Hi RPM,
Here are my logs. TDS Killer did not find anything. It did not give me the option to skip or cure. It just went back to the home screen. Did I mess something up? Thanks so much for your help.
13:05:31.0501 3848 TDSS rootkit removing tool 2.7.9.0 Feb 1 2012 09:28:49
13:05:31.0798 3848 ============================================================
13:05:31.0798 3848 Current date / time: 2012/02/05 13:05:31.0798
13:05:31.0798 3848 SystemInfo:
13:05:31.0798 3848
13:05:31.0798 3848 OS Version: 6.1.7601 ServicePack: 1.0
13:05:31.0798 3848 Product type: Workstation
13:05:31.0798 3848 ComputerName: DREW-PC
13:05:31.0798 3848 UserName: Drew
13:05:31.0798 3848 Windows directory: C:\Windows
13:05:31.0798 3848 System windows directory: C:\Windows
13:05:31.0798 3848 Processor architecture: Intel x86
13:05:31.0798 3848 Number of processors: 2
13:05:31.0798 3848 Page size: 0x1000
13:05:31.0798 3848 Boot type: Normal boot
13:05:31.0798 3848 ============================================================
13:05:32.0203 3848 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
13:05:32.0219 3848 Drive \Device\Harddisk3\DR3 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:05:32.0219 3848 \Device\Harddisk1\DR1:
13:05:32.0219 3848 MBR used
13:05:32.0219 3848 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:05:32.0219 3848 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x129E6800
13:05:32.0219 3848 \Device\Harddisk3\DR3:
13:05:32.0219 3848 MBR used
13:05:32.0219 3848 \Device\Harddisk3\DR3\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82
13:05:32.0234 3848 Initialize success
13:05:32.0234 3848 ============================================================
13:06:10.0612 6016 ============================================================
13:06:10.0612 6016 Scan started
13:06:10.0612 6016 Mode: Manual;
13:06:10.0612 6016 ============================================================
13:06:11.0095 6016 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
13:06:11.0111 6016 1394ohci - ok
13:06:11.0142 6016 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
13:06:11.0158 6016 ACPI - ok
13:06:11.0205 6016 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
13:06:11.0205 6016 AcpiPmi - ok
13:06:11.0236 6016 ADIHdAudAddService (6c61bceb60c2c187e6f96001fd69493e) C:\Windows\system32\drivers\ADIHdAud.sys
13:06:11.0251 6016 ADIHdAudAddService - ok
13:06:11.0314 6016 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
13:06:11.0314 6016 adp94xx - ok
13:06:11.0361 6016 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
13:06:11.0361 6016 adpahci - ok
13:06:11.0407 6016 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
13:06:11.0407 6016 adpu320 - ok
13:06:11.0454 6016 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
13:06:11.0470 6016 AFD - ok
13:06:11.0532 6016 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
13:06:11.0532 6016 agp440 - ok
13:06:11.0563 6016 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
13:06:11.0563 6016 aic78xx - ok
13:06:11.0610 6016 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
13:06:11.0610 6016 aliide - ok
13:06:11.0641 6016 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
13:06:11.0641 6016 amdagp - ok
13:06:11.0673 6016 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
13:06:11.0673 6016 amdide - ok
13:06:11.0704 6016 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
13:06:11.0704 6016 AmdK8 - ok
13:06:11.0735 6016 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
13:06:11.0735 6016 AmdPPM - ok
13:06:11.0766 6016 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
13:06:11.0782 6016 amdsata - ok
13:06:11.0813 6016 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
13:06:11.0813 6016 amdsbs - ok
13:06:11.0844 6016 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
13:06:11.0844 6016 amdxata - ok
13:06:11.0907 6016 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
13:06:11.0907 6016 AppID - ok
13:06:11.0953 6016 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
13:06:11.0969 6016 arc - ok
13:06:12.0016 6016 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
13:06:12.0016 6016 arcsas - ok
13:06:12.0047 6016 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
13:06:12.0047 6016 AsyncMac - ok
13:06:12.0078 6016 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
13:06:12.0078 6016 atapi - ok
13:06:12.0125 6016 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
13:06:12.0141 6016 b06bdrv - ok
13:06:12.0187 6016 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
13:06:12.0187 6016 b57nd60x - ok
13:06:12.0219 6016 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
13:06:12.0219 6016 Beep - ok
13:06:12.0250 6016 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
13:06:12.0265 6016 blbdrive - ok
13:06:12.0297 6016 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
13:06:12.0297 6016 bowser - ok
13:06:12.0328 6016 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:06:12.0328 6016 BrFiltLo - ok
13:06:12.0359 6016 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:06:12.0359 6016 BrFiltUp - ok
13:06:12.0406 6016 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
13:06:12.0406 6016 BridgeMP - ok
13:06:12.0453 6016 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
13:06:12.0453 6016 Brserid - ok
13:06:12.0499 6016 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
13:06:12.0499 6016 BrSerWdm - ok
13:06:12.0531 6016 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:06:12.0531 6016 BrUsbMdm - ok
13:06:12.0562 6016 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
13:06:12.0562 6016 BrUsbSer - ok
13:06:12.0624 6016 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys
13:06:12.0624 6016 BthEnum - ok
13:06:12.0655 6016 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
13:06:12.0655 6016 BTHMODEM - ok
13:06:12.0702 6016 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
13:06:12.0702 6016 BthPan - ok
13:06:12.0765 6016 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys
13:06:12.0780 6016 BTHPORT - ok
13:06:12.0827 6016 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys
13:06:12.0827 6016 BTHUSB - ok
13:06:12.0843 6016 catchme - ok
13:06:12.0889 6016 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
13:06:12.0889 6016 cdfs - ok
13:06:12.0936 6016 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
13:06:12.0936 6016 cdrom - ok
13:06:12.0967 6016 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
13:06:12.0967 6016 circlass - ok
13:06:12.0999 6016 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
13:06:13.0014 6016 CLFS - ok
13:06:13.0045 6016 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
13:06:13.0045 6016 CmBatt - ok
13:06:13.0108 6016 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
13:06:13.0108 6016 cmdide - ok
13:06:13.0139 6016 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
13:06:13.0155 6016 CNG - ok
13:06:13.0186 6016 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
13:06:13.0186 6016 Compbatt - ok
13:06:13.0217 6016 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
13:06:13.0217 6016 CompositeBus - ok
13:06:13.0248 6016 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
13:06:13.0248 6016 crcdisk - ok
13:06:13.0295 6016 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys
13:06:13.0311 6016 CSC - ok
13:06:13.0357 6016 CVirtA (b5ecadf7708960f1818c7fa015f4c239) C:\Windows\system32\DRIVERS\CVirtA.sys
13:06:13.0357 6016 CVirtA - ok
13:06:13.0389 6016 CVPNDRVA (34c345aaf390c12ae6e51b75198e8564) C:\Windows\system32\Drivers\CVPNDRVA.sys
13:06:13.0404 6016 CVPNDRVA - ok
13:06:13.0435 6016 dc3d (91c1736e77cff029302728b431d0eedb) C:\Windows\system32\DRIVERS\dc3d.sys
13:06:13.0435 6016 dc3d - ok
13:06:13.0467 6016 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
13:06:13.0467 6016 DfsC - ok
13:06:13.0498 6016 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
13:06:13.0498 6016 discache - ok
13:06:13.0529 6016 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
13:06:13.0545 6016 Disk - ok
13:06:13.0560 6016 DNE (b5aa5aa5ac327bd7c1aec0c58f0c1144) C:\Windows\system32\DRIVERS\dne2000.sys
13:06:13.0576 6016 DNE - ok
13:06:13.0607 6016 DozeHDD (6d279bb0de1d8e34f454e1b353f4d738) C:\Windows\system32\DRIVERS\DozeHDD.sys
13:06:13.0607 6016 DozeHDD - ok
13:06:13.0654 6016 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
13:06:13.0654 6016 drmkaud - ok
13:06:13.0701 6016 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
13:06:13.0732 6016 DXGKrnl - ok
13:06:13.0763 6016 e1express (cf0a6015f437161698c5b2a0a12cf052) C:\Windows\system32\DRIVERS\e1e6032.sys
13:06:13.0763 6016 e1express - ok
13:06:13.0919 6016 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
13:06:13.0950 6016 ebdrv - ok
13:06:13.0966 6016 eeCtrl (579a6b6135d32b857faf0e3a974535d8) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
13:06:13.0981 6016 eeCtrl - ok
13:06:14.0044 6016 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
13:06:14.0059 6016 elxstor - ok
13:06:14.0091 6016 EraserUtilRebootDrv (028d50f059bd0d2ccb209e9011b9a9a4) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:06:14.0091 6016 EraserUtilRebootDrv - ok
13:06:14.0137 6016 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
13:06:14.0137 6016 ErrDev - ok
13:06:14.0184 6016 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
13:06:14.0200 6016 exfat - ok
13:06:14.0231 6016 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
13:06:14.0231 6016 fastfat - ok
13:06:14.0278 6016 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
13:06:14.0278 6016 fdc - ok
13:06:14.0309 6016 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
13:06:14.0309 6016 FileInfo - ok
13:06:14.0340 6016 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
13:06:14.0340 6016 Filetrace - ok
13:06:14.0387 6016 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
13:06:14.0387 6016 flpydisk - ok
13:06:14.0418 6016 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
13:06:14.0418 6016 FltMgr - ok
13:06:14.0449 6016 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
13:06:14.0449 6016 FsDepends - ok
13:06:14.0481 6016 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
13:06:14.0481 6016 Fs_Rec - ok
13:06:14.0512 6016 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
13:06:14.0527 6016 fvevol - ok
13:06:14.0559 6016 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:06:14.0559 6016 gagp30kx - ok
13:06:14.0590 6016 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:06:14.0590 6016 GEARAspiWDM - ok
13:06:14.0621 6016 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
13:06:14.0621 6016 hcw85cir - ok
13:06:14.0668 6016 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
13:06:14.0668 6016 HdAudAddService - ok
13:06:14.0699 6016 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
13:06:14.0699 6016 HDAudBus - ok
13:06:14.0746 6016 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
13:06:14.0746 6016 HidBatt - ok
13:06:14.0777 6016 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
13:06:14.0777 6016 HidBth - ok
13:06:14.0824 6016 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
13:06:14.0824 6016 HidIr - ok
13:06:14.0871 6016 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
13:06:14.0871 6016 HidUsb - ok
13:06:14.0917 6016 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
13:06:14.0917 6016 HpSAMD - ok
13:06:14.0980 6016 HSF_DPV (7bc42c65b5c6281777c1a7605b253ba8) C:\Windows\system32\DRIVERS\HSX_DPV.sys
13:06:15.0011 6016 HSF_DPV - ok
13:06:15.0042 6016 HSXHWAZL (9ebf2d102ccbb6bcdfbf1b7922f8ba2e) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
13:06:15.0042 6016 HSXHWAZL - ok
13:06:15.0089 6016 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
13:06:15.0105 6016 HTTP - ok
13:06:15.0136 6016 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
13:06:15.0136 6016 hwpolicy - ok
13:06:15.0167 6016 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
13:06:15.0167 6016 i8042prt - ok
13:06:15.0214 6016 iaNvStor (d0310c79c5a9d42b96e37c5c510c6a5c) C:\Windows\system32\DRIVERS\iaNvStor.sys
13:06:15.0214 6016 iaNvStor - ok
13:06:15.0245 6016 iaStor (01446278d4563b3013c92830ae6cbb26) C:\Windows\system32\DRIVERS\iaStor.sys
13:06:15.0261 6016 iaStor - ok
13:06:15.0323 6016 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
13:06:15.0323 6016 iaStorV - ok
13:06:15.0354 6016 IBMPMDRV (fa3d0a6da7bb7968efe5c5bc267f0e55) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
13:06:15.0354 6016 IBMPMDRV - ok
13:06:15.0385 6016 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
13:06:15.0385 6016 iirsp - ok
13:06:15.0417 6016 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
13:06:15.0417 6016 intelide - ok
13:06:15.0448 6016 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
13:06:15.0448 6016 intelppm - ok
13:06:15.0479 6016 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:06:15.0479 6016 IpFilterDriver - ok
13:06:15.0526 6016 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
13:06:15.0526 6016 IPMIDRV - ok
13:06:15.0557 6016 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
13:06:15.0573 6016 IPNAT - ok
13:06:15.0604 6016 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
13:06:15.0604 6016 IRENUM - ok
13:06:15.0635 6016 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
13:06:15.0635 6016 isapnp - ok
13:06:15.0682 6016 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
13:06:15.0682 6016 iScsiPrt - ok
13:06:15.0713 6016 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
13:06:15.0713 6016 kbdclass - ok
13:06:15.0744 6016 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
13:06:15.0744 6016 kbdhid - ok
13:06:15.0775 6016 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
13:06:15.0775 6016 KSecDD - ok
13:06:15.0807 6016 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
13:06:15.0807 6016 KSecPkg - ok
13:06:15.0838 6016 Lbd (713cd5267abfb86fe90a72e384e82a38) C:\Windows\system32\DRIVERS\Lbd.sys
13:06:15.0853 6016 Lbd - ok
13:06:15.0885 6016 lenovo.smi (9aac267a225f3caebb9e633f7eb16e4b) C:\Windows\system32\DRIVERS\smiif32.sys
13:06:15.0885 6016 lenovo.smi - ok
13:06:15.0916 6016 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\Windows\system32\DRIVERS\LHidFilt.Sys
13:06:15.0916 6016 LHidFilt - ok
13:06:15.0947 6016 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
13:06:15.0947 6016 lltdio - ok
13:06:15.0978 6016 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\Windows\system32\DRIVERS\LMouFilt.Sys
13:06:15.0978 6016 LMouFilt - ok
13:06:16.0025 6016 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:06:16.0025 6016 LSI_FC - ok
13:06:16.0072 6016 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:06:16.0072 6016 LSI_SAS - ok
13:06:16.0103 6016 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:06:16.0119 6016 LSI_SAS2 - ok
13:06:16.0150 6016 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:06:16.0150 6016 LSI_SCSI - ok
13:06:16.0181 6016 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
13:06:16.0181 6016 luafv - ok
13:06:16.0228 6016 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\Windows\system32\Drivers\LVPr2Mon.sys
13:06:16.0228 6016 LVPr2Mon - ok
13:06:16.0306 6016 LVRS (a1857fbb9b4930eeb2fd92386c45c529) C:\Windows\system32\DRIVERS\lvrs.sys
13:06:16.0306 6016 LVRS - ok
13:06:16.0477 6016 LVUVC (3703406af0726badd24c5e552493e5b1) C:\Windows\system32\DRIVERS\lvuvc.sys
13:06:16.0524 6016 LVUVC - ok
13:06:16.0555 6016 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
13:06:16.0555 6016 mdmxsdk - ok
13:06:16.0587 6016 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
13:06:16.0587 6016 megasas - ok
13:06:16.0633 6016 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
13:06:16.0633 6016 MegaSR - ok
13:06:16.0665 6016 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
13:06:16.0665 6016 Modem - ok
13:06:16.0711 6016 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
13:06:16.0711 6016 monitor - ok
13:06:16.0727 6016 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
13:06:16.0743 6016 mouclass - ok
13:06:16.0774 6016 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
13:06:16.0774 6016 mouhid - ok
13:06:16.0789 6016 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
13:06:16.0805 6016 mountmgr - ok
13:06:16.0836 6016 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
13:06:16.0836 6016 mpio - ok
13:06:16.0867 6016 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
13:06:16.0867 6016 mpsdrv - ok
13:06:16.0914 6016 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
13:06:16.0914 6016 MRxDAV - ok
13:06:16.0945 6016 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:06:16.0961 6016 mrxsmb - ok
13:06:16.0992 6016 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:06:16.0992 6016 mrxsmb10 - ok
13:06:17.0023 6016 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:06:17.0023 6016 mrxsmb20 - ok
13:06:17.0055 6016 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
13:06:17.0055 6016 msahci - ok
13:06:17.0148 6016 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
13:06:17.0148 6016 msdsm - ok
13:06:17.0179 6016 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
13:06:17.0179 6016 Msfs - ok
13:06:17.0211 6016 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
13:06:17.0211 6016 mshidkmdf - ok
13:06:17.0242 6016 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
13:06:17.0242 6016 msisadrv - ok
13:06:17.0289 6016 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
13:06:17.0289 6016 MSKSSRV - ok
13:06:17.0320 6016 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
13:06:17.0320 6016 MSPCLOCK - ok
13:06:17.0367 6016 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
13:06:17.0367 6016 MSPQM - ok
13:06:17.0398 6016 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
13:06:17.0398 6016 MsRPC - ok
13:06:17.0429 6016 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
13:06:17.0429 6016 mssmbios - ok
13:06:17.0460 6016 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
13:06:17.0460 6016 MSTEE - ok
13:06:17.0491 6016 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
13:06:17.0491 6016 MTConfig - ok
13:06:17.0523 6016 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
13:06:17.0523 6016 Mup - ok
13:06:17.0569 6016 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
13:06:17.0569 6016 NativeWifiP - ok
13:06:17.0632 6016 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120204.023\NAVENG.SYS
13:06:17.0632 6016 NAVENG - ok
13:06:17.0679 6016 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120204.023\NAVEX15.SYS
13:06:17.0694 6016 NAVEX15 - ok
13:06:17.0741 6016 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
13:06:17.0741 6016 NDIS - ok
13:06:17.0803 6016 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
13:06:17.0803 6016 NdisCap - ok
13:06:17.0835 6016 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
13:06:17.0835 6016 NdisTapi - ok
13:06:17.0850 6016 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
13:06:17.0866 6016 Ndisuio - ok
13:06:17.0881 6016 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
13:06:17.0897 6016 NdisWan - ok
13:06:17.0913 6016 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
13:06:17.0928 6016 NDProxy - ok
13:06:17.0944 6016 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
13:06:17.0959 6016 NetBIOS - ok
13:06:17.0991 6016 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
13:06:17.0991 6016 NetBT - ok
13:06:18.0147 6016 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys
13:06:18.0193 6016 netw5v32 - ok
13:06:18.0443 6016 NETwLv32 (d4ef7a9767c05905500ec312cb29ef46) C:\Windows\system32\DRIVERS\NETwLv32.sys
13:06:18.0661 6016 NETwLv32 - ok
13:06:18.0708 6016 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
13:06:18.0708 6016 nfrd960 - ok
13:06:18.0739 6016 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
13:06:18.0739 6016 Npfs - ok
13:06:18.0755 6016 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
13:06:18.0771 6016 nsiproxy - ok
13:06:18.0833 6016 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
13:06:18.0833 6016 Ntfs - ok
13:06:18.0864 6016 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
13:06:18.0864 6016 Null - ok
13:06:19.0223 6016 nvlddmkm (4a6688bf47940cdc1475772b235c6323) C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:06:19.0551 6016 nvlddmkm - ok
13:06:19.0597 6016 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
13:06:19.0597 6016 nvraid - ok
13:06:19.0660 6016 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
13:06:19.0660 6016 nvstor - ok
13:06:19.0722 6016 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
13:06:19.0722 6016 nv_agp - ok
13:06:19.0769 6016 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
13:06:19.0769 6016 ohci1394 - ok
13:06:19.0800 6016 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
13:06:19.0800 6016 Parport - ok
13:06:19.0831 6016 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
13:06:19.0831 6016 partmgr - ok
13:06:19.0863 6016 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
13:06:19.0863 6016 Parvdm - ok
13:06:19.0894 6016 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
13:06:19.0909 6016 pci - ok
13:06:19.0941 6016 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
13:06:19.0956 6016 pciide - ok
13:06:19.0987 6016 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
13:06:19.0987 6016 pcmcia - ok
13:06:20.0019 6016 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
13:06:20.0019 6016 pcw - ok
13:06:20.0065 6016 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
13:06:20.0081 6016 PEAUTH - ok
13:06:20.0143 6016 Point32 (60a044879c4fa76314494f5fddc43b93) C:\Windows\system32\DRIVERS\point32.sys
13:06:20.0143 6016 Point32 - ok
13:06:20.0190 6016 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
13:06:20.0190 6016 PptpMiniport - ok
13:06:20.0221 6016 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
13:06:20.0221 6016 Processor - ok
13:06:20.0253 6016 psadd (651d3abc1d82d61b6cfb40cb947b3db3) C:\Windows\system32\DRIVERS\psadd.sys
13:06:20.0253 6016 psadd - ok
13:06:20.0299 6016 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
13:06:20.0299 6016 Psched - ok
13:06:20.0377 6016 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
13:06:20.0393 6016 ql2300 - ok
13:06:20.0424 6016 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
13:06:20.0424 6016 ql40xx - ok
13:06:20.0471 6016 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
13:06:20.0471 6016 QWAVEdrv - ok
13:06:20.0502 6016 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
13:06:20.0502 6016 RasAcd - ok
13:06:20.0533 6016 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:06:20.0533 6016 RasAgileVpn - ok
13:06:20.0565 6016 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:06:20.0565 6016 Rasl2tp - ok
13:06:20.0596 6016 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
13:06:20.0596 6016 RasPppoe - ok
13:06:20.0627 6016 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
13:06:20.0627 6016 RasSstp - ok
13:06:20.0674 6016 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
13:06:20.0674 6016 rdbss - ok
13:06:20.0689 6016 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
13:06:20.0705 6016 rdpbus - ok
13:06:20.0721 6016 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:06:20.0721 6016 RDPCDD - ok
13:06:20.0767 6016 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys
13:06:20.0783 6016 RDPDR - ok
13:06:20.0799 6016 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
13:06:20.0799 6016 RDPENCDD - ok
13:06:20.0830 6016 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
13:06:20.0830 6016 RDPREFMP - ok
13:06:20.0892 6016 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
13:06:20.0892 6016 RDPWD - ok
13:06:20.0923 6016 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
13:06:20.0923 6016 rdyboost - ok
13:06:20.0986 6016 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
13:06:20.0986 6016 RFCOMM - ok
13:06:21.0017 6016 rimmptsk (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys
13:06:21.0017 6016 rimmptsk - ok
13:06:21.0033 6016 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys
13:06:21.0048 6016 rimsptsk - ok
13:06:21.0079 6016 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\Windows\system32\Drivers\RimUsb.sys
13:06:21.0079 6016 RimUsb - ok
13:06:21.0111 6016 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys
13:06:21.0111 6016 RimVSerPort - ok
13:06:21.0142 6016 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys
13:06:21.0142 6016 rismxdp - ok
13:06:21.0157 6016 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys
13:06:21.0173 6016 ROOTMODEM - ok
13:06:21.0204 6016 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
13:06:21.0204 6016 rspndr - ok
13:06:21.0251 6016 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys
13:06:21.0251 6016 s3cap - ok
13:06:21.0251 6016 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
13:06:21.0251 6016 SASDIFSV - ok
13:06:21.0267 6016 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
13:06:21.0267 6016 SASKUTIL - ok
13:06:21.0298 6016 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
13:06:21.0298 6016 sbp2port - ok
13:06:21.0345 6016 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
13:06:21.0345 6016 scfilter - ok
13:06:21.0376 6016 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys
13:06:21.0376 6016 sdbus - ok
13:06:21.0407 6016 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
13:06:21.0407 6016 secdrv - ok
13:06:21.0438 6016 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
13:06:21.0454 6016 Serenum - ok
13:06:21.0469 6016 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
13:06:21.0485 6016 Serial - ok
13:06:21.0532 6016 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
13:06:21.0532 6016 sermouse - ok
13:06:21.0579 6016 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
13:06:21.0579 6016 sffdisk - ok
13:06:21.0610 6016 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
13:06:21.0610 6016 sffp_mmc - ok
13:06:21.0641 6016 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
13:06:21.0641 6016 sffp_sd - ok
13:06:21.0688 6016 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
13:06:21.0688 6016 sfloppy - ok
13:06:21.0719 6016 Shockprf (fc0127343bd1ce1986ba12f8937f1057) C:\Windows\system32\DRIVERS\Apsx86.sys
13:06:21.0719 6016 Shockprf - ok
13:06:21.0781 6016 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
13:06:21.0781 6016 sisagp - ok
13:06:21.0813 6016 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:06:21.0813 6016 SiSRaid2 - ok
13:06:21.0859 6016 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
13:06:21.0859 6016 SiSRaid4 - ok
13:06:21.0906 6016 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
13:06:21.0906 6016 Smb - ok
13:06:21.0953 6016 SPBBCDrv (e87cf104f12c92401c4d33c50a3d5dc8) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
13:06:21.0969 6016 SPBBCDrv - ok
13:06:21.0984 6016 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
13:06:21.0984 6016 spldr - ok
13:06:22.0031 6016 SRTSP (b36f8d6a02ff2b3a53e250a629782f29) C:\Windows\system32\Drivers\SRTSP.SYS
13:06:22.0031 6016 SRTSP - ok
13:06:22.0078 6016 SRTSPL (e99bd98ac171a29fc1ba9376be87ae73) C:\Windows\system32\Drivers\SRTSPL.SYS
13:06:22.0078 6016 SRTSPL - ok
13:06:22.0109 6016 SRTSPX (1af34729898063e9b7df8d149d767e07) C:\Windows\system32\Drivers\SRTSPX.SYS
13:06:22.0109 6016 SRTSPX - ok
13:06:22.0156 6016 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
13:06:22.0156 6016 srv - ok
13:06:22.0203 6016 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
13:06:22.0218 6016 srv2 - ok
13:06:22.0265 6016 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
13:06:22.0265 6016 SrvHsfHDA - ok
13:06:22.0327 6016 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
13:06:22.0343 6016 SrvHsfV92 - ok
13:06:22.0405 6016 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
13:06:22.0405 6016 SrvHsfWinac - ok
13:06:22.0437 6016 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
13:06:22.0437 6016 srvnet - ok
13:06:22.0483 6016 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
13:06:22.0499 6016 stexstor - ok
13:06:22.0546 6016 StillCam (edb05bd63148796f23ea78506404a538) C:\Windows\system32\DRIVERS\serscan.sys
13:06:22.0546 6016 StillCam - ok
13:06:22.0577 6016 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys
13:06:22.0593 6016 storflt - ok
13:06:22.0655 6016 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys
13:06:22.0655 6016 storvsc - ok
13:06:22.0686 6016 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
13:06:22.0686 6016 swenum - ok
13:06:22.0717 6016 SymEvent (e42a34e6f5ca71a84d4c2de620aad13d) C:\Windows\system32\Drivers\SYMEVENT.SYS
13:06:22.0717 6016 SymEvent - ok
13:06:22.0749 6016 SYMREDRV (394b2368212114d538316812af60fddd) C:\Windows\System32\Drivers\SYMREDRV.SYS
13:06:22.0749 6016 SYMREDRV - ok
13:06:22.0780 6016 SYMTDI (d46676bb414c7531bdffe637a33f5033) C:\Windows\System32\Drivers\SYMTDI.SYS
13:06:22.0780 6016 SYMTDI - ok
13:06:22.0827 6016 SynTP (d7dc30b8b41e7a913c3fccc0631e72ec) C:\Windows\system32\DRIVERS\SynTP.sys
13:06:22.0827 6016 SynTP - ok
13:06:22.0873 6016 SysPlant (666992d996c524812e713effd836d043) C:\Windows\SYSTEM32\Drivers\SysPlant.sys
13:06:22.0873 6016 SysPlant - ok
13:06:22.0951 6016 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
13:06:22.0983 6016 Tcpip - ok
13:06:23.0061 6016 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
13:06:23.0076 6016 TCPIP6 - ok
13:06:23.0107 6016 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
13:06:23.0107 6016 tcpipreg - ok
13:06:23.0154 6016 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
13:06:23.0170 6016 TDPIPE - ok
13:06:23.0201 6016 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
13:06:23.0201 6016 TDTCP - ok
13:06:23.0232 6016 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
13:06:23.0232 6016 tdx - ok
13:06:23.0263 6016 Teefer2 (f63439ac8fa992bfa0c757eb644a1a0c) C:\Windows\system32\DRIVERS\teefer2.sys
13:06:23.0263 6016 Teefer2 - ok
13:06:23.0295 6016 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
13:06:23.0295 6016 TermDD - ok
13:06:23.0326 6016 TPDIGIMN (521866a3ce5a1a69b4b4a87bdb52be26) C:\Windows\system32\DRIVERS\ApsHM86.sys
13:06:23.0326 6016 TPDIGIMN - ok
13:06:23.0357 6016 TPM (5ad05191dc8b444a7ba4d79b76c42a30) C:\Windows\system32\drivers\tpm.sys
13:06:23.0373 6016 TPM - ok
13:06:23.0388 6016 TPPWRIF (c16ec6a5390904d3971179553852025b) C:\Windows\system32\drivers\Tppwr32v.sys
13:06:23.0388 6016 TPPWRIF - ok
13:06:23.0435 6016 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:06:23.0451 6016 tssecsrv - ok
13:06:23.0466 6016 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
13:06:23.0466 6016 TsUsbFlt - ok
13:06:23.0497 6016 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
13:06:23.0497 6016 tunnel - ok
13:06:23.0544 6016 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
13:06:23.0544 6016 uagp35 - ok
13:06:23.0591 6016 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
13:06:23.0591 6016 udfs - ok
13:06:23.0653 6016 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
13:06:23.0653 6016 uliagpkx - ok
13:06:23.0685 6016 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
13:06:23.0685 6016 umbus - ok
13:06:23.0716 6016 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
13:06:23.0716 6016 UmPass - ok
13:06:23.0778 6016 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
13:06:23.0778 6016 USBAAPL - ok
13:06:23.0809 6016 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
13:06:23.0809 6016 usbaudio - ok
13:06:23.0841 6016 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
13:06:23.0841 6016 usbccgp - ok
13:06:23.0903 6016 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
13:06:23.0903 6016 usbcir - ok
13:06:23.0934 6016 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys
13:06:23.0934 6016 usbehci - ok
13:06:23.0965 6016 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
13:06:23.0981 6016 usbhub - ok
13:06:24.0043 6016 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
13:06:24.0043 6016 usbohci - ok
13:06:24.0059 6016 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
13:06:24.0075 6016 usbprint - ok
13:06:24.0090 6016 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
13:06:24.0090 6016 usbscan - ok
13:06:24.0121 6016 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:06:24.0137 6016 USBSTOR - ok
13:06:24.0153 6016 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
13:06:24.0153 6016 usbuhci - ok
13:06:24.0231 6016 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
13:06:24.0246 6016 vdrvroot - ok
13:06:24.0277 6016 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
13:06:24.0277 6016 vga - ok
13:06:24.0309 6016 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
13:06:24.0309 6016 VgaSave - ok
13:06:24.0340 6016 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
13:06:24.0355 6016 vhdmp - ok
13:06:24.0387 6016 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
13:06:24.0387 6016 viaagp - ok
13:06:24.0433 6016 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
13:06:24.0433 6016 ViaC7 - ok
13:06:24.0465 6016 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
13:06:24.0465 6016 viaide - ok
13:06:24.0496 6016 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys
13:06:24.0496 6016 vmbus - ok
13:06:24.0543 6016 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys
13:06:24.0543 6016 VMBusHID - ok
13:06:24.0558 6016 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
13:06:24.0574 6016 volmgr - ok
13:06:24.0605 6016 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
13:06:24.0605 6016 volmgrx - ok
13:06:24.0652 6016 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
13:06:24.0652 6016 volsnap - ok
13:06:24.0730 6016 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
13:06:24.0730 6016 vsmraid - ok
13:06:24.0777 6016 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
13:06:24.0777 6016 vwifibus - ok
13:06:24.0808 6016 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
13:06:24.0808 6016 WacomPen - ok
13:06:24.0855 6016 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:06:24.0855 6016 WANARP - ok
13:06:24.0855 6016 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
13:06:24.0855 6016 Wanarpv6 - ok
13:06:24.0901 6016 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
13:06:24.0901 6016 Wd - ok
13:06:24.0948 6016 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
13:06:24.0964 6016 Wdf01000 - ok
13:06:24.0995 6016 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
13:06:24.0995 6016 WfpLwf - ok
13:06:25.0026 6016 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
13:06:25.0042 6016 WIMMount - ok
13:06:25.0089 6016 winachsf (5a77ac34a0ffb70ce8b35b524fede9ba) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
13:06:25.0104 6016 winachsf - ok
13:06:25.0151 6016 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
13:06:25.0151 6016 WinUsb - ok
13:06:25.0182 6016 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
13:06:25.0198 6016 WmiAcpi - ok
13:06:25.0229 6016 WPS (9748e527f0d71bc86a1fe45f294e368b) C:\Windows\system32\drivers\wpsdrvnt.sys
13:06:25.0229 6016 WPS - ok
13:06:25.0260 6016 WpsHelper (ff983a25ae6f7d3f87f26bf51f02a201) C:\Windows\system32\drivers\WpsHelper.sys
13:06:25.0276 6016 WpsHelper - ok
13:06:25.0307 6016 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
13:06:25.0307 6016 ws2ifsl - ok
13:06:25.0338 6016 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
13:06:25.0338 6016 WudfPf - ok
13:06:25.0369 6016 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:06:25.0385 6016 WUDFRd - ok
13:06:25.0416 6016 XAudio (88af537264f2b818da15479ceeaf5d7c) C:\Windows\system32\DRIVERS\xaudio.sys
13:06:25.0416 6016 XAudio - ok
13:06:25.0432 6016 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
13:06:25.0463 6016 \Device\Harddisk1\DR1 - ok
13:06:25.0463 6016 MBR (0x1B8) (bbb0a0725ad66f38b1a32135f3cb55d6) \Device\Harddisk3\DR3
13:06:25.0463 6016 \Device\Harddisk3\DR3 - ok
13:06:25.0479 6016 Boot (0x1200) (f8d8d6812e93b8c2ecda04c04c870f14) \Device\Harddisk1\DR1\Partition0
13:06:25.0479 6016 \Device\Harddisk1\DR1\Partition0 - ok
13:06:25.0479 6016 Boot (0x1200) (77d7e04756deedb604f1ebbb2b27e41d) \Device\Harddisk1\DR1\Partition1
13:06:25.0479 6016 \Device\Harddisk1\DR1\Partition1 - ok
13:06:25.0479 6016 Boot (0x1200) (2eccdc5ca8b26d2cd0ebce415403cc52) \Device\Harddisk3\DR3\Partition0
13:06:25.0479 6016 \Device\Harddisk3\DR3\Partition0 - ok
13:06:25.0479 6016 ============================================================
13:06:25.0479 6016 Scan finished
13:06:25.0479 6016 ============================================================
13:06:25.0494 5200 Detected object count: 0
13:06:25.0494 5200 Actual detected object count: 0
COMBOFIX
ComboFix 12-02-05.02 - Drew 02/05/2012 12:27:03.3.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2014.241 [GMT -5:00]
Running from: c:\users\Drew\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Symantec Endpoint Protection *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Files Created from 2012-01-05 to 2012-02-05 )))))))))))))))))))))))))))))))
.
.
2012-02-05 17:38 . 2012-02-05 17:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-02-05 17:38 . 2012-02-05 17:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-05 17:08 . 2012-02-05 17:08 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FE19DB3-E209-4DC6-A03D-0DCB5749C048}\offreg.dll
2012-02-03 23:25 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FE19DB3-E209-4DC6-A03D-0DCB5749C048}\mpengine.dll
2012-01-31 23:05 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-31 23:05 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-31 23:05 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-31 23:05 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-31 23:05 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-31 23:05 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-31 23:05 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-31 23:05 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-31 23:05 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-31 23:04 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-21 23:38 . 2012-01-21 23:38 -------- d-----w- c:\program files\iPod
2012-01-21 23:37 . 2012-01-21 23:38 -------- d-----w- c:\program files\iTunes
2012-01-13 03:47 . 2012-01-13 03:47 -------- d-----w- c:\program files\Bonjour
2012-01-13 03:18 . 2012-01-13 03:18 -------- d-----w- c:\program files\Apple Software Update
2012-01-10 22:54 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-10 22:54 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-10 22:54 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 22:54 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-27 05:21 . 2009-12-23 17:30 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-12-10 20:24 . 2010-01-31 01:32 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-08 23:17 . 2011-12-08 23:18 485576 ----a-w- c:\users\Drew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina Marketing Corp\UninstallCouponActivator.exe
2011-11-24 15:15 . 2011-05-19 05:16 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25 . 2011-12-13 22:47 2342912 ----a-w- c:\windows\system32\win32k.sys
2012-01-31 23:53 . 2011-11-11 02:38 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MusicManager"="c:\users\Drew\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-01-11 13224448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"IaNvSrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2009-10-06 33304]
"PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2011-06-02 1258856]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"TpShocks"="TpShocks.exe" [2009-07-09 337184]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2011-02-08 115560]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-23 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-03 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 17:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^VPN Client.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\VPN Client.lnk
backup=c:\windows\pss\VPN Client.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-12-01 01:27 136176 ----atw- c:\users\Drew\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2010-07-21 21:52 1797008 ----a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-01-16 22:22 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2012-01-13 19:53 981680 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 19:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 15:47 79192 ----a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2011-04-04 45496]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2010-07-07 44432]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2011-06-02 83304]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-05 1343400]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R4 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [2009-09-25 93960]
S0 DozeHDD;DozeHDD;c:\windows\System32\DRIVERS\DozeHDD.sys [2011-06-02 25968]
S0 iaNvStor;Intel® Turbo Memory Controller;c:\windows\system32\DRIVERS\iaNvStor.sys [2009-08-21 232472]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-12-02 64288]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2009-06-29 20520]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2010-09-07 13680]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-03 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-08-03 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-20 116608]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [2009-09-14 153600]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2009-09-14 121856]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
S2 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files\ThinkPad\Utilities\PWMEWSVC.EXE [2011-06-02 148840]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-04-20 130920]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2011-03-29 64952]
S3 DozeSvc;Lenovo Doze Mode Service;c:\program files\ThinkPad\Utilities\DOZESVC.EXE [2011-06-02 292200]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-03 106104]
S3 NETwLv32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETwLv32.sys [2010-10-07 6639616]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 11316257
*NewlyCreated* - 37572355
*NewlyCreated* - 81916085
*Deregistered* - 11316257
*Deregistered* - 37572355
*Deregistered* - 81916085
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3967998290-1135611248-1365206589-1000Core.job
- c:\users\Drew\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-01 01:27]
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3967998290-1135611248-1365206589-1000UA.job
- c:\users\Drew\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-01 01:27]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Drew\AppData\Roaming\Mozilla\Firefox\Profiles\pi3w0wwa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.1.7601
.
CreateFile("\\.\PHYSICALDRIVE1"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(4808)
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\ThinkPad\Utilities\PWMTR32V.DLL
c:\progra~1\ThinkPad\UTILIT~1\US\PWMRT32V.DLL
c:\progra~1\ThinkPad\UTILIT~1\PWMIF32V.DLL
.
Completion time: 2012-02-05 12:49:52
ComboFix-quarantined-files.txt 2012-02-05 17:49
.
Pre-Run: 47,669,989,376 bytes free
Post-Run: 47,596,437,504 bytes free
.
- - End Of File - - 4D07E0BB226A7BA90117395E8A271DE3