This is a similar post to a topic closed recently as I was away, sorry. I didn't respond in time, but my searchqu issues remain.
I have included the logs as previously requested:
- DDS Scan
- RK Unhooker about half way down this page.
- Attach (attached below).
- DDS Scan below:
.
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_25
Run by Sean at 0:19:48 on 2011-06-15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.64.1033.18.2975.2002 [GMT 12:00]
.
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
.
============== Running Processes ===============
.
G:\Windows\system32\wininit.exe
G:\Windows\system32\lsm.exe
G:\Windows\system32\svchost.exe -k DcomLaunch
G:\Windows\system32\svchost.exe -k RPCSS
G:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
G:\Windows\system32\svchost.exe -k NetworkService
G:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
G:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
G:\Windows\system32\svchost.exe -k netsvcs
G:\Windows\system32\svchost.exe -k LocalService
G:\Windows\System32\spoolsv.exe
G:\Program Files\Avira\AntiVir Desktop\sched.exe
G:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
G:\Program Files\Avira\AntiVir Desktop\avguard.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
G:\Program Files\Avira\AntiVir Desktop\avshadow.exe
G:\Windows\system32\conhost.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
G:\Windows\system32\svchost.exe -k imgsvc
G:\Windows\system32\taskhost.exe
G:\Windows\system32\Dwm.exe
G:\Windows\Explorer.EXE
G:\Program Files\Avira\AntiVir Desktop\avgnt.exe
G:\Program Files\COMODO\COMODO Internet Security\cfp.exe
G:\Windows\System32\igfxtray.exe
G:\Windows\System32\hkcmd.exe
G:\Windows\System32\igfxpers.exe
G:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\DivX\DivX Update\DivXUpdate.exe
G:\Program Files\Common Files\Java\Java Update\jusched.exe
G:\Program Files\Skype\Phone\Skype.exe
G:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
G:\Windows\system32\WUDFHost.exe
G:\Windows\System32\StikyNot.exe
G:\Program Files\Windows Live\Messenger\msnmsgr.exe
G:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
G:\Windows\system32\SearchIndexer.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\Program Files\Windows Media Player\wmpnetwk.exe
G:\Program Files\Skype\Plugin Manager\skypePM.exe
G:\Windows\System32\svchost.exe -k secsvcs
G:\Windows\system32\wuauclt.exe
G:\Users\Sean\AppData\Local\Google\Chrome\Application\chrome.exe
G:\Users\Sean\AppData\Local\Google\Chrome\Application\chrome.exe
G:\Users\Sean\AppData\Local\Google\Chrome\Application\chrome.exe
G:\Windows\system32\msiexec.exe
G:\Windows\system32\SearchProtocolHost.exe
G:\Windows\system32\SearchFilterHost.exe
G:\Windows\system32\rundll32.exe
G:\Users\Sean\AppData\Local\Google\Chrome\Application\chrome.exe
G:\Users\Sean\AppData\Local\Google\Chrome\Application\chrome.exe
G:\Windows\system32\conhost.exe
G:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - g:\program files\bittorrentbar\tbBit1.dll
mURLSearchHooks: H - No File
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - g:\program files\bittorrentbar\tbBit1.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - g:\program files\vshare\vshare_toolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - g:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - g:\program files\conduitengine\ConduitEngine.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - g:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - g:\program files\bittorrentbar\tbBit1.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - g:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - g:\program files\ask.com\GenericAskToolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - g:\program files\java\jre6\bin\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - g:\program files\daemon tools toolbar\DTToolbar.dll
TB: vShare Plugin: {043c5167-00bb-4324-af7e-62013faedacf} - g:\program files\vshare\vshare_toolbar.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - g:\program files\bittorrentbar\tbBit1.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - g:\program files\conduitengine\ConduitEngine.dll
TB: {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - No File
uRun: [Skype] "g:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Sidebar] g:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [RESTART_STICKY_NOTES] g:\windows\system32\StikyNot.exe
uRun: [msnmsgr] "g:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Google Update] "g:\users\sean\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [avgnt] "g:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [COMODO Internet Security] "g:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [IgfxTray] g:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] g:\windows\system32\hkcmd.exe
mRun: [Persistence] g:\windows\system32\igfxpers.exe
mRun: [GrooveMonitor] "g:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "g:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "g:\program files\itunes\iTunesHelper.exe"
mRun: [DivXUpdate] "g:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe Reader Speed Launcher] "g:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "g:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "g:\program files\common files\java\java update\jusched.exe"
mRunOnce: [removeSearchqudatamngr] cmd.exe /c RD /S /Q "g:\program files\Windows iLivid Toolbar"
mRunOnce: [removeSearchqutoolbar] cmd.exe /c RD /S /Q "g:\program files\windows ilivid toolbar\ToolBar"
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - g:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - g:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - g:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - g:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{1A45AAA2-5DC4-4ED0-938B-EF375253646D} : DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{B73F15F2-1508-47DC-A003-3F3AC2E3AA42} : DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{B73F15F2-1508-47DC-A003-3F3AC2E3AA42}\1476E656376716E64656B6C657E646562747 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{B73F15F2-1508-47DC-A003-3F3AC2E3AA42}\3586F62756C4962627162796563775966496 : DhcpNameServer = 202.126.207.10 202.126.207.193
TCP: Interfaces\{B73F15F2-1508-47DC-A003-3F3AC2E3AA42}\36166656E65647 : DhcpNameServer = 202.126.206.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - g:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - g:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} -
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: g:\windows\system32\guard32.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - g:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - g:\users\sean\appdata\roaming\mozilla\firefox\profiles\kb5pfudh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&q=
FF - component: g:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - component: g:\users\sean\appdata\roaming\mozilla\firefox\profiles\kb5pfudh.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCoreGecko19.dll
FF - component: g:\users\sean\appdata\roaming\mozilla\firefox\profiles\kb5pfudh.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: g:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: g:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: g:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: g:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: g:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: g:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: g:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: g:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: g:\users\sean\appdata\local\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: g:\users\sean\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - plugin: g:\windows\microsoft.net\framework\v4.0.20506\wpf\NPWPF.dll
.
============= SERVICES / DRIVERS ===============
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;g:\windows\system32\drivers\cmdGuard.sys [2010-3-23 238960]
R1 cmdHlp;COMODO Internet Security Helper Driver;g:\windows\system32\drivers\cmdhlp.sys [2010-3-3 37592]
R1 vwififlt;Virtual WiFi Filter Driver;g:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;g:\program files\avira\antivir desktop\sched.exe [2010-3-26 136360]
R2 AntiVirService;Avira AntiVir Guard;g:\program files\avira\antivir desktop\avguard.exe [2010-3-26 269480]
R2 avgntflt;avgntflt;g:\windows\system32\drivers\avgntflt.sys [2010-3-26 61960]
R3 RTL8167;Realtek 8167 NT Driver;g:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776]
R3 SrvHsfHDA;SrvHsfHDA;g:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360]
R3 SrvHsfV92;SrvHsfV92;g:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]
R3 SrvHsfWinac;SrvHsfWinac;g:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504]
S2 gupdate;Google Update Service (gupdate);g:\program files\google\update\GoogleUpdate.exe [2011-3-18 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;g:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 clr_optimization_v4.0.20506_32;.NET Runtime Optimization Service v4.0.20506_X86;g:\windows\microsoft.net\framework\v4.0.20506\mscorsvw.exe [2009-5-6 104272]
S3 epmntdrv;epmntdrv;g:\windows\system32\epmntdrv.sys [2010-5-23 14216]
S3 EuGdiDrv;EuGdiDrv;g:\windows\system32\EuGdiDrv.sys [2010-5-23 8456]
S3 gupdatem;Google Update Service (gupdatem);g:\program files\google\update\GoogleUpdate.exe [2011-3-18 136176]
S3 SwitchBoard;Adobe SwitchBoard;g:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WatAdminSvc;Windows Activation Technologies Service;g:\windows\system32\wat\WatAdminSvc.exe [2010-4-13 1343400]
S3 WPFFontCache_v0400;WPFFontCache_v0400;g:\windows\microsoft.net\framework\v4.0.30128\wpf\wpffontcache_v0400.exe --> g:\windows\microsoft.net\framework\v4.0.30128\wpf\WPFFontCache_v0400.exe [?]
.
=============== Created Last 30 ================
.
2011-06-10 06:47:37 6962000 ----a-w- g:\programdata\microsoft\windows defender\definition updates\{3f1029e5-2779-4b25-971f-4b163b272a9a}\mpengine.dll
2011-05-25 11:24:27 26496 ----a-w- g:\windows\system32\drivers\Diskdump.sys
2011-05-25 10:58:41 -------- d-----w- g:\windows\system32\EventProviders
2011-05-24 09:28:53 83249512 ----a-w- g:\program files\common files\windows live\.cache\wlc35DD.tmp
2011-05-19 11:43:42 -------- d-----w- g:\users\sean\appdata\local\Ilivid Player
2011-05-19 11:42:43 -------- d-----w- g:\users\sean\appdata\local\PackageAware
2011-05-17 08:12:21 123904 ----a-w- g:\windows\system32\poqexec.exe
.
==================== Find3M ====================
.
2011-05-12 12:19:43 284744 ----a-w- g:\windows\system32\guard32.dll
2011-05-12 12:19:41 37592 ----a-w- g:\windows\system32\drivers\cmdhlp.sys
2011-05-12 12:19:40 238960 ----a-w- g:\windows\system32\drivers\cmdGuard.sys
2011-05-12 12:19:40 19088 ----a-w- g:\windows\system32\drivers\cmderd.sys
2011-04-13 17:07:59 472808 ----a-w- g:\windows\system32\deployJava1.dll
2011-04-09 06:13:06 3957632 ----a-w- g:\windows\system32\ntkrnlpa.exe
2011-04-09 06:13:06 3901824 ----a-w- g:\windows\system32\ntoskrnl.exe
2011-04-06 04:20:16 91424 ----a-w- g:\windows\system32\dnssd.dll
2011-04-06 04:20:16 75040 ----a-w- g:\windows\system32\jdns_sd.dll
2011-04-06 04:20:16 197920 ----a-w- g:\windows\system32\dnssdX.dll
2011-04-06 04:20:16 107808 ----a-w- g:\windows\system32\dns-sd.exe
.
============= FINISH: 0:23:49.56 ===============
RK Unhooker Report.
RkU Version: 3.8.389.593, Type LE (SR2)
==============================================
OS Name: Windows 7
Version 6.1.7600
Number of processors #2
==============================================
>Drivers
==============================================
0x9262C000 G:\Windows\system32\DRIVERS\igdkmd32.sys 9555968 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x82E19000 G:\Windows\system32\ntkrnlpa.exe 4259840 bytes (Microsoft Corporation, NT Kernel & System)
0x82E19000 PnpManager 4259840 bytes
0x82E19000 RAW 4259840 bytes
0x82E19000 WMIxWDM 4259840 bytes
0x81EB0000 Win32k 2404352 bytes
0x81EB0000 G:\Windows\System32\win32k.sys 2404352 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8B692000 G:\Windows\System32\drivers\tcpip.sys 1347584 bytes (Microsoft Corporation, TCP/IP Driver)
0x8B423000 G:\Windows\System32\Drivers\Ntfs.sys 1241088 bytes (Microsoft Corporation, NT File System Driver)
0x93001000 G:\Windows\system32\DRIVERS\athr.sys 1114112 bytes (Atheros Communications, Inc., Atheros Extensible Wireless LAN device driver)
0x9A008000 G:\Windows\system32\DRIVERS\VSTDPV3.SYS 1056768 bytes (Conexant Systems, Inc., HSF_DP driver)
0x8B0B0000 PCI_PNP5723 995328 bytes
0x8B0B0000 G:\Windows\System32\Drivers\sppe.sys 995328 bytes
0x8B0B0000 sptd 995328 bytes
0x92F49000 G:\Windows\System32\drivers\dxgkrnl.sys 749568 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8B32A000 G:\Windows\system32\drivers\ndis.sys 749568 bytes (Microsoft Corporation, NDIS 6.20 driver)
0x9A10A000 G:\Windows\system32\DRIVERS\VSTCNXT3.SYS 741376 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0x8AEFC000 G:\Windows\system32\CI.dll 700416 bytes (Microsoft Corporation, Code Integrity Module)
0xAF80C000 G:\Windows\system32\drivers\peauth.sys 618496 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x9B481000 G:\Windows\system32\drivers\HTTP.sys 544768 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8AE29000 G:\Windows\system32\mcupdate_GenuineIntel.dll 491520 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x8B031000 G:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0x91201000 G:\Windows\system32\drivers\csc.sys 409600 bytes (Microsoft Corporation, Windows Client Side Caching Driver)
0x8B590000 G:\Windows\System32\Drivers\cng.sys 380928 bytes (Microsoft Corporation, Kernel Cryptography, Next Generation)
0x9183E000 G:\Windows\system32\drivers\afd.sys 368640 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0xAF92A000 G:\Windows\System32\DRIVERS\srv.sys 335872 bytes (Microsoft Corporation, Server driver)
0x94B4E000 G:\Windows\system32\drivers\HdAudio.sys 327680 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0xAF8DB000 G:\Windows\System32\DRIVERS\srv2.sys 323584 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x82160000 G:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0x91326000 G:\Windows\system32\DRIVERS\USBPORT.SYS 307200 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x8B22D000 G:\Windows\System32\drivers\volmgrx.sys 307200 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x8AFA7000 G:\Windows\system32\DRIVERS\ACPI.sys 294912 bytes (Microsoft Corporation, ACPI Driver for NT)
0x9B418000 G:\Windows\system32\DRIVERS\nwifi.sys 286720 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x94A39000 G:\Windows\system32\DRIVERS\usbhub.sys 278528 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x8AEBA000 G:\Windows\system32\CLFS.SYS 270336 bytes (Microsoft Corporation, Common Log File System Driver)
0x9194E000 G:\Windows\system32\DRIVERS\rdbss.sys 266240 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8B863000 G:\Windows\system32\DRIVERS\volsnap.sys 258048 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8B9A9000 G:\Windows\System32\DRIVERS\cmdguard.sys 253952 bytes (COMODO, COMODO Internet Security Sandbox Driver)
0x8B62F000 G:\Windows\system32\drivers\NETIO.SYS 253952 bytes (Microsoft Corporation, Network I/O Subsystem)
0x94B11000 G:\Windows\system32\DRIVERS\VSTAZL3.SYS 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0x94A8E000 G:\Windows\system32\drivers\CHDRT32.sys 241664 bytes (Conexant Systems Inc., High Definition Audio Function Driver)
0x9B554000 G:\Windows\system32\DRIVERS\mrxsmb10.sys 241664 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x93157000 G:\Windows\System32\Drivers\awemikc4.SYS 233472 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x912ED000 G:\Windows\System32\drivers\dxgmms1.sys 233472 bytes (Microsoft Corporation, DirectX Graphics MMS)
0x83229000 ACPI_HAL 225280 bytes
0x83229000 G:\Windows\system32\halmacpi.dll 225280 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x8B2DB000 G:\Windows\system32\drivers\fltmgr.sys 212992 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x919B0000 G:\Windows\system32\DRIVERS\ks.sys 212992 bytes (Microsoft Corporation, Kernel CSA Library)
0x8B8EF000 G:\Windows\System32\DRIVERS\fvevol.sys 204800 bytes (Microsoft Corporation, BitLocker Drive Encryption Driver)
0x91898000 G:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8B829000 G:\Windows\System32\drivers\fwpkclnt.sys 200704 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x94AC9000 G:\Windows\system32\drivers\portcls.sys 192512 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x8B8AA000 G:\Windows\System32\drivers\rdyboost.sys 184320 bytes (Microsoft Corporation, ReadyBoost Driver)
0x8B552000 G:\Windows\System32\Drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8B000000 G:\Windows\system32\DRIVERS\pci.sys 172032 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x9128B000 G:\Windows\system32\DRIVERS\avipbb.sys 155648 bytes (Avira GmbH, Avira Driver for Security Enhancement)
0x8B1AC000 G:\Windows\System32\Drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver)
0x8B932000 G:\Windows\system32\DRIVERS\CLASSPNP.SYS 151552 bytes (Microsoft Corporation, SCSI Class System Dll)
0x8B66D000 G:\Windows\System32\Drivers\ksecpkg.sys 151552 bytes (Microsoft Corporation, Kernel Security Support Provider Interface Packages)
0x91390000 G:\Windows\system32\DRIVERS\Rt86win7.sys 151552 bytes (Realtek Corporation , Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver )
0x94B9E000 G:\Windows\System32\Drivers\usbvideo.sys 147456 bytes (Microsoft Corporation, USB Video Class Driver)
0x8B297000 G:\Windows\system32\DRIVERS\ataport.SYS 143360 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9B531000 G:\Windows\system32\DRIVERS\mrxsmb.sys 143360 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x931D2000 G:\Windows\system32\DRIVERS\ndiswan.sys 139264 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xAF8AD000 G:\Windows\System32\DRIVERS\srvnet.sys 135168 bytes (Microsoft Corporation, Server Network driver)
0x912B1000 G:\Windows\system32\DRIVERS\tunnel.sys 135168 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8B7DB000 G:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0xAF97C000 G:\Windows\system32\DRIVERS\WUDFRd.sys 135168 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector)
0x8B98A000 G:\Windows\system32\DRIVERS\cdrom.sys 126976 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x91371000 G:\Windows\system32\DRIVERS\HDAudBus.sys 126976 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x918D1000 G:\Windows\system32\DRIVERS\pacer.sys 126976 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x82140000 G:\Windows\System32\cdd.dll 122880 bytes (Microsoft Corporation, Canonical Display Driver)
0x94A0B000 G:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x9B58F000 G:\Windows\system32\DRIVERS\mrxsmb20.sys 110592 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x91800000 G:\Windows\system32\drivers\WudfPf.sys 106496 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0x9B506000 G:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x94AF8000 G:\Windows\system32\drivers\drmk.sys 102400 bytes (Microsoft Corporation, Microsoft Trusted Audio Drivers)
0x91265000 G:\Windows\System32\Drivers\dfsc.sys 98304 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x9311B000 G:\Windows\system32\DRIVERS\i8042prt.sys 98304 bytes (Microsoft Corporation, i8042 Port Driver)
0x931AF000 G:\Windows\system32\DRIVERS\rasl2tp.sys 98304 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x913B5000 G:\Windows\system32\DRIVERS\raspppoe.sys 98304 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x913CD000 G:\Windows\system32\DRIVERS\raspptp.sys 94208 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x913E4000 G:\Windows\system32\DRIVERS\rassstp.sys 94208 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8B409000 G:\Windows\system32\DRIVERS\tdx.sys 94208 bytes (Microsoft Corporation, TDI Translation Driver)
0x9A1E5000 G:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0x9A1CC000 G:\Windows\system32\DRIVERS\USBSTOR.SYS 94208 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0x91901000 G:\Windows\system32\DRIVERS\inspect.sys 90112 bytes (COMODO, COMODO Internet Security Firewall Driver)
0x8B278000 G:\Windows\System32\drivers\mountmgr.sys 90112 bytes (Microsoft Corporation, Mount Point Manager)
0x919E4000 G:\Windows\system32\DRIVERS\avgntflt.sys 86016 bytes (Avira GmbH, Avira Minifilter Driver)
0x8B57D000 G:\Windows\System32\Drivers\ksecdd.sys 77824 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x9B46E000 G:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x91925000 G:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x9319D000 G:\Windows\system32\DRIVERS\AgileVpn.sys 73728 bytes (Microsoft Corporation, RAS Agile Vpn Miniport Call Manager)
0x912D2000 G:\Windows\system32\DRIVERS\intelppm.sys 73728 bytes (Microsoft Corporation, Processor Device Driver)
0x9B51F000 G:\Windows\System32\drivers\mpsdrv.sys 73728 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8B921000 G:\Windows\system32\DRIVERS\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x94BEE000 G:\Windows\System32\Drivers\dump_dumpfve.sys 69632 bytes
0x8B30F000 G:\Windows\system32\drivers\fileinfo.sys 69632 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x94A7D000 G:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x8B1E5000 G:\Windows\System32\drivers\partmgr.sys 69632 bytes (Microsoft Corporation, Partition Management Driver)
0x8AEA1000 G:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x918F0000 G:\Windows\system32\DRIVERS\vwififlt.sys 69632 bytes (Microsoft Corporation, Virtual WiFi Filter Driver)
0x94A26000 G:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x8B8D7000 G:\Windows\System32\Drivers\mup.sys 65536 bytes (Microsoft Corporation, Multiple UNC Provider Driver)
0x9B45E000 G:\Windows\system32\DRIVERS\ndisuio.sys 65536 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x91938000 G:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Remote Desktop Server Driver)
0x8AE00000 G:\Windows\system32\DRIVERS\volmgr.sys 65536 bytes (Microsoft Corporation, Volume Manager Driver)
0x9260B000 G:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x9127D000 G:\Windows\system32\DRIVERS\blbdrive.sys 57344 bytes (Microsoft Corporation, BLB Drive Driver)
0x91917000 G:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8B60B000 G:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x8B2C4000 G:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8B5ED000 G:\Windows\System32\drivers\pcw.sys 57344 bytes (Microsoft Corporation, Performance Counters for Windows Driver)
0x9261A000 G:\Windows\system32\DRIVERS\umbus.sys 57344 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x8B0A2000 G:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0x93190000 G:\Windows\system32\DRIVERS\CompositeBus.sys 53248 bytes (Microsoft Corporation, Multi-Transport Composite Bus Enumerator)
0x94BCC000 G:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x93133000 G:\Windows\system32\DRIVERS\kbdclass.sys 53248 bytes (Microsoft Corporation, Keyboard Class Driver)
0x9A1BF000 G:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x93140000 G:\Windows\system32\DRIVERS\mouclass.sys 53248 bytes (Microsoft Corporation, Mouse Class Driver)
0xAF8CE000 G:\Windows\System32\drivers\tcpipreg.sys 53248 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x8B80C000 G:\Windows\System32\drivers\watchdog.sys 53248 bytes (Microsoft Corporation, Watchdog Driver)
0x919A4000 G:\Windows\System32\drivers\discache.sys 49152 bytes (Microsoft Corporation, System Indexer/Cache Driver)
0x8B800000 G:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8AFEF000 G:\Windows\system32\DRIVERS\BATTC.SYS 45056 bytes (Microsoft Corporation, Battery Class Driver)
0x8B624000 G:\Windows\System32\DRIVERS\cmdhlp.sys 45056 bytes (COMODO, COMODO Internet Security Helper Driver)
0x94BD9000 G:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x94A00000 G:\Windows\system32\DRIVERS\monitor.sys 45056 bytes (Microsoft Corporation, Monitor Driver)
0x8B600000 G:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x931C7000 G:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8B619000 G:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x92600000 G:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8B1DA000 G:\Windows\system32\DRIVERS\vdrvroot.sys 45056 bytes (Microsoft Corporation, Virtual Drive Root Enumerator)
0x94BE4000 G:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x94BC2000 G:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x8B2BA000 G:\Windows\system32\DRIVERS\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x9199A000 G:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x91990000 G:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x8B320000 G:\Windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0x931F4000 G:\Windows\system32\DRIVERS\rdpbus.sys 40960 bytes (Microsoft Corporation, Microsoft RDP Bus Device driver)
0xAF8A3000 G:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x93111000 G:\Windows\system32\DRIVERS\vwifibus.sys 40960 bytes (Microsoft Corporation, Virtual WiFi Bus Driver)
0x8B2D2000 G:\Windows\system32\drivers\amdxata.sys 36864 bytes (Advanced Micro Devices, Storage Filter Driver)
0x8B28E000 G:\Windows\system32\DRIVERS\atapi.sys 36864 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0xAF99D000 G:\Windows\System32\Drivers\BlackBox.SYS 36864 bytes (RKU Driver)
0x8B400000 G:\Windows\System32\Drivers\Fs_Rec.sys 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x82110000 G:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8B85A000 G:\Windows\system32\DRIVERS\vmstorfl.sys 36864 bytes (Microsoft Corporation, Virtual Storage Filter Driver)
0x912E4000 G:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x8B1A3000 G:\Windows\System32\Drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x8AEB2000 G:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x8B1F6000 G:\Windows\system32\DRIVERS\compbatt.sys 32768 bytes (Microsoft Corporation, Composite Battery Driver)
0x8B8E7000 G:\Windows\System32\drivers\hwpolicy.sys 32768 bytes (Microsoft Corporation, Hardware Policy Driver)
0x80BD0000 G:\Windows\system32\kdcom.dll 32768 bytes (Microsoft Corporation, Serial Kernel Debugger)
0x8B1D2000 G:\Windows\system32\DRIVERS\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8B819000 G:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8B821000 G:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Encoder Miniport)
0x8B9F5000 G:\Windows\system32\drivers\rdprefmp.sys 32768 bytes (Microsoft Corporation, RDP Reflector Driver Miniport)
0x8B8A2000 G:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8B9EE000 G:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x8B9E7000 G:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x918CA000 G:\Windows\system32\DRIVERS\wfplwf.sys 28672 bytes (Microsoft Corporation, WFP NDIS 6.20 Lightweight Filter Driver)
0x93151000 G:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0x91948000 G:\Windows\system32\DRIVERS\ssmdrv.sys 24576 bytes (Avira GmbH, AVIRA SnapShot Driver)
0x9314D000 G:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x931FE000 G:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x9A1E3000 G:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0x9198F000 G:\Windows\System32\Drivers\PQNTDrv.SYS 4096 bytes (PowerQuest Corporation, PowerQuest Boot Mode Driver.)
0x854F61F8 unknown_irp_handler 3592 bytes
0x854F31F8 unknown_irp_handler 3592 bytes
0x866AC1F8 unknown_irp_handler 3592 bytes
0x871F91F8 unknown_irp_handler 3592 bytes
0x868FC1F8 unknown_irp_handler 3592 bytes
0x854F51F8 unknown_irp_handler 3592 bytes
0x8681E1F8 unknown_irp_handler 3592 bytes
0x869951F8 unknown_irp_handler 3592 bytes
0x854F11F8 unknown_irp_handler 3592 bytes
0x854F41F8 unknown_irp_handler 3592 bytes
0x867261F8 unknown_irp_handler 3592 bytes
0x868C0500 unknown_irp_handler 2816 bytes
==============================================
>Stealth
==============================================
WARNING: File locked for read access [G:\Windows\system32\drivers\sptd.sys]
Thanks for your time in discussing this with me.
Attached File(s)
-
Attach.txt (8.41K)
Number of downloads: 0

Help
This topic is locked


Back to top



textbox. Do not include the word Code
.








