWS
20:40:33.0933 4092 System windows directory: C:\WINDOWS
20:40:33.0933 4092 Processor architecture: Intel x86
20:40:33.0933 4092 Number of processors: 1
20:40:33.0933 4092 Page size: 0x1000
20:40:33.0933 4092 Boot type: Normal boot
20:40:33.0933 4092 ============================================================
20:40:35.0445 4092 Initialize success
20:40:49.0525 3152 ============================================================
20:40:49.0525 3152 Scan started
20:40:49.0525 3152 Mode: Manual;
20:40:49.0525 3152 ============================================================
20:40:49.0856 3152 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
20:40:49.0866 3152 61883 - ok
20:40:49.0926 3152 Aavmker4 (3f6884eff406238d39aaa892218f1df7) C:\WINDOWS\system32\drivers\Aavmker4.sys
20:40:49.0926 3152 Aavmker4 - ok
20:40:49.0946 3152 Abiosdsk - ok
20:40:49.0966 3152 abp480n5 - ok
20:40:50.0006 3152 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:40:50.0006 3152 ACPI - ok
20:40:50.0026 3152 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
20:40:50.0026 3152 ACPIEC - ok
20:40:50.0046 3152 adpu160m - ok
20:40:50.0096 3152 aeaudio (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
20:40:50.0106 3152 aeaudio - ok
20:40:50.0156 3152 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:40:50.0156 3152 aec - ok
20:40:50.0216 3152 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
20:40:50.0216 3152 AFD - ok
20:40:50.0236 3152 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
20:40:50.0236 3152 agp440 - ok
20:40:50.0256 3152 Aha154x - ok
20:40:50.0287 3152 aic78u2 - ok
20:40:50.0307 3152 aic78xx - ok
20:40:50.0337 3152 AliIde - ok
20:40:50.0357 3152 amsint - ok
20:40:50.0417 3152 AR5211 (655d16ae3156986eba366a50dc2696d3) C:\WINDOWS\system32\DRIVERS\ar5211.sys
20:40:50.0427 3152 AR5211 - ok
20:40:50.0527 3152 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
20:40:50.0527 3152 Arp1394 - ok
20:40:50.0547 3152 asc - ok
20:40:50.0567 3152 asc3350p - ok
20:40:50.0587 3152 asc3550 - ok
20:40:50.0627 3152 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:40:50.0627 3152 aswFsBlk - ok
20:40:50.0657 3152 aswMon2 (c2181ef6b54752273a0759a968c59279) C:\WINDOWS\system32\drivers\aswMon2.sys
20:40:50.0667 3152 aswMon2 - ok
20:40:50.0707 3152 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINDOWS\system32\drivers\aswRdr.sys
20:40:50.0707 3152 aswRdr - ok
20:40:50.0777 3152 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\WINDOWS\system32\drivers\aswSnx.sys
20:40:50.0797 3152 aswSnx - ok
20:40:50.0827 3152 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\WINDOWS\system32\drivers\aswSP.sys
20:40:50.0837 3152 aswSP - ok
20:40:50.0877 3152 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\WINDOWS\system32\drivers\aswTdi.sys
20:40:50.0877 3152 aswTdi - ok
20:40:50.0957 3152 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:40:50.0967 3152 AsyncMac - ok
20:40:50.0988 3152 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:40:50.0988 3152 atapi - ok
20:40:51.0008 3152 Atdisk - ok
20:40:51.0098 3152 ati2mtag (5719f857136ee618f6ec7a5ccd9fb7ab) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:40:51.0128 3152 ati2mtag - ok
20:40:51.0258 3152 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:40:51.0258 3152 Atmarpc - ok
20:40:51.0298 3152 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:40:51.0298 3152 audstub - ok
20:40:51.0358 3152 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
20:40:51.0358 3152 Avc - ok
20:40:51.0408 3152 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:40:51.0408 3152 Beep - ok
20:40:51.0438 3152 catchme - ok
20:40:51.0458 3152 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:40:51.0458 3152 cbidf2k - ok
20:40:51.0508 3152 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
20:40:51.0508 3152 CCDECODE - ok
20:40:51.0528 3152 cd20xrnt - ok
20:40:51.0588 3152 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:40:51.0588 3152 Cdaudio - ok
20:40:51.0638 3152 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:40:51.0638 3152 Cdfs - ok
20:40:51.0679 3152 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:40:51.0679 3152 Cdrom - ok
20:40:51.0699 3152 Changer - ok
20:40:51.0769 3152 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
20:40:51.0769 3152 CmBatt - ok
20:40:51.0879 3152 CmdIde - ok
20:40:51.0899 3152 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
20:40:51.0899 3152 Compbatt - ok
20:40:51.0939 3152 Cpqarray - ok
20:40:51.0959 3152 dac2w2k - ok
20:40:51.0979 3152 dac960nt - ok
20:40:52.0009 3152 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:40:52.0009 3152 Disk - ok
20:40:52.0089 3152 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
20:40:52.0109 3152 dmboot - ok
20:40:52.0139 3152 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
20:40:52.0139 3152 dmio - ok
20:40:52.0179 3152 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:40:52.0179 3152 dmload - ok
20:40:52.0209 3152 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:40:52.0209 3152 DMusic - ok
20:40:52.0239 3152 dpti2o - ok
20:40:52.0269 3152 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:40:52.0269 3152 drmkaud - ok
20:40:52.0319 3152 E1000 (4de4bae4accb5a49fa85801d4f226355) C:\WINDOWS\system32\DRIVERS\e1000325.sys
20:40:52.0319 3152 E1000 - ok
20:40:52.0400 3152 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:40:52.0400 3152 Fastfat - ok
20:40:52.0460 3152 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
20:40:52.0460 3152 Fdc - ok
20:40:52.0580 3152 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
20:40:52.0590 3152 Fips - ok
20:40:52.0610 3152 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
20:40:52.0610 3152 Flpydisk - ok
20:40:52.0650 3152 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
20:40:52.0650 3152 FltMgr - ok
20:40:52.0670 3152 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:40:52.0670 3152 Fs_Rec - ok
20:40:52.0710 3152 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:40:52.0710 3152 Ftdisk - ok
20:40:52.0760 3152 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
20:40:52.0760 3152 GEARAspiWDM - ok
20:40:52.0780 3152 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:40:52.0790 3152 Gpc - ok
20:40:52.0860 3152 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:40:52.0860 3152 HidUsb - ok
20:40:52.0880 3152 hpn - ok
20:40:52.0920 3152 HSFHWICH (e7bcc7ec37dd2dd36a39bb9ac87a897b) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
20:40:52.0920 3152 HSFHWICH - ok
20:40:52.0990 3152 HSF_DPV (822c60f2abee73a0e089230d94064f39) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
20:40:53.0010 3152 HSF_DPV - ok
20:40:53.0161 3152 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:40:53.0171 3152 HTTP - ok
20:40:53.0191 3152 i2omgmt - ok
20:40:53.0211 3152 i2omp - ok
20:40:53.0261 3152 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:40:53.0271 3152 i8042prt - ok
20:40:53.0301 3152 IBMPMDRV (bf648877413f6160e480814a24942b65) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
20:40:53.0301 3152 IBMPMDRV - ok
20:40:53.0331 3152 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:40:53.0341 3152 Imapi - ok
20:40:53.0361 3152 ini910u - ok
20:40:53.0401 3152 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
20:40:53.0401 3152 IntelIde - ok
20:40:53.0431 3152 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:40:53.0441 3152 intelppm - ok
20:40:53.0471 3152 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
20:40:53.0471 3152 Ip6Fw - ok
20:40:53.0491 3152 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:40:53.0491 3152 IpFilterDriver - ok
20:40:53.0531 3152 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:40:53.0531 3152 IpInIp - ok
20:40:53.0551 3152 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:40:53.0561 3152 IpNat - ok
20:40:53.0581 3152 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:40:53.0591 3152 IPSec - ok
20:40:53.0621 3152 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
20:40:53.0621 3152 irda - ok
20:40:53.0641 3152 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:40:53.0641 3152 IRENUM - ok
20:40:53.0671 3152 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:40:53.0671 3152 isapnp - ok
20:40:53.0701 3152 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:40:53.0701 3152 Kbdclass - ok
20:40:53.0741 3152 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:40:53.0741 3152 kmixer - ok
20:40:53.0762 3152 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:40:53.0772 3152 KSecDD - ok
20:40:53.0802 3152 lbrtfdc - ok
20:40:53.0852 3152 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
20:40:53.0852 3152 mdmxsdk - ok
20:40:53.0902 3152 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:40:53.0902 3152 mnmdd - ok
20:40:54.0002 3152 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
20:40:54.0002 3152 Modem - ok
20:40:54.0032 3152 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:40:54.0032 3152 Mouclass - ok
20:40:54.0072 3152 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:40:54.0082 3152 mouhid - ok
20:40:54.0112 3152 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:40:54.0112 3152 MountMgr - ok
20:40:54.0132 3152 mraid35x - ok
20:40:54.0172 3152 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:40:54.0182 3152 MRxDAV - ok
20:40:54.0252 3152 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:40:54.0262 3152 MRxSmb - ok
20:40:54.0322 3152 MSDV (8575d788395c4d6378d98d1ed7cdadb9) C:\WINDOWS\system32\DRIVERS\msdv.sys
20:40:54.0322 3152 MSDV - ok
20:40:54.0342 3152 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:40:54.0342 3152 Msfs - ok
20:40:54.0382 3152 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:40:54.0392 3152 MSKSSRV - ok
20:40:54.0412 3152 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:40:54.0412 3152 MSPCLOCK - ok
20:40:54.0442 3152 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:40:54.0442 3152 MSPQM - ok
20:40:54.0563 3152 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:40:54.0563 3152 mssmbios - ok
20:40:54.0583 3152 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\system32\drivers\MSTEE.sys
20:40:54.0583 3152 MSTEE - ok
20:40:54.0623 3152 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:40:54.0623 3152 Mup - ok
20:40:54.0663 3152 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
20:40:54.0663 3152 NABTSFEC - ok
20:40:54.0723 3152 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:40:54.0723 3152 NDIS - ok
20:40:54.0753 3152 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
20:40:54.0753 3152 NdisIP - ok
20:40:54.0823 3152 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:40:54.0823 3152 NdisTapi - ok
20:40:54.0853 3152 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:40:54.0853 3152 Ndisuio - ok
20:40:54.0883 3152 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:40:54.0893 3152 NdisWan - ok
20:40:54.0933 3152 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:40:54.0933 3152 NDProxy - ok
20:40:54.0973 3152 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:40:54.0973 3152 NetBIOS - ok
20:40:55.0003 3152 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:40:55.0013 3152 NetBT - ok
20:40:55.0154 3152 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
20:40:55.0154 3152 NIC1394 - ok
20:40:55.0184 3152 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:40:55.0184 3152 Npfs - ok
20:40:55.0204 3152 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
20:40:55.0204 3152 NSCIRDA - ok
20:40:55.0284 3152 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:40:55.0284 3152 Ntfs - ok
20:40:55.0354 3152 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:40:55.0364 3152 Null - ok
20:40:55.0414 3152 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:40:55.0414 3152 NwlnkFlt - ok
20:40:55.0444 3152 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:40:55.0444 3152 NwlnkFwd - ok
20:40:55.0484 3152 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
20:40:55.0484 3152 ohci1394 - ok
20:40:55.0524 3152 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
20:40:55.0524 3152 Parport - ok
20:40:55.0544 3152 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:40:55.0544 3152 PartMgr - ok
20:40:55.0584 3152 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
20:40:55.0584 3152 ParVdm - ok
20:40:55.0664 3152 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
20:40:55.0664 3152 PCI - ok
20:40:55.0684 3152 PCIDump - ok
20:40:55.0704 3152 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:40:55.0704 3152 PCIIde - ok
20:40:55.0734 3152 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
20:40:55.0734 3152 Pcmcia - ok
20:40:55.0754 3152 PDCOMP - ok
20:40:55.0774 3152 PDFRAME - ok
20:40:55.0794 3152 PDRELI - ok
20:40:55.0814 3152 PDRFRAME - ok
20:40:55.0834 3152 perc2 - ok
20:40:55.0855 3152 perc2hib - ok
20:40:55.0925 3152 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:40:55.0925 3152 PptpMiniport - ok
20:40:55.0965 3152 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:40:55.0965 3152 Ptilink - ok
20:40:55.0985 3152 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:40:55.0985 3152 PxHelp20 - ok
20:40:56.0005 3152 ql1080 - ok
20:40:56.0025 3152 Ql10wnt - ok
20:40:56.0045 3152 ql12160 - ok
20:40:56.0065 3152 ql1240 - ok
20:40:56.0085 3152 ql1280 - ok
20:40:56.0105 3152 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:40:56.0115 3152 RasAcd - ok
20:40:56.0155 3152 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
20:40:56.0165 3152 Rasirda - ok
20:40:56.0185 3152 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:40:56.0185 3152 Rasl2tp - ok
20:40:56.0205 3152 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:40:56.0215 3152 RasPppoe - ok
20:40:56.0235 3152 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:40:56.0235 3152 Raspti - ok
20:40:56.0275 3152 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:40:56.0275 3152 Rdbss - ok
20:40:56.0295 3152 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:40:56.0295 3152 RDPCDD - ok
20:40:56.0335 3152 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:40:56.0345 3152 rdpdr - ok
20:40:56.0415 3152 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:40:56.0415 3152 RDPWD - ok
20:40:56.0455 3152 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:40:56.0455 3152 redbook - ok
20:40:56.0525 3152 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:40:56.0536 3152 Secdrv - ok
20:40:56.0566 3152 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:40:56.0566 3152 serenum - ok
20:40:56.0596 3152 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:40:56.0606 3152 Serial - ok
20:40:56.0636 3152 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:40:56.0636 3152 Sfloppy - ok
20:40:56.0666 3152 Simbad - ok
20:40:56.0706 3152 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\system32\DRIVERS\SLIP.sys
20:40:56.0716 3152 SLIP - ok
20:40:56.0756 3152 smwdm (1319ea66a96250d59665d133c0ff7cd0) C:\WINDOWS\system32\drivers\smwdm.sys
20:40:56.0756 3152 smwdm - ok
20:40:56.0826 3152 Sparrow - ok
20:40:56.0886 3152 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:40:56.0886 3152 splitter - ok
20:40:56.0926 3152 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:40:56.0926 3152 sr - ok
20:40:56.0996 3152 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:40:57.0006 3152 Srv - ok
20:40:57.0046 3152 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
20:40:57.0046 3152 streamip - ok
20:40:57.0086 3152 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:40:57.0086 3152 swenum - ok
20:40:57.0126 3152 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:40:57.0126 3152 swmidi - ok
20:40:57.0146 3152 symc810 - ok
20:40:57.0176 3152 symc8xx - ok
20:40:57.0196 3152 sym_hi - ok
20:40:57.0206 3152 sym_u3 - ok
20:40:57.0267 3152 SynTP (1cde0a5c0416187b9b89e03980c6e8de) C:\WINDOWS\system32\DRIVERS\SynTP.sys
20:40:57.0277 3152 SynTP - ok
20:40:57.0307 3152 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:40:57.0307 3152 sysaudio - ok
20:40:57.0377 3152 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:40:57.0387 3152 Tcpip - ok
20:40:57.0527 3152 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:40:57.0537 3152 TDPIPE - ok
20:40:57.0567 3152 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:40:57.0567 3152 TDTCP - ok
20:40:57.0597 3152 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:40:57.0597 3152 TermDD - ok
20:40:57.0637 3152 TosIde - ok
20:40:57.0667 3152 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:40:57.0667 3152 Udfs - ok
20:40:57.0687 3152 ultra - ok
20:40:57.0717 3152 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:40:57.0727 3152 Update - ok
20:40:57.0797 3152 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:40:57.0807 3152 usbccgp - ok
20:40:57.0857 3152 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:40:57.0857 3152 usbehci - ok
20:40:57.0897 3152 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:40:57.0897 3152 usbhub - ok
20:40:57.0948 3152 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:40:57.0958 3152 usbscan - ok
20:40:57.0988 3152 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:40:57.0988 3152 USBSTOR - ok
20:40:58.0068 3152 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:40:58.0068 3152 usbuhci - ok
20:40:58.0098 3152 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
20:40:58.0108 3152 usbvideo - ok
20:40:58.0158 3152 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:40:58.0158 3152 VgaSave - ok
20:40:58.0178 3152 ViaIde - ok
20:40:58.0198 3152 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:40:58.0208 3152 VolSnap - ok
20:40:58.0268 3152 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:40:58.0268 3152 Wanarp - ok
20:40:58.0288 3152 WDICA - ok
20:40:58.0318 3152 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:40:58.0328 3152 wdmaud - ok
20:40:58.0388 3152 winachsf (5ea185425bfcbc2d4b96d673d8c4deaf) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
20:40:58.0408 3152 winachsf - ok
20:40:58.0478 3152 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:40:58.0478 3152 WS2IFSL - ok
20:40:58.0538 3152 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
20:40:58.0538 3152 WSTCODEC - ok
20:40:58.0608 3152 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:40:58.0608 3152 WudfPf - ok
20:40:58.0719 3152 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:40:58.0719 3152 WudfRd - ok
20:40:58.0779 3152 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
20:40:58.0889 3152 \Device\Harddisk0\DR0 - ok
20:40:58.0899 3152 Boot (0x1200) (56e353e98760abb6f9b14dc6328920c0) \Device\Harddisk0\DR0\Partition0
20:40:58.0899 3152 \Device\Harddisk0\DR0\Partition0 - ok
20:40:58.0919 3152 Boot (0x1200) (569b07d10353f6748efdecd04354232d) \Device\Harddisk0\DR0\Partition1
20:40:58.0929 3152 \Device\Harddisk0\DR0\Partition1 - ok
20:40:58.0929 3152 ============================================================
20:40:58.0929 3152 Scan finished
20:40:58.0929 3152 ============================================================
20:40:58.0949 2160 Detected object count: 0
20:40:58.0949 2160 Actual detected object count: 0
20:41:10.0295 3388 ============================================================
20:41:10.0295 3388 Scan started
20:41:10.0295 3388 Mode: Manual;
20:41:10.0295 3388 ============================================================
20:41:10.0486 3388 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
20:41:10.0486 3388 61883 - ok
20:41:10.0536 3388 Aavmker4 (3f6884eff406238d39aaa892218f1df7) C:\WINDOWS\system32\drivers\Aavmker4.sys
20:41:10.0536 3388 Aavmker4 - ok
20:41:10.0566 3388 Abiosdsk - ok
20:41:10.0586 3388 abp480n5 - ok
20:41:10.0616 3388 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:41:10.0616 3388 ACPI - ok
20:41:10.0636 3388 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
20:41:10.0636 3388 ACPIEC - ok
20:41:10.0656 3388 adpu160m - ok
20:41:10.0716 3388 aeaudio (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
20:41:10.0716 3388 aeaudio - ok
20:41:10.0766 3388 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:41:10.0766 3388 aec - ok
20:41:10.0876 3388 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
20:41:10.0876 3388 AFD - ok
20:41:10.0896 3388 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
20:41:10.0896 3388 agp440 - ok
20:41:10.0916 3388 Aha154x - ok
20:41:10.0936 3388 aic78u2 - ok
20:41:10.0956 3388 aic78xx - ok
20:41:10.0996 3388 AliIde - ok
20:41:11.0016 3388 amsint - ok
20:41:11.0076 3388 AR5211 (655d16ae3156986eba366a50dc2696d3) C:\WINDOWS\system32\DRIVERS\ar5211.sys
20:41:11.0076 3388 AR5211 - ok
20:41:11.0126 3388 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
20:41:11.0126 3388 Arp1394 - ok
20:41:11.0147 3388 asc - ok
20:41:11.0167 3388 asc3350p - ok
20:41:11.0187 3388 asc3550 - ok
20:41:11.0227 3388 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:41:11.0227 3388 aswFsBlk - ok
20:41:11.0267 3388 aswMon2 (c2181ef6b54752273a0759a968c59279) C:\WINDOWS\system32\drivers\aswMon2.sys
20:41:11.0267 3388 aswMon2 - ok
20:41:11.0297 3388 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINDOWS\system32\drivers\aswRdr.sys
20:41:11.0297 3388 aswRdr - ok
20:41:11.0367 3388 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\WINDOWS\system32\drivers\aswSnx.sys
20:41:11.0377 3388 aswSnx - ok
20:41:11.0407 3388 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\WINDOWS\system32\drivers\aswSP.sys
20:41:11.0417 3388 aswSP - ok
20:41:11.0457 3388 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\WINDOWS\system32\drivers\aswTdi.sys
20:41:11.0457 3388 aswTdi - ok
20:41:11.0517 3388 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:41:11.0517 3388 AsyncMac - ok
20:41:11.0597 3388 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:41:11.0597 3388 atapi - ok
20:41:11.0617 3388 Atdisk - ok
20:41:11.0717 3388 ati2mtag (5719f857136ee618f6ec7a5ccd9fb7ab) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
20:41:11.0727 3388 ati2mtag - ok
20:41:11.0767 3388 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:41:11.0767 3388 Atmarpc - ok
20:41:11.0807 3388 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:41:11.0817 3388 audstub - ok
20:41:11.0868 3388 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
20:41:11.0868 3388 Avc - ok
20:41:11.0948 3388 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:41:11.0948 3388 Beep - ok
20:41:11.0968 3388 catchme - ok
20:41:11.0998 3388 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:41:11.0998 3388 cbidf2k - ok
20:41:12.0098 3388 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
20:41:12.0098 3388 CCDECODE - ok
20:41:12.0118 3388 cd20xrnt - ok
20:41:12.0168 3388 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:41:12.0168 3388 Cdaudio - ok
20:41:12.0218 3388 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:41:12.0218 3388 Cdfs - ok
20:41:12.0278 3388 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:41:12.0278 3388 Cdrom - ok
20:41:12.0308 3388 Changer - ok
20:41:12.0378 3388 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
20:41:12.0378 3388 CmBatt - ok
20:41:12.0398 3388 CmdIde - ok
20:41:12.0418 3388 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
20:41:12.0418 3388 Compbatt - ok
20:41:12.0458 3388 Cpqarray - ok
20:41:12.0478 3388 dac2w2k - ok
20:41:12.0498 3388 dac960nt - ok
20:41:12.0528 3388 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:41:12.0528 3388 Disk - ok
20:41:12.0609 3388 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
20:41:12.0619 3388 dmboot - ok
20:41:12.0699 3388 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
20:41:12.0699 3388 dmio - ok
20:41:12.0719 3388 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:41:12.0729 3388 dmload - ok
20:41:12.0759 3388 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:41:12.0759 3388 DMusic - ok
20:41:12.0789 3388 dpti2o - ok
20:41:12.0829 3388 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:41:12.0829 3388 drmkaud - ok
20:41:12.0889 3388 E1000 (4de4bae4accb5a49fa85801d4f226355) C:\WINDOWS\system32\DRIVERS\e1000325.sys
20:41:12.0889 3388 E1000 - ok
20:41:12.0949 3388 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:41:12.0949 3388 Fastfat - ok
20:41:12.0979 3388 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
20:41:12.0979 3388 Fdc - ok
20:41:13.0029 3388 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
20:41:13.0029 3388 Fips - ok
20:41:13.0069 3388 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
20:41:13.0069 3388 Flpydisk - ok
20:41:13.0099 3388 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
20:41:13.0109 3388 FltMgr - ok
20:41:13.0129 3388 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:41:13.0129 3388 Fs_Rec - ok
20:41:13.0189 3388 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:41:13.0189 3388 Ftdisk - ok
20:41:13.0290 3388 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
20:41:13.0290 3388 GEARAspiWDM - ok
20:41:13.0310 3388 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:41:13.0310 3388 Gpc - ok
20:41:13.0380 3388 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:41:13.0380 3388 HidUsb - ok
20:41:13.0400 3388 hpn - ok
20:41:13.0460 3388 HSFHWICH (e7bcc7ec37dd2dd36a39bb9ac87a897b) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
20:41:13.0470 3388 HSFHWICH - ok
20:41:13.0540 3388 HSF_DPV (822c60f2abee73a0e089230d94064f39) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
20:41:13.0550 3388 HSF_DPV - ok
20:41:13.0620 3388 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:41:13.0620 3388 HTTP - ok
20:41:13.0650 3388 i2omgmt - ok
20:41:13.0670 3388 i2omp - ok
20:41:13.0720 3388 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:41:13.0720 3388 i8042prt - ok
20:41:13.0800 3388 IBMPMDRV (bf648877413f6160e480814a24942b65) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
20:41:13.0810 3388 IBMPMDRV - ok
20:41:13.0850 3388 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:41:13.0850 3388 Imapi - ok
20:41:13.0880 3388 ini910u - ok
20:41:13.0951 3388 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
20:41:13.0951 3388 IntelIde - ok
20:41:13.0971 3388 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:41:13.0971 3388 intelppm - ok
20:41:14.0011 3388 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
20:41:14.0011 3388 Ip6Fw - ok
20:41:14.0031 3388 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:41:14.0031 3388 IpFilterDriver - ok
20:41:14.0061 3388 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:41:14.0061 3388 IpInIp - ok
20:41:14.0101 3388 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:41:14.0101 3388 IpNat - ok
20:41:14.0131 3388 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:41:14.0131 3388 IPSec - ok
20:41:14.0161 3388 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
20:41:14.0171 3388 irda - ok
20:41:14.0191 3388 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:41:14.0191 3388 IRENUM - ok
20:41:14.0221 3388 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:41:14.0221 3388 isapnp - ok
20:41:14.0261 3388 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:41:14.0261 3388 Kbdclass - ok
20:41:14.0321 3388 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:41:14.0321 3388 kmixer - ok
20:41:14.0341 3388 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:41:14.0341 3388 KSecDD - ok
20:41:14.0371 3388 lbrtfdc - ok
20:41:14.0421 3388 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
20:41:14.0421 3388 mdmxsdk - ok
20:41:14.0461 3388 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:41:14.0461 3388 mnmdd - ok
20:41:14.0501 3388 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
20:41:14.0501 3388 Modem - ok
20:41:14.0581 3388 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:41:14.0591 3388 Mouclass - ok
20:41:14.0632 3388 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:41:14.0632 3388 mouhid - ok
20:41:14.0662 3388 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:41:14.0662 3388 MountMgr - ok
20:41:14.0682 3388 mraid35x - ok
20:41:14.0722 3388 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:41:14.0722 3388 MRxDAV - ok
20:41:14.0792 3388 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:41:14.0802 3388 MRxSmb - ok
20:41:14.0882 3388 MSDV (8575d788395c4d6378d98d1ed7cdadb9) C:\WINDOWS\system32\DRIVERS\msdv.sys
20:41:14.0892 3388 MSDV - ok
20:41:14.0912 3388 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:41:14.0912 3388 Msfs - ok
20:41:14.0942 3388 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:41:14.0942 3388 MSKSSRV - ok
20:41:14.0962 3388 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:41:14.0962 3388 MSPCLOCK - ok
20:41:15.0002 3388 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:41:15.0002 3388 MSPQM - ok
20:41:15.0092 3388 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:41:15.0102 3388 mssmbios - ok
20:41:15.0132 3388 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\system32\drivers\MSTEE.sys
20:41:15.0132 3388 MSTEE - ok
20:41:15.0162 3388 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:41:15.0172 3388 Mup - ok
20:41:15.0212 3388 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
20:41:15.0212 3388 NABTSFEC - ok
20:41:15.0262 3388 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:41:15.0272 3388 NDIS - ok
20:41:15.0302 3388 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
20:41:15.0302 3388 NdisIP - ok
20:41:15.0353 3388 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:41:15.0353 3388 NdisTapi - ok
20:41:15.0393 3388 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:41:15.0393 3388 Ndisuio - ok
20:41:15.0453 3388 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:41:15.0453 3388 NdisWan - ok
20:41:15.0503 3388 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:41:15.0503 3388 NDProxy - ok
20:41:15.0543 3388 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:41:15.0543 3388 NetBIOS - ok
20:41:15.0633 3388 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:41:15.0633 3388 NetBT - ok
20:41:15.0713 3388 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
20:41:15.0713 3388 NIC1394 - ok
20:41:15.0743 3388 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:41:15.0743 3388 Npfs - ok
20:41:15.0763 3388 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
20:41:15.0763 3388 NSCIRDA - ok
20:41:15.0823 3388 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:41:15.0833 3388 Ntfs - ok
20:41:15.0893 3388 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:41:15.0893 3388 Null - ok
20:41:15.0933 3388 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:41:15.0933 3388 NwlnkFlt - ok
20:41:16.0003 3388 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:41:16.0003 3388 NwlnkFwd - ok
20:41:16.0044 3388 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
20:41:16.0044 3388 ohci1394 - ok
20:41:16.0094 3388 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
20:41:16.0094 3388 Parport - ok
20:41:16.0164 3388 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:41:16.0164 3388 PartMgr - ok
20:41:16.0194 3388 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
20:41:16.0204 3388 ParVdm - ok
20:41:16.0224 3388 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
20:41:16.0224 3388 PCI - ok
20:41:16.0244 3388 PCIDump - ok
20:41:16.0264 3388 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:41:16.0264 3388 PCIIde - ok
20:41:16.0284 3388 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
20:41:16.0284 3388 Pcmcia - ok
20:41:16.0304 3388 PDCOMP - ok
20:41:16.0324 3388 PDFRAME - ok
20:41:16.0344 3388 PDRELI - ok
20:41:16.0364 3388 PDRFRAME - ok
20:41:16.0384 3388 perc2 - ok
20:41:16.0404 3388 perc2hib - ok
20:41:16.0464 3388 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:41:16.0464 3388 PptpMiniport - ok
20:41:16.0494 3388 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:41:16.0494 3388 Ptilink - ok
20:41:16.0514 3388 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:41:16.0524 3388 PxHelp20 - ok
20:41:16.0544 3388 ql1080 - ok
20:41:16.0554 3388 Ql10wnt - ok
20:41:16.0584 3388 ql12160 - ok
20:41:16.0604 3388 ql1240 - ok
20:41:16.0624 3388 ql1280 - ok
20:41:16.0644 3388 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:41:16.0644 3388 RasAcd - ok
20:41:16.0694 3388 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
20:41:16.0694 3388 Rasirda - ok
20:41:16.0715 3388 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:41:16.0725 3388 Rasl2tp - ok
20:41:16.0745 3388 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:41:16.0745 3388 RasPppoe - ok
20:41:16.0765 3388 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:41:16.0775 3388 Raspti - ok
20:41:16.0805 3388 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:41:16.0805 3388 Rdbss - ok
20:41:16.0835 3388 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:41:16.0835 3388 RDPCDD - ok
20:41:16.0875 3388 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:41:16.0875 3388 rdpdr - ok
20:41:16.0955 3388 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:41:16.0965 3388 RDPWD - ok
20:41:17.0015 3388 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:41:17.0015 3388 redbook - ok
20:41:17.0105 3388 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:41:17.0105 3388 Secdrv - ok
20:41:17.0135 3388 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:41:17.0145 3388 serenum - ok
20:41:17.0175 3388 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:41:17.0175 3388 Serial - ok
20:41:17.0215 3388 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:41:17.0215 3388 Sfloppy - ok
20:41:17.0245 3388 Simbad - ok
20:41:17.0285 3388 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\system32\DRIVERS\SLIP.sys
20:41:17.0295 3388 SLIP - ok
20:41:17.0395 3388 smwdm (1319ea66a96250d59665d133c0ff7cd0) C:\WINDOWS\system32\drivers\smwdm.sys
20:41:17.0406 3388 smwdm - ok
20:41:17.0416 3388 Sparrow - ok
20:41:17.0476 3388 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:41:17.0476 3388 splitter - ok
20:41:17.0506 3388 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:41:17.0506 3388 sr - ok
20:41:17.0576 3388 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:41:17.0586 3388 Srv - ok
20:41:17.0626 3388 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
20:41:17.0626 3388 streamip - ok
20:41:17.0646 3388 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:41:17.0656 3388 swenum - ok
20:41:17.0676 3388 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:41:17.0686 3388 swmidi - ok
20:41:17.0706 3388 symc810 - ok
20:41:17.0726 3388 symc8xx - ok
20:41:17.0746 3388 sym_hi - ok
20:41:17.0766 3388 sym_u3 - ok
20:41:17.0826 3388 SynTP (1cde0a5c0416187b9b89e03980c6e8de) C:\WINDOWS\system32\DRIVERS\SynTP.sys
20:41:17.0836 3388 SynTP - ok
20:41:17.0886 3388 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:41:17.0886 3388 sysaudio - ok
20:41:17.0966 3388 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:41:17.0976 3388 Tcpip - ok
20:41:18.0066 3388 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:41:18.0066 3388 TDPIPE - ok
20:41:18.0107 3388 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:41:18.0107 3388 TDTCP - ok
20:41:18.0127 3388 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:41:18.0137 3388 TermDD - ok
20:41:18.0167 3388 TosIde - ok
20:41:18.0197 3388 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:41:18.0207 3388 Udfs - ok
20:41:18.0227 3388 ultra - ok
20:41:18.0277 3388 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:41:18.0287 3388 Update - ok
20:41:18.0347 3388 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:41:18.0347 3388 usbccgp - ok
20:41:18.0397 3388 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:41:18.0407 3388 usbehci - ok
20:41:18.0427 3388 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:41:18.0427 3388 usbhub - ok
20:41:18.0477 3388 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:41:18.0477 3388 usbscan - ok
20:41:18.0517 3388 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:41:18.0517 3388 USBSTOR - ok
20:41:18.0537 3388 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:41:18.0537 3388 usbuhci - ok
20:41:18.0567 3388 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
20:41:18.0577 3388 usbvideo - ok
20:41:18.0607 3388 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:41:18.0617 3388 VgaSave - ok
20:41:18.0677 3388 ViaIde - ok
20:41:18.0717 3388 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:41:18.0717 3388 VolSnap - ok
20:41:18.0777 3388 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:41:18.0777 3388 Wanarp - ok
20:41:18.0798 3388 WDICA - ok
20:41:18.0838 3388 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:41:18.0838 3388 wdmaud - ok
20:41:18.0898 3388 winachsf (5ea185425bfcbc2d4b96d673d8c4deaf) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
20:41:18.0908 3388 winachsf - ok
20:41:18.0998 3388 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:41:18.0998 3388 WS2IFSL - ok
20:41:19.0038 3388 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
20:41:19.0038 3388 WSTCODEC - ok
20:41:19.0118 3388 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:41:19.0128 3388 WudfPf - ok
20:41:19.0148 3388 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:41:19.0158 3388 WudfRd - ok
20:41:19.0218 3388 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
20:41:19.0328 3388 \Device\Harddisk0\DR0 - ok
20:41:19.0338 3388 Boot (0x1200) (56e353e98760abb6f9b14dc6328920c0) \Device\Harddisk0\DR0\Partition0
20:41:19.0338 3388 \Device\Harddisk0\DR0\Partition0 - ok
20:41:19.0358 3388 Boot (0x1200) (569b07d10353f6748efdecd04354232d) \Device\Harddisk0\DR0\Partition1
20:41:19.0358 3388 \Device\Harddisk0\DR0\Partition1 - ok
20:41:19.0358 3388 ============================================================
20:41:19.0358 3388 Scan finished
20:41:19.0358 3388 ============================================================
20:41:19.0378 3228 Detected object count: 0
20:41:19.0378 3228 Actual detected object count: 0
20:41:55.0100 2960 Deinitialize success


aswMBR log, "Fix" button NOT enabled:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-01 20:46:00
-----------------------------
20:46:00.062 OS Version: Windows 5.1.2600 Service Pack 3
20:46:00.062 Number of processors: 1 586 0x905
20:46:00.062 ComputerName: DESERT7210 UserName: Primo
20:46:01.053 Initialize success
20:46:02.145 AVAST engine defs: 11120101
20:46:34.001 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
20:46:34.001 Disk 0 Vendor: HTS548040M9AT00 MG2OA5DA Size: 38154MB BusType: 3
20:46:36.024 Disk 0 MBR read successfully
20:46:36.024 Disk 0 MBR scan
20:46:36.024 Disk 0 Windows XP default MBR code
20:46:36.024 Disk 0 scanning sectors +78125040
20:46:36.104 Disk 0 scanning C:\WINDOWS\system32\drivers
20:46:42.593 Service scanning
20:46:43.605 Modules scanning
20:47:08.070 AVAST engine scan C:\WINDOWS
20:47:20.878 AVAST engine scan C:\WINDOWS\system32
20:48:54.252 AVAST engine scan C:\WINDOWS\system32\drivers
20:49:03.255 AVAST engine scan C:\Documents and Settings\Primo
21:01:12.454 AVAST engine scan C:\Documents and Settings\All Users
21:03:29.451 Scan finished successfully
21:06:49.028 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Primo\Desktop\malware stuff\MBR.dat"
21:06:49.048 The log file has been saved successfully to "C:\Documents and Settings\Primo\Desktop\malware stuff\aswMBR2.txt"
  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
Looking much better. Run TDSSKiller one more time but this time
before you hit the Scan hit Change Parameters and check the two items under Additional Options. OK then Scan.
This mode is a bit prone to False Positives so don't change the default from Skip unless it is obvious that it is TDSS.

Also run Combofix one more time to make sure that the infection is really gone.

Finally

Run OTL
select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.

Ron
  • 0

Advertisements


#11
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
TDSSKiller log:

22:20:13.0641 1264 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
22:20:13.0802 1264 ============================================================
22:20:13.0802 1264 Current date / time: 2011/12/01 22:20:13.0802
22:20:13.0802 1264 SystemInfo:
22:20:13.0802 1264
22:20:13.0802 1264 OS Version: 5.1.2600 ServicePack: 3.0
22:20:13.0802 1264 Product type: Workstation
22:20:13.0802 1264 ComputerName: DESERT7210
22:20:13.0802 1264 UserName: Primo
22:20:13.0802 1264 Windows directory: C:\WINDOWS
22:20:13.0802 1264 System windows directory: C:\WINDOWS
22:20:13.0802 1264 Processor architecture: Intel x86
22:20:13.0802 1264 Number of processors: 1
22:20:13.0802 1264 Page size: 0x1000
22:20:13.0802 1264 Boot type: Normal boot
22:20:13.0802 1264 ============================================================
22:20:15.0454 1264 Initialize success
22:21:11.0745 3372 ============================================================
22:21:11.0745 3372 Scan started
22:21:11.0745 3372 Mode: Manual; SigCheck; TDLFS;
22:21:11.0745 3372 ============================================================
22:21:12.0326 3372 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
22:21:13.0197 3372 61883 - ok
22:21:13.0337 3372 Aavmker4 (3f6884eff406238d39aaa892218f1df7) C:\WINDOWS\system32\drivers\Aavmker4.sys
22:21:28.0479 3372 Aavmker4 - ok
22:21:28.0569 3372 Abiosdsk - ok
22:21:28.0589 3372 abp480n5 - ok
22:21:28.0649 3372 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:21:28.0809 3372 ACPI - ok
22:21:28.0830 3372 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
22:21:29.0000 3372 ACPIEC - ok
22:21:29.0020 3372 adpu160m - ok
22:21:29.0070 3372 aeaudio (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
22:21:29.0100 3372 aeaudio - ok
22:21:29.0140 3372 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:21:29.0320 3372 aec - ok
22:21:29.0380 3372 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
22:21:29.0510 3372 AFD - ok
22:21:29.0651 3372 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
22:21:29.0841 3372 agp440 - ok
22:21:29.0851 3372 Aha154x - ok
22:21:29.0871 3372 aic78u2 - ok
22:21:29.0891 3372 aic78xx - ok
22:21:29.0921 3372 AliIde - ok
22:21:29.0941 3372 amsint - ok
22:21:30.0001 3372 AR5211 (655d16ae3156986eba366a50dc2696d3) C:\WINDOWS\system32\DRIVERS\ar5211.sys
22:21:30.0081 3372 AR5211 - ok
22:21:30.0131 3372 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
22:21:30.0322 3372 Arp1394 - ok
22:21:30.0342 3372 asc - ok
22:21:30.0362 3372 asc3350p - ok
22:21:30.0382 3372 asc3550 - ok
22:21:30.0412 3372 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\WINDOWS\system32\drivers\aswFsBlk.sys
22:21:39.0575 3372 aswFsBlk - ok
22:21:39.0615 3372 aswMon2 (c2181ef6b54752273a0759a968c59279) C:\WINDOWS\system32\drivers\aswMon2.sys
22:21:39.0635 3372 aswMon2 - ok
22:21:39.0725 3372 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\WINDOWS\system32\drivers\aswRdr.sys
22:21:39.0745 3372 aswRdr - ok
22:21:39.0805 3372 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\WINDOWS\system32\drivers\aswSnx.sys
22:21:39.0845 3372 aswSnx - ok
22:21:39.0905 3372 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\WINDOWS\system32\drivers\aswSP.sys
22:21:39.0935 3372 aswSP - ok
22:21:39.0976 3372 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\WINDOWS\system32\drivers\aswTdi.sys
22:21:39.0986 3372 aswTdi - ok
22:21:40.0046 3372 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:21:40.0206 3372 AsyncMac - ok
22:21:40.0326 3372 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:21:40.0496 3372 atapi - ok
22:21:40.0516 3372 Atdisk - ok
22:21:40.0606 3372 ati2mtag (5719f857136ee618f6ec7a5ccd9fb7ab) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
22:21:40.0717 3372 ati2mtag ( UnsignedFile.Multi.Generic ) - warning
22:21:40.0717 3372 ati2mtag - detected UnsignedFile.Multi.Generic (1)
22:21:40.0777 3372 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:21:40.0937 3372 Atmarpc - ok
22:21:41.0057 3372 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:21:41.0217 3372 audstub - ok
22:21:41.0267 3372 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
22:21:41.0448 3372 Avc - ok
22:21:41.0478 3372 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:21:41.0628 3372 Beep - ok
22:21:41.0648 3372 catchme - ok
22:21:41.0678 3372 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:21:41.0858 3372 cbidf2k - ok
22:21:41.0908 3372 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:21:41.0938 3372 CCDECODE - ok
22:21:41.0948 3372 cd20xrnt - ok
22:21:41.0998 3372 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:21:42.0169 3372 Cdaudio - ok
22:21:42.0219 3372 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:21:42.0389 3372 Cdfs - ok
22:21:42.0529 3372 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:21:42.0699 3372 Cdrom - ok
22:21:42.0719 3372 Changer - ok
22:21:42.0780 3372 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
22:21:42.0960 3372 CmBatt - ok
22:21:42.0980 3372 CmdIde - ok
22:21:43.0000 3372 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
22:21:43.0170 3372 Compbatt - ok
22:21:43.0200 3372 Cpqarray - ok
22:21:43.0230 3372 dac2w2k - ok
22:21:43.0250 3372 dac960nt - ok
22:21:43.0280 3372 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:21:43.0441 3372 Disk - ok
22:21:43.0511 3372 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:21:43.0701 3372 dmboot - ok
22:21:43.0751 3372 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:21:43.0951 3372 dmio - ok
22:21:44.0041 3372 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:21:44.0232 3372 dmload - ok
22:21:44.0262 3372 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:21:44.0462 3372 DMusic - ok
22:21:44.0492 3372 dpti2o - ok
22:21:44.0532 3372 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:21:44.0682 3372 drmkaud - ok
22:21:44.0732 3372 E1000 (4de4bae4accb5a49fa85801d4f226355) C:\WINDOWS\system32\DRIVERS\e1000325.sys
22:21:44.0752 3372 E1000 - ok
22:21:44.0802 3372 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:21:44.0973 3372 Fastfat - ok
22:21:45.0023 3372 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
22:21:45.0193 3372 Fdc - ok
22:21:45.0253 3372 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:21:45.0423 3372 Fips - ok
22:21:45.0453 3372 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
22:21:45.0624 3372 Flpydisk - ok
22:21:45.0684 3372 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:21:45.0844 3372 FltMgr - ok
22:21:45.0944 3372 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:21:46.0114 3372 Fs_Rec - ok
22:21:46.0144 3372 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:21:46.0305 3372 Ftdisk - ok
22:21:46.0385 3372 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
22:21:46.0395 3372 GEARAspiWDM - ok
22:21:46.0425 3372 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:21:46.0605 3372 Gpc - ok
22:21:46.0675 3372 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:21:46.0845 3372 HidUsb - ok
22:21:46.0865 3372 hpn - ok
22:21:46.0926 3372 HSFHWICH (e7bcc7ec37dd2dd36a39bb9ac87a897b) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
22:21:46.0956 3372 HSFHWICH - ok
22:21:47.0086 3372 HSF_DPV (822c60f2abee73a0e089230d94064f39) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
22:21:47.0196 3372 HSF_DPV - ok
22:21:47.0256 3372 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
22:21:47.0306 3372 HTTP - ok
22:21:47.0386 3372 i2omgmt - ok
22:21:47.0406 3372 i2omp - ok
22:21:47.0446 3372 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:21:47.0627 3372 i8042prt - ok
22:21:47.0677 3372 IBMPMDRV (bf648877413f6160e480814a24942b65) C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
22:21:47.0687 3372 IBMPMDRV - ok
22:21:47.0717 3372 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:21:47.0897 3372 Imapi - ok
22:21:47.0927 3372 ini910u - ok
22:21:47.0957 3372 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
22:21:48.0117 3372 IntelIde - ok
22:21:48.0127 3372 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:21:48.0287 3372 intelppm - ok
22:21:48.0328 3372 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:21:48.0508 3372 Ip6Fw - ok
22:21:48.0528 3372 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:21:48.0698 3372 IpFilterDriver - ok
22:21:48.0728 3372 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:21:48.0878 3372 IpInIp - ok
22:21:48.0918 3372 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:21:49.0079 3372 IpNat - ok
22:21:49.0109 3372 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:21:49.0269 3372 IPSec - ok
22:21:49.0299 3372 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
22:21:49.0389 3372 irda - ok
22:21:49.0559 3372 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:21:49.0629 3372 IRENUM - ok
22:21:49.0679 3372 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:21:49.0840 3372 isapnp - ok
22:21:49.0870 3372 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:21:50.0030 3372 Kbdclass - ok
22:21:50.0070 3372 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:21:50.0230 3372 kmixer - ok
22:21:50.0250 3372 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
22:21:50.0330 3372 KSecDD - ok
22:21:50.0360 3372 lbrtfdc - ok
22:21:50.0421 3372 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
22:21:50.0431 3372 mdmxsdk - ok
22:21:50.0461 3372 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:21:50.0621 3372 mnmdd - ok
22:21:50.0671 3372 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:21:50.0861 3372 Modem - ok
22:21:50.0891 3372 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:21:51.0031 3372 Mouclass - ok
22:21:51.0082 3372 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:21:51.0252 3372 mouhid - ok
22:21:51.0432 3372 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:21:51.0622 3372 MountMgr - ok
22:21:51.0632 3372 mraid35x - ok
22:21:51.0662 3372 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:21:51.0813 3372 MRxDAV - ok
22:21:51.0883 3372 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:21:51.0963 3372 MRxSmb - ok
22:21:52.0033 3372 MSDV (8575d788395c4d6378d98d1ed7cdadb9) C:\WINDOWS\system32\DRIVERS\msdv.sys
22:21:52.0043 3372 MSDV - ok
22:21:52.0063 3372 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:21:52.0233 3372 Msfs - ok
22:21:52.0353 3372 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:21:52.0524 3372 MSKSSRV - ok
22:21:52.0544 3372 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:21:52.0704 3372 MSPCLOCK - ok
22:21:52.0734 3372 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
22:21:52.0894 3372 MSPQM - ok
22:21:52.0944 3372 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:21:53.0114 3372 mssmbios - ok
22:21:53.0144 3372 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\system32\drivers\MSTEE.sys
22:21:53.0185 3372 MSTEE - ok
22:21:53.0245 3372 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
22:21:53.0275 3372 Mup - ok
22:21:53.0315 3372 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:21:53.0335 3372 NABTSFEC - ok
22:21:53.0395 3372 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:21:53.0585 3372 NDIS - ok
22:21:53.0745 3372 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:21:53.0765 3372 NdisIP - ok
22:21:53.0825 3372 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:21:53.0866 3372 NdisTapi - ok
22:21:53.0916 3372 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:21:54.0086 3372 Ndisuio - ok
22:21:54.0146 3372 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:21:54.0296 3372 NdisWan - ok
22:21:54.0346 3372 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
22:21:54.0376 3372 NDProxy - ok
22:21:54.0446 3372 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:21:54.0617 3372 NetBIOS - ok
22:21:54.0707 3372 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:21:54.0867 3372 NetBT - ok
22:21:54.0917 3372 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
22:21:55.0107 3372 NIC1394 - ok
22:21:55.0127 3372 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:21:55.0298 3372 Npfs - ok
22:21:55.0348 3372 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
22:21:55.0418 3372 NSCIRDA - ok
22:21:55.0498 3372 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:21:55.0668 3372 Ntfs - ok
22:21:55.0728 3372 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:21:55.0878 3372 Null - ok
22:21:56.0009 3372 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:21:56.0189 3372 NwlnkFlt - ok
22:21:56.0219 3372 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:21:56.0379 3372 NwlnkFwd - ok
22:21:56.0419 3372 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
22:21:56.0569 3372 ohci1394 - ok
22:21:56.0619 3372 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
22:21:56.0780 3372 Parport - ok
22:21:56.0810 3372 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:21:56.0970 3372 PartMgr - ok
22:21:57.0020 3372 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:21:57.0180 3372 ParVdm - ok
22:21:57.0200 3372 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:21:57.0381 3372 PCI - ok
22:21:57.0401 3372 PCIDump - ok
22:21:57.0421 3372 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:21:57.0561 3372 PCIIde - ok
22:21:57.0601 3372 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
22:21:57.0761 3372 Pcmcia - ok
22:21:57.0781 3372 PDCOMP - ok
22:21:57.0801 3372 PDFRAME - ok
22:21:57.0821 3372 PDRELI - ok
22:21:57.0831 3372 PDRFRAME - ok
22:21:57.0861 3372 perc2 - ok
22:21:57.0881 3372 perc2hib - ok
22:21:57.0941 3372 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:21:58.0092 3372 PptpMiniport - ok
22:21:58.0132 3372 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:21:58.0282 3372 Ptilink - ok
22:21:58.0442 3372 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
22:21:58.0462 3372 PxHelp20 - ok
22:21:58.0472 3372 ql1080 - ok
22:21:58.0492 3372 Ql10wnt - ok
22:21:58.0512 3372 ql12160 - ok
22:21:58.0532 3372 ql1240 - ok
22:21:58.0552 3372 ql1280 - ok
22:21:58.0582 3372 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:21:58.0743 3372 RasAcd - ok
22:21:58.0793 3372 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
22:21:58.0853 3372 Rasirda - ok
22:21:58.0873 3372 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:21:59.0033 3372 Rasl2tp - ok
22:21:59.0063 3372 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:21:59.0233 3372 RasPppoe - ok
22:21:59.0253 3372 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:21:59.0403 3372 Raspti - ok
22:21:59.0464 3372 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:21:59.0634 3372 Rdbss - ok
22:21:59.0654 3372 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:21:59.0814 3372 RDPCDD - ok
22:21:59.0864 3372 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:22:00.0014 3372 rdpdr - ok
22:22:00.0074 3372 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
22:22:00.0104 3372 RDPWD - ok
22:22:00.0135 3372 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:22:00.0285 3372 redbook - ok
22:22:00.0365 3372 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:22:00.0435 3372 Secdrv - ok
22:22:00.0535 3372 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:22:00.0715 3372 serenum - ok
22:22:00.0765 3372 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
22:22:00.0926 3372 Serial - ok
22:22:00.0956 3372 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:22:01.0136 3372 Sfloppy - ok
22:22:01.0166 3372 Simbad - ok
22:22:01.0236 3372 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:22:01.0256 3372 SLIP - ok
22:22:01.0346 3372 smwdm (1319ea66a96250d59665d133c0ff7cd0) C:\WINDOWS\system32\drivers\smwdm.sys
22:22:01.0366 3372 smwdm - ok
22:22:01.0386 3372 Sparrow - ok
22:22:01.0436 3372 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:22:01.0777 3372 splitter - ok
22:22:01.0937 3372 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:22:02.0017 3372 sr - ok
22:22:02.0087 3372 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
22:22:02.0157 3372 Srv - ok
22:22:02.0238 3372 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:22:02.0248 3372 streamip - ok
22:22:02.0338 3372 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:22:02.0548 3372 swenum - ok
22:22:02.0668 3372 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:22:02.0818 3372 swmidi - ok
22:22:02.0838 3372 symc810 - ok
22:22:02.0858 3372 symc8xx - ok
22:22:02.0878 3372 sym_hi - ok
22:22:02.0909 3372 sym_u3 - ok
22:22:02.0969 3372 SynTP (1cde0a5c0416187b9b89e03980c6e8de) C:\WINDOWS\system32\DRIVERS\SynTP.sys
22:22:03.0019 3372 SynTP - ok
22:22:03.0059 3372 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:22:03.0229 3372 sysaudio - ok
22:22:03.0309 3372 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:22:03.0409 3372 Tcpip - ok
22:22:03.0589 3372 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:22:03.0760 3372 TDPIPE - ok
22:22:03.0790 3372 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:22:03.0950 3372 TDTCP - ok
22:22:03.0980 3372 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:22:04.0120 3372 TermDD - ok
22:22:04.0160 3372 TosIde - ok
22:22:04.0190 3372 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:22:04.0401 3372 Udfs - ok
22:22:04.0431 3372 ultra - ok
22:22:04.0471 3372 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:22:04.0641 3372 Update - ok
22:22:04.0701 3372 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:22:04.0871 3372 usbccgp - ok
22:22:04.0921 3372 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:22:05.0082 3372 usbehci - ok
22:22:05.0112 3372 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:22:05.0272 3372 usbhub - ok
22:22:05.0392 3372 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:22:05.0562 3372 usbscan - ok
22:22:05.0602 3372 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:22:05.0763 3372 USBSTOR - ok
22:22:05.0783 3372 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:22:05.0923 3372 usbuhci - ok
22:22:05.0963 3372 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
22:22:06.0133 3372 usbvideo - ok
22:22:06.0163 3372 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:22:06.0323 3372 VgaSave - ok
22:22:06.0343 3372 ViaIde - ok
22:22:06.0374 3372 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:22:06.0554 3372 VolSnap - ok
22:22:06.0614 3372 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:22:06.0764 3372 Wanarp - ok
22:22:06.0784 3372 WDICA - ok
22:22:06.0824 3372 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:22:07.0004 3372 wdmaud - ok
22:22:07.0064 3372 winachsf (5ea185425bfcbc2d4b96d673d8c4deaf) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
22:22:07.0145 3372 winachsf - ok
22:22:07.0415 3372 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:22:07.0595 3372 WS2IFSL - ok
22:22:07.0635 3372 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:22:07.0665 3372 WSTCODEC - ok
22:22:07.0725 3372 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:22:07.0766 3372 WudfPf - ok
22:22:07.0806 3372 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:22:07.0826 3372 WudfRd - ok
22:22:07.0896 3372 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
22:22:08.0036 3372 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
22:22:08.0036 3372 \Device\Harddisk0\DR0 - detected TDSS File System (1)
22:22:08.0046 3372 Boot (0x1200) (56e353e98760abb6f9b14dc6328920c0) \Device\Harddisk0\DR0\Partition0
22:22:08.0046 3372 \Device\Harddisk0\DR0\Partition0 - ok
22:22:08.0086 3372 Boot (0x1200) (569b07d10353f6748efdecd04354232d) \Device\Harddisk0\DR0\Partition1
22:22:08.0086 3372 \Device\Harddisk0\DR0\Partition1 - ok
22:22:08.0086 3372 ============================================================
22:22:08.0086 3372 Scan finished
22:22:08.0086 3372 ============================================================
22:22:08.0206 3308 Detected object count: 2
22:22:08.0206 3308 Actual detected object count: 2
22:24:00.0948 3308 ati2mtag ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:00.0948 3308 ati2mtag ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:24:00.0948 3308 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
22:24:00.0948 3308 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
22:25:08.0235 3952 Deinitialize success


Combofix log:

ComboFix 11-12-01.03 - Primo 12/01/2011 22:28:43.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.615 [GMT -6:00]
Running from: c:\documents and settings\Primo\Desktop\malware stuff\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infected copy of c:\windows\system32\Drivers\atapi.sys was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\atapi.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-11-02 to 2011-12-02 )))))))))))))))))))))))))))))))
.
.
2011-11-29 16:52 . 2011-11-29 16:52 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-11-28 20:37 . 2011-11-28 20:37 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2011-11-28 05:30 . 2011-11-28 05:30 -------- d-s---w- c:\documents and settings\LocalService\UserData
2011-11-28 04:13 . 2011-12-02 01:35 -------- d-sh--w- c:\documents and settings\Primo\Local Settings\Application Data\e39cc36a
2011-11-17 20:18 . 1998-10-29 22:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-11-04 00:40 . 2011-11-05 07:00 -------- d-----w- c:\documents and settings\Primo\Local Settings\Application Data\Akamai
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-20 08:55 . 2011-08-17 15:52 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2006-04-04 02:58 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2006-04-04 02:41 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2006-04-04 02:42 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2006-04-04 02:42 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-04-04 02:42 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2006-04-04 02:42 667136 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2006-04-04 02:42 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2006-04-04 02:41 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2006-04-04 02:41 369664 ----a-w- c:\windows\system32\html.iec
2011-11-09 21:37 . 2011-10-04 16:18 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( [email protected]_01.53.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-02 04:45 . 2011-12-02 04:45 16384 c:\windows\Temp\Perflib_Perfdata_d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-24 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-24 561152]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-03-16 325000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
c:\documents and settings\Primo\Start Menu\Programs\Startup\
Seagate na02sx8d Product Registration.lnk - c:\documents and settings\Primo\Application Data\Leadertech\PowerRegister\Seagate na02sx8d Product Registration.exe [2011-10-4 1731736]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Primo\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\BillP Studios\\WinPatrol\\WinPatrol.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Program Files\\Common Files\\Java\\Java Update\\jucheck.exe"=
"c:\\Program Files\\McAfee Security Scan\\2.0.181\\mcuicnt.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5/4/2011 1:51 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/8/2010 12:16 PM 307928]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [4/3/2006 8:42 PM 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/8/2010 12:16 PM 19544]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/1/2011 7:22 PM 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-11-11 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2011-05-05 02:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
uInternet Settings,ProxyOverride = ;*.local;<local>
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z039&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
user_pref(security.warn_viewing_mixed,false);
user_pref(security.warn_viewing_mixed.show_once,false);
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
user_pref(security.warn_submit_insecure,false);
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-01 22:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_d768ebc.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1648)
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\documents and settings\Primo\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-12-01 22:55:49 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-02 04:55
ComboFix2.txt 2011-12-02 02:02
ComboFix3.txt 2011-05-04 05:55
.
Pre-Run: 10,436,292,608 bytes free
Post-Run: 10,420,453,376 bytes free
.
- - End Of File - - 18D238A34BEFE1F94EF694588271B2D2


OTL log:

OTL logfile created on: 12/1/2011 11:20:58 PM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Primo\Desktop\malware stuff
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 526.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.35 Gb Total Space | 9.70 Gb Free Space | 29.08% Space Free | Partition Type: NTFS

Computer Name: DESERT7210 | User Name: Primo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/09 15:37:31 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/05/10 06:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
PRC - [2011/04/08 11:59:52 | 000,507,624 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2011/03/16 16:32:59 | 000,325,000 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2010/06/02 18:50:58 | 001,144,104 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/01/15 06:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/08/21 06:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003/06/24 13:34:38 | 000,126,976 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


========== Modules (SafeList) ==========

MOD - [2011/05/10 06:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2011/04/30 01:14:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Primo\Desktop\malware stuff\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2007/03/26 12:03:20 | 000,057,344 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll
MOD - [2003/06/24 13:33:54 | 000,065,536 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [Auto | Stopped] -- -- (IBMPMSVC)
SRV - File not found [Auto | Stopped] -- -- (Bonjour Service)
SRV - File not found [Auto | Stopped] -- -- (Ati HotKey Poller)
SRV - File not found [Auto | Stopped] -- -- (Apple Mobile Device)
SRV - [2011/11/17 19:08:21 | 003,313,752 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_d768ebc.dll -- (Akamai)
SRV - [2011/05/10 06:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/01/15 06:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/11/28 11:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/28 11:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/28 11:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/28 11:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/28 11:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/28 11:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/28 11:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2007/05/02 07:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007/02/06 21:38:32 | 001,133,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/01/25 16:27:14 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/01/25 16:26:36 | 000,207,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/01/25 16:26:28 | 000,703,616 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...UGO&form=ZGAPHP
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;<local>

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 15:37:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/21 21:14:44 | 000,000,000 | ---D | M]

[2010/04/21 22:18:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Extensions
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions
[2011/11/10 12:01:37 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/11/12 13:09:32 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/22 19:27:41 | 000,000,000 | ---D | M] (Search Toolbar) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2010/10/27 20:40:11 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Documents and Settings\Primo\Application Data\Mozilla\Firefox\Profiles\37v2w6j0.default\extensions\[email protected]
[2011/11/09 15:37:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/07 12:51:33 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PRIMO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\37V2W6J0.DEFAULT\EXTENSIONS\{40A1F5D7-AFC2-498F-B264-02668D616FF6}.XPI
[2011/11/09 15:37:31 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/10/04 10:17:50 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/01/01 02:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old
[2011/11/09 15:37:31 | 000,002,040 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/12/01 22:41:32 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKLM..\RunOnce: [aswAhAScr.dll] C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk = C:\Documents and Settings\Primo\Application Data\Leadertech\PowerRegister\Seagate na02sx8d Product Registration.exe (Leader Technologies/Seagate)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Primo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/03 21:00:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/01 23:15:05 | 000,199,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/12/01 18:40:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/12/01 18:40:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/12/01 18:40:43 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/12/01 18:40:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/12/01 18:39:59 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/28 23:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2011/11/27 22:13:53 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\e39cc36a
[2011/11/17 14:18:56 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[2011/11/07 20:13:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Desktop\lcs_win32_4.04.0
[2011/11/03 18:40:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Primo\Local Settings\Application Data\Akamai
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/01 23:15:08 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/01 22:47:13 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/01 22:41:32 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/01 22:40:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/28 23:13:34 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/28 12:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/11/28 12:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/11/28 11:53:53 | 000,435,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/11/28 11:53:35 | 000,314,456 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/11/28 11:52:19 | 000,034,392 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/11/28 11:52:16 | 000,052,952 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/11/28 11:52:02 | 000,111,320 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/11/28 11:51:59 | 000,105,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/11/28 11:51:50 | 000,020,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/11/28 11:48:49 | 000,030,808 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/11/27 22:45:46 | 000,001,313 | ---- | M] () -- C:\Documents and Settings\Primo\Start Menu\Programs\Startup\Seagate na02sx8d Product Registration.lnk
[2011/11/22 01:52:48 | 000,000,285 | ---- | M] () -- C:\Documents and Settings\Primo\Desktop\Shortcut to New Volume (D).lnk
[2011/11/21 20:38:09 | 000,108,544 | ---- | M] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 20:52:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/12 13:06:41 | 000,135,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/10 18:04:35 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/11/10 03:02:37 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/07 10:56:28 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/11/06 12:42:54 | 000,426,932 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/06 12:42:54 | 000,065,776 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/01 18:40:43 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/12/01 18:40:43 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/12/01 18:40:43 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/12/01 18:40:43 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/12/01 18:40:43 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/11/10 18:04:33 | 000,000,268 | ---- | C] () -- C:\WINDOWS\tasks\prismShakeIcon.job
[2011/05/11 22:34:31 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2011/05/02 01:21:08 | 000,025,380 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/04/02 16:14:58 | 000,108,544 | ---- | C] () -- C:\Documents and Settings\Primo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/02 19:05:32 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/02/02 19:05:32 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/02/01 18:54:17 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/04/25 02:25:10 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/22 13:15:47 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010/04/21 22:18:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/07/15 07:56:42 | 000,087,540 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/04/04 12:58:35 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/04/03 21:03:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2006/04/03 20:57:28 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/04/03 20:42:01 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/04/03 20:42:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/04/03 20:42:00 | 000,426,932 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2006/04/03 20:42:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/04/03 20:42:00 | 000,065,776 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2006/04/03 20:42:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/04/03 20:42:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/04/03 20:41:59 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/04/03 20:41:59 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/04/03 20:41:59 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2006/04/03 20:41:51 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/04/03 20:41:50 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/04/03 13:51:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/04/03 13:50:44 | 000,135,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/06/24 13:43:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll

< End of report >


OTL Extras log:

OTL Extras logfile created on: 12/1/2011 11:20:58 PM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Primo\Desktop\malware stuff
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 526.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.35 Gb Total Space | 9.70 Gb Free Space | 29.08% Space Free | Partition Type: NTFS

Computer Name: DESERT7210 | User Name: Primo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
.js [@ = JSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] -- %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
InternetShortcut [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Disabled:Veoh Web Player -- (Veoh Networks)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Mozilla Firefox -- (Mozilla Corporation)
"C:\Documents and Settings\Primo\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Primo\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe" = C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe:*:Enabled:WinPatrol System Monitor -- (BillP Studios)
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe" = C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Enabled:DivX Update -- ()
"C:\Program Files\Common Files\Java\Java Update\jucheck.exe" = C:\Program Files\Common Files\Java\Java Update\jucheck.exe:*:Enabled:Java™ Update Checker -- (Sun Microsystems, Inc.)
"C:\Program Files\McAfee Security Scan\2.0.181\mcuicnt.exe" = C:\Program Files\McAfee Security Scan\2.0.181\mcuicnt.exe:*:Enabled:McAfee HTML UI Container -- (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 26
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZero Preloader
"{3990E632-42C3-4A25-ADFF-1101E3D6DD47}" = VSClassic
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B66765B-8596-4698-A208-E23D11D84AA7}" = Canon Camera WIA Driver
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7D15B945-2725-4443-AB3F-D900556612FE}" = User Profile Hive Cleanup Service
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9FF889B0-2F9A-495d-9C65-9F0710310A82DC}" = Download Center
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A567895C-1D23-48ED-BE83-FB3ED7D30442}" = IPM_VS_Pro
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA902C31-B49D-4608-BCCF-2519EB77722D}" = ICA
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B0125BEB-6731-43FA-88DA-B64D7BD3AD2D}" = VSPro
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B84ECBE1-6ED5-4E86-B4AB-DF46D342411F}" = Share
"{B87FAC24-973D-4A4F-AFC4-555FB95B32DB}" = PureHD
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{BCD99FFB-70B6-475E-9BAF-536FBF9AA962}" = PEOPLEPCAOL
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4778408-3268-45CE-AE15-772D1739A1F1}" = VIO
"{C6017EEA-9E51-4129-84BA-EFA9520E69D8}" = Common
"{CC4C7E9B-4B26-4D8D-8076-40CF708A9FA4}" = Contents
"{CD6163D8-60AB-4681-A79E-B677C2D98BA5}" = Mega Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07F85DE-22F1-4FB4-B3D1-402FD22C4870}" = DeviceIO
"{D68897FC-7E8D-4849-819A-726B2489713C}" = ISCOM
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{D8D9BCF5-0F5F-4D3F-8427-64B7632F93BE}" = Setup
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Akamai" = Akamai NetSession Interface Service
"ATI Display Driver" = ATI Display Driver
"avast" = avast! Free Antivirus
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014" = ThinkPad Integrated 56K Modem
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-06-26
"DivX Setup.divx.com" = DivX Setup
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"GPL Ghostscript 8.60" = GPL Ghostscript 8.60
"GPL Ghostscript Fonts" = GPL Ghostscript Fonts
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{4B66765B-8596-4698-A208-E23D11D84AA7}" = Canon Camera WIA Driver 6.2.5
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"MSNINST" = MSN
"Power Management Driver" = ThinkPad Power Management Driver
"Prism" = Prism Video File Converter
"PROSet" = Intel® PRO Network Connections Drivers
"SynTPDeinstKey" = IBM ThinkPad UltraNav Driver
"Veetle TV" = Veetle TV 0.9.18
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/1/2011 8:37:13 PM | Computer Name = DESERT7210 | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 9.4.6.252, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/1/2011 8:37:13 PM | Computer Name = DESERT7210 | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 9.4.6.252, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/1/2011 8:45:57 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 12/1/2011 8:46:03 PM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 12/2/2011 12:21:28 AM | Computer Name = DESERT7210 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 12/1/2011 9:49:49 PM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Bonjour Service service failed to start due to the following error:
%%2

Error - 12/1/2011 9:49:49 PM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2

Error - 12/1/2011 9:51:15 PM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 12/1/2011 9:51:15 PM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 12/2/2011 12:45:02 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%2

Error - 12/2/2011 12:45:03 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Apple Mobile Device service failed to start due to the following
error: %%2

Error - 12/2/2011 12:45:03 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Bonjour Service service failed to start due to the following error:
%%2

Error - 12/2/2011 12:45:03 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2

Error - 12/2/2011 12:45:03 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Image Acquisition
(WIA) service to connect.

Error - 12/2/2011 12:45:03 AM | Computer Name = DESERT7210 | Source = Service Control Manager | ID = 7000
Description = The Windows Image Acquisition (WIA) service failed to start due to
the following error: %%1053


< End of report >
  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
Run TDSSKiller again and let it delete this one:

22:24:00.0948 3308 \Device\Harddisk0\DR0 ( TDSS File System )


Do the following:
Start -> Run
type diskmgmt.msc
Click "OK"

Disk Management will open.

Click and hold the right side of the Disk Management Window and drag it to the right until you can see all the columns.

Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.

http://graphicssoft....nscreenshot.htm Save the file as a .jpg or the forum won't allow it.

Start, Run, eventvwr.msc, OK to bring up the Event Viewer. Right click on System and Clear All Events, No (we don't want to save the old log), OK. Repeat for Application. Reboot.

1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Double-click VEW.exe
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Ron
  • 0

#13
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
VEW System log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 03/12/2011 5:44:26 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 03/12/2011 5:34:52 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 03/12/2011 5:34:51 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.

Log: 'System' Date/Time: 03/12/2011 5:34:28 PM
Type: error Category: 0
Event: 7022 Source: Service Control Manager
The wscsvc service hung on starting.

Log: 'System' Date/Time: 03/12/2011 5:34:28 PM
Type: error Category: 0
Event: 7022 Source: Service Control Manager
The Windows Firewall/Internet Connection Sharing (ICS) service hung on starting.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7022 Source: Service Control Manager
The Computer Browser service hung on starting.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7022 Source: Service Control Manager
The Automatic Updates service hung on starting.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Windows Image Acquisition (WIA) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Windows Image Acquisition (WIA) service to connect.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Java Quick Starter service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 03/12/2011 5:34:27 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Bonjour Service service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 03/12/2011 5:34:26 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Apple Mobile Device service failed to start due to the following error: The system cannot find the file specified.

Log: 'System' Date/Time: 03/12/2011 5:34:26 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 03/12/2011 5:34:26 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.

Log: 'System' Date/Time: 03/12/2011 5:34:25 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Ati HotKey Poller service failed to start due to the following error: The system cannot find the file specified.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


VEW Application log:

Vino's Event Viewer v01c run on Windows XP in English
Report run at 03/12/2011 5:44:54 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Attached Thumbnails

  • untitled.JPG

  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,788 posts
  • MVP
Start, Run, services.msc, OK to bring up the Services window. Find Application Layer Gateway Service and right click on it and select Properties. If the Startup Type: does not say Automatic, change it and then hit Apply. Attempt to start the service. What error does it give?
  • 0

#15
General Field Marshal

General Field Marshal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 71 posts
no error given
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP