*****************************************************
*****************************************************
TDSSKiller Log
*****************************************************
19:56:53.0916 4360 TDSS rootkit removing tool 2.7.3.0 Jan 16 2012 18:53:41
19:57:04.0868 4360 ============================================================
19:57:04.0868 4360 Current date / time: 2012/01/19 19:57:04.0868
19:57:04.0868 4360 SystemInfo:
19:57:04.0868 4360
19:57:04.0868 4360 OS Version: 6.0.6002 ServicePack: 2.0
19:57:04.0868 4360 Product type: Workstation
19:57:04.0868 4360 ComputerName: CARUDA
19:57:04.0868 4360 UserName: _admin
19:57:04.0868 4360 Windows directory: C:\Windows
19:57:04.0868 4360 System windows directory: C:\Windows
19:57:04.0868 4360 Processor architecture: Intel x86
19:57:04.0868 4360 Number of processors: 2
19:57:04.0868 4360 Page size: 0x1000
19:57:04.0868 4360 Boot type: Normal boot
19:57:04.0868 4360 ============================================================
19:57:05.0367 4360 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:57:05.0414 4360 Initialize success
19:57:16.0256 5832 ============================================================
19:57:16.0256 5832 Scan started
19:57:16.0256 5832 Mode: Manual; SigCheck; TDLFS;
19:57:16.0256 5832 ============================================================
19:57:16.0739 5832 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
19:57:16.0848 5832 ACPI - ok
19:57:16.0926 5832 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
19:57:16.0958 5832 adp94xx - ok
19:57:17.0020 5832 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
19:57:17.0036 5832 adpahci - ok
19:57:17.0098 5832 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
19:57:17.0114 5832 adpu160m - ok
19:57:17.0192 5832 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
19:57:17.0207 5832 adpu320 - ok
19:57:17.0316 5832 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
19:57:17.0348 5832 AFD - ok
19:57:17.0410 5832 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
19:57:17.0426 5832 agp440 - ok
19:57:17.0535 5832 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
19:57:17.0566 5832 aic78xx - ok
19:57:17.0628 5832 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
19:57:17.0644 5832 aliide - ok
19:57:17.0691 5832 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
19:57:17.0706 5832 amdagp - ok
19:57:17.0753 5832 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
19:57:17.0769 5832 amdide - ok
19:57:17.0831 5832 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
19:57:17.0862 5832 AmdK7 - ok
19:57:17.0925 5832 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
19:57:17.0956 5832 AmdK8 - ok
19:57:18.0065 5832 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
19:57:18.0081 5832 arc - ok
19:57:18.0159 5832 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
19:57:18.0174 5832 arcsas - ok
19:57:18.0237 5832 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
19:57:18.0284 5832 AsyncMac - ok
19:57:18.0346 5832 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
19:57:18.0377 5832 atapi - ok
19:57:18.0502 5832 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
19:57:18.0564 5832 BCM43XV - ok
19:57:18.0611 5832 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
19:57:18.0642 5832 Beep - ok
19:57:18.0689 5832 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
19:57:18.0736 5832 blbdrive - ok
19:57:18.0830 5832 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
19:57:18.0845 5832 bowser - ok
19:57:18.0908 5832 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
19:57:18.0939 5832 BrFiltLo - ok
19:57:19.0001 5832 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
19:57:19.0017 5832 BrFiltUp - ok
19:57:19.0079 5832 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
19:57:19.0142 5832 Brserid - ok
19:57:19.0173 5832 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
19:57:19.0220 5832 BrSerWdm - ok
19:57:19.0282 5832 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
19:57:19.0344 5832 BrUsbMdm - ok
19:57:19.0407 5832 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
19:57:19.0454 5832 BrUsbSer - ok
19:57:19.0547 5832 BTCFilterService (4813df77ede536a52e3737971f910baa) C:\Windows\system32\DRIVERS\motfilt.sys
19:57:19.0578 5832 BTCFilterService - ok
19:57:19.0625 5832 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
19:57:19.0688 5832 BTHMODEM - ok
19:57:19.0781 5832 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\Windows\system32\drivers\BVRPMPR5.SYS
19:57:19.0797 5832 BVRPMPR5 ( UnsignedFile.Multi.Generic ) - warning
19:57:19.0797 5832 BVRPMPR5 - detected UnsignedFile.Multi.Generic (1)
19:57:19.0875 5832 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
19:57:19.0906 5832 cdfs - ok
19:57:19.0984 5832 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
19:57:20.0015 5832 cdrom - ok
19:57:20.0046 5832 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
19:57:20.0093 5832 circlass - ok
19:57:20.0171 5832 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
19:57:20.0202 5832 CLFS - ok
19:57:20.0280 5832 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
19:57:20.0312 5832 CmBatt - ok
19:57:20.0358 5832 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
19:57:20.0374 5832 cmdide - ok
19:57:20.0452 5832 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
19:57:20.0468 5832 Compbatt - ok
19:57:20.0546 5832 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
19:57:20.0561 5832 crcdisk - ok
19:57:20.0608 5832 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
19:57:20.0639 5832 Crusoe - ok
19:57:20.0733 5832 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
19:57:20.0748 5832 DfsC - ok
19:57:20.0873 5832 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
19:57:20.0889 5832 disk - ok
19:57:20.0951 5832 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
19:57:20.0982 5832 drmkaud - ok
19:57:21.0076 5832 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
19:57:21.0107 5832 DXGKrnl - ok
19:57:21.0170 5832 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
19:57:21.0201 5832 E1G60 - ok
19:57:21.0326 5832 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
19:57:21.0357 5832 Ecache - ok
19:57:21.0419 5832 eeCtrl (8f7dbc4be48f5388a6fe1f285e7948ef) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
19:57:21.0482 5832 eeCtrl - ok
19:57:21.0575 5832 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
19:57:21.0606 5832 elxstor - ok
19:57:21.0684 5832 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
19:57:21.0700 5832 EraserUtilRebootDrv - ok
19:57:21.0762 5832 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
19:57:21.0794 5832 ErrDev - ok
19:57:21.0887 5832 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
19:57:21.0918 5832 exfat - ok
19:57:21.0996 5832 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
19:57:22.0028 5832 fastfat - ok
19:57:22.0090 5832 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
19:57:22.0121 5832 fdc - ok
19:57:22.0199 5832 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
19:57:22.0215 5832 FileInfo - ok
19:57:22.0262 5832 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
19:57:22.0293 5832 Filetrace - ok
19:57:22.0324 5832 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
19:57:22.0371 5832 flpydisk - ok
19:57:22.0433 5832 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
19:57:22.0464 5832 FltMgr - ok
19:57:22.0527 5832 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
19:57:22.0558 5832 Fs_Rec - ok
19:57:22.0605 5832 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
19:57:22.0636 5832 gagp30kx - ok
19:57:22.0730 5832 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:57:22.0745 5832 GEARAspiWDM - ok
19:57:22.0792 5832 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
19:57:22.0854 5832 HdAudAddService - ok
19:57:22.0948 5832 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
19:57:22.0995 5832 HDAudBus - ok
19:57:23.0057 5832 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
19:57:23.0120 5832 HidBth - ok
19:57:23.0166 5832 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
19:57:23.0229 5832 HidIr - ok
19:57:23.0291 5832 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
19:57:23.0322 5832 HidUsb - ok
19:57:23.0385 5832 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
19:57:23.0400 5832 HpCISSs - ok
19:57:23.0478 5832 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
19:57:23.0494 5832 HpqKbFiltr - ok
19:57:23.0541 5832 HpqRemHid (115c0933b3ed51dfbec4449348c8065b) C:\Windows\system32\DRIVERS\HpqRemHid.sys
19:57:23.0556 5832 HpqRemHid - ok
19:57:23.0650 5832 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
19:57:23.0681 5832 HSFHWAZL - ok
19:57:23.0759 5832 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
19:57:23.0837 5832 HSF_DPV - ok
19:57:23.0947 5832 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
19:57:23.0979 5832 HTTP - ok
19:57:24.0025 5832 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
19:57:24.0041 5832 i2omp - ok
19:57:24.0088 5832 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
19:57:24.0119 5832 i8042prt - ok
19:57:24.0197 5832 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\DRIVERS\iaStor.sys
19:57:24.0213 5832 iaStor - ok
19:57:24.0306 5832 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
19:57:24.0337 5832 iaStorV - ok
19:57:24.0447 5832 IDSvix86 (74f2b7d99b8613eac36edf22a2ab3b08) C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090811.002\IDSvix86.sys
19:57:24.0478 5832 IDSvix86 - ok
19:57:24.0571 5832 igfx (038815297078d236d8cc064c295a74c6) C:\Windows\system32\DRIVERS\igdkmd32.sys
19:57:24.0712 5832 igfx - ok
19:57:24.0790 5832 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
19:57:24.0805 5832 iirsp - ok
19:57:24.0930 5832 IntcAzAudAddService (2967e9c168cb5e0108a8a243ae179bad) C:\Windows\system32\drivers\RTKVHDA.sys
19:57:25.0055 5832 IntcAzAudAddService - ok
19:57:25.0102 5832 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
19:57:25.0117 5832 intelide - ok
19:57:25.0180 5832 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
19:57:25.0211 5832 intelppm - ok
19:57:25.0258 5832 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:57:25.0289 5832 IpFilterDriver - ok
19:57:25.0336 5832 IpInIp - ok
19:57:25.0367 5832 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
19:57:25.0414 5832 IPMIDRV - ok
19:57:25.0461 5832 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
19:57:25.0507 5832 IPNAT - ok
19:57:25.0601 5832 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
19:57:25.0648 5832 IRENUM - ok
19:57:25.0695 5832 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
19:57:25.0726 5832 isapnp - ok
19:57:25.0804 5832 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
19:57:25.0819 5832 iScsiPrt - ok
19:57:25.0866 5832 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
19:57:25.0897 5832 iteatapi - ok
19:57:25.0944 5832 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
19:57:25.0975 5832 iteraid - ok
19:57:26.0022 5832 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
19:57:26.0038 5832 kbdclass - ok
19:57:26.0116 5832 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
19:57:26.0147 5832 kbdhid - ok
19:57:26.0225 5832 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
19:57:26.0256 5832 KSecDD - ok
19:57:26.0350 5832 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
19:57:26.0381 5832 lltdio - ok
19:57:26.0443 5832 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
19:57:26.0459 5832 LSI_FC - ok
19:57:26.0506 5832 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
19:57:26.0537 5832 LSI_SAS - ok
19:57:26.0599 5832 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
19:57:26.0631 5832 LSI_SCSI - ok
19:57:26.0662 5832 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
19:57:26.0693 5832 luafv - ok
19:57:26.0818 5832 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys
19:57:26.0833 5832 MBAMProtector - ok
19:57:26.0880 5832 MCSTRM - ok
19:57:26.0943 5832 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
19:57:26.0974 5832 megasas - ok
19:57:27.0052 5832 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
19:57:27.0083 5832 MegaSR - ok
19:57:27.0145 5832 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
19:57:27.0177 5832 Modem - ok
19:57:27.0223 5832 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
19:57:27.0255 5832 monitor - ok
19:57:27.0317 5832 motccgp (7b8d7bb9ae3ae9cd133bbc5aa91dd3cc) C:\Windows\system32\DRIVERS\motccgp.sys
19:57:27.0348 5832 motccgp - ok
19:57:27.0379 5832 motccgpfl (b812da6605caf02641312f1f65c75419) C:\Windows\system32\DRIVERS\motccgpfl.sys
19:57:27.0411 5832 motccgpfl - ok
19:57:27.0504 5832 motmodem (c3b0fd4f463e90b3917ff6ccea853bb6) C:\Windows\system32\DRIVERS\motmodem.sys
19:57:27.0520 5832 motmodem - ok
19:57:27.0598 5832 MotoSwitchService (fd8c2cef7ad8b23c6714103d621fac1f) C:\Windows\system32\DRIVERS\motswch.sys
19:57:27.0613 5832 MotoSwitchService - ok
19:57:27.0676 5832 Motousbnet (ddc489d40b49f443787e7ffa75373522) C:\Windows\system32\DRIVERS\Motousbnet.sys
19:57:27.0707 5832 Motousbnet - ok
19:57:27.0769 5832 motusbdevice (2136cca3d1bf7c0248e5366b1a6c24e3) C:\Windows\system32\DRIVERS\motusbdevice.sys
19:57:27.0801 5832 motusbdevice - ok
19:57:27.0879 5832 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
19:57:27.0894 5832 mouclass - ok
19:57:27.0941 5832 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
19:57:27.0972 5832 mouhid - ok
19:57:28.0019 5832 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
19:57:28.0035 5832 MountMgr - ok
19:57:28.0081 5832 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
19:57:28.0097 5832 mpio - ok
19:57:28.0175 5832 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
19:57:28.0206 5832 mpsdrv - ok
19:57:28.0253 5832 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
19:57:28.0269 5832 Mraid35x - ok
19:57:28.0331 5832 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
19:57:28.0362 5832 MRxDAV - ok
19:57:28.0440 5832 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:57:28.0456 5832 mrxsmb - ok
19:57:28.0549 5832 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:57:28.0581 5832 mrxsmb10 - ok
19:57:28.0627 5832 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:57:28.0643 5832 mrxsmb20 - ok
19:57:28.0705 5832 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
19:57:28.0721 5832 msahci - ok
19:57:28.0768 5832 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
19:57:28.0799 5832 msdsm - ok
19:57:28.0846 5832 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
19:57:28.0877 5832 Msfs - ok
19:57:28.0924 5832 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
19:57:28.0939 5832 msisadrv - ok
19:57:29.0002 5832 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
19:57:29.0033 5832 MSKSSRV - ok
19:57:29.0095 5832 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
19:57:29.0127 5832 MSPCLOCK - ok
19:57:29.0158 5832 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
19:57:29.0189 5832 MSPQM - ok
19:57:29.0283 5832 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
19:57:29.0298 5832 MsRPC - ok
19:57:29.0345 5832 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
19:57:29.0361 5832 mssmbios - ok
19:57:29.0392 5832 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
19:57:29.0439 5832 MSTEE - ok
19:57:29.0485 5832 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
19:57:29.0501 5832 Mup - ok
19:57:29.0610 5832 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
19:57:29.0626 5832 NativeWifiP - ok
19:57:29.0751 5832 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110929.032\NAVENG.SYS
19:57:29.0766 5832 NAVENG - ok
19:57:29.0829 5832 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20110929.032\NAVEX15.SYS
19:57:29.0907 5832 NAVEX15 - ok
19:57:30.0031 5832 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
19:57:30.0063 5832 NDIS - ok
19:57:30.0109 5832 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
19:57:30.0141 5832 NdisTapi - ok
19:57:30.0172 5832 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
19:57:30.0203 5832 Ndisuio - ok
19:57:30.0281 5832 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
19:57:30.0312 5832 NdisWan - ok
19:57:30.0359 5832 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
19:57:30.0390 5832 NDProxy - ok
19:57:30.0468 5832 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
19:57:30.0499 5832 NetBIOS - ok
19:57:30.0593 5832 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
19:57:30.0624 5832 netbt - ok
19:57:30.0765 5832 NETw4v32 (25acccfc33dd448b9d3037c5e439e830) C:\Windows\system32\DRIVERS\NETw4v32.sys
19:57:30.0858 5832 NETw4v32 - ok
19:57:30.0936 5832 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
19:57:30.0952 5832 nfrd960 - ok
19:57:31.0045 5832 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
19:57:31.0077 5832 Npfs - ok
19:57:31.0123 5832 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
19:57:31.0155 5832 nsiproxy - ok
19:57:31.0248 5832 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
19:57:31.0311 5832 Ntfs - ok
19:57:31.0389 5832 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
19:57:31.0435 5832 ntrigdigi - ok
19:57:31.0482 5832 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
19:57:31.0513 5832 Null - ok
19:57:31.0576 5832 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
19:57:31.0638 5832 NVENETFD - ok
19:57:31.0685 5832 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
19:57:31.0701 5832 nvraid - ok
19:57:31.0779 5832 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
19:57:31.0794 5832 nvstor - ok
19:57:31.0841 5832 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
19:57:31.0857 5832 nv_agp - ok
19:57:31.0888 5832 NwlnkFlt - ok
19:57:31.0903 5832 NwlnkFwd - ok
19:57:31.0981 5832 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
19:57:32.0013 5832 ohci1394 - ok
19:57:32.0075 5832 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
19:57:32.0122 5832 Parport - ok
19:57:32.0200 5832 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
19:57:32.0231 5832 partmgr - ok
19:57:32.0278 5832 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
19:57:32.0325 5832 Parvdm - ok
19:57:32.0403 5832 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
19:57:32.0434 5832 pci - ok
19:57:32.0481 5832 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
19:57:32.0496 5832 pciide - ok
19:57:32.0527 5832 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
19:57:32.0559 5832 pcmcia - ok
19:57:32.0637 5832 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
19:57:32.0715 5832 PEAUTH - ok
19:57:32.0808 5832 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
19:57:32.0839 5832 PptpMiniport - ok
19:57:32.0902 5832 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
19:57:32.0933 5832 Processor - ok
19:57:33.0027 5832 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
19:57:33.0058 5832 PSched - ok
19:57:33.0167 5832 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
19:57:33.0214 5832 ql2300 - ok
19:57:33.0292 5832 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
19:57:33.0323 5832 ql40xx - ok
19:57:33.0385 5832 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
19:57:33.0401 5832 QWAVEdrv - ok
19:57:33.0432 5832 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
19:57:33.0463 5832 RasAcd - ok
19:57:33.0510 5832 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:57:33.0541 5832 Rasl2tp - ok
19:57:33.0635 5832 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
19:57:33.0666 5832 RasPppoe - ok
19:57:33.0729 5832 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
19:57:33.0744 5832 RasSstp - ok
19:57:33.0822 5832 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
19:57:33.0853 5832 rdbss - ok
19:57:33.0900 5832 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:57:33.0947 5832 RDPCDD - ok
19:57:33.0994 5832 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
19:57:34.0025 5832 rdpdr - ok
19:57:34.0072 5832 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
19:57:34.0103 5832 RDPENCDD - ok
19:57:34.0181 5832 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
19:57:34.0212 5832 RDPWD - ok
19:57:34.0290 5832 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
19:57:34.0306 5832 rimmptsk - ok
19:57:34.0353 5832 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
19:57:34.0368 5832 rimsptsk - ok
19:57:34.0399 5832 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
19:57:34.0431 5832 rismxdp - ok
19:57:34.0477 5832 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
19:57:34.0524 5832 rspndr - ok
19:57:34.0587 5832 RTL8169 (9a929308a64183d3d9dccbb6df4badae) C:\Windows\system32\DRIVERS\Rtlh86.sys
19:57:34.0618 5832 RTL8169 - ok
19:57:34.0649 5832 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
19:57:34.0665 5832 sbp2port - ok
19:57:34.0758 5832 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
19:57:34.0789 5832 sdbus - ok
19:57:34.0852 5832 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
19:57:34.0899 5832 secdrv - ok
19:57:34.0977 5832 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
19:57:35.0023 5832 Serenum - ok
19:57:35.0086 5832 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
19:57:35.0133 5832 Serial - ok
19:57:35.0195 5832 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
19:57:35.0226 5832 sermouse - ok
19:57:35.0273 5832 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
19:57:35.0304 5832 sffdisk - ok
19:57:35.0351 5832 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
19:57:35.0398 5832 sffp_mmc - ok
19:57:35.0476 5832 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
19:57:35.0507 5832 sffp_sd - ok
19:57:35.0538 5832 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
19:57:35.0585 5832 sfloppy - ok
19:57:35.0632 5832 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
19:57:35.0647 5832 sisagp - ok
19:57:35.0694 5832 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
19:57:35.0710 5832 SiSRaid2 - ok
19:57:35.0757 5832 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
19:57:35.0788 5832 SiSRaid4 - ok
19:57:35.0881 5832 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
19:57:35.0913 5832 Smb - ok
19:57:35.0991 5832 smserial (63b3b77bdb67ee674771c0e6fb96da9e) C:\Windows\system32\DRIVERS\smserial.sys
19:57:36.0069 5832 smserial - ok
19:57:36.0209 5832 SPBBCDrv (d7bb213566e16bca372e2cb517eda907) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
19:57:36.0225 5832 SPBBCDrv - ok
19:57:36.0287 5832 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
19:57:36.0303 5832 spldr - ok
19:57:36.0365 5832 SRTSP (522651a0e7dc6415e083317370b609cc) C:\Windows\system32\Drivers\SRTSP.SYS
19:57:36.0381 5832 SRTSP - ok
19:57:36.0443 5832 SRTSPL (34e823b8d730099d032608fcccbc6a25) C:\Windows\system32\Drivers\SRTSPL.SYS
19:57:36.0459 5832 SRTSPL - ok
19:57:36.0490 5832 SRTSPX (469006e15f5b0fe8ae94184a18a81586) C:\Windows\system32\Drivers\SRTSPX.SYS
19:57:36.0521 5832 SRTSPX - ok
19:57:36.0599 5832 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
19:57:36.0630 5832 srv - ok
19:57:36.0755 5832 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
19:57:36.0786 5832 srv2 - ok
19:57:36.0833 5832 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
19:57:36.0864 5832 srvnet - ok
19:57:36.0942 5832 ssfs0bbc (a3cc244f1e043c2b7ae32899ff99a0a0) C:\Windows\system32\DRIVERS\ssfs0bbc.sys
19:57:36.0958 5832 ssfs0bbc - ok
19:57:36.0989 5832 sshrmd (e041026dafa17af2610afc4da8f4ea14) C:\Windows\system32\DRIVERS\sshrmd.sys
19:57:37.0005 5832 sshrmd - ok
19:57:37.0051 5832 ssidrv (5a40b485825cc31b3a49bb4701b30d35) C:\Windows\system32\DRIVERS\ssidrv.sys
19:57:37.0067 5832 ssidrv - ok
19:57:37.0114 5832 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
19:57:37.0129 5832 swenum - ok
19:57:37.0192 5832 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
19:57:37.0207 5832 Symc8xx - ok
19:57:37.0285 5832 SymEvent (e03ee3ef1037099554d17bed99545a5e) C:\Windows\system32\Drivers\SYMEVENT.SYS
19:57:37.0301 5832 SymEvent - ok
19:57:37.0348 5832 SymIMMP - ok
19:57:37.0410 5832 SYMREDRV (be3c117150c055e50a4caf23e548c856) C:\Windows\System32\Drivers\SYMREDRV.SYS
19:57:37.0441 5832 SYMREDRV - ok
19:57:37.0488 5832 SYMTDI (7b0af4e22b32f8c5bfba5a5d53522160) C:\Windows\System32\Drivers\SYMTDI.SYS
19:57:37.0504 5832 SYMTDI - ok
19:57:37.0566 5832 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
19:57:37.0597 5832 Sym_hi - ok
19:57:37.0644 5832 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
19:57:37.0660 5832 Sym_u3 - ok
19:57:37.0722 5832 SynTP (f5d926807bd9bc0af68f9376144de425) C:\Windows\system32\DRIVERS\SynTP.sys
19:57:37.0738 5832 SynTP - ok
19:57:37.0847 5832 Tcpip (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys
19:57:37.0909 5832 Tcpip - ok
19:57:38.0034 5832 Tcpip6 (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys
19:57:38.0081 5832 Tcpip6 - ok
19:57:38.0175 5832 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
19:57:38.0206 5832 tcpipreg - ok
19:57:38.0253 5832 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
19:57:38.0284 5832 TDPIPE - ok
19:57:38.0331 5832 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
19:57:38.0362 5832 TDTCP - ok
19:57:38.0455 5832 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
19:57:38.0487 5832 tdx - ok
19:57:38.0565 5832 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
19:57:38.0580 5832 TermDD - ok
19:57:38.0643 5832 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:57:38.0674 5832 tssecsrv - ok
19:57:38.0736 5832 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
19:57:38.0767 5832 tunmp - ok
19:57:38.0830 5832 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
19:57:38.0861 5832 tunnel - ok
19:57:38.0908 5832 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
19:57:38.0923 5832 uagp35 - ok
19:57:39.0001 5832 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
19:57:39.0033 5832 udfs - ok
19:57:39.0095 5832 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
19:57:39.0111 5832 uliagpkx - ok
19:57:39.0173 5832 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
19:57:39.0204 5832 uliahci - ok
19:57:39.0267 5832 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
19:57:39.0282 5832 UlSata - ok
19:57:39.0345 5832 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
19:57:39.0376 5832 ulsata2 - ok
19:57:39.0407 5832 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
19:57:39.0438 5832 umbus - ok
19:57:39.0532 5832 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
19:57:39.0547 5832 USBAAPL ( UnsignedFile.Multi.Generic ) - warning
19:57:39.0547 5832 USBAAPL - detected UnsignedFile.Multi.Generic (1)
19:57:39.0594 5832 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
19:57:39.0625 5832 usbccgp - ok
19:57:39.0688 5832 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
19:57:39.0750 5832 usbcir - ok
19:57:39.0828 5832 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
19:57:39.0859 5832 usbehci - ok
19:57:39.0891 5832 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
19:57:39.0922 5832 usbhub - ok
19:57:39.0969 5832 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
19:57:40.0015 5832 usbohci - ok
19:57:40.0078 5832 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
19:57:40.0126 5832 usbprint - ok
19:57:40.0172 5832 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:57:40.0204 5832 USBSTOR - ok
19:57:40.0266 5832 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
19:57:40.0297 5832 usbuhci - ok
19:57:40.0360 5832 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
19:57:40.0391 5832 usbvideo - ok
19:57:40.0453 5832 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
19:57:40.0484 5832 vga - ok
19:57:40.0516 5832 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
19:57:40.0547 5832 VgaSave - ok
19:57:40.0609 5832 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
19:57:40.0625 5832 viaagp - ok
19:57:40.0687 5832 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
19:57:40.0718 5832 ViaC7 - ok
19:57:40.0781 5832 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
19:57:40.0796 5832 viaide - ok
19:57:40.0843 5832 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
19:57:40.0874 5832 volmgr - ok
19:57:40.0968 5832 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
19:57:40.0999 5832 volmgrx - ok
19:57:41.0077 5832 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
19:57:41.0093 5832 volsnap - ok
19:57:41.0156 5832 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
19:57:41.0172 5832 vsmraid - ok
19:57:41.0234 5832 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
19:57:41.0297 5832 WacomPen - ok
19:57:41.0343 5832 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
19:57:41.0375 5832 Wanarp - ok
19:57:41.0390 5832 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
19:57:41.0421 5832 Wanarpv6 - ok
19:57:41.0468 5832 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
19:57:41.0484 5832 Wd - ok
19:57:41.0531 5832 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
19:57:41.0577 5832 Wdf01000 - ok
19:57:41.0687 5832 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
19:57:41.0749 5832 winachsf - ok
19:57:41.0811 5832 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
19:57:41.0843 5832 WmiAcpi - ok
19:57:41.0921 5832 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
19:57:41.0936 5832 WpdUsb - ok
19:57:41.0983 5832 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
19:57:42.0030 5832 ws2ifsl - ok
19:57:42.0123 5832 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:57:42.0171 5832 WUDFRd - ok
19:57:42.0202 5832 MBR (0x1B8) (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0
19:57:42.0312 5832 \Device\Harddisk0\DR0 - ok
19:57:42.0327 5832 Boot (0x1200) (0298555a6eea010cd3c199e30391c393) \Device\Harddisk0\DR0\Partition0
19:57:42.0327 5832 \Device\Harddisk0\DR0\Partition0 - ok
19:57:42.0327 5832 Boot (0x1200) (486b6d319a106d46b6871fbb06ea3800) \Device\Harddisk0\DR0\Partition1
19:57:42.0327 5832 \Device\Harddisk0\DR0\Partition1 - ok
19:57:42.0327 5832 ============================================================
19:57:42.0327 5832 Scan finished
19:57:42.0327 5832 ============================================================
19:57:42.0343 5804 Detected object count: 2
19:57:42.0343 5804 Actual detected object count: 2
19:57:48.0677 5804 BVRPMPR5 ( UnsignedFile.Multi.Generic ) - skipped by user
19:57:48.0677 5804 BVRPMPR5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:57:48.0677 5804 USBAAPL ( UnsignedFile.Multi.Generic ) - skipped by user
19:57:48.0677 5804 USBAAPL ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:57:51.0361 4120 Deinitialize success
*****************************************************
*****************************************************
Below is OTL custom scan/run fix log
*****************************************************
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ deleted successfully.
C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
Prefs.js: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems
Prefs.js:
[email protected]:3.6.6.117 removed from extensions.enabledItems
Prefs.js: "
http://supertoolbar....ocale=en_US&q=" removed from keyword.URL
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\searchplugins folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\logs folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\defaults\preferences folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\defaults folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\datastore folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\chrome\temp\skin.Sat-24-Apr-2010-13-54-12-GMT folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\chrome\temp\ff-config.Tue-08-Nov-2011-09-24-30-GMT folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\chrome\temp folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\chrome\skin folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\too
[email protected]\chrome\content folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected]\chrome folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\
[email protected] folder moved successfully.
C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\searchplugins\askcom.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\askcom.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\w0ucS2ibDp8234A not found.
File C:\Windows\System32\YRL9gTXqjCkVz.exe not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ not found.
File F:\BOOTEX\thumbcache_131.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ not found.
File F:\BOOTEX/thumbcache_131.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c672ad40-7dba-11dd-a4ed-001e68b4a676}\ not found.
File F:\.////BOOTEX/thumbcache_131.exe not found.
C:\Users\_admin\AppData\Roaming\lgTXqjYCeIrOtAu folder moved successfully.
C:\Users\_admin\AppData\Roaming\rhTXwjUCeIrPyAu folder moved successfully.
C:\Users\_admin\AppData\Roaming\LdEK8gRZ9YwUeIt folder moved successfully.
C:\Users\_admin\AppData\Roaming\hPNycA1uv2b4m5Q folder moved successfully.
C:\Users\_admin\AppData\Local\AskToolbar\Downloaded Program Files\temp folder moved successfully.
C:\Users\_admin\AppData\Local\AskToolbar\Downloaded Program Files folder moved successfully.
C:\Users\_admin\AppData\Local\AskToolbar folder moved successfully.
C:\Users\_admin\AppData\Roaming\WsQJ7dEK8R9YwUe folder moved successfully.
C:\Users\_admin\AppData\Roaming\h7dEL8gRZhXk folder moved successfully.
File C:\ProgramData\privacy.exe not found.
File C:\Users\_admin\AppData\Roaming\ldr.ini not found.
C:\ProgramData\6DSS92c31Apgjk moved successfully.
C:\ProgramData\~6DSS92c31Apgjk moved successfully.
C:\ProgramData\~6DSS92c31Apgjkr moved successfully.
File C:\ProgramData\6DSS92c31Apgjk.exe not found.
C:\Windows\E80F62FF5D3C4A1984099721F2928206.TMP\WiseCustomCall.dll deleted successfully.
C:\Windows\E80F62FF5D3C4A1984099721F2928206.TMP folder deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\_admin\Desktop\cmd.bat deleted successfully.
C:\Users\_admin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: owner
->Temp folder emptied: 268928657 bytes
->Temporary Internet Files folder emptied: 10256034 bytes
->Java cache emptied: 1156012 bytes
->FireFox cache emptied: 60534554 bytes
->Apple Safari cache emptied: 127254528 bytes
->Flash cache emptied: 169867 bytes
User: Public
User: _admin
->Temp folder emptied: 58549602 bytes
->Temporary Internet Files folder emptied: 85140182 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 6748028 bytes
->Apple Safari cache emptied: 1459200 bytes
->Flash cache emptied: 1562 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1147019749 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,685.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 01192012_201015
Files\Folders moved on Reboot...
C:\Users\_admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LBTWAZV4\1066301710[1].htm moved successfully.
C:\Users\_admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\LBTWAZV4\fastbutton[3].htm moved successfully.
C:\Users\_admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5056IGBS\confirm[1].htm moved successfully.
C:\Users\_admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\_admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Windows\temp\895B.tmp moved successfully.
Registry entries deleted on Reboot...
*****************************************************
*****************************************************
Rerun OTL with "Scan All Users" option
*****************************************************
OTL logfile created on: 1/19/2012 8:23:13 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\_admin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 60.58% Memory free
6.18 Gb Paging File | 5.07 Gb Available in Paging File | 81.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.19 Gb Total Space | 107.43 Gb Free Space | 48.57% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 2.02 Gb Free Space | 17.30% Space Free | Partition Type: NTFS
Drive F: | 1.90 Gb Total Space | 1.90 Gb Free Space | 100.00% Space Free | Partition Type: FAT
Computer Name: CARUDA | User Name: _admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Users\_admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
PRC - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
PRC - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Panda Security)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\E_FATIEMA.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
========== Modules (No Company Name) ========== MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe ()
MOD - C:\Windows\System32\igfxTMM.dll ()
========== Win32 Services (SafeList) ========== SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MotoHelper) -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe ()
SRV - (WRConsumerService) -- C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) -- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe ()
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SmcService) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe ()
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
========== Driver Services (SafeList) ========== DRV - (SRTSP) -- C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20110929.032\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20110929.032\NAVENG.SYS (Symantec Corporation)
DRV - (motccgp) -- C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (motmodem) -- C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (Motousbnet) -- C:\Windows\System32\drivers\Motousbnet.sys (Motorola)
DRV - (motusbdevice) -- C:\Windows\System32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (ssidrv) -- C:\Windows\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) -- C:\Windows\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) -- C:\Windows\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (BVRPMPR5) -- C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (SRTSPL) -- C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) -- C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (IDSvix86) -- C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20090811.002\IDSvix86.sys (Symantec Corporation)
DRV - (motccgpfl) -- C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (BTCFilterService) -- C:\Windows\System32\drivers\motfilt.sys (Motorola Inc)
DRV - (MotoSwitchService) -- C:\Windows\System32\drivers\motswch.sys (Motorola)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (HpqRemHid) -- C:\Windows\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NETw4v32) Intel® -- C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (smserial) -- C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...ilion&pf=laptopIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...ilion&pf=laptopIE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...ilion&pf=laptopIE - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...ilion&pf=laptopIE - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems:
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/08/31 19:45:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/02 19:22:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/02 19:22:11 | 000,000,000 | ---D | M]
[2009/12/23 10:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\_admin\AppData\Roaming\Mozilla\Extensions
[2012/01/19 20:10:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions
[2009/12/23 11:02:00 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/01/16 06:52:15 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/01/02 19:22:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/02 19:22:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/01/02 19:22:13 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/20 23:04:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/09 05:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2010/05/06 20:22:31 | 000,001,490 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\AOL Search.xml
[2011/11/20 20:04:05 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/20 20:04:05 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/01/19 20:10:39 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [WinampAgent] "C:\Users\owner\Desktop\Winamp\winampa.exe" File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001..\Run: [\\mac001ff3d8ffdd\EPSON Artisan 800] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEMA.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001..\Run: [EPSON Artisan 800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIEMA.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001..\Run: [WindowsWelcomeCenter] "C:\Windows\system32\rundll32.exe" oobefldr.dll,ShowWelcomeCenter File not found
O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Welcome Center.lnk = C:\Windows\System32\control.exe (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-1643871695-1882474329-1398546539-1001\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C187B1F-FC4B-45FF-8753-2264EA38E7AD}: DhcpNameServer = 216.183.102.115 66.179.168.118
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE41FC19-29CB-4C60-8950-CADE512413A1}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\HPRadiance.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\HPRadiance.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/01 08:18:01 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/01/19 20:10:15 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/19 20:03:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2012/01/19 20:03:00 | 000,000,000 | ---D | C] -- C:\Program Files\Panda USB Vaccine
[2012/01/19 20:03:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
[2012/01/17 09:19:35 | 001,976,112 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\_admin\Desktop\tdsskiller.exe
[2012/01/17 09:06:17 | 000,000,000 | ---D | C] -- C:\e6767b004533ac8a30eb3661c92de8
[2012/01/16 13:45:49 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Users\_admin\Desktop\aswMBR.exe
[2012/01/16 12:51:50 | 000,000,000 | ---D | C] -- C:\Users\_admin\AppData\Roaming\Malwarebytes
[2012/01/16 12:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/16 12:51:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/16 12:51:26 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/01/16 12:51:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/16 11:08:30 | 000,000,000 | ---D | C] -- C:\Users\_admin\AppData\Roaming\XjYCekIVrOtAu
[2012/01/16 11:08:30 | 000,000,000 | ---D | C] -- C:\Users\_admin\AppData\Roaming\n3pnG5aQHdKfLgX
[2012/01/16 06:56:14 | 000,000,000 | ---D | C] -- C:\Users\_admin\AppData\Local\Winamp Toolbar
========== Files - Modified Within 30 Days ========== [2012/01/19 20:22:17 | 000,604,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/01/19 20:22:17 | 000,104,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/01/19 20:16:48 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/19 20:16:48 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/19 20:16:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/19 20:16:33 | 3211,190,272 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/19 20:10:39 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012/01/19 20:01:09 | 000,823,346 | ---- | M] () -- C:\Users\_admin\Desktop\USBVaccine.zip
[2012/01/18 08:05:34 | 000,000,512 | ---- | M] () -- C:\Users\_admin\Desktop\MBR.dat
[2012/01/18 07:53:11 | 000,080,384 | ---- | M] () -- C:\Users\_admin\Desktop\MBRCheck.exe
[2012/01/17 09:58:32 | 000,000,903 | ---- | M] () -- C:\Users\_admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/17 09:48:31 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2012/01/17 09:48:31 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2012/01/17 09:48:20 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/01/17 09:25:41 | 000,280,112 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\srtsp.sys
[2012/01/17 09:01:42 | 001,922,249 | ---- | M] () -- C:\Users\_admin\Desktop\Windows6.0-KB968389-x86.msu
[2012/01/17 08:47:26 | 001,976,112 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\_admin\Desktop\tdsskiller.exe
[2012/01/16 13:44:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\_admin\Desktop\aswMBR.exe
[2012/01/16 12:51:28 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/16 08:49:39 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2012/01/16 08:49:39 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2012/01/16 08:46:09 | 000,002,678 | ---- | M] () -- C:\Users\_admin\Desktop\Windows Compatibility Report.htm
[2012/01/16 08:32:20 | 314,467,661 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/01/02 19:22:19 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
========== Files Created - No Company Name ========== [2012/01/19 20:01:05 | 000,823,346 | ---- | C] () -- C:\Users\_admin\Desktop\USBVaccine.zip
[2012/01/18 07:53:11 | 000,080,384 | ---- | C] () -- C:\Users\_admin\Desktop\MBRCheck.exe
[2012/01/17 09:58:32 | 000,000,903 | ---- | C] () -- C:\Users\_admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/17 09:48:20 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/01/17 09:28:40 | 001,922,249 | ---- | C] () -- C:\Users\_admin\Desktop\Windows6.0-KB968389-x86.msu
[2012/01/16 14:10:13 | 000,000,512 | ---- | C] () -- C:\Users\_admin\Desktop\MBR.dat
[2012/01/16 13:23:46 | 3211,190,272 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/16 12:51:28 | 000,000,866 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/16 08:46:09 | 000,002,678 | ---- | C] () -- C:\Users\_admin\Desktop\Windows Compatibility Report.htm
[2012/01/16 07:17:56 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012/01/16 07:17:56 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2012/01/02 19:22:19 | 000,000,818 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/02 19:22:19 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/05 15:27:31 | 000,000,680 | ---- | C] () -- C:\Users\_admin\AppData\Local\d3d9caps.dat
[2011/05/28 01:04:09 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/07/07 15:04:12 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/04/24 08:34:00 | 000,000,164 | ---- | C] () -- C:\Windows\install.dat
[2010/04/24 07:43:07 | 000,004,608 | ---- | C] () -- C:\Users\_admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/10 21:12:37 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/10 21:12:36 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/12/13 15:58:21 | 000,121,368 | ---- | C] () -- C:\Windows\hpoins15.dat
[2008/12/13 15:58:21 | 000,001,037 | ---- | C] () -- C:\Windows\hpomdl15.dat
[2008/08/31 20:26:32 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/08/31 20:26:32 | 000,000,063 | ---- | C] () -- C:\Windows\mdm.ini
[2008/08/31 20:26:18 | 000,000,000 | ---- | C] () -- C:\Windows\NSREX.INI
[2008/08/30 21:39:06 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/19 02:57:22 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ1.dat
[2008/07/19 02:57:22 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ0.dat
[2008/07/19 02:56:53 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/07/01 08:33:22 | 000,101,605 | ---- | C] () -- C:\Windows\hpqins13.dat
[2007/09/13 10:31:06 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/13 10:22:46 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/09/13 10:22:46 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007/09/13 10:11:18 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,315,440 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,502 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,170 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:24:01 | 048,324,552 | ---- | C] () -- C:\Windows\System32\mrt.exe
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/03/09 15:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[1999/01/22 06:46:56 | 000,065,536 | ---- | C] () -- C:\Windows\System32\MSRTEDIT.DLL
========== LOP Check ========== [2008/09/01 08:06:38 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\acccore
[2011/10/01 12:10:45 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\arlONtxP0c1b3
[2012/01/16 06:40:30 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\d2ibF3pnGaHdKfL
[2011/10/02 08:08:47 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\dwkIVrlONx0c1b3
[2011/09/30 10:48:14 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\EZZZqhhYXw
[2011/11/08 04:18:11 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\f9hTXwjUClBzNx1
[2010/06/21 19:30:50 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\Facebook
[2011/11/04 18:03:50 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\FCelIBrzPyAuSoF
[2011/10/01 12:10:44 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\FH6sWK7fE9TqYwI
[2012/01/02 18:46:18 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\GtzP0ycA1v2n4
[2012/01/02 19:15:48 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\hF4pmG5sQ6E8R9T
[2011/11/05 13:44:23 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\IOBtzP0yc1v2
[2011/10/02 08:08:47 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\JG4aQH6sW7E9TqY
[2011/11/04 18:10:06 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\jsQQQJ6dEK8fTXj
[2011/11/05 13:49:31 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\K4pmH5sQJdLgZhX
[2011/09/30 20:57:29 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\KxA0uvS2iFpGaHd
[2012/01/16 13:21:56 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\lAAA1iivD2on4pH
[2011/11/04 17:56:37 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\LrlOBtxP0c1v3n
[2012/01/16 06:40:30 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\lWK8fRL9hXjCkBz
[2011/10/01 01:34:56 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\NBrzONyxAuS
[2012/01/02 18:51:31 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\NmH5sQJ7dKgZhXj
[2011/09/30 10:48:25 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\nmmGG5ssQJ6EKfR
[2010/11/02 19:18:16 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ooVoo Details
[2012/01/16 06:33:15 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\P4amH5sWJgZ
[2011/09/30 20:57:29 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\R7fRL9gTXjCkVzN
[2011/09/30 10:51:40 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\rhhTTXwwj
[2012/01/02 19:10:40 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\RjUVelIBtPyAuDo
[2011/09/30 20:44:30 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\sZ9hTXwjUeIrPyA
[2011/11/05 11:06:32 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ueeelIIBrzPNxAu
[2011/09/30 20:44:30 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\UuvS2obF3m5Q6W8
[2011/11/04 18:03:49 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\vF4pm5sQJdfZhXj
[2011/11/04 17:51:19 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\vH6sWJ7fE8TqYwU
[2011/10/01 01:34:56 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\VibF3pnG5Q6W7R9
[2011/09/30 15:28:20 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\wYXXwwkUVe
[2011/09/30 15:28:20 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\XnFF44amH5sW7
[2011/11/08 04:18:11 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\z5QJ6dEK8R
[2012/01/16 06:33:15 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\ZhYXwkUVeOtPyAi
[2011/11/08 05:11:18 | 000,000,000 | ---D | M] -- C:\Users\_admin\AppData\Roaming\maQJ6dWK8R9TqUe
[2012/01/16 11:08:30 | 000,000,000 | ---D | M] -- C:\Users\_admin\AppData\Roaming\n3pnG5aQHdKfLgX
[2011/11/08 05:11:17 | 000,000,000 | ---D | M] -- C:\Users\_admin\AppData\Roaming\sA1uvS2ob3m
[2012/01/16 11:08:30 | 000,000,000 | ---D | M] -- C:\Users\_admin\AppData\Roaming\XjYCekIVrOtAu
[2012/01/19 20:15:13 | 000,032,576 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/09/23 10:35:53 | 000,001,478 | ---- | M] () -- C:\Windows\Tasks\wrSpySweeperFullSweep.job
[2011/10/02 08:03:14 | 000,001,630 | ---- | M] () -- C:\Windows\Tasks\wrSpySweeper_L3A520F780CE4472BA4C2EBD76CD7484E.job
========== Purity Check ========== < End of report >
*****************************************************************
ComboFix Log below
*****************************************************************
ComboFix 12-01-19.02 - _admin 01/19/2012 21:56:22.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3062.1827 [GMT -5:00]
Running from: c:\users\_admin\Downloads\ComboFix.exe
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {3A033352-45FD-579C-DF47-2D2DA7A56A3D}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {8162D2B6-63C7-5812-E5F7-165FDC222080}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\_admin\AppData\Roaming\hPNycA1uv2b4m5QOpenCloud Security.ico
c:\users\_admin\AppData\Roaming\lgTXqjYCeIrOtAuOpenCloud Security.ico
c:\users\_admin\AppData\Roaming\maQJ6dWK8R9TqUeOpenCloud Security.ico
c:\users\_admin\AppData\Roaming\WsQJ7dEK8R9YwUeOpenCloud Security.ico
c:\users\_admin\AppData\Roaming\XjYCekIVrOtAuOpenCloud Security.ico
c:\users\owner\AppData\Roaming\arlONtxP0c1b3OpenCloud Security.ico
c:\users\owner\AppData\Roaming\d2ibF3pnGaHdKfLOpenCloud Security.ico
c:\users\owner\AppData\Roaming\dwkIVrlONx0c1b3OpenCloud Security.ico
c:\users\owner\AppData\Roaming\f9hTXwjUClBzNx1OpenCloud Security.ico
c:\users\owner\AppData\Roaming\FCelIBrzPyAuSoFOpenCloud Security.ico
c:\users\owner\AppData\Roaming\hF4pmG5sQ6E8R9TOpenCloud Security.ico
c:\users\owner\AppData\Roaming\K4pmH5sQJdLgZhXOpenCloud Security.ico
c:\users\owner\AppData\Roaming\LrlOBtxP0c1v3nOpenCloud Security.ico
c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\System Restore.lnk
c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\Uninstall System Restore.lnk
c:\users\owner\AppData\Roaming\NmH5sQJ7dKgZhXjOpenCloud Security.ico
c:\users\owner\AppData\Roaming\R7fRL9gTXjCkVzNOpenCloud Security.ico
c:\users\owner\AppData\Roaming\rhhTTXwwjOpenCloud Security.ico
c:\users\owner\AppData\Roaming\ueeelIIBrzPNxAuOpenCloud Security.ico
c:\users\owner\AppData\Roaming\UuvS2obF3m5Q6W8OpenCloud Security.ico
c:\users\owner\AppData\Roaming\VibF3pnG5Q6W7R9OpenCloud Security.ico
c:\users\owner\AppData\Roaming\wYXXwwkUVeOpenCloud Security.ico
c:\users\owner\AppData\Roaming\ZhYXwkUVeOtPyAiOpenCloud Security.ico
c:\windows\$NtUninstallKB3255$
c:\windows\$NtUninstallKB3255$\2216314045
c:\windows\$NtUninstallKB3255$\485945278\@
c:\windows\$NtUninstallKB3255$\485945278\bckfg.tmp
c:\windows\$NtUninstallKB3255$\485945278\cfg.ini
c:\windows\$NtUninstallKB3255$\485945278\Desktop.ini
c:\windows\$NtUninstallKB3255$\485945278\keywords
c:\windows\$NtUninstallKB3255$\485945278\kwrd.dll
c:\windows\$NtUninstallKB3255$\485945278\L\qnbwvoto
c:\windows\$NtUninstallKB3255$\485945278\lsflt7.ver
c:\windows\$NtUninstallKB3255$\485945278\U\00000001.@
c:\windows\$NtUninstallKB3255$\485945278\U\00000002.@
c:\windows\$NtUninstallKB3255$\485945278\U\00000004.@
c:\windows\$NtUninstallKB3255$\485945278\U\80000000.@
c:\windows\$NtUninstallKB3255$\485945278\U\80000004.@
c:\windows\$NtUninstallKB3255$\485945278\U\80000032.@
c:\windows\system32\AutoRun.inf
c:\windows\system32\KBL.LOG
c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIEMA.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-12-20 to 2012-01-20 )))))))))))))))))))))))))))))))
.
.
2012-01-20 03:10 . 2012-01-20 03:10 -------- d-----w- c:\users\_admin\AppData\Local\temp
2012-01-20 01:10 . 2012-01-20 01:10 -------- d-----w- C:\_OTL
2012-01-20 01:03 . 2012-01-20 01:03 -------- d-----w- c:\programdata\Panda Security
2012-01-20 01:03 . 2012-01-20 01:03 -------- d-----w- c:\program files\Panda USB Vaccine
2012-01-17 14:31 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2012-01-17 14:06 . 2012-01-17 14:06 -------- d-----w- C:\e6767b004533ac8a30eb3661c92de8
2012-01-16 17:51 . 2012-01-16 17:51 -------- d-----w- c:\users\_admin\AppData\Roaming\Malwarebytes
2012-01-16 17:51 . 2012-01-16 17:51 -------- d-----w- c:\programdata\Malwarebytes
2012-01-16 17:51 . 2012-01-16 17:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-16 17:51 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-16 16:08 . 2012-01-16 16:08 -------- d-----w- c:\users\_admin\AppData\Roaming\XjYCekIVrOtAu
2012-01-16 16:08 . 2012-01-16 16:08 -------- d-----w- c:\users\_admin\AppData\Roaming\n3pnG5aQHdKfLgX
2012-01-16 11:56 . 2012-01-16 11:56 -------- d-----w- c:\users\_admin\AppData\Local\Winamp Toolbar
2012-01-16 11:40 . 2012-01-16 11:40 -------- d-----w- c:\users\owner\AppData\Roaming\lWK8fRL9hXjCkBz
2012-01-16 11:40 . 2012-01-16 11:40 -------- d-----w- c:\users\owner\AppData\Roaming\d2ibF3pnGaHdKfL
2012-01-16 11:33 . 2012-01-16 11:33 -------- d-----w- c:\users\owner\AppData\Roaming\ZhYXwkUVeOtPyAi
2012-01-16 11:33 . 2012-01-16 11:33 -------- d-----w- c:\users\owner\AppData\Roaming\P4amH5sWJgZ
2012-01-03 00:22 . 2011-11-21 04:04 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-01-03 00:22 . 2011-10-17 07:37 65536 ----a-w- c:\program files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll
2012-01-03 00:22 . 2011-11-21 04:04 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2012-01-03 00:22 . 2011-11-21 04:04 801752 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-01-03 00:22 . 2011-11-21 04:04 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2012-01-03 00:22 . 2011-11-21 04:04 478168 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2012-01-03 00:22 . 2011-11-21 04:04 1989592 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-01-03 00:22 . 2011-11-21 04:04 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2012-01-03 00:22 . 2011-11-21 04:04 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2012-01-03 00:22 . 2011-11-21 01:04 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2012-01-03 00:22 . 2011-11-21 01:04 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-01-03 00:10 . 2012-01-03 00:15 -------- d-----w- c:\users\owner\AppData\Roaming\hF4pmG5sQ6E8R9T
2012-01-03 00:10 . 2012-01-03 00:10 -------- d-----w- c:\users\owner\AppData\Roaming\RjUVelIBtPyAuDo
2012-01-02 23:46 . 2012-01-02 23:51 -------- d-----w- c:\users\owner\AppData\Roaming\NmH5sQJ7dKgZhXj
2012-01-02 23:46 . 2012-01-02 23:46 -------- d-----w- c:\users\owner\AppData\Roaming\GtzP0ycA1v2n4
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-17 14:25 . 2009-07-08 17:13 280112 ----a-w- c:\windows\system32\drivers\srtsp.sys
2011-11-21 04:04 . 2012-01-03 00:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-08 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2007-10-09 4702208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2009-11-06 6515784]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
.
c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Sidebar.lnk - c:\program files\Windows Sidebar\sidebar.exe [2009-9-10 1233920]
Welcome Center.lnk - c:\windows\System32\control.exe [2006-11-2 211968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2009-07-08 17:13 115560 ----a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-09-19 15:38 154136 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-10-01 23:10 1783136 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 23:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2007-09-13 15:47 480560 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2007-10-24 10:02 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-09-19 15:39 141848 ----a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 ----a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-09-19 15:39 129560 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2007-09-19 21:31 202032 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-12-20 02:27 468264 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2007-10-09 16:59 4702208 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2007-01-17 13:34 634880 ----a-w- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 11:00 132496 ----a-w- c:\program files\Java\jre1.6.0_02\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-03-28 06:05 1045800 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ------w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 22:53 311296 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1643871695-1882474329-1398546539-1000]
"EnableNotificationsRef"=dword:00000001
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-23 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-31 19:19]
.
2011-09-23 c:\windows\Tasks\wrSpySweeperFullSweep.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-31 19:19]
.
2011-10-02 c:\windows\Tasks\wrSpySweeper_L3A520F780CE4472BA4C2EBD76CD7484E.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-31 19:19]
.
2011-10-02 c:\windows\Tasks\wrSpySweeper_L3A520F780CE4472BA4C2EBD76CD7484E.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-31 19:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\_admin\AppData\Roaming\Mozilla\Firefox\Profiles\hlk4iq79.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-\\mac001ff3d8ffdd\EPSON Artisan 800 - c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIEMA.EXE
HKLM-Run-WinampAgent - c:\users\owner\Desktop\Winamp\winampa.exe
SafeBoot-93854943.sys
SafeBoot-96348536.sys
SafeBoot-Symantec Antvirus
MSConfigStartUp-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
MSConfigStartUp-isCfgWiz - c:\program files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-01-19 22:10
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-01-19 22:13:02
ComboFix-quarantined-files.txt 2012-01-20 03:12
.
Pre-Run: 115,028,881,408 bytes free
Post-Run: 114,930,802,688 bytes free
.
- - End Of File - - 628440BC280FC7420C527506014F9AA8
*****************************************************
*****************************************************
I am supposed to be using Webroot A/V which is licensed until April 2012.
Unfortunately it will not load & run right now.
I'm trying to work with Webroot to get it reinstalled.
Symantec is no longer licensed and should probably be uninstalled.
*****************************************************