Thanks Cat. I did as requested and here are the log files. Both programs found rootkits.
23:09:52.0125 2776 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
23:09:52.0296 2776 ============================================================
23:09:52.0296 2776 Current date / time: 2011/12/05 23:09:52.0296
23:09:52.0296 2776 SystemInfo:
23:09:52.0296 2776
23:09:52.0296 2776 OS Version: 5.1.2600 ServicePack: 3.0
23:09:52.0296 2776 Product type: Workstation
23:09:52.0296 2776 ComputerName: DDQ6FT61
23:09:52.0296 2776 UserName: The Haymakers
23:09:52.0296 2776 Windows directory: C:\WINDOWS
23:09:52.0296 2776 System windows directory: C:\WINDOWS
23:09:52.0296 2776 Processor architecture: Intel x86
23:09:52.0296 2776 Number of processors: 2
23:09:52.0296 2776 Page size: 0x1000
23:09:52.0296 2776 Boot type: Normal boot
23:09:52.0296 2776 ============================================================
23:09:54.0046 2776 Initialize success
23:09:56.0375 3872 ============================================================
23:09:56.0375 3872 Scan started
23:09:56.0375 3872 Mode: Manual;
23:09:56.0375 3872 ============================================================
23:09:57.0546 3872 A3AB (886a8a267b39bf510ddd1838fda9756e) C:\WINDOWS\system32\DRIVERS\A3AB.sys
23:09:57.0562 3872 A3AB - ok
23:09:57.0562 3872 Abiosdsk - ok
23:09:57.0640 3872 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
23:09:57.0640 3872 abp480n5 - ok
23:09:57.0687 3872 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:09:57.0687 3872 ACPI - ok
23:09:57.0718 3872 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:09:57.0718 3872 ACPIEC - ok
23:09:57.0843 3872 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
23:09:57.0843 3872 adpu160m - ok
23:09:57.0859 3872 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
23:09:57.0890 3872 aeaudio - ok
23:09:57.0921 3872 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
23:09:57.0921 3872 aec - ok
23:09:57.0968 3872 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
23:09:57.0984 3872 AFD - ok
23:09:58.0015 3872 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
23:09:58.0015 3872 agp440 - ok
23:09:58.0093 3872 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
23:09:58.0093 3872 agpCPQ - ok
23:09:58.0140 3872 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
23:09:58.0140 3872 Aha154x - ok
23:09:58.0187 3872 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
23:09:58.0187 3872 aic78u2 - ok
23:09:58.0234 3872 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
23:09:58.0234 3872 aic78xx - ok
23:09:58.0265 3872 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
23:09:58.0265 3872 AliIde - ok
23:09:58.0281 3872 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
23:09:58.0281 3872 alim1541 - ok
23:09:58.0296 3872 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
23:09:58.0296 3872 amdagp - ok
23:09:58.0296 3872 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
23:09:58.0312 3872 amsint - ok
23:09:58.0343 3872 ANIO (920298c7aef97d8168d219d35975d295) C:\WINDOWS\system32\ANIO.SYS
23:09:58.0390 3872 ANIO - ok
23:09:58.0437 3872 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
23:09:58.0437 3872 asc - ok
23:09:58.0453 3872 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
23:09:58.0453 3872 asc3350p - ok
23:09:58.0468 3872 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
23:09:58.0484 3872 asc3550 - ok
23:09:58.0531 3872 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:09:58.0546 3872 AsyncMac - ok
23:09:58.0562 3872 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:09:58.0562 3872 atapi - ok
23:09:58.0578 3872 Atdisk - ok
23:09:58.0609 3872 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:09:58.0609 3872 Atmarpc - ok
23:09:58.0671 3872 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:09:58.0671 3872 audstub - ok
23:09:58.0687 3872 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:09:58.0687 3872 Beep - ok
23:09:58.0703 3872 BLKWGU(Belkin) - ok
23:09:58.0718 3872 bvrp_pci - ok
23:09:58.0890 3872 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
23:09:58.0953 3872 cbidf - ok
23:09:59.0125 3872 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:09:59.0125 3872 cbidf2k - ok
23:09:59.0218 3872 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
23:09:59.0218 3872 CCDECODE - ok
23:09:59.0281 3872 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
23:09:59.0281 3872 cd20xrnt - ok
23:09:59.0296 3872 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:09:59.0296 3872 Cdaudio - ok
23:09:59.0343 3872 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
23:09:59.0343 3872 Cdfs - ok
23:09:59.0375 3872 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:09:59.0375 3872 Cdrom - ok
23:09:59.0421 3872 Changer - ok
23:09:59.0453 3872 CLBStor (cc82215750723d839dbc5d2d625fc130) C:\WINDOWS\system32\drivers\CLBStor.sys
23:09:59.0500 3872 CLBStor - ok
23:09:59.0562 3872 CLBUDFR (c002f79e6ee9bdf442514435c3d2bcb6) C:\WINDOWS\system32\drivers\CLBUDFR.sys
23:09:59.0609 3872 CLBUDFR - ok
23:09:59.0625 3872 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
23:09:59.0625 3872 CmdIde - ok
23:09:59.0687 3872 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
23:09:59.0687 3872 Cpqarray - ok
23:09:59.0734 3872 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
23:09:59.0734 3872 dac2w2k - ok
23:09:59.0750 3872 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
23:09:59.0750 3872 dac960nt - ok
23:09:59.0765 3872 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
23:09:59.0781 3872 Disk - ok
23:09:59.0843 3872 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
23:09:59.0859 3872 dmboot - ok
23:09:59.0953 3872 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
23:09:59.0953 3872 dmio - ok
23:10:00.0046 3872 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:10:00.0046 3872 dmload - ok
23:10:00.0093 3872 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
23:10:00.0093 3872 DMusic - ok
23:10:00.0125 3872 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
23:10:00.0125 3872 dpti2o - ok
23:10:00.0171 3872 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
23:10:00.0171 3872 drmkaud - ok
23:10:00.0265 3872 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
23:10:00.0328 3872 drvmcdb - ok
23:10:00.0453 3872 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
23:10:00.0500 3872 drvnddm - ok
23:10:00.0625 3872 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
23:10:00.0671 3872 DSproct - ok
23:10:00.0765 3872 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
23:10:00.0765 3872 dsunidrv - ok
23:10:00.0812 3872 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
23:10:00.0828 3872 E100B - ok
23:10:00.0875 3872 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
23:10:00.0875 3872 Fastfat - ok
23:10:00.0921 3872 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:10:00.0921 3872 Fdc - ok
23:10:00.0937 3872 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
23:10:00.0953 3872 Fips - ok
23:10:01.0031 3872 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:10:01.0031 3872 Flpydisk - ok
23:10:01.0046 3872 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
23:10:01.0046 3872 FltMgr - ok
23:10:01.0109 3872 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:10:01.0109 3872 Fs_Rec - ok
23:10:01.0156 3872 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:10:01.0171 3872 Ftdisk - ok
23:10:01.0187 3872 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
23:10:01.0250 3872 GEARAspiWDM - ok
23:10:01.0281 3872 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:10:01.0281 3872 Gpc - ok
23:10:01.0375 3872 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:10:01.0375 3872 HidUsb - ok
23:10:01.0453 3872 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
23:10:01.0453 3872 hpn - ok
23:10:01.0484 3872 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
23:10:01.0531 3872 HSFHWBS2 - ok
23:10:01.0578 3872 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
23:10:01.0625 3872 HSF_DP - ok
23:10:01.0671 3872 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
23:10:01.0671 3872 HTTP - ok
23:10:01.0765 3872 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
23:10:01.0765 3872 i2omgmt - ok
23:10:01.0859 3872 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
23:10:01.0859 3872 i2omp - ok
23:10:01.0906 3872 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:10:01.0906 3872 i8042prt - ok
23:10:02.0000 3872 ialm (5a8e05f1d5c36abd58cffa111eb325ea) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23:10:02.0078 3872 ialm - ok
23:10:02.0171 3872 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:10:02.0171 3872 Imapi - ok
23:10:02.0250 3872 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
23:10:02.0250 3872 ini910u - ok
23:10:02.0265 3872 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
23:10:02.0265 3872 IntelIde - ok
23:10:02.0281 3872 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:10:02.0281 3872 intelppm - ok
23:10:02.0328 3872 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
23:10:02.0328 3872 Ip6Fw - ok
23:10:02.0343 3872 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:10:02.0343 3872 IpFilterDriver - ok
23:10:02.0421 3872 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:10:02.0421 3872 IpInIp - ok
23:10:02.0468 3872 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:10:02.0468 3872 IpNat - ok
23:10:02.0484 3872 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:10:02.0500 3872 IPSec - ok
23:10:02.0531 3872 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:10:02.0546 3872 IRENUM - ok
23:10:02.0593 3872 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:10:02.0593 3872 isapnp - ok
23:10:02.0609 3872 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:10:02.0609 3872 Kbdclass - ok
23:10:02.0687 3872 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
23:10:02.0687 3872 kmixer - ok
23:10:02.0750 3872 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
23:10:02.0765 3872 KSecDD - ok
23:10:02.0812 3872 L8042Kbd (5a11400ea1f0a106fe7edb28c270f7b8) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
23:10:02.0859 3872 L8042Kbd - ok
23:10:02.0906 3872 L8042mou (20c919b52897b72ebcb2ad2fc29d8ef0) C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
23:10:02.0953 3872 L8042mou - ok
23:10:02.0968 3872 lbrtfdc - ok
23:10:03.0015 3872 LMouKE (90a794d0a0bf3531c4ba1c0510449629) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
23:10:03.0078 3872 LMouKE - ok
23:10:03.0109 3872 MASPINT (a2ae666cee860babe7fa6f1662b71737) C:\WINDOWS\system32\drivers\MASPINT.sys
23:10:03.0156 3872 MASPINT - ok
23:10:03.0234 3872 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys
23:10:03.0312 3872 MBAMProtector - ok
23:10:03.0359 3872 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
23:10:03.0421 3872 mdmxsdk - ok
23:10:03.0484 3872 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:10:03.0484 3872 mnmdd - ok
23:10:03.0531 3872 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
23:10:03.0531 3872 Modem - ok
23:10:03.0546 3872 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
23:10:03.0546 3872 MODEMCSA - ok
23:10:03.0593 3872 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:10:03.0593 3872 Mouclass - ok
23:10:03.0609 3872 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
23:10:03.0609 3872 MountMgr - ok
23:10:03.0656 3872 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
23:10:03.0656 3872 mraid35x - ok
23:10:03.0703 3872 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:10:03.0703 3872 MRxDAV - ok
23:10:03.0765 3872 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:10:03.0765 3872 MRxSmb - ok
23:10:03.0828 3872 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
23:10:03.0828 3872 Msfs - ok
23:10:03.0875 3872 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:10:03.0875 3872 MSKSSRV - ok
23:10:03.0890 3872 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:10:03.0890 3872 MSPCLOCK - ok
23:10:03.0937 3872 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
23:10:03.0937 3872 MSPQM - ok
23:10:03.0984 3872 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:10:04.0000 3872 mssmbios - ok
23:10:04.0046 3872 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
23:10:04.0046 3872 MSTEE - ok
23:10:04.0093 3872 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
23:10:04.0109 3872 Mup - ok
23:10:04.0156 3872 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
23:10:04.0156 3872 NABTSFEC - ok
23:10:04.0203 3872 NaiAvFilter1 (93941b922810f9dfa68dfffc6ad67a77) C:\WINDOWS\system32\drivers\naiavf5x.sys
23:10:04.0234 3872 NaiAvFilter1 - ok
23:10:04.0343 3872 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
23:10:04.0343 3872 NDIS - ok
23:10:04.0390 3872 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
23:10:04.0390 3872 NdisIP - ok
23:10:04.0453 3872 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:10:04.0453 3872 NdisTapi - ok
23:10:04.0453 3872 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:10:04.0468 3872 Ndisuio - ok
23:10:04.0484 3872 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:10:04.0484 3872 NdisWan - ok
23:10:04.0546 3872 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
23:10:04.0546 3872 NDProxy - ok
23:10:04.0609 3872 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:10:04.0609 3872 NetBIOS - ok
23:10:04.0640 3872 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:10:04.0640 3872 NetBT - ok
23:10:04.0734 3872 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
23:10:04.0734 3872 Npfs - ok
23:10:04.0812 3872 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
23:10:04.0828 3872 Ntfs - ok
23:10:04.0875 3872 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:10:04.0875 3872 Null - ok
23:10:04.0968 3872 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
23:10:05.0000 3872 nv - ok
23:10:05.0171 3872 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:10:05.0171 3872 NwlnkFlt - ok
23:10:05.0203 3872 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:10:05.0203 3872 NwlnkFwd - ok
23:10:05.0265 3872 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
23:10:05.0296 3872 omci - ok
23:10:05.0312 3872 PalmUSBD - ok
23:10:05.0359 3872 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
23:10:05.0359 3872 Parport - ok
23:10:05.0406 3872 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
23:10:05.0406 3872 PartMgr - ok
23:10:05.0453 3872 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
23:10:05.0453 3872 ParVdm - ok
23:10:05.0500 3872 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
23:10:05.0500 3872 PCI - ok
23:10:05.0531 3872 PCIDump - ok
23:10:05.0546 3872 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
23:10:05.0546 3872 PCIIde - ok
23:10:05.0593 3872 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:10:05.0593 3872 Pcmcia - ok
23:10:05.0703 3872 PDCOMP - ok
23:10:05.0718 3872 PDFRAME - ok
23:10:05.0718 3872 PDRELI - ok
23:10:05.0734 3872 PDRFRAME - ok
23:10:05.0781 3872 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
23:10:05.0781 3872 perc2 - ok
23:10:05.0796 3872 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
23:10:05.0796 3872 perc2hib - ok
23:10:05.0875 3872 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:10:05.0875 3872 PptpMiniport - ok
23:10:05.0906 3872 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
23:10:05.0906 3872 PSched - ok
23:10:05.0921 3872 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:10:05.0921 3872 Ptilink - ok
23:10:05.0953 3872 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
23:10:06.0000 3872 PxHelp20 - ok
23:10:06.0046 3872 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
23:10:06.0062 3872 ql1080 - ok
23:10:06.0093 3872 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
23:10:06.0109 3872 Ql10wnt - ok
23:10:06.0109 3872 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
23:10:06.0125 3872 ql12160 - ok
23:10:06.0140 3872 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
23:10:06.0140 3872 ql1240 - ok
23:10:06.0171 3872 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
23:10:06.0171 3872 ql1280 - ok
23:10:06.0187 3872 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:10:06.0187 3872 RasAcd - ok
23:10:06.0234 3872 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:10:06.0234 3872 Rasl2tp - ok
23:10:06.0359 3872 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:10:06.0359 3872 RasPppoe - ok
23:10:06.0359 3872 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:10:06.0375 3872 Raspti - ok
23:10:06.0390 3872 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:10:06.0390 3872 Rdbss - ok
23:10:06.0406 3872 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:10:06.0421 3872 RDPCDD - ok
23:10:06.0468 3872 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
23:10:06.0468 3872 rdpdr - ok
23:10:06.0640 3872 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
23:10:06.0640 3872 RDPWD - ok
23:10:06.0671 3872 redbook (08fbe0b348a3ab907b250e9dc89550e3) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:10:06.0687 3872 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: 08fbe0b348a3ab907b250e9dc89550e3, Fake md5: f828dd7e1419b6653894a8f97a0094c5
23:10:06.0687 3872 redbook ( Rootkit.Win32.ZAccess.k ) - infected
23:10:06.0687 3872 redbook - detected Rootkit.Win32.ZAccess.k (0)
23:10:06.0921 3872 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
23:10:07.0062 3872 RimUsb - ok
23:10:07.0171 3872 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:10:07.0187 3872 Secdrv - ok
23:10:07.0484 3872 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:10:07.0484 3872 serenum - ok
23:10:07.0593 3872 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
23:10:07.0609 3872 Serial - ok
23:10:07.0640 3872 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:10:07.0640 3872 Sfloppy - ok
23:10:07.0781 3872 Simbad - ok
23:10:07.0828 3872 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
23:10:07.0828 3872 sisagp - ok
23:10:07.0890 3872 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
23:10:07.0890 3872 SLIP - ok
23:10:07.0968 3872 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys
23:10:08.0015 3872 smwdm - ok
23:10:08.0062 3872 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS
23:10:08.0062 3872 SONYPVU1 - ok
23:10:08.0171 3872 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
23:10:08.0171 3872 Sparrow - ok
23:10:08.0265 3872 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
23:10:08.0265 3872 splitter - ok
23:10:08.0328 3872 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
23:10:08.0328 3872 sr - ok
23:10:08.0406 3872 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
23:10:08.0421 3872 Srv - ok
23:10:08.0484 3872 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
23:10:08.0531 3872 sscdbhk5 - ok
23:10:08.0546 3872 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
23:10:08.0578 3872 ssrtln - ok
23:10:08.0625 3872 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
23:10:08.0625 3872 streamip - ok
23:10:08.0718 3872 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:10:08.0718 3872 swenum - ok
23:10:08.0734 3872 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
23:10:08.0734 3872 swmidi - ok
23:10:08.0765 3872 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
23:10:08.0765 3872 symc810 - ok
23:10:08.0781 3872 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
23:10:08.0781 3872 symc8xx - ok
23:10:08.0796 3872 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
23:10:08.0796 3872 sym_hi - ok
23:10:08.0812 3872 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
23:10:08.0812 3872 sym_u3 - ok
23:10:08.0828 3872 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
23:10:08.0828 3872 sysaudio - ok
23:10:08.0890 3872 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:10:08.0890 3872 Tcpip - ok
23:10:09.0031 3872 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:10:09.0031 3872 TDPIPE - ok
23:10:09.0046 3872 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
23:10:09.0046 3872 TDTCP - ok
23:10:09.0093 3872 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:10:09.0093 3872 TermDD - ok
23:10:09.0187 3872 tfsnboio (75b30b9ea32fe7d8bbc332d3b944ad46) C:\WINDOWS\system32\dla\tfsnboio.sys
23:10:09.0234 3872 tfsnboio - ok
23:10:09.0343 3872 tfsncofs (b811a431b14694d88eb5befaa55b4501) C:\WINDOWS\system32\dla\tfsncofs.sys
23:10:09.0375 3872 tfsncofs - ok
23:10:09.0406 3872 tfsndrct (f5e2cf2144f1fe51dadd6e9063d311eb) C:\WINDOWS\system32\dla\tfsndrct.sys
23:10:09.0437 3872 tfsndrct - ok
23:10:09.0453 3872 tfsndres (e32b32045b6b914fd4caae8be6ca7e8a) C:\WINDOWS\system32\dla\tfsndres.sys
23:10:09.0500 3872 tfsndres - ok
23:10:09.0515 3872 tfsnifs (43034b10a94d1c6f13a1a0e848f51226) C:\WINDOWS\system32\dla\tfsnifs.sys
23:10:09.0562 3872 tfsnifs - ok
23:10:09.0656 3872 tfsnopio (f5ee0faafde37326ea35acbfa5defd3d) C:\WINDOWS\system32\dla\tfsnopio.sys
23:10:09.0687 3872 tfsnopio - ok
23:10:09.0781 3872 tfsnpool (597348eb65b3e19709e9a45ca2b30b61) C:\WINDOWS\system32\dla\tfsnpool.sys
23:10:09.0812 3872 tfsnpool - ok
23:10:09.0828 3872 tfsnudf (767affd52432a0f7e7d39f6ff64401f4) C:\WINDOWS\system32\dla\tfsnudf.sys
23:10:09.0890 3872 tfsnudf - ok
23:10:09.0937 3872 tfsnudfa (2806b2fd00263ccd90cc0638c6139eb0) C:\WINDOWS\system32\dla\tfsnudfa.sys
23:10:09.0984 3872 tfsnudfa - ok
23:10:10.0078 3872 thdudf (9d4bbd6e27b5562aea8295de7134e386) C:\WINDOWS\system32\DRIVERS\thdudf.sys
23:10:10.0125 3872 thdudf - ok
23:10:10.0187 3872 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
23:10:10.0187 3872 TosIde - ok
23:10:10.0234 3872 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
23:10:10.0234 3872 Udfs - ok
23:10:10.0265 3872 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
23:10:10.0265 3872 ultra - ok
23:10:10.0343 3872 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
23:10:10.0343 3872 Update - ok
23:10:10.0406 3872 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys
23:10:10.0500 3872 USBAAPL - ok
23:10:10.0578 3872 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
23:10:10.0578 3872 usbaudio - ok
23:10:10.0656 3872 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:10:10.0656 3872 usbccgp - ok
23:10:10.0703 3872 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:10:10.0703 3872 usbehci - ok
23:10:10.0718 3872 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:10:10.0718 3872 usbhub - ok
23:10:10.0734 3872 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:10:10.0734 3872 usbprint - ok
23:10:10.0750 3872 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:10:10.0750 3872 usbscan - ok
23:10:10.0765 3872 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:10:10.0765 3872 USBSTOR - ok
23:10:10.0781 3872 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:10:10.0781 3872 usbuhci - ok
23:10:10.0828 3872 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
23:10:10.0828 3872 VgaSave - ok
23:10:10.0875 3872 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
23:10:10.0875 3872 viaagp - ok
23:10:10.0890 3872 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
23:10:10.0890 3872 ViaIde - ok
23:10:10.0968 3872 VNA (6588080a0872c772df85689df18cfe42) C:\WINDOWS\system32\DRIVERS\vna.sys
23:10:11.0015 3872 VNA - ok
23:10:11.0046 3872 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
23:10:11.0046 3872 VolSnap - ok
23:10:11.0218 3872 VX6000 (3c296e30c519e2f71e47820d8f4dd1e7) C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys
23:10:11.0265 3872 VX6000 - ok
23:10:11.0406 3872 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:10:11.0421 3872 Wanarp - ok
23:10:11.0437 3872 wanatw - ok
23:10:11.0453 3872 WDICA - ok
23:10:11.0484 3872 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
23:10:11.0484 3872 wdmaud - ok
23:10:11.0578 3872 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
23:10:11.0578 3872 winachsf - ok
23:10:11.0718 3872 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
23:10:11.0718 3872 WS2IFSL - ok
23:10:11.0781 3872 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
23:10:11.0781 3872 WSTCODEC - ok
23:10:11.0812 3872 ZDPSp50 - ok
23:10:12.0046 3872 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054} (74ec37b9eaf9fca015b933a526825c7a) C:\Program Files\CyberLink\PowerDVD8\000.fcl
23:10:13.0406 3872 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054} - ok
23:10:13.0421 3872 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0
23:10:13.0421 3872 \Device\Harddisk0\DR0 - ok
23:10:13.0437 3872 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1
23:10:14.0281 3872 \Device\Harddisk1\DR1 - ok
23:10:14.0296 3872 MBR (0x1B8) (bbb0a0725ad66f38b1a32135f3cb55d6) \Device\Harddisk2\DR6
23:10:14.0656 3872 \Device\Harddisk2\DR6 - ok
23:10:14.0671 3872 Boot (0x1200) (32ffde642bb0ec5faa7555806e2838b0) \Device\Harddisk0\DR0\Partition0
23:10:14.0671 3872 \Device\Harddisk0\DR0\Partition0 - ok
23:10:14.0671 3872 Boot (0x1200) (ca672faf37e17143fa21fc19eb67bca4) \Device\Harddisk1\DR1\Partition0
23:10:14.0671 3872 \Device\Harddisk1\DR1\Partition0 - ok
23:10:14.0687 3872 Boot (0x1200) (20e9e897ce5418a919dfabebc40d2ff7) \Device\Harddisk2\DR6\Partition0
23:10:14.0687 3872 \Device\Harddisk2\DR6\Partition0 - ok
23:10:14.0687 3872 ============================================================
23:10:14.0687 3872 Scan finished
23:10:14.0687 3872 ============================================================
23:10:14.0703 0172 Detected object count: 1
23:10:14.0703 0172 Actual detected object count: 1
23:11:52.0656 0172 Backup copy found, using it..
23:11:52.0843 0172 C:\WINDOWS\system32\DRIVERS\redbook.sys - will be cured on reboot
23:11:55.0687 0172 redbook ( Rootkit.Win32.ZAccess.k ) - User select action: Cure
23:12:04.0546 2888 Deinitialize success
ComboFix 11-12-05.04 - The Haymakers 12/05/2011 23:49:39.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1478 [GMT -5:00]
Running from: c:\documents and settings\The Haymakers\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
c:\documents and settings\The Haymakers\g2mdlhlpx.exe
c:\documents and settings\The Haymakers\Local Settings\Application Data\asam.exe
c:\documents and settings\The Haymakers\Local Settings\Application Data\syssvc.exe
c:\documents and settings\The Haymakers\Recent\Thumbs.db
c:\documents and settings\The Haymakers\WINDOWS
C:\Documents
c:\program files\MyWaySA
c:\program files\Shared
c:\program files\Shared\lib.sig
c:\windows\$NtUninstallKB13844$
c:\windows\$NtUninstallKB13844$\4197895202\@
c:\windows\$NtUninstallKB13844$\4197895202\bckfg.tmp
c:\windows\$NtUninstallKB13844$\4197895202\cfg.ini
c:\windows\$NtUninstallKB13844$\4197895202\Desktop.ini
c:\windows\$NtUninstallKB13844$\4197895202\keywords
c:\windows\$NtUninstallKB13844$\4197895202\kwrd.dll
c:\windows\$NtUninstallKB13844$\4197895202\L\odetmngk
c:\windows\$NtUninstallKB13844$\4197895202\lsflt7.ver
c:\windows\$NtUninstallKB13844$\4197895202\U\00000001.@
c:\windows\$NtUninstallKB13844$\4197895202\U\00000002.@
c:\windows\$NtUninstallKB13844$\4197895202\U\00000004.@
c:\windows\$NtUninstallKB13844$\4197895202\U\80000000.@
c:\windows\$NtUninstallKB13844$\4197895202\U\80000004.@
c:\windows\$NtUninstallKB13844$\4197895202\U\80000032.@
c:\windows\$NtUninstallKB13844$\4209842385
c:\windows\bwUnin-7.2.0.137-8876480SL.exe
c:\windows\dasetup.log
c:\windows\herjek.config
c:\windows\svcs.exe
c:\windows\system32\ie.ico
c:\windows\system32\open.ico
c:\windows\system32\regobj.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-01 19:17 . 2011-12-01 19:17 -------- d-----w- c:\documents and settings\The Haymakers\Application Data\Malwarebytes
2011-12-01 19:17 . 2011-12-01 19:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-01 19:17 . 2011-12-01 19:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-01 19:17 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-17 03:36 . 2011-11-17 03:36 388096 ----a-r- c:\documents and settings\The Haymakers\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-17 03:36 . 2011-11-17 03:36 -------- d-----w- c:\program files\Trend Micro
2011-11-17 02:31 . 2011-11-17 02:31 -------- d-----w- c:\windows\system32\LogFiles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-06 04:12 . 2004-08-04 04:59 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-10-10 14:22 . 2004-08-04 11:00 692736 ------w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 11:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 11:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 11:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2005-04-21 12:51 . 2005-04-21 12:51 278528 -c--a-w- c:\program files\internet explorer\plugins\PanoViewer.dll
2005-04-21 12:52 . 2005-04-21 12:52 98304 -c--a-w- c:\program files\internet explorer\plugins\UPjpeg.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2003-09-29 81990]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 135251]
"AWMON"="c:\program files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2004-09-16 538112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\The Haymakers\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\Dropbox.exe [2011-1-27 23361424]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-2-22 385024]
ScreenHunter 5.1 Free.lnk - c:\program files\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe [2009-7-14 5689344]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2010-5-30 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-2-13 24576]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-6-2 450560]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 20:08 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Documents and Settings\\The Haymakers\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\The Haymakers\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\SYSTEM32\\USMT\\MIGWIZ.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
.
R0 CLBStor;CyberLink InstantBurn UDF Reader Help Driver;c:\windows\SYSTEM32\DRIVERS\CLBStor.sys [3/28/2011 9:25 PM 10368]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2011/03/28 22:30];c:\program files\CyberLink\PowerDVD8\000.fcl [8/28/2009 5:36 PM 87536]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 6:00 AM 14336]
R2 CLBUDFR;CyberLink UDF Filesystem;c:\windows\SYSTEM32\DRIVERS\CLBUDFR.sys [3/28/2011 9:25 PM 154368]
R2 cpextender;Check Point SSL Network Extender;c:\program files\CheckPoint\SSL Network Extender\slimsvc.exe [6/10/2007 3:48 PM 331870]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/1/2011 2:17 PM 366152]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [9/2/2010 4:46 AM 206120]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [9/2/2010 4:46 AM 185640]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\SYSTEM32\DRIVERS\thdudf.sys [3/30/2011 8:21 PM 66944]
R2 TomTomHOMEService;TomTomHOMEService;g:\tomtom home 2\TomTomHOMEService.exe [12/10/2010 7:29 AM 92008]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/15/2007 4:33 PM 24652]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [12/1/2011 2:17 PM 22216]
R3 VNA;Check Point Virtual Network Adapter;c:\windows\SYSTEM32\DRIVERS\vna.sys [9/12/2006 5:14 PM 110160]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/29/2011 10:07 AM 136176]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\SYSTEM32\DRIVERS\A3AB.sys [8/25/2005 2:00 PM 466880]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/29/2011 10:07 AM 136176]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\SYSTEM32\DRIVERS\VX6000Xp.sys [2/8/2009 5:53 PM 2385896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
.
2011-12-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-29 15:07]
.
2011-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-29 15:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell4me.com/myway
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/vso/en-us/redir.asp?affid=105-36&installtype=force&dtag=dq6ft61&systempopup=true
uInternet Settings,ProxyServer = http=127.0.0.1:4185
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: csplans.com\lmco
Trusted Zone: ebay.com\signin
Trusted Zone: gmail.com\www
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: msb.edu\storage
Trusted Zone: turbotax.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxps://sslvpn.mindshift.com/sre/ICSScanner.cab
FF - ProfilePath - c:\documents and settings\The Haymakers\Application Data\Mozilla\Firefox\Profiles\vzk8qt4n.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\The Haymakers\Application Data\Move Networks
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-DellSupport - c:\program files\Dell Support\DSAgnt.exe
HKCU-Run-Akamai NetSession Interface - c:\documents and settings\The Haymakers\Local Settings\Application Data\Akamai\netsession_win.exe
HKLM-Run-BuildBU - c:\dell\bldbubg.exe
HKLM-Run-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
HKLM-Run-mmtask - c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
HKLM-Run-MMTray - c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
HKLM-Run-EPSON Stylus Photo RX500 - c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
Notify-WgaLogon - (no file)
SafeBoot-42480066.sys
SafeBoot-klmdb.sys
MSConfigStartUp-mmtask - c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
MSConfigStartUp-MMTray - c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
MSConfigStartUp-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
AddRemove-HijackThis - c:\docume~1\THEHAY~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-06 00:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_d768ebc.dll"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2276)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\documents and settings\The Haymakers\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\Mcshield.exe
c:\program files\Network Associates\VirusScan\VsTskMgr.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2011-12-06 00:22:33 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-06 05:22
.
Pre-Run: 13,982,339,072 bytes free
Post-Run: 17,058,381,824 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 69E50F0E6A45663B4269557B7B6113E3