Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default Windows Update Hell

    Been having this for a while, and I think its affecting other functions of my system now, so I've just about had it it with this. Basically put, Windows Update cannot check for updates, neither can I access the update website manually. The same pretty much goes for any other virus/malware scanning/removal program that needs updates of virus definitions (i.e. Microsoft Security Essentials, Avast, etc.). Latest error code is 80246002. Sometimes the updates come through, but often it will fail. I have reason to belive its some type of malware, but thus far all my attempts to locate it have failed. Any help is appreciated!

    Attached is the most recent HiJackThis log. Unfortunately, whatever is ailing my PC is preventing me from downloading either Malwarebytes or Superantispyware, so all I've got is the HijackThis Log.




    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 9:56:16 AM, on 7/7/2011
    Platform: Windows Vista SP2 (WinNT

    6.00.1906)
    MSIE: Internet Explorer v9.00

    (9.00.8112.16421)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Common

    Files\aol\1210728131\ee\aolsoftware.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Java\Java

    Update\jusched.exe
    C:\Program Files\AVAST

    Software\Avast\AvastUI.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program

    Files\Google\GoogleToolbarNotifier\GoogleToo

    lbarNotifier.exe
    C:\Program Files\AOL 9.0\waol.exe
    C:\Program Files\EarthLink\ISP\ISP8300

    \Browser\Bartshel.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\EarthLink\ISP\ISP8300

    \Browser\PPShared.exe
    C:\Program Files\AOL 9.0\shellmon.exe
    C:\Program Files\Common

    Files\AOL\Topspeed\3.0\aoltpsd3.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Windows\system32\rundll32.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\A

    pplication\chrome.exe
    C:\Users\Lycan\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Default_Page_URL =

    HP - United States | Laptop Computers, Desktops, Printers, Servers and more

    TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar

    io&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://start.earthlink.net/AL/Search
    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Start Page =

    eBay | Electronics, Cars, Clothing, Collectibles and More Online Shopping
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Default_Page_URL =

    HP - United States | Laptop Computers, Desktops, Printers, Servers and more

    TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar

    io&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Default_Search_URL =

    Bing
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Search Page =

    Bing
    R0 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Start Page =

    HP - United States | Laptop Computers, Desktops, Printers, Servers and more

    TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presar

    io&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet

    Explorer\Search,SearchAssistant =

    http://start.earthlink.net/AL/Search
    R0 - HKLM\Software\Microsoft\Internet

    Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

    C:\Program Files\Common

    Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: EarthLink PopUp Blocker V2 -

    {512ACF1B-64D9-4928-B382-A80556F28DB4} -

    C:\Program

    Files\EarthLink\Toolbar\ElnkPub.dll
    O2 - BHO: Accelerator Plugin - {656EC4B7-

    072B-4698-B504-2A414C1F0037} - C:\PROGRA~1

    \EARTHL~3\PRPL_I~1.DLL
    O2 - BHO: avast! WebRep - {8E5E2654-AD2D-

    48bf-AC2D-D17F00898D06} - C:\Program

    Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Earthlink Protection BHO -

    {9579D574-D4D8-4335-9560-FE8641A013BD} -

    C:\Program

    Files\EarthLink\Toolbar\ProtctIE.dll
    O2 - BHO: Google Toolbar Notifier BHO -

    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -

    C:\Program

    Files\Google\GoogleToolbarNotifier\5.6.5612.

    1312\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper -

    {DBC80044-A445-435b-BC74-9C25C1C588A9} -

    C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Uninstall Legacy Earthlink Toolbar

    - {E713904C-DF05-4C79-BBAD-02DB923253BE} -

    C:\Program

    Files\EarthLink\Toolbar\uninsttb.dll
    O2 - BHO: Cooliris Plug-In for Internet

    Explorer - {EAEE5C74-6D0D-4aca-9232-

    0DA4A7B866BA} - C:\Program

    Files\PicLensIE\cooliris.dll
    O3 - Toolbar: DAEMON Tools Toolbar -

    {32099AAC-C132-4136-9E9A-4E364A424E17} -

    C:\Program Files\DAEMON Tools

    Toolbar\DTToolbar.dll
    O3 - Toolbar: avast! WebRep - {8E5E2654-

    AD2D-48bf-AC2D-D17F00898D06} - C:\Program

    Files\AVAST Software\Avast\aswWebRepIE.dll
    O3 - Toolbar: EarthLink Toolbar - {C7768536

    -96F8-4001-B1A2-90EE21279187} - C:\Program

    Files\EarthLink\Toolbar\Toolbar.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program

    Files\Common Files\AOL\1210728131

    \ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

    C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter]

    RUNDLL32.EXE C:\Windows\system32

    \NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SwitchBoard] C:\Program

    Files\Common

    Files\Adobe\SwitchBoard\SwitchBoard.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched]

    "C:\Program Files\Common Files\Java\Java

    Update\jusched.exe"
    O4 - HKLM\..\Run: [avast] "C:\Program

    Files\AVAST Software\Avast\avastUI.exe"

    /nogui
    O4 - HKLM\..\Run: [Bart Station] C:\Program

    Files\EarthLink\ISP\ISP8300\BIN\PPCOLink.exe

    -STATION
    O4 - HKLM\..\Run: [Windows Defender] %

    ProgramFiles%\Windows Defender\MSASCui.exe

    -hide
    O4 - HKCU\..\Run: [Sidebar] C:\Program

    Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [swg] "C:\Program

    Files\Google\GoogleToolbarNotifier\GoogleToo

    lbarNotifier.exe"
    O4 - HKCU\..\Run: [AOL Fast Start]

    "C:\Program Files\AOL 9.0\AOL.EXE" -b
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate]

    C:\Windows\system32

    \Macromed\Flash\FlashUtil10i_ActiveX.exe -

    update activex
    O4 - Startup: Adobe Gamma.lnk = C:\Program

    Files\Common Files\Adobe\Calibration\Adobe

    Gamma Loader.exe
    O8 - Extra context menu item: Add to Google

    Photos Screensa&ver -

    res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: EarthLink

    Google Search - res://C:\Program

    Files\EarthLink\Toolbar\SearchUI.dll/search.

    html
    O9 - Extra button: Launch Cooliris -

    {3437D640-C91A-458f-89F5-B9095EA4C28B} -

    C:\Program Files\PicLensIE\cooliris.dll
    O11 - Options group: [ACCELERATED_GRAPHICS]

    Accelerated graphics
    O17 -

    HKLM\System\CCS\Services\Tcpip\..\{2058ABE3

    -0B7D-4978-A86E-673F575ACF9D}: NameServer =

    93.188.164.35,93.188.160.105
    O17 - HKLM\System\CS1

    \Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E

    -673F575ACF9D}: NameServer =

    93.188.164.35,93.188.160.105
    O17 - HKLM\System\CS2

    \Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E

    -673F575ACF9D}: NameServer =

    93.188.164.35,93.188.160.105
    O17 - HKLM\System\CS3

    \Services\Tcpip\..\{2058ABE3-0B7D-4978-A86E

    -673F575ACF9D}: NameServer =

    93.188.164.35,93.188.160.105
    O22 - SharedTaskScheduler: Component

    Categories cache daemon - {8C7461EF-2B13-

    11d2-BE35-3078302C2030} -

    C:\Windows\system32\browseui.dll
    O23 - Service: Adobe LM Service - Adobe

    Systems - C:\Program Files\Common

    Files\Adobe Systems

    Shared\Service\Adobelmsvc.exe
    O23 - Service: AOL Connectivity Service (AOL

    ACS) - AOL LLC - C:\Program Files\Common

    Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: avast! Antivirus - AVAST

    Software - C:\Program Files\AVAST

    Software\Avast\AvastSvc.exe
    O23 - Service:

    ##Id_String1.6844F930_1628_4223_B5CC_5BB94B8

    79762## (Bonjour Service) - Apple Computer,

    Inc. - C:\Program

    Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service -

    Macrovision Europe Ltd. - C:\Program

    Files\Common Files\Macrovision

    Shared\FLEXnet

    Publisher\FNPLicensingService.exe
    O23 - Service: Google Update Service

    (gupdate1c9bbf3acd1fde0)

    (gupdate1c9bbf3acd1fde0) - Google Inc. -

    C:\Program

    Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service

    (gupdatem) (gupdatem) - Google Inc. -

    C:\Program

    Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater

    (gusvc) - Google - C:\Program

    Files\Google\Common\Google

    Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service -

    Hewlett-Packard - c:\Program Files\Hewlett-

    Packard\HP Health Check\hphc_service.exe
    O23 - Service: LightScribeService Direct

    Disc Labeling Service (LightScribeService) -

    Hewlett-Packard Company - C:\Program

    Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NIHardwareService - Native

    Instruments GmbH - C:\Program Files\Common

    Files\Native

    Instruments\Hardware\NIHardwareService.exe
    O23 - Service: NVIDIA Display Driver Service

    (nvsvc) - NVIDIA Corporation -

    C:\Windows\system32\nvvsvc.exe
    O23 - Service: Cyberlink RichVideo Service

    (CRVS) (RichVideo) - Unknown owner -

    C:\Program Files\CyberLink\Shared

    Files\RichVideo.exe
    O23 - Service: Adobe SwitchBoard

    (SwitchBoard) - Adobe Systems Incorporated -

    C:\Program Files\Common

    Files\Adobe\SwitchBoard\SwitchBoard.exe
    O23 - Service: VideoAcceleratorService -

    Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1

    \VideoAcceleratorService.exe
    O23 - Service: XAudioService - Conexant

    Systems, Inc. - C:\Windows\system32

    \DRIVERS\xaudio.exe

    --
    End of file - 9136 bytes

  2. #2
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello and welcome to Help2Go

    We apologize for the delay in responding to your request for help. Here at Help2Go we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

    Please take note:

    1. If you have since resolved the original problem you were having, we would appreciate you letting us know.
    2. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
      • If you are unsure about any of these characteristics just post what you can and we will guide you.
    3. Please tell us if you have your original Windows CD/DVD available.
    4. If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information.
    5. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.
    6. Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.
    7. If you have already posted a DDS log, please do so again, as your situation may have changed.
    8. Use the 'Add Reply' and add the new log to this thread.


    We need to see some information about what is happening in your machine. Please perform the following scan again:

    • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
    • Notepad will open with the results.
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.
    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control HERE


    We also need a new log from the GMER anti-rootkit Scanner.

    Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

    Please first disable any CD emulation programs using the steps found in this topic:

    Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:


    Note:
    If you are unable to run a Gmer scan due the fact you are running a64bit machine please run the following tool and post its log.

    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.




    Thanks and again sorry for the delay.
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  3. #3
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default

    OK, apologies for the delay. The Gmer scan took a while. Here's the DDS log, and attached are the DDS attach file and the Gmer log.



    .
    DDS (Ver_2011-06-23.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421
    Run by Lycan at 23:53:19 on 2011-07-07
    Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1918.974 [GMT -7:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\svchost.exe -k Akamai
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Common Files\aol\1210728131\ee\aolsoftware.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\AOL 9.0\waol.exe
    C:\Program Files\EarthLink\ISP\ISP8300\Browser\Bartshel.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\EarthLink\ISP\ISP8300\Browser\PPShared.exe
    C:\Program Files\AOL 9.0\shellmon.exe
    C:\Windows\System32\notepad.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Lycan\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.ebay.com/
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://start.earthlink.net/AL/Search
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://start.earthlink.net/AL/Search
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: ElnkPubBHO Class: {512acf1b-64d9-4928-b382-a80556f28db4} - c:\program files\earthlink\toolbar\ElnkPub.dll
    BHO: Accelerator Plugin: {656ec4b7-072b-4698-b504-2a414c1f0037} - c:\progra~1\earthl~3\PRPL_I~1.DLL
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: ElnkProtectionBHO Class: {9579d574-d4d8-4335-9560-fe8641a013bd} - c:\program files\earthlink\toolbar\ProtctIE.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: ElnkLegacyUninstBHO Class: {e713904c-df05-4c79-bbad-02db923253be} - c:\program files\earthlink\toolbar\uninsttb.dll
    BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    TB: EarthLink Toolbar: {c7768536-96f8-4001-b1a2-90ee21279187} - c:\program files\earthlink\toolbar\Toolbar.dll
    TB: {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No File
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [AOL Fast Start] "c:\program files\aol 9.0\AOL.EXE" -b
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [HostManager] c:\program files\common files\aol\1210728131\ee\AOLSoftware.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    mRun: [Bart Station] c:\program files\earthlink\isp\isp8300\bin\PPCOLink.exe -STATION
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    StartupFolder: c:\users\lycan\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: EarthLink Google Search - c:\program files\earthlink\toolbar\SearchUI.dll/search.html
    IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll
    Trusted Zone: wolfquest.org\www
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D} : NameServer = 93.188.164.35,93.188.160.105
    TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D} : DhcpNameServer = 192.168.1.1
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-5 441176]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-6-5 307928]
    R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-6-5 19544]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-6-5 53592]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-6-5 42184]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 NIHardwareService;NIHardwareService;c:\program files\common files\native instruments\hardware\NIHardwareService.exe [2010-2-26 3623424]
    R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate1c9bbf3acd1fde0;Google Update Service (gupdate1c9bbf3acd1fde0);c:\program files\google\update\GoogleUpdate.exe [2009-4-12 133104]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-4-12 133104]
    S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== File Associations ===============
    .
    regfile=regedit.exe "%1" %*
    scrfile="%1" %*
    .
    =============== Created Last 30 ================
    .
    2011-07-07 16:49:45 388096 ----a-r- c:\users\lycan\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-07-07 16:49:44 -------- d-----w- c:\program files\HJack
    2011-07-07 05:57:09 -------- d-----w- c:\users\lycan\appdata\roaming\PFStaticIP
    2011-07-07 05:56:58 -------- d-----w- c:\program files\PFStaticIP
    2011-07-03 06:44:46 -------- d-----w- c:\program files\TC Electronic
    2011-07-03 06:09:24 -------- d-----w- c:\program files\Focusrite
    2011-07-01 23:41:31 0 ---ha-w- c:\users\lycan\appdata\local\BIT5C90.tmp
    2011-06-30 11:11:11 -------- d-----w- c:\program files\Sibelius Software
    2011-06-30 07:04:20 -------- d-----w- c:\program files\uTorrent
    2011-06-30 07:01:26 -------- d-----w- c:\users\lycan\appdata\roaming\uTorrent
    2011-06-30 07:01:26 -------- d-----w- c:\users\lycan\appdata\local\uTorrent
    2011-06-30 04:33:09 -------- d-----w- c:\program files\EarthLink Accelerated
    2011-06-30 04:09:22 -------- d-----w- c:\program files\common files\EarthLink
    2011-06-30 04:09:20 69440 ------w- c:\windows\system32\unPPC6000.exe
    2011-06-30 04:09:19 73728 ------w- c:\windows\system32\ppcpanel.cpl
    2011-06-30 04:09:19 73192 ------w- c:\windows\system32\unPPC.exe
    2011-06-30 04:09:19 41792 ------w- c:\windows\system32\ppcwebi.dll
    2011-06-30 04:09:17 66880 ------w- c:\windows\system32\PPCOUNIN.exe
    2011-06-30 04:09:17 34136 ------w- c:\windows\system32\RegHero.exe
    2011-06-30 04:09:17 28992 ------w- c:\windows\system32\PopWait.exe
    2011-06-30 04:09:16 40600 ------w- c:\windows\system32\PPCClean.exe
    2011-06-30 04:09:16 255296 ------w- c:\windows\system32\PPCInfo.exe
    2011-06-30 04:09:06 84992 ------w- c:\windows\system32\ATL70.dll
    2011-06-30 04:07:31 -------- d-----w- c:\program files\EarthLink
    .
    ==================== Find3M ====================
    .
    2011-05-10 12:10:59 40112 ----a-w- c:\windows\avastSS.scr
    2011-05-10 12:03:54 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-05-10 11:59:44 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2011-04-13 22:40:10 4284416 ----a-w- c:\windows\system32\GPhotos.scr
    .
    ============= FINISH: 23:54:06.48 ===============
    Attached Files

  4. #4
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello,

    We will begin cleaning your machine. Note this could take a few tries. I will let you know when your machine is clean of Malware.

    1.
    We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
    • Open Windows Defender.
    • Click on Tools, General Settings.
    • Scroll down and uncheck Turn on real-time protection (recommended).
    • After you uncheck this, click on the Save button and close Windows Defender.
    After all of the fixes are complete it is very important that you enable Real-time Protection again.

    2.
    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
    Be sure to download TDSSKiller.exe (v2.5.6.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.
    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.5.6.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C.
    • Copy and paste the contents of that file in your next reply.



    3.
    Install Recovery Console and Run ComboFix

    This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
    • Close any open windows, including this one.
    • Double click on ComboFix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • If you did not have it installed, you will see the prompt below. Choose YES.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
    should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    • Click on Yes, to continue scanning for malware.
    • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
    Leave your computer alone while ComboFix is running.
    ComboFix will restart your computer if malware is found; allow it to do so.


    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.


    Things to include in your next reply::
    TDSSKiller log
    Combofix.txt
    How is your machine running now?
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  5. #5
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default

    OK, both are done. Thus far the PC seems a little faster, some diskspace gained, but other than that we're still in the same boat.

    Here is the TDSKiller log.


    2011/07/08 15:44:25.0544 1744 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21
    2011/07/08 15:44:26.0176 1744 ================================================================================
    2011/07/08 15:44:26.0176 1744 SystemInfo:
    2011/07/08 15:44:26.0176 1744
    2011/07/08 15:44:26.0176 1744 OS Version: 6.0.6002 ServicePack: 2.0
    2011/07/08 15:44:26.0176 1744 Product type: Workstation
    2011/07/08 15:44:26.0176 1744 ComputerName: HOMOLUPISSTUDIO
    2011/07/08 15:44:26.0176 1744 UserName: Lycan
    2011/07/08 15:44:26.0176 1744 Windows directory: C:\Windows
    2011/07/08 15:44:26.0176 1744 System windows directory: C:\Windows
    2011/07/08 15:44:26.0177 1744 Processor architecture: Intel x86
    2011/07/08 15:44:26.0177 1744 Number of processors: 1
    2011/07/08 15:44:26.0177 1744 Page size: 0x1000
    2011/07/08 15:44:26.0177 1744 Boot type: Normal boot
    2011/07/08 15:44:26.0177 1744 ================================================================================
    2011/07/08 15:44:26.0785 1744 Initialize success
    2011/07/08 15:44:29.0669 3016 ================================================================================
    2011/07/08 15:44:29.0669 3016 Scan started
    2011/07/08 15:44:29.0669 3016 Mode: Manual;
    2011/07/08 15:44:29.0669 3016 ================================================================================
    2011/07/08 15:44:30.0385 3016 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
    2011/07/08 15:44:30.0636 3016 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
    2011/07/08 15:44:30.0788 3016 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
    2011/07/08 15:44:30.0855 3016 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
    2011/07/08 15:44:30.0937 3016 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
    2011/07/08 15:44:31.0125 3016 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
    2011/07/08 15:44:31.0245 3016 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
    2011/07/08 15:44:31.0324 3016 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
    2011/07/08 15:44:31.0411 3016 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
    2011/07/08 15:44:31.0479 3016 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
    2011/07/08 15:44:31.0573 3016 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
    2011/07/08 15:44:31.0649 3016 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
    2011/07/08 15:44:31.0755 3016 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
    2011/07/08 15:44:31.0989 3016 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
    2011/07/08 15:44:32.0061 3016 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
    2011/07/08 15:44:32.0142 3016 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
    2011/07/08 15:44:32.0227 3016 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
    2011/07/08 15:44:32.0410 3016 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
    2011/07/08 15:44:32.0500 3016 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
    2011/07/08 15:44:32.0672 3016 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
    2011/07/08 15:44:32.0751 3016 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
    2011/07/08 15:44:32.0810 3016 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
    2011/07/08 15:44:32.0892 3016 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
    2011/07/08 15:44:32.0953 3016 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
    2011/07/08 15:44:33.0012 3016 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
    2011/07/08 15:44:33.0069 3016 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
    2011/07/08 15:44:33.0225 3016 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
    2011/07/08 15:44:33.0433 3016 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
    2011/07/08 15:44:33.0500 3016 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
    2011/07/08 15:44:33.0646 3016 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
    2011/07/08 15:44:33.0747 3016 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
    2011/07/08 15:44:33.0908 3016 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
    2011/07/08 15:44:33.0950 3016 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
    2011/07/08 15:44:34.0001 3016 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
    2011/07/08 15:44:34.0037 3016 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
    2011/07/08 15:44:34.0212 3016 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
    2011/07/08 15:44:34.0445 3016 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
    2011/07/08 15:44:34.0530 3016 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
    2011/07/08 15:44:34.0632 3016 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
    2011/07/08 15:44:34.0719 3016 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
    2011/07/08 15:44:34.0818 3016 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
    2011/07/08 15:44:34.0910 3016 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
    2011/07/08 15:44:34.0982 3016 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
    2011/07/08 15:44:35.0086 3016 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
    2011/07/08 15:44:35.0172 3016 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
    2011/07/08 15:44:35.0267 3016 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
    2011/07/08 15:44:35.0391 3016 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
    2011/07/08 15:44:35.0507 3016 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
    2011/07/08 15:44:35.0749 3016 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
    2011/07/08 15:44:35.0854 3016 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
    2011/07/08 15:44:35.0981 3016 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
    2011/07/08 15:44:36.0051 3016 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
    2011/07/08 15:44:36.0326 3016 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
    2011/07/08 15:44:36.0407 3016 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
    2011/07/08 15:44:36.0514 3016 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
    2011/07/08 15:44:36.0613 3016 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
    2011/07/08 15:44:36.0709 3016 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
    2011/07/08 15:44:36.0971 3016 HSF_DP (88749fbf8beb18c90e7d6626c8c1910b) C:\Windows\system32\DRIVERS\HSX_DP.sys
    2011/07/08 15:44:37.0062 3016 HSXHWBS2 (fe440536bd98af772130dc3a6fe1915f) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
    2011/07/08 15:44:37.0173 3016 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
    2011/07/08 15:44:37.0268 3016 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
    2011/07/08 15:44:37.0337 3016 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
    2011/07/08 15:44:37.0432 3016 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
    2011/07/08 15:44:37.0536 3016 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
    2011/07/08 15:44:37.0752 3016 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys
    2011/07/08 15:44:37.0899 3016 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
    2011/07/08 15:44:37.0946 3016 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
    2011/07/08 15:44:38.0018 3016 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    2011/07/08 15:44:38.0185 3016 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
    2011/07/08 15:44:38.0246 3016 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
    2011/07/08 15:44:38.0305 3016 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
    2011/07/08 15:44:38.0465 3016 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
    2011/07/08 15:44:38.0559 3016 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
    2011/07/08 15:44:38.0650 3016 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
    2011/07/08 15:44:38.0711 3016 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
    2011/07/08 15:44:38.0753 3016 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
    2011/07/08 15:44:38.0837 3016 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
    2011/07/08 15:44:38.0997 3016 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
    2011/07/08 15:44:39.0166 3016 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
    2011/07/08 15:44:39.0281 3016 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
    2011/07/08 15:44:39.0363 3016 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
    2011/07/08 15:44:39.0435 3016 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
    2011/07/08 15:44:39.0516 3016 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
    2011/07/08 15:44:39.0601 3016 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
    2011/07/08 15:44:39.0719 3016 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
    2011/07/08 15:44:39.0773 3016 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
    2011/07/08 15:44:39.0920 3016 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
    2011/07/08 15:44:40.0033 3016 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
    2011/07/08 15:44:40.0134 3016 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
    2011/07/08 15:44:40.0204 3016 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
    2011/07/08 15:44:40.0291 3016 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
    2011/07/08 15:44:40.0347 3016 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
    2011/07/08 15:44:40.0594 3016 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
    2011/07/08 15:44:40.0715 3016 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
    2011/07/08 15:44:40.0792 3016 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
    2011/07/08 15:44:40.0890 3016 mrxsmb (5fe5cf325f5b02ebc60832d3440cb414) C:\Windows\system32\DRIVERS\mrxsmb.sys
    2011/07/08 15:44:40.0949 3016 mrxsmb10 (30b9c769446af379a2afb72b0392604d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    2011/07/08 15:44:41.0006 3016 mrxsmb20 (fea239b3ec4877e2b7e23204af589ddf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    2011/07/08 15:44:41.0101 3016 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
    2011/07/08 15:44:41.0146 3016 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
    2011/07/08 15:44:41.0233 3016 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
    2011/07/08 15:44:41.0284 3016 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
    2011/07/08 15:44:41.0366 3016 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
    2011/07/08 15:44:41.0440 3016 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
    2011/07/08 15:44:41.0498 3016 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
    2011/07/08 15:44:41.0605 3016 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
    2011/07/08 15:44:41.0719 3016 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
    2011/07/08 15:44:41.0765 3016 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
    2011/07/08 15:44:41.0854 3016 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
    2011/07/08 15:44:41.0951 3016 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
    2011/07/08 15:44:42.0062 3016 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
    2011/07/08 15:44:42.0157 3016 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
    2011/07/08 15:44:42.0222 3016 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
    2011/07/08 15:44:42.0318 3016 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
    2011/07/08 15:44:42.0423 3016 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
    2011/07/08 15:44:42.0524 3016 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
    2011/07/08 15:44:42.0647 3016 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
    2011/07/08 15:44:42.0804 3016 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
    2011/07/08 15:44:43.0029 3016 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
    2011/07/08 15:44:43.0106 3016 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
    2011/07/08 15:44:43.0238 3016 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
    2011/07/08 15:44:43.0333 3016 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
    2011/07/08 15:44:43.0385 3016 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
    2011/07/08 15:44:43.0491 3016 NVENETFD (d668632606d1cebf0b6ec64c1df7ed6f) C:\Windows\system32\DRIVERS\nvmfdx32.sys
    2011/07/08 15:44:43.0768 3016 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys
    2011/07/08 15:44:44.0270 3016 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
    2011/07/08 15:44:44.0357 3016 nvrd32 (6f5bb0b40d251351a913b61ba9d64b3f) C:\Windows\system32\drivers\nvrd32.sys
    2011/07/08 15:44:44.0436 3016 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\drivers\nvsmu.sys
    2011/07/08 15:44:44.0545 3016 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
    2011/07/08 15:44:44.0656 3016 nvstor32 (1a649b87a7b7c1220a2b16b121f2198e) C:\Windows\system32\DRIVERS\nvstor32.sys
    2011/07/08 15:44:44.0756 3016 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
    2011/07/08 15:44:44.0921 3016 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
    2011/07/08 15:44:44.0993 3016 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
    2011/07/08 15:44:45.0108 3016 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
    2011/07/08 15:44:45.0151 3016 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
    2011/07/08 15:44:45.0310 3016 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
    2011/07/08 15:44:45.0397 3016 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
    2011/07/08 15:44:45.0496 3016 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
    2011/07/08 15:44:45.0567 3016 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
    2011/07/08 15:44:45.0802 3016 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
    2011/07/08 15:44:45.0910 3016 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
    2011/07/08 15:44:46.0021 3016 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
    2011/07/08 15:44:46.0141 3016 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
    2011/07/08 15:44:46.0270 3016 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
    2011/07/08 15:44:46.0435 3016 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
    2011/07/08 15:44:46.0518 3016 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
    2011/07/08 15:44:46.0573 3016 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
    2011/07/08 15:44:46.0648 3016 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
    2011/07/08 15:44:46.0713 3016 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
    2011/07/08 15:44:46.0775 3016 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
    2011/07/08 15:44:46.0877 3016 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
    2011/07/08 15:44:46.0976 3016 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
    2011/07/08 15:44:47.0057 3016 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
    2011/07/08 15:44:47.0110 3016 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
    2011/07/08 15:44:47.0203 3016 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
    2011/07/08 15:44:47.0415 3016 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
    2011/07/08 15:44:47.0523 3016 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
    2011/07/08 15:44:47.0636 3016 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
    2011/07/08 15:44:47.0772 3016 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
    2011/07/08 15:44:47.0866 3016 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
    2011/07/08 15:44:47.0963 3016 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
    2011/07/08 15:44:48.0089 3016 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
    2011/07/08 15:44:48.0165 3016 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
    2011/07/08 15:44:48.0260 3016 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
    2011/07/08 15:44:48.0320 3016 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
    2011/07/08 15:44:48.0419 3016 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
    2011/07/08 15:44:48.0474 3016 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
    2011/07/08 15:44:48.0563 3016 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
    2011/07/08 15:44:48.0732 3016 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
    2011/07/08 15:44:48.0935 3016 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
    2011/07/08 15:44:49.0097 3016 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
    2011/07/08 15:44:49.0097 3016 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
    2011/07/08 15:44:49.0133 3016 sptd - detected LockedFile.Multi.Generic (1)
    2011/07/08 15:44:49.0238 3016 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
    2011/07/08 15:44:49.0283 3016 srv2 (a5940ca32ed206f90be9fabdf6e92de4) C:\Windows\system32\DRIVERS\srv2.sys
    2011/07/08 15:44:49.0388 3016 srvnet (37aa1d560d5fa486c4b11c2f276ada61) C:\Windows\system32\DRIVERS\srvnet.sys
    2011/07/08 15:44:49.0683 3016 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
    2011/07/08 15:44:49.0943 3016 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
    2011/07/08 15:44:50.0133 3016 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
    2011/07/08 15:44:50.0241 3016 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
    2011/07/08 15:44:50.0417 3016 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
    2011/07/08 15:44:50.0525 3016 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
    2011/07/08 15:44:50.0619 3016 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
    2011/07/08 15:44:50.0726 3016 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
    2011/07/08 15:44:50.0799 3016 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
    2011/07/08 15:44:50.0930 3016 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
    2011/07/08 15:44:50.0990 3016 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
    2011/07/08 15:44:51.0093 3016 TPkd (2f4e8077febfe11199ee3b011a34cd18) C:\Windows\system32\drivers\TPkd.sys
    2011/07/08 15:44:51.0197 3016 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
    2011/07/08 15:44:51.0249 3016 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
    2011/07/08 15:44:51.0296 3016 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
    2011/07/08 15:44:51.0352 3016 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
    2011/07/08 15:44:51.0428 3016 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
    2011/07/08 15:44:51.0521 3016 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
    2011/07/08 15:44:51.0580 3016 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
    2011/07/08 15:44:51.0693 3016 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
    2011/07/08 15:44:51.0758 3016 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
    2011/07/08 15:44:51.0816 3016 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
    2011/07/08 15:44:51.0931 3016 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
    2011/07/08 15:44:52.0055 3016 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
    2011/07/08 15:44:52.0154 3016 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
    2011/07/08 15:44:52.0247 3016 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
    2011/07/08 15:44:52.0352 3016 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
    2011/07/08 15:44:52.0417 3016 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
    2011/07/08 15:44:52.0493 3016 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
    2011/07/08 15:44:52.0567 3016 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
    2011/07/08 15:44:52.0686 3016 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    2011/07/08 15:44:52.0783 3016 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
    2011/07/08 15:44:52.0859 3016 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
    2011/07/08 15:44:52.0916 3016 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
    2011/07/08 15:44:52.0982 3016 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
    2011/07/08 15:44:53.0048 3016 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
    2011/07/08 15:44:53.0113 3016 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
    2011/07/08 15:44:53.0200 3016 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
    2011/07/08 15:44:53.0331 3016 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
    2011/07/08 15:44:53.0410 3016 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
    2011/07/08 15:44:53.0528 3016 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
    2011/07/08 15:44:53.0626 3016 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
    2011/07/08 15:44:53.0677 3016 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/07/08 15:44:53.0706 3016 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/07/08 15:44:53.0838 3016 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\Windows\system32\DRIVERS\wanatw4.sys
    2011/07/08 15:44:53.0970 3016 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
    2011/07/08 15:44:54.0113 3016 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
    2011/07/08 15:44:54.0288 3016 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
    2011/07/08 15:44:54.0602 3016 WinUSB (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUSB.sys
    2011/07/08 15:44:54.0707 3016 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
    2011/07/08 15:44:54.0845 3016 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
    2011/07/08 15:44:54.0966 3016 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
    2011/07/08 15:44:55.0119 3016 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
    2011/07/08 15:44:55.0180 3016 MBR (0x1B8) (81cd5ec01db0ce57edd853f82462ef27) \Device\Harddisk0\DR0
    2011/07/08 15:44:55.0391 3016 Boot (0x1200) (4f6a8f4c009d18060799a7641b0e8e8c) \Device\Harddisk0\DR0\Partition0
    2011/07/08 15:44:55.0422 3016 Boot (0x1200) (a6ac6c0ece8222765dbc0e56ef748734) \Device\Harddisk0\DR0\Partition1
    2011/07/08 15:44:55.0440 3016 ================================================================================
    2011/07/08 15:44:55.0440 3016 Scan finished
    2011/07/08 15:44:55.0440 3016 ================================================================================
    2011/07/08 15:44:55.0469 1016 Detected object count: 1
    2011/07/08 15:44:55.0469 1016 Actual detected object count: 1
    2011/07/08 15:45:28.0060 1016 LockedFile.Multi.Generic(sptd) - User select action: Skip
    2011/07/08 15:45:46.0837 1616 ================================================================================
    2011/07/08 15:45:46.0837 1616 Scan started
    2011/07/08 15:45:46.0837 1616 Mode: Manual;
    2011/07/08 15:45:46.0838 1616 ================================================================================
    2011/07/08 15:45:47.0141 1616 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
    2011/07/08 15:45:47.0251 1616 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
    2011/07/08 15:45:47.0312 1616 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
    2011/07/08 15:45:47.0362 1616 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
    2011/07/08 15:45:47.0419 1616 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
    2011/07/08 15:45:47.0516 1616 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
    2011/07/08 15:45:47.0568 1616 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
    2011/07/08 15:45:47.0623 1616 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
    2011/07/08 15:45:47.0685 1616 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
    2011/07/08 15:45:47.0728 1616 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
    2011/07/08 15:45:47.0780 1616 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
    2011/07/08 15:45:47.0831 1616 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
    2011/07/08 15:45:47.0878 1616 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
    2011/07/08 15:45:47.0955 1616 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
    2011/07/08 15:45:48.0002 1616 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
    2011/07/08 15:45:48.0058 1616 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
    2011/07/08 15:45:48.0151 1616 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
    2011/07/08 15:45:48.0218 1616 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
    2011/07/08 15:45:48.0291 1616 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
    2011/07/08 15:45:48.0380 1616 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
    2011/07/08 15:45:48.0433 1616 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
    2011/07/08 15:45:48.0476 1616 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
    2011/07/08 15:45:48.0533 1616 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
    2011/07/08 15:45:48.0578 1616 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
    2011/07/08 15:45:48.0644 1616 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
    2011/07/08 15:45:48.0679 1616 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
    2011/07/08 15:45:48.0724 1616 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
    2011/07/08 15:45:48.0774 1616 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
    2011/07/08 15:45:48.0841 1616 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
    2011/07/08 15:45:48.0920 1616 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
    2011/07/08 15:45:48.0997 1616 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
    2011/07/08 15:45:49.0066 1616 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
    2011/07/08 15:45:49.0108 1616 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys
    2011/07/08 15:45:49.0167 1616 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
    2011/07/08 15:45:49.0228 1616 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
    2011/07/08 15:45:49.0316 1616 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
    2011/07/08 15:45:49.0378 1616 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
    2011/07/08 15:45:49.0479 1616 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
    2011/07/08 15:45:49.0565 1616 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
    2011/07/08 15:45:49.0652 1616 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
    2011/07/08 15:45:49.0735 1616 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
    2011/07/08 15:45:49.0801 1616 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
    2011/07/08 15:45:49.0873 1616 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
    2011/07/08 15:45:49.0968 1616 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
    2011/07/08 15:45:50.0013 1616 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
    2011/07/08 15:45:50.0083 1616 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
    2011/07/08 15:45:50.0141 1616 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
    2011/07/08 15:45:50.0198 1616 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
    2011/07/08 15:45:50.0231 1616 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
    2011/07/08 15:45:50.0303 1616 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
    2011/07/08 15:45:50.0389 1616 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
    2011/07/08 15:45:50.0451 1616 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
    2011/07/08 15:45:50.0567 1616 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
    2011/07/08 15:45:50.0623 1616 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
    2011/07/08 15:45:50.0681 1616 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
    2011/07/08 15:45:50.0783 1616 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
    2011/07/08 15:45:50.0850 1616 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
    2011/07/08 15:45:50.0971 1616 HSF_DP (88749fbf8beb18c90e7d6626c8c1910b) C:\Windows\system32\DRIVERS\HSX_DP.sys
    2011/07/08 15:45:51.0029 1616 HSXHWBS2 (fe440536bd98af772130dc3a6fe1915f) C:\Windows\system32\DRIVERS\HSXHWBS2.sys
    2011/07/08 15:45:51.0122 1616 HTTP (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
    2011/07/08 15:45:51.0209 1616 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
    2011/07/08 15:45:51.0255 1616 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
    2011/07/08 15:45:51.0315 1616 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
    2011/07/08 15:45:51.0378 1616 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
    2011/07/08 15:45:51.0527 1616 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys
    2011/07/08 15:45:51.0591 1616 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
    2011/07/08 15:45:51.0629 1616 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
    2011/07/08 15:45:51.0685 1616 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    2011/07/08 15:45:51.0793 1616 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
    2011/07/08 15:45:51.0880 1616 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
    2011/07/08 15:45:51.0955 1616 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
    2011/07/08 15:45:51.0999 1616 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
    2011/07/08 15:45:52.0076 1616 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
    2011/07/08 15:45:52.0133 1616 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
    2011/07/08 15:45:52.0186 1616 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
    2011/07/08 15:45:52.0212 1616 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
    2011/07/08 15:45:52.0287 1616 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
    2011/07/08 15:45:52.0389 1616 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
    2011/07/08 15:45:52.0483 1616 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
    2011/07/08 15:45:52.0565 1616 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
    2011/07/08 15:45:52.0613 1616 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
    2011/07/08 15:45:52.0652 1616 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
    2011/07/08 15:45:52.0741 1616 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
    2011/07/08 15:45:52.0826 1616 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
    2011/07/08 15:45:52.0861 1616 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
    2011/07/08 15:45:52.0899 1616 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
    2011/07/08 15:45:52.0954 1616 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
    2011/07/08 15:45:53.0000 1616 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
    2011/07/08 15:45:53.0051 1616 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
    2011/07/08 15:45:53.0112 1616 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
    2011/07/08 15:45:53.0141 1616 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
    2011/07/08 15:45:53.0231 1616 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
    2011/07/08 15:45:53.0353 1616 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
    2011/07/08 15:45:53.0431 1616 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
    2011/07/08 15:45:53.0517 1616 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
    2011/07/08 15:45:53.0607 1616 mrxsmb (5fe5cf325f5b02ebc60832d3440cb414) C:\Windows\system32\DRIVERS\mrxsmb.sys
    2011/07/08 15:45:53.0638 1616 mrxsmb10 (30b9c769446af379a2afb72b0392604d) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    2011/07/08 15:45:53.0666 1616 mrxsmb20 (fea239b3ec4877e2b7e23204af589ddf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    2011/07/08 15:45:53.0751 1616 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
    2011/07/08 15:45:53.0788 1616 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
    2011/07/08 15:45:53.0859 1616 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
    2011/07/08 15:45:53.0893 1616 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
    2011/07/08 15:45:53.0967 1616 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
    2011/07/08 15:45:54.0016 1616 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
    2011/07/08 15:45:54.0057 1616 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
    2011/07/08 15:45:54.0165 1616 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
    2011/07/08 15:45:54.0220 1616 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
    2011/07/08 15:45:54.0274 1616 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
    2011/07/08 15:45:54.0355 1616 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
    2011/07/08 15:45:54.0460 1616 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
    2011/07/08 15:45:54.0512 1616 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
    2011/07/08 15:45:54.0608 1616 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
    2011/07/08 15:45:54.0660 1616 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
    2011/07/08 15:45:54.0727 1616 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
    2011/07/08 15:45:54.0774 1616 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
    2011/07/08 15:45:54.0817 1616 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
    2011/07/08 15:45:54.0906 1616 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
    2011/07/08 15:45:54.0987 1616 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
    2011/07/08 15:45:55.0092 1616 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
    2011/07/08 15:45:55.0148 1616 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
    2011/07/08 15:45:55.0263 1616 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
    2011/07/08 15:45:55.0333 1616 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
    2011/07/08 15:45:55.0385 1616 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
    2011/07/08 15:45:55.0499 1616 NVENETFD (d668632606d1cebf0b6ec64c1df7ed6f) C:\Windows\system32\DRIVERS\nvmfdx32.sys
    2011/07/08 15:45:55.0762 1616 nvlddmkm (fbba09782f2fac5a57619df378ba9372) C:\Windows\system32\DRIVERS\nvlddmkm.sys
    2011/07/08 15:45:55.0922 1616 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
    2011/07/08 15:45:56.0017 1616 nvrd32 (6f5bb0b40d251351a913b61ba9d64b3f) C:\Windows\system32\drivers\nvrd32.sys
    2011/07/08 15:45:56.0095 1616 nvsmu (c44ee36dd84fa95eb81d79c374756003) C:\Windows\system32\drivers\nvsmu.sys
    2011/07/08 15:45:56.0203 1616 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
    2011/07/08 15:45:56.0299 1616 nvstor32 (1a649b87a7b7c1220a2b16b121f2198e) C:\Windows\system32\DRIVERS\nvstor32.sys
    2011/07/08 15:45:56.0411 1616 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
    2011/07/08 15:45:56.0564 1616 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
    2011/07/08 15:45:56.0661 1616 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
    2011/07/08 15:45:56.0783 1616 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
    2011/07/08 15:45:56.0852 1616 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
    2011/07/08 15:45:56.0996 1616 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
    2011/07/08 15:45:57.0048 1616 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
    2011/07/08 15:45:57.0156 1616 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
    2011/07/08 15:45:57.0234 1616 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
    2011/07/08 15:45:57.0394 1616 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
    2011/07/08 15:45:57.0470 1616 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
    2011/07/08 15:45:57.0580 1616 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
    2011/07/08 15:45:57.0676 1616 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys
    2011/07/08 15:45:57.0796 1616 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
    2011/07/08 15:45:57.0869 1616 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
    2011/07/08 15:45:57.0936 1616 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
    2011/07/08 15:45:57.0999 1616 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
    2011/07/08 15:45:58.0066 1616 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
    2011/07/08 15:45:58.0175 1616 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
    2011/07/08 15:45:58.0234 1616 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
    2011/07/08 15:45:58.0346 1616 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
    2011/07/08 15:45:58.0445 1616 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
    2011/07/08 15:45:58.0532 1616 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
    2011/07/08 15:45:58.0577 1616 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
    2011/07/08 15:45:58.0696 1616 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
    2011/07/08 15:45:58.0867 1616 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
    2011/07/08 15:45:58.0941 1616 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
    2011/07/08 15:45:59.0036 1616 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
    2011/07/08 15:45:59.0123 1616 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
    2011/07/08 15:45:59.0192 1616 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
    2011/07/08 15:45:59.0255 1616 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
    2011/07/08 15:45:59.0357 1616 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
    2011/07/08 15:45:59.0433 1616 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
    2011/07/08 15:45:59.0511 1616 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
    2011/07/08 15:45:59.0579 1616 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
    2011/07/08 15:45:59.0661 1616 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
    2011/07/08 15:45:59.0725 1616 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
    2011/07/08 15:45:59.0781 1616 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
    2011/07/08 15:45:59.0900 1616 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
    2011/07/08 15:45:59.0978 1616 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
    2011/07/08 15:46:00.0122 1616 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
    2011/07/08 15:46:00.0122 1616 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
    2011/07/08 15:46:00.0138 1616 sptd - detected LockedFile.Multi.Generic (1)
    2011/07/08 15:46:00.0240 1616 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
    2011/07/08 15:46:00.0296 1616 srv2 (a5940ca32ed206f90be9fabdf6e92de4) C:\Windows\system32\DRIVERS\srv2.sys
    2011/07/08 15:46:00.0348 1616 srvnet (37aa1d560d5fa486c4b11c2f276ada61) C:\Windows\system32\DRIVERS\srvnet.sys
    2011/07/08 15:46:00.0501 1616 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
    2011/07/08 15:46:00.0586 1616 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
    2011/07/08 15:46:00.0652 1616 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
    2011/07/08 15:46:00.0710 1616 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
    2011/07/08 15:46:00.0860 1616 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
    2011/07/08 15:46:00.0959 1616 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
    2011/07/08 15:46:01.0079 1616 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
    2011/07/08 15:46:01.0178 1616 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
    2011/07/08 15:46:01.0242 1616 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
    2011/07/08 15:46:01.0331 1616 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
    2011/07/08 15:46:01.0433 1616 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
    2011/07/08 15:46:01.0561 1616 TPkd (2f4e8077febfe11199ee3b011a34cd18) C:\Windows\system32\drivers\TPkd.sys
    2011/07/08 15:46:01.0675 1616 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
    2011/07/08 15:46:01.0725 1616 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
    2011/07/08 15:46:01.0805 1616 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
    2011/07/08 15:46:01.0855 1616 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
    2011/07/08 15:46:01.0971 1616 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
    2011/07/08 15:46:02.0065 1616 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
    2011/07/08 15:46:02.0124 1616 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
    2011/07/08 15:46:02.0186 1616 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
    2011/07/08 15:46:02.0251 1616 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
    2011/07/08 15:46:02.0309 1616 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
    2011/07/08 15:46:02.0423 1616 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
    2011/07/08 15:46:02.0531 1616 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
    2011/07/08 15:46:02.0630 1616 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
    2011/07/08 15:46:02.0699 1616 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
    2011/07/08 15:46:02.0812 1616 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
    2011/07/08 15:46:02.0869 1616 usbohci (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
    2011/07/08 15:46:02.0928 1616 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
    2011/07/08 15:46:03.0018 1616 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
    2011/07/08 15:46:03.0113 1616 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    2011/07/08 15:46:03.0201 1616 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
    2011/07/08 15:46:03.0286 1616 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
    2011/07/08 15:46:03.0342 1616 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
    2011/07/08 15:46:03.0406 1616 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
    2011/07/08 15:46:03.0474 1616 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
    2011/07/08 15:46:03.0556 1616 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
    2011/07/08 15:46:03.0609 1616 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
    2011/07/08 15:46:03.0725 1616 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
    2011/07/08 15:46:03.0841 1616 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
    2011/07/08 15:46:03.0946 1616 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
    2011/07/08 15:46:04.0044 1616 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
    2011/07/08 15:46:04.0095 1616 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/07/08 15:46:04.0120 1616 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/07/08 15:46:04.0214 1616 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\Windows\system32\DRIVERS\wanatw4.sys
    2011/07/08 15:46:04.0321 1616 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
    2011/07/08 15:46:04.0423 1616 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
    2011/07/08 15:46:04.0613 1616 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
    2011/07/08 15:46:04.0787 1616 WinUSB (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUSB.sys
    2011/07/08 15:46:04.0892 1616 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys
    2011/07/08 15:46:05.0031 1616 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
    2011/07/08 15:46:05.0118 1616 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
    2011/07/08 15:46:05.0254 1616 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
    2011/07/08 15:46:05.0315 1616 MBR (0x1B8) (81cd5ec01db0ce57edd853f82462ef27) \Device\Harddisk0\DR0
    2011/07/08 15:46:05.0501 1616 Boot (0x1200) (4f6a8f4c009d18060799a7641b0e8e8c) \Device\Harddisk0\DR0\Partition0
    2011/07/08 15:46:05.0526 1616 Boot (0x1200) (a6ac6c0ece8222765dbc0e56ef748734) \Device\Harddisk0\DR0\Partition1
    2011/07/08 15:46:05.0557 1616 ================================================================================
    2011/07/08 15:46:05.0557 1616 Scan finished
    2011/07/08 15:46:05.0557 1616 ================================================================================
    2011/07/08 15:46:05.0585 2968 Detected object count: 1
    2011/07/08 15:46:05.0585 2968 Actual detected object count: 1
    2011/07/08 15:46:15.0279 2968 LockedFile.Multi.Generic(sptd) - User select action: Skip
    2011/07/08 15:48:51.0742 2476 Deinitialize success

  6. #6
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default

    Here is the ComboFix log.


    ComboFix 11-07-08.03 - Lycan 07/08/2011 15:52:37.1.1 - x86
    Running from: c:\users\Lycan\Downloads\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files\ErrorSmart
    c:\program files\ErrorSmart\DataBase.ref
    c:\program files\ErrorSmart\ErrorSmart.exe
    c:\program files\ErrorSmart\ErrorSmart.url
    c:\program files\FLV Direct Player
    c:\program files\FLV Direct Player\downloading.swf
    c:\program files\FLV Direct Player\FLVPlayer.exe
    c:\program files\FLV Direct Player\player.swf
    c:\program files\FLV Direct Player\preload.swf
    c:\program files\FLV Direct Player\Skin\DirectFLV\Button.bmp
    c:\program files\FLV Direct Player\Skin\DirectFLV\Logo.bmp
    c:\program files\FLV Direct Player\Skin\DirectFLV\skin.xml
    c:\program files\FLV Direct Player\Skin\DirectFLV\SysCloseButton.bmp
    c:\program files\FLV Direct Player\Skin\DirectFLV\SysMaxButton.bmp
    c:\program files\FLV Direct Player\Skin\DirectFLV\SysMinButton.bmp
    c:\program files\FLV Direct Player\Skin\DirectFLV\Window.bmp
    c:\program files\FLV Direct Player\uninstall.exe
    c:\program files\somototoolbar\vmNTemplatex.dll
    c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart
    c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart\ErrorSmart on the Web.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\ErrorSmart\ErrorSmart.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player
    c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\FLV Direct Player.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\FLV Direct Player\Uninstall FLV Direct Player.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\HeroCodec
    c:\programdata\Microsoft\Windows\Start Menu\Programs\HeroCodec\Uninstall.lnk
    c:\users\Lycan\AppData\Local\Temp\swtlib-32\swt-gdip-win32-3650.dll
    c:\users\Lycan\AppData\Local\Temp\swtlib-32\swt-win32-3650.dll
    c:\users\Lycan\AppData\Roaming\.#
    c:\users\Lycan\AppData\Roaming\ErrorSmart
    c:\users\Lycan\AppData\Roaming\ErrorSmart\Log\2011 Feb 04 - 07_15_44 PM_141.log
    c:\users\Lycan\AppData\Roaming\ErrorSmart\Registry Backups\2011-02-04_19-17-11.reg
    c:\users\Lycan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HeroCodec
    c:\users\Lycan\hosts
    c:\users\Public\Desktop\ErrorSmart.lnk
    c:\users\Public\Desktop\FLV Direct Player.lnk
    c:\users\Public\WINDOWS
    c:\users\Public\WINDOWS\DigitalLocker\enUs\BITSCTRS.INI
    c:\users\Public\WINDOWS\DigitalLocker\enUs\DXG.INI
    c:\users\Public\WINDOWS\Microsoft.Net\Authmen\DJSVS.INI
    c:\users\Public\WINDOWS\MSAgent\Chars\DRVLOCK.SYS
    c:\users\Public\WINDOWS\MSAgent\Chars\SYMBIOS.SYS
    c:\users\Public\WINDOWS\PLA\System\EPCL5UI.INI
    c:\users\Public\WINDOWS\SoftwareDistribution\DataStore\Logs\EPNPVE3N.INI
    c:\users\Public\WINDOWS\SoftwareDistribution\DataStore\Logs\MSDFMAP.INI
    c:\users\Public\WINDOWS\WindowsMobile\enUs\BRMTBIDI.INI
    c:\users\Public\WINDOWS\WindowsMobile\enUs\EWPKCLNT.INI
    c:\windows\system32\AutoRun.inf
    c:\windows\system32\Filters
    c:\windows\system32\Filters\AviSplitter.ax
    c:\windows\system32\Filters\ffdshow\custom matrices\andreas_78er.matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\andreas_doppelte_99er.matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\andreas_einfache_99er.matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's Heavy Compression Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Bulletproof's High Quality Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\CG-Animation Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\hvs-best-picture.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\hvs-better-picture.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\hvs-good-picture.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Low Bitrate Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\MPEG.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\pvcd.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V3.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Soulhunters V5.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Standard.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Ultimate Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Ultra Low Bitrate Matrix.xcm
    c:\windows\system32\Filters\ffdshow\custom matrices\Very Low Bitrate Matrix.xcm
    c:\windows\system32\Filters\ffdshow\dict\Czech.dic
    c:\windows\system32\Filters\ffdshow\dict\dicts.txt
    c:\windows\system32\Filters\ffdshow\dict\Greek.dic
    c:\windows\system32\Filters\ffdshow\dict\Polski.dic
    c:\windows\system32\Filters\ffdshow\ff_kernelDeint.dll
    c:\windows\system32\Filters\ffdshow\ff_liba52.dll
    c:\windows\system32\Filters\ffdshow\ff_libdts.dll
    c:\windows\system32\Filters\ffdshow\ff_libfaad2.dll
    c:\windows\system32\Filters\ffdshow\ff_libmad.dll
    c:\windows\system32\Filters\ffdshow\ff_realaac.dll
    c:\windows\system32\Filters\ffdshow\ff_samplerate.dll
    c:\windows\system32\Filters\ffdshow\ff_theora.dll
    c:\windows\system32\Filters\ffdshow\ff_tremor.dll
    c:\windows\system32\Filters\ffdshow\ff_unrar.dll
    c:\windows\system32\Filters\ffdshow\ff_wmv9.dll
    c:\windows\system32\Filters\ffdshow\ff_x264.dll
    c:\windows\system32\Filters\ffdshow\ffdshow.ax
    c:\windows\system32\Filters\ffdshow\ffdshow.ax.manifest
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1028.tc
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1029.cz
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1031.de
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1033.en
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1034.es
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1036.fr
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1038.hu
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1040.it
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.ja
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1041.jp
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1045.pl
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1046.br
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1049.ru
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1051.sk
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.1053.se
    c:\windows\system32\Filters\ffdshow\languages\ffdshow.2052.sc
    c:\windows\system32\Filters\ffdshow\libavcodec.dll
    c:\windows\system32\Filters\ffdshow\libmpeg2_ff.dll
    c:\windows\system32\Filters\ffdshow\libmplayer.dll
    c:\windows\system32\Filters\ffdshow\reg\ffdshow.reg
    c:\windows\system32\Filters\ffdshow\reg\reg.exe
    c:\windows\system32\Filters\ffdshow\reg\rempc.reg
    c:\windows\system32\Filters\ffdshow\TomsMoComp_ff.dll
    c:\windows\system32\Filters\FLVSplitter.ax
    c:\windows\system32\Filters\MatroskaSplitter.ax
    c:\windows\system32\Filters\MP4Splitter.ax
    c:\windows\system32\Filters\Quicktime.ax
    c:\windows\system32\Filters\RealMediaSplitter.ax
    c:\windows\system32\Filters\VSFilter.dll
    c:\windows\system32\jusched.exe
    c:\windows\UA000106.DLL
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-06-08 to 2011-07-08 )))))))))))))))))))))))))))))))
    .
    .
    2011-07-08 23:06 . 2011-07-08 23:06 0 ---ha-w- c:\users\Lycan\AppData\Local\BIT1313.tmp
    2011-07-08 21:33 . 2011-07-08 21:33 -------- d-----w- c:\program files\Vuze
    2011-07-08 21:33 . 2011-07-08 23:02 -------- d-----w- c:\program files\somototoolbar
    2011-07-08 21:33 . 2011-07-08 21:33 -------- d-----w- c:\program files\Vuze FileBulldog Toolbar
    2011-07-08 09:36 . 2011-07-08 09:36 -------- d-----w- c:\program files\TruePianos2
    2011-07-07 16:49 . 2011-07-07 16:49 388096 ----a-r- c:\users\Lycan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-07-07 16:49 . 2011-07-07 16:49 -------- d-----w- c:\program files\HJack
    2011-07-07 05:57 . 2011-07-08 20:08 -------- d-----w- c:\users\Lycan\AppData\Roaming\PFStaticIP
    2011-07-07 05:56 . 2011-07-07 05:56 -------- d-----w- c:\program files\PFStaticIP
    2011-07-03 06:44 . 2011-07-03 06:44 -------- d-----w- c:\program files\TC Electronic
    2011-07-03 06:09 . 2011-07-03 06:09 -------- d-----w- c:\program files\Focusrite
    2011-07-01 23:41 . 2011-07-01 23:41 0 ---ha-w- c:\users\Lycan\AppData\Local\BIT5C90.tmp
    2011-06-30 11:11 . 2011-06-30 11:11 -------- d-----w- c:\program files\Sibelius Software
    2011-06-30 07:04 . 2011-06-30 07:04 -------- d-----w- c:\program files\uTorrent
    2011-06-30 07:01 . 2011-07-08 21:36 -------- d-----w- c:\users\Lycan\AppData\Roaming\uTorrent
    2011-06-30 07:01 . 2011-06-30 07:01 -------- d-----w- c:\users\Lycan\AppData\Local\uTorrent
    2011-06-30 04:33 . 2011-06-30 04:33 -------- d-----w- c:\program files\EarthLink Accelerated
    2011-06-30 04:09 . 2011-06-30 05:39 -------- d-----w- c:\program files\Common Files\EarthLink
    2011-06-30 04:09 . 2010-07-30 21:20 69440 ------w- c:\windows\system32\unPPC6000.exe
    2011-06-30 04:09 . 2010-07-30 21:20 41792 ------w- c:\windows\system32\ppcwebi.dll
    2011-06-30 04:09 . 2010-07-30 21:10 73728 ------w- c:\windows\system32\ppcpanel.cpl
    2011-06-30 04:09 . 2010-07-01 18:37 73192 ------w- c:\windows\system32\unPPC.exe
    2011-06-30 04:09 . 2010-07-30 21:20 66880 ------w- c:\windows\system32\PPCOUNIN.exe
    2011-06-30 04:09 . 2010-07-30 21:20 28992 ------w- c:\windows\system32\PopWait.exe
    2011-06-30 04:09 . 2010-07-01 21:08 34136 ------w- c:\windows\system32\RegHero.exe
    2011-06-30 04:09 . 2010-07-30 21:20 40600 ------w- c:\windows\system32\PPCClean.exe
    2011-06-30 04:09 . 2010-07-30 21:20 255296 ------w- c:\windows\system32\PPCInfo.exe
    2011-06-30 04:09 . 2010-07-01 21:08 84992 ------w- c:\windows\system32\ATL70.dll
    2011-06-30 04:07 . 2011-06-30 04:10 -------- d-----w- c:\program files\EarthLink
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-06-06 03:06 . 2011-06-06 03:06 161792 ----a-w- c:\windows\system32\msls31.dll
    2011-06-06 03:06 . 2011-06-06 03:06 1126912 ----a-w- c:\windows\system32\wininet.dll
    2011-06-06 03:06 . 2011-06-06 03:06 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
    2011-06-06 03:06 . 2011-06-06 03:06 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
    2011-06-06 03:06 . 2011-06-06 03:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
    2011-06-06 03:06 . 2011-06-06 03:06 86528 ----a-w- c:\windows\system32\iesysprep.dll
    2011-06-06 03:06 . 2011-06-06 03:06 63488 ----a-w- c:\windows\system32\tdc.ocx
    2011-06-06 03:06 . 2011-06-06 03:06 367104 ----a-w- c:\windows\system32\html.iec
    2011-06-06 03:06 . 2011-06-06 03:06 74752 ----a-w- c:\windows\system32\iesetup.dll
    2011-06-06 03:06 . 2011-06-06 03:06 23552 ----a-w- c:\windows\system32\licmgr10.dll
    2011-06-06 03:06 . 2011-06-06 03:06 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
    2011-06-06 03:06 . 2011-06-06 03:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-06-06 03:06 . 2011-06-06 03:06 152064 ----a-w- c:\windows\system32\wextract.exe
    2011-06-06 03:06 . 2011-06-06 03:06 150528 ----a-w- c:\windows\system32\iexpress.exe
    2011-06-06 03:06 . 2011-06-06 03:06 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-06-06 03:06 . 2011-06-06 03:06 142848 ----a-w- c:\windows\system32\ieUnatt.exe
    2011-06-06 03:06 . 2011-06-06 03:06 11776 ----a-w- c:\windows\system32\mshta.exe
    2011-06-06 03:06 . 2011-06-06 03:06 101888 ----a-w- c:\windows\system32\admparse.dll
    2011-06-06 03:06 . 2011-06-06 03:06 35840 ----a-w- c:\windows\system32\imgutil.dll
    2011-06-06 03:06 . 2011-06-06 03:06 1797632 ----a-w- c:\windows\system32\jscript9.dll
    2011-06-06 03:06 . 2011-06-06 03:06 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
    2011-04-14 23:30 . 2011-04-15 08:40 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C9F58FA8-8BD2-4870-9575-66A8064370D9}\mpengine.dll
    2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-12 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
    "HostManager"="c:\program files\Common Files\AOL\1210728131\ee\AOLSoftware.exe" [2006-09-26 50736]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
    "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "Bart Station"="c:\program files\EarthLink\ISP\ISP8300\BIN\PPCOLink.exe" [2010-07-30 25920]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux6"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
    @="Driver"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bitcomet Ultra Accelerator.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bitcomet Ultra Accelerator.lnk
    backup=c:\windows\pss\Bitcomet Ultra Accelerator.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
    backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2008-10-15 09:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
    2010-03-06 10:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
    2010-02-22 11:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
    2006-11-10 12:12 50736 ----a-w- c:\program files\AOL 9.0\aol.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
    2008-03-05 14:30 5980160 ----a-w- c:\program files\Blubster\blubster.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    2010-04-12 22:46 1135912 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DPService]
    2008-01-15 08:58 90112 ----a-w- c:\program files\HP\DVDPlay\DPService.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EverioService]
    2007-11-02 01:13 151552 ------w- c:\program files\CyberLink\PCM4Everio\EverioService.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    2007-03-12 05:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
    2007-04-18 15:01 65536 ----a-w- c:\hp\support\hpsysdrv.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OsdMaestro]
    2007-02-15 11:59 118784 ----a-w- c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-30 00:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedBitVideoAccelerator]
    2010-04-20 22:32 1607272 ----a-w- c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-07-12 06:20 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    2010-05-14 13:55 37888 ----a-w- c:\program files\Winamp\winampa.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R1 MpKsl8473dbbf;MpKsl8473dbbf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1FBA307A-6816-4BB3-A2F4-077063B5B291}\MpKsl8473dbbf.sys [x]
    R1 MpKsl96e53cd6;MpKsl96e53cd6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1FBA307A-6816-4BB3-A2F4-077063B5B291}\MpKsl96e53cd6.sys [x]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate1c9bbf3acd1fde0;Google Update Service (gupdate1c9bbf3acd1fde0);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104]
    R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-17 691696]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
    S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2010-02-26 3623424]
    S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe [2010-04-20 300656]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    Akamai REG_MULTI_SZ Akamai
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2009-06-17 19:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-07-08 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-12 17:45]
    .
    2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 04:52]
    .
    2011-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 04:52]
    .
    2011-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1277242936-3510254915-2159929779-1000Core.job
    - c:\users\Lycan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-15 03:47]
    .
    2011-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1277242936-3510254915-2159929779-1000UA.job
    - c:\users\Lycan\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-15 03:47]
    .
    2011-06-28 c:\windows\Tasks\HPCeeScheduleForLycan.job
    - c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-02-27 20:10]
    .
    2011-07-04 c:\windows\Tasks\SmartDefrag.job
    - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-04-11 01:08]
    .
    2011-02-05 c:\windows\Tasks\SpeedyPC Program Check.job
    - c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
    .
    2011-02-05 c:\windows\Tasks\SpeedyPC.job
    - c:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.ebay.com/
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=desktop
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: EarthLink Google Search - c:\program files\EarthLink\Toolbar\SearchUI.dll/search.html
    Trusted Zone: wolfquest.org\www
    TCP: Interfaces\{2058ABE3-0B7D-4978-A86E-673F575ACF9D}: NameServer = 93.188.164.35,93.188.160.105
    .
    - - - - ORPHANS REMOVED - - - -
    .
    WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
    MSConfigStartUp-MSC - c:\program files\Microsoft Security Client\msseces.exe
    MSConfigStartUp-MySpaceIM - c:\program files\MySpace\IM\MySpaceIM.exe
    MSConfigStartUp-prbgqdqm - c:\users\Lycan\AppData\Local\Temp\tsaowrxyy\urxkvobsika.exe
    MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
    AddRemove-184466066.fuse.fender.com - c:\program files\Microsoft Silverlight\4.0.50826.0\Silverlight.Configuration.exe
    .
    .
    .
    **************************************************************************
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files:
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1277242936-3510254915-2159929779-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E6867C0E-9EA6-49EA-FC10-39D2D5E1B716}*]
    "hajifpflpmepclhi"=hex:69,61,66,6c,65,68,63,6a,65,65,62,66,61,69,6c,6a,67,6e,
    00,00
    "iahkhoofnedabnbabm"=hex:6a,61,63,6c,69,68,6f,6f,6d,6b,66,68,69,70,70,6d,68,6f,
    70,62,00,d2
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'Explorer.exe'(3016)
    c:\program files\Microangelo On Display\MODIcon.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\CyberLink\Shared Files\RichVideo.exe
    c:\windows\system32\DRIVERS\xaudio.exe
    c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
    c:\windows\RtHDVCpl.exe
    c:\windows\System32\rundll32.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\EarthLink\ISP\ISP8300\Browser\Bartshel.exe
    c:\program files\EarthLink\ISP\ISP8300\Browser\PPShared.exe
    c:\windows\servicing\TrustedInstaller.exe
    .
    **************************************************************************
    .
    Completion time: 2011-07-08 16:13:48 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-07-08 23:13
    .
    Pre-Run: 11,433,414,656 bytes free
    Post-Run: 16,897,085,440 bytes free
    .
    - - End Of File - - EE648E47C648BE2120027DD5AAE45905

  7. #7
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello,

    Lets try this tool and see what it uncovers.

    Click here to download Kaspersky Virus Removal Tool.
    • Double click on the file you just downloaded and let it install.
    • It will install to your desktop.
    • After that leave what is selected and put a check next to My Computer.
    • Click on the option that says Threat Detection and change it to Disinfect => Do not select, delete if disinfection fails.
    • Then click on Start Scan.
    • Before it is done it may prompt for action regardless of the setting so choose skip if prompted.
    • When the scan is done no log will be produced.
    • Click on the bottom where it says Report to open the report.
    • Then highlight of of the items found by using ctrl + a on your keyboard to select all or use your mouse to select all then right click and choose copy.
    • This will copy the items that it found to the clipboard you can then open notepad (go to start then run then type in notepad) and choose paste to paste the contents into Notepad.
    • You can save this on the desktop.
    • Post the contents of the document in your next reply.
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  8. #8
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello.

    Are you still there?

    If you are please follow the instructions in my previous post.

    If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

    Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

    Thanks for understanding

    With Regards,
    fireman4it
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  9. #9
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default

    Yes, I'm still with you. I've just gotten back from work. I'll have the logs for you shortly.

  10. #10
    Member
    Join Date
    Jul 2011
    Posts
    6
    Points
    0

    Default

    I can't download the tool from Kaspersky, something on my PC is blocking their website. However, I found a slightly older version (from last year) on Pirate Bay, so I'll get that. Apologies, its the best I can do given the circumstances. :\

Page 1 of 2 12 LastLast