Windows Update Hell
Been having this for a while, and I think its affecting other functions of my system now, so I've just about had it it with this. Basically put, Windows Update cannot check for updates, neither can I access the update website manually. The same pretty much goes for any other virus/malware scanning/removal program that needs updates of virus definitions (i.e. Microsoft Security Essentials, Avast, etc.). Latest error code is 80246002. Sometimes the updates come through, but often it will fail. I have reason to belive its some type of malware, but thus far all my attempts to locate it have failed. Any help is appreciated!
Attached is the most recent HiJackThis log. Unfortunately, whatever is ailing my PC is preventing me from downloading either Malwarebytes or Superantispyware, so all I've got is the HijackThis Log.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:56:16 AM, on 7/7/2011
Platform: Windows Vista SP2 (WinNT
6.00.1906)
MSIE: Internet Explorer v9.00
(9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common
Files\aol\1210728131\ee\aolsoftware.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java
Update\jusched.exe
C:\Program Files\AVAST
Software\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToo
lbarNotifier.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\EarthLink\ISP\ISP8300
\Browser\Bartshel.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\EarthLink\ISP\ISP8300
\Browser\PPShared.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common
Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\A
pplication\chrome.exe
C:\Users\Lycan\Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = HP - United States | Laptop Computers, Desktops, Printers, Servers and more
TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar
io&pf=desktop
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page = eBay | Electronics, Cars, Clothing, Collectibles and More Online Shopping
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = HP - United States | Laptop Computers, Desktops, Printers, Servers and more
TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar
io&pf=desktop
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page = HP - United States | Laptop Computers, Desktops, Printers, Servers and more
TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar
io&pf=desktop
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink PopUp Blocker V2 -
{512ACF1B-64D9-4928-B382-A80556F28DB4} -
C:\Program
Files\EarthLink\Toolbar\ElnkPub.dll
O2 - BHO: Accelerator Plugin - {656EC4B7-
072B-4698-B504-2A414C1F0037} - C:\PROGRA~1
\EARTHL~3\PRPL_I~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-
48bf-AC2D-D17F00898D06} - C:\Program
Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Earthlink Protection BHO -
{9579D574-D4D8-4335-9560-FE8641A013BD} -
C:\Program
Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Notifier BHO -
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -
C:\Program
Files\Google\GoogleToolbarNotifier\5.6.5612.
1312\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -
{DBC80044-A445-435b-BC74-9C25C1C588A9} -
C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar
- {E713904C-DF05-4C79-BBAD-02DB923253BE} -
C:\Program
Files\EarthLink\Toolbar\uninsttb.dll
O2 - BHO: Cooliris Plug-In for Internet
Explorer - {EAEE5C74-6D0D-4aca-9232-
0DA4A7B866BA} - C:\Program
Files\PicLensIE\cooliris.dll
O3 - Toolbar: DAEMON Tools Toolbar -
{32099AAC-C132-4136-9E9A-4E364A424E17} -
C:\Program Files\DAEMON Tools
Toolbar\DTToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-
AD2D-48bf-AC2D-D17F00898D06} - C:\Program
Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536
-96F8-4001-B1A2-90EE21279187} - C:\Program
Files\EarthLink\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HostManager] C:\Program
Files\Common Files\AOL\1210728131
\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE C:\Windows\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SwitchBoard] C:\Program
Files\Common
Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program Files\Common Files\Java\Java
Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program
Files\AVAST Software\Avast\avastUI.exe"
/nogui
O4 - HKLM\..\Run: [Bart Station] C:\Program
Files\EarthLink\ISP\ISP8300\BIN\PPCOLink.exe
-STATION
O4 - HKLM\..\Run: [Windows Defender] %
ProgramFiles%\Windows Defender\MSASCui.exe
-hide
O4 - HKCU\..\Run: [Sidebar] C:\Program
Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToo
lbarNotifier.exe"
O4 - HKCU\..\Run: [AOL Fast Start]
"C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate]
C:\Windows\system32
\Macromed\Flash\FlashUtil10i_ActiveX.exe -
update activex
O4 - Startup: Adobe Gamma.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe
Gamma Loader.exe
O8 - Extra context menu item: Add to Google
Photos Screensa&ver -
res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: EarthLink
Google Search - res://C:\Program
Files\EarthLink\Toolbar\SearchUI.dll/search.
html
O9 - Extra button: Launch Cooliris -
{3437D640-C91A-458f-89F5-B9095EA4C28B} -
C:\Program Files\PicLensIE\cooliris.dll
O11 - Options group: [ACCELERATED_GRAPHICS]
Accelerated graphics
O17 -
HKLM\System\CCS\Services\Tcpip\..\{2058ABE3
-0B7D-4978-A86E-673F575ACF9D}: NameServer =
93.188.164.35,93.188.160.105
O17 - HKLM\System\CS1
\Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E
-673F575ACF9D}: NameServer =
93.188.164.35,93.188.160.105
O17 - HKLM\System\CS2
\Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E
-673F575ACF9D}: NameServer =
93.188.164.35,93.188.160.105
O17 - HKLM\System\CS3
\Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E
-673F575ACF9D}: NameServer =
93.188.164.35,93.188.160.105
O22 - SharedTaskScheduler: Component
Categories cache daemon - {8C7461EF-2B13-
11d2-BE35-3078302C2030} -
C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe
Systems - C:\Program Files\Common
Files\Adobe Systems
Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL
ACS) - AOL LLC - C:\Program Files\Common
Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! Antivirus - AVAST
Software - C:\Program Files\AVAST
Software\Avast\AvastSvc.exe
O23 - Service:
##Id_String1.6844F930_1628_4223_B5CC_5BB94B8
79762## (Bonjour Service) - Apple Computer,
Inc. - C:\Program
Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service -
Macrovision Europe Ltd. - C:\Program
Files\Common Files\Macrovision
Shared\FLEXnet
Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service
(gupdate1c9bbf3acd1fde0)
(gupdate1c9bbf3acd1fde0) - Google Inc. -
C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service
(gupdatem) (gupdatem) - Google Inc. -
C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater
(gusvc) - Google - C:\Program
Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service -
Hewlett-Packard - c:\Program Files\Hewlett-
Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct
Disc Labeling Service (LightScribeService) -
Hewlett-Packard Company - C:\Program
Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NIHardwareService - Native
Instruments GmbH - C:\Program Files\Common
Files\Native
Instruments\Hardware\NIHardwareService.exe
O23 - Service: NVIDIA Display Driver Service
(nvsvc) - NVIDIA Corporation -
C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service
(CRVS) (RichVideo) - Unknown owner -
C:\Program Files\CyberLink\Shared
Files\RichVideo.exe
O23 - Service: Adobe SwitchBoard
(SwitchBoard) - Adobe Systems Incorporated -
C:\Program Files\Common
Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VideoAcceleratorService -
Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1
\VideoAcceleratorService.exe
O23 - Service: XAudioService - Conexant
Systems, Inc. - C:\Windows\system32
\DRIVERS\xaudio.exe
--
End of file - 9136 bytes
Hello and welcome to Help2 Go
We apologize for the delay in responding to your request for help. Here at Help2Go we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
Please take note: If you have since resolved the original problem you were having, we would appreciate you letting us know. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version , Edition and if it is a 32bit or a 64bit system . If you are unsure about any of these characteristics just post what you can and we will guide you. Please tell us if you have your original Windows CD/DVD available. If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information. If you have not done so, include a clear description of the problems you're having , along with any steps you may have performed so far. Upon completing the steps below another staff member will review your topic an do their best to resolve your issues. If you have already posted a DDS log, please do so again , as your situation may have changed. Use the 'Add Reply' and add the new log to this thread.
We need to see some information about what is happening in your machine. Please perform the following scan again: Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop. Double click on the DDS icon, allow it to run. A small box will open, with an explanation about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that pop up for posting the results. Close the program window, and delete the program from your desktop. Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
We also need a new log from the GMER anti-rootkit Scanner . Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.
Please first disable any CD emulation programs using the steps found in this topic: Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here: Note:
If you are unable to run a Gmer scan due the fact you are running a64bi t machine please run the following tool and post its log.
Please download aswMBR ( 511KB ) to your desktop. Double click the aswMBR.exe icon to run it Click the Scan button to start the scan On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
Thanks and again sorry for the delay.
" Extinguishing Malware from the world" The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you. HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-
OK, apologies for the delay. The Gmer scan took a while. Here's the DDS log, and attached are the DDS attach file and the Gmer log.
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Lycan at 23:53:19 on 2011-07-07
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1918.974 [GMT -7:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\aol\1210728131\ee\aolsoftware.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\EarthLink\ISP\ISP8300\Browser\Bartshel.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\EarthLink\ISP\ISP8300\Browser\PPShared.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Windows\System32\notepad.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ebay.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://start.earthlink.net/AL/Search
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://start.earthlink.net/AL/Search
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ElnkPubBHO Class: {512acf1b-64d9-4928-b382-a80556f28db4} - c:\program files\earthlink\toolbar\ElnkPub.dll
BHO: Accelerator Plugin: {656ec4b7-072b-4698-b504-2a414c1f0037} - c:\progra~1\earthl~3\PRPL_I~1.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: ElnkProtectionBHO Class: {9579d574-d4d8-4335-9560-fe8641a013bd} - c:\program files\earthlink\toolbar\ProtctIE.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: ElnkLegacyUninstBHO Class: {e713904c-df05-4c79-bbad-02db923253be} - c:\program files\earthlink\toolbar\uninsttb.dll
BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: EarthLink Toolbar: {c7768536-96f8-4001-b1a2-90ee21279187} - c:\program files\earthlink\toolbar\Toolbar.dll
TB: {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [AOL Fast Start] "c:\program files\aol 9.0\AOL.EXE" -b
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [HostManager] c:\program files\common files\aol\1210728131\ee\AOLSoftware.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Bart Station] c:\program files\earthlink\isp\isp8300\bin\PPCOLink.exe -STATION
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
StartupFolder: c:\users\lycan\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: EarthLink Google Search - c:\program files\earthlink\toolbar\SearchUI.dll/search.html
IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll
Trusted Zone: wolfquest.org\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D} : NameServer = 93.188.164.35,93.188.160.105
TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D} : DhcpNameServer = 192.168.1.1
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-5 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-6-5 307928]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-6-5 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-6-5 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-6-5 42184]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 NIHardwareService;NIHardwareService;c:\program files\common files\native instruments\hardware\NIHardwareService.exe [2010-2-26 3623424]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c9bbf3acd1fde0;Google Update Service (gupdate1c9bbf3acd1fde0);c:\program files\google\update\GoogleUpdate.exe [2009-4-12 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-4-12 133104]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-07-07 16:49:45 388096 ----a-r- c:\users\lycan\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-07-07 16:49:44 -------- d-----w- c:\program files\HJack
2011-07-07 05:57:09 -------- d-----w- c:\users\lycan\appdata\roaming\PFStaticIP
2011-07-07 05:56:58 -------- d-----w- c:\program files\PFStaticIP
2011-07-03 06:44:46 -------- d-----w- c:\program files\TC Electronic
2011-07-03 06:09:24 -------- d-----w- c:\program files\Focusrite
2011-07-01 23:41:31 0 ---ha-w- c:\users\lycan\appdata\local\BIT5C90.tmp
2011-06-30 11:11:11 -------- d-----w- c:\program files\Sibelius Software
2011-06-30 07:04:20 -------- d-----w- c:\program files\uTorrent
2011-06-30 07:01:26 -------- d-----w- c:\users\lycan\appdata\roaming\uTorrent
2011-06-30 07:01:26 -------- d-----w- c:\users\lycan\appdata\local\uTorrent
2011-06-30 04:33:09 -------- d-----w- c:\program files\EarthLink Accelerated
2011-06-30 04:09:22 -------- d-----w- c:\program files\common files\EarthLink
2011-06-30 04:09:20 69440 ------w- c:\windows\system32\unPPC6000.exe
2011-06-30 04:09:19 73728 ------w- c:\windows\system32\ppcpanel.cpl
2011-06-30 04:09:19 73192 ------w- c:\windows\system32\unPPC.exe
2011-06-30 04:09:19 41792 ------w- c:\windows\system32\ppcwebi.dll
2011-06-30 04:09:17 66880 ------w- c:\windows\system32\PPCOUNIN.exe
2011-06-30 04:09:17 34136 ------w- c:\windows\system32\RegHero.exe
2011-06-30 04:09:17 28992 ------w- c:\windows\system32\PopWait.exe
2011-06-30 04:09:16 40600 ------w- c:\windows\system32\PPCClean.exe
2011-06-30 04:09:16 255296 ------w- c:\windows\system32\PPCInfo.exe
2011-06-30 04:09:06 84992 ------w- c:\windows\system32\ATL70.dll
2011-06-30 04:07:31 -------- d-----w- c:\program files\EarthLink
.
==================== Find3M ====================
.
2011-05-10 12:10:59 40112 ----a-w- c:\windows\avastSS.scr
2011-05-10 12:03:54 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 11:59:44 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-13 22:40:10 4284416 ----a-w- c:\windows\system32\GPhotos.scr
.
============= FINISH: 23:54:06.48 ===============
Attached Files
Hello,
We will begin cleaning your machine. Note this could take a few tries. I will let you know when your machine is clean of Malware. 1.
We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make. Open Windows Defender . Click on Tools , General Settings . Scroll down and uncheck Turn on real-time protection (recommended) . After you uncheck this, click on the Save button and close Windows Defender. After all of the fixes are complete it is very important that you enable Real-time Protection again. 2.
Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe ) and save it to your Desktop. <-Important!!! Be sure to download TDSSKiller.exe (v2.5.6.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool. Double-click on TDSSKiller.exe to run the tool for known TDSS variants. Vista /Windows 7 users right-click and select Run As Administrator . If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe , select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension . Click the Start Scan button. Do not use the computer during the scan If the scan completes with nothing found, click Close to exit. If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options. Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process. A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.5.6.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C . Copy and paste the contents of that file in your next reply. 3. Install Recovery Console and Run ComboFix This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.
Download Combofix from any of the links below, and save it to your desktop . Link 1 Link 2 Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.Close any open windows , including this one.Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed . With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. If you did not have it installed, you will see the prompt below. Choose YES . Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console , and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes , to continue scanning for malware. When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt ). Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so. Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
Things to include in your next reply::
TDSSKiller log
Combofix.txt
How is your machine running now?
" Extinguishing Malware from the world" The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you. HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-
OK, both are done. Thus far the PC seems a little faster, some diskspace gained, but other than that we're still in the same boat.
Here is the TDSKiller log.
2011/07/08 15:44:25.0544 1744 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
2011/07/08 15:44:26.0176 1744 ================================================================================
2011/07/08 15:44:26.0176 1744 SystemInfo:
2011/07/08 15:44:26.0176 1744
2011/07/08 15:44:26.0176 1744 OS Version: 6.0.6002 ServicePack: 2.0
2011/07/08 15:44:26.0176 1744 Product type: Workstation
2011/07/08 15:44:26.0176 1744 ComputerName: HOMOLUPISSTUDIO
2011/07/08 15:44:26.0176 1744 UserName: Lycan
2011/07/08 15:44:26.0176 1744 Windows directory: C:\Windows
2011/07/08 15:44:26.0176 1744 System windows directory: C:\Windows
2011/07/08 15:44:26.0177 1744 Processor architecture: Intel x86
2011/07/08 15:44:26.0177 1744 Number of processors: 1
2011/07/08 15:44:26.0177 1744 Page size: 0x1000
2011/07/08 15:44:26.0177 1744 Boot type: Normal boot
2011/07/08 15:44:26.0177 1744 ================================================================================
2011/07/08 15:44:26.0785 1744 Initialize success
2011/07/08 15:44:29.0669 3016 ================================================================================
2011/07/08 15:44:29.0669 3016 Scan started
2011/07/08 15:44:29.0669 3016 Mode: Manual;
2011/07/08 15:44:29.0669 3016 ================================================================================
2011/07/08 15:44:30.0385 3016 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/07/08 15:44:30.0636 3016 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/07/08 15:44:30.0788 3016 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/07/08 15:44:30.0855 3016 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/07/08 15:44:30.0937 3016 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/07/08 15:44:31.0125 3016 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/07/08 15:44:31.0245 3016 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/07/08 15:44:31.0324 3016 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/07/08 15:44:31.0411 3016 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/07/08 15:44:31.0479 3016 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/07/08 15:44:31.0573 3016 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/07/08 15:44:31.0649 3016 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/07/08 15:44:31.0755 3016 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/08 15:44:31.0989 3016 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/07/08 15:44:32.0061 3016 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/07/08 15:44:32.0142 3016 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/08 15:44:32.0227 3016 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/07/08 15:44:32.0410 3016 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/07/08 15:44:32.0500 3016 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/07/08 15:44:32.0672 3016 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/08 15:44:32.0751 3016 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/07/08 15:44:32.0810 3016 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/07/08 15:44:32.0892 3016 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/07/08 15:44:32.0953 3016 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/07/08 15:44:33.0012 3016 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/07/08 15:44:33.0069 3016 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/07/08 15:44:33.0225 3016 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/07/08 15:44:33.0433 3016 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/08 15:44:33.0500 3016 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/07/08 15:44:33.0646 3016 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/07/08 15:44:33.0747 3016 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/07/08 15:44:33.0908 3016 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/07/08 15:44:33.0950 3016 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
2011/07/08 15:44:34.0001 3016 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/07/08 15:44:34.0037 3016 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/07/08 15:44:34.0212 3016 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/07/08 15:44:34.0445 3016 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/07/08 15:44:34.0530 3016 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/07/08 15:44:34.0632 3016 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/08 15:44:34.0719 3016 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/07/08 15:44:34.0818 3016 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/07/08 15:44:34.0910 3016 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/07/08 15:44:34.0982 3016 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/07/08 15:44:35.0086 3016 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/07/08 15:44:35.0172 3016 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/07/08 15:44:35.0267 3016 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/08 15:44:35.0391 3016 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/07/08 15:44:35.0507 3016 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/07/08 15:44:35.0749 3016 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/08 15:44:35.0854 3016 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/07/08 15:44:35.0981 3016 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/08 15:44:36.0051 3016 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/07/08 15:44:36.0326 3016 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/08 15:44:36.0407 3016 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/07/08 15:44:36.0514 3016 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/07/08 15:44:36.0613 3016 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/07/08 15:44:36.0709 3016 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/07/08 15:44:36.0971 3016 HSF_DP (88749fbf8beb18c90e7d6626c8c1910b) C:\Windows\system32\DRIVERS\HSX_DP.sys
2011/07/08 15:44:37.0062 3016 HSXHWBS2 (fe440536bd98af772130dc3a6fe1915f) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
2011/07/08 15:44:37.0173 3016 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
2011/07/08 15:44:37.0268 3016 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/07/08 15:44:37.0337 3016 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/07/08 15:44:37.0432 3016 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/07/08 15:44:37.0536 3016 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/07/08 15:44:37.0752 3016 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys
2011/07/08 15:44:37.0899 3016 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/07/08 15:44:37.0946 3016 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/08 15:44:38.0018 3016 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/08 15:44:38.0185 3016 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/07/08 15:44:38.0246 3016 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/07/08 15:44:38.0305 3016 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/07/08 15:44:38.0465 3016 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/07/08 15:44:38.0559 3016 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/07/08 15:44:38.0650 3016 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/07/08 15:44:38.0711 3016 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/07/08 15:44:38.0753 3016 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/07/08 15:44:38.0837 3016 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/07/08 15:44:38.0997 3016 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/08 15:44:39.0166 3016 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/08 15:44:39.0281 3016 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/07/08 15:44:39.0363 3016 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/07/08 15:44:39.0435 3016 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/07/08 15:44:39.0516 3016 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/07/08 15:44:39.0601 3016 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/07/08 15:44:39.0719 3016 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/07/08 15:44:39.0773 3016 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/07/08 15:44:39.0920 3016 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/07/08 15:44:40.0033 3016 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/08 15:44:40.0134 3016 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/07/08 15:44:40.0204 3016 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/08 15:44:40.0291 3016 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/07/08 15:44:40.0347 3016 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/07/08 15:44:40.0594 3016 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/08 15:44:40.0715 3016 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/07/08 15:44:40.0792 3016 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/07/08 15:44:40.0890 3016 mrxsmb (5fe5cf325f5b02ebc60832d3440cb414) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/08 15:44:40.0949 3016 mrxsmb10 (30b9c769446af379a2afb72b0392604d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/08 15:44:41.0006 3016 mrxsmb20 (fea239b3ec4877e2b7e23204af589ddf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/08 15:44:41.0101 3016 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/07/08 15:44:41.0146 3016 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/07/08 15:44:41.0233 3016 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/07/08 15:44:41.0284 3016 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/07/08 15:44:41.0366 3016 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/08 15:44:41.0440 3016 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/08 15:44:41.0498 3016 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/07/08 15:44:41.0605 3016 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/07/08 15:44:41.0719 3016 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/07/08 15:44:41.0765 3016 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/07/08 15:44:41.0854 3016 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/07/08 15:44:41.0951 3016 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/08 15:44:42.0062 3016 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/07/08 15:44:42.0157 3016 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/08 15:44:42.0222 3016 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/08 15:44:42.0318 3016 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/08 15:44:42.0423 3016 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/07/08 15:44:42.0524 3016 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/08 15:44:42.0647 3016 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/08 15:44:42.0804 3016 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/07/08 15:44:43.0029 3016 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/07/08 15:44:43.0106 3016 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/08 15:44:43.0238 3016 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/07/08 15:44:43.0333 3016 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/07/08 15:44:43.0385 3016 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/07/08 15:44:43.0491 3016 NVENETFD (d668632606d1cebf0b6ec64c1df7ed6f) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/07/08 15:44:43.0768 3016 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/07/08 15:44:44.0270 3016 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/07/08 15:44:44.0357 3016 nvrd32 (6f5bb0b40d251351a913b61ba9d64b3f) C:\Windows\system32\drivers\nvrd32.sys
2011/07/08 15:44:44.0436 3016 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\drivers\nvsmu.sys
2011/07/08 15:44:44.0545 3016 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/07/08 15:44:44.0656 3016 nvstor32 (1a649b87a7b7c1220a2b16b121f2198e) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/07/08 15:44:44.0756 3016 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/07/08 15:44:44.0921 3016 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/07/08 15:44:44.0993 3016 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/07/08 15:44:45.0108 3016 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/07/08 15:44:45.0151 3016 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/07/08 15:44:45.0310 3016 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/07/08 15:44:45.0397 3016 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2011/07/08 15:44:45.0496 3016 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/07/08 15:44:45.0567 3016 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/07/08 15:44:45.0802 3016 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/08 15:44:45.0910 3016 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/07/08 15:44:46.0021 3016 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/08 15:44:46.0141 3016 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
2011/07/08 15:44:46.0270 3016 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/07/08 15:44:46.0435 3016 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/07/08 15:44:46.0518 3016 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/08 15:44:46.0573 3016 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/08 15:44:46.0648 3016 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/08 15:44:46.0713 3016 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/08 15:44:46.0775 3016 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/08 15:44:46.0877 3016 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/08 15:44:46.0976 3016 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/08 15:44:47.0057 3016 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/07/08 15:44:47.0110 3016 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/08 15:44:47.0203 3016 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/07/08 15:44:47.0415 3016 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/08 15:44:47.0523 3016 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/07/08 15:44:47.0636 3016 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/08 15:44:47.0772 3016 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/07/08 15:44:47.0866 3016 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/07/08 15:44:47.0963 3016 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/07/08 15:44:48.0089 3016 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/07/08 15:44:48.0165 3016 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/07/08 15:44:48.0260 3016 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/07/08 15:44:48.0320 3016 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/07/08 15:44:48.0419 3016 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/07/08 15:44:48.0474 3016 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/07/08 15:44:48.0563 3016 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/07/08 15:44:48.0732 3016 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/07/08 15:44:48.0935 3016 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/07/08 15:44:49.0097 3016 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/07/08 15:44:49.0097 3016 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/07/08 15:44:49.0133 3016 sptd - detected LockedFile.Multi.Generic (1)
2011/07/08 15:44:49.0238 3016 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/07/08 15:44:49.0283 3016 srv2 (a5940ca32ed206f90be9fabdf6e92de4) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/08 15:44:49.0388 3016 srvnet (37aa1d560d5fa486c4b11c2f276ada61) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/08 15:44:49.0683 3016 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/07/08 15:44:49.0943 3016 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/07/08 15:44:50.0133 3016 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/07/08 15:44:50.0241 3016 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/07/08 15:44:50.0417 3016 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/07/08 15:44:50.0525 3016 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/08 15:44:50.0619 3016 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/08 15:44:50.0726 3016 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/07/08 15:44:50.0799 3016 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/07/08 15:44:50.0930 3016 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/08 15:44:50.0990 3016 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/07/08 15:44:51.0093 3016 TPkd (2f4e8077febfe11199ee3b011a34cd18) C:\Windows\system32\drivers\TPkd.sys
2011/07/08 15:44:51.0197 3016 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/08 15:44:51.0249 3016 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/07/08 15:44:51.0296 3016 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/08 15:44:51.0352 3016 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/07/08 15:44:51.0428 3016 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/08 15:44:51.0521 3016 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/07/08 15:44:51.0580 3016 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/07/08 15:44:51.0693 3016 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/07/08 15:44:51.0758 3016 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/07/08 15:44:51.0816 3016 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/07/08 15:44:51.0931 3016 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
2011/07/08 15:44:52.0055 3016 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/08 15:44:52.0154 3016 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/07/08 15:44:52.0247 3016 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/08 15:44:52.0352 3016 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/08 15:44:52.0417 3016 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2011/07/08 15:44:52.0493 3016 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/08 15:44:52.0567 3016 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/08 15:44:52.0686 3016 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/08 15:44:52.0783 3016 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/08 15:44:52.0859 3016 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/08 15:44:52.0916 3016 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/07/08 15:44:52.0982 3016 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/07/08 15:44:53.0048 3016 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/07/08 15:44:53.0113 3016 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/07/08 15:44:53.0200 3016 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/07/08 15:44:53.0331 3016 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/07/08 15:44:53.0410 3016 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/07/08 15:44:53.0528 3016 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/07/08 15:44:53.0626 3016 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/07/08 15:44:53.0677 3016 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/08 15:44:53.0706 3016 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/08 15:44:53.0838 3016 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\Windows\system32\DRIVERS\wanatw4.sys
2011/07/08 15:44:53.0970 3016 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/07/08 15:44:54.0113 3016 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/08 15:44:54.0288 3016 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2011/07/08 15:44:54.0602 3016 WinUSB (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUSB.sys
2011/07/08 15:44:54.0707 3016 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/07/08 15:44:54.0845 3016 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/07/08 15:44:54.0966 3016 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/08 15:44:55.0119 3016 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2011/07/08 15:44:55.0180 3016 MBR (0x1B8) (81cd5ec01db0ce57edd853f82462ef27) \Device\Harddisk0\DR0
2011/07/08 15:44:55.0391 3016 Boot (0x1200) (4f6a8f4c009d18060799a7641b0e8e8c) \Device\Harddisk0\DR0\Partition0
2011/07/08 15:44:55.0422 3016 Boot (0x1200) (a6ac6c0ece8222765dbc0e56ef748734) \Device\Harddisk0\DR0\Partition1
2011/07/08 15:44:55.0440 3016 ================================================================================
2011/07/08 15:44:55.0440 3016 Scan finished
2011/07/08 15:44:55.0440 3016 ================================================================================
2011/07/08 15:44:55.0469 1016 Detected object count: 1
2011/07/08 15:44:55.0469 1016 Actual detected object count: 1
2011/07/08 15:45:28.0060 1016 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/07/08 15:45:46.0837 1616 ================================================================================
2011/07/08 15:45:46.0837 1616 Scan started
2011/07/08 15:45:46.0837 1616 Mode: Manual;
2011/07/08 15:45:46.0838 1616 ================================================================================
2011/07/08 15:45:47.0141 1616 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/07/08 15:45:47.0251 1616 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/07/08 15:45:47.0312 1616 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/07/08 15:45:47.0362 1616 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/07/08 15:45:47.0419 1616 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/07/08 15:45:47.0516 1616 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/07/08 15:45:47.0568 1616 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/07/08 15:45:47.0623 1616 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/07/08 15:45:47.0685 1616 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/07/08 15:45:47.0728 1616 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/07/08 15:45:47.0780 1616 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/07/08 15:45:47.0831 1616 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/07/08 15:45:47.0878 1616 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/07/08 15:45:47.0955 1616 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/07/08 15:45:48.0002 1616 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/07/08 15:45:48.0058 1616 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/07/08 15:45:48.0151 1616 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/07/08 15:45:48.0218 1616 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/07/08 15:45:48.0291 1616 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/07/08 15:45:48.0380 1616 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/07/08 15:45:48.0433 1616 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/07/08 15:45:48.0476 1616 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/07/08 15:45:48.0533 1616 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/07/08 15:45:48.0578 1616 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/07/08 15:45:48.0644 1616 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/07/08 15:45:48.0679 1616 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/07/08 15:45:48.0724 1616 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/07/08 15:45:48.0774 1616 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/07/08 15:45:48.0841 1616 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/07/08 15:45:48.0920 1616 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/07/08 15:45:48.0997 1616 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/07/08 15:45:49.0066 1616 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/07/08 15:45:49.0108 1616 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
2011/07/08 15:45:49.0167 1616 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/07/08 15:45:49.0228 1616 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/07/08 15:45:49.0316 1616 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/07/08 15:45:49.0378 1616 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/07/08 15:45:49.0479 1616 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/07/08 15:45:49.0565 1616 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/07/08 15:45:49.0652 1616 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/07/08 15:45:49.0735 1616 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/07/08 15:45:49.0801 1616 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/07/08 15:45:49.0873 1616 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/07/08 15:45:49.0968 1616 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/07/08 15:45:50.0013 1616 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/07/08 15:45:50.0083 1616 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/07/08 15:45:50.0141 1616 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/07/08 15:45:50.0198 1616 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/07/08 15:45:50.0231 1616 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/07/08 15:45:50.0303 1616 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/07/08 15:45:50.0389 1616 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/07/08 15:45:50.0451 1616 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/07/08 15:45:50.0567 1616 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/07/08 15:45:50.0623 1616 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/07/08 15:45:50.0681 1616 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/07/08 15:45:50.0783 1616 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/07/08 15:45:50.0850 1616 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/07/08 15:45:50.0971 1616 HSF_DP (88749fbf8beb18c90e7d6626c8c1910b) C:\Windows\system32\DRIVERS\HSX_DP.sys
2011/07/08 15:45:51.0029 1616 HSXHWBS2 (fe440536bd98af772130dc3a6fe1915f) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
2011/07/08 15:45:51.0122 1616 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
2011/07/08 15:45:51.0209 1616 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/07/08 15:45:51.0255 1616 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/07/08 15:45:51.0315 1616 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/07/08 15:45:51.0378 1616 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/07/08 15:45:51.0527 1616 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys
2011/07/08 15:45:51.0591 1616 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/07/08 15:45:51.0629 1616 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/07/08 15:45:51.0685 1616 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/07/08 15:45:51.0793 1616 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/07/08 15:45:51.0880 1616 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/07/08 15:45:51.0955 1616 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/07/08 15:45:51.0999 1616 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/07/08 15:45:52.0076 1616 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/07/08 15:45:52.0133 1616 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/07/08 15:45:52.0186 1616 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/07/08 15:45:52.0212 1616 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/07/08 15:45:52.0287 1616 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/07/08 15:45:52.0389 1616 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/07/08 15:45:52.0483 1616 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/07/08 15:45:52.0565 1616 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/07/08 15:45:52.0613 1616 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/07/08 15:45:52.0652 1616 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/07/08 15:45:52.0741 1616 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/07/08 15:45:52.0826 1616 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/07/08 15:45:52.0861 1616 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/07/08 15:45:52.0899 1616 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/07/08 15:45:52.0954 1616 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/07/08 15:45:53.0000 1616 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/07/08 15:45:53.0051 1616 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/07/08 15:45:53.0112 1616 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/07/08 15:45:53.0141 1616 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/07/08 15:45:53.0231 1616 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/07/08 15:45:53.0353 1616 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/07/08 15:45:53.0431 1616 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/07/08 15:45:53.0517 1616 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/07/08 15:45:53.0607 1616 mrxsmb (5fe5cf325f5b02ebc60832d3440cb414) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/07/08 15:45:53.0638 1616 mrxsmb10 (30b9c769446af379a2afb72b0392604d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/07/08 15:45:53.0666 1616 mrxsmb20 (fea239b3ec4877e2b7e23204af589ddf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/07/08 15:45:53.0751 1616 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/07/08 15:45:53.0788 1616 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/07/08 15:45:53.0859 1616 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/07/08 15:45:53.0893 1616 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/07/08 15:45:53.0967 1616 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/07/08 15:45:54.0016 1616 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/07/08 15:45:54.0057 1616 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/07/08 15:45:54.0165 1616 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/07/08 15:45:54.0220 1616 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/07/08 15:45:54.0274 1616 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/07/08 15:45:54.0355 1616 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/07/08 15:45:54.0460 1616 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/07/08 15:45:54.0512 1616 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/07/08 15:45:54.0608 1616 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/07/08 15:45:54.0660 1616 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/07/08 15:45:54.0727 1616 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/07/08 15:45:54.0774 1616 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/07/08 15:45:54.0817 1616 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/07/08 15:45:54.0906 1616 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/07/08 15:45:54.0987 1616 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/07/08 15:45:55.0092 1616 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/07/08 15:45:55.0148 1616 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/07/08 15:45:55.0263 1616 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/07/08 15:45:55.0333 1616 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/07/08 15:45:55.0385 1616 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/07/08 15:45:55.0499 1616 NVENETFD (d668632606d1cebf0b6ec64c1df7ed6f) C:\Windows\system32\DRIVERS\nvmfdx32.sys
2011/07/08 15:45:55.0762 1616 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/07/08 15:45:55.0922 1616 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/07/08 15:45:56.0017 1616 nvrd32 (6f5bb0b40d251351a913b61ba9d64b3f) C:\Windows\system32\drivers\nvrd32.sys
2011/07/08 15:45:56.0095 1616 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\drivers\nvsmu.sys
2011/07/08 15:45:56.0203 1616 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/07/08 15:45:56.0299 1616 nvstor32 (1a649b87a7b7c1220a2b16b121f2198e) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/07/08 15:45:56.0411 1616 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/07/08 15:45:56.0564 1616 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/07/08 15:45:56.0661 1616 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/07/08 15:45:56.0783 1616 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/07/08 15:45:56.0852 1616 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/07/08 15:45:56.0996 1616 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/07/08 15:45:57.0048 1616 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
2011/07/08 15:45:57.0156 1616 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/07/08 15:45:57.0234 1616 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/07/08 15:45:57.0394 1616 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/07/08 15:45:57.0470 1616 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/07/08 15:45:57.0580 1616 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/07/08 15:45:57.0676 1616 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
2011/07/08 15:45:57.0796 1616 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/07/08 15:45:57.0869 1616 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/07/08 15:45:57.0936 1616 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/07/08 15:45:57.0999 1616 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/07/08 15:45:58.0066 1616 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/07/08 15:45:58.0175 1616 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/07/08 15:45:58.0234 1616 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/07/08 15:45:58.0346 1616 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/07/08 15:45:58.0445 1616 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/07/08 15:45:58.0532 1616 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/07/08 15:45:58.0577 1616 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/07/08 15:45:58.0696 1616 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/07/08 15:45:58.0867 1616 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/07/08 15:45:58.0941 1616 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/07/08 15:45:59.0036 1616 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/07/08 15:45:59.0123 1616 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/07/08 15:45:59.0192 1616 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/07/08 15:45:59.0255 1616 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/07/08 15:45:59.0357 1616 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/07/08 15:45:59.0433 1616 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/07/08 15:45:59.0511 1616 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/07/08 15:45:59.0579 1616 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/07/08 15:45:59.0661 1616 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/07/08 15:45:59.0725 1616 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/07/08 15:45:59.0781 1616 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/07/08 15:45:59.0900 1616 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/07/08 15:45:59.0978 1616 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/07/08 15:46:00.0122 1616 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/07/08 15:46:00.0122 1616 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/07/08 15:46:00.0138 1616 sptd - detected LockedFile.Multi.Generic (1)
2011/07/08 15:46:00.0240 1616 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/07/08 15:46:00.0296 1616 srv2 (a5940ca32ed206f90be9fabdf6e92de4) C:\Windows\system32\DRIVERS\srv2.sys
2011/07/08 15:46:00.0348 1616 srvnet (37aa1d560d5fa486c4b11c2f276ada61) C:\Windows\system32\DRIVERS\srvnet.sys
2011/07/08 15:46:00.0501 1616 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/07/08 15:46:00.0586 1616 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/07/08 15:46:00.0652 1616 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/07/08 15:46:00.0710 1616 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/07/08 15:46:00.0860 1616 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/07/08 15:46:00.0959 1616 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/07/08 15:46:01.0079 1616 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/07/08 15:46:01.0178 1616 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/07/08 15:46:01.0242 1616 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/07/08 15:46:01.0331 1616 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/07/08 15:46:01.0433 1616 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/07/08 15:46:01.0561 1616 TPkd (2f4e8077febfe11199ee3b011a34cd18) C:\Windows\system32\drivers\TPkd.sys
2011/07/08 15:46:01.0675 1616 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/07/08 15:46:01.0725 1616 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/07/08 15:46:01.0805 1616 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/07/08 15:46:01.0855 1616 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/07/08 15:46:01.0971 1616 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/07/08 15:46:02.0065 1616 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/07/08 15:46:02.0124 1616 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/07/08 15:46:02.0186 1616 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/07/08 15:46:02.0251 1616 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/07/08 15:46:02.0309 1616 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/07/08 15:46:02.0423 1616 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
2011/07/08 15:46:02.0531 1616 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/07/08 15:46:02.0630 1616 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/07/08 15:46:02.0699 1616 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/07/08 15:46:02.0812 1616 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/07/08 15:46:02.0869 1616 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
2011/07/08 15:46:02.0928 1616 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/07/08 15:46:03.0018 1616 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/07/08 15:46:03.0113 1616 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/07/08 15:46:03.0201 1616 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/07/08 15:46:03.0286 1616 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/07/08 15:46:03.0342 1616 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/07/08 15:46:03.0406 1616 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/07/08 15:46:03.0474 1616 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/07/08 15:46:03.0556 1616 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/07/08 15:46:03.0609 1616 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/07/08 15:46:03.0725 1616 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/07/08 15:46:03.0841 1616 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/07/08 15:46:03.0946 1616 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/07/08 15:46:04.0044 1616 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/07/08 15:46:04.0095 1616 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/08 15:46:04.0120 1616 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/07/08 15:46:04.0214 1616 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\Windows\system32\DRIVERS\wanatw4.sys
2011/07/08 15:46:04.0321 1616 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/07/08 15:46:04.0423 1616 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/07/08 15:46:04.0613 1616 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2011/07/08 15:46:04.0787 1616 WinUSB (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUSB.sys
2011/07/08 15:46:04.0892 1616 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
2011/07/08 15:46:05.0031 1616 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/07/08 15:46:05.0118 1616 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/07/08 15:46:05.0254 1616 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2011/07/08 15:46:05.0315 1616 MBR (0x1B8) (81cd5ec01db0ce57edd853f82462ef27) \Device\Harddisk0\DR0
2011/07/08 15:46:05.0501 1616 Boot (0x1200) (4f6a8f4c009d18060799a7641b0e8e8c) \Device\Harddisk0\DR0\Partition0
2011/07/08 15:46:05.0526 1616 Boot (0x1200) (a6ac6c0ece8222765dbc0e56ef748734) \Device\Harddisk0\DR0\Partition1
2011/07/08 15:46:05.0557 1616 ================================================================================
2011/07/08 15:46:05.0557 1616 Scan finished
2011/07/08 15:46:05.0557 1616 ================================================================================
2011/07/08 15:46:05.0585 2968 Detected object count: 1
2011/07/08 15:46:05.0585 2968 Actual detected object count: 1
2011/07/08 15:46:15.0279 2968 LockedFile.Multi.Generic(sptd) - User select action: Skip
2011/07/08 15:48:51.0742 2476 Deinitialize success
Here is the ComboFix log.
ComboFix 11-07-08.03 - Lycan 07/08/2011 15:52:37.1.1 - x86
Running from: c:\users\Lycan\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ErrorSmart
c:\program files\ErrorSmart\DataBase.ref
c:\program files\ErrorSmart\ErrorSmart.exe
c:\program files\ErrorSmart\ErrorSmart.url
c:\program files\FLV Direct Player
c:\program files\FLV Direct Player\downloading.swf
c:\program files\FLV Direct Player\FLVPlayer.exe
c:\program files\FLV Direct Player\player.swf
c:\program files\FLV Direct Player\preload.swf
c:\program files\FLV Direct Player\Skin\DirectFLV\Button.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\Logo.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\skin.xml
c:\program files\FLV Direct Player\Skin\DirectFLV\SysCloseButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\SysMaxButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\SysMinButton.bmp
c:\program files\FLV Direct Player\Skin\DirectFLV\Window.bmp
c:\program files\FLV Direct Player\uninstall.exe
c:\program files\somototoolbar\vmNTemplatex.dll
c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart
c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart\ErrorSmart on the Web.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart\ErrorSmart.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\FLV Direct Player.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\Uninstall FLV Direct Player.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\HeroCodec
c:\programdata\Microsoft\Windows\Start Menu\Programs\HeroCodec\Uninstall.lnk
c:\users\Lycan\AppData\Local\Temp\swtlib-32\swt-gdip-win32-3650.dll
c:\users\Lycan\AppData\Local\Temp\swtlib-32\swt-win32-3650.dll
c:\users\Lycan\AppData\Roaming\.#
c:\users\Lycan\AppData\Roaming\ErrorSmart
c:\users\Lycan\AppData\Roaming\ErrorSmart\Log\2011 Feb 04 - 07_15_44 PM_141.log
c:\users\Lycan\AppData\Roaming\ErrorSmart\Registry Backups\2011-02-04_19-17-11.reg
c:\users\Lycan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HeroCodec
c:\users\Lycan\hosts
c:\users\Public\Desktop\ErrorSmart.lnk
c:\users\Public\Desktop\FLV Direct Player.lnk
c:\users\Public\WINDOWS
c:\users\Public\WINDOWS\DigitalLocker\enUs\BITSCTRS.INI
c:\users\Public\WINDOWS\DigitalLocker\enUs\DXG.INI
c:\users\Public\WINDOWS\Microsoft.Net\Authmen\DJSVS.INI
c:\users\Public\WINDOWS\MSAgent\Chars\DRVLOCK.SYS
c:\users\Public\WINDOWS\MSAgent\Chars\SYMBIOS.SYS
c:\users\Public\WINDOWS\PLA\System\EPCL5UI.INI
c:\users\Public\WINDOWS\SoftwareDistribution\DataStore\Logs\EPNPVE3N.INI
c:\users\Public\WINDOWS\SoftwareDistribution\DataStore\Logs\MSDFMAP.INI
c:\users\Public\WINDOWS\WindowsMobile\enUs\BRMTBIDI.INI
c:\users\Public\WINDOWS\WindowsMobile\enUs\EWPKCLNT.INI
c:\windows\system32\AutoRun.inf
c:\windows\system32\Filters
c:\windows\system32\Filters\AviSplitter.ax
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_78er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_doppelte_99er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\andreas_einfache_99er.matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's Heavy Compression Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's High Quality Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\CG-Animation Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-best-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-better-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\hvs-good-picture.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\MPEG.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\pvcd.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V3.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V5.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Standard.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Ultimate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Ultra Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\custom matrices\Very Low Bitrate Matrix.xcm
c:\windows\system32\Filters\ffdshow\dict\Czech.dic
c:\windows\system32\Filters\ffdshow\dict\dicts.txt
c:\windows\system32\Filters\ffdshow\dict\Greek.dic
c:\windows\system32\Filters\ffdshow\dict\Polski.dic
c:\windows\system32\Filters\ffdshow\ff_kernelDeint.dll
c:\windows\system32\Filters\ffdshow\ff_liba52.dll
c:\windows\system32\Filters\ffdshow\ff_libdts.dll
c:\windows\system32\Filters\ffdshow\ff_libfaad2.dll
c:\windows\system32\Filters\ffdshow\ff_libmad.dll
c:\windows\system32\Filters\ffdshow\ff_realaac.dll
c:\windows\system32\Filters\ffdshow\ff_samplerate.dll
c:\windows\system32\Filters\ffdshow\ff_theora.dll
c:\windows\system32\Filters\ffdshow\ff_tremor.dll
c:\windows\system32\Filters\ffdshow\ff_unrar.dll
c:\windows\system32\Filters\ffdshow\ff_wmv9.dll
c:\windows\system32\Filters\ffdshow\ff_x264.dll
c:\windows\system32\Filters\ffdshow\ffdshow.ax
c:\windows\system32\Filters\ffdshow\ffdshow.ax.manifest
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1028.tc
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1029.cz
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1031.de
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1033.en
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1034.es
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1036.fr
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1038.hu
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1040.it
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.ja
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.jp
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1045.pl
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1046.br
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1049.ru
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1051.sk
c:\windows\system32\Filters\ffdshow\languages\ffdshow.1053.se
c:\windows\system32\Filters\ffdshow\languages\ffdshow.2052.sc
c:\windows\system32\Filters\ffdshow\libavcodec.dll
c:\windows\system32\Filters\ffdshow\libmpeg2_ff.dll
c:\windows\system32\Filters\ffdshow\libmplayer.dll
c:\windows\system32\Filters\ffdshow\reg\ffdshow.reg
c:\windows\system32\Filters\ffdshow\reg\reg.exe
c:\windows\system32\Filters\ffdshow\reg\rempc.reg
c:\windows\system32\Filters\ffdshow\TomsMoComp_ff.dll
c:\windows\system32\Filters\FLVSplitter.ax
c:\windows\system32\Filters\MatroskaSplitter.ax
c:\windows\system32\Filters\MP4Splitter.ax
c:\windows\system32\Filters\Quicktime.ax
c:\windows\system32\Filters\RealMediaSplitter.ax
c:\windows\system32\Filters\VSFilter.dll
c:\windows\system32\jusched.exe
c:\windows\UA000106.DLL
.
.
((((((((((((((((((((((((( Files Created from 2011-06-08 to 2011-07-08 )))))))))))))))))))))))))))))))
.
.
2011-07-08 23:06 . 2011-07-08 23:06 0 ---ha-w- c:\users\Lycan\AppData\Local\BIT1313.tmp
2011-07-08 21:33 . 2011-07-08 21:33 -------- d-----w- c:\program files\Vuze
2011-07-08 21:33 . 2011-07-08 23:02 -------- d-----w- c:\program files\somototoolbar
2011-07-08 21:33 . 2011-07-08 21:33 -------- d-----w- c:\program files\Vuze FileBulldog Toolbar
2011-07-08 09:36 . 2011-07-08 09:36 -------- d-----w- c:\program files\TruePianos2
2011-07-07 16:49 . 2011-07-07 16:49 388096 ----a-r- c:\users\Lycan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-07 16:49 . 2011-07-07 16:49 -------- d-----w- c:\program files\HJack
2011-07-07 05:57 . 2011-07-08 20:08 -------- d-----w- c:\users\Lycan\AppData\Roaming\PFStaticIP
2011-07-07 05:56 . 2011-07-07 05:56 -------- d-----w- c:\program files\PFStaticIP
2011-07-03 06:44 . 2011-07-03 06:44 -------- d-----w- c:\program files\TC Electronic
2011-07-03 06:09 . 2011-07-03 06:09 -------- d-----w- c:\program files\Focusrite
2011-07-01 23:41 . 2011-07-01 23:41 0 ---ha-w- c:\users\Lycan\AppData\Local\BIT5C90.tmp
2011-06-30 11:11 . 2011-06-30 11:11 -------- d-----w- c:\program files\Sibelius Software
2011-06-30 07:04 . 2011-06-30 07:04 -------- d-----w- c:\program files\uTorrent
2011-06-30 07:01 . 2011-07-08 21:36 -------- d-----w- c:\users\Lycan\AppData\Roaming\uTorrent
2011-06-30 07:01 . 2011-06-30 07:01 -------- d-----w- c:\users\Lycan\AppData\Local\uTorrent
2011-06-30 04:33 . 2011-06-30 04:33 -------- d-----w- c:\program files\EarthLink Accelerated
2011-06-30 04:09 . 2011-06-30 05:39 -------- d-----w- c:\program files\Common Files\EarthLink
2011-06-30 04:09 . 2010-07-30 21:20 69440 ------w- c:\windows\system32\unPPC6000.exe
2011-06-30 04:09 . 2010-07-30 21:20 41792 ------w- c:\windows\system32\ppcwebi.dll
2011-06-30 04:09 . 2010-07-30 21:10 73728 ------w- c:\windows\system32\ppcpanel.cpl
2011-06-30 04:09 . 2010-07-01 18:37 73192 ------w- c:\windows\system32\unPPC.exe
2011-06-30 04:09 . 2010-07-30 21:20 66880 ------w- c:\windows\system32\PPCOUNIN.exe
2011-06-30 04:09 . 2010-07-30 21:20 28992 ------w- c:\windows\system32\PopWait.exe
2011-06-30 04:09 . 2010-07-01 21:08 34136 ------w- c:\windows\system32\RegHero.exe
2011-06-30 04:09 . 2010-07-30 21:20 40600 ------w- c:\windows\system32\PPCClean.exe
2011-06-30 04:09 . 2010-07-30 21:20 255296 ------w- c:\windows\system32\PPCInfo.exe
2011-06-30 04:09 . 2010-07-01 21:08 84992 ------w- c:\windows\system32\ATL70.dll
2011-06-30 04:07 . 2011-06-30 04:10 -------- d-----w- c:\program files\EarthLink
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 03:06 . 2011-06-06 03:06 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-06 03:06 . 2011-06-06 03:06 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-06-06 03:06 . 2011-06-06 03:06 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-06 03:06 . 2011-06-06 03:06 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-06 03:06 . 2011-06-06 03:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-06 03:06 . 2011-06-06 03:06 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-06 03:06 . 2011-06-06 03:06 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-06 03:06 . 2011-06-06 03:06 367104 ----a-w- c:\windows\system32\html.iec
2011-06-06 03:06 . 2011-06-06 03:06 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-06 03:06 . 2011-06-06 03:06 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-06 03:06 . 2011-06-06 03:06 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-06 03:06 . 2011-06-06 03:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-06 03:06 . 2011-06-06 03:06 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-06 03:06 . 2011-06-06 03:06 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-06 03:06 . 2011-06-06 03:06 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-06 03:06 . 2011-06-06 03:06 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-06 03:06 . 2011-06-06 03:06 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-06 03:06 . 2011-06-06 03:06 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-06 03:06 . 2011-06-06 03:06 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-06 03:06 . 2011-06-06 03:06 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-06 03:06 . 2011-06-06 03:06 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-14 23:30 . 2011-04-15 08:40 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C9F58FA8-8BD2-4870-9575-66A8064370D9}\mpengine.dll
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"HostManager"="c:\program files\Common Files\AOL\1210728131\ee\AOLSoftware.exe" [2006-09-26 50736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Bart Station"="c:\program files\EarthLink\ISP\ISP8300\BIN\PPCOLink.exe" [2010-07-30 25920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bitcomet Ultra Accelerator.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bitcomet Ultra Accelerator.lnk
backup=c:\windows\pss\Bitcomet Ultra Accelerator.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 09:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 10:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 11:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2006-11-10 12:12 50736 ----a-w- c:\program files\AOL 9.0\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
2008-03-05 14:30 5980160 ----a-w- c:\program files\Blubster\blubster.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-04-12 22:46 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DPService]
2008-01-15 08:58 90112 ----a-w- c:\program files\HP\DVDPlay\DPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
2007-11-02 01:13 151552 ------w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 05:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2007-04-18 15:01 65536 ----a-w- c:\hp\support\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OsdMaestro]
2007-02-15 11:59 118784 ----a-w- c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedBitVideoAccelerator]
2010-04-20 22:32 1607272 ----a-w- c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-07-12 06:20 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-05-14 13:55 37888 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl8473dbbf;MpKsl8473dbbf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1FBA307A-6816-4BB3-A2F4-077063B5B291}\MpKsl8473dbbf.sys [x]
R1 MpKsl96e53cd6;MpKsl96e53cd6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1FBA307A-6816-4BB3-A2F4-077063B5B291}\MpKsl96e53cd6.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9bbf3acd1fde0;Google Update Service (gupdate1c9bbf3acd1fde0);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-17 691696]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2010-02-26 3623424]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe [2010-04-20 300656]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-12 17:45]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 04:52]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 04:52]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1277242936-3510254915-2159929779-1000Core.job
- c:\users\Lycan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-15 03:47]
.
2011-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1277242936-3510254915-2159929779-1000UA.job
- c:\users\Lycan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-15 03:47]
.
2011-06-28 c:\windows\Tasks\HPCeeScheduleForLycan.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-02-27 20:10]
.
2011-07-04 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-04-11 01:08]
.
2011-02-05 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
2011-02-05 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ebay.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: EarthLink Google Search - c:\program files\EarthLink\Toolbar\SearchUI.dll/search.html
Trusted Zone: wolfquest.org\www
TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D}: NameServer = 93.188.164.35,93.188.160.105
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
MSConfigStartUp-MSC - c:\program files\Microsoft Security Client\msseces.exe
MSConfigStartUp-MySpaceIM - c:\program files\MySpace\IM\MySpaceIM.exe
MSConfigStartUp-prbgqdqm - c:\users\Lycan\AppData\Local\Temp\tsaowrxyy\urxkvobsika.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
AddRemove-184466066.fuse.fender.com - c:\program files\Microsoft Silverlight\4.0.50826.0\Silverlight.Configuration.exe
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1277242936-3510254915-2159929779-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6867C0E-9EA6-49EA-FC10-39D2D5E1B716}*]
"hajifpflpmepclhi"=hex:69,61,66,6c,65,68,63,6a,65,65,62,66,61,69,6c,6a,67,6e,
00,00
"iahkhoofnedabnbabm"=hex:6a,61,63,6c,69,68,6f,6f,6d,6b,66,68,69,70,70,6d,68,6f,
70,62,00,d2
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3016)
c:\program files\Microangelo On Display\MODIcon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\EarthLink\ISP\ISP8300\Browser\Bartshel.exe
c:\program files\EarthLink\ISP\ISP8300\Browser\PPShared.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2011-07-08 16:13:48 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-08 23:13
.
Pre-Run: 11,433,414,656 bytes free
Post-Run: 16,897,085,440 bytes free
.
- - End Of File - - EE648E47C648BE2120027DD5AAE45905
Yes, I'm still with you. I've just gotten back from work. I'll have the logs for you shortly.
I can't download the tool from Kaspersky, something on my PC is blocking their website. However, I found a slightly older version (from last year) on Pirate Bay, so I'll get that. Apologies, its the best I can do given the circumstances. :\