I downloaded MBAM and HiJackThis, but was not able to run them even in safe mode. I was able to run esetsmartinstaller_enu, MS Malicious Software Removal Tool, MS Scanner, and rkill. Several trojans were detected and removed including win32/Alvreon and win32/FakeCog. Tried to follow the Prep Guide but wasunable to get DDS to run, but was able to get a HiJackThis log with RSIT.
Here is a copy of the log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2009-11-09 18:36:57
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 38 GB (50%) free of 76 GB
Total RAM: 1023 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:37:31 PM, on 11/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
c:Program FilesMicrosoft Security EssentialsMsMpEng.exe
C:Program FilesWindows DefenderMsMpEng.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
C:PROGRA~1EARTHL~2PCFINE~1MXTask.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcAppFlt.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnTrayFw.exe
C:WINDOWSAGRSMMSG.exe
C:Program FilesYahoo!Search ProtectionSearchProtection.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesMicrosoft Security Essentialsmsseces.exe
C:WINDOWSexplorer.exe
C:Documents and SettingsuserDesktopRSIT.exe
C:Program Filestrend microuser.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yahoo.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com/
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://start.earthlink.net/AL/Search
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:Program FilesEarthLinkToolbarElnkPuB.dll
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:Program FilesEarthLinkToolbarProtctIE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:Program FilesEarthLinkToolbaruninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:Program FilesEarthLinkToolbarToolbar.dll
O4 - HKLM..Run: [nTrayFw] C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnTrayFw.exe
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [YSearchProtection] "C:Program FilesYahoo!Search ProtectionSearchProtection.exe"
O4 - HKLM..Run: [Windows Defender] "C:Program FilesWindows DefenderMSASCui.exe" -hide
O4 - HKLM..Run: [MSSE] "c:Program FilesMicrosoft Security Essentialsmsseces.exe" -hide
O4 - HKCU..Run: [Protection System] C:Program FilesProtection Systempsystem.exe
O4 - HKCU..Run: [Messenger (Yahoo!)] "C:Program FilesYahoo!MessengerYahooMessenger.exe" -quiet
O4 - HKCU..Run: [Search Protection] C:Program FilesYahoo!Search ProtectionSearchProtection.exe
O4 - HKCU..Run: [ms18_word] C:Documents and Settingsuserms18_word.exe
O8 - Extra context menu item: EarthLink Google Search - res://C:Program FilesEarthLinkToolbarSearchUI.dll/search.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O12 - Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINSnppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1247701221125
O23 - Service: app_filter - Unknown owner - C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:WINDOWSSystem32hwclock.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
O23 - Service: PC FineTune Task Manager - Avanquest North America, Inc. - C:PROGRA~1EARTHL~2PCFINE~1MXTask.exe
--
End of file - 5971 bytes
======Scheduled tasks folder======
C:WINDOWStasksMP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{512ACF1B-64D9-4928-B382-A80556F28DB4}]
ElnkPubBHO Class - C:Program FilesEarthLinkToolbarElnkPuB.dll [2008-11-04 255472]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9579D574-D4D8-4335-9560-FE8641A013BD}]
ElnkProtectionBHO Class - C:Program FilesEarthLinkToolbarProtctIE.dll [2008-11-04 415216]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E713904C-DF05-4C79-BBAD-02DB923253BE}]
ElnkLegacyUninstBHO Class - C:Program FilesEarthLinkToolbaruninsttb.dll [2008-11-04 280048]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{C7768536-96F8-4001-B1A2-90EE21279187} - EarthLink Toolbar - C:Program FilesEarthLinkToolbarToolbar.dll [2008-11-04 873968]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"nTrayFw"=C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnTrayFw.exe [2004-11-20 266240]
"AGRSMMSG"=C:WINDOWSAGRSMMSG.exe [2005-12-12 88204]
"YSearchProtection"=C:Program FilesYahoo!Search ProtectionSearchProtection.exe [2009-02-23 111856]
"Windows Defender"=C:Program FilesWindows DefenderMSASCui.exe [2006-11-03 866584]
"MSSE"=c:Program FilesMicrosoft Security Essentialsmsseces.exe [2009-09-13 1048392]
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"Protection System"=C:Program FilesProtection Systempsystem.exe []
"Messenger (Yahoo!)"=C:Program FilesYahoo!MessengerYahooMessenger.exe [2009-05-26 4351216]
"Search Protection"=C:Program FilesYahoo!Search ProtectionSearchProtection.exe [2009-02-23 111856]
"ms18_word"=C:Documents and Settingsuserms18_word.exe []
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:PROGRA~1WIFD1F~1MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalMsMpSvc]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWinDefend]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkMsMpSvc]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkUploadMgr]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkWinDefend]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"C:WINDOWSSystem32qbubjogw.exe"="C:WINDOWSSystem32qbubjogw.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32azvyue.exe"="C:WINDOWSSystem32azvyue.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32ssywx.exe"="C:WINDOWSSystem32ssywx.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32qvvcq.exe"="C:WINDOWSSystem32qvvcq.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32jqbfdhz.exe"="C:WINDOWSSystem32jqbfdhz.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32apkprhx.exe"="C:WINDOWSSystem32apkprhx.exe:*:Enabled:Ultimate Tool"
"C:youre.exe"="C:youre.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32zoyyyz.exe"="C:WINDOWSSystem32zoyyyz.exe:*:Enabled:Ultimate Tool"
"C:WINDOWSSystem32msbiygma.exe"="C:WINDOWSSystem32msbiygma.exe:*:Enabled:Ultimate Tool"
"%windir%system32sessmgr.exe"="%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
"%windir%system32sessmgr.exe"="%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{51d10ffe-719b-11de-9c9c-806d6172696f}]
shellAutoRuncommand - D:setup.exe
======List of files/folders created in the last 1 months======
2009-11-09 18:36:58 ----D---- C:Program Filestrend micro
2009-11-09 18:36:57 ----D---- C:rsit
2009-11-09 14:41:06 ----D---- C:Program FilesMicrosoft Security Essentials
2009-11-09 14:40:56 ----HDC---- C:WINDOWS$NtUninstallKB914882$
2009-11-09 14:32:31 ----N---- C:WINDOWSsystem32MpSigStub.exe
2009-11-09 14:29:37 ----D---- C:Program FilesWindows Defender
2009-11-09 14:24:30 ----D---- C:WINDOWSPrefetch
2009-11-09 14:19:58 ----N---- C:WINDOWSsystem32proxycfg.exe
2009-11-09 14:19:58 ----N---- C:WINDOWSsystem32logman.exe
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32cmsetacl.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32btpanui.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32bthserv.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32bthci.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32blastcln.exe
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32auditusr.exe
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ativvaxx.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ativtmxx.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ati3duag.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ati3d1ag.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ati2dvag.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ati2dvaa.dll
2009-11-09 14:19:53 ----N---- C:WINDOWSsystem32ati2cqag.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32mdmxsdk.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdukx.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdsmsno.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdsmsfi.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdno1.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdmlt48.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdmlt47.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdmaori.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdinmal.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdinben.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdinbe1.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32kbdfi1.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ir50_qcx.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ir50_qc.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ir50_32.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ir41_qcx.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ir41_qc.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32ieencode.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32httpapi.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32hsfcisp2.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32fwcfg.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32fsquirt.exe
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32fltmc.exe
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32fltlib.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32extmgr.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32dxdiagn.dll
2009-11-09 14:19:52 ----N---- C:WINDOWSsystem32d3d9.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32slextspk.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32slcoinst.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32sdhcinst.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32s3gnb.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32powercfg.exe
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32pnrpnsp.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32p2psvc.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32p2pnetsh.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32p2pgraph.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32p2pgasvc.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32p2p.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32mtxparhd.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32mspmsnsv.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32msdadiag.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32mp4sdmod.dll
2009-11-09 14:19:51 ----N---- C:WINDOWSsystem32mp43dmod.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmspdmod.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmsdmoe2.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmpdxm.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmpasf.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmp.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmidx.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32wmerror.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32winshfhc.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32w3ssl.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32twext.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32strmfilt.dll
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32smbinst.exe
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32slserv.exe
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32slrundll.exe
2009-11-09 14:19:50 ----N---- C:WINDOWSsystem32slgen.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32xmlprovi.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32xmlprov.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wuaueng1.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wuauclt1.exe
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wshbth.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wscsvc.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wscntfy.exe
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wmvdmoe2.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSsystem32wmspdmoe.dll
2009-11-09 14:19:49 ----N---- C:WINDOWSslrundll.exe
2009-11-09 14:17:08 ----N---- C:WINDOWSsystem32xpsp2res.dll
2009-11-09 14:16:40 ----A---- C:WINDOWS002220_.tmp
2009-11-09 11:38:47 ----D---- C:Documents and SettingsuserApplication DataSun
2009-11-07 22:18:20 ----D---- C:Program FilesWindows Live Safety Center
2009-11-07 14:02:07 ----D---- C:Documents and SettingsuserApplication DataAVG8
2009-11-07 10:33:04 ----A---- C:WINDOWSsystem32MRT.exe
2009-11-06 21:00:32 ----D---- C:Program FilesMalwarebytes' Anti-Malware
2009-11-06 21:00:32 ----D---- C:Documents and SettingsAll Users.WINDOWSApplication DataMalwarebytes
2009-11-06 20:33:14 ----A---- C:WINDOWSntbtlog.txt
======List of files/folders modified in the last 1 months======
2009-11-09 18:36:58 ----RD---- C:Program Files
2009-11-09 16:23:14 ----D---- C:WINDOWSTemp
2009-11-09 15:06:46 ----SD---- C:WINDOWSTasks
2009-11-09 15:05:22 ----A---- C:WINDOWSSchedLgU.Txt
2009-11-09 14:48:31 ----D---- C:WINDOWSsystem32CatRoot2
2009-11-09 14:45:38 ----D---- C:WINDOWS
2009-11-09 14:45:26 ----D---- C:WINDOWSDebug
2009-11-09 14:41:42 ----D---- C:WINDOWSsecurity
2009-11-09 14:41:14 ----SHD---- C:WINDOWSInstaller
2009-11-09 14:41:11 ----HD---- C:WINDOWSinf
2009-11-09 14:41:11 ----D---- C:WINDOWSsystem32drivers
2009-11-09 14:41:10 ----SD---- C:Documents and SettingsAll Users.WINDOWSApplication DataMicrosoft
2009-11-09 14:40:58 ----D---- C:WINDOWSsystem32
2009-11-09 14:40:54 ----HD---- C:WINDOWS$hf_mig$
2009-11-09 14:28:41 ----A---- C:WINDOWSsystem32PerfStringBackup.INI
2009-11-09 14:25:55 ----A---- C:WINDOWSOEWABLog.txt
2009-11-09 14:25:44 ----A---- C:WINDOWSimsins.BAK
2009-11-09 14:24:57 ----A---- C:WINDOWSsetuplog.txt
2009-11-09 14:24:04 ----D---- C:WINDOWSsystem32wbem
2009-11-09 14:24:04 ----D---- C:WINDOWSAppPatch
2009-11-09 14:24:03 ----RSD---- C:WINDOWSFonts
2009-11-09 14:22:04 ----D---- C:WINDOWSsystem32CatRoot
2009-11-09 14:20:21 ----RASH---- C:boot.ini
2009-11-09 14:20:21 ----A---- C:WINDOWSwin.ini
2009-11-09 14:19:58 ----D---- C:WINDOWSHelp
2009-11-09 14:19:57 ----D---- C:WINDOWSsystem32Setup
2009-11-09 14:19:57 ----D---- C:WINDOWSsystem32oobe
2009-11-09 14:19:57 ----D---- C:Program FilesCommon FilesSystem
2009-11-09 14:19:56 ----D---- C:WINDOWSsystem32mui
2009-11-09 14:19:56 ----D---- C:WINDOWSime
2009-11-09 14:19:49 ----D---- C:Program FilesWindows Media Player
2009-11-09 14:19:48 ----D---- C:WINDOWSPeerNet
2009-11-09 14:19:48 ----D---- C:Program FilesMovie Maker
2009-11-09 14:19:47 ----D---- C:WINDOWSMedia
2009-11-09 14:18:23 ----D---- C:Program FilesInternet Explorer
2009-11-09 14:18:22 ----D---- C:WINDOWSsystem32Restore
2009-11-09 14:18:22 ----D---- C:WINDOWSsystem32npp
2009-11-09 14:18:22 ----D---- C:WINDOWSmsagent
2009-11-09 14:18:20 ----D---- C:WINDOWSsrchasst
2009-11-09 14:18:18 ----D---- C:Program FilesNetMeeting
2009-11-09 14:18:17 ----D---- C:WINDOWSsystem32Com
2009-11-09 14:18:14 ----D---- C:Program FilesWindows NT
2009-11-09 14:18:14 ----D---- C:Program FilesOutlook Express
2009-11-09 14:18:09 ----RSHDC---- C:WINDOWSsystem32dllcache
2009-11-09 14:18:02 ----D---- C:WINDOWSsystem32usmt
2009-11-09 14:18:01 ----D---- C:WINDOWSsystem
2009-11-09 14:17:08 ----RD---- C:WINDOWSWeb
2009-11-09 14:17:00 ----RASH---- C:NTDETECT.COM
2009-11-09 14:16:33 ----HDC---- C:WINDOWS$NtServicePackUninstall$
2009-11-09 14:15:30 ----D---- C:WINDOWSEHome
2009-11-07 22:18:20 ----SD---- C:WINDOWSDownloaded Program Files
2009-11-06 21:11:25 ----D---- C:Program FilesESET
2009-11-06 20:39:41 ----D---- C:WINDOWSMinidump
2009-11-06 20:33:24 ----D---- C:Documents and Settings
2009-10-12 12:32:09 ----D---- C:Documents and SettingsuserApplication DataMSN6
2009-10-12 12:23:28 ----A---- C:WINDOWSModemLog_Agere Systems PCI Soft Modem.txt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 MpFilter;Microsoft Malware Protection Driver; C:WINDOWSsystem32DRIVERSMpFilter.sys [2009-06-18 142832]
R1 NVTCP;NVIDIA TCP/IP Protocol Driver; C:WINDOWSSystem32DRIVERSNVTcp.sys [2004-11-10 94976]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:WINDOWSSystem32driversws2ifsl.sys [2003-03-31 12032]
R3 AgereSoftModem;Agere Systems Soft Modem; C:WINDOWSSystem32DRIVERSAGRSM.sys [2005-12-12 1124097]
R3 Arp1394;1394 ARP Client Protocol; C:WINDOWSSystem32DRIVERSarp1394.sys [2004-08-03 60800]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:WINDOWSsystem32driversmsmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:WINDOWSSystem32DRIVERSASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:WINDOWSSystem32DRIVERSnic1394.sys [2004-08-03 61824]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:WINDOWSSystem32DRIVERSNVENETFD.sys [2004-11-10 33408]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:WINDOWSSystem32DRIVERSnvnetbus.sys [2004-11-10 12928]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:WINDOWSSystem32DRIVERSusbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:WINDOWSSystem32DRIVERSusbhub.sys [2004-08-03 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:WINDOWSSystem32DRIVERSusbohci.sys [2004-08-03 17024]
S1 jwgvxnhg;jwgvxnhg; ??C:WINDOWSsystem32driversjwgvxnhg.sys []
S1 kbdhid;Keyboard HID Driver; C:WINDOWSSystem32DRIVERSkbdhid.sys [2004-08-03 14848]
S1 SABKUTIL;SABKUTIL; ??C:Documents and SettingsuserDesktopSABKUTIL.sys []
S3 HidUsb;Microsoft HID Class Driver; C:WINDOWSSystem32DRIVERShidusb.sys [2001-08-17 9600]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:WINDOWSSystem32DriversRootMdm.sys [2003-03-31 5888]
S3 RT2500;RT2500 Wireless Driver; C:WINDOWSSystem32DRIVERSRT2500.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:WINDOWSSystem32DRIVERSusbccgp.sys [2004-08-03 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:WINDOWSSystem32DRIVERSusbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:WINDOWSSystem32DRIVERSusbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:WINDOWSSystem32DRIVERSUSBSTOR.SYS [2004-08-03 26496]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 app_filter;app_filter; C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcAppFlt.exe [2004-11-20 139264]
R2 ForcewareWebInterface;Forceware Web Interface; C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe [2004-10-30 20543]
R2 MsMpSvc;Microsoft Antimalware Service; c:Program FilesMicrosoft Security EssentialsMsMpEng.exe [2009-07-02 17904]
R2 nSvcIp;ForceWare IP service; C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe [2004-11-20 110653]
R2 nSvcLog;ForceWare user log service; C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe [2004-11-20 53313]
R2 PC FineTune Task Manager;PC FineTune Task Manager; C:PROGRA~1EARTHL~2PCFINE~1MXTask.exe [2008-11-14 120088]
R2 WinDefend;Windows Defender; C:Program FilesWindows DefenderMsMpEng.exe [2006-11-03 13592]
S2 hwclock;Hardware Clock Driver; C:WINDOWSSystem32hwclock.exe []
-----------------EOF-----------------
P.S. When trying to run RootRepeal the error message is sisplayed: Could not read the boot sector. Try adjusting the Disk Access Level in the Options dialog.
When continuing RootRepeal the computer freezes in the Initializing, please wait..... process.
Merged posts. ~ OB
This post has been edited by Orange Blossom: 09 November 2009 - 09:50 PM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top












