Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Alureon, the start of all my woes


  • This topic is locked This topic is locked
32 replies to this topic

#1 Dr_Million

Dr_Million

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 23 May 2011 - 01:44 PM

Hi all, and thanks for reading my topic,

Please forgive me if my account is garbled, I've been working on this problem for days now, while still working my usual job for the bulk of the day, so I'm a bit tired and everything is kind of merging into one alarming mess.

The setting - My girlfrined's Sony Vaio laptop, running vista SP2: an infrequently updated, overpriced, but very important piece of plastic. She is writing a novel. She has NOT been backing up her work (yes, I know what you're thinking, I thought it too and told her so).

What happened - (she was using it at the time, not me, so forgive me if this is not entirely accurate). She recieved an update notification, clicked to allow it, then there was some kind of security alert popup saying that the hard drive had failed. At this time her documents and desktop suddenly disappeared. I googled the alert and the symptoms and self-diagnosed a TDSS/Alureon infection. While I was doing this google redirects seemed to be operating too. I followed the instructions I found on Bleeping Computer to remove the infection, which did not work the first time, or the second, but appeared to the third (I think) when a boot time scan showed the trojan and allowed it to be treated. However, upon trying to boot after, the computer was unable to start. Startup repair attempts to repair the problem but fails, using both of the backups created by Avast! prior to the tinkering.

I managed to get the book onto a USB drive however there is a lot of other stuff on her computer that stands to be lost. I'm also concerned about the other computers on our home network, so am endeavouring to secure them as well as I can before I try to get the book off the USB that might harbour malware.

I have used TDSSkiller, Avast!, AVG, MalwareBytes, and SpyBot S&D, as far as I can remember.


Any advice would be much appreciated - I wish I had come here sooner but I thought I could handle this. I was wrong

Edited by Blade Zephon, 23 May 2011 - 01:54 PM.
Moved to AII as no logs provided and Prep Guide not followed. ~BZ


BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:11:51 PM

Posted 26 May 2011 - 01:37 PM

Can you post the logs from the tools that you have used?

#3 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 26 May 2011 - 03:04 PM

Unfortunately I can't, as the computer concerned will not start windows, as mentioned. Difficult to help with obviously. Is the infection likely to have caused this inability to start, or is it my tinkering do you think?

#4 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:11:51 PM

Posted 26 May 2011 - 03:07 PM

Can it boot up in safe mode with the use of F8 after the Post Screen?

#5 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 27 May 2011 - 11:55 AM

No. It begins to load all of the necessary files to boot safe mode, goes to the loading windows splash screen with scrolling green light, then I get the 'Windows failed to start' page, it tries to run startup repair, then says 'startup repair cannot repair this computer automatically'. Problem details:

Problem signature:
Problem Event Name: StartupRepairV2
Problem signature 01: AutoFailOver
Problem signature 02: 6.0.6001.18000.6.0.6001.18000
Problem signature 03: 6
Problem signature 04: 327685
Problem signature 05: NoRootCause
Problem signature 06: NoRootCause
Problem signature 07: 0
Problem signature 08: 2
Problem signature 09: WrpRepair
Problem signature 10: 1168
OS Version: 6.0.6001.2.1.0.256.1
Locale ID: 1033

'View advanced options for system repair' reveals
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

'System Restore' gives me the option to restore to two different points:
5.19.11 9:26pm - Install: Avast! Free Antivirus Setup
5.19.11 6:55pm - Install: Avast! Free Antivirus Setup

Picking one of these gives me the options to tick boxes for:
(C:) (System) Ready to restore
Recovery (E:) The disk is not in the selected restore point
Boot (X:) The disk is not in the selected restore point

C: is ticked by default, and from here I'm a bit lost, so I tried using the default settings and it failed. I FAIL!

Thanks for taking the time to try and help cryptodan, I appreciate you are a volunteer doing this off your own back - so thanks man.

#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,703 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:01:51 AM

Posted 28 May 2011 - 04:47 AM

Hi Dr_Million,

Welcome to Bleeping Computer. I will be assisting you with this issue.

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Scan your computer's memory for errors.
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list]

#7 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,703 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:01:51 AM

Posted 28 May 2011 - 04:50 AM

Also I moved your topic to Virus, Spyware, And Malware Removal Logs.

#8 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 07 June 2011 - 09:50 AM

Scan result of Farbars's Recovery Tool (FRST written by farbar) Version 2.0.8
Ran by SYSTEM at 2011-06-07 15:40:22
Running from F:\
Windows Vista ™ Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry ==========================

HKLM\...\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [835584 2007-03-10] (Synaptics, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [150040 2008-08-22] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [170520 2008-08-22] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [145944 2008-08-22] (Intel Corporation)
HKLM\...\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [317280 2008-04-04] (Sony Corporation)
HKLM\...\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [24576 2008-11-27] (Sony Corporation)
HKLM\...\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe [2048352 2010-07-21] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all [1032640 2007-04-23] (Kontiki Inc.)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [58656 2011-04-20] (Apple Inc.)
HKLM\...\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" [37888 2009-07-01] ()
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [Skytel] Skytel.exe
HKLM\...\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [1584640 2009-12-07] (Alcatel-Lucent)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421160 2011-04-27] (Apple Inc.)
HKLM\...\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [963976 2010-12-20] (Malwarebytes Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2011-01-31] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-09-20] (Adobe Systems Incorporated)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKU\Default\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-06] (Sony Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKU\Default User\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-06] (Sony Corporation)
HKU\Lucinda\...\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe" [270336 2008-11-06] (Sony Corporation)
HKU\Lucinda\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Lucinda\...\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2144088 2009-01-26] (Safer Networking Limited)
HKU\Lucinda\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\Lucinda\...\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2424192 2011-05-04] (SUPERAntiSpyware.com)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [318464 2008-01-21] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe, [25088 2008-01-21] (Microsoft Corporation)
HKLM\...\Winlogon: [Shell] explorer.exe [2926592 2009-04-11] (Microsoft Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll [X]
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\VESWinlogon: VESWinlogon.dll (Sony Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
AppInit_DLLs: avgrsstx.dll


========================== Services ==========================

3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
2 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [24576 2006-11-02] (Microsoft Corporation)
3 ALG; C:\Windows\System32\alg.exe [59392 2008-01-21] (Microsoft Corporation)
3 Appinfo; C:\Windows\System32\appinfo.dll [33280 2008-01-21] (Microsoft Corporation)
2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [37664 2011-02-18] (Apple Inc.)
2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation)
2 Audiosrv; C:\Windows\System32\Audiosrv.dll [315392 2009-04-11] (Microsoft Corporation)
2 avg8wd; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [297752 2009-08-28] (AVG Technologies CZ, s.r.o.)
2 BcmSqlStartupSvc; "C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [30312 2008-01-12] (Microsoft Corporation)
2 BFE; C:\Windows\System32\bfe.dll [334848 2009-04-11] (Microsoft Corporation)
2 BITS; C:\Windows\System32\qmgr.dll [758784 2009-04-11] (Microsoft Corporation)
2 Bonjour Service; "C:\Program Files\Bonjour\mDNSResponder.exe" [349472 2011-04-06] (Apple Inc.)
2 Browser; C:\Windows\System32\browser.dll [81920 2008-01-21] (Microsoft Corporation)
3 CertPropSvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation)
3 clr_optimization_v2.0.50727_32; C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [66368 2009-03-30] (Microsoft Corporation)
3 COMSysApp; C:\Windows\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} [7168 2006-11-02] (Microsoft Corporation)
2 CryptSvc; C:\Windows\System32\cryptsvc.dll [129024 2009-04-11] (Microsoft Corporation)
2 DcomLaunch; C:\Windows\System32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation)
3 DFSR; C:\Windows\System32\DFSR.exe [2092544 2009-04-11] (Microsoft Corporation)
2 Dhcp; C:\Windows\System32\dhcpcsvc.dll [204288 2009-04-11] (Microsoft Corporation)
2 Dnscache; C:\Windows\System32\dnsrslvr.dll [86528 2011-03-02] (Microsoft Corporation)
3 dot3svc; C:\Windows\System32\dot3svc.dll [175616 2009-04-11] (Microsoft Corporation)
2 DPS; C:\Windows\System32\dps.dll [134656 2008-01-21] (Microsoft Corporation)
3 EapHost; C:\Windows\System32\eapsvc.dll [57344 2008-01-21] (Microsoft Corporation)
3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [292352 2008-01-21] (Microsoft Corporation)
3 ehSched; C:\Windows\ehome\ehsched.exe [131072 2006-11-02] (Microsoft Corporation)
2 ehstart; C:\Windows\ehome\ehstart.dll [13312 2006-11-02] (Microsoft Corporation)
2 EMDMgmt; C:\Windows\System32\emdmgmt.dll [564224 2009-04-11] (Microsoft Corporation)
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-21] (Microsoft Corporation)
2 EventSystem; C:\Windows\System32\es.dll [268800 2009-04-11] (Microsoft Corporation)
2 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [860160 2008-08-21] (Intel® Corporation)
3 fdPHost; C:\Windows\System32\fdPHost.dll [13312 2008-01-21] (Microsoft Corporation)
2 FDResPub; C:\Windows\System32\fdrespub.dll [27648 2006-11-02] (Microsoft Corporation)
2 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [43904 2009-02-18] (Microsoft Corporation)
3 GoToAssist; "C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe" Start=service [16680 2010-08-19] (Citrix Online, a division of Citrix Systems, Inc.)
2 gpsvc; C:\Windows\System32\gpsvc.dll [576512 2009-04-11] (Microsoft Corporation)
3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [137200 2009-03-07] (Google)
2 hidserv; C:\Windows\System32\hidserv.dll [26112 2009-04-11] (Microsoft Corporation)
3 hkmsvc; C:\Windows\System32\kmsvc.dll [68096 2008-01-21] (Microsoft Corporation)
3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.)
3 idsvc; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" [879448 2009-02-18] (Microsoft Corporation)
2 IKEEXT; C:\Windows\System32\ikeext.dll [438784 2009-04-11] (Microsoft Corporation)
3 IPBusEnum; C:\Windows\System32\ipbusenum.dll [74240 2008-01-21] (Microsoft Corporation)
2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [200704 2010-02-18] (Microsoft Corporation)
3 iPod Service; "C:\Program Files\iPod\bin\iPodService.exe" [820520 2011-04-27] (Apple Inc.)
2 IviRegMgr; "C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [112152 2007-01-05] (InterVideo)
3 KeyIso; C:\Windows\System32\lsass.exe [9728 2009-06-15] (Microsoft Corporation)
2 KtmRm; C:\Windows\System32\msdtckrm.dll [344576 2008-01-21] (Microsoft Corporation)
2 LanmanServer; C:\Windows\System32\srvsvc.dll [125952 2010-09-06] (Microsoft Corporation)
2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [160256 2009-06-10] (Microsoft Corporation)
3 lltdsvc; C:\Windows\System32\lltdsvc.dll [188928 2008-01-21] (Microsoft Corporation)
2 lmhosts; C:\Windows\System32\lmhsvc.dll [18944 2006-11-02] (Microsoft Corporation)
2 McciCMService; "C:\Program Files\Common Files\Motive\McciCMService.exe" [319488 2009-08-14] (Alcatel-Lucent)
4 Mcx2Svc; C:\Windows\System32\Mcx2Svc.dll [53760 2008-01-21] (Microsoft Corporation)
2 MMCSS; C:\Windows\System32\mmcss.dll [45056 2008-01-21] (Microsoft Corporation)
2 MpsSvc; C:\Windows\System32\mpssvc.dll [407552 2009-04-11] (Microsoft Corporation)
3 MSCSPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" [53248 2008-05-20] (Sony Corporation)
3 MSDTC; C:\Windows\System32\msdtc.exe [105984 2008-01-21] (Microsoft Corporation)
3 MSiSCSI; C:\Windows\System32\iscsiexe.dll [111616 2008-01-21] (Microsoft Corporation)
3 MSSQL$MSSMLBIZ; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [29293408 2010-12-10] (Microsoft Corporation)
4 MSSQLServerADHelper; "C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [44384 2010-12-10] (Microsoft Corporation)
3 napagent; C:\Windows\System32\qagentRT.dll [302592 2009-04-11] (Microsoft Corporation)
2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2008-01-16] (Hewlett-Packard)
3 Netlogon; C:\Windows\System32\lsass.exe [9728 2009-06-15] (Microsoft Corporation)
3 Netman; C:\Windows\System32\netman.dll [274432 2008-01-21] (Microsoft Corporation)
2 netprofm; C:\Windows\System32\netprofm.dll [237056 2008-01-21] (Microsoft Corporation)
4 NetTcpPortSharing; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" [129880 2009-02-18] (Microsoft Corporation)
2 NlaSvc; C:\Windows\System32\nlasvc.dll [168448 2008-01-21] (Microsoft Corporation)
2 nsi; C:\Windows\System32\nsisvc.dll [18432 2008-01-21] (Microsoft Corporation)
2 NSUService; "C:\Program Files\sony\Network Utility\NSUService.exe" [303104 2008-11-06] (Sony Corporation)
3 odserv; "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE" [441712 2008-11-04] (Microsoft Corporation)
3 ose; "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" [145184 2006-10-26] (Microsoft Corporation)
3 p2pimsvc; C:\Windows\System32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation)
3 p2psvc; C:\Windows\System32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation)
3 PACSPTISVR; "C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe" [53248 2008-05-20] (Sony Corporation)
2 PcaSvc; C:\Windows\System32\pcasvc.dll [37888 2008-01-21] (Microsoft Corporation)
3 pla; C:\Windows\System32\pla.dll [1502208 2008-01-21] (Microsoft Corporation)
2 PlugPlay; C:\Windows\System32\umpnpmgr.dll [222720 2009-04-11] (Microsoft Corporation)
2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-01-16] (Hewlett-Packard)
3 PNRPAutoReg; C:\Windows\System32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation)
3 PNRPsvc; C:\Windows\System32\p2psvc.dll [644608 2009-04-11] (Microsoft Corporation)
2 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [364032 2009-04-11] (Microsoft Corporation)
2 ProfSvc; C:\Windows\System32\profsvc.dll [153088 2009-04-11] (Microsoft Corporation)
3 ProtectedStorage; C:\Windows\System32\lsass.exe [9728 2009-06-15] (Microsoft Corporation)
3 QWAVE; C:\Windows\system32\qwave.dll [243712 2008-01-21] (Microsoft Corporation)
2 RapportMgmtService; "C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe" [870200 2011-04-28] (Trusteer Ltd.)
3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2008-01-21] (Microsoft Corporation)
3 RasMan; C:\Windows\System32\rasmans.dll [262144 2009-04-11] (Microsoft Corporation)
2 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [466944 2008-08-21] (Intel® Corporation)
4 RemoteAccess; C:\Windows\System32\mprdim.dll [68608 2008-01-21] (Microsoft Corporation)
3 RemoteRegistry; C:\Windows\System32\regsvc.dll [107008 2009-04-11] (Microsoft Corporation)
3 RpcLocator; C:\Windows\System32\locator.exe [7680 2006-11-02] (Microsoft Corporation)
2 RpcSs; C:\Windows\System32\rpcss.dll [550400 2009-04-11] (Microsoft Corporation)
2 RtkAudioService; C:\Windows\RtkAudioService.exe [104992 2008-10-17] (Realtek Semiconductor)
2 SamSs; C:\Windows\System32\lsass.exe [9728 2009-06-15] (Microsoft Corporation)
2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
3 SCardSvr; C:\Windows\System32\SCardSvr.dll [95232 2009-04-11] (Microsoft Corporation)
2 Schedule; C:\Windows\System32\schedsvc.dll [601600 2010-11-04] (Microsoft Corporation)
3 SCPolicySvc; C:\Windows\System32\certprop.dll [40448 2009-04-11] (Microsoft Corporation)
3 SDRSVC; C:\Windows\System32\SDRSVC.dll [104960 2008-01-21] (Microsoft Corporation)
2 seclogon; C:\Windows\system32\seclogon.dll [19968 2008-01-21] (Microsoft Corporation)
2 SENS; C:\Windows\System32\sens.dll [47104 2008-01-21] (Microsoft Corporation)
3 SessionEnv; C:\Windows\System32\sessenv.dll [84992 2008-01-21] (Microsoft Corporation)
4 SharedAccess; C:\Windows\System32\ipnathlp.dll [288256 2008-01-21] (Microsoft Corporation)
2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation)
2 slsvc; C:\Windows\System32\SLsvc.exe [3408896 2009-04-11] (Microsoft Corporation)
3 SLUINotify; C:\Windows\System32\SLUINotify.dll [60928 2009-04-11] (Microsoft Corporation)
3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2006-11-02] (Microsoft Corporation)
3 SOHCImp; "C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe" [103712 2008-10-21] (Sony Corporation)
3 SOHDms; "C:\Program Files\Sony\VAIO Media plus\SOHDms.exe" [353568 2008-10-21] (Sony Corporation)
3 SOHDs; "C:\Program Files\Sony\VAIO Media plus\SOHDs.exe" [62752 2008-10-21] (Sony Corporation)
2 Spooler; C:\Windows\System32\spoolsv.exe [128000 2010-08-17] (Microsoft Corporation)
3 SPTISRV; "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" [77824 2008-05-20] (Sony Corporation)
2 SQLBrowser; "C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [238944 2010-12-10] (Microsoft Corporation)
2 SQLWriter; "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [86880 2010-12-10] (Microsoft Corporation)
3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [155648 2008-01-21] (Microsoft Corporation)
3 SstpSvc; C:\Windows\System32\sstpsvc.dll [116736 2008-01-21] (Microsoft Corporation)
2 stisvc; C:\Windows\System32\wiaservc.dll [453120 2009-04-11] (Microsoft Corporation)
3 swprv; C:\Windows\System32\swprv.dll [311808 2009-04-11] (Microsoft Corporation)
2 SysMain; C:\Windows\System32\sysmain.dll [558080 2009-04-11] (Microsoft Corporation)
2 TabletInputService; C:\Windows\System32\TabSvc.dll [68096 2006-11-02] (Microsoft Corporation)
3 TapiSrv; C:\Windows\System32\tapisrv.dll [242688 2009-04-11] (Microsoft Corporation)
2 TBS; C:\Windows\System32\tbssvc.dll [56320 2008-01-21] (Microsoft Corporation)
2 TermService; C:\Windows\System32\termsrv.dll [449024 2009-04-11] (Microsoft Corporation)
2 Themes; C:\Windows\System32\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation)
3 THREADORDER; C:\Windows\System32\mmcss.dll [45056 2008-01-21] (Microsoft Corporation)
2 TrkWks; C:\Windows\System32\trkwks.dll [75264 2008-01-21] (Microsoft Corporation)
3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [39424 2009-04-11] (Microsoft Corporation)
2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
3 UI0Detect; C:\Windows\System32\UI0Detect.exe [35840 2008-01-21] (Microsoft Corporation)
3 upnphost; C:\Windows\System32\upnphost.dll [259072 2008-01-21] (Microsoft Corporation)
2 UxSms; C:\Windows\System32\uxsms.dll [29184 2009-04-11] (Microsoft Corporation)
3 VAIO Entertainment TV Device Arbitration Service; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe" [73728 2008-09-08] (Sony Corporation)
2 VAIO Event Service; "C:\Program Files\sony\VAIO Event Service\VESMgr.exe" [203624 2008-11-06] (Sony Corporation)
2 VAIO Power Management; "C:\Program Files\Sony\VAIO Power Management\SPMService.exe" [411488 2008-09-05] (Sony Corporation)
2 VCFw; "C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe" [446464 2008-09-12] (Sony Corporation)
2 VcmIAlzMgr; "C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [337184 2008-06-12] (Sony Corporation)
3 VcmXmlIfHelper; "C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [83232 2008-06-12] (Sony Corporation)
3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM [279848 2008-09-08] (Sony Corporation)
3 vds; C:\Windows\System32\vds.exe [385536 2009-04-11] (Microsoft Corporation)
3 VSS; C:\Windows\System32\vssvc.exe [1055232 2009-04-11] (Microsoft Corporation)
3 VUAgent; "C:\Program Files\sony\VAIO Update 5\VUAgent.exe" [722288 2010-04-09] (Sony Corporation)
2 VzCdbSvc; "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" [192512 2008-09-08] (Sony Corporation)
2 W32Time; C:\Windows\System32\w32time.dll [282624 2009-04-11] (Microsoft Corporation)
3 wcncsvc; C:\Windows\System32\wcncsvc.dll [413696 2009-04-11] (Microsoft Corporation)
3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32256 2006-11-02] (Microsoft Corporation)
3 WdiServiceHost; C:\Windows\System32\wdi.dll [73728 2008-01-21] (Microsoft Corporation)
3 WdiSystemHost; C:\Windows\System32\wdi.dll [73728 2008-01-21] (Microsoft Corporation)
2 WebClient; C:\Windows\System32\webclnt.dll [199680 2009-04-11] (Microsoft Corporation)
3 Wecsvc; C:\Windows\System32\wecsvc.dll [145408 2008-01-21] (Microsoft Corporation)
3 wercplsupport; C:\Windows\System32\wercplsupport.dll [62976 2008-01-21] (Microsoft Corporation)
2 WerSvc; C:\Windows\System32\WerSvc.dll [126976 2009-04-11] (Microsoft Corporation)
2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
3 WinHttpAutoProxySvc; winhttp.dll [377344 2009-08-24] (Microsoft Corporation)
2 Winmgmt; C:\Windows\System32\wbem\WMIsvc.dll [162304 2009-04-11] (Microsoft Corporation)
3 WinRM; C:\Windows\System32\WsmSvc.dll [747008 2009-04-11] (Microsoft Corporation)
2 Wlansvc; C:\Windows\System32\wlansvc.dll [513536 2009-07-11] (Microsoft Corporation)
3 wmiApSrv; C:\Windows\System32\wbem\WmiApSrv.exe [137728 2009-04-11] (Microsoft Corporation)
3 WMPNetworkSvc; "C:\Program Files\Windows Media Player\wmpnetwk.exe" [896512 2008-01-21] (Microsoft Corporation)
3 WPCSvc; C:\Windows\System32\wpcsvc.dll [140288 2009-04-11] (Microsoft Corporation)
2 WPDBusEnum; C:\Windows\System32\wpdbusenum.dll [70144 2008-01-21] (Microsoft Corporation)
2 wscsvc; C:\Windows\System32\wscsvc.dll [61440 2009-04-11] (Microsoft Corporation)
2 WSearch; C:\Windows\System32\SearchIndexer.exe /Embedding [441344 2009-04-11] (Microsoft Corporation)
2 wuauserv; C:\Windows\System32\wuaueng.dll [1929952 2009-08-07] (Microsoft Corporation)
2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [55296 2008-01-21] (Microsoft Corporation)
2 XAudioService; C:\Windows\System32\DRIVERS\xaudio.exe [386560 2008-01-25] (Conexant Systems, Inc.)

========================== Drivers ===========================

0 ACPI; C:\Windows\System32\drivers\acpi.sys [265688 2009-04-11] (Microsoft Corporation)
4 adp94xx; C:\Windows\System32\drivers\adp94xx.sys [422968 2008-01-21] (Adaptec, Inc.)
4 adpahci; C:\Windows\System32\drivers\adpahci.sys [300600 2008-01-21] (Adaptec, Inc.)
4 adpu160m; C:\Windows\System32\drivers\adpu160m.sys [101432 2008-01-21] (Adaptec, Inc.)
4 adpu320; C:\Windows\System32\drivers\adpu320.sys [149560 2008-01-21] (Adaptec, Inc.)
1 AFD; C:\Windows\System32\drivers\afd.sys [273920 2009-04-11] (Microsoft Corporation)
3 agp440; C:\Windows\System32\drivers\agp440.sys [56376 2008-01-21] (Microsoft Corporation)
4 aic78xx; C:\Windows\System32\drivers\djsvs.sys [71272 2006-11-02] (Adaptec, Inc.)
4 aliide; C:\Windows\System32\drivers\aliide.sys [17464 2008-01-21] (Acer Laboratories Inc.)
3 amdagp; C:\Windows\System32\drivers\amdagp.sys [57400 2008-01-21] (Microsoft Corporation)
4 amdide; C:\Windows\System32\drivers\amdide.sys [17976 2008-01-21] (Microsoft Corporation)
4 AmdK7; C:\Windows\System32\drivers\amdk7.sys [41472 2008-01-21] (Microsoft Corporation)
4 AmdK8; C:\Windows\System32\drivers\amdk8.sys [44032 2008-01-21] (Microsoft Corporation)
4 arc; C:\Windows\System32\drivers\arc.sys [79416 2008-01-21] (Adaptec, Inc.)
4 arcsas; C:\Windows\System32\drivers\arcsas.sys [79928 2008-01-21] (Adaptec, Inc.)
3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.)
3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17408 2008-01-21] (Microsoft Corporation)
4 atapi; C:\Windows\System32\drivers\atapi.sys [21560 2008-01-21] (Microsoft Corporation)
3 athr; C:\Windows\System32\DRIVERS\athr.sys [909824 2008-06-10] (Atheros Communications, Inc.)
3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [3847168 2008-10-07] (ATI Technologies Inc.)
1 AvgLdx86; C:\Windows\System32\Drivers\avgldx86.sys [335240 2009-08-28] (AVG Technologies CZ, s.r.o.)
1 AvgMfx86; C:\Windows\System32\Drivers\avgmfx86.sys [27784 2009-08-28] (AVG Technologies CZ, s.r.o.)
1 Beep; C:\Windows\System32\Drivers\Beep.sys [6144 2008-01-21] (Microsoft Corporation)
4 blbdrive; C:\Windows\System32\drivers\blbdrive.sys [45568 2008-01-21] (Microsoft Corporation)
3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2011-02-22] (Microsoft Corporation)
3 BrFiltLo; C:\Windows\System32\drivers\brfiltlo.sys [13568 2006-11-02] (Brother Industries, Ltd.)
3 BrFiltUp; C:\Windows\System32\drivers\brfiltup.sys [5248 2006-11-02] (Brother Industries, Ltd.)
4 Brserid; C:\Windows\System32\drivers\brserid.sys [71808 2006-11-02] (Brother Industries Ltd.)
4 BrSerWdm; C:\Windows\System32\drivers\brserwdm.sys [62336 2006-11-02] (Brother Industries Ltd.)
4 BrUsbMdm; C:\Windows\System32\drivers\brusbmdm.sys [12160 2006-11-02] (Brother Industries Ltd.)
3 BrUsbSer; C:\Windows\System32\drivers\brusbser.sys [11904 2006-11-02] (Brother Industries Ltd.)
4 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [39936 2006-11-02] (Microsoft Corporation)
4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70144 2008-01-21] (Microsoft Corporation)
1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [67072 2009-04-11] (Microsoft Corporation)
4 circlass; C:\Windows\System32\drivers\circlass.sys [35328 2008-01-21] (Microsoft Corporation)
0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14208 2008-01-21] (Microsoft Corporation)
4 cmdide; C:\Windows\System32\drivers\cmdide.sys [19000 2008-01-21] (CMD Technology, Inc.)
0 Compbatt; C:\Windows\System32\DRIVERS\compbatt.sys [20792 2008-01-21] (Microsoft Corporation)
0 crcdisk; C:\Windows\System32\drivers\crcdisk.sys [24632 2008-01-21] (Microsoft Corporation)
4 Crusoe; C:\Windows\System32\drivers\crusoe.sys [40960 2008-01-21] (Microsoft Corporation)
1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [75264 2009-04-11] (Microsoft Corporation)
0 disk; C:\Windows\System32\drivers\disk.sys [53736 2009-04-11] (Microsoft Corporation)
1 DMICall; C:\Windows\System32\DRIVERS\DMICall.sys [10216 2008-08-23] (Sony Corporation)
3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5632 2008-01-21] (Microsoft Corporation)
3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [626176 2009-04-11] (Microsoft Corporation)
3 E1G60; C:\Windows\System32\DRIVERS\E1G60I32.sys [118784 2008-01-21] (Intel Corporation)
0 Ecache; C:\Windows\System32\drivers\ecache.sys [141288 2009-04-11] (Microsoft Corporation)
4 elxstor; C:\Windows\System32\drivers\elxstor.sys [342584 2008-01-21] (Emulex)
4 ErrDev; C:\Windows\System32\drivers\errdev.sys [6656 2008-01-21] (Microsoft Corporation)
3 exfat; C:\Windows\System32\Drivers\exfat.sys [136704 2009-04-11] (Microsoft Corporation)
3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [142848 2009-04-11] (Microsoft Corporation)
4 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2008-01-21] (Microsoft Corporation)
0 FileInfo; C:\Windows\System32\drivers\fileinfo.sys [58936 2008-01-21] (Microsoft Corporation)
3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [27648 2008-01-21] (Microsoft Corporation)
4 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [20480 2008-01-21] (Microsoft Corporation)
0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Microsoft Corporation)
1 Fs_Rec; C:\Windows\System32\Drivers\Fs_Rec.sys [12800 2008-01-21] (Microsoft Corporation)
3 gagp30kx; C:\Windows\System32\drivers\gagp30kx.sys [61496 2008-01-21] (Microsoft Corporation)
3 GEARAspiWDM; C:\Windows\System32\DRIVERS\GEARAspiWDM.sys [26600 2009-05-18] (GEAR Software Inc.)
3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [235520 2006-11-02] (Microsoft Corporation)
3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [561152 2009-04-11] (Microsoft Corporation)
4 HidBth; C:\Windows\System32\drivers\hidbth.sys [29184 2006-11-02] (Microsoft Corporation)
4 HidIr; C:\Windows\System32\drivers\hidir.sys [21504 2006-11-02] (Microsoft Corporation)
3 HidUsb; C:\Windows\System32\DRIVERS\hidusb.sys [12800 2009-04-11] (Microsoft Corporation)
4 HpCISSs; C:\Windows\System32\drivers\hpcisss.sys [40504 2008-01-21] (Hewlett-Packard Company)
3 HSFHWAZL; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [200704 2008-01-21] (Conexant Systems, Inc.)
3 HSF_DPV; C:\Windows\System32\DRIVERS\HSX_DPV.sys [985600 2008-01-25] (Conexant Systems, Inc.)
3 HSXHWAZL; C:\Windows\System32\DRIVERS\HSXHWAZL.sys [207360 2008-01-25] (Conexant Systems, Inc.)
3 HTTP; C:\Windows\System32\drivers\HTTP.sys [411648 2010-02-20] (Microsoft Corporation)
4 i2omp; C:\Windows\System32\drivers\i2omp.sys [30264 2008-01-21] (Microsoft Corporation)
1 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [54784 2008-01-21] (Microsoft Corporation)
0 iaStor; C:\Windows\System32\DRIVERS\iaStor.sys [312344 2008-04-22] (Intel Corporation)
4 iaStorV; C:\Windows\System32\drivers\iastorv.sys [235064 2008-01-21] (Intel Corporation)
3 igfx; C:\Windows\System32\DRIVERS\igdkmd32.sys [2377216 2008-08-22] (Intel Corporation)
4 iirsp; C:\Windows\System32\drivers\iirsp.sys [41576 2006-11-02] (Intel Corp./ICP vortex GmbH)
3 IntcAzAudAddService; C:\Windows\System32\drivers\RTKVHDA.sys [2149912 2008-10-17] (Realtek Semiconductor Corp.)
4 intelide; C:\Windows\System32\drivers\intelide.sys [17976 2008-01-21] (Microsoft Corporation)
3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [41472 2008-01-21] (Microsoft Corporation)
4 IPMIDRV; C:\Windows\System32\drivers\ipmidrv.sys [64512 2008-01-21] (Microsoft Corporation)
3 IPNAT; C:\Windows\System32\DRIVERS\ipnat.sys [100864 2008-01-21] (Microsoft Corporation)
3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13312 2008-01-21] (Microsoft Corporation)
4 isapnp; C:\Windows\System32\drivers\isapnp.sys [49720 2008-01-21] (Microsoft Corporation)
3 iScsiPrt; C:\Windows\System32\DRIVERS\msiscsi.sys [180712 2009-04-11] (Microsoft Corporation)
4 iteatapi; C:\Windows\System32\drivers\iteatapi.sys [35944 2006-11-02] (Integrated Technology Express, Inc.)
4 iteraid; C:\Windows\System32\drivers\iteraid.sys [35944 2006-11-02] (Integrated Technology Express, Inc.)
1 kbdclass; C:\Windows\System32\DRIVERS\kbdclass.sys [35384 2008-01-21] (Microsoft Corporation)
4 kbdhid; C:\Windows\System32\drivers\kbdhid.sys [15872 2008-01-21] (Microsoft Corporation)
0 KSecDD; C:\Windows\System32\Drivers\ksecdd.sys [439864 2009-06-16] (Microsoft Corporation)
2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [47104 2008-01-21] (Microsoft Corporation)
4 LSI_FC; C:\Windows\System32\drivers\lsi_fc.sys [96312 2008-01-21] (LSI Logic)
4 LSI_SAS; C:\Windows\System32\drivers\lsi_sas.sys [89656 2008-01-21] (LSI Logic)
4 LSI_SCSI; C:\Windows\System32\drivers\lsi_scsi.sys [96312 2008-01-21] (LSI Logic)
2 luafv; C:\Windows\System32\drivers\luafv.sys [84480 2008-01-21] (Microsoft Corporation)
2 mdmxsdk; C:\Windows\System32\DRIVERS\mdmxsdk.sys [12672 2008-01-25] (Conexant)
4 megasas; C:\Windows\System32\drivers\megasas.sys [31288 2008-01-21] (LSI Corporation)
4 MegaSR; C:\Windows\System32\drivers\megasr.sys [386616 2008-01-21] (LSI Corporation, Inc.)
3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2008-01-21] (Microsoft Corporation)
3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [41984 2008-01-21] (Microsoft Corporation)
1 mouclass; C:\Windows\System32\DRIVERS\mouclass.sys [34360 2008-01-21] (Microsoft Corporation)
3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [15872 2008-01-21] (Microsoft Corporation)
0 MountMgr; C:\Windows\System32\drivers\mountmgr.sys [57400 2008-01-21] (Microsoft Corporation)
4 mpio; C:\Windows\System32\drivers\mpio.sys [105016 2008-01-21] (Microsoft Corporation)
3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [64000 2008-01-21] (Microsoft Corporation)
4 Mraid35x; C:\Windows\System32\drivers\mraid35x.sys [33384 2006-11-02] (LSI Logic Corporation)
3 MREMP50; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [21248 2009-12-07] (Printing Communications Assoc., Inc. (PCAUSA))
3 MRESP50; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [20096 2009-12-07] (Printing Communications Assoc., Inc. (PCAUSA))
3 MRxDAV; C:\Windows\System32\drivers\mrxdav.sys [114688 2009-04-11] (Microsoft Corporation)
3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [106496 2011-02-22] (Microsoft Corporation)
3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [213504 2011-02-22] (Microsoft Corporation)
3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [79360 2011-02-22] (Microsoft Corporation)
4 msahci; C:\Windows\System32\drivers\msahci.sys [28728 2008-01-21] (Microsoft Corporation)
4 msdsm; C:\Windows\System32\drivers\msdsm.sys [94776 2008-01-21] (Microsoft Corporation)
1 Msfs; C:\Windows\System32\Drivers\Msfs.sys [22528 2008-01-21] (Microsoft Corporation)
0 msisadrv; C:\Windows\System32\drivers\msisadrv.sys [16440 2008-01-21] (Microsoft Corporation)
3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8192 2008-01-21] (Microsoft Corporation)
3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2008-01-21] (Microsoft Corporation)
3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2008-01-21] (Microsoft Corporation)
3 MsRPC; C:\Windows\System32\Drivers\MsRPC.sys [161752 2009-04-11] (Microsoft Corporation)
3 mssmbios; C:\Windows\System32\DRIVERS\mssmbios.sys [31288 2008-01-21] (Microsoft Corporation)
3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6016 2008-01-21] (Microsoft Corporation)
0 Mup; C:\Windows\System32\Drivers\mup.sys [48104 2009-04-11] (Microsoft Corporation)
3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [148480 2009-04-11] (Microsoft Corporation)
0 NDIS; C:\Windows\System32\drivers\ndis.sys [527848 2009-04-11] (Microsoft Corporation)
3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2008-01-21] (Microsoft Corporation)
3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [16896 2008-01-21] (Microsoft Corporation)
3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [121344 2009-04-11] (Microsoft Corporation)
3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [49664 2008-01-21] (Microsoft Corporation)
1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [35840 2008-01-21] (Microsoft Corporation)
1 netbt; C:\Windows\System32\DRIVERS\netbt.sys [185856 2009-04-11] (Microsoft Corporation)
3 NETw5v32; C:\Windows\System32\DRIVERS\NETw5v32.sys [3664384 2008-08-29] (Intel Corporation)
4 nfrd960; C:\Windows\System32\drivers\nfrd960.sys [45160 2006-11-02] (IBM Corporation)
1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [35328 2009-04-11] (Microsoft Corporation)
1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16384 2008-01-21] (Microsoft Corporation)
3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1083880 2009-04-11] (Microsoft Corporation)
4 ntrigdigi; C:\Windows\System32\drivers\ntrigdigi.sys [20608 2006-11-02] (N-trig Innovative Technologies)
1 Null; C:\Windows\System32\Drivers\Null.sys [4608 2008-01-21] (Microsoft Corporation)
4 nvraid; C:\Windows\System32\drivers\nvraid.sys [102968 2008-01-21] (NVIDIA Corporation)
4 nvstor; C:\Windows\System32\drivers\nvstor.sys [45112 2008-01-21] (NVIDIA Corporation)
3 nv_agp; C:\Windows\System32\drivers\nv_agp.sys [109112 2008-01-21] (Microsoft Corporation)
3 ohci1394; C:\Windows\System32\DRIVERS\ohci1394.sys [62208 2009-04-11] (Microsoft Corporation)
3 Parport; C:\Windows\System32\drivers\parport.sys [79360 2006-11-02] (Microsoft Corporation)
0 partmgr; C:\Windows\System32\drivers\partmgr.sys [54248 2009-04-11] (Microsoft Corporation)
2 Parvdm; C:\Windows\System32\drivers\parvdm.sys [8704 2006-11-02] (Microsoft Corporation)
0 pci; C:\Windows\System32\drivers\pci.sys [149480 2009-04-11] (Microsoft Corporation)
4 pciide; C:\Windows\System32\drivers\pciide.sys [16440 2008-01-21] (Microsoft Corporation)
4 pcmcia; C:\Windows\System32\drivers\pcmcia.sys [167528 2006-11-02] (Microsoft Corporation)
2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [878080 2006-11-02] (Microsoft Corporation)
3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [62976 2008-01-21] (Microsoft Corporation)
4 Processor; C:\Windows\System32\drivers\processr.sys [40960 2008-01-21] (Microsoft Corporation)
1 PSched; C:\Windows\System32\DRIVERS\pacer.sys [72192 2009-04-11] (Microsoft Corporation)
0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [44944 2008-06-16] (Sonic Solutions)
4 ql2300; C:\Windows\System32\drivers\ql2300.sys [1122360 2008-01-21] (QLogic Corporation)
4 ql40xx; C:\Windows\System32\drivers\ql40xx.sys [106088 2006-11-02] (QLogic Corporation)
3 QWAVEdrv; C:\Windows\System32\drivers\qwavedrv.sys [31232 2008-01-21] (Microsoft Corporation)
1 RapportCerberus_26169; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\26169\RapportCerberus_26169.sys [57144 2011-05-02] (Trusteer Ltd.)
1 RapportEI; \??\C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [66360 2011-04-28] (Trusteer Ltd.)
0 RapportKELL; C:\Windows\System32\Drivers\RapportKELL.sys [53816 2011-04-28] (Trusteer Ltd.)
1 RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [158904 2011-04-28] (Trusteer Ltd.)
1 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2008-01-21] (Microsoft Corporation)
3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [76288 2008-01-21] (Microsoft Corporation)
3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [41472 2009-04-11] (Microsoft Corporation)
3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [69120 2009-04-11] (Microsoft Corporation)
1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [225280 2009-04-11] (Microsoft Corporation)
1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6144 2008-01-21] (Microsoft Corporation)
4 rdpdr; C:\Windows\System32\drivers\rdpdr.sys [248832 2008-01-21] (Microsoft Corporation)
1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6144 2008-01-21] (Microsoft Corporation)
3 RDPWD; C:\Windows\System32\Drivers\RDPWD.sys [180736 2009-04-11] (Microsoft Corporation)
2 regi; C:\Windows\System32\drivers\regi.sys [11032 2007-04-18] (InterVideo)
2 rimsptsk; C:\Windows\System32\DRIVERS\rimsptsk.sys [68608 2008-06-28] (REDC)
2 risdptsk; C:\Windows\System32\DRIVERS\risdptsk.sys [46592 2008-10-03] (REDC)
2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60416 2008-01-21] (Microsoft Corporation)
3 s217bus; C:\Windows\System32\DRIVERS\s217bus.sys [83496 2007-11-02] (MCCI Corporation)
3 s217mdfl; C:\Windows\System32\DRIVERS\s217mdfl.sys [15016 2007-11-02] (MCCI Corporation)
3 s217mdm; C:\Windows\System32\DRIVERS\s217mdm.sys [109992 2007-11-02] (MCCI Corporation)
3 s217mgmt; C:\Windows\System32\DRIVERS\s217mgmt.sys [103976 2007-11-02] (MCCI Corporation)
3 s217nd5; C:\Windows\System32\DRIVERS\s217nd5.sys [24872 2007-11-02] (MCCI Corporation)
3 s217obex; C:\Windows\System32\DRIVERS\s217obex.sys [100008 2007-11-02] (MCCI Corporation)
3 s217unic; C:\Windows\System32\DRIVERS\s217unic.sys [105896 2007-11-02] (MCCI)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67656 2010-05-10] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
4 sbp2port; C:\Windows\System32\drivers\sbp2port.sys [76392 2006-11-02] (Microsoft Corporation)
4 sdbus; C:\Windows\System32\DRIVERS\sdbus.sys [88576 2008-01-21] (Microsoft Corporation)
2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [20480 2006-11-02] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
3 Serenum; C:\Windows\System32\drivers\serenum.sys [17920 2006-11-02] (Microsoft Corporation)
3 Serial; C:\Windows\System32\drivers\serial.sys [83456 2006-11-02] (Microsoft Corporation)
4 sermouse; C:\Windows\System32\drivers\sermouse.sys [19968 2008-01-21] (Microsoft Corporation)
3 SFEP; C:\Windows\System32\DRIVERS\SFEP.sys [9344 2008-08-22] (Sony Corporation)
4 sffdisk; C:\Windows\System32\drivers\sffdisk.sys [13312 2008-01-21] (Microsoft Corporation)
3 sffp_mmc; C:\Windows\System32\drivers\sffp_mmc.sys [12288 2008-01-21] (Microsoft Corporation)
3 sffp_sd; C:\Windows\System32\drivers\sffp_sd.sys [11776 2008-01-21] (Microsoft Corporation)
3 sfloppy; C:\Windows\System32\DRIVERS\sfloppy.sys [13312 2008-01-21] (Microsoft Corporation)
3 sisagp; C:\Windows\System32\drivers\sisagp.sys [55864 2008-01-21] (Microsoft Corporation)
4 SiSRaid2; C:\Windows\System32\drivers\sisraid2.sys [41016 2008-01-21] (Microsoft Corporation)
4 SiSRaid4; C:\Windows\System32\drivers\sisraid4.sys [74808 2008-01-21] (Silicon Integrated Systems)
1 Smb; C:\Windows\System32\DRIVERS\smb.sys [66560 2009-04-11] (Microsoft Corporation)
0 spldr; C:\Windows\System32\Drivers\spldr.sys [21048 2008-01-21] (Microsoft Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2010-01-16] (Duplex Secure Ltd.)
3 srv; C:\Windows\System32\DRIVERS\srv.sys [305152 2011-02-18] (Microsoft Corporation)
3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [146432 2011-02-18] (Microsoft Corporation)
3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [102400 2011-02-18] (Microsoft Corporation)
3 StillCam; C:\Windows\System32\DRIVERS\serscan.sys [9216 2008-01-21] (Microsoft Corporation)
3 swenum; C:\Windows\System32\DRIVERS\swenum.sys [15288 2008-01-21] (Microsoft Corporation)
4 Symc8xx; C:\Windows\System32\drivers\symc8xx.sys [35944 2006-11-02] (LSI Logic)
4 Sym_hi; C:\Windows\System32\drivers\sym_hi.sys [31848 2006-11-02] (LSI Logic)
4 Sym_u3; C:\Windows\System32\drivers\sym_u3.sys [34920 2006-11-02] (LSI Logic)
3 SynTP; C:\Windows\System32\DRIVERS\SynTP.sys [181560 2007-03-10] (Synaptics, Inc.)
0 Tcpip; C:\Windows\System32\drivers\tcpip.sys [905088 2010-06-16] (Microsoft Corporation)
3 Tcpip6; C:\Windows\System32\DRIVERS\tcpip.sys [905088 2010-06-16] (Microsoft Corporation)
2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [30720 2009-12-08] (Microsoft Corporation)
3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [17920 2008-01-21] (Microsoft Corporation)
3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [29184 2008-01-21] (Microsoft Corporation)
1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [72192 2009-04-11] (Microsoft Corporation)
1 TermDD; C:\Windows\System32\DRIVERS\termdd.sys [53224 2009-04-11] (Microsoft Corporation)
3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [23552 2008-01-21] (Microsoft Corporation)
3 tunmp; C:\Windows\System32\DRIVERS\tunmp.sys [15360 2008-01-21] (Microsoft Corporation)
3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [25088 2010-02-18] (Microsoft Corporation)
3 uagp35; C:\Windows\System32\drivers\uagp35.sys [59448 2008-01-21] (Microsoft Corporation)
4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [226816 2009-04-11] (Microsoft Corporation)
3 uliagpkx; C:\Windows\System32\drivers\uliagpkx.sys [60984 2008-01-21] (Microsoft Corporation)
4 uliahci; C:\Windows\System32\drivers\uliahci.sys [238648 2008-01-21] (ULi Electronics Inc.)
4 UlSata; C:\Windows\System32\drivers\ulsata.sys [98408 2006-11-02] (Promise Technology, Inc.)
4 ulsata2; C:\Windows\System32\drivers\ulsata2.sys [115816 2008-01-21] (Promise Technology, Inc.)
3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [34816 2008-01-21] (Microsoft Corporation)
3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [41472 2009-10-16] (Apple, Inc.)
3 usbaudio; C:\Windows\System32\drivers\usbaudio.sys [73216 2009-04-11] (Microsoft Corporation)
3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [73216 2008-01-21] (Microsoft Corporation)
4 usbcir; C:\Windows\System32\drivers\usbcir.sys [68608 2006-11-02] (Microsoft Corporation)
3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [39936 2009-04-11] (Microsoft Corporation)
3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [196096 2009-04-11] (Microsoft Corporation)
4 usbohci; C:\Windows\System32\drivers\usbohci.sys [19456 2006-11-02] (Microsoft Corporation)
3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [18944 2008-01-21] (Microsoft Corporation)
3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [65536 2009-04-11] (Microsoft Corporation)
3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [23552 2008-01-21] (Microsoft Corporation)
3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [134016 2008-01-21] (Microsoft Corporation)
3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2008-01-21] (Microsoft Corporation)
1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2008-01-21] (Microsoft Corporation)
3 viaagp; C:\Windows\System32\drivers\viaagp.sys [56888 2008-01-21] (Microsoft Corporation)
4 ViaC7; C:\Windows\System32\drivers\viac7.sys [41472 2008-01-21] (Microsoft Corporation)
4 viaide; C:\Windows\System32\drivers\viaide.sys [20024 2008-01-21] (VIA Technologies, Inc.)
0 volmgr; C:\Windows\System32\drivers\volmgr.sys [52792 2008-01-21] (Microsoft Corporation)
0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [292840 2009-04-11] (Microsoft Corporation)
0 volsnap; C:\Windows\System32\drivers\volsnap.sys [226280 2009-04-11] ()
4 vsmraid; C:\Windows\System32\drivers\vsmraid.sys [130616 2008-01-21] (VIA Technologies Inc.,Ltd)
4 WacomPen; C:\Windows\System32\drivers\wacompen.sys [20608 2006-11-02] (Microsoft Corporation)
3 Wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-21] (Microsoft Corporation)
1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-21] (Microsoft Corporation)
4 Wd; C:\Windows\System32\drivers\wd.sys [22072 2008-01-21] (Microsoft Corporation)
0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [503864 2008-01-21] (Microsoft Corporation)
3 WimFltr; C:\Windows\System32\DRIVERS\wimfltr.sys [131000 2008-06-07] (Microsoft Corporation)
3 winachsf; C:\Windows\System32\DRIVERS\HSX_CNXT.sys [659968 2008-01-25] (Conexant Systems, Inc.)
4 WmiAcpi; C:\Windows\System32\drivers\wmiacpi.sys [11264 2008-01-21] (Microsoft Corporation)
3 WpdUsb; C:\Windows\System32\DRIVERS\wpdusb.sys [39936 2008-01-21] (Microsoft Corporation)
4 ws2ifsl; C:\Windows\System32\drivers\ws2ifsl.sys [15872 2008-01-21] (Microsoft Corporation)
3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [83328 2008-01-21] (Microsoft Corporation)
2 XAudio; C:\Windows\System32\DRIVERS\xaudio.sys [8192 2008-01-25] (Conexant Systems, Inc.)
3 yukonwlh; C:\Windows\System32\DRIVERS\yk60x86.sys [310272 2008-05-28] (Marvell)
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
3 msiserver; C:\Windows\System32\msiexec /V [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
4 UIUSys; C:\Windows\System32\DRIVERS\UIUSYS.SYS [x]

========================= NetSvcs ============================

============ One Month Created Files and folders =============

2011-06-07 15:40 - 2011-06-07 15:40 - 0000000 ____D C:\FRST
2011-05-19 22:09 - 2011-05-19 22:09 - 1677328 ___AH C:\Users\Lucinda\AppData\Local\IconCache.db
2011-05-19 21:16 - 2011-05-22 19:33 - 3081801728 __ASH C:\hiberfil.sys
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\Users\All Users\AVAST Software
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\ProgramData\AVAST Software
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\Program Files\AVAST Software
2011-05-19 18:42 - 2011-05-19 18:42 - 56923744 ____A C:\Users\Lucinda\Desktop\setup_av_free.exe
2011-05-19 18:12 - 2011-05-19 18:13 - 1930720 ____A (Symantec Corporation) C:\Users\Lucinda\Desktop\FixTDSS.exe
2011-05-18 23:05 - 2011-05-18 23:05 - 0002855 ____A C:\Users\Lucinda\Desktop\abc123.PIF
2011-05-18 22:49 - 2011-05-18 22:49 - 0001800 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Program Files\SUPERAntiSpyware
2011-05-18 22:48 - 2011-05-18 22:49 - 11166400 ____A (SUPERAntiSpyware.com) C:\Users\Lucinda\Desktop\SAS.exe
2011-05-18 22:36 - 2011-05-18 22:36 - 1407280 ____A (Kaspersky Lab ZAO) C:\Users\Lucinda\Desktop\abc123.com
2011-05-18 22:33 - 2011-05-18 22:33 - 0000000 _RASH C:\MSDOS.SYS
2011-05-18 22:33 - 2011-05-18 22:33 - 0000000 _RASH C:\IO.SYS
2011-05-18 22:32 - 2011-05-18 22:32 - 0000000 ___HD C:\Windows\PIF
2011-05-18 18:54 - 2011-05-18 18:54 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2011-05-18 18:52 - 2011-05-18 18:52 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_07_00.Wdf
2011-05-18 18:39 - 2011-05-18 18:39 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2011-05-18 18:32 - 2011-05-18 18:37 - 0004072 ____A C:\Windows\IE9_main.log
2011-05-18 17:48 - 2011-02-02 18:11 - 0222080 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2011-05-18 17:38 - 2011-05-18 17:40 - 0001887 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2011-05-18 17:37 - 2011-05-18 17:38 - 0000000 ____D C:\Program Files\Common Files\Adobe
2011-05-18 15:41 - 2011-05-18 15:41 - 0000906 ____A C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Users\All Users\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\ProgramData\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2011-05-18 15:41 - 2010-12-20 18:09 - 0038224 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2011-05-18 15:36 - 2011-05-18 15:37 - 0134000 ____A C:\Windows\Minidump\Mini051811-01.dmp
2011-05-18 15:36 - 2011-05-18 15:36 - 248191849 ____A C:\Windows\MEMORY.DMP
2011-05-18 15:36 - 2011-05-18 15:36 - 0000000 ____D C:\Windows\Minidump
2011-05-18 15:22 - 2011-05-18 22:43 - 0000370 ____A C:\rkill.log
2011-05-18 15:21 - 2011-05-18 15:14 - 1006778 ____A C:\Users\Lucinda\Desktop\iExplore.exe
2011-05-18 15:21 - 2011-05-18 14:59 - 7734208 ____A (Malwarebytes Corporation ) C:\Users\Lucinda\Desktop\mbam-setup-1.50.1.1100.exe
2011-05-18 15:21 - 2011-05-18 14:41 - 1402880 ____A C:\Users\Lucinda\Desktop\HiJackThis.msi
2011-05-13 14:09 - 2011-05-13 14:11 - 0000000 ____D C:\Program Files\iTunes
2011-05-13 14:09 - 2011-05-13 14:09 - 0000000 ____D C:\Program Files\iPod
2011-05-13 13:53 - 2011-05-13 13:53 - 0000000 ____D C:\Program Files\Bonjour

============ 3 Months Modified Files and folders =============

2011-05-23 16:50 - 2009-03-14 18:33 - 0000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2011-05-23 16:50 - 2009-03-14 18:33 - 0000000 ____D C:\ProgramData\Spybot - Search & Destroy
2011-05-23 16:50 - 2009-03-14 18:16 - 0000000 ____D C:\Windows\System32\Drivers\Avg
2011-05-23 16:50 - 2009-03-06 21:52 - 0000000 ____D C:\users\Lucinda
2011-05-23 16:50 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\System32\wbem
2011-05-23 16:50 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\System32\spool
2011-05-23 16:50 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\System32\Msdtc
2011-05-23 16:50 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\registration
2011-05-22 19:33 - 2011-05-19 21:16 - 3081801728 __ASH C:\hiberfil.sys
2011-05-19 22:09 - 2011-05-19 22:09 - 1677328 ___AH C:\Users\Lucinda\AppData\Local\IconCache.db
2011-05-19 22:09 - 2008-12-18 10:41 - 2030800 ____A C:\Windows\WindowsUpdate.log
2011-05-19 21:23 - 2006-11-02 11:33 - 0760648 ____A C:\Windows\System32\PerfStringBackup.INI
2011-05-19 21:23 - 2006-11-02 11:33 - 0649990 ____A C:\Windows\System32\perfh009.dat
2011-05-19 21:23 - 2006-11-02 11:33 - 0124218 ____A C:\Windows\System32\perfc009.dat
2011-05-19 21:16 - 2006-11-02 14:01 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2011-05-19 21:16 - 2006-11-02 13:47 - 0003616 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2011-05-19 21:16 - 2006-11-02 13:47 - 0003616 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2011-05-19 21:08 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\System32\LogFiles
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\Users\All Users\AVAST Software
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\ProgramData\AVAST Software
2011-05-19 18:56 - 2011-05-19 18:56 - 0000000 ____D C:\Program Files\AVAST Software
2011-05-19 18:42 - 2011-05-19 18:42 - 56923744 ____A C:\Users\Lucinda\Desktop\setup_av_free.exe
2011-05-19 18:19 - 2006-11-02 14:01 - 0032644 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2011-05-19 18:13 - 2011-05-19 18:12 - 1930720 ____A (Symantec Corporation) C:\Users\Lucinda\Desktop\FixTDSS.exe
2011-05-18 23:05 - 2011-05-18 23:05 - 0002855 ____A C:\Users\Lucinda\Desktop\abc123.PIF
2011-05-18 22:49 - 2011-05-18 22:49 - 0001800 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2011-05-18 22:49 - 2011-05-18 22:49 - 0000000 ____D C:\Program Files\SUPERAntiSpyware
2011-05-18 22:49 - 2011-05-18 22:48 - 11166400 ____A (SUPERAntiSpyware.com) C:\Users\Lucinda\Desktop\SAS.exe
2011-05-18 22:43 - 2011-05-18 15:22 - 0000370 ____A C:\rkill.log
2011-05-18 22:42 - 2010-02-08 20:22 - 0801296 ____A C:\Windows\ntbtlog.txt
2011-05-18 22:36 - 2011-05-18 22:36 - 1407280 ____A (Kaspersky Lab ZAO) C:\Users\Lucinda\Desktop\abc123.com
2011-05-18 22:33 - 2011-05-18 22:33 - 0000000 _RASH C:\MSDOS.SYS
2011-05-18 22:33 - 2011-05-18 22:33 - 0000000 _RASH C:\IO.SYS
2011-05-18 22:32 - 2011-05-18 22:32 - 0000000 ___HD C:\Windows\PIF
2011-05-18 21:28 - 2009-03-25 13:29 - 0000000 ____D C:\$AVG8.VAULT$
2011-05-18 19:31 - 2006-11-02 13:52 - 0093228 ____A C:\Windows\setupact.log
2011-05-18 19:29 - 2006-11-02 12:18 - 0000000 ___SD C:\Windows\Downloaded Program Files
2011-05-18 18:58 - 2008-01-21 03:47 - 0335598 ____A C:\Windows\PFRO.log
2011-05-18 18:54 - 2011-05-18 18:54 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2011-05-18 18:52 - 2011-05-18 18:52 - 0000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_07_00.Wdf
2011-05-18 18:48 - 2010-01-21 10:40 - 0000000 ____D C:\Update
2011-05-18 18:48 - 2006-11-02 12:18 - 0000000 ____D C:\Program Files\Common Files\microsoft shared
2011-05-18 18:40 - 2008-10-22 19:43 - 0000000 ___HD C:\Program Files\InstallShield Installation Information
2011-05-18 18:40 - 2008-10-22 18:57 - 0000000 ____D C:\Program Files\sony
2011-05-18 18:39 - 2011-05-18 18:39 - 0000000 ____D C:\Program Files\Microsoft Silverlight
2011-05-18 18:37 - 2011-05-18 18:32 - 0004072 ____A C:\Windows\IE9_main.log
2011-05-18 17:47 - 2009-03-09 12:48 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\Skype
2011-05-18 17:40 - 2011-05-18 17:38 - 0001887 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2011-05-18 17:38 - 2011-05-18 17:37 - 0000000 ____D C:\Program Files\Common Files\Adobe
2011-05-18 17:38 - 2008-10-22 22:54 - 0000000 ____D C:\Users\All Users\Adobe
2011-05-18 17:38 - 2008-10-22 22:54 - 0000000 ____D C:\ProgramData\Adobe
2011-05-18 17:37 - 2009-03-06 21:52 - 0000000 ____D C:\Users\Lucinda\AppData\Local\Adobe
2011-05-18 17:37 - 2008-10-22 22:54 - 0000000 ____D C:\Program Files\Adobe
2011-05-18 17:29 - 2008-10-22 22:55 - 0000000 ____D C:\Users\All Users\Sony Corporation
2011-05-18 17:29 - 2008-10-22 22:55 - 0000000 ____D C:\ProgramData\Sony Corporation
2011-05-18 17:24 - 2009-03-06 21:52 - 0000000 ____D C:\Users\Lucinda\AppData\LocalLow
2011-05-18 17:21 - 2009-03-09 12:56 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\skypePM
2011-05-18 16:55 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\L2Schemas
2011-05-18 15:41 - 2011-05-18 15:41 - 0000906 ____A C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Users\All Users\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\ProgramData\Malwarebytes
2011-05-18 15:41 - 2011-05-18 15:41 - 0000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2011-05-18 15:37 - 2011-05-18 15:36 - 0134000 ____A C:\Windows\Minidump\Mini051811-01.dmp
2011-05-18 15:36 - 2011-05-18 15:36 - 248191849 ____A C:\Windows\MEMORY.DMP
2011-05-18 15:36 - 2011-05-18 15:36 - 0000000 ____D C:\Windows\Minidump
2011-05-18 15:14 - 2011-05-18 15:21 - 1006778 ____A C:\Users\Lucinda\Desktop\iExplore.exe
2011-05-18 14:59 - 2011-05-18 15:21 - 7734208 ____A (Malwarebytes Corporation ) C:\Users\Lucinda\Desktop\mbam-setup-1.50.1.1100.exe
2011-05-18 14:58 - 2009-04-06 17:20 - 0000000 ____D C:\Users\Lucinda\Documents\Max
2011-05-18 14:53 - 2009-03-06 22:11 - 0145408 ____A C:\Users\Lucinda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-05-18 14:41 - 2011-05-18 15:21 - 1402880 ____A C:\Users\Lucinda\Desktop\HiJackThis.msi
2011-05-16 14:11 - 2010-01-29 15:07 - 0000000 ____D C:\Users\Lucinda\Documents\Misc
2011-05-13 14:11 - 2011-05-13 14:09 - 0000000 ____D C:\Program Files\iTunes
2011-05-13 14:09 - 2011-05-13 14:09 - 0000000 ____D C:\Program Files\iPod
2011-05-13 14:09 - 2009-03-12 11:17 - 0000000 ____D C:\Program Files\Common Files\Apple
2011-05-13 13:53 - 2011-05-13 13:53 - 0000000 ____D C:\Program Files\Bonjour
2011-05-13 12:30 - 2010-01-14 15:29 - 0000000 ____D C:\Users\Lucinda\Documents\Nannying
2011-05-13 07:35 - 2008-11-27 22:41 - 0000000 ____D C:\Users\All Users\Microsoft Help
2011-05-13 07:35 - 2008-11-27 22:41 - 0000000 ____D C:\ProgramData\Microsoft Help
2011-05-13 07:31 - 2006-11-02 11:24 - 42829768 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2011-05-12 08:12 - 2010-01-29 15:06 - 0000000 ____D C:\Users\Lucinda\Documents\Writing Projects
2011-05-12 08:02 - 2009-03-10 19:35 - 0000000 ____D C:\Program Files\Mozilla Firefox
2011-05-01 21:46 - 2011-05-01 21:46 - 0000000 ____D C:\Users\Lucinda\AppData\Local\Trusteer
2011-04-28 14:34 - 2011-04-28 14:34 - 0053816 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKELL.sys
2011-04-26 20:33 - 2006-11-02 12:18 - 0000000 ____D C:\Windows\Microsoft.NET
2011-04-26 20:24 - 2006-11-02 13:47 - 0406072 ____A C:\Windows\System32\FNTCACHE.DAT
2011-04-13 23:40 - 2011-04-13 23:40 - 4284416 ____A (Google Inc.) C:\Windows\System32\GPhotos.scr
2011-04-07 13:40 - 2011-04-07 13:39 - 12399552 ____A (Mozilla) C:\Users\Lucinda\Downloads\Firefox Setup 4.0.exe
2011-04-06 16:20 - 2011-04-06 16:20 - 0197920 ____A (Apple Inc.) C:\Windows\System32\dnssdX.dll
2011-04-06 16:20 - 2011-04-06 16:20 - 0107808 ____A (Apple Inc.) C:\Windows\System32\dns-sd.exe
2011-04-06 16:20 - 2011-04-06 16:20 - 0091424 ____A (Apple Inc.) C:\Windows\System32\dnssd.dll
2011-04-06 16:20 - 2011-04-06 16:20 - 0075040 ____A (Apple Inc.) C:\Windows\System32\jdns_sd.dll
2011-04-05 19:08 - 2011-03-15 10:43 - 0000000 ____D C:\Users\Lucinda\Documents\Cardiff Move
2011-03-28 16:57 - 2009-06-19 22:58 - 0000000 ____D C:\Users\Lucinda\AppData\Roaming\Spotify
2011-03-28 10:03 - 2008-11-27 22:47 - 0000000 ____D C:\Program Files\Microsoft SQL Server
2011-03-15 10:43 - 2011-03-15 10:43 - 0000000 ____D C:\Users\Lucinda\Documents\Australia
2011-03-10 18:03 - 2011-04-20 13:38 - 1162240 ____A (Microsoft Corporation) C:\Windows\System32\mfc42u.dll
2011-03-10 18:03 - 2011-04-20 13:38 - 1136640 ____A (Microsoft Corporation) C:\Windows\System32\mfc42.dll
2011-03-08 10:21 - 2011-03-08 10:21 - 0167410 ____A C:\Users\Lucinda\Documents\HowtoRegwithOfsted.pdf
2011-03-08 10:01 - 2011-03-07 21:57 - 2832544 ____A (Adobe Systems, Inc.) C:\Users\Lucinda\Downloads\install_flash_player.exe


========================= Known DLLs =========================

[2009-09-16 22:37] - [2009-04-11 07:28] - 0800768 ____A (Microsoft Corporation) C:\Windows\System32\advapi32.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0523776 ____A (Microsoft Corporation) C:\Windows\System32\clbcatq.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0450560 ____A (Microsoft Corporation) C:\Windows\System32\comdlg32.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0297472 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0270336 ____A (Microsoft Corporation) C:\Windows\System32\IERTUTIL.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0153088 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
[2009-09-16 22:36] - [2009-04-11 07:28] - 0114688 ____A (Microsoft Corporation) C:\Windows\System32\IMM32.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0891392 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
[2009-07-24 19:01] - [2009-06-15 15:52] - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\LPK.dll
[2006-11-02 09:33] - [2006-11-02 09:33] - 0003072 ____A (Microsoft Corporation) C:\Windows\System32\lz32.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0807424 ____A (Microsoft Corporation) C:\Windows\System32\MSCTF.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0679936 ____A (Microsoft Corporation) C:\Windows\System32\MSVCRT.dll
[2006-11-02 09:33] - [2006-11-02 09:33] - 0002560 ____A (Microsoft Corporation) C:\Windows\System32\NORMALIZ.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\NSI.dll
[2010-10-14 12:10] - [2010-06-28 18:00] - 1316864 ____A (Microsoft Corporation) C:\Windows\System32\ole32.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0563712 ____A (Microsoft Corporation) C:\Windows\System32\oleaut32.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\olecli32.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0027648 ____A (Microsoft Corporation) C:\Windows\System32\olesvr32.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0077824 ____A (Microsoft Corporation) C:\Windows\System32\olethk32.dll
[2009-06-11 12:18] - [2009-04-23 13:15] - 0784896 ____A (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 1591296 ____A (Microsoft Corporation) C:\Windows\System32\Setupapi.dll
[2011-02-09 11:34] - [2011-01-21 17:35] - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
[2011-02-09 11:34] - [2011-01-21 17:35] - 0353280 ____A (Microsoft Corporation) C:\Windows\System32\SHLWAPI.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
[2011-04-20 13:38] - [2011-02-18 17:38] - 1176064 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0627712 ____A (Microsoft Corporation) C:\Windows\System32\user32.dll
[2010-09-15 07:52] - [2010-04-16 17:46] - 0502272 ____A (Microsoft Corporation) C:\Windows\System32\USP10.dll
[2009-09-16 22:36] - [2009-04-11 07:28] - 0020480 ____A (Microsoft Corporation) C:\Windows\System32\version.dll
[2011-04-20 13:38] - [2011-02-18 17:38] - 0834048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
[2009-09-16 22:37] - [2009-04-11 07:28] - 0287744 ____A (Microsoft Corporation) C:\Windows\System32\wldap32.dll
[2008-01-21 03:24] - [2008-01-21 03:24] - 0179200 ____A (Microsoft Corporation) C:\Windows\System32\WS2_32.dll

========================= Bamital Check ======================

C:\Windows\System32\winlogon.exe
[2009-09-16 22:37] - [2009-04-11 07:28] - 0314368 ____A (Microsoft Corporation) 898E7C06A350D4A1A64A9EA264D55452

C:\Windows\System32\wininit.exe
[2008-01-21 03:23] - [2008-01-21 03:23] - 0096768 ____A (Microsoft Corporation) 101BA3EA053480BB5D957EF37C06B5ED

C:\Windows\explorer.exe
[2009-09-16 22:37] - [2009-04-11 07:27] - 2926592 ____A (Microsoft Corporation) D07D4C3038F3578FFCE1C0237F2A1253


========================= Memory info ========================

Percentage of memory in use: 14%
Total physical RAM: 2938.31 MB
Available physical RAM: 2505.06 MB
Total Pagefile: 2731.85 MB
Available Pagefile: 2600.79 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.32 MB

======================= Partitions ===========================

1 Drive c: () (Fixed) (Total:288.44 GB) (Free:188.09 GB) NTFS
3 Drive e: (Recovery) (Fixed) (Total:9.65 GB) (Free:0.84 GB) NTFS
4 Drive f: (MAX'S DATA) (Removable) (Total:1.9 GB) (Free:1.89 GB) FAT32
5 Drive g: (MAX *****) (Removable) (Total:1.88 GB) (Free:1.57 GB) FAT32
6 Drive h: (BLUE STICK) (Removable) (Total:1.97 GB) (Free:1.91 GB) FAT32
7 Drive x: (Boot) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS

#9 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,703 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:01:51 AM

Posted 07 June 2011 - 01:56 PM

Well done.

Boot to System Recovery Options and run FRST.
Type the following in the edit box after "Search:".

volsnap.sys

Click Search button and post the log it makes to your reply.

#10 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 07 June 2011 - 04:00 PM

searching now, thanks Farbar - really appreciate your help

#11 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 07 June 2011 - 04:02 PM

Done:

Farbars Recovery Scan Tool 2.0.3
Ran by SYSTEM at 2011-06-07 21:54:45
Running from F:\

================== Search: volsnap.sys ===================

C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_17a2308cf936c619\volsnap.sys
[2009-09-16 22:37] - [2009-04-11 07:32] - 0226280 ____A (Microsoft Corporation) 147281C01FCB1DF9252DE2A10D5E7093

C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6001.18000_none_15b6b780fc14facd\volsnap.sys
[2008-01-21 03:23] - [2008-01-21 03:23] - 0227896 ____A (Microsoft Corporation) D8B4A53DD2769F226B3EB374374987C9

C:\Windows\System32\DriverStore\FileRepository\volume.inf_f53a1785\volsnap.sys
[2008-01-21 03:23] - [2008-01-21 03:23] - 0227896 ____A (Microsoft Corporation) D8B4A53DD2769F226B3EB374374987C9

C:\Windows\System32\DriverStore\FileRepository\volume.inf_9320b452\volsnap.sys
[2006-11-02 11:25] - [2006-11-02 10:51] - 0208488 ____A (Microsoft Corporation) 11EF6C1CAEF76B685233450A126125D6

C:\Windows\System32\DriverStore\FileRepository\volume.inf_1e6030e4\volsnap.sys
[2009-09-16 22:37] - [2009-04-11 07:32] - 0226280 ____A (Microsoft Corporation) 147281C01FCB1DF9252DE2A10D5E7093

C:\Windows\System32\drivers\volsnap.sys
[2009-09-16 22:37] - [2009-04-11 07:32] - 0226280 ____A () A7FD7A8EAAA2DECE5B683EC0DB1C6FFE

================== End Of Search =================

#12 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,703 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:01:51 AM

Posted 07 June 2011 - 04:20 PM

Good. We are going to replace the infected/patched driver with a good copy.

Open notepad. Please copy the contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt

Replace: C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_17a2308cf936c619\volsnap.sys C:\Windows\System32\drivers\volsnap.sys

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options.
Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Also restart the computer and tell me how it went.

#13 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 07 June 2011 - 04:52 PM

Thank you so much Farbar. I'll try it tomorrow, have to get to bed now :o yawn

#14 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,703 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:01:51 AM

Posted 07 June 2011 - 04:54 PM

Good night Dr_Million.:)

#15 Dr_Million

Dr_Million
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:11:51 PM

Posted 08 June 2011 - 03:11 AM

Fix result of Farbars's Recovery Tool (FRST written by farbar Version 2.0.8)
Ran by SYSTEM at 2011-06-08 09:09:34 R:1
Running from H:\

==============================================

C:\Windows\System32\drivers\volsnap.sys moved successfully.
C:\Windows\System32\drivers\volsnap.sys repleced successfully with C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.0.6002.18005_none_17a2308cf936c619\volsnap.sys


I'm fascinated by this process, and amazed how these lines of code mean something to you!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users