hi cat
i ran the apps as requested
TDSSKiller came up clear..log follows
2011/08/19 12:43:36.0006 57380 TDSS rootkit removing tool 2.5.15.0 Aug 11 2011 16:32:13
2011/08/19 12:43:36.0402 57380 ================================================================================
2011/08/19 12:43:36.0402 57380 SystemInfo:
2011/08/19 12:43:36.0402 57380
2011/08/19 12:43:36.0402 57380 OS Version: 6.0.6002 ServicePack: 2.0
2011/08/19 12:43:36.0402 57380 Product type: Workstation
2011/08/19 12:43:36.0402 57380 ComputerName: JHG_LAPTOP
2011/08/19 12:43:36.0403 57380 UserName: jhg
2011/08/19 12:43:36.0403 57380 Windows directory: C:\Windows
2011/08/19 12:43:36.0403 57380 System windows directory: C:\Windows
2011/08/19 12:43:36.0403 57380 Processor architecture: Intel x86
2011/08/19 12:43:36.0403 57380 Number of processors: 2
2011/08/19 12:43:36.0403 57380 Page size: 0x1000
2011/08/19 12:43:36.0403 57380 Boot type: Normal boot
2011/08/19 12:43:36.0403 57380 ================================================================================
2011/08/19 12:43:39.0353 57380 Initialize success
2011/08/19 12:43:44.0043 57844 ================================================================================
2011/08/19 12:43:44.0043 57844 Scan started
2011/08/19 12:43:44.0043 57844 Mode: Manual;
2011/08/19 12:43:44.0043 57844 ================================================================================
2011/08/19 12:43:47.0243 57844 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/08/19 12:43:47.0477 57844 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/08/19 12:43:47.0639 57844 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/08/19 12:43:47.0831 57844 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/08/19 12:43:47.0911 57844 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/08/19 12:43:48.0098 57844 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
2011/08/19 12:43:48.0757 57844 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/08/19 12:43:48.0903 57844 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/08/19 12:43:49.0007 57844 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/08/19 12:43:49.0100 57844 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/08/19 12:43:49.0153 57844 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/08/19 12:43:49.0305 57844 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/08/19 12:43:49.0470 57844 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
2011/08/19 12:43:49.0601 57844 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/08/19 12:43:49.0702 57844 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/08/19 12:43:49.0772 57844 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/08/19 12:43:49.0838 57844 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/08/19 12:43:49.0970 57844 athr (2846f5ee802889d500fcf5cc48b28381) C:\Windows\system32\DRIVERS\athr.sys
2011/08/19 12:43:50.0575 57844 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys
2011/08/19 12:43:50.0721 57844 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/08/19 12:43:50.0858 57844 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/08/19 12:43:51.0000 57844 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
2011/08/19 12:43:51.0490 57844 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/08/19 12:43:51.0563 57844 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/08/19 12:43:51.0680 57844 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/08/19 12:43:51.0770 57844 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/08/19 12:43:51.0855 57844 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/08/19 12:43:51.0930 57844 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/08/19 12:43:52.0465 57844 BthEnum (cce53afc28347cc18ea139972e5b5e5a) C:\Windows\system32\DRIVERS\BthEnum.sys
2011/08/19 12:43:52.0907 57844 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/08/19 12:43:53.0029 57844 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
2011/08/19 12:43:53.0171 57844 BTHPORT (ac8a1689d5efc4d214201155a78d8f4b) C:\Windows\system32\Drivers\BTHport.sys
2011/08/19 12:43:53.0644 57844 BTHUSB (288c1f74e3e2eed6c7b54eb3aac70856) C:\Windows\system32\Drivers\BTHUSB.sys
2011/08/19 12:43:53.0969 57844 btnetBUs (7bb8ac22bc9e6a1e7707daecada95cd9) C:\Windows\system32\Drivers\btnetBus.sys
2011/08/19 12:43:54.0264 57844 CbFs (560c3ac812597d58626d6c92fdc7f58d) C:\Windows\system32\drivers\cbfs.sys
2011/08/19 12:43:54.0757 57844 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/08/19 12:43:54.0849 57844 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/08/19 12:43:54.0920 57844 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/08/19 12:43:55.0026 57844 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/08/19 12:43:55.0269 57844 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/08/19 12:43:55.0402 57844 cmderd (de82681c08eb3840913ed0338cbee0ba) C:\Windows\system32\DRIVERS\cmderd.sys
2011/08/19 12:43:55.0677 57844 cmdGuard (bbe32e04e88b0048ec16f1d6c8936c4b) C:\Windows\system32\DRIVERS\cmdguard.sys
2011/08/19 12:43:56.0275 57844 cmdHlp (497590ea7a94b98ea7a4516ebf0fb8d2) C:\Windows\system32\DRIVERS\cmdhlp.sys
2011/08/19 12:43:56.0575 57844 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/08/19 12:43:56.0677 57844 CnxtHdAudService (dda0cb141150fef87419926790cd26c8) C:\Windows\system32\drivers\CHDRT32.sys
2011/08/19 12:43:57.0220 57844 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/08/19 12:43:57.0302 57844 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/08/19 12:43:57.0402 57844 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/08/19 12:43:57.0591 57844 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
2011/08/19 12:43:57.0962 57844 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/08/19 12:43:58.0108 57844 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/08/19 12:43:58.0195 57844 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/08/19 12:43:58.0831 57844 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/08/19 12:43:59.0065 57844 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/08/19 12:43:59.0300 57844 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/08/19 12:43:59.0651 57844 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/08/19 12:43:59.0945 57844 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/08/19 12:44:00.0263 57844 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/08/19 12:44:00.0514 57844 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/08/19 12:44:00.0756 57844 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/08/19 12:44:00.0850 57844 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/08/19 12:44:00.0933 57844 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/08/19 12:44:01.0023 57844 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/08/19 12:44:01.0344 57844 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/08/19 12:44:01.0508 57844 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/08/19 12:44:01.0650 57844 ggflt (007aea2e06e7cef7372e40c277163959) C:\Windows\system32\DRIVERS\ggflt.sys
2011/08/19 12:44:02.0085 57844 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\Windows\system32\DRIVERS\ggsemc.sys
2011/08/19 12:44:02.0710 57844 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/08/19 12:44:02.0899 57844 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/08/19 12:44:03.0272 57844 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/08/19 12:44:03.0631 57844 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/08/19 12:44:03.0889 57844 HidUsb (e2b5bd48afcc0f0974fb44641b223250) C:\Windows\system32\DRIVERS\hidusb.sys
2011/08/19 12:44:04.0444 57844 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/08/19 12:44:04.0615 57844 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
2011/08/19 12:44:04.0762 57844 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
2011/08/19 12:44:04.0940 57844 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys
2011/08/19 12:44:05.0233 57844 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
2011/08/19 12:44:05.0476 57844 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/08/19 12:44:06.0348 57844 HWiNFO32 (a8631a5c888203d9ebef43a474d7613f) C:\Program Files\HWiNFO32\HWiNFO32.SYS
2011/08/19 12:44:06.0690 57844 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/08/19 12:44:07.0005 57844 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/08/19 12:44:07.0676 57844 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/08/19 12:44:08.0686 57844 igfx (dce0b53570703cce580d066f89ef58cd) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/08/19 12:44:11.0911 57844 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/08/19 12:44:12.0226 57844 inspect (1c65e930aba113f2ce59d32c7d8bc03f) C:\Windows\system32\DRIVERS\inspect.sys
2011/08/19 12:44:12.0547 57844 IntcHdmiAddService (ab8b0206bcdff0ed03cec500fa03a32a) C:\Windows\system32\drivers\IntcHdmi.sys
2011/08/19 12:44:12.0706 57844 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/08/19 12:44:12.0777 57844 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/08/19 12:44:12.0956 57844 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/08/19 12:44:13.0143 57844 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/08/19 12:44:13.0382 57844 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/08/19 12:44:13.0587 57844 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/08/19 12:44:13.0699 57844 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/08/19 12:44:13.0909 57844 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/08/19 12:44:14.0055 57844 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/08/19 12:44:14.0378 57844 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/08/19 12:44:14.0855 57844 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/08/19 12:44:15.0063 57844 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/08/19 12:44:15.0419 57844 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/08/19 12:44:15.0850 57844 LEqdUsb (0fe8fefe98626509661b50ea20ecd129) C:\Windows\system32\Drivers\LEqdUsb.Sys
2011/08/19 12:44:16.0912 57844 LHidEqd (93657522a5dd7da4c81fb347973ae01c) C:\Windows\system32\Drivers\LHidEqd.Sys
2011/08/19 12:44:17.0310 57844 LHidFilt (05d6b85ecc3204931923ab7940b9596e) C:\Windows\system32\DRIVERS\LHidFilt.Sys
2011/08/19 12:44:17.0666 57844 LMouFilt (053dbcc1082fdf74ab145a71917a6556) C:\Windows\system32\DRIVERS\LMouFilt.Sys
2011/08/19 12:44:18.0395 57844 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/08/19 12:44:18.0776 57844 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/08/19 12:44:19.0308 57844 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/08/19 12:44:20.0109 57844 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/08/19 12:44:20.0600 57844 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\Windows\system32\DRIVERS\mcdbus.sys
2011/08/19 12:44:21.0946 57844 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
2011/08/19 12:44:22.0402 57844 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/08/19 12:44:23.0417 57844 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/08/19 12:44:23.0804 57844 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/08/19 12:44:24.0094 57844 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/08/19 12:44:24.0719 57844 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/08/19 12:44:25.0184 57844 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/08/19 12:44:25.0574 57844 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/08/19 12:44:26.0121 57844 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/08/19 12:44:26.0604 57844 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/08/19 12:44:27.0309 57844 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/08/19 12:44:27.0702 57844 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/08/19 12:44:28.0193 57844 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/08/19 12:44:29.0748 57844 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/08/19 12:44:30.0857 57844 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/08/19 12:44:31.0658 57844 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys
2011/08/19 12:44:32.0146 57844 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/08/19 12:44:32.0612 57844 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/08/19 12:44:32.0950 57844 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/08/19 12:44:33.0456 57844 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/08/19 12:44:33.0945 57844 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/08/19 12:44:34.0250 57844 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/08/19 12:44:34.0499 57844 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/08/19 12:44:34.0740 57844 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/08/19 12:44:34.0919 57844 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/08/19 12:44:35.0089 57844 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/08/19 12:44:35.0900 57844 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/08/19 12:44:36.0321 57844 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/08/19 12:44:36.0432 57844 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/08/19 12:44:36.0551 57844 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/08/19 12:44:36.0612 57844 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/08/19 12:44:36.0741 57844 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/08/19 12:44:36.0983 57844 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/08/19 12:44:37.0091 57844 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/08/19 12:44:37.0394 57844 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/08/19 12:44:37.0515 57844 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/08/19 12:44:37.0647 57844 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/08/19 12:44:38.0039 57844 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/08/19 12:44:38.0360 57844 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/08/19 12:44:38.0515 57844 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/08/19 12:44:38.0697 57844 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys
2011/08/19 12:44:38.0809 57844 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/08/19 12:44:38.0870 57844 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/08/19 12:44:39.0027 57844 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/08/19 12:44:39.0287 57844 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys
2011/08/19 12:44:39.0487 57844 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/08/19 12:44:39.0615 57844 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/08/19 12:44:39.0720 57844 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/08/19 12:44:39.0908 57844 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/08/19 12:44:40.0384 57844 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/08/19 12:44:40.0619 57844 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
2011/08/19 12:44:40.0864 57844 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/08/19 12:44:41.0295 57844 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/08/19 12:44:41.0390 57844 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/08/19 12:44:41.0709 57844 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/08/19 12:44:41.0878 57844 PSI (d24dfd16a1e2a76034df5aa18125c35d) C:\Windows\system32\DRIVERS\psi_mf.sys
2011/08/19 12:44:42.0336 57844 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/08/19 12:44:42.0624 57844 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/08/19 12:44:43.0122 57844 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/08/19 12:44:43.0352 57844 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/08/19 12:44:43.0669 57844 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/08/19 12:44:44.0073 57844 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/08/19 12:44:44.0319 57844 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/08/19 12:44:44.0464 57844 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/08/19 12:44:44.0796 57844 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/08/19 12:44:45.0212 57844 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/08/19 12:44:45.0586 57844 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/08/19 12:44:45.0948 57844 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/08/19 12:44:47.0055 57844 RFCOMM (23f486726da7a9b2f3ec7326421a9c36) C:\Windows\system32\DRIVERS\rfcomm.sys
2011/08/19 12:44:47.0568 57844 RimUsb (f17713d108aca124a139fde877eef68a) C:\Windows\system32\Drivers\RimUsb.sys
2011/08/19 12:44:47.0897 57844 RTL8169 (06992132cf20c3c1cba3f072c4086de8) C:\Windows\system32\DRIVERS\Rtlh86.sys
2011/08/19 12:44:48.0489 57844 RTSTOR (08c3394391ab0aff65d75ae65d4207e1) C:\Windows\system32\drivers\RTSTOR.SYS
2011/08/19 12:44:48.0862 57844 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/08/19 12:44:49.0246 57844 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/08/19 12:44:49.0628 57844 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/08/19 12:44:50.0073 57844 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/08/19 12:44:50.0380 57844 seehcri (e5b56569a9f79b70314fede6c953641e) C:\Windows\system32\DRIVERS\seehcri.sys
2011/08/19 12:44:50.0854 57844 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/08/19 12:44:51.0085 57844 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/08/19 12:44:51.0246 57844 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/08/19 12:44:51.0498 57844 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/08/19 12:44:51.0705 57844 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/08/19 12:44:51.0892 57844 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/08/19 12:44:52.0064 57844 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/08/19 12:44:52.0491 57844 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/08/19 12:44:52.0708 57844 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/08/19 12:44:52.0987 57844 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/08/19 12:44:53.0411 57844 SmartDefragDriver (cc48f88fe17bb8e5eb6fa1a8a9477006) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2011/08/19 12:44:53.0639 57844 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/08/19 12:44:53.0867 57844 snapman (98b44c15b4eed76aa8dccb64a4ca11af) C:\Windows\system32\DRIVERS\snapman.sys
2011/08/19 12:44:56.0540 57844 Soluto (ff35c2d01ac36b446a1b997f305f0fc2) C:\Windows\system32\DRIVERS\Soluto.sys
2011/08/19 12:44:57.0046 57844 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/08/19 12:44:57.0237 57844 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
2011/08/19 12:44:57.0825 57844 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
2011/08/19 12:44:58.0266 57844 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
2011/08/19 12:44:58.0752 57844 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/08/19 12:44:58.0944 57844 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/08/19 12:44:59.0020 57844 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/08/19 12:44:59.0082 57844 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/08/19 12:44:59.0482 57844 SynTP (00b19f27858f56181edb58b71a7c67a0) C:\Windows\system32\DRIVERS\SynTP.sys
2011/08/19 12:44:59.0983 57844 tap0901 (1e89de7a4fb7a854ebb241d0aa8996dd) C:\Windows\system32\DRIVERS\tap0901.sys
2011/08/19 12:45:00.0469 57844 Tcpip (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\drivers\tcpip.sys
2011/08/19 12:45:01.0039 57844 Tcpip6 (6647fce6fc4970daafe5c64c794513d3) C:\Windows\system32\DRIVERS\tcpip.sys
2011/08/19 12:45:01.0197 57844 tcpipreg (36606b165d04a397bdf613096986d85d) C:\Windows\system32\drivers\tcpipreg.sys
2011/08/19 12:45:01.0406 57844 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/08/19 12:45:01.0499 57844 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/08/19 12:45:01.0776 57844 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/08/19 12:45:01.0974 57844 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/08/19 12:45:02.0238 57844 timounter (d8a96d0e25d43fdac3bed09adf39fde9) C:\Windows\system32\DRIVERS\timntr.sys
2011/08/19 12:45:02.0708 57844 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/08/19 12:45:02.0946 57844 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys
2011/08/19 12:45:03.0205 57844 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/08/19 12:45:03.0373 57844 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys
2011/08/19 12:45:03.0439 57844 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/08/19 12:45:03.0537 57844 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/08/19 12:45:03.0750 57844 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/08/19 12:45:03.0855 57844 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/08/19 12:45:03.0972 57844 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/08/19 12:45:04.0062 57844 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/08/19 12:45:04.0310 57844 UltraMonUtility (5a5bd0f66e84eb039cb227520d49908c) C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys
2011/08/19 12:45:04.0746 57844 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/08/19 12:45:04.0965 57844 UMPass (88bd96a1baeed33ee8bdf9499c07a841) C:\Windows\system32\DRIVERS\umpass.sys
2011/08/19 12:45:05.0177 57844 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/08/19 12:45:05.0329 57844 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/08/19 12:45:05.0438 57844 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/08/19 12:45:05.0811 57844 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/08/19 12:45:06.0266 57844 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys
2011/08/19 12:45:06.0624 57844 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/08/19 12:45:06.0939 57844 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/08/19 12:45:07.0260 57844 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/08/19 12:45:07.0494 57844 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/08/19 12:45:07.0740 57844 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/08/19 12:45:07.0995 57844 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/08/19 12:45:08.0530 57844 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/08/19 12:45:08.0676 57844 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/08/19 12:45:08.0759 57844 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/08/19 12:45:09.0011 57844 vididr (149ec3e217f9d11e9ca6c54ce3d70c73) C:\Windows\system32\DRIVERS\vididr.sys
2011/08/19 12:45:09.0708 57844 vidsflt53 (e31e9cd40677b84b3adaa7a0d80dc439) C:\Windows\system32\DRIVERS\vsflt53.sys
2011/08/19 12:45:10.0182 57844 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/08/19 12:45:10.0479 57844 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/08/19 12:45:10.0992 57844 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/08/19 12:45:11.0826 57844 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/08/19 12:45:12.0249 57844 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/08/19 12:45:12.0550 57844 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/19 12:45:12.0728 57844 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/08/19 12:45:13.0538 57844 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/08/19 12:45:14.0749 57844 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/08/19 12:45:15.0311 57844 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
2011/08/19 12:45:16.0307 57844 WinUSB (676f4b665bdd8053eaa53ac1695b8074) C:\Windows\system32\DRIVERS\WinUSB.sys
2011/08/19 12:45:17.0104 57844 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/08/19 12:45:18.0397 57844 WRkrn (3c8e702b967119770e3e57fcf678bcfb) C:\Windows\system32\drivers\WRkrn.sys
2011/08/19 12:45:18.0828 57844 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/08/19 12:45:19.0814 57844 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/08/19 12:45:20.0569 57844 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
2011/08/19 12:45:20.0952 57844 ZTEusbmdm6k (2a6f72d2b6a549b1fc6a6522bc204159) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
2011/08/19 12:45:21.0374 57844 ZTEusbnet (453a60f8dc22fc296bc482cbf3eff213) C:\Windows\system32\DRIVERS\ZTEusbnet.sys
2011/08/19 12:45:21.0972 57844 ZTEusbnmea (2a6f72d2b6a549b1fc6a6522bc204159) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
2011/08/19 12:45:22.0370 57844 ZTEusbser6k (2a6f72d2b6a549b1fc6a6522bc204159) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
2011/08/19 12:45:22.0719 57844 ZTEusbvoice (2a6f72d2b6a549b1fc6a6522bc204159) C:\Windows\system32\DRIVERS\ZTEusbvoice.sys
2011/08/19 12:45:23.0457 57844 MBR (0x1B8) (85d751f0e41b8e520aee8c07a8da777b) \Device\Harddisk0\DR0
2011/08/19 12:45:23.0741 57844 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk2\DR2
2011/08/19 12:45:23.0949 57844 Boot (0x1200) (c9381cd32913c202d48c69daf1a403ff) \Device\Harddisk0\DR0\Partition0
2011/08/19 12:45:23.0973 57844 Boot (0x1200) (4224632c6dcfd067e4fba4c37c43e6a6) \Device\Harddisk0\DR0\Partition1
2011/08/19 12:45:24.0001 57844 Boot (0x1200) (881eba253013f2eec390ae07973058f4) \Device\Harddisk2\DR2\Partition0
2011/08/19 12:45:24.0020 57844 ================================================================================
2011/08/19 12:45:24.0020 57844 Scan finished
2011/08/19 12:45:24.0020 57844 ================================================================================
2011/08/19 12:45:24.0099 57832 Detected object count: 0
2011/08/19 12:45:24.0099 57832 Actual detected object count: 0
2011/08/19 12:45:31.0666 56880 Deinitialize success
combofix ran fine, no reboot ...log follows
ComboFix 11-08-18.03 - jhg 19/08/2011 13:02:15.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3002.2065 [GMT 1:00]
Running from: c:\users\jhg\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51}
FW: COMODO Firewall *Disabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
SP: COMODO Defense+ *Disabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jhg\AppData\Roaming\5ED2.EFE
c:\windows\system32\shsvcs.dll.vgorg
c:\windows\system32\themeui.dll.vgorg
c:\windows\system32\uxtheme.dll.vgorg
F:\autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-07-19 to 2011-08-19 )))))))))))))))))))))))))))))))
.
.
2011-08-19 12:14 . 2011-08-19 12:14 -------- dc----w- c:\users\Default\AppData\Local\temp
2011-08-19 11:28 . 2011-08-19 11:28 -------- dc----w- c:\program files\HWiNFO32
2011-08-19 11:08 . 2011-08-15 11:13 21312 -c--a-w- c:\windows\system32\authuitu.dll
2011-08-19 11:08 . 2011-08-15 11:13 29504 -c--a-w- c:\windows\system32\uxtuneup.dll
2011-08-18 13:34 . 2011-08-18 13:34 -------- dc----w- c:\users\jhg\AppData\Local\IsolatedStorage
2011-08-15 16:30 . 2011-08-15 16:32 -------- dc----w- c:\users\jhg\AppData\Roaming\Delicious IE Extension
2011-08-15 16:28 . 2011-08-15 16:34 -------- dc----w- c:\program files\Delicious Add-on for Internet Explorer
2011-08-11 15:29 . 2011-07-21 10:33 51144 -c--a-w- c:\windows\system32\drivers\Soluto.sys
2011-08-11 11:17 . 2011-08-11 11:17 2106216 -c--a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-08-11 11:17 . 2011-08-11 11:17 1998168 -c--a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-08-11 10:03 . 2011-08-11 10:03 -------- d-----w- C:\CPQSYSTEM
2011-08-11 09:34 . 2011-08-11 09:34 601408 -c--a-w- c:\windows\system32\drivers\timntr.sys
2011-08-11 09:32 . 2011-08-11 09:32 125472 -c--a-w- c:\windows\system32\drivers\vididr.sys
2011-08-11 09:31 . 2011-08-11 09:31 83392 -c--a-w- c:\windows\system32\drivers\vsflt53.sys
2011-08-11 09:31 . 2011-08-11 09:31 169088 -c--a-w- c:\windows\system32\drivers\snapman.sys
2011-08-11 09:10 . 2011-08-11 09:10 -------- d-----w- C:\VritualRoot
2011-08-11 07:32 . 2011-08-17 09:57 134104 -c--a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-08-11 07:32 . 2011-08-17 09:57 89048 -c--a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-08-11 07:32 . 2011-08-17 09:57 478168 -c--a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-08-11 07:32 . 2011-08-17 09:57 1846232 -c--a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-08-11 07:32 . 2011-08-17 09:57 15832 -c--a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-08-11 07:32 . 2011-08-17 09:57 785368 -c--a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-08-10 17:27 . 2011-06-17 16:03 375808 -c--a-w- c:\windows\system32\winsrv.dll
2011-08-10 17:27 . 2011-07-06 15:31 214016 -c--a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 17:26 . 2011-06-06 10:59 2409784 -c--a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 17:24 . 2011-06-20 08:54 3602832 -c--a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-10 17:24 . 2011-06-20 08:54 3550096 -c--a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 17:24 . 2011-06-17 20:13 913296 -c--a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-10 17:24 . 2011-06-17 13:31 31232 -c--a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-08-09 17:45 . 2011-08-09 17:45 -------- dc----w- c:\program files\ESET
2011-08-09 08:15 . 2011-08-09 08:15 -------- dc----w- c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-08-08 17:21 . 2011-08-08 17:21 -------- dc----w- c:\program files\Acronis
2011-08-08 17:21 . 2011-08-11 09:30 -------- dc----w- c:\program files\Common Files\Acronis
2011-08-08 17:15 . 2011-08-08 17:15 -------- dc----w- c:\program files\Western Digital Corporation
2011-08-07 15:10 . 2008-01-21 02:24 6144 -c--a-w- c:\windows\system32\csrss - Copy.exe
2011-08-07 12:16 . 2011-08-07 12:34 -------- dc----w- c:\programdata\MFAData
2011-08-05 13:55 . 2011-02-23 15:52 16184 -c--a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-08-05 13:55 . 2011-02-23 15:52 29520 -c--a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-08-04 17:07 . 2011-08-04 17:34 -------- dc----w- c:\users\jhg\AppData\Roaming\Systweak
2011-08-04 17:07 . 2011-07-07 12:26 17280 -c--a-w- c:\windows\system32\roboot.exe
2011-08-04 13:21 . 2011-08-04 13:21 -------- dc----w- c:\users\jhg\AppData\Roaming\SUPERAntiSpyware.com
2011-08-04 13:20 . 2011-08-04 13:20 -------- dc----w- c:\programdata\!SASCORE
2011-08-04 13:20 . 2011-08-11 15:09 -------- dc----w- c:\program files\SUPERAntiSpyware
2011-08-03 09:45 . 2011-08-03 09:45 118112 -c--a-w- c:\windows\system32\WRusr.dll
2011-08-03 09:45 . 2011-08-03 09:45 103752 -c--a-w- c:\windows\system32\drivers\WRkrn.sys
2011-08-03 09:45 . 2011-08-07 09:04 -------- dc----w- c:\programdata\WRData
2011-08-02 16:11 . 2011-08-19 12:15 -------- dc----w- c:\users\jhg\AppData\Local\temp
2011-07-29 11:30 . 2011-07-29 11:30 -------- dc----w- c:\program files\Bonjour
2011-07-27 13:38 . 2011-07-20 08:35 29504 -c--a-w- c:\windows\system32\uxt3F82.tmp
2011-07-26 12:36 . 2008-01-30 15:36 90112 -c--a-w- c:\windows\unvise32.exe
2011-07-25 16:22 . 2011-07-25 16:22 -------- d-----w- C:\For Sync
2011-07-25 08:08 . 2011-08-07 08:48 -------- dc----w- c:\programdata\Immunet
2011-07-25 08:08 . 2011-07-25 08:11 -------- dc----w- c:\users\jhg\AppData\Local\Immunet
2011-07-21 07:47 . 2011-07-21 07:47 53248 -c--a-r- c:\users\jhg\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-07-21 07:47 . 2011-07-21 07:47 -------- dc----w- c:\users\jhg\AppData\Local\Logishrd
2011-07-21 07:45 . 2011-07-21 07:45 -------- dc----w- c:\program files\Logitech
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-15 11:19 . 2010-12-01 12:06 31552 -c--a-w- c:\windows\system32\TURegOpt.exe
2011-08-13 17:34 . 2011-06-12 06:30 404640 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-07 13:08 . 2010-12-02 09:43 21064 -c--a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-07-21 07:46 . 2011-01-05 14:12 16400 -c--a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-07-06 18:52 . 2010-12-02 11:59 41272 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 18:52 . 2010-12-02 11:59 22712 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-06-30 08:37 . 2010-09-10 23:40 82400 -c--a-w- c:\windows\system32\drivers\inspect.sys
2011-06-30 08:37 . 2010-09-10 23:40 36568 -c--a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-06-30 08:37 . 2010-09-10 23:40 238960 -c--a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-06-30 08:37 . 2010-09-10 23:40 19088 -c--a-w- c:\windows\system32\drivers\cmderd.sys
2011-06-30 08:37 . 2010-09-10 23:41 285256 -c--a-w- c:\windows\system32\guard32.dll
2011-06-02 13:34 . 2011-07-13 08:19 2043392 -c--a-w- c:\windows\system32\win32k.sys
2011-05-24 18:14 . 2010-11-30 22:27 222080 -c----w- c:\windows\system32\MpSigStub.exe
2011-08-11 07:19 . 2011-08-11 07:21 1650688 -c--a-w- c:\program files\opera\program\plugins\rf-np-plugin.dll
2011-08-17 09:57 . 2011-08-11 07:32 134104 -c--a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-08-10 17:36 . 2010-12-04 16:14 119808 -c--a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter]
@="{D25B32FE-CB96-491A-98FF-AD59DA382D69}"
[HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}]
2010-07-30 00:19 754176 -c--a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter]
@="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}"
[HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}]
2010-07-30 00:19 754176 -c--a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter]
@="{B3C78E40-6B64-47C3-AE34-60B770881EB8}"
[HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}]
2010-07-30 00:19 754176 -c--a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter]
@="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}"
[HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}]
2010-07-30 00:19 754176 -c--a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04Zecter]
@="{855156F0-2A0F-11DE-8C30-0800200C9A66}"
[HKEY_CLASSES_ROOT\CLSID\{855156F0-2A0F-11DE-8C30-0800200C9A66}]
2010-07-30 00:19 754176 -c--a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-05-28 01:03 94208 -c--a-w- c:\users\jhg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-05-28 01:03 94208 -c--a-w- c:\users\jhg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-05-28 01:03 94208 -c--a-w- c:\users\jhg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-05-28 01:03 94208 -c--a-w- c:\users\jhg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MzCpuAccelerator"="c:\program files\Mz Ultimate Tools\Mz CPU Accelerator\MzCPUAccelerator.exe" [2010-12-18 272384]
"Glary Memory Optimizer"="c:\program files\Glary Utilities\memdefrag.exe" [2011-07-01 108344]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-08-11 107000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Task Catcher"="c:\program files\BillP Studios\Task Catcher\tasktrap.exe" [2006-08-15 140856]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-06-30 2554696]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1386776]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-05-12 202032]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2010-03-08 468264]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-06-22 2637824]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-06-22 395392]
.
c:\users\jhg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\jhg\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
UltraMon.exe - Shortcut.lnk - c:\program files\UltraMon\UltraMon.exe [2010-12-20 505856]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{537056B7-32A4-4408-9B54-0341963C7C9C}\IcoUltraMon.ico [2011-3-29 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 -c--a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^jhg^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk.disabled]
backup=c:\windows\pss\Dropbox.lnk.disabled.Startup
backupExtension=.Startup
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter
"EPSON Stylus D78 Series"=c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIBGE.EXE /FU "c:\windows\TEMP\E_SF8D6.tmp" /EF "HKCU"
"TrayFactory"=c:\program files\PS Tray Factory\PSTrayFactory.exe /start
"Google Update"="c:\users\jhg\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"3C3E8D0B2FACD61E9B91857039AFD1A949EF5FD3._service_run"="c:\users\jhg\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"MobileBroadband"=c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MobileBroadband"=c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
"Reader Library Launcher"=c:\program files\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-766714266-3305230590-1689769915-1000]
"EnableNotificationsRef"=dword:00000001
.
R0 BtHidBus;Bluetooth HID Bus Service; [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe [2011-07-21 392224]
R3 BTCOM;Bluetooth Serial port driver; [x]
R3 BTCOMBUS;Bluetooth Serial Port Bus Service; [x]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2010-04-06 25864]
R3 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-12-15 13224]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2011-08-10 30192]
R3 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-28 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-28 136176]
R3 IvtBtBUs;IVT Bluetooth Bus Service; [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [x]
R3 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
R3 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-04-28 9216]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2010-03-25 114688]
R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2010-04-19 105856]
R4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-07-19 123264]
R4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-24 406016]
R4 SDFirewallService;Spybot-S&D 2 Firewall Service;c:\program files\Spybot - Search & Destroy 2\SDFWSvc.exe [2011-05-10 3585696]
R4 SDMonitorService;Spybot-S&D 2 Monitoring Service;c:\program files\Spybot - Search & Destroy 2\SDMonSvc.exe [2011-05-10 3834456]
R4 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [2011-05-10 3515656]
R4 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2011-05-10 3769048]
R4 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2011-05-11 167040]
R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-04-19 993848]
R4 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2010-10-26 155344]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys [2011-07-21 51144]
S0 vididr;Acronis Virtual Disk;c:\windows\system32\DRIVERS\vididr.sys [2011-08-11 125472]
S0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\DRIVERS\vsflt53.sys [2011-08-11 83392]
S0 WRkrn;WRkrn;c:\windows\System32\drivers\WRkrn.sys [2011-08-03 103752]
S1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2010-12-18 147416]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2011-06-30 19088]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-06-30 238960]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-06-30 36568]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [2011-05-22 20216]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S2 sesvc;ShadowExplorer Service;c:\program files\ShadowExplorer\sesvc.exe [2011-01-02 9216]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-08-15 1526080]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2008-11-14 17184]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-04 113664]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2011-04-30 42648]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2011-04-30 12184]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-12-15 27632]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-07 10064]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 43254714
*NewlyCreated* - HWINFO32
*Deregistered* - 43254714
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
netsvcs_Untrusted_BZ REG_MULTI_SZ winmgmt_Untrusted_BZ
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 22:06 451872 -c----w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-18 c:\windows\Tasks\Defrag Job 00.job
- c:\program files\Disktrix\UltimateDefrag\Udefrag.exe [2010-08-17 12:58]
.
2011-08-19 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-12-01 07:26]
.
2011-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-28 16:48]
.
2011-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-28 16:48]
.
2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-766714266-3305230590-1689769915-1000Core.job
- c:\users\jhg\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-30 22:07]
.
2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-766714266-3305230590-1689769915-1000UA.job
- c:\users\jhg\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-30 22:07]
.
2011-04-13 c:\windows\Tasks\User_Feed_Synchronization-{BB661F4E-7BF2-41C3-AD6D-069E375F4996}.job
- c:\windows\system32\msfeedssync.exe [2011-08-10 09:26]
.
2011-08-12 c:\windows\Tasks\WebUpdate.job
- c:\program files\Smart PC Utilities\Vista Services Optimizer\WebUpdate.exe [2010-07-04 17:03]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://www.arithmosolutions.co.uk/app/messages-inbox.asp
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:49434
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: LastPass - file://c:\program files\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\program files\LastPass\context.html?cmd=fillforms
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
TCP: DhcpNameServer = 192.168.145.8
TCP: Interfaces\{4D7DD770-0ABF-45B9-8922-0D3A8EB58CF9}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{FE69ADA2-9CFA-4410-A446-22DB54DD89D3}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\jhg\AppData\Roaming\Mozilla\Firefox\Profiles\smzl27v5.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.mg1.mail.yahoo.com/dc/launch?.gx=1&.rand=9juh0rmbk4k95
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autoFill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 600000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-19 13:15
Windows 6.0.6002 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1036)
c:\windows\SYSTEM32\GUARD32.DLL
.
- - - - - - - > 'lsass.exe'(916)
c:\windows\SYSTEM32\GUARD32.DLL
.
Completion time: 2011-08-19 13:19:27
ComboFix-quarantined-files.txt 2011-08-19 12:19
ComboFix2.txt 2011-08-02 16:11
ComboFix3.txt 2011-08-02 11:52
.
Pre-Run: 121,084,637,184 bytes free
Post-Run: 121,297,805,312 bytes free
.
- - End Of File - - 19006919928FFF552FBE25A949B837EA
....what do you think??
I have said it before but your expert opinion is HIGHLY valued
many thanks
jeremy