Hi. I've been having this problem with Firefox & Chrome where searches are taking me to wrong sites. I've done everything as required with Gmer, Malwarebytes etc. Here are the logs:-

GMER One log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-09-20 19:25:09
Windows 6.1.7600
Running: 0g2vzqhn.exe; Driver: C:\Users\BOBBYD~1\AppData\Local\Temp\kwkirpoc.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 86708EC5

---- Files - GMER 1.0.15 ----

File C:\Windows\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----

GMER Two log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-20 19:51:15
Windows 6.1.7600
Running: 0g2vzqhn.exe; Driver: C:\Users\BOBBYD~1\AppData\Local\Temp\kwkirpoc.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys ZwOpenProcess [0x94888730]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys ZwTerminateProcess [0x948887E0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys ZwTerminateThread [0x94888880]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys ZwWriteVirtualMemory [0x94888920]

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302AAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302A104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302A3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830132D8
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302A1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302A958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302A6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302AF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302B1A8

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys

Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 86708EC5

---- Files - GMER 1.0.15 ----

File C:\Windows\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----

Malwarebytes log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4611

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

20/09/2010 15:29:03
mbam-log-2010-09-20 (15-29-03).txt

Scan type: Full scan (C:\|)
Objects scanned: 293002
Time elapsed: 1 hour(s), 23 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{F64CB1F0-0CE6-46C2-8DD1-3BB88CA01E29}\RP339\A0025732.exe (Trojan.MultiDropper) -> Quarantined and deleted successfully.
C:\Users\Bobby Digital\Documents\Backup\Your.Uninstaller.Pro.2008+Keygen-HeartBug\Keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.
C:\Windows.old\Documents and Settings\Bobby Digital\My Documents\Backup\Your.Uninstaller.Pro.2008+Keygen-HeartBug\Keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.

DDS attach log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 17/01/2010 15:21:35
System Uptime: 20/09/2010 19:53:24 (0 hours ago)

Motherboard: ASRock | | G31M-GS
Processor: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz | CPUSocket | 2327/333mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 466 GiB total, 263.63 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP242: 14/09/2010 14:48:29 - Installed Adobe Reader 9.3.
RP243: 15/09/2010 20:48:32 - Installed Emma Device Driver(s)
RP245: 20/09/2010 12:35:19 - Avg Update
RP247: 20/09/2010 12:36:13 - Avg Update

==== Installed Programs ======================


"Nero SoundTrax Help
Activision(R)
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 9.3.4
Advanced SystemCare 3
Advertising Center
Apple Application Support
Apple Software Update
Ask Toolbar
µTorrent
Avanquest update
AVG 9.0
Blur(TM)
CCleaner
ConvertXtoDVD 3.0.0.1
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Setup
DivX Version Checker
DolbyFiles
EA Download Manager
EA Download Manager UI
Emma Core
FLFooty TV 2.2
FrostWire 4.20.9
Google Chrome
GPL MPEG-1/2 DirectShow Decoder Filter
ImagXpress
Java Auto Updater
Java(TM) 6 Update 21
K-Lite Codec Pack 6.3.0 (Full)
LightScribe System Software 1.14.17.1
Malwarebytes' Anti-Malware
Menu Templates - Starter Kit
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Xbox 360 Accessories 1.1
Movie Templates - Starter Kit
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 9
Nero BurningROM
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
PeerBlock 1.0.0 (r181)
PowerISO
PVSonyDll
QuickTime
SEMC OMSI Module
Smart Defrag
Sony Ericsson PC Suite 6.009.00
SopCast 3.2.9
SoundTrax
Spotify
Spybot - Search & Destroy
System Requirements Lab
Update Service
VC80CRTRedist - 8.0.50727.4053
VirtuaGirl HD
VLC media player 1.1.4
Winamp
Winamp Application Detect
Windows Media Player Firefox Plugin
WinRAR
Your Uninstaller! 2008 Version 6.0
Your Uninstaller! 2010

==== Event Viewer Messages From Past Week ========

20/09/2010 19:53:40, Error: volmgr [46] - Crash dump initialization failed!
20/09/2010 19:53:38, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.
19/09/2010 11:33:11, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
19/09/2010 11:31:11, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
15/09/2010 20:42:07, Error: Service Control Manager [7030] - The Sony Ericsson OMSI download service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

==== End Of File ===========================

DDS txt log:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Bobby Digital at 19:55:31.86 on 20/09/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3263.2238 [GMT 1:00]

AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET Smart Security 3.0 *disabled* (Outdated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\conhost.exe
C:\Users\Bobby Digital\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://uk.ask.com?o=15007&l=dis
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
STS: Deskscapes: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - Deskscapes Class
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\bobbyd~1\appdata\roaming\mozilla\firefox\profiles\x5usodvj.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&source=iglk
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15004&locale=en_UK&apn_uid=050D1F59-0333-4543-B406-7407EBCDCCF8&apn_ptnrs=PW&apn_sauid=EE86A4B7-9F30-4A92-B9AD-396593AC7F19&apn_dtid=YYYYYYYYGB&q=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\users\bobby digital\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrw7x;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSwx.sys [2010-8-25 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-8-25 52872]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-8-25 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-8-25 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-8-25 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-8-25 243024]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-8-25 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-8-25 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-8-25 5897808]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\common files\sony ericsson\emma core\services\EmmaDeviceMgmt.exe [2010-8-24 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\common files\sony ericsson\emma core\services\EmmaUpdateMgmt.exe [2010-8-24 162936]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\sony ericsson\sony ericsson pc suite\SupServ.exe [2010-9-15 90112]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-6-7 240232]
R3 AVGIDSDriverw7x;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSDriver.sys [2010-8-25 122448]
R3 AVGIDSFilterw7x;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSFilter.sys [2010-8-25 30288]
R3 AVGIDSShimw7x;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSShim.sys [2010-8-25 20560]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-2 139776]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-9-13 27632]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-9-9 430152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-9-13 13224]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-3-10 16472]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [2010-9-15 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [2010-9-15 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [2010-9-15 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [2010-9-15 108328]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [2010-9-15 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [2010-9-15 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [2010-9-15 109736]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-7 1343400]
S4 ekrn;Eset Service;c:\program files\eset\eset smart security\ekrn.exe [2007-12-21 468224]

=============== Created Last 30 ================

2010-09-19 19:50:20 6656 ----a-w- c:\windows\system32\drivers\qzsjgnvx.sys
2010-09-15 19:58:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2010-09-15 19:58:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf
2010-09-15 19:48:20 0 d-----w- c:\program files\common files\Sony Ericsson
2010-09-15 19:42:07 148736 ----a-w- c:\programdata\hpe78A6.dll
2010-09-15 19:41:41 0 d-----w- c:\program files\Avanquest update
2010-09-15 19:39:59 0 d-----w- c:\programdata\BVRP Software
2010-09-15 19:35:56 86696 ----a-w- c:\windows\system32\drivers\s1018bus.sys
2010-09-15 19:35:56 26024 ----a-w- c:\windows\system32\drivers\s1018nd5.sys
2010-09-15 19:35:56 15016 ----a-w- c:\windows\system32\drivers\s1018mdfl.sys
2010-09-15 19:35:56 148736 ----a-w- c:\programdata\hpeD27B.dll
2010-09-15 19:35:56 12200 ----a-w- c:\windows\system32\drivers\s1018whnt.sys
2010-09-15 19:35:56 12200 ----a-w- c:\windows\system32\drivers\s1018wh.sys
2010-09-15 19:35:56 12200 ----a-w- c:\windows\system32\drivers\s1018cmnt.sys
2010-09-15 19:35:56 12200 ----a-w- c:\windows\system32\drivers\s1018cm.sys
2010-09-15 19:35:56 114472 ----a-w- c:\windows\system32\drivers\s1018mdm.sys
2010-09-15 19:35:56 109736 ----a-w- c:\windows\system32\drivers\s1018unic.sys
2010-09-15 19:35:56 108328 ----a-w- c:\windows\system32\drivers\s1018mgmt.sys
2010-09-15 19:35:56 10792 ----a-w- c:\windows\system32\drivers\s1018cr.sys
2010-09-15 19:35:56 104616 ----a-w- c:\windows\system32\drivers\s1018obex.sys
2010-09-15 19:35:52 0 d-----w- c:\programdata\Sony Ericsson
2010-09-14 03:37:56 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 03:37:54 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 03:24:30 6656 ----a-w- c:\windows\system32\drivers\pacbmxlf.sys
2010-09-14 03:22:27 0 d-----w- c:\windows\system32\MpEngineStore
2010-09-13 15:01:07 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-09-13 15:00:33 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-09-13 15:00:32 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2010-09-13 15:00:32 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2010-09-13 14:59:57 0 d-----w- c:\program files\Sony Ericsson
2010-09-09 17:50:02 0 d-----w- c:\programdata\AVG Security Toolbar
2010-08-31 18:01:56 0 d-----w- c:\program files\VideoLAN
2010-08-31 17:35:57 0 d-----w- c:\program files\Your Uninstaller 2010
2010-08-27 23:18:11 0 d--h--w- C:\$AVG
2010-08-27 16:14:59 0 d-----w- c:\users\bobbyd~1\appdata\roaming\AVG9
2010-08-25 16:17:27 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-25 16:17:26 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-25 16:17:26 25168 ----a-w- c:\windows\system32\drivers\AVGIDSwx.sys
2010-08-25 16:17:23 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-25 16:17:18 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-25 16:17:14 0 d-----w- c:\windows\system32\drivers\Avg
2010-08-25 16:15:51 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-08-23 21:19:52 6656 ----a-w- c:\windows\system32\drivers\kjkwpvpg.sys
2010-08-23 19:44:00 6656 ----a-w- c:\windows\system32\drivers\jhojzwca.sys
2010-08-23 18:58:05 6656 ----a-w- c:\windows\system32\drivers\rkixfjlc.sys

==================== Find3M ====================

2010-08-21 10:31:13 112 ----a-w- c:\programdata\kA2P3gX4O.dat
2010-08-21 00:48:37 224 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-12 08:00:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 04:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25:31 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 06:40:12 43318 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 19:56:48.51 ===============


Thanks for any assistance.

Please download ComboFix by sUBs from HERE or HERE

  • You must download it to and run it from your Desktop
  • Physically disconnect from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply.
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

===============

Download MBRCheck to your desktop

Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
It will show a black screen with some data on it.
A report called MBRcheckxxxx.txt will be on your desktop
Open this report and post its content in your next reply.

Hi Crunchie. I ran CF & it got to the stage where it was preparing the log file. I left it over night and was still in the same place in the morning. It says to only run once so need some advice thanks.

Please try it in safe mode. Tap the F8 key whilst starting the pc and select the Safe Mode option.

ComboFix:-

ComboFix 10-09-20.01 - Bobby Digital 21/09/2010 12:21:31.2.4 - x86 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3263.2556 [GMT 1:00]
Running from: c:\users\Bobby Digital\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Outdated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\ErrLog.txt
C:\install.exe
c:\programdata\hpe78A6.dll
c:\programdata\hpeD27B.dll
c:\users\Bobby Digital\AppData\Roaming\inst.exe
c:\windows\system32\system

.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.

2010-09-21 11:28 . 2010-09-21 11:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-21 11:20 . 2010-09-21 11:21 -------- d-----w- C:\32788R22FWJFW
2010-09-21 11:17 . 2010-09-21 11:17 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-09-20 21:50 . 2010-09-21 11:28 -------- d-----w- c:\users\Bobby Digital\AppData\Local\temp
2010-09-20 20:08 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-20 19:46 . 2010-09-21 10:10 -------- d-----w- c:\program files\SpywareBlaster
2010-09-20 19:40 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-20 19:39 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-09-20 19:39 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-20 19:39 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-09-20 19:39 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-09-20 19:39 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-09-20 19:39 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-09-20 11:36 . 2010-09-20 11:36 4093792 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-09-20 11:36 . 2010-09-20 11:36 3586912 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-09-20 11:36 . 2010-09-20 11:36 620896 ----a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2010-09-20 11:36 . 2010-09-20 11:36 1619296 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-09-20 11:36 . 2010-09-20 11:36 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-20 11:36 . 2010-09-20 11:36 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-20 11:36 . 2010-09-20 11:36 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-20 11:36 . 2010-09-20 11:36 5649320 ----a-w- c:\programdata\avg9\update\backup\winspamcatcher.dll
2010-09-20 11:36 . 2010-09-20 11:36 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-20 11:36 . 2010-09-20 11:36 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-20 11:36 . 2010-09-20 11:36 2331032 ----a-w- c:\programdata\avg9\update\backup\avgfws9.exe
2010-09-20 11:35 . 2010-09-20 11:35 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-19 19:50 . 2010-09-19 19:50 6656 ----a-w- c:\windows\system32\drivers\qzsjgnvx.sys
2010-09-15 20:12 . 2010-09-15 20:12 81016 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\71\1\.cp\lib\S1SLEngineWrapper.dll
2010-09-15 20:12 . 2010-09-15 20:12 1772664 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQ.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\61\1\.cp\lib\MemStickFlash.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQFlash.dll
2010-09-15 20:10 . 2010-09-15 20:10 101496 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\81\1\.cp\lib\USBFlash.dll
2010-09-15 20:03 . 2010-09-15 20:03 56440 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\73\1\.cp\lib\sef3x1Controller.dll
2010-09-15 19:49 . 2010-09-15 19:49 109752 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\67\1\.cp\lib\osds.dll
2010-09-15 19:49 . 2010-09-15 19:49 85176 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\79\1\.cp\lib\UAC.dll
2010-09-15 19:49 . 2010-09-15 19:49 57344 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\4\1\.cp\lib\serialio.dll
2010-09-15 19:49 . 2010-09-15 19:49 323648 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DIFxAPI.dll
2010-09-15 19:49 . 2010-09-15 19:49 216184 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\69\1\.cp\lib\RegistryReader.dll
2010-09-15 19:49 . 2010-09-15 19:49 158840 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DriverInstaller.exe
2010-09-15 19:49 . 2010-09-15 19:49 154744 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\8\1\.cp\lib\win32\DeviceRemover.exe
2010-09-15 19:49 . 2010-09-15 19:49 117880 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\6\1\.cp\lib\DeviceManager.dll
2010-09-15 19:48 . 2010-09-15 19:48 -------- d-----w- c:\program files\Common Files\Sony Ericsson
2010-09-15 19:41 . 2010-09-15 19:41 -------- d-----w- c:\program files\Avanquest update
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\users\Bobby Digital\AppData\Local\Sony Ericsson
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\programdata\BVRP Software
2010-09-14 13:49 . 2010-09-14 13:49 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-14 03:37 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 03:37 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 03:24 . 2010-09-14 03:24 6656 ----a-w- c:\windows\system32\drivers\pacbmxlf.sys
2010-09-14 03:22 . 2010-09-19 19:50 -------- d-----w- c:\windows\system32\MpEngineStore
2010-09-13 15:01 . 2010-09-13 15:01 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-09-13 15:00 . 2010-09-13 15:00 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-09-13 15:00 . 2010-09-13 15:00 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2010-09-13 15:00 . 2010-09-13 15:00 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2010-09-13 14:59 . 2010-09-15 19:48 -------- d-----w- c:\program files\Sony Ericsson
2010-09-11 18:27 . 2010-09-11 18:27 -------- d-----w- c:\users\Bobby Digital\AppData\Local\AVG Security Toolbar
2010-09-09 17:50 . 2010-09-09 17:50 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-09-07 04:03 . 2010-09-07 04:03 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-08-31 18:01 . 2010-08-31 18:01 -------- d-----w- c:\program files\VideoLAN
2010-08-31 17:35 . 2010-08-31 17:35 -------- d-----w- c:\program files\Your Uninstaller 2010
2010-08-27 23:18 . 2010-08-27 23:18 -------- d-----w- C:\$AVG
2010-08-27 16:14 . 2010-08-27 16:14 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\AVG9
2010-08-25 16:17 . 2010-08-25 16:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-25 16:17 . 2010-08-25 16:17 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-25 16:17 . 2010-08-25 16:17 25168 ----a-w- c:\windows\system32\drivers\AVGIDSwx.sys
2010-08-25 16:17 . 2010-08-25 16:17 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-25 16:17 . 2010-08-25 16:17 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-25 16:17 . 2010-09-21 08:40 -------- d-----w- c:\windows\system32\drivers\Avg
2010-08-25 16:17 . 2010-08-25 16:17 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-25 16:15 . 2010-08-25 16:15 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-08-23 21:19 . 2010-08-23 21:19 6656 ----a-w- c:\windows\system32\drivers\kjkwpvpg.sys
2010-08-23 19:44 . 2010-08-23 19:44 6656 ----a-w- c:\windows\system32\drivers\jhojzwca.sys
2010-08-23 18:58 . 2010-08-23 18:58 6656 ----a-w- c:\windows\system32\drivers\rkixfjlc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 09:27 . 2010-05-13 01:18 0 ----a-w- c:\users\Bobby Digital\AppData\Local\prvlcl.dat
2010-09-21 09:14 . 2010-01-17 17:25 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\uTorrent
2010-09-20 21:27 . 2010-01-17 15:33 87400 ----a-w- c:\users\Bobby Digital\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-20 20:32 . 2010-01-24 20:32 -------- d-----w- c:\programdata\NVIDIA
2010-09-20 20:32 . 2010-01-31 11:03 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-20 19:59 . 2010-06-21 13:48 -------- d-----w- c:\program files\Microsoft.NET
2010-09-20 19:35 . 2009-07-14 00:01 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys
2010-09-16 14:59 . 2010-01-17 16:52 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Vso
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf
2010-09-15 19:48 . 2010-09-15 19:35 -------- d-----w- c:\programdata\Sony Ericsson
2010-09-15 19:42 . 2010-07-14 14:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-14 03:37 . 2010-08-20 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 03:37 . 2010-05-23 22:03 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
2010-09-07 04:03 . 2010-04-05 13:48 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-07 04:03 . 2010-04-05 13:48 -------- d-----w- c:\programdata\DivX
2010-09-07 04:03 . 2010-01-17 16:00 -------- d-----w- c:\program files\DivX
2010-09-07 04:02 . 2010-09-01 15:22 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-07 04:02 . 2010-09-01 15:22 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-07 04:02 . 2010-08-16 19:02 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-07 03:59 . 2010-09-01 15:22 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-01 15:22 . 2010-01-17 16:00 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-01 12:43 . 2010-08-10 19:45 530158 ----a-w- c:\programdata\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-08-31 20:30 . 2010-01-17 17:10 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\IObit
2010-08-31 20:30 . 2010-01-17 16:56 -------- d-----w- c:\program files\IObit
2010-08-31 17:39 . 2010-02-19 18:16 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\DivX
2010-08-31 17:36 . 2010-01-17 17:03 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\URSoft
2010-08-31 17:32 . 2010-01-17 17:03 -------- d-----w- c:\program files\Your Uninstaller 2008
2010-08-30 09:39 . 2010-01-17 17:25 -------- d-----w- c:\program files\uTorrent
2010-08-27 23:18 . 2010-05-10 21:44 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Royh
2010-08-25 18:04 . 2010-01-29 21:56 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Spotify
2010-08-25 16:14 . 2010-03-28 14:25 -------- d-----w- c:\programdata\avg9
2010-08-24 00:21 . 2010-08-18 17:46 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\FrostWire
2010-08-23 17:33 . 2010-06-06 05:58 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Ysahfy
2010-08-22 01:03 . 2010-02-04 18:02 -------- d-----w- c:\program files\PeerBlock
2010-08-21 10:31 . 2010-08-21 00:32 112 ----a-w- c:\programdata\kA2P3gX4O.dat
2010-08-21 00:52 . 2010-08-20 21:56 -------- d-----w- c:\programdata\STOPzilla!
2010-08-21 00:48 . 2010-08-21 00:48 224 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-21 00:09 . 2010-08-21 00:09 -------- d-----w- c:\program files\Common Files\Java
2010-08-21 00:09 . 2010-02-19 21:57 -------- d-----w- c:\program files\Java
2010-08-20 22:57 . 2010-01-17 17:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 21:58 . 2010-08-20 22:01 1129120 ----a-w- c:\programdata\STOPzilla!\vdb\vbcorent.dll
2010-08-18 18:01 . 2010-08-18 18:01 0 ----a-w- c:\users\Bobby Digital\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-08-18 17:47 . 2010-08-18 17:45 -------- d-----w- c:\program files\FrostWire
2010-08-14 19:41 . 2010-08-14 19:40 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-08-14 19:37 . 2010-08-14 19:37 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Media Player Classic
2010-08-12 22:36 . 2010-08-12 22:36 -------- d-----w- c:\program files\GPL MPEG Decoder
2010-08-12 08:00 . 2010-08-14 19:41 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-08-10 21:05 . 2010-08-08 14:46 -------- d-----w- c:\program files\Ask.com
2010-08-08 14:46 . 2010-08-08 14:46 -------- d-----w- c:\program files\SopCast
2010-08-06 10:21 . 2010-08-06 10:21 -------- d-----w- c:\program files\CCleaner
2010-07-29 06:30 . 2010-08-11 13:18 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 13:18 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 04:00 . 2010-08-21 00:09 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-14 14:51 . 2010-07-14 14:51 10274313 ----a-w- c:\users\Bobby Digital\AppData\Roaming\bizarre creations\blur\BizUpdaterPack.exe
2010-07-09 15:37 . 2010-07-09 15:37 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 15:37 . 2010-07-09 15:37 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 15:37 . 2010-07-09 15:37 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 15:37 . 2010-07-09 15:37 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-30 06:25 . 2010-08-11 13:18 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

<pre>
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\IObit\IObit Security 360\IS360tray .exe
c:\windows\WindowsMobile\wmdcBase .exe
</pre>

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"<NO NAME>"="" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{9D4420A4-CB45-07AE-2EBC-143FF39E05D9}

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-08-25 16:16 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2007-12-21 08:21 1443072 ----a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-08-21 12:00 136176 ----atw- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 10:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 14:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
c:\program files\Microsoft Security Essentials\msseces.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerBlock]
2009-09-28 02:02 1529432 ----a-w- c:\program files\PeerBlock\peerblock.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-01-20 07:05 217088 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 20:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-09-24 13:41 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 16:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-08-29 22:23 328568 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-27 01:05 734264 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe

R1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-08-25 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-08-25 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-08-25 243024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-08-25 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-09-20 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-08-24 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-08-24 162936]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 AVGIDSDriverw7x;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys [2010-08-25 122448]
R3 AVGIDSFilterw7x;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys [2010-08-25 30288]
R3 AVGIDSShimw7x;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys [2010-08-25 20560]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-13 13224]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2009-09-28 16472]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108328]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]
R4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S0 AVGIDSErHrw7x;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSwx.sys [2010-08-25 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-08-25 52872]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-09-13 27632]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 10:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-20 c:\windows\Tasks\AWC AutoCare.job
- c:\program files\IObit\Advanced SystemCare 3\AutoCare.exe [2010-08-20 13:10]

2010-09-21 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-08-20 14:13]

2010-08-20 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-08-20 10:08]

2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001Core.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001UA.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]

2010-08-31 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-08-31 17:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=15007&l=dis
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Bobby Digital\AppData\Roaming\Mozilla\Firefox\Profiles\x5usodvj.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&source=iglk
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15004&locale=en_UK&apn_uid=050D1F59-0333-4543-B406-7407EBCDCCF8&apn_ptnrs=PW&apn_sauid=EE86A4B7-9F30-4A92-B9AD-396593AC7F19&apn_dtid=YYYYYYYYGB&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\Bobby Digital\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-21 12:29:29
ComboFix-quarantined-files.txt 2010-09-21 11:29

Pre-Run: 289,565,245,440 bytes free
Post-Run: 289,007,763,456 bytes free

- - End Of File - - 744EDD44CA797F44E1FF9FE0155874B7

MBR check:-

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: ASRock
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: To Be Filled By O.E.M.
System Product Name: To Be Filled By O.E.M.
Logical Drives Mask: 0x0000000c

Kernel Drivers (total 191):
0x82C07000 \SystemRoot\system32\ntoskrnl.exe
0x8300B000 \SystemRoot\system32\halmacpi.dll
0x80BAC000 \SystemRoot\system32\kdcom.dll
0x8BC3A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8BCB2000 \SystemRoot\system32\PSHED.dll
0x8BCC3000 \SystemRoot\system32\BOOTVID.dll
0x8BCCB000 \SystemRoot\system32\CLFS.SYS
0x8BD0D000 \SystemRoot\system32\CI.dll
0x8BDB8000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8BE29000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8BE37000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8BE7F000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x8BE88000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8BE90000 \SystemRoot\system32\DRIVERS\pci.sys
0x8BEBA000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x8BEC5000 \SystemRoot\System32\drivers\partmgr.sys
0x8BED6000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8BEE6000 \SystemRoot\System32\drivers\volmgrx.sys
0x8BF31000 \SystemRoot\system32\DRIVERS\intelide.sys
0x8BF38000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8BF46000 \SystemRoot\System32\drivers\mountmgr.sys
0x8BF5C000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8BF65000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8BF88000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8BF91000 \SystemRoot\system32\drivers\fltmgr.sys
0x8BFC5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8C02E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8C15D000 \SystemRoot\System32\Drivers\msrpc.sys
0x8C188000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8C19B000 \SystemRoot\System32\Drivers\cng.sys
0x8C1F8000 \SystemRoot\System32\drivers\pcw.sys
0x8C206000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8C20F000 \SystemRoot\system32\drivers\ndis.sys
0x8C2C6000 \SystemRoot\system32\drivers\NETIO.SYS
0x8C304000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8C405000 \SystemRoot\System32\drivers\tcpip.sys
0x8C54E000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8C57F000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8C588000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8C5C7000 \SystemRoot\System32\Drivers\spldr.sys
0x8C5CF000 \SystemRoot\System32\drivers\rdyboost.sys
0x8C5FC000 \SystemRoot\System32\Drivers\mup.sys
0x8C60C000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8C614000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8C646000 \SystemRoot\system32\DRIVERS\disk.sys
0x8C657000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8C67C000 \SystemRoot\System32\Drivers\avgrkx86.sys
0x8C688000 \SystemRoot\System32\Drivers\AVGIDSwx.sys
0x8C69E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8C6BD000 \SystemRoot\System32\Drivers\Null.SYS
0x8C6C4000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C6CB000 \SystemRoot\System32\drivers\vga.sys
0x8C6D7000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8C6F8000 \SystemRoot\System32\drivers\watchdog.sys
0x8C705000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8C70D000 \SystemRoot\SYSTEM32\DRIVERS\RDPENCDD.SYS
0x8C715000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8C71D000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C728000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8C736000 \SystemRoot\system32\DRIVERS\avgfwd6x.sys
0x8C740000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C757000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8C762000 \SystemRoot\System32\Drivers\avgtdix.sys
0x8C79C000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8C329000 \SystemRoot\system32\drivers\afd.sys
0x8C7CE000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8C7D5000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8C383000 \SystemRoot\system32\DRIVERS\vpcnfltr.sys
0x8C393000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8C3A1000 \SystemRoot\system32\DRIVERS\serial.sys
0x8C3BB000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x92C26000 \SystemRoot\system32\drivers\vpcvmm.sys
0x92C6D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x92C7D000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x92C85000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92CC6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x92CD0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x92CDA000 \SystemRoot\System32\drivers\discache.sys
0x92CE6000 \SystemRoot\system32\drivers\csc.sys
0x92D4A000 \SystemRoot\System32\Drivers\dfsc.sys
0x92D62000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x92D70000 \SystemRoot\System32\Drivers\avgmfx86.sys
0x92D76000 \SystemRoot\System32\Drivers\avgldx86.sys
0x92DAA000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x92DCB000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x93C22000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x946A0000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x946A2000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x94759000 \SystemRoot\System32\drivers\dxgmms1.sys
0x94792000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x947B1000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x947D6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x92DDD000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x947E1000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x93C00000 \SystemRoot\system32\DRIVERS\parport.sys
0x92E28000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x947F0000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x93C18000 \SystemRoot\system32\DRIVERS\serenum.sys
0x92E40000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x92E4D000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x92E5F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x92E77000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x92E82000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92EA4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x92EBC000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x92ED3000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x92EEA000 \SystemRoot\System32\Drivers\pcouffin.sys
0x92EF6000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x92F00000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x92F0D000 \SystemRoot\system32\DRIVERS\seehcri.sys
0x947FD000 \SystemRoot\system32\DRIVERS\swenum.sys
0x92F13000 \SystemRoot\system32\DRIVERS\ks.sys
0x92F47000 \SystemRoot\system32\DRIVERS\umbus.sys
0x92F55000 \SystemRoot\system32\DRIVERS\vpcusb.sys
0x92F6D000 \SystemRoot\system32\DRIVERS\usbrpm.sys
0x92F7A000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x92F7C000 \SystemRoot\system32\DRIVERS\vpchbus.sys
0x92FB2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x92C00000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x95C36000 \SystemRoot\system32\drivers\HdAudio.sys
0x95C86000 \SystemRoot\system32\drivers\portcls.sys
0x95CB5000 \SystemRoot\system32\drivers\drmk.sys
0x96C40000 \SystemRoot\System32\win32k.sys
0x95CCE000 \SystemRoot\System32\drivers\Dxapi.sys
0x95CE5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x95CF0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x95D03000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x95D0A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x95D15000 \SystemRoot\system32\DRIVERS\monitor.sys
0x96EA0000 \SystemRoot\System32\TSDDD.dll
0x96ED0000 \SystemRoot\System32\cdd.dll
0x95D20000 \SystemRoot\system32\DRIVERS\xusb21.sys
0x95D2F000 \SystemRoot\system32\drivers\luafv.sys
0x95D4A000 \SystemRoot\system32\drivers\WudfPf.sys
0x95D64000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x95D74000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x95D87000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys
0x95D90000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys
0x95D9A000 \SystemRoot\system32\drivers\HTTP.sys
0x95E1F000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys
0x95E47000 \SystemRoot\system32\DRIVERS\bowser.sys
0x95E60000 \SystemRoot\System32\drivers\mpsdrv.sys
0x95E72000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x95E95000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x95ED0000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x95EEB000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x95EF2000 \SystemRoot\system32\drivers\peauth.sys
0x95F89000 \SystemRoot\System32\Drivers\secdrv.SYS
0x95F93000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x95FB4000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAB430000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAB47F000 \SystemRoot\System32\DRIVERS\srv.sys
0x77CB0000 \Windows\System32\ntdll.dll
0x47D20000 \Windows\System32\smss.exe
0x77EF0000 \Windows\System32\apisetschema.dll
0x00F30000 \Windows\System32\autochk.exe
0x77B10000 \Windows\System32\setupapi.dll
0x779D0000 \Windows\System32\urlmon.dll
0x778D0000 \Windows\System32\wininet.dll
0x77E30000 \Windows\System32\msvcrt.dll
0x77830000 \Windows\System32\usp10.dll
0x77790000 \Windows\System32\advapi32.dll
0x77630000 \Windows\System32\ole32.dll
0x77E10000 \Windows\System32\imm32.dll
0x77430000 \Windows\System32\iertutil.dll
0x773E0000 \Windows\System32\gdi32.dll
0x77E00000 \Windows\System32\normaliz.dll
0x77360000 \Windows\System32\comdlg32.dll
0x77290000 \Windows\System32\msctf.dll
0x77DF0000 \Windows\System32\nsi.dll
0x771C0000 \Windows\System32\user32.dll
0x77160000 \Windows\System32\difxapi.dll
0x770B0000 \Windows\System32\rpcrt4.dll
0x76FD0000 \Windows\System32\kernel32.dll
0x76FC0000 \Windows\System32\lpk.dll
0x76F60000 \Windows\System32\shlwapi.dll
0x76F10000 \Windows\System32\Wldap32.dll
0x76EF0000 \Windows\System32\sechost.dll
0x76EE0000 \Windows\System32\psapi.dll
0x76E50000 \Windows\System32\oleaut32.dll
0x76E20000 \Windows\System32\imagehlp.dll
0x76DE0000 \Windows\System32\ws2_32.dll
0x76D50000 \Windows\System32\clbcatq.dll
0x76100000 \Windows\System32\shell32.dll
0x760D0000 \Windows\System32\wintrust.dll
0x760A0000 \Windows\System32\cfgmgr32.dll
0x76080000 \Windows\System32\devobj.dll
0x76030000 \Windows\System32\KernelBase.dll
0x75F10000 \Windows\System32\crypt32.dll
0x75E80000 \Windows\System32\comctl32.dll
0x75E70000 \Windows\System32\msasn1.dll

Processes (total 57):
0 System Idle Process
4 System
316 C:\Windows\System32\smss.exe
408 csrss.exe
476 C:\Windows\System32\wininit.exe
484 csrss.exe
524 C:\Windows\System32\services.exe
540 C:\Windows\System32\lsass.exe
552 C:\Windows\System32\lsm.exe
644 C:\Windows\System32\winlogon.exe
712 C:\Windows\System32\svchost.exe
776 C:\Windows\System32\nvvsvc.exe
804 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1016 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\audiodg.exe
1140 C:\Windows\System32\svchost.exe
1248 C:\Windows\System32\svchost.exe
1344 C:\Windows\System32\nvvsvc.exe
1412 C:\Windows\System32\spoolsv.exe
1448 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
1660 C:\Windows\System32\dwm.exe
1668 C:\Windows\System32\taskhost.exe
1716 C:\Windows\explorer.exe
1832 C:\Windows\System32\taskeng.exe
1944 C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
800 C:\Program Files\Windows Sidebar\sidebar.exe
1536 C:\Windows\System32\svchost.exe
1808 C:\Program Files\AVG\AVG9\avgwdsvc.exe
424 C:\Program Files\AVG\AVG9\avgfws9.exe
916 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
936 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
1516 C:\Windows\System32\svchost.exe
392 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2076 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
2152 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
2208 C:\Windows\System32\svchost.exe
2260 C:\Windows\System32\svchost.exe
2772 C:\Program Files\AVG\AVG9\avgam.exe
3020 C:\Program Files\AVG\AVG9\avgnsx.exe
3308 C:\Windows\System32\SearchIndexer.exe
3388 WmiPrvSE.exe
3532 C:\Windows\System32\svchost.exe
3788 C:\Program Files\Windows Media Player\wmpnetwk.exe
4044 C:\Program Files\AVG\AVG9\avgcsrvx.exe
4092 C:\Program Files\AVG\AVG9\avgrsx.exe
2140 C:\Program Files\AVG\AVG9\avgchsvx.exe
468 WmiPrvSE.exe
3240 C:\Program Files\AVG\AVG9\avgcsrvx.exe
1492 C:\Windows\System32\SearchProtocolHost.exe
3740 C:\Windows\System32\SearchFilterHost.exe
4108 C:\Windows\System32\svchost.exe
4496 C:\Users\Bobby Digital\Desktop\MBRCheck.exe
4508 C:\Windows\System32\conhost.exe
4540 C:\Windows\System32\dllhost.exe
4972 <unknown>

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00004400 (NTFS)

PhysicalDrive0 Model Number: HitachiHDP725050GLA360, Rev: GM4OA5CA

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!

ComboFix:-

ComboFix 10-09-20.01 - Bobby Digital 21/09/2010 12:21:31.2.4 - x86 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3263.2556 [GMT 1:00]
Running from: c:\users\Bobby Digital\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Outdated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\ErrLog.txt
C:\install.exe
c:\programdata\hpe78A6.dll
c:\programdata\hpeD27B.dll
c:\users\Bobby Digital\AppData\Roaming\inst.exe
c:\windows\system32\system

.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.

2010-09-21 11:28 . 2010-09-21 11:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-21 11:20 . 2010-09-21 11:21 -------- d-----w- C:\32788R22FWJFW
2010-09-21 11:17 . 2010-09-21 11:17 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-09-20 21:50 . 2010-09-21 11:28 -------- d-----w- c:\users\Bobby Digital\AppData\Local\temp
2010-09-20 20:08 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-20 19:46 . 2010-09-21 10:10 -------- d-----w- c:\program files\SpywareBlaster
2010-09-20 19:40 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-20 19:39 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-09-20 19:39 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-20 19:39 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-09-20 19:39 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-09-20 19:39 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-09-20 19:39 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-09-20 11:36 . 2010-09-20 11:36 4093792 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-09-20 11:36 . 2010-09-20 11:36 3586912 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-09-20 11:36 . 2010-09-20 11:36 620896 ----a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2010-09-20 11:36 . 2010-09-20 11:36 1619296 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-09-20 11:36 . 2010-09-20 11:36 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-20 11:36 . 2010-09-20 11:36 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-20 11:36 . 2010-09-20 11:36 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-20 11:36 . 2010-09-20 11:36 5649320 ----a-w- c:\programdata\avg9\update\backup\winspamcatcher.dll
2010-09-20 11:36 . 2010-09-20 11:36 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-20 11:36 . 2010-09-20 11:36 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-20 11:36 . 2010-09-20 11:36 2331032 ----a-w- c:\programdata\avg9\update\backup\avgfws9.exe
2010-09-20 11:35 . 2010-09-20 11:35 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-19 19:50 . 2010-09-19 19:50 6656 ----a-w- c:\windows\system32\drivers\qzsjgnvx.sys
2010-09-15 20:12 . 2010-09-15 20:12 81016 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\71\1\.cp\lib\S1SLEngineWrapper.dll
2010-09-15 20:12 . 2010-09-15 20:12 1772664 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQ.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\61\1\.cp\lib\MemStickFlash.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQFlash.dll
2010-09-15 20:10 . 2010-09-15 20:10 101496 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\81\1\.cp\lib\USBFlash.dll
2010-09-15 20:03 . 2010-09-15 20:03 56440 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\73\1\.cp\lib\sef3x1Controller.dll
2010-09-15 19:49 . 2010-09-15 19:49 109752 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\67\1\.cp\lib\osds.dll
2010-09-15 19:49 . 2010-09-15 19:49 85176 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\79\1\.cp\lib\UAC.dll
2010-09-15 19:49 . 2010-09-15 19:49 57344 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\4\1\.cp\lib\serialio.dll
2010-09-15 19:49 . 2010-09-15 19:49 323648 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DIFxAPI.dll
2010-09-15 19:49 . 2010-09-15 19:49 216184 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\69\1\.cp\lib\RegistryReader.dll
2010-09-15 19:49 . 2010-09-15 19:49 158840 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DriverInstaller.exe
2010-09-15 19:49 . 2010-09-15 19:49 154744 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\8\1\.cp\lib\win32\DeviceRemover.exe
2010-09-15 19:49 . 2010-09-15 19:49 117880 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\6\1\.cp\lib\DeviceManager.dll
2010-09-15 19:48 . 2010-09-15 19:48 -------- d-----w- c:\program files\Common Files\Sony Ericsson
2010-09-15 19:41 . 2010-09-15 19:41 -------- d-----w- c:\program files\Avanquest update
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\users\Bobby Digital\AppData\Local\Sony Ericsson
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\programdata\BVRP Software
2010-09-14 13:49 . 2010-09-14 13:49 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-14 03:37 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 03:37 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 03:24 . 2010-09-14 03:24 6656 ----a-w- c:\windows\system32\drivers\pacbmxlf.sys
2010-09-14 03:22 . 2010-09-19 19:50 -------- d-----w- c:\windows\system32\MpEngineStore
2010-09-13 15:01 . 2010-09-13 15:01 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-09-13 15:00 . 2010-09-13 15:00 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-09-13 15:00 . 2010-09-13 15:00 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2010-09-13 15:00 . 2010-09-13 15:00 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2010-09-13 14:59 . 2010-09-15 19:48 -------- d-----w- c:\program files\Sony Ericsson
2010-09-11 18:27 . 2010-09-11 18:27 -------- d-----w- c:\users\Bobby Digital\AppData\Local\AVG Security Toolbar
2010-09-09 17:50 . 2010-09-09 17:50 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-09-07 04:03 . 2010-09-07 04:03 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-08-31 18:01 . 2010-08-31 18:01 -------- d-----w- c:\program files\VideoLAN
2010-08-31 17:35 . 2010-08-31 17:35 -------- d-----w- c:\program files\Your Uninstaller 2010
2010-08-27 23:18 . 2010-08-27 23:18 -------- d-----w- C:\$AVG
2010-08-27 16:14 . 2010-08-27 16:14 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\AVG9
2010-08-25 16:17 . 2010-08-25 16:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-25 16:17 . 2010-08-25 16:17 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-25 16:17 . 2010-08-25 16:17 25168 ----a-w- c:\windows\system32\drivers\AVGIDSwx.sys
2010-08-25 16:17 . 2010-08-25 16:17 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-25 16:17 . 2010-08-25 16:17 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-25 16:17 . 2010-09-21 08:40 -------- d-----w- c:\windows\system32\drivers\Avg
2010-08-25 16:17 . 2010-08-25 16:17 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-25 16:15 . 2010-08-25 16:15 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-08-23 21:19 . 2010-08-23 21:19 6656 ----a-w- c:\windows\system32\drivers\kjkwpvpg.sys
2010-08-23 19:44 . 2010-08-23 19:44 6656 ----a-w- c:\windows\system32\drivers\jhojzwca.sys
2010-08-23 18:58 . 2010-08-23 18:58 6656 ----a-w- c:\windows\system32\drivers\rkixfjlc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 09:27 . 2010-05-13 01:18 0 ----a-w- c:\users\Bobby Digital\AppData\Local\prvlcl.dat
2010-09-21 09:14 . 2010-01-17 17:25 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\uTorrent
2010-09-20 21:27 . 2010-01-17 15:33 87400 ----a-w- c:\users\Bobby Digital\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-20 20:32 . 2010-01-24 20:32 -------- d-----w- c:\programdata\NVIDIA
2010-09-20 20:32 . 2010-01-31 11:03 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-20 19:59 . 2010-06-21 13:48 -------- d-----w- c:\program files\Microsoft.NET
2010-09-20 19:35 . 2009-07-14 00:01 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys
2010-09-16 14:59 . 2010-01-17 16:52 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Vso
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf
2010-09-15 19:48 . 2010-09-15 19:35 -------- d-----w- c:\programdata\Sony Ericsson
2010-09-15 19:42 . 2010-07-14 14:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-14 03:37 . 2010-08-20 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 03:37 . 2010-05-23 22:03 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
2010-09-07 04:03 . 2010-04-05 13:48 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-07 04:03 . 2010-04-05 13:48 -------- d-----w- c:\programdata\DivX
2010-09-07 04:03 . 2010-01-17 16:00 -------- d-----w- c:\program files\DivX
2010-09-07 04:02 . 2010-09-01 15:22 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-07 04:02 . 2010-09-01 15:22 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-07 04:02 . 2010-08-16 19:02 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-07 03:59 . 2010-09-01 15:22 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-01 15:22 . 2010-01-17 16:00 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-01 12:43 . 2010-08-10 19:45 530158 ----a-w- c:\programdata\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-08-31 20:30 . 2010-01-17 17:10 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\IObit
2010-08-31 20:30 . 2010-01-17 16:56 -------- d-----w- c:\program files\IObit
2010-08-31 17:39 . 2010-02-19 18:16 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\DivX
2010-08-31 17:36 . 2010-01-17 17:03 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\URSoft
2010-08-31 17:32 . 2010-01-17 17:03 -------- d-----w- c:\program files\Your Uninstaller 2008
2010-08-30 09:39 . 2010-01-17 17:25 -------- d-----w- c:\program files\uTorrent
2010-08-27 23:18 . 2010-05-10 21:44 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Royh
2010-08-25 18:04 . 2010-01-29 21:56 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Spotify
2010-08-25 16:14 . 2010-03-28 14:25 -------- d-----w- c:\programdata\avg9
2010-08-24 00:21 . 2010-08-18 17:46 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\FrostWire
2010-08-23 17:33 . 2010-06-06 05:58 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Ysahfy
2010-08-22 01:03 . 2010-02-04 18:02 -------- d-----w- c:\program files\PeerBlock
2010-08-21 10:31 . 2010-08-21 00:32 112 ----a-w- c:\programdata\kA2P3gX4O.dat
2010-08-21 00:52 . 2010-08-20 21:56 -------- d-----w- c:\programdata\STOPzilla!
2010-08-21 00:48 . 2010-08-21 00:48 224 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-21 00:09 . 2010-08-21 00:09 -------- d-----w- c:\program files\Common Files\Java
2010-08-21 00:09 . 2010-02-19 21:57 -------- d-----w- c:\program files\Java
2010-08-20 22:57 . 2010-01-17 17:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 21:58 . 2010-08-20 22:01 1129120 ----a-w- c:\programdata\STOPzilla!\vdb\vbcorent.dll
2010-08-18 18:01 . 2010-08-18 18:01 0 ----a-w- c:\users\Bobby Digital\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-08-18 17:47 . 2010-08-18 17:45 -------- d-----w- c:\program files\FrostWire
2010-08-14 19:41 . 2010-08-14 19:40 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-08-14 19:37 . 2010-08-14 19:37 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Media Player Classic
2010-08-12 22:36 . 2010-08-12 22:36 -------- d-----w- c:\program files\GPL MPEG Decoder
2010-08-12 08:00 . 2010-08-14 19:41 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-08-10 21:05 . 2010-08-08 14:46 -------- d-----w- c:\program files\Ask.com
2010-08-08 14:46 . 2010-08-08 14:46 -------- d-----w- c:\program files\SopCast
2010-08-06 10:21 . 2010-08-06 10:21 -------- d-----w- c:\program files\CCleaner
2010-07-29 06:30 . 2010-08-11 13:18 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 13:18 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 04:00 . 2010-08-21 00:09 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-14 14:51 . 2010-07-14 14:51 10274313 ----a-w- c:\users\Bobby Digital\AppData\Roaming\bizarre creations\blur\BizUpdaterPack.exe
2010-07-09 15:37 . 2010-07-09 15:37 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 15:37 . 2010-07-09 15:37 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 15:37 . 2010-07-09 15:37 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 15:37 . 2010-07-09 15:37 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-30 06:25 . 2010-08-11 13:18 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

<pre>
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\IObit\IObit Security 360\IS360tray .exe
c:\windows\WindowsMobile\wmdcBase .exe
</pre>

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"<NO NAME>"="" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{9D4420A4-CB45-07AE-2EBC-143FF39E05D9}

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-08-25 16:16 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2007-12-21 08:21 1443072 ----a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-08-21 12:00 136176 ----atw- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 10:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 14:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
c:\program files\Microsoft Security Essentials\msseces.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerBlock]
2009-09-28 02:02 1529432 ----a-w- c:\program files\PeerBlock\peerblock.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-01-20 07:05 217088 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 20:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-09-24 13:41 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 16:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-08-29 22:23 328568 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-27 01:05 734264 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe

R1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-08-25 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-08-25 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-08-25 243024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-08-25 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-09-20 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-08-24 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-08-24 162936]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 AVGIDSDriverw7x;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys [2010-08-25 122448]
R3 AVGIDSFilterw7x;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys [2010-08-25 30288]
R3 AVGIDSShimw7x;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys [2010-08-25 20560]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-13 13224]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2009-09-28 16472]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108328]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]
R4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S0 AVGIDSErHrw7x;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSwx.sys [2010-08-25 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-08-25 52872]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-09-13 27632]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 10:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-20 c:\windows\Tasks\AWC AutoCare.job
- c:\program files\IObit\Advanced SystemCare 3\AutoCare.exe [2010-08-20 13:10]

2010-09-21 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-08-20 14:13]

2010-08-20 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-08-20 10:08]

2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001Core.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001UA.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]

2010-08-31 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-08-31 17:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=15007&l=dis
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Bobby Digital\AppData\Roaming\Mozilla\Firefox\Profiles\x5usodvj.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&source=iglk
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15004&locale=en_UK&apn_uid=050D1F59-0333-4543-B406-7407EBCDCCF8&apn_ptnrs=PW&apn_sauid=EE86A4B7-9F30-4A92-B9AD-396593AC7F19&apn_dtid=YYYYYYYYGB&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\Bobby Digital\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-21 12:29:29
ComboFix-quarantined-files.txt 2010-09-21 11:29

Pre-Run: 289,565,245,440 bytes free
Post-Run: 289,007,763,456 bytes free

- - End Of File - - 744EDD44CA797F44E1FF9FE0155874B7

MBR check:-

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: ASRock
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: To Be Filled By O.E.M.
System Product Name: To Be Filled By O.E.M.
Logical Drives Mask: 0x0000000c

Kernel Drivers (total 191):
0x82C07000 \SystemRoot\system32\ntoskrnl.exe
0x8300B000 \SystemRoot\system32\halmacpi.dll
0x80BAC000 \SystemRoot\system32\kdcom.dll
0x8BC3A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8BCB2000 \SystemRoot\system32\PSHED.dll
0x8BCC3000 \SystemRoot\system32\BOOTVID.dll
0x8BCCB000 \SystemRoot\system32\CLFS.SYS
0x8BD0D000 \SystemRoot\system32\CI.dll
0x8BDB8000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8BE29000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8BE37000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x8BE7F000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x8BE88000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x8BE90000 \SystemRoot\system32\DRIVERS\pci.sys
0x8BEBA000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x8BEC5000 \SystemRoot\System32\drivers\partmgr.sys
0x8BED6000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x8BEE6000 \SystemRoot\System32\drivers\volmgrx.sys
0x8BF31000 \SystemRoot\system32\DRIVERS\intelide.sys
0x8BF38000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x8BF46000 \SystemRoot\System32\drivers\mountmgr.sys
0x8BF5C000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8BF65000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x8BF88000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x8BF91000 \SystemRoot\system32\drivers\fltmgr.sys
0x8BFC5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8C02E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8C15D000 \SystemRoot\System32\Drivers\msrpc.sys
0x8C188000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8C19B000 \SystemRoot\System32\Drivers\cng.sys
0x8C1F8000 \SystemRoot\System32\drivers\pcw.sys
0x8C206000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8C20F000 \SystemRoot\system32\drivers\ndis.sys
0x8C2C6000 \SystemRoot\system32\drivers\NETIO.SYS
0x8C304000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8C405000 \SystemRoot\System32\drivers\tcpip.sys
0x8C54E000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8C57F000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x8C588000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8C5C7000 \SystemRoot\System32\Drivers\spldr.sys
0x8C5CF000 \SystemRoot\System32\drivers\rdyboost.sys
0x8C5FC000 \SystemRoot\System32\Drivers\mup.sys
0x8C60C000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8C614000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8C646000 \SystemRoot\system32\DRIVERS\disk.sys
0x8C657000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8C67C000 \SystemRoot\System32\Drivers\avgrkx86.sys
0x8C688000 \SystemRoot\System32\Drivers\AVGIDSwx.sys
0x8C69E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8C6BD000 \SystemRoot\System32\Drivers\Null.SYS
0x8C6C4000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C6CB000 \SystemRoot\System32\drivers\vga.sys
0x8C6D7000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8C6F8000 \SystemRoot\System32\drivers\watchdog.sys
0x8C705000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8C70D000 \SystemRoot\SYSTEM32\DRIVERS\RDPENCDD.SYS
0x8C715000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8C71D000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C728000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8C736000 \SystemRoot\system32\DRIVERS\avgfwd6x.sys
0x8C740000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C757000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8C762000 \SystemRoot\System32\Drivers\avgtdix.sys
0x8C79C000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8C329000 \SystemRoot\system32\drivers\afd.sys
0x8C7CE000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8C7D5000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8C383000 \SystemRoot\system32\DRIVERS\vpcnfltr.sys
0x8C393000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8C3A1000 \SystemRoot\system32\DRIVERS\serial.sys
0x8C3BB000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x92C26000 \SystemRoot\system32\drivers\vpcvmm.sys
0x92C6D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x92C7D000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x92C85000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x92CC6000 \SystemRoot\system32\drivers\nsiproxy.sys
0x92CD0000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x92CDA000 \SystemRoot\System32\drivers\discache.sys
0x92CE6000 \SystemRoot\system32\drivers\csc.sys
0x92D4A000 \SystemRoot\System32\Drivers\dfsc.sys
0x92D62000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x92D70000 \SystemRoot\System32\Drivers\avgmfx86.sys
0x92D76000 \SystemRoot\System32\Drivers\avgldx86.sys
0x92DAA000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x92DCB000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x93C22000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x946A0000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x946A2000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x94759000 \SystemRoot\System32\drivers\dxgmms1.sys
0x94792000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x947B1000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x947D6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x92DDD000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x947E1000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x93C00000 \SystemRoot\system32\DRIVERS\parport.sys
0x92E28000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x947F0000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x93C18000 \SystemRoot\system32\DRIVERS\serenum.sys
0x92E40000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x92E4D000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x92E5F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x92E77000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x92E82000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x92EA4000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x92EBC000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x92ED3000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x92EEA000 \SystemRoot\System32\Drivers\pcouffin.sys
0x92EF6000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x92F00000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x92F0D000 \SystemRoot\system32\DRIVERS\seehcri.sys
0x947FD000 \SystemRoot\system32\DRIVERS\swenum.sys
0x92F13000 \SystemRoot\system32\DRIVERS\ks.sys
0x92F47000 \SystemRoot\system32\DRIVERS\umbus.sys
0x92F55000 \SystemRoot\system32\DRIVERS\vpcusb.sys
0x92F6D000 \SystemRoot\system32\DRIVERS\usbrpm.sys
0x92F7A000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x92F7C000 \SystemRoot\system32\DRIVERS\vpchbus.sys
0x92FB2000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x92C00000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x95C36000 \SystemRoot\system32\drivers\HdAudio.sys
0x95C86000 \SystemRoot\system32\drivers\portcls.sys
0x95CB5000 \SystemRoot\system32\drivers\drmk.sys
0x96C40000 \SystemRoot\System32\win32k.sys
0x95CCE000 \SystemRoot\System32\drivers\Dxapi.sys
0x95CE5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x95CF0000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x95D03000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x95D0A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x95D15000 \SystemRoot\system32\DRIVERS\monitor.sys
0x96EA0000 \SystemRoot\System32\TSDDD.dll
0x96ED0000 \SystemRoot\System32\cdd.dll
0x95D20000 \SystemRoot\system32\DRIVERS\xusb21.sys
0x95D2F000 \SystemRoot\system32\drivers\luafv.sys
0x95D4A000 \SystemRoot\system32\drivers\WudfPf.sys
0x95D64000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x95D74000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x95D87000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys
0x95D90000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys
0x95D9A000 \SystemRoot\system32\drivers\HTTP.sys
0x95E1F000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys
0x95E47000 \SystemRoot\system32\DRIVERS\bowser.sys
0x95E60000 \SystemRoot\System32\drivers\mpsdrv.sys
0x95E72000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x95E95000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x95ED0000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x95EEB000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x95EF2000 \SystemRoot\system32\drivers\peauth.sys
0x95F89000 \SystemRoot\System32\Drivers\secdrv.SYS
0x95F93000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x95FB4000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAB430000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAB47F000 \SystemRoot\System32\DRIVERS\srv.sys
0x77CB0000 \Windows\System32\ntdll.dll
0x47D20000 \Windows\System32\smss.exe
0x77EF0000 \Windows\System32\apisetschema.dll
0x00F30000 \Windows\System32\autochk.exe
0x77B10000 \Windows\System32\setupapi.dll
0x779D0000 \Windows\System32\urlmon.dll
0x778D0000 \Windows\System32\wininet.dll
0x77E30000 \Windows\System32\msvcrt.dll
0x77830000 \Windows\System32\usp10.dll
0x77790000 \Windows\System32\advapi32.dll
0x77630000 \Windows\System32\ole32.dll
0x77E10000 \Windows\System32\imm32.dll
0x77430000 \Windows\System32\iertutil.dll
0x773E0000 \Windows\System32\gdi32.dll
0x77E00000 \Windows\System32\normaliz.dll
0x77360000 \Windows\System32\comdlg32.dll
0x77290000 \Windows\System32\msctf.dll
0x77DF0000 \Windows\System32\nsi.dll
0x771C0000 \Windows\System32\user32.dll
0x77160000 \Windows\System32\difxapi.dll
0x770B0000 \Windows\System32\rpcrt4.dll
0x76FD0000 \Windows\System32\kernel32.dll
0x76FC0000 \Windows\System32\lpk.dll
0x76F60000 \Windows\System32\shlwapi.dll
0x76F10000 \Windows\System32\Wldap32.dll
0x76EF0000 \Windows\System32\sechost.dll
0x76EE0000 \Windows\System32\psapi.dll
0x76E50000 \Windows\System32\oleaut32.dll
0x76E20000 \Windows\System32\imagehlp.dll
0x76DE0000 \Windows\System32\ws2_32.dll
0x76D50000 \Windows\System32\clbcatq.dll
0x76100000 \Windows\System32\shell32.dll
0x760D0000 \Windows\System32\wintrust.dll
0x760A0000 \Windows\System32\cfgmgr32.dll
0x76080000 \Windows\System32\devobj.dll
0x76030000 \Windows\System32\KernelBase.dll
0x75F10000 \Windows\System32\crypt32.dll
0x75E80000 \Windows\System32\comctl32.dll
0x75E70000 \Windows\System32\msasn1.dll

Processes (total 57):
0 System Idle Process
4 System
316 C:\Windows\System32\smss.exe
408 csrss.exe
476 C:\Windows\System32\wininit.exe
484 csrss.exe
524 C:\Windows\System32\services.exe
540 C:\Windows\System32\lsass.exe
552 C:\Windows\System32\lsm.exe
644 C:\Windows\System32\winlogon.exe
712 C:\Windows\System32\svchost.exe
776 C:\Windows\System32\nvvsvc.exe
804 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\svchost.exe
976 C:\Windows\System32\svchost.exe
1016 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\audiodg.exe
1140 C:\Windows\System32\svchost.exe
1248 C:\Windows\System32\svchost.exe
1344 C:\Windows\System32\nvvsvc.exe
1412 C:\Windows\System32\spoolsv.exe
1448 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
1660 C:\Windows\System32\dwm.exe
1668 C:\Windows\System32\taskhost.exe
1716 C:\Windows\explorer.exe
1832 C:\Windows\System32\taskeng.exe
1944 C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
800 C:\Program Files\Windows Sidebar\sidebar.exe
1536 C:\Windows\System32\svchost.exe
1808 C:\Program Files\AVG\AVG9\avgwdsvc.exe
424 C:\Program Files\AVG\AVG9\avgfws9.exe
916 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
936 C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
1516 C:\Windows\System32\svchost.exe
392 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2076 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
2152 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
2208 C:\Windows\System32\svchost.exe
2260 C:\Windows\System32\svchost.exe
2772 C:\Program Files\AVG\AVG9\avgam.exe
3020 C:\Program Files\AVG\AVG9\avgnsx.exe
3308 C:\Windows\System32\SearchIndexer.exe
3388 WmiPrvSE.exe
3532 C:\Windows\System32\svchost.exe
3788 C:\Program Files\Windows Media Player\wmpnetwk.exe
4044 C:\Program Files\AVG\AVG9\avgcsrvx.exe
4092 C:\Program Files\AVG\AVG9\avgrsx.exe
2140 C:\Program Files\AVG\AVG9\avgchsvx.exe
468 WmiPrvSE.exe
3240 C:\Program Files\AVG\AVG9\avgcsrvx.exe
1492 C:\Windows\System32\SearchProtocolHost.exe
3740 C:\Windows\System32\SearchFilterHost.exe
4108 C:\Windows\System32\svchost.exe
4496 C:\Users\Bobby Digital\Desktop\MBRCheck.exe
4508 C:\Windows\System32\conhost.exe
4540 C:\Windows\System32\dllhost.exe
4972 <unknown>

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00004400 (NTFS)

PhysicalDrive0 Model Number: HitachiHDP725050GLA360, Rev: GM4OA5CA

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!

Please go to Jotti's or to virustotal and have these files scanned. Post the results back here.

c:\windows\system32\drivers\qzsjgnvx.sys
c:\windows\system32\drivers\kjkwpvpg.sys
c:\windows\system32\drivers\jhojzwca.sys
c:\windows\system32\drivers\rkixfjlc.sys

================

Boot into safe mode and do the following:

1. Please open Notepad

  • Click Start , then Run
  • Type notepad.exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

RENV::
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\IObit\IObit Security 360\IS360tray .exe
c:\windows\WindowsMobile\wmdcBase .exe

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}]

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Physically disconnect from the internet.

5. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

6. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[IMG]http://i5.photobucket.com/albums/y153/crunchie1/CFScript.gif[/IMG]


7. After reboot, (in case it asks to reboot), please post the following reports/logs into your next replyafter you re-enable all the programs that were disabled during the running of ComboFix:

  • Combofix.txt

Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

ComboFix 10-09-20.03 - Bobby Digital 21/09/2010 14:12:24.3.4 - x86 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3263.2897 [GMT 1:00]
Running from: c:\users\Bobby Digital\Desktop\ComboFix.exe
Command switches used :: c:\users\Bobby Digital\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Outdated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.

2010-09-21 13:17 . 2010-09-21 13:17 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-21 13:17 . 2010-09-21 13:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-21 13:10 . 2010-09-21 13:10 -------- d-----w- C:\32788R22FWJFW
2010-09-21 13:00 . 2010-09-21 13:00 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\TrojanHunter
2010-09-21 12:51 . 2010-09-21 12:52 -------- d-----w- c:\programdata\TrojanHunter
2010-09-21 12:51 . 2010-09-21 12:53 -------- d-----w- c:\program files\TrojanHunter 5.3
2010-09-21 12:40 . 2010-09-21 13:01 -------- dc----w- c:\windows\system32\DRVSTORE
2010-09-21 12:40 . 2010-09-21 12:40 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-21 12:38 . 2010-09-21 12:38 -------- d-----w- c:\users\Bobby Digital\AppData\Local\Sunbelt Software
2010-09-21 12:38 . 2010-09-21 13:01 -------- dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-21 12:38 . 2010-08-12 12:16 2979848 -c----w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-09-21 12:38 . 2010-09-21 13:01 -------- d-----w- c:\programdata\Lavasoft
2010-09-21 12:38 . 2010-09-21 12:38 -------- d-----w- c:\program files\Lavasoft
2010-09-21 11:17 . 2010-09-21 11:17 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-09-20 21:50 . 2010-09-21 13:17 -------- d-----w- c:\users\Bobby Digital\AppData\Local\temp
2010-09-20 20:08 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-20 19:46 . 2010-09-21 10:10 -------- d-----w- c:\program files\SpywareBlaster
2010-09-20 19:40 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-09-20 19:39 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-09-20 19:39 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-20 19:39 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-09-20 19:39 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-09-20 19:39 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-09-20 19:39 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-09-20 19:39 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-09-20 19:39 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-09-20 11:36 . 2010-09-20 11:36 4093792 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-09-20 11:36 . 2010-09-20 11:36 3586912 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-09-20 11:36 . 2010-09-20 11:36 620896 ----a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2010-09-20 11:36 . 2010-09-20 11:36 1619296 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-09-20 11:36 . 2010-09-20 11:36 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-20 11:36 . 2010-09-20 11:36 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-20 11:36 . 2010-09-20 11:36 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-20 11:36 . 2010-09-20 11:36 5649320 ----a-w- c:\programdata\avg9\update\backup\winspamcatcher.dll
2010-09-20 11:36 . 2010-09-20 11:36 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-20 11:36 . 2010-09-20 11:36 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-20 11:36 . 2010-09-20 11:36 2331032 ----a-w- c:\programdata\avg9\update\backup\avgfws9.exe
2010-09-20 11:35 . 2010-09-20 11:35 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-19 19:50 . 2010-09-19 19:50 6656 ----a-w- c:\windows\system32\drivers\qzsjgnvx.sys
2010-09-15 20:12 . 2010-09-15 20:12 81016 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\71\1\.cp\lib\S1SLEngineWrapper.dll
2010-09-15 20:12 . 2010-09-15 20:12 1772664 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQ.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\61\1\.cp\lib\MemStickFlash.dll
2010-09-15 20:12 . 2010-09-15 20:12 105592 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\42\1\.cp\lib\BHQFlash.dll
2010-09-15 20:10 . 2010-09-15 20:10 101496 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\81\1\.cp\lib\USBFlash.dll
2010-09-15 20:03 . 2010-09-15 20:03 56440 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\73\1\.cp\lib\sef3x1Controller.dll
2010-09-15 19:49 . 2010-09-15 19:49 109752 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\67\1\.cp\lib\osds.dll
2010-09-15 19:49 . 2010-09-15 19:49 85176 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\79\1\.cp\lib\UAC.dll
2010-09-15 19:49 . 2010-09-15 19:49 57344 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\4\1\.cp\lib\serialio.dll
2010-09-15 19:49 . 2010-09-15 19:49 323648 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DIFxAPI.dll
2010-09-15 19:49 . 2010-09-15 19:49 216184 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\69\1\.cp\lib\RegistryReader.dll
2010-09-15 19:49 . 2010-09-15 19:49 158840 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DriverInstaller.exe
2010-09-15 19:49 . 2010-09-15 19:49 154744 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\8\1\.cp\lib\win32\DeviceRemover.exe
2010-09-15 19:49 . 2010-09-15 19:49 117880 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\6\1\.cp\lib\DeviceManager.dll
2010-09-15 19:48 . 2010-09-15 19:48 -------- d-----w- c:\program files\Common Files\Sony Ericsson
2010-09-15 19:41 . 2010-09-15 19:41 -------- d-----w- c:\program files\Avanquest update
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\users\Bobby Digital\AppData\Local\Sony Ericsson
2010-09-15 19:39 . 2010-09-15 19:39 -------- d-----w- c:\programdata\BVRP Software
2010-09-14 13:49 . 2010-09-14 13:49 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-14 03:37 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-14 03:37 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-14 03:24 . 2010-09-14 03:24 6656 ----a-w- c:\windows\system32\drivers\pacbmxlf.sys
2010-09-14 03:22 . 2010-09-19 19:50 -------- d-----w- c:\windows\system32\MpEngineStore
2010-09-13 15:01 . 2010-09-13 15:01 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-09-13 15:00 . 2010-09-13 15:00 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-09-13 15:00 . 2010-09-13 15:00 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2010-09-13 15:00 . 2010-09-13 15:00 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2010-09-13 14:59 . 2010-09-15 19:48 -------- d-----w- c:\program files\Sony Ericsson
2010-09-11 18:27 . 2010-09-11 18:27 -------- d-----w- c:\users\Bobby Digital\AppData\Local\AVG Security Toolbar
2010-09-09 17:50 . 2010-09-09 17:50 -------- d-----w- c:\programdata\AVG Security Toolbar
2010-09-07 04:03 . 2010-09-07 04:03 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-07 04:03 . 2010-09-07 04:03 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-08-31 18:01 . 2010-08-31 18:01 -------- d-----w- c:\program files\VideoLAN
2010-08-31 17:35 . 2010-08-31 17:35 -------- d-----w- c:\program files\Your Uninstaller 2010
2010-08-27 23:18 . 2010-08-27 23:18 -------- d-----w- C:\$AVG
2010-08-27 16:14 . 2010-08-27 16:14 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\AVG9
2010-08-25 16:17 . 2010-08-25 16:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-25 16:17 . 2010-08-25 16:17 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-08-25 16:17 . 2010-08-25 16:17 25168 ----a-w- c:\windows\system32\drivers\AVGIDSwx.sys
2010-08-25 16:17 . 2010-08-25 16:17 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-25 16:17 . 2010-08-25 16:17 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-25 16:17 . 2010-09-21 11:34 -------- d-----w- c:\windows\system32\drivers\Avg
2010-08-25 16:17 . 2010-08-25 16:17 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-25 16:15 . 2010-08-25 16:15 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-08-23 21:19 . 2010-08-23 21:19 6656 ----a-w- c:\windows\system32\drivers\kjkwpvpg.sys
2010-08-23 19:44 . 2010-08-23 19:44 6656 ----a-w- c:\windows\system32\drivers\jhojzwca.sys
2010-08-23 18:58 . 2010-08-23 18:58 6656 ----a-w- c:\windows\system32\drivers\rkixfjlc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 12:57 . 2010-05-13 01:18 0 ----a-w- c:\users\Bobby Digital\AppData\Local\prvlcl.dat
2010-09-21 12:46 . 2010-02-04 18:02 -------- d-----w- c:\program files\PeerBlock
2010-09-21 12:40 . 2010-01-17 16:52 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Vso
2010-09-21 12:36 . 2010-01-17 17:25 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\uTorrent
2010-09-20 21:27 . 2010-01-17 15:33 87400 ----a-w- c:\users\Bobby Digital\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-20 20:32 . 2010-01-24 20:32 -------- d-----w- c:\programdata\NVIDIA
2010-09-20 20:32 . 2010-01-31 11:03 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-20 19:59 . 2010-06-21 13:48 -------- d-----w- c:\program files\Microsoft.NET
2010-09-20 19:35 . 2009-07-14 00:01 6656 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2010-09-15 19:58 . 2010-09-15 19:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf
2010-09-15 19:48 . 2010-09-15 19:35 -------- d-----w- c:\programdata\Sony Ericsson
2010-09-15 19:42 . 2010-07-14 14:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-14 03:37 . 2010-08-20 23:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-14 03:37 . 2010-05-23 22:03 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
2010-09-07 04:03 . 2010-04-05 13:48 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-07 04:03 . 2010-04-05 13:48 -------- d-----w- c:\programdata\DivX
2010-09-07 04:03 . 2010-01-17 16:00 -------- d-----w- c:\program files\DivX
2010-09-07 04:02 . 2010-09-01 15:22 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-07 04:02 . 2010-09-01 15:22 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-07 04:02 . 2010-08-16 19:02 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-07 03:59 . 2010-09-01 15:22 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-01 15:22 . 2010-01-17 16:00 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-01 12:43 . 2010-08-10 19:45 530158 ----a-w- c:\programdata\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-08-31 20:30 . 2010-01-17 17:10 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\IObit
2010-08-31 20:30 . 2010-01-17 16:56 -------- d-----w- c:\program files\IObit
2010-08-31 17:39 . 2010-02-19 18:16 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\DivX
2010-08-31 17:36 . 2010-01-17 17:03 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\URSoft
2010-08-31 17:32 . 2010-01-17 17:03 -------- d-----w- c:\program files\Your Uninstaller 2008
2010-08-30 09:39 . 2010-01-17 17:25 -------- d-----w- c:\program files\uTorrent
2010-08-27 23:18 . 2010-05-10 21:44 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Royh
2010-08-25 18:04 . 2010-01-29 21:56 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Spotify
2010-08-25 16:14 . 2010-03-28 14:25 -------- d-----w- c:\programdata\avg9
2010-08-24 00:21 . 2010-08-18 17:46 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\FrostWire
2010-08-23 17:33 . 2010-06-06 05:58 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Ysahfy
2010-08-21 10:31 . 2010-08-21 00:32 112 ----a-w- c:\programdata\kA2P3gX4O.dat
2010-08-21 00:52 . 2010-08-20 21:56 -------- d-----w- c:\programdata\STOPzilla!
2010-08-21 00:48 . 2010-08-21 00:48 224 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-08-21 00:09 . 2010-08-21 00:09 -------- d-----w- c:\program files\Common Files\Java
2010-08-21 00:09 . 2010-02-19 21:57 -------- d-----w- c:\program files\Java
2010-08-20 22:57 . 2010-01-17 17:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-20 21:58 . 2010-08-20 22:01 1129120 ----a-w- c:\programdata\STOPzilla!\vdb\vbcorent.dll
2010-08-18 18:01 . 2010-08-18 18:01 0 ----a-w- c:\users\Bobby Digital\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-08-18 17:47 . 2010-08-18 17:45 -------- d-----w- c:\program files\FrostWire
2010-08-14 19:41 . 2010-08-14 19:40 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-08-14 19:37 . 2010-08-14 19:37 -------- d-----w- c:\users\Bobby Digital\AppData\Roaming\Media Player Classic
2010-08-12 22:36 . 2010-08-12 22:36 -------- d-----w- c:\program files\GPL MPEG Decoder
2010-08-12 08:00 . 2010-08-14 19:41 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-08-10 21:05 . 2010-08-08 14:46 -------- d-----w- c:\program files\Ask.com
2010-08-08 14:46 . 2010-08-08 14:46 -------- d-----w- c:\program files\SopCast
2010-08-06 10:21 . 2010-08-06 10:21 -------- d-----w- c:\program files\CCleaner
2010-07-29 06:30 . 2010-08-11 13:18 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 13:18 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 04:00 . 2010-08-21 00:09 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-14 14:51 . 2010-07-14 14:51 10274313 ----a-w- c:\users\Bobby Digital\AppData\Roaming\bizarre creations\blur\BizUpdaterPack.exe
2010-07-09 15:37 . 2010-07-09 15:37 1469544 ----a-w- c:\windows\system32\nvsvc.dll
2010-07-09 15:37 . 2010-07-09 15:37 13939816 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 15:37 . 2010-07-09 15:37 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 15:37 . 2010-07-09 15:37 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-30 06:25 . 2010-08-11 13:18 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-09-21_11.28.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-21 12:37 . 2010-09-21 12:37 80896 c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfcm90ud.dll
+ 2010-09-21 12:37 . 2010-09-21 12:37 80896 c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfcm90d.dll
+ 2010-01-17 16:51 . 2010-09-21 12:43 38186 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-09-21 12:43 31512 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-17 15:25 . 2010-09-21 12:43 15044 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4069786763-3556713811-4017036512-1001_UserData.bin
+ 2010-09-21 12:51 . 2010-09-21 12:52 59392 c:\windows\System32\streamhlp.dll
+ 2010-01-17 15:18 . 2010-09-21 13:03 81920 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-17 15:18 . 2010-09-21 11:17 81920 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:41 . 2010-09-21 11:17 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2010-09-21 13:03 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-17 15:25 . 2010-09-21 08:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:34 . 2010-09-21 12:44 71736 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-17 15:25 . 2010-09-21 08:36 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-17 15:25 . 2010-09-21 08:36 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-17 15:25 . 2010-09-21 08:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-01-17 20:01 . 2010-09-21 11:13 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-17 20:01 . 2010-09-21 12:08 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-17 20:01 . 2010-09-21 12:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-01-17 20:01 . 2010-09-21 11:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-01-17 20:01 . 2010-09-21 11:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-01-17 20:01 . 2010-09-21 12:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-17 15:25 . 2010-09-21 11:13 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-01-17 15:25 . 2010-09-21 08:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-17 15:25 . 2010-09-21 12:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-21 11:17 . 2010-09-21 11:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-21 13:03 . 2010-09-21 13:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-21 11:17 . 2010-09-21 11:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-21 13:03 . 2010-09-21 13:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-21 12:37 . 2010-09-21 12:37 875520 c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcp90d.dll
+ 2010-09-21 12:37 . 2010-09-21 12:37 312832 c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcm90d.dll
+ 2007-05-31 16:21 . 2007-05-31 16:21 648072 c:\windows\WindowsMobile\wmdcBase.exe
+ 2008-08-31 19:35 . 2008-08-31 19:35 240128 c:\windows\Installer\3da2c3.msi
+ 2010-09-21 12:37 . 2010-09-21 12:37 5982720 c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfc90ud.dll
+ 2010-09-21 12:37 . 2010-09-21 12:37 5937144 c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfc90d.dll
+ 2010-09-21 12:37 . 2010-09-21 12:37 1180672 c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcr90d.dll
- 2010-01-17 15:18 . 2010-09-21 11:17 1343488 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-17 15:18 . 2010-09-21 13:03 1343488 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:34 . 2010-09-21 12:44 3606621 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:34 . 2010-09-20 21:28 3606621 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-01-17 23:07 . 2010-09-21 12:37 28901711 c:\windows\winsxs\ManifestCache\5e6635d15edac146_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-06-22 09:41 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2007-12-21 08:21 1443072 ----a-w- c:\program files\ESET\ESET Smart Security\egui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-08-21 12:00 136176 ----atw- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 10:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 14:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-01-20 07:05 217088 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 20:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-09-24 13:41 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 16:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2010-06-16 17:13 1070296 ----a-w- c:\program files\TrojanHunter 5.3\THGuard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-08-29 22:23 328568 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
2007-09-27 01:05 734264 ----a-w- c:\program files\Microsoft Xbox 360 Accessories\XBoxStat.exe

R1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-08-25 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-08-25 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-08-25 243024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-08-25 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-09-20 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-08-24 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-08-24 162936]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-04-19 430152]
R3 AVGIDSDriverw7x;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys [2010-08-25 122448]
R3 AVGIDSFilterw7x;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys [2010-08-25 30288]
R3 AVGIDSShimw7x;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys [2010-08-25 20560]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-09-13 13224]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [x]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108328]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]
R4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S0 AVGIDSErHrw7x;AVG9IDSErHr;c:\windows\System32\Drivers\AVGIDSwx.sys [2010-08-25 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-08-25 52872]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-09-13 27632]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 10:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-21 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-08-20 14:13]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001Core.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4069786763-3556713811-4017036512-1001UA.job
- c:\users\Bobby Digital\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-21 12:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=15007&l=dis
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Bobby Digital\AppData\Roaming\Mozilla\Firefox\Profiles\x5usodvj.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&source=iglk
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15004&locale=en_UK&apn_uid=050D1F59-0333-4543-B406-7407EBCDCCF8&apn_ptnrs=PW&apn_sauid=EE86A4B7-9F30-4A92-B9AD-396593AC7F19&apn_dtid=YYYYYYYYGB&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\Bobby Digital\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-RunOnce-<NO NAME> - (no file)
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-PeerBlock - c:\program files\PeerBlock\peerblock.exe


.
Completion time: 2010-09-21 14:18:48
ComboFix-quarantined-files.txt 2010-09-21 13:18
ComboFix2.txt 2010-09-21 11:29

Pre-Run: 287,973,744,640 bytes free
Post-Run: 287,530,180,608 bytes free

- - End Of File - - D2B5A33AEBB6F59366019B6635A57769

Please go to Jotti's or to virustotal and have these files scanned. Post the results back here.

c:\windows\system32\drivers\qzsjgnvx.sys
c:\windows\system32\drivers\kjkwpvpg.sys
c:\windows\system32\drivers\jhojzwca.sys
c:\windows\system32\drivers\rkixfjlc.sys

================

I need these done too.

Done those, nothing to report

When I wrote 'post the results back here' I meant the results as they are shown on the site.
Those files do not look right. What did Jotti's actually report?

c:\windows\system32\drivers\qzsjgnvx.sys

File size: 6656 bytes
Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5: 5a53ca1598dd4156d44196d200c94b8a
SHA1: 83cc73e2f2cebb11b179f4cd7e862d3698e8bda3

c:\windows\system32\drivers\kjkwpvpg.sys

File size: 6656 bytes
Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5: 5a53ca1598dd4156d44196d200c94b8a
SHA1: 83cc73e2f2cebb11b179f4cd7e862d3698e8bda3

c:\windows\system32\drivers\jhojzwca.sys

File size: 6656 bytes
Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5: 5a53ca1598dd4156d44196d200c94b8a
SHA1: 83cc73e2f2cebb11b179f4cd7e862d3698e8bda3

c:\windows\system32\drivers\rkixfjlc.sys

File size: 6656 bytes
Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5: 5a53ca1598dd4156d44196d200c94b8a
SHA1: 83cc73e2f2cebb11b179f4cd7e862d3698e8bda3

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    c:\windows\system32\drivers\qzsjgnvx.sys
    c:\windows\system32\drivers\kjkwpvpg.sys
    c:\windows\system32\drivers\jhojzwca.sys
    c:\windows\system32\drivers\rkixfjlc.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

SystemLook:-

SystemLook 04.09.10 by jpshortstuff
Log created at 11:26 on 22/09/2010 by Bobby Digital
Administrator - Elevation successful

========== file ==========

c:\windows\system32\drivers\qzsjgnvx.sys - File found and opened.
MD5: 5A53CA1598DD4156D44196D200C94B8A
Created at 19:50 on 19/09/2010
Modified at 19:50 on 19/09/2010
Size: 6656 bytes
Attributes: --a----
FileDescription: RDP Encoder Miniport
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
OriginalFilename: RDPENCDD.SYS
InternalName: RDPENCDD.SYS
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

c:\windows\system32\drivers\kjkwpvpg.sys - File found and opened.
MD5: 5A53CA1598DD4156D44196D200C94B8A
Created at 21:19 on 23/08/2010
Modified at 21:19 on 23/08/2010
Size: 6656 bytes
Attributes: --a----
FileDescription: RDP Encoder Miniport
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
OriginalFilename: RDPENCDD.SYS
InternalName: RDPENCDD.SYS
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

c:\windows\system32\drivers\jhojzwca.sys - File found and opened.
MD5: 5A53CA1598DD4156D44196D200C94B8A
Created at 19:44 on 23/08/2010
Modified at 19:44 on 23/08/2010
Size: 6656 bytes
Attributes: --a----
FileDescription: RDP Encoder Miniport
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
OriginalFilename: RDPENCDD.SYS
InternalName: RDPENCDD.SYS
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

c:\windows\system32\drivers\rkixfjlc.sys - File found and opened.
MD5: 5A53CA1598DD4156D44196D200C94B8A
Created at 18:58 on 23/08/2010
Modified at 18:58 on 23/08/2010
Size: 6656 bytes
Attributes: --a----
FileDescription: RDP Encoder Miniport
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
ProductVersion: 6.1.7600.16385
OriginalFilename: RDPENCDD.SYS
InternalName: RDPENCDD.SYS
ProductName: Microsoft® Windows® Operating System
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.

-= EOF =-

Thats a surprise. They seem to be legit.

How is the pc at the moment?

PC's ok, a little bit slow & still getting re-directed online.

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

===============

Are you running through a router?

2010/09/22 12:28:36.0400 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/22 12:28:36.0400 ================================================================================
2010/09/22 12:28:36.0400 SystemInfo:
2010/09/22 12:28:36.0400
2010/09/22 12:28:36.0400 OS Version: 6.1.7600 ServicePack: 0.0
2010/09/22 12:28:36.0400 Product type: Workstation
2010/09/22 12:28:36.0400 ComputerName: BOBBYDIGITAL-PC
2010/09/22 12:28:36.0404 UserName: Bobby Digital
2010/09/22 12:28:36.0404 Windows directory: C:\Windows
2010/09/22 12:28:36.0404 System windows directory: C:\Windows
2010/09/22 12:28:36.0405 Processor architecture: Intel x86
2010/09/22 12:28:36.0405 Number of processors: 4
2010/09/22 12:28:36.0405 Page size: 0x1000
2010/09/22 12:28:36.0405 Boot type: Normal boot
2010/09/22 12:28:36.0405 ================================================================================
2010/09/22 12:28:37.0320 Initialize success
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:42.0086 Scan started
2010/09/22 12:28:42.0086 Mode: Manual;
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:44.0065 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/09/22 12:28:44.0099 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2010/09/22 12:28:44.0124 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/09/22 12:28:44.0156 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/09/22 12:28:44.0181 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2010/09/22 12:28:44.0235 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2010/09/22 12:28:44.0297 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2010/09/22 12:28:44.0511 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2010/09/22 12:28:44.0566 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2010/09/22 12:28:44.0606 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2010/09/22 12:28:44.0646 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2010/09/22 12:28:44.0689 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2010/09/22 12:28:44.0730 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2010/09/22 12:28:44.0817 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2010/09/22 12:28:44.0982 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2010/09/22 12:28:45.0036 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/09/22 12:28:45.0075 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2010/09/22 12:28:45.0125 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2010/09/22 12:28:45.0189 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2010/09/22 12:28:45.0240 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2010/09/22 12:28:45.0429 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/09/22 12:28:45.0477 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2010/09/22 12:28:45.0562 Avgfwfd (26a4640a8f16f8ce39b93329c83bb15a) C:\Windows\system32\DRIVERS\avgfwd6x.sys
2010/09/22 12:28:45.0776 AVGIDSDriverw7x (9e6b5bc75fd68b0d56a6f68a2d967241) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys
2010/09/22 12:28:45.0901 AVGIDSErHrw7x (25d906e3419ec2e7813d0627dd054032) C:\Windows\system32\Drivers\AVGIDSwx.sys
2010/09/22 12:28:45.0978 AVGIDSFilterw7x (57b9a71774c9e334dc8ef97657ff18a1) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys
2010/09/22 12:28:46.0065 AVGIDSShimw7x (c996c03d160137938a122a951305d645) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys
2010/09/22 12:28:46.0226 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\Windows\system32\Drivers\avgldx86.sys
2010/09/22 12:28:46.0260 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\system32\Drivers\avgmfx86.sys
2010/09/22 12:28:46.0281 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\Windows\system32\Drivers\avgrkx86.sys
2010/09/22 12:28:46.0366 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\Windows\system32\Drivers\avgtdix.sys
2010/09/22 12:28:46.0447 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2010/09/22 12:28:46.0654 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2010/09/22 12:28:46.0718 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2010/09/22 12:28:46.0790 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/09/22 12:28:46.0855 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2010/09/22 12:28:46.0980 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/09/22 12:28:47.0432 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/09/22 12:28:47.0571 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2010/09/22 12:28:47.0600 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/09/22 12:28:47.0666 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/09/22 12:28:47.0745 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/09/22 12:28:47.0789 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/09/22 12:28:48.0240 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2010/09/22 12:28:48.0315 cdrom (656d1ec977e3c5316a62dbbe52cb9663) C:\Windows\system32\DRIVERS\cdrom.sys
2010/09/22 12:28:48.0406 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2010/09/22 12:28:48.0468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2010/09/22 12:28:48.0625 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/09/22 12:28:48.0673 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2010/09/22 12:28:48.0820 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2010/09/22 12:28:48.0893 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2010/09/22 12:28:49.0021 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/09/22 12:28:49.0293 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/09/22 12:28:49.0380 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2010/09/22 12:28:49.0512 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2010/09/22 12:28:49.0575 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2010/09/22 12:28:49.0686 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2010/09/22 12:28:49.0801 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2010/09/22 12:28:49.0869 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2010/09/22 12:28:50.0121 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2010/09/22 12:28:50.0352 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2010/09/22 12:28:50.0464 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2010/09/22 12:28:50.0574 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2010/09/22 12:28:50.0627 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2010/09/22 12:28:50.0763 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2010/09/22 12:28:50.0815 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2010/09/22 12:28:50.0834 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2010/09/22 12:28:50.0896 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/09/22 12:28:51.0045 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2010/09/22 12:28:51.0085 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2010/09/22 12:28:51.0110 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2010/09/22 12:28:51.0163 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2010/09/22 12:28:51.0192 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/09/22 12:28:51.0416 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2010/09/22 12:28:51.0537 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2010/09/22 12:28:51.0658 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2010/09/22 12:28:51.0749 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2010/09/22 12:28:51.0909 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/09/22 12:28:51.0945 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/09/22 12:28:51.0984 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2010/09/22 12:28:52.0073 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2010/09/22 12:28:52.0158 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2010/09/22 12:28:52.0271 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/09/22 12:28:52.0466 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2010/09/22 12:28:52.0551 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2010/09/22 12:28:52.0707 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/09/22 12:28:52.0784 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/09/22 12:28:52.0828 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2010/09/22 12:28:52.0955 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2010/09/22 12:28:53.0048 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2010/09/22 12:28:53.0095 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/09/22 12:28:53.0184 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/09/22 12:28:53.0213 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2010/09/22 12:28:53.0239 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2010/09/22 12:28:53.0326 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2010/09/22 12:28:53.0413 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/09/22 12:28:53.0444 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/09/22 12:28:53.0500 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/09/22 12:28:53.0534 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2010/09/22 12:28:53.0643 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2010/09/22 12:28:53.0802 Lavasoft Kernexplorer (32da3fde01f1bb080c2e69521dd8881e) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2010/09/22 12:28:53.0923 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
2010/09/22 12:28:54.0067 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/09/22 12:28:54.0156 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/09/22 12:28:54.0201 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/09/22 12:28:54.0241 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/09/22 12:28:54.0381 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/09/22 12:28:54.0443 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2010/09/22 12:28:54.0597 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\Windows\system32\drivers\mbam.sys
2010/09/22 12:28:54.0697 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2010/09/22 12:28:54.0823 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/09/22 12:28:54.0929 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2010/09/22 12:28:55.0023 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2010/09/22 12:28:55.0107 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2010/09/22 12:28:55.0188 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2010/09/22 12:28:55.0243 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2010/09/22 12:28:55.0348 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2010/09/22 12:28:55.0419 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2010/09/22 12:28:55.0469 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2010/09/22 12:28:55.0576 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/09/22 12:28:55.0625 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/09/22 12:28:55.0705 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/09/22 12:28:55.0772 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2010/09/22 12:28:55.0885 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2010/09/22 12:28:55.0968 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2010/09/22 12:28:56.0023 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2010/09/22 12:28:56.0081 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/09/22 12:28:56.0148 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2010/09/22 12:28:56.0193 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/09/22 12:28:56.0334 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2010/09/22 12:28:56.0380 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2010/09/22 12:28:56.0441 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/09/22 12:28:56.0474 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2010/09/22 12:28:56.0576 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/09/22 12:28:56.0672 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2010/09/22 12:28:56.0820 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2010/09/22 12:28:56.0875 NDIS (779e9149d3662ed6beb58a67e3c775f4) C:\Windows\system32\drivers\ndis.sys
2010/09/22 12:28:56.0962 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/09/22 12:28:57.0078 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/09/22 12:28:57.0181 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/09/22 12:28:57.0223 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/09/22 12:28:57.0265 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2010/09/22 12:28:57.0328 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2010/09/22 12:28:57.0383 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2010/09/22 12:28:57.0506 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/09/22 12:28:57.0625 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2010/09/22 12:28:57.0708 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2010/09/22 12:28:57.0907 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2010/09/22 12:28:58.0001 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2010/09/22 12:28:58.0361 nvlddmkm (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/09/22 12:28:58.0729 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/09/22 12:28:58.0806 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2010/09/22 12:28:58.0833 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/09/22 12:28:58.0875 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/09/22 12:28:58.0943 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2010/09/22 12:28:59.0111 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2010/09/22 12:28:59.0137 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2010/09/22 12:28:59.0238 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2010/09/22 12:28:59.0310 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2010/09/22 12:28:59.0520 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/09/22 12:28:59.0583 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2010/09/22 12:28:59.0631 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2010/09/22 12:28:59.0744 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2010/09/22 12:29:00.0080 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2010/09/22 12:29:00.0114 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2010/09/22 12:29:00.0170 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2010/09/22 12:29:00.0274 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2010/09/22 12:29:00.0303 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/09/22 12:29:00.0360 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2010/09/22 12:29:00.0596 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2010/09/22 12:29:00.0717 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/09/22 12:29:00.0772 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/09/22 12:29:00.0822 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/09/22 12:29:00.0883 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2010/09/22 12:29:01.0019 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2010/09/22 12:29:01.0056 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/09/22 12:29:01.0135 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/09/22 12:29:01.0196 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2010/09/22 12:29:01.0245 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\DRIVERS\RDPENCDD.SYS
2010/09/22 12:29:01.0289 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2010/09/22 12:29:01.0477 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2010/09/22 12:29:01.0579 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2010/09/22 12:29:01.0696 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2010/09/22 12:29:01.0844 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
2010/09/22 12:29:01.0956 s1018bus (12a851f30853a5a8e7b50341fa4b0ffb) C:\Windows\system32\DRIVERS\s1018bus.sys
2010/09/22 12:29:02.0112 s1018mdfl (a0141d5dc689a892b3f30446cbe52575) C:\Windows\system32\DRIVERS\s1018mdfl.sys
2010/09/22 12:29:02.0237 s1018mdm (07d430e4b2bfde6b07f31f1da6e7cab0) C:\Windows\system32\DRIVERS\s1018mdm.sys
2010/09/22 12:29:02.0287 s1018mgmt (d73c20d3f0f825c8fd23f841cdcb14c0) C:\Windows\system32\DRIVERS\s1018mgmt.sys
2010/09/22 12:29:02.0408 s1018nd5 (895a1a2812dbd5afdd5ca4686a89a33c) C:\Windows\system32\DRIVERS\s1018nd5.sys
2010/09/22 12:29:02.0471 s1018obex (a986e9683c74fa06456fd2ad34ba1490) C:\Windows\system32\DRIVERS\s1018obex.sys
2010/09/22 12:29:03.0061 s1018unic (da83525924c23f30f37ac1d1f11d6f15) C:\Windows\system32\DRIVERS\s1018unic.sys
2010/09/22 12:29:03.0401 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2010/09/22 12:29:03.0525 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/09/22 12:29:03.0620 SCDEmu (a73ae2510014103a44a5a58845219dcb) C:\Windows\system32\drivers\SCDEmu.sys
2010/09/22 12:29:03.0660 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2010/09/22 12:29:03.0737 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/09/22 12:29:03.0870 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
2010/09/22 12:29:03.0956 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2010/09/22 12:29:04.0016 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2010/09/22 12:29:04.0040 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2010/09/22 12:29:04.0143 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/09/22 12:29:04.0405 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/09/22 12:29:04.0620 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/09/22 12:29:04.0703 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/09/22 12:29:04.0956 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2010/09/22 12:29:05.0032 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/09/22 12:29:05.0063 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/09/22 12:29:05.0169 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2010/09/22 12:29:05.0248 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2010/09/22 12:29:05.0325 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys
2010/09/22 12:29:05.0399 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys
2010/09/22 12:29:05.0520 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys
2010/09/22 12:29:05.0681 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2010/09/22 12:29:05.0739 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2010/09/22 12:29:05.0788 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2010/09/22 12:29:05.0879 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2010/09/22 12:29:06.0031 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2010/09/22 12:29:06.0166 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2010/09/22 12:29:06.0230 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2010/09/22 12:29:06.0299 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2010/09/22 12:29:06.0333 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2010/09/22 12:29:06.0384 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2010/09/22 12:29:06.0445 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2010/09/22 12:29:06.0548 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/09/22 12:29:06.0637 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2010/09/22 12:29:06.0741 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2010/09/22 12:29:06.0855 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2010/09/22 12:29:06.0965 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/09/22 12:29:07.0038 umbus (71bbf3e8078d585abf27411a8986eb95) C:\Windows\system32\DRIVERS\umbus.sys
2010/09/22 12:29:07.0078 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2010/09/22 12:29:07.0158 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/09/22 12:29:07.0279 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2010/09/22 12:29:07.0363 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2010/09/22 12:29:07.0480 usbhub (0db84eda895894ba222e27acf597c806) C:\Windows\system32\DRIVERS\usbhub.sys
2010/09/22 12:29:07.0543 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2010/09/22 12:29:07.0588 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2010/09/22 12:29:07.0721 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/09/22 12:29:07.0781 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/09/22 12:29:07.0879 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
2010/09/22 12:29:07.0923 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/09/22 12:29:07.0955 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/09/22 12:29:08.0007 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2010/09/22 12:29:08.0054 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/09/22 12:29:08.0134 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2010/09/22 12:29:08.0154 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2010/09/22 12:29:08.0235 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2010/09/22 12:29:08.0255 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2010/09/22 12:29:08.0284 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2010/09/22 12:29:08.0345 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/09/22 12:29:08.0381 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2010/09/22 12:29:08.0445 volsnap (70f41d1ebdd9ee6ed2fd0fc05aa1fc13) C:\Windows\system32\DRIVERS\volsnap.sys
2010/09/22 12:29:08.0468 vpcbus (33e74df34753fcaab06f6f2bdc8cabf5) C:\Windows\system32\DRIVERS\vpchbus.sys
2010/09/22 12:29:08.0494 vpcnfltr (5f04362ceb5fb5901037e9d9eadd3760) C:\Windows\system32\DRIVERS\vpcnfltr.sys
2010/09/22 12:29:08.0654 vpcusb (625088d6ee9ede977fd03cf18d1cd5c5) C:\Windows\system32\DRIVERS\vpcusb.sys
2010/09/22 12:29:08.0764 vpcvmm (5ed378d91e32134f3c0b3810860ffd71) C:\Windows\system32\drivers\vpcvmm.sys
2010/09/22 12:29:08.0816 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/09/22 12:29:08.0867 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2010/09/22 12:29:08.0965 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2010/09/22 12:29:09.0024 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/22 12:29:09.0057 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/22 12:29:09.0214 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2010/09/22 12:29:09.0246 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2010/09/22 12:29:09.0301 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/09/22 12:29:09.0320 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2010/09/22 12:29:09.0456 WINUSB (b5ba3cc19d00f2eba92f1cfbebb5d650) C:\Windows\system32\DRIVERS\WinUSB.SYS
2010/09/22 12:29:09.0545 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/09/22 12:29:09.0685 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/09/22 12:29:09.0741 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2010/09/22 12:29:09.0784 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/09/22 12:29:09.0844 xusb21 (c26c68bcbac1f33f890c226769759209) C:\Windows\system32\DRIVERS\xusb21.sys
2010/09/22 12:29:09.0935 ================================================================================
2010/09/22 12:29:09.0935 Scan finished
2010/09/22 12:29:09.0935 ================================================================================


Are you running through a router?

Just want to check the MBR again.

Download Bootkit Remover to your Desktop.

  • You then need to extract the remover.exe file from the RAR using a program capable of extracting RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
  • After extracting remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
  • It will show a Black screen with some data on it.
  • Right click on the screen and click Select All.
  • Press CTRL+C
  • Open a Notepad and press CTRL+V
  • Post the output back here.

2010/09/22 12:28:36.0400 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/22 12:28:36.0400 ================================================================================
2010/09/22 12:28:36.0400 SystemInfo:
2010/09/22 12:28:36.0400
2010/09/22 12:28:36.0400 OS Version: 6.1.7600 ServicePack: 0.0
2010/09/22 12:28:36.0400 Product type: Workstation
2010/09/22 12:28:36.0400 ComputerName: BOBBYDIGITAL-PC
2010/09/22 12:28:36.0404 UserName: Bobby Digital
2010/09/22 12:28:36.0404 Windows directory: C:\Windows
2010/09/22 12:28:36.0404 System windows directory: C:\Windows
2010/09/22 12:28:36.0405 Processor architecture: Intel x86
2010/09/22 12:28:36.0405 Number of processors: 4
2010/09/22 12:28:36.0405 Page size: 0x1000
2010/09/22 12:28:36.0405 Boot type: Normal boot
2010/09/22 12:28:36.0405 ================================================================================
2010/09/22 12:28:37.0320 Initialize success
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:42.0086 Scan started
2010/09/22 12:28:42.0086 Mode: Manual;
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:44.0065 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/09/22 12:28:44.0099 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2010/09/22 12:28:44.0124 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/09/22 12:28:44.0156 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/09/22 12:28:44.0181 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2010/09/22 12:28:44.0235 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2010/09/22 12:28:44.0297 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2010/09/22 12:28:44.0511 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2010/09/22 12:28:44.0566 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2010/09/22 12:28:44.0606 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2010/09/22 12:28:44.0646 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2010/09/22 12:28:44.0689 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2010/09/22 12:28:44.0730 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2010/09/22 12:28:44.0817 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2010/09/22 12:28:44.0982 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2010/09/22 12:28:45.0036 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/09/22 12:28:45.0075 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2010/09/22 12:28:45.0125 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2010/09/22 12:28:45.0189 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2010/09/22 12:28:45.0240 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2010/09/22 12:28:45.0429 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/09/22 12:28:45.0477 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2010/09/22 12:28:45.0562 Avgfwfd (26a4640a8f16f8ce39b93329c83bb15a) C:\Windows\system32\DRIVERS\avgfwd6x.sys
2010/09/22 12:28:45.0776 AVGIDSDriverw7x (9e6b5bc75fd68b0d56a6f68a2d967241) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys
2010/09/22 12:28:45.0901 AVGIDSErHrw7x (25d906e3419ec2e7813d0627dd054032) C:\Windows\system32\Drivers\AVGIDSwx.sys
2010/09/22 12:28:45.0978 AVGIDSFilterw7x (57b9a71774c9e334dc8ef97657ff18a1) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys
2010/09/22 12:28:46.0065 AVGIDSShimw7x (c996c03d160137938a122a951305d645) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys
2010/09/22 12:28:46.0226 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\Windows\system32\Drivers\avgldx86.sys
2010/09/22 12:28:46.0260 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\system32\Drivers\avgmfx86.sys
2010/09/22 12:28:46.0281 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\Windows\system32\Drivers\avgrkx86.sys
2010/09/22 12:28:46.0366 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\Windows\system32\Drivers\avgtdix.sys
2010/09/22 12:28:46.0447 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2010/09/22 12:28:46.0654 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2010/09/22 12:28:46.0718 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2010/09/22 12:28:46.0790 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/09/22 12:28:46.0855 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2010/09/22 12:28:46.0980 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/09/22 12:28:47.0432 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/09/22 12:28:47.0571 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2010/09/22 12:28:47.0600 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/09/22 12:28:47.0666 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/09/22 12:28:47.0745 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/09/22 12:28:47.0789 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/09/22 12:28:48.0240 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2010/09/22 12:28:48.0315 cdrom (656d1ec977e3c5316a62dbbe52cb9663) C:\Windows\system32\DRIVERS\cdrom.sys
2010/09/22 12:28:48.0406 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2010/09/22 12:28:48.0468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2010/09/22 12:28:48.0625 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/09/22 12:28:48.0673 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2010/09/22 12:28:48.0820 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2010/09/22 12:28:48.0893 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2010/09/22 12:28:49.0021 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/09/22 12:28:49.0293 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/09/22 12:28:49.0380 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2010/09/22 12:28:49.0512 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2010/09/22 12:28:49.0575 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2010/09/22 12:28:49.0686 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2010/09/22 12:28:49.0801 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2010/09/22 12:28:49.0869 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2010/09/22 12:28:50.0121 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2010/09/22 12:28:50.0352 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2010/09/22 12:28:50.0464 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2010/09/22 12:28:50.0574 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2010/09/22 12:28:50.0627 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2010/09/22 12:28:50.0763 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2010/09/22 12:28:50.0815 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2010/09/22 12:28:50.0834 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2010/09/22 12:28:50.0896 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/09/22 12:28:51.0045 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2010/09/22 12:28:51.0085 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2010/09/22 12:28:51.0110 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2010/09/22 12:28:51.0163 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2010/09/22 12:28:51.0192 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/09/22 12:28:51.0416 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2010/09/22 12:28:51.0537 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2010/09/22 12:28:51.0658 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2010/09/22 12:28:51.0749 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2010/09/22 12:28:51.0909 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/09/22 12:28:51.0945 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/09/22 12:28:51.0984 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2010/09/22 12:28:52.0073 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2010/09/22 12:28:52.0158 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2010/09/22 12:28:52.0271 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/09/22 12:28:52.0466 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2010/09/22 12:28:52.0551 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2010/09/22 12:28:52.0707 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/09/22 12:28:52.0784 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/09/22 12:28:52.0828 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2010/09/22 12:28:52.0955 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2010/09/22 12:28:53.0048 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2010/09/22 12:28:53.0095 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/09/22 12:28:53.0184 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/09/22 12:28:53.0213 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2010/09/22 12:28:53.0239 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2010/09/22 12:28:53.0326 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2010/09/22 12:28:53.0413 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/09/22 12:28:53.0444 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/09/22 12:28:53.0500 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/09/22 12:28:53.0534 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2010/09/22 12:28:53.0643 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2010/09/22 12:28:53.0802 Lavasoft Kernexplorer (32da3fde01f1bb080c2e69521dd8881e) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2010/09/22 12:28:53.0923 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
2010/09/22 12:28:54.0067 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/09/22 12:28:54.0156 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/09/22 12:28:54.0201 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/09/22 12:28:54.0241 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/09/22 12:28:54.0381 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/09/22 12:28:54.0443 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2010/09/22 12:28:54.0597 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\Windows\system32\drivers\mbam.sys
2010/09/22 12:28:54.0697 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2010/09/22 12:28:54.0823 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/09/22 12:28:54.0929 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2010/09/22 12:28:55.0023 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2010/09/22 12:28:55.0107 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2010/09/22 12:28:55.0188 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2010/09/22 12:28:55.0243 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2010/09/22 12:28:55.0348 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2010/09/22 12:28:55.0419 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2010/09/22 12:28:55.0469 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2010/09/22 12:28:55.0576 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/09/22 12:28:55.0625 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/09/22 12:28:55.0705 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/09/22 12:28:55.0772 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2010/09/22 12:28:55.0885 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2010/09/22 12:28:55.0968 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2010/09/22 12:28:56.0023 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2010/09/22 12:28:56.0081 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/09/22 12:28:56.0148 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2010/09/22 12:28:56.0193 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/09/22 12:28:56.0334 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2010/09/22 12:28:56.0380 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2010/09/22 12:28:56.0441 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/09/22 12:28:56.0474 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2010/09/22 12:28:56.0576 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/09/22 12:28:56.0672 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2010/09/22 12:28:56.0820 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2010/09/22 12:28:56.0875 NDIS (779e9149d3662ed6beb58a67e3c775f4) C:\Windows\system32\drivers\ndis.sys
2010/09/22 12:28:56.0962 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/09/22 12:28:57.0078 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/09/22 12:28:57.0181 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/09/22 12:28:57.0223 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/09/22 12:28:57.0265 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2010/09/22 12:28:57.0328 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2010/09/22 12:28:57.0383 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2010/09/22 12:28:57.0506 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/09/22 12:28:57.0625 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2010/09/22 12:28:57.0708 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2010/09/22 12:28:57.0907 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2010/09/22 12:28:58.0001 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2010/09/22 12:28:58.0361 nvlddmkm (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/09/22 12:28:58.0729 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/09/22 12:28:58.0806 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2010/09/22 12:28:58.0833 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/09/22 12:28:58.0875 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/09/22 12:28:58.0943 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2010/09/22 12:28:59.0111 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2010/09/22 12:28:59.0137 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2010/09/22 12:28:59.0238 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2010/09/22 12:28:59.0310 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2010/09/22 12:28:59.0520 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/09/22 12:28:59.0583 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2010/09/22 12:28:59.0631 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2010/09/22 12:28:59.0744 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2010/09/22 12:29:00.0080 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2010/09/22 12:29:00.0114 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2010/09/22 12:29:00.0170 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2010/09/22 12:29:00.0274 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2010/09/22 12:29:00.0303 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/09/22 12:29:00.0360 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2010/09/22 12:29:00.0596 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2010/09/22 12:29:00.0717 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/09/22 12:29:00.0772 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/09/22 12:29:00.0822 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/09/22 12:29:00.0883 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2010/09/22 12:29:01.0019 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2010/09/22 12:29:01.0056 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/09/22 12:29:01.0135 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/09/22 12:29:01.0196 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2010/09/22 12:29:01.0245 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\DRIVERS\RDPENCDD.SYS
2010/09/22 12:29:01.0289 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2010/09/22 12:29:01.0477 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2010/09/22 12:29:01.0579 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2010/09/22 12:29:01.0696 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2010/09/22 12:29:01.0844 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
2010/09/22 12:29:01.0956 s1018bus (12a851f30853a5a8e7b50341fa4b0ffb) C:\Windows\system32\DRIVERS\s1018bus.sys
2010/09/22 12:29:02.0112 s1018mdfl (a0141d5dc689a892b3f30446cbe52575) C:\Windows\system32\DRIVERS\s1018mdfl.sys
2010/09/22 12:29:02.0237 s1018mdm (07d430e4b2bfde6b07f31f1da6e7cab0) C:\Windows\system32\DRIVERS\s1018mdm.sys
2010/09/22 12:29:02.0287 s1018mgmt (d73c20d3f0f825c8fd23f841cdcb14c0) C:\Windows\system32\DRIVERS\s1018mgmt.sys
2010/09/22 12:29:02.0408 s1018nd5 (895a1a2812dbd5afdd5ca4686a89a33c) C:\Windows\system32\DRIVERS\s1018nd5.sys
2010/09/22 12:29:02.0471 s1018obex (a986e9683c74fa06456fd2ad34ba1490) C:\Windows\system32\DRIVERS\s1018obex.sys
2010/09/22 12:29:03.0061 s1018unic (da83525924c23f30f37ac1d1f11d6f15) C:\Windows\system32\DRIVERS\s1018unic.sys
2010/09/22 12:29:03.0401 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2010/09/22 12:29:03.0525 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/09/22 12:29:03.0620 SCDEmu (a73ae2510014103a44a5a58845219dcb) C:\Windows\system32\drivers\SCDEmu.sys
2010/09/22 12:29:03.0660 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2010/09/22 12:29:03.0737 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/09/22 12:29:03.0870 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
2010/09/22 12:29:03.0956 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2010/09/22 12:29:04.0016 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2010/09/22 12:29:04.0040 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2010/09/22 12:29:04.0143 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/09/22 12:29:04.0405 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/09/22 12:29:04.0620 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/09/22 12:29:04.0703 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/09/22 12:29:04.0956 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2010/09/22 12:29:05.0032 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/09/22 12:29:05.0063 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/09/22 12:29:05.0169 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2010/09/22 12:29:05.0248 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2010/09/22 12:29:05.0325 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys
2010/09/22 12:29:05.0399 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys
2010/09/22 12:29:05.0520 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys
2010/09/22 12:29:05.0681 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2010/09/22 12:29:05.0739 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2010/09/22 12:29:05.0788 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2010/09/22 12:29:05.0879 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2010/09/22 12:29:06.0031 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2010/09/22 12:29:06.0166 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2010/09/22 12:29:06.0230 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2010/09/22 12:29:06.0299 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2010/09/22 12:29:06.0333 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2010/09/22 12:29:06.0384 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2010/09/22 12:29:06.0445 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2010/09/22 12:29:06.0548 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/09/22 12:29:06.0637 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2010/09/22 12:29:06.0741 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2010/09/22 12:29:06.0855 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2010/09/22 12:29:06.0965 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/09/22 12:29:07.0038 umbus (71bbf3e8078d585abf27411a8986eb95) C:\Windows\system32\DRIVERS\umbus.sys
2010/09/22 12:29:07.0078 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2010/09/22 12:29:07.0158 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/09/22 12:29:07.0279 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2010/09/22 12:29:07.0363 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2010/09/22 12:29:07.0480 usbhub (0db84eda895894ba222e27acf597c806) C:\Windows\system32\DRIVERS\usbhub.sys
2010/09/22 12:29:07.0543 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2010/09/22 12:29:07.0588 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2010/09/22 12:29:07.0721 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/09/22 12:29:07.0781 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/09/22 12:29:07.0879 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
2010/09/22 12:29:07.0923 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/09/22 12:29:07.0955 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/09/22 12:29:08.0007 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2010/09/22 12:29:08.0054 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/09/22 12:29:08.0134 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2010/09/22 12:29:08.0154 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2010/09/22 12:29:08.0235 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2010/09/22 12:29:08.0255 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2010/09/22 12:29:08.0284 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2010/09/22 12:29:08.0345 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/09/22 12:29:08.0381 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2010/09/22 12:29:08.0445 volsnap (70f41d1ebdd9ee6ed2fd0fc05aa1fc13) C:\Windows\system32\DRIVERS\volsnap.sys
2010/09/22 12:29:08.0468 vpcbus (33e74df34753fcaab06f6f2bdc8cabf5) C:\Windows\system32\DRIVERS\vpchbus.sys
2010/09/22 12:29:08.0494 vpcnfltr (5f04362ceb5fb5901037e9d9eadd3760) C:\Windows\system32\DRIVERS\vpcnfltr.sys
2010/09/22 12:29:08.0654 vpcusb (625088d6ee9ede977fd03cf18d1cd5c5) C:\Windows\system32\DRIVERS\vpcusb.sys
2010/09/22 12:29:08.0764 vpcvmm (5ed378d91e32134f3c0b3810860ffd71) C:\Windows\system32\drivers\vpcvmm.sys
2010/09/22 12:29:08.0816 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/09/22 12:29:08.0867 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2010/09/22 12:29:08.0965 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2010/09/22 12:29:09.0024 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/22 12:29:09.0057 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2010/09/22 12:29:09.0214 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2010/09/22 12:29:09.0246 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2010/09/22 12:29:09.0301 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/09/22 12:29:09.0320 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2010/09/22 12:29:09.0456 WINUSB (b5ba3cc19d00f2eba92f1cfbebb5d650) C:\Windows\system32\DRIVERS\WinUSB.SYS
2010/09/22 12:29:09.0545 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/09/22 12:29:09.0685 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2010/09/22 12:29:09.0741 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2010/09/22 12:29:09.0784 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/09/22 12:29:09.0844 xusb21 (c26c68bcbac1f33f890c226769759209) C:\Windows\system32\DRIVERS\xusb21.sys
2010/09/22 12:29:09.0935 ================================================================================
2010/09/22 12:29:09.0935 Scan finished
2010/09/22 12:29:09.0935 ================================================================================
2010/09/22 12:28:36.0400 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44
2010/09/22 12:28:36.0400 ================================================================================
2010/09/22 12:28:36.0400 SystemInfo:
2010/09/22 12:28:36.0400
2010/09/22 12:28:36.0400 OS Version: 6.1.7600 ServicePack: 0.0
2010/09/22 12:28:36.0400 Product type: Workstation
2010/09/22 12:28:36.0400 ComputerName: BOBBYDIGITAL-PC
2010/09/22 12:28:36.0404 UserName: Bobby Digital
2010/09/22 12:28:36.0404 Windows directory: C:\Windows
2010/09/22 12:28:36.0404 System windows directory: C:\Windows
2010/09/22 12:28:36.0405 Processor architecture: Intel x86
2010/09/22 12:28:36.0405 Number of processors: 4
2010/09/22 12:28:36.0405 Page size: 0x1000
2010/09/22 12:28:36.0405 Boot type: Normal boot
2010/09/22 12:28:36.0405 ================================================================================
2010/09/22 12:28:37.0320 Initialize success
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:42.0086 Scan started
2010/09/22 12:28:42.0086 Mode: Manual;
2010/09/22 12:28:42.0086 ================================================================================
2010/09/22 12:28:44.0065 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/09/22 12:28:44.0099 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2010/09/22 12:28:44.0124 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/09/22 12:28:44.0156 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/09/22 12:28:44.0181 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2010/09/22 12:28:44.0235 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2010/09/22 12:28:44.0297 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2010/09/22 12:28:44.0511 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2010/09/22 12:28:44.0566 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2010/09/22 12:28:44.0606 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2010/09/22 12:28:44.0646 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2010/09/22 12:28:44.0689 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2010/09/22 12:28:44.0730 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2010/09/22 12:28:44.0817 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2010/09/22 12:28:44.0982 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2010/09/22 12:28:45.0036 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/09/22 12:28:45.0075 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2010/09/22 12:28:45.0125 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2010/09/22 12:28:45.0189 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2010/09/22 12:28:45.0240 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2010/09/22 12:28:45.0429 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/09/22 12:28:45.0477 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2010/09/22 12:28:45.0562 Avgfwfd (26a4640a8f16f8ce39b93329c83bb15a) C:\Windows\system32\DRIVERS\avgfwd6x.sys
2010/09/22 12:28:45.0776 AVGIDSDriverw7x (9e6b5bc75fd68b0d56a6f68a2d967241) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSDriver.sys
2010/09/22 12:28:45.0901 AVGIDSErHrw7x (25d906e3419ec2e7813d0627dd054032) C:\Windows\system32\Drivers\AVGIDSwx.sys
2010/09/22 12:28:45.0978 AVGIDSFilterw7x (57b9a71774c9e334dc8ef97657ff18a1) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSFilter.sys
2010/09/22 12:28:46.0065 AVGIDSShimw7x (c996c03d160137938a122a951305d645) C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_WIN7\AVGIDSShim.sys
2010/09/22 12:28:46.0226 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\Windows\system32\Drivers\avgldx86.sys
2010/09/22 12:28:46.0260 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\system32\Drivers\avgmfx86.sys
2010/09/22 12:28:46.0281 AvgRkx86 (5bbcd8646074a3af4ee9b321d12c2b64) C:\Windows\system32\Drivers\avgrkx86.sys
2010/09/22 12:28:46.0366 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\Windows\system32\Drivers\avgtdix.sys
2010/09/22 12:28:46.0447 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2010/09/22 12:28:46.0654 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2010/09/22 12:28:46.0718 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2010/09/22 12:28:46.0790 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/09/22 12:28:46.0855 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
2010/09/22 12:28:46.0980 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/09/22 12:28:47.0432 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/09/22 12:28:47.0571 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2010/09/22 12:28:47.0600 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/09/22 12:28:47.0666 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/09/22 12:28:47.0745 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/09/22 12:28:47.0789 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/09/22 12:28:48.0240 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2010/09/22 12:28:48.0315 cdrom (656d1ec977e3c5316a62dbbe52cb9663) C:\Windows\system32\DRIVERS\cdrom.sys
2010/09/22 12:28:48.0406 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2010/09/22 12:28:48.0468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2010/09/22 12:28:48.0625 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/09/22 12:28:48.0673 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2010/09/22 12:28:48.0820 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2010/09/22 12:28:48.0893 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2010/09/22 12:28:49.0021 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/09/22 12:28:49.0293 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/09/22 12:28:49.0380 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2010/09/22 12:28:49.0512 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2010/09/22 12:28:49.0575 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2010/09/22 12:28:49.0686 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2010/09/22 12:28:49.0801 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2010/09/22 12:28:49.0869 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
2010/09/22 12:28:50.0121 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2010/09/22 12:28:50.0352 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2010/09/22 12:28:50.0464 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2010/09/22 12:28:50.0574 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2010/09/22 12:28:50.0627 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2010/09/22 12:28:50.0763 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2010/09/22 12:28:50.0815 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2010/09/22 12:28:50.0834 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2010/09/22 12:28:50.0896 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/09/22 12:28:51.0045 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2010/09/22 12:28:51.0085 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2010/09/22 12:28:51.0110 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2010/09/22 12:28:51.0163 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2010/09/22 12:28:51.0192 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/09/22 12:28:51.0416 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2010/09/22 12:28:51.0537 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2010/09/22 12:28:51.0658 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2010/09/22 12:28:51.0749 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2010/09/22 12:28:51.0909 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/09/22 12:28:51.0945 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/09/22 12:28:51.0984 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2010/09/22 12:28:52.0073 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2010/09/22 12:28:52.0158 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2010/09/22 12:28:52.0271 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/09/22 12:28:52.0466 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2010/09/22 12:28:52.0551 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2010/09/22 12:28:52.0707 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/09/22 12:28:52.0784 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/09/22 12:28:52.0828 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2010/09/22 12:28:52.0955 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2010/09/22 12:28:53.0048 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2010/09/22 12:28:53.0095 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/09/22 12:28:53.0184 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/09/22 12:28:53.0213 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2010/09/22 12:28:53.0239 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2010/09/22 12:28:53.0326 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2010/09/22 12:28:53.0413 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/09/22 12:28:53.0444 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/09/22 12:28:53.0500 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/09/22 12:28:53.0534 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2010/09/22 12:28:53.0643 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2010/09/22 12:28:53.0802 Lavasoft Kernexplorer (32da3fde01f1bb080c2e69521dd8881e) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
2010/09/22 12:28:53.0923 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
2010/09/22 12:28:54.0067 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2010/09/22 12:28:54.0156 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/09/22 12:28:54.0201 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/09/22 12:28:54.0241 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/09/22 12:28:54.0381 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/09/22 12:28:54.0443 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2010/09/22 12:28:54.0597 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\Windows\system32\drivers\mbam.sys
2010/09/22 12:28:54.0697 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2010/09/22 12:28:54.0823 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/09/22 12:28:54.0929 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2010/09/22 12:28:55.0023 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2010/09/22 12:28:55.0107 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2010/09/22 12:28:55.0188 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2010/09/22 12:28:55.0243 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2010/09/22 12:28:55.0348 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2010/09/22 12:28:55.0419 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2010/09/22 12:28:55.0469 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2010/09/22 12:28:55.0576 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/09/22 12:28:55.0625 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/09/22 12:28:55.0705 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/09/22 12:28:55.0772 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2010/09/22 12:28:55.0885 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2010/09/22 12:28:55.0968 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2010/09/22 12:28:56.0023 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2010/09/22 12:28:56.0081 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/09/22 12:28:56.0148 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2010/09/22 12:28:56.0193 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/09/22 12:28:56.0334 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2010/09/22 12:28:56.0380 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2010/09/22 12:28:56.0441 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/09/22 12:28:56.0474 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2010/09/22 12:28:56.0576 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/09/22 12:28:56.0672 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2010/09/22 12:28:56.0820 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2010/09/22 12:28:56.0875 NDIS (779e9149d3662ed6beb58a67e3c775f4) C:\Windows\system32\drivers\ndis.sys
2010/09/22 12:28:56.0962 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/09/22 12:28:57.0078 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/09/22 12:28:57.0181 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/09/22 12:28:57.0223 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/09/22 12:28:57.0265 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2010/09/22 12:28:57.0328 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2010/09/22 12:28:57.0383 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2010/09/22 12:28:57.0506 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/09/22 12:28:57.0625 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2010/09/22 12:28:57.0708 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2010/09/22 12:28:57.0907 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2010/09/22 12:28:58.0001 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2010/09/22 12:28:58.0361 nvlddmkm (377140a534d013bd661c69f1741de43c) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/09/22 12:28:58.0729 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/09/22 12:28:58.0806 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2010/09/22 12:28:58.0833 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/09/22 12:28:58.0875 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/09/22 12:28:58.0943 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2010/09/22 12:28:59.0111 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2010/09/22 12:28:59.0137 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2010/09/22 12:28:59.0238 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2010/09/22 12:28:59.0310 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2010/09/22 12:28:59.0520 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/09/22 12:28:59.0583 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2010/09/22 12:28:59.0631 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2010/09/22 12:28:59.0744 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2010/09/22 12:29:00.0080 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2010/09/22 12:29:00.0114 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2010/09/22 12:29:00.0170 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2010/09/22 12:29:00.0274 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2010/09/22 12:29:00.0303 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/09/22 12:29:00.0360 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2010/09/22 12:29:00.0596 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2010/09/22 12:29:00.0717 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/09/22 12:29:00.0772 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/09/22 12:29:00.0822 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/09/22 12:29:00.0883 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2010/09/22 12:29:01.0019 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2010/09/22 12:29:01.0056 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/09/22 12:29:01.0135 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/09/22 12:29:01.0196 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2010/09/22 12:29:01.0245 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\DRIVERS\RDPENCDD.SYS
2010/09/22 12:29:01.0289 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2010/09/22 12:29:01.0477 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2010/09/22 12:29:01.0579 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2010/09/22 12:29:01.0696 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2010/09/22 12:29:01.0844 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys
2010/09/22 12:29:01.0956 s1018bus (12a851f30853a5a8e7b50341fa4b0ffb) C:\Windows\system32\DRIVERS\s1018bus.sys
2010/09/22 12:29:02.0112 s1018mdfl (a0141d5dc689a892b3f30446cbe52575) C:\Windows\system32\DRIVERS\s1018mdfl.sys
2010/09/22 12:29:02.0237 s1018mdm (07d430e4b2bfde6b07f31f1da6e7cab0) C:\Windows\system32\DRIVERS\s1018mdm.sys
2010/09/22 12:29:02.0287 s1018mgmt (d73c20d3f0f825c8fd23f841cdcb14c0) C:\Windows\system32\DRIVERS\s1018mgmt.sys
2010/09/22 12:29:02.0408 s1018nd5 (895a1a2812dbd5afdd5ca4686a89a33c) C:\Windows\system32\DRIVERS\s1018nd5.sys
2010/09/22 12:29:02.0471 s1018obex (a986e9683c74fa06456fd2ad34ba1490) C:\Windows\system32\DRIVERS\s1018obex.sys
2010/09/22 12:29:03.0061 s1018unic (da83525924c23f30f37ac1d1f11d6f15) C:\Windows\system32\DRIVERS\s1018unic.sys
2010/09/22 12:29:03.0401 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2010/09/22 12:29:03.0525 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/09/22 12:29:03.0620 SCDEmu (a73ae2510014103a44a5a58845219dcb) C:\Windows\system32\drivers\SCDEmu.sys
2010/09/22 12:29:03.0660 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2010/09/22 12:29:03.0737 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2010/09/22 12:29:03.0870 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
2010/09/22 12:29:03.0956 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2010/09/22 12:29:04.0016 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2010/09/22 12:29:04.0040 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2010/09/22 12:29:04.0143 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/09/22 12:29:04.0405 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/09/22 12:29:04.0620 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/09/22 12:29:04.0703 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/09/22 12:29:04.0956 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2010/09/22 12:29:05.0032 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/09/22 12:29:05.0063 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/09/22 12:29:05.0169 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2010/09/22 12:29:05.0248 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2010/09/22 12:29:05.0325 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\Windows\system32\DRIVERS\srv.sys
2010/09/22 12:29:05.0399 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\Windows\system32\DRIVERS\srv2.sys
2010/09/22 12:29:05.0520 srvnet (08f28676802b58138e48a2b40caf6204) C:\Windows\system32\DRIVERS\srvnet.sys
2010/09/22 12:29:05.0681 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2010/09/22 12:29:05.0739 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2010/09/22 12:29:05.0788 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2010/09/22 12:29:05.0879 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2010/09/22 12:29:06.0031 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2010/09/22 12:29:06.0166 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2010/09/22 12:29:06.0230 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2010/09/22 12:29:06.0299 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2010/09/22 12:29:06.0333 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2010/09/22 12:29:06.0384 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2010/09/22 12:29:06.0445 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2010/09/22 12:29:06.0548 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/09/22 12:29:06.0637 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2010/09/22 12:29:06.0741 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2010/09/22 12:29:06.0855 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2010/09/22 12:29:06.0965 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/09/22 12:29:07.0038 umbus (71bbf3e8078d585abf27411a8986eb95) C:\Windows\system32\DRIVERS\umbus.sys
2010/09/22 12:29:07.0078 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2010/09/22 12:29:07.0158 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/09/22 12:29:07.0279 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2010/09/22 12:29:07.0363 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2010/09/22 12:29:07.0480 usbhub (0db84eda895894ba222e27acf597c806) C:\Windows\system32\DRIVERS\usbhub.sys
2010/09/22 12:29:07.0543 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2010/09/22 12:29:07.0588 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2010/09/22 12:29:07.0721 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/09/22 12:29:07.0781 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/09/22 12:29:07.0879 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
2010/09/22 12:29:07.0923 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/09/22 12:29:07.0955 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/09/22 12:29:08.0007 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\

That is not the correct log.

You have still not answered my question too.

Sorry Crunchie, didn't see that last log, Yes I'm running through BT home hub.

Bootkit log:


Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com

Program version: 1.2.0.0
OS Version: Microsoft Windows 7 Ultimate Edition (build 7600), 32-bit

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00004400
Boot sector MD5 is: bb4f1627d8b9beda49ac0d010229f3ff

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


Done;
Press any key to quit...

Try this;

Go Start>Run (Start search in Vista/7), type in:
cmd
Click OK (in Vista/7, while holding CTRL, and SHIFT, press Enter).

In Command Prompt window, type in following commands, and hit Enter after each one:
ipconfig /flushdns
ipconfig /registerdns
ipconfig /release
ipconfig /renew
net stop "dns client"
net start "dns client"


Turn the computer off.

On your router, you'll find a pinhole marked "Reset".
Keep pushing the hole, using a pencil, or a paperclip until all lights briefly come off and on.
Restart computer and check for redirections.

Thanks mate, done all that. Hasn't redirected yet, is it fixed?

Just give it another day and let me know if it is still good. Will have you remove the tools we have used when you report back.

Been three days now & everything seems to be fine. Thanks for all your time & effort.

You are welcome :).

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC by OldTimer:
Save it to your Desktop.
Double click OTC.exe.
Click the CleanUp! button.
If you are prompted to Reboot during the cleanup, select Yes. The tool will delete itself once it finishes.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.