Results 1 to 6 of 6

Thread: Moms computer needs help

  1. #1
    Member
    Join Date
    Jul 2009
    Posts
    74

    Default Moms computer needs help

    she says that the internet is being extremely slow and many other things are going wrong. i remember a few weeks ago i saw her click on a fake anti virus pop up and everything was fine until now. she is running windows vista if you need that but here is he HTJ log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:19:32 PM, on 03/12/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18319)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Users\Anton\Program Files\DNA\btdna.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
    O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/reso...PUplden-ca.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
    O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Update Service (gupdate1c9b60d61076b20) (gupdate1c9b60d61076b20) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
    O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
    O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 12171 bytes

  2. #2
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hello Anton

    Welcome to Safer Networking.

    Please read Before You Post
    While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

    Nothing really jumping out at me on your log, but this stuff hides.


    Please download RootRepeal from one of these locations and save it to your desktop
    Here
    Here
    Here
    • Open on your desktop.
    • Click the tab.
    • Click the button.
    • Check just these boxes:
    • Push Ok
    • Check the box for your main system drive (Usually C:, and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.






    Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.scr
    • DDS.pif
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
    • Notepad will open with the results, click no to the Optional_Scan
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control Here
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  3. #3
    Member
    Join Date
    Jul 2009
    Posts
    74

    Default

    okay scanning now

  4. #4
    Member
    Join Date
    Jul 2009
    Posts
    74

    Default

    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time: 2009/12/06 14:04
    Program Version: Version 1.3.5.0
    Windows Version: Windows Vista SP1
    ==================================================

    Drivers
    -------------------
    Name: 1394BUS.SYS
    Image Path: C:\Windows\system32\DRIVERS\1394BUS.SYS
    Address: 0x8C1EC000 Size: 57344 File Visible: - Signed: -
    Status: -

    Name: acpi.sys
    Image Path: C:\Windows\system32\drivers\acpi.sys
    Address: 0x80696000 Size: 286720 File Visible: - Signed: -
    Status: -

    Name: ACPI_HAL
    Image Path: \Driver\ACPI_HAL
    Address: 0x81E3F000 Size: 3903488 File Visible: - Signed: -
    Status: -

    Name: afd.sys
    Image Path: C:\Windows\system32\drivers\afd.sys
    Address: 0x8CC7A000 Size: 294912 File Visible: - Signed: -
    Status: -

    Name: asyncmac.sys
    Image Path: C:\Windows\system32\DRIVERS\asyncmac.sys
    Address: 0xAD5CF000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: atapi.sys
    Image Path: C:\Windows\system32\drivers\atapi.sys
    Address: 0x87AC9000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: ataport.SYS
    Image Path: C:\Windows\system32\drivers\ataport.SYS
    Address: 0x87AD1000 Size: 122880 File Visible: - Signed: -
    Status: -

    Name: ATMFD.DLL
    Image Path: C:\Windows\System32\ATMFD.DLL
    Address: 0x95310000 Size: 311296 File Visible: - Signed: -
    Status: -

    Name: bcmwl6.sys
    Image Path: C:\Windows\system32\DRIVERS\bcmwl6.sys
    Address: 0x8C606000 Size: 479232 File Visible: - Signed: -
    Status: -

    Name: Beep.SYS
    Image Path: C:\Windows\System32\Drivers\Beep.SYS
    Address: 0x8C5F5000 Size: 28672 File Visible: - Signed: -
    Status: -

    Name: BOOTVID.dll
    Image Path: C:\Windows\system32\BOOTVID.dll
    Address: 0x80486000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: bowser.sys
    Image Path: C:\Windows\system32\DRIVERS\bowser.sys
    Address: 0xA86D6000 Size: 102400 File Visible: - Signed: -
    Status: -

    Name: cdd.dll
    Image Path: C:\Windows\System32\cdd.dll
    Address: 0x95300000 Size: 57344 File Visible: - Signed: -
    Status: -

    Name: cdfs.sys
    Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
    Address: 0xAD4F2000 Size: 90112 File Visible: - Signed: -
    Status: -

    Name: cdrom.sys
    Image Path: C:\Windows\system32\DRIVERS\cdrom.sys
    Address: 0x8C6D0000 Size: 98304 File Visible: - Signed: -
    Status: -

    Name: CI.dll
    Image Path: C:\Windows\system32\CI.dll
    Address: 0x804CF000 Size: 917504 File Visible: - Signed: -
    Status: -

    Name: CLASSPNP.SYS
    Image Path: C:\Windows\system32\drivers\CLASSPNP.SYS
    Address: 0x881A6000 Size: 135168 File Visible: - Signed: -
    Status: -

    Name: CLFS.SYS
    Image Path: C:\Windows\system32\CLFS.SYS
    Address: 0x8048E000 Size: 266240 File Visible: - Signed: -
    Status: -

    Name: crashdmp.sys
    Image Path: C:\Windows\System32\Drivers\crashdmp.sys
    Address: 0x8D2CE000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: crcdisk.sys
    Image Path: C:\Windows\system32\drivers\crcdisk.sys
    Address: 0x881C7000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: dfsc.sys
    Image Path: C:\Windows\System32\Drivers\dfsc.sys
    Address: 0x8D2B7000 Size: 94208 File Visible: - Signed: -
    Status: -

    Name: disk.sys
    Image Path: C:\Windows\system32\drivers\disk.sys
    Address: 0x88195000 Size: 69632 File Visible: - Signed: -
    Status: -

    Name: drmk.sys
    Image Path: C:\Windows\system32\drivers\drmk.sys
    Address: 0x87BD8000 Size: 151552 File Visible: - Signed: -
    Status: -

    Name: dump_iaStor.sys
    Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
    Address: 0x8D2DB000 Size: 815104 File Visible: No Signed: -
    Status: -

    Name: Dxapi.sys
    Image Path: C:\Windows\System32\drivers\Dxapi.sys
    Address: 0x8D3B6000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: dxgkrnl.sys
    Image Path: C:\Windows\System32\drivers\dxgkrnl.sys
    Address: 0x8C0C6000 Size: 651264 File Visible: - Signed: -
    Status: -

    Name: e100b325.sys
    Image Path: C:\Windows\system32\DRIVERS\e100b325.sys
    Address: 0x8C67B000 Size: 159744 File Visible: - Signed: -
    Status: -

    Name: ecache.sys
    Image Path: C:\Windows\System32\drivers\ecache.sys
    Address: 0x8816E000 Size: 159744 File Visible: - Signed: -
    Status: -

    Name: eeCtrl.sys
    Image Path: C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
    Address: 0x8D235000 Size: 405504 File Visible: - Signed: -
    Status: -

    Name: EraserUtilRebootDrv.sys
    Image Path: C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    Address: 0x8D298000 Size: 126976 File Visible: - Signed: -
    Status: -

    Name: fastfat.SYS
    Image Path: C:\Windows\System32\Drivers\fastfat.SYS
    Address: 0xAD5D8000 Size: 163840 File Visible: - Signed: -
    Status: -

    Name: fileinfo.sys
    Image Path: C:\Windows\system32\drivers\fileinfo.sys
    Address: 0x87B21000 Size: 65536 File Visible: - Signed: -
    Status: -

    Name: fltmgr.sys
    Image Path: C:\Windows\system32\drivers\fltmgr.sys
    Address: 0x87AEF000 Size: 204800 File Visible: - Signed: -
    Status: -

    Name: Fs_Rec.SYS
    Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
    Address: 0x8CBF3000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: fwpkclnt.sys
    Image Path: C:\Windows\System32\drivers\fwpkclnt.sys
    Address: 0x87EF3000 Size: 110592 File Visible: - Signed: -
    Status: -

    Name: GEARAspiWDM.sys
    Image Path: C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    Address: 0x8C6E8000 Size: 9984 File Visible: - Signed: -
    Status: -

    Name: hal.dll
    Image Path: C:\Windows\system32\hal.dll
    Address: 0x81E0C000 Size: 208896 File Visible: - Signed: -
    Status: -

    Name: HDAudBus.sys
    Image Path: C:\Windows\system32\DRIVERS\HDAudBus.sys
    Address: 0x8C172000 Size: 73728 File Visible: - Signed: -
    Status: -

    Name: HSX_CNXT.sys
    Image Path: C:\Windows\system32\DRIVERS\HSX_CNXT.sys
    Address: 0x8C50E000 Size: 741376 File Visible: - Signed: -
    Status: -

    Name: HSX_DP.sys
    Image Path: C:\Windows\system32\DRIVERS\HSX_DP.sys
    Address: 0x8C40C000 Size: 1056768 File Visible: - Signed: -
    Status: -

    Name: HSXHWBS2.sys
    Image Path: C:\Windows\system32\DRIVERS\HSXHWBS2.sys
    Address: 0x87D75000 Size: 311296 File Visible: - Signed: -
    Status: -

    Name: HTTP.sys
    Image Path: C:\Windows\system32\drivers\HTTP.sys
    Address: 0xA864E000 Size: 438272 File Visible: - Signed: -
    Status: -

    Name: i8042prt.sys
    Image Path: C:\Windows\system32\DRIVERS\i8042prt.sys
    Address: 0x8C6A2000 Size: 77824 File Visible: - Signed: -
    Status: -

    Name: iastor.sys
    Image Path: C:\Windows\system32\drivers\iastor.sys
    Address: 0x87A02000 Size: 815104 File Visible: - Signed: -
    Status: -

    Name: IDSvix86.sys
    Image Path: C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071116.001\IDSvix86.sys
    Address: 0x8D206000 Size: 192512 File Visible: - Signed: -
    Status: -

    Name: igdkmd32.sys
    Image Path: C:\Windows\system32\DRIVERS\igdkmd32.sys
    Address: 0x8BA09000 Size: 7065600 File Visible: - Signed: -
    Status: -

    Name: intelide.sys
    Image Path: C:\Windows\system32\drivers\intelide.sys
    Address: 0x8077C000 Size: 28672 File Visible: - Signed: -
    Status: -

    Name: intelppm.sys
    Image Path: C:\Windows\system32\DRIVERS\intelppm.sys
    Address: 0x881F1000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: kbdclass.sys
    Image Path: C:\Windows\system32\DRIVERS\kbdclass.sys
    Address: 0x8C6C5000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: kdcom.dll
    Image Path: C:\Windows\system32\kdcom.dll
    Address: 0x8040D000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: ks.sys
    Image Path: C:\Windows\system32\DRIVERS\ks.sys
    Address: 0x87FD5000 Size: 172032 File Visible: - Signed: -
    Status: -

    Name: ksecdd.sys
    Image Path: C:\Windows\System32\Drivers\ksecdd.sys
    Address: 0x87B3A000 Size: 462848 File Visible: - Signed: -
    Status: -

    Name: lltdio.sys
    Image Path: C:\Windows\system32\DRIVERS\lltdio.sys
    Address: 0x87FBD000 Size: 65536 File Visible: - Signed: -
    Status: -

    Name: luafv.sys
    Image Path: C:\Windows\system32\drivers\luafv.sys
    Address: 0x8CDE4000 Size: 110592 File Visible: - Signed: -
    Status: -

    Name: mcupdate_GenuineIntel.dll
    Image Path: C:\Windows\system32\mcupdate_GenuineIntel.dll
    Address: 0x80415000 Size: 393216 File Visible: - Signed: -
    Status: -

    Name: mdmxsdk.sys
    Image Path: C:\Windows\system32\DRIVERS\mdmxsdk.sys
    Address: 0xAA667000 Size: 12672 File Visible: - Signed: -
    Status: -

    Name: modem.sys
    Image Path: C:\Windows\system32\drivers\modem.sys
    Address: 0x8C5C3000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: monitor.sys
    Image Path: C:\Windows\system32\DRIVERS\monitor.sys
    Address: 0x8D3EE000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: mouclass.sys
    Image Path: C:\Windows\system32\DRIVERS\mouclass.sys
    Address: 0x8C6B5000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: mountmgr.sys
    Image Path: C:\Windows\System32\drivers\mountmgr.sys
    Address: 0x80791000 Size: 65536 File Visible: - Signed: -
    Status: -

    Name: mpsdrv.sys
    Image Path: C:\Windows\System32\drivers\mpsdrv.sys
    Address: 0xA86EF000 Size: 86016 File Visible: - Signed: -
    Status: -

    Name: mrxdav.sys
    Image Path: C:\Windows\system32\drivers\mrxdav.sys
    Address: 0xA8704000 Size: 131072 File Visible: - Signed: -
    Status: -

    Name: mrxsmb.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb.sys
    Address: 0xA8724000 Size: 126976 File Visible: - Signed: -
    Status: -

    Name: mrxsmb10.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb10.sys
    Address: 0xA8743000 Size: 233472 File Visible: - Signed: -
    Status: -

    Name: mrxsmb20.sys
    Image Path: C:\Windows\system32\DRIVERS\mrxsmb20.sys
    Address: 0xA877C000 Size: 98304 File Visible: - Signed: -
    Status: -

    Name: Msfs.SYS
    Image Path: C:\Windows\System32\Drivers\Msfs.SYS
    Address: 0x87DF5000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: msisadrv.sys
    Image Path: C:\Windows\system32\drivers\msisadrv.sys
    Address: 0x806E5000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: msiscsi.sys
    Image Path: C:\Windows\system32\DRIVERS\msiscsi.sys
    Address: 0x8C6EB000 Size: 188416 File Visible: - Signed: -
    Status: -

    Name: msrpc.sys
    Image Path: C:\Windows\system32\drivers\msrpc.sys
    Address: 0x87D10000 Size: 176128 File Visible: - Signed: -
    Status: -

    Name: mssmbios.sys
    Image Path: C:\Windows\system32\DRIVERS\mssmbios.sys
    Address: 0x8C7F4000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: mup.sys
    Image Path: C:\Windows\System32\Drivers\mup.sys
    Address: 0x8815F000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: NAVENG.SYS
    Image Path: C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20071118.016\NAVENG.SYS
    Address: 0xAD4DF000 Size: 74528 File Visible: - Signed: -
    Status: -

    Name: NAVEX15.SYS
    Image Path: C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20071118.016\NAVEX15.SYS
    Address: 0xAD40D000 Size: 859200 File Visible: - Signed: -
    Status: -

    Name: ndis.sys
    Image Path: C:\Windows\system32\drivers\ndis.sys
    Address: 0x87C05000 Size: 1093632 File Visible: - Signed: -
    Status: -

    Name: ndistapi.sys
    Image Path: C:\Windows\system32\DRIVERS\ndistapi.sys
    Address: 0x8C77C000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: ndisuio.sys
    Image Path: C:\Windows\system32\DRIVERS\ndisuio.sys
    Address: 0xA8631000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: ndiswan.sys
    Image Path: C:\Windows\system32\DRIVERS\ndiswan.sys
    Address: 0x8C787000 Size: 143360 File Visible: - Signed: -
    Status: -

    Name: NDProxy.SYS
    Image Path: C:\Windows\System32\Drivers\NDProxy.SYS
    Address: 0x8C5DD000 Size: 69632 File Visible: - Signed: -
    Status: -

    Name: netbios.sys
    Image Path: C:\Windows\system32\DRIVERS\netbios.sys
    Address: 0x8CD0A000 Size: 57344 File Visible: - Signed: -
    Status: -

    Name: netbt.sys
    Image Path: C:\Windows\System32\DRIVERS\netbt.sys
    Address: 0x8CCC2000 Size: 204800 File Visible: - Signed: -
    Status: -

    Name: NETIO.SYS
    Image Path: C:\Windows\system32\drivers\NETIO.SYS
    Address: 0x87D3B000 Size: 237568 File Visible: - Signed: -
    Status: -

    Name: Npfs.SYS
    Image Path: C:\Windows\System32\Drivers\Npfs.SYS
    Address: 0x807C2000 Size: 57344 File Visible: - Signed: -
    Status: -

    Name: nsiproxy.sys
    Image Path: C:\Windows\system32\drivers\nsiproxy.sys
    Address: 0x8CDDA000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: Ntfs.sys
    Image Path: C:\Windows\System32\Drivers\Ntfs.sys
    Address: 0x8800F000 Size: 1110016 File Visible: - Signed: -
    Status: -

    Name: ntkrnlpa.exe
    Image Path: C:\Windows\system32\ntkrnlpa.exe
    Address: 0x81E3F000 Size: 3903488 File Visible: - Signed: -
    Status: -

    Name: Null.SYS
    Image Path: C:\Windows\System32\Drivers\Null.SYS
    Address: 0x8C5EE000 Size: 28672 File Visible: - Signed: -
    Status: -

    Name: nwifi.sys
    Image Path: C:\Windows\system32\DRIVERS\nwifi.sys
    Address: 0xA8607000 Size: 172032 File Visible: - Signed: -
    Status: -

    Name: ohci1394.sys
    Image Path: C:\Windows\system32\DRIVERS\ohci1394.sys
    Address: 0x8C1DC000 Size: 61952 File Visible: - Signed: -
    Status: -

    Name: pacer.sys
    Image Path: C:\Windows\system32\DRIVERS\pacer.sys
    Address: 0x8CCF4000 Size: 90112 File Visible: - Signed: -
    Status: -

    Name: partmgr.sys
    Image Path: C:\Windows\System32\drivers\partmgr.sys
    Address: 0x80714000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: pci.sys
    Image Path: C:\Windows\system32\drivers\pci.sys
    Address: 0x806ED000 Size: 159744 File Visible: - Signed: -
    Status: -

    Name: PCIIDEX.SYS
    Image Path: C:\Windows\system32\drivers\PCIIDEX.SYS
    Address: 0x80783000 Size: 57344 File Visible: - Signed: -
    Status: -

    Name: peauth.sys
    Image Path: C:\Windows\system32\drivers\peauth.sys
    Address: 0xAA66B000 Size: 909312 File Visible: - Signed: -
    Status: -

    Name: PnpManager
    Image Path: \Driver\PnpManager
    Address: 0x81E3F000 Size: 3903488 File Visible: - Signed: -
    Status: -

    Name: portcls.sys
    Image Path: C:\Windows\system32\drivers\portcls.sys
    Address: 0x87BAB000 Size: 184320 File Visible: - Signed: -
    Status: -

    Name: PS2.sys
    Image Path: C:\Windows\system32\DRIVERS\PS2.sys
    Address: 0x8C6C0000 Size: 19072 File Visible: - Signed: -
    Status: -

    Name: PSHED.dll
    Image Path: C:\Windows\system32\PSHED.dll
    Address: 0x80475000 Size: 69632 File Visible: - Signed: -
    Status: -

    Name: PxHelp20.sys
    Image Path: C:\Windows\System32\Drivers\PxHelp20.sys
    Address: 0x87B31000 Size: 36320 File Visible: - Signed: -
    Status: -

    Name: rasacd.sys
    Image Path: C:\Windows\System32\DRIVERS\rasacd.sys
    Address: 0x87E00000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: rasl2tp.sys
    Image Path: C:\Windows\system32\DRIVERS\rasl2tp.sys
    Address: 0x8C765000 Size: 94208 File Visible: - Signed: -
    Status: -

    Name: raspppoe.sys
    Image Path: C:\Windows\system32\DRIVERS\raspppoe.sys
    Address: 0x8C7AA000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: raspptp.sys
    Image Path: C:\Windows\system32\DRIVERS\raspptp.sys
    Address: 0x8C7B9000 Size: 81920 File Visible: - Signed: -
    Status: -

    Name: rassstp.sys
    Image Path: C:\Windows\system32\DRIVERS\rassstp.sys
    Address: 0x8C7CD000 Size: 86016 File Visible: - Signed: -
    Status: -

    Name: RAW
    Image Path: \FileSystem\RAW
    Address: 0x81E3F000 Size: 3903488 File Visible: - Signed: -
    Status: -

    Name: rdbss.sys
    Image Path: C:\Windows\system32\DRIVERS\rdbss.sys
    Address: 0x8CD9E000 Size: 245760 File Visible: - Signed: -
    Status: -

    Name: RDPCDD.sys
    Image Path: C:\Windows\System32\DRIVERS\RDPCDD.sys
    Address: 0x8BA00000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: rdpencdd.sys
    Image Path: C:\Windows\system32\drivers\rdpencdd.sys
    Address: 0x88000000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: rootrepeal.sys
    Image Path: C:\Windows\system32\drivers\rootrepeal.sys
    Address: 0xAD400000 Size: 49152 File Visible: No Signed: -
    Status: -

    Name: rspndr.sys
    Image Path: C:\Windows\system32\DRIVERS\rspndr.sys
    Address: 0xA863B000 Size: 77824 File Visible: - Signed: -
    Status: -

    Name: RTKVHDA.sys
    Image Path: C:\Windows\system32\drivers\RTKVHDA.sys
    Address: 0x8CA00000 Size: 2042176 File Visible: - Signed: -
    Status: -

    Name: secdrv.SYS
    Image Path: C:\Windows\System32\Drivers\secdrv.SYS
    Address: 0xAA749000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: smb.sys
    Image Path: C:\Windows\system32\DRIVERS\smb.sys
    Address: 0x8CC66000 Size: 81920 File Visible: - Signed: -
    Status: -

    Name: SPBBCDrv.sys
    Image Path: C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
    Address: 0x8CD35000 Size: 430080 File Visible: - Signed: -
    Status: -

    Name: spldr.sys
    Image Path: C:\Windows\System32\Drivers\spldr.sys
    Address: 0x88157000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: spsys.sys
    Image Path: C:\Windows\system32\drivers\spsys.sys
    Address: 0x87F0E000 Size: 716800 File Visible: - Signed: -
    Status: -

    Name: SRTSP.SYS
    Image Path: C:\Windows\System32\Drivers\SRTSP.SYS
    Address: 0xAA78E000 Size: 299008 File Visible: - Signed: -
    Status: -

    Name: SRTSPX.SYS
    Image Path: C:\Windows\System32\Drivers\SRTSPX.SYS
    Address: 0x8CD2B000 Size: 36992 File Visible: - Signed: -
    Status: -

    Name: srv.sys
    Image Path: C:\Windows\System32\DRIVERS\srv.sys
    Address: 0xAA603000 Size: 311296 File Visible: - Signed: -
    Status: -

    Name: srv2.sys
    Image Path: C:\Windows\System32\DRIVERS\srv2.sys
    Address: 0xA8794000 Size: 159744 File Visible: - Signed: -
    Status: -

    Name: srvnet.sys
    Image Path: C:\Windows\System32\DRIVERS\srvnet.sys
    Address: 0xA86B9000 Size: 118784 File Visible: - Signed: -
    Status: -

    Name: storport.sys
    Image Path: C:\Windows\system32\DRIVERS\storport.sys
    Address: 0x8C719000 Size: 266240 File Visible: - Signed: -
    Status: -

    Name: swenum.sys
    Image Path: C:\Windows\system32\DRIVERS\swenum.sys
    Address: 0x8C7F2000 Size: 4992 File Visible: - Signed: -
    Status: -

    Name: SYMDNS.SYS
    Image Path: C:\Windows\System32\Drivers\SYMDNS.SYS
    Address: 0x8CC2E000 Size: 6016 File Visible: - Signed: -
    Status: -

    Name: SYMEVENT.SYS
    Image Path: C:\Windows\system32\Drivers\SYMEVENT.SYS
    Address: 0x8CC04000 Size: 151552 File Visible: - Signed: -
    Status: -

    Name: SYMFW.SYS
    Image Path: C:\Windows\System32\Drivers\SYMFW.SYS
    Address: 0x8CC3B000 Size: 139264 File Visible: - Signed: -
    Status: -

    Name: SYMIDS.SYS
    Image Path: C:\Windows\System32\Drivers\SYMIDS.SYS
    Address: 0x8CC5D000 Size: 33152 File Visible: - Signed: -
    Status: -

    Name: SYMNDISV.SYS
    Image Path: C:\Windows\System32\Drivers\SYMNDISV.SYS
    Address: 0x8CC30000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: SYMREDRV.SYS
    Image Path: C:\Windows\System32\Drivers\SYMREDRV.SYS
    Address: 0x8CC29000 Size: 19712 File Visible: - Signed: -
    Status: -

    Name: SYMTDI.SYS
    Image Path: C:\Windows\System32\Drivers\SYMTDI.SYS
    Address: 0x805AF000 Size: 181376 File Visible: - Signed: -
    Status: -

    Name: tcpip.sys
    Image Path: C:\Windows\System32\drivers\tcpip.sys
    Address: 0x87E0A000 Size: 954368 File Visible: - Signed: -
    Status: -

    Name: tcpipreg.sys
    Image Path: C:\Windows\System32\drivers\tcpipreg.sys
    Address: 0xAA753000 Size: 49152 File Visible: - Signed: -
    Status: -

    Name: TDI.SYS
    Image Path: C:\Windows\system32\DRIVERS\TDI.SYS
    Address: 0x8C75A000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: tdx.sys
    Image Path: C:\Windows\system32\DRIVERS\tdx.sys
    Address: 0x807D0000 Size: 90112 File Visible: - Signed: -
    Status: -

    Name: termdd.sys
    Image Path: C:\Windows\system32\DRIVERS\termdd.sys
    Address: 0x8C7E2000 Size: 65536 File Visible: - Signed: -
    Status: -

    Name: TSDDD.dll
    Image Path: C:\Windows\System32\TSDDD.dll
    Address: 0x952E0000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: tunmp.sys
    Image Path: C:\Windows\system32\DRIVERS\tunmp.sys
    Address: 0x881E8000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: tunnel.sys
    Image Path: C:\Windows\system32\DRIVERS\tunnel.sys
    Address: 0x881DD000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: udfs.sys
    Image Path: C:\Windows\system32\DRIVERS\udfs.sys
    Address: 0xAD564000 Size: 241664 File Visible: - Signed: -
    Status: -

    Name: umbus.sys
    Image Path: C:\Windows\system32\DRIVERS\umbus.sys
    Address: 0x8C5D0000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: usbccgp.sys
    Image Path: C:\Windows\system32\DRIVERS\usbccgp.sys
    Address: 0xAD508000 Size: 94208 File Visible: - Signed: -
    Status: -

    Name: USBD.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBD.SYS
    Address: 0x8D3B4000 Size: 8192 File Visible: - Signed: -
    Status: -

    Name: usbehci
    Image Path: \Driver\usbehci
    Address: 0x8C9C6000 Size: 61440 File Visible: No Signed: -
    Status: Hidden from the Windows API!

    Name: usbehci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbehci.sys
    Address: 0x8C1CD000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: usbhub.sys
    Image Path: C:\Windows\system32\DRIVERS\usbhub.sys
    Address: 0x87DC1000 Size: 212992 File Visible: - Signed: -
    Status: -

    Name: USBPORT.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBPORT.SYS
    Address: 0x8C18F000 Size: 253952 File Visible: - Signed: -
    Status: -

    Name: usbprint.sys
    Image Path: C:\Windows\system32\DRIVERS\usbprint.sys
    Address: 0xAD52C000 Size: 40960 File Visible: - Signed: -
    Status: -

    Name: usbscan.sys
    Image Path: C:\Windows\system32\DRIVERS\usbscan.sys
    Address: 0xAD51F000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: USBSTOR.SYS
    Image Path: C:\Windows\system32\DRIVERS\USBSTOR.SYS
    Address: 0x8D3A2000 Size: 73728 File Visible: - Signed: -
    Status: -

    Name: usbuhci.sys
    Image Path: C:\Windows\system32\DRIVERS\usbuhci.sys
    Address: 0x8C184000 Size: 45056 File Visible: - Signed: -
    Status: -

    Name: vga.sys
    Image Path: C:\Windows\System32\drivers\vga.sys
    Address: 0x8C400000 Size: 49152 File Visible: - Signed: -
    Status: -

    Name: VIDEOPRT.SYS
    Image Path: C:\Windows\System32\drivers\VIDEOPRT.SYS
    Address: 0x807A1000 Size: 135168 File Visible: - Signed: -
    Status: -

    Name: volmgr.sys
    Image Path: C:\Windows\system32\drivers\volmgr.sys
    Address: 0x80723000 Size: 61440 File Visible: - Signed: -
    Status: -

    Name: volmgrx.sys
    Image Path: C:\Windows\System32\drivers\volmgrx.sys
    Address: 0x80732000 Size: 303104 File Visible: - Signed: -
    Status: -

    Name: volsnap.sys
    Image Path: C:\Windows\system32\drivers\volsnap.sys
    Address: 0x8811E000 Size: 233472 File Visible: - Signed: -
    Status: -

    Name: wanarp.sys
    Image Path: C:\Windows\system32\DRIVERS\wanarp.sys
    Address: 0x8CD18000 Size: 77824 File Visible: - Signed: -
    Status: -

    Name: watchdog.sys
    Image Path: C:\Windows\System32\drivers\watchdog.sys
    Address: 0x8C165000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: Wdf01000.sys
    Image Path: C:\Windows\system32\drivers\Wdf01000.sys
    Address: 0x8060D000 Size: 507904 File Visible: - Signed: -
    Status: -

    Name: WDFLDR.SYS
    Image Path: C:\Windows\system32\drivers\WDFLDR.SYS
    Address: 0x80689000 Size: 53248 File Visible: - Signed: -
    Status: -

    Name: Win32k
    Image Path: \Driver\Win32k
    Address: 0x950C0000 Size: 2105344 File Visible: - Signed: -
    Status: -

    Name: win32k.sys
    Image Path: C:\Windows\System32\win32k.sys
    Address: 0x950C0000 Size: 2105344 File Visible: - Signed: -
    Status: -

    Name: WMILIB.SYS
    Image Path: C:\Windows\system32\drivers\WMILIB.SYS
    Address: 0x806DC000 Size: 36864 File Visible: - Signed: -
    Status: -

    Name: WMIxWDM
    Image Path: \Driver\WMIxWDM
    Address: 0x81E3F000 Size: 3903488 File Visible: - Signed: -
    Status: -

    Name: WUDFPf.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFPf.sys
    Address: 0xAA774000 Size: 73728 File Visible: - Signed: -
    Status: -

    Name: WUDFRd.sys
    Image Path: C:\Windows\system32\DRIVERS\WUDFRd.sys
    Address: 0xAA75F000 Size: 83328 File Visible: - Signed: -
    Status: -

    Name: xaudio.sys
    Image Path: C:\Windows\system32\DRIVERS\xaudio.sys
    Address: 0xAA786000 Size: 32768 File Visible: - Signed: -
    Status: -

    Name: 条s
    Image Path: 条s
    Address: 0x87D75000 Size: 311296 File Visible: No Signed: -
    Status: Hidden from the Windows API!





    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Anton at 14:11:04.02 on 06/12/2009
    Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_07
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2038.1032 [GMT -6:00]

    AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
    SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
    FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Users\Anton\Program Files\DNA\btdna.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\Anton\Desktop\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://sympatico.msn.ca/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=desktop
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
    TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [CCUTRAYICON] FactoryMode
    mRun: [SnapfishMediaDetector] c:\program files\snapfish media detector\SnapfishMediaDetector.exe
    mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
    mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
    mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
    mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\snapfi~1.lnk - c:\program files\snapfish media detector\SnapfishMediaDetector.exe
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Risk/Images/stg_drm.ocx
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-ca.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
    Notify: igfxcui - igfxdev.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\anton\appdata\roaming\mozilla\firefox\profiles\nloke4d8.default\
    FF - prefs.js: browser.startup.homepage - hxxp://sympatico.msn.ca/
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
    FF - plugin: c:\users\anton\program files\dna\plugins\npbtdna.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20071116.001\IDSvix86.sys [2007-11-16 180272]
    R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2006-9-3 208896]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2007-12-6 809296]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2007-11-18 112688]
    R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-8-3 38448]
    S2 gupdate1c9b60d61076b20;Google Update Service (gupdate1c9b60d61076b20);c:\program files\google\update\GoogleUpdate.exe [2009-4-5 133104]
    S2 IntelDHSvcConf;Intel DH Service;c:\program files\intel\inteldh\intel media server\tools\IntelDHSvcConf.exe [2006-5-10 29696]

    =============== Created Last 30 ================

    2009-12-03 17:18 <DIR> --d----- c:\program files\Trend Micro
    2009-12-01 16:54 <DIR> --d----- c:\programdata\Norton
    2009-12-01 16:54 <DIR> --d----- c:\progra~2\Norton
    2009-11-25 03:02 2,048 a------- c:\windows\system32\tzres.dll
    2009-11-24 18:00 1,399,296 a------- c:\windows\system32\msxml6.dll
    2009-11-24 18:00 1,257,472 a------- c:\windows\system32\msxml3.dll
    2009-11-24 18:00 714,240 a------- c:\windows\system32\timedate.cpl
    2009-11-11 17:23 2,035,712 a------- c:\windows\system32\win32k.sys
    2009-11-11 17:22 351,232 a------- c:\windows\system32\WSDApi.dll
    2009-11-07 14:55 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf

    ==================== Find3M ====================

    2009-11-25 07:28 63 a------- c:\users\anton\jagex_runescape_preferences2.dat
    2009-11-25 07:28 38 a------- c:\users\anton\jagex_runescape_preferences.dat
    2009-11-02 20:42 195,456 -------- c:\windows\system32\MpSigStub.exe
    2009-10-18 14:04 143,360 a------- c:\windows\inf\infstrng.dat
    2009-10-18 14:04 51,200 a------- c:\windows\inf\infpub.dat
    2009-10-18 14:04 86,016 a------- c:\windows\inf\infstor.dat
    2009-09-10 11:30 213,504 a------- c:\windows\system32\msv1_0.dll
    2009-09-10 09:21 8,147,456 a------- c:\windows\system32\wmploc.DLL
    2009-09-10 09:21 310,784 a------- c:\windows\system32\unregmp2.exe
    2009-07-01 10:23 4 a------- c:\users\anton\appdata\roaming\wklnhst.dat
    2008-08-07 11:56 174 a--sh--- c:\program files\desktop.ini
    2008-08-06 21:00 665,600 a------- c:\windows\inf\drvindex.dat
    2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat

    ============= FINISH: 14:11:59.40 ===============


    i didnt know if i should attach the attach file so here it is



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 20/06/2007 5:19:15 PM
    System Uptime: 12/02/2009 11:25:34 AM (7131 hours ago)

    Motherboard: ASUSTek Computer INC. | | Leonite2
    Processor: Intel(R) Core(TM)2 CPU 4400 @ 2.00GHz | Socket 775 | 2000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 289 GiB total, 208.629 GiB free.
    D: is FIXED (NTFS) - 9 GiB total, 1.008 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    K: is Removable
    L: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP811: 14/11/2009 6:25:52 PM - Scheduled Checkpoint
    RP812: 15/11/2009 9:58:21 AM - Scheduled Checkpoint
    RP813: 16/11/2009 3:56:07 PM - Windows Update
    RP814: 17/11/2009 9:00:17 AM - Scheduled Checkpoint
    RP815: 18/11/2009 12:46:27 AM - Scheduled Checkpoint
    RP816: 19/11/2009 9:27:13 AM - Scheduled Checkpoint
    RP817: 20/11/2009 8:12:22 AM - Windows Update
    RP818: 21/11/2009 12:00:05 AM - Scheduled Checkpoint
    RP819: 22/11/2009 12:00:06 AM - Scheduled Checkpoint
    RP820: 23/11/2009 8:39:03 AM - Scheduled Checkpoint
    RP821: 24/11/2009 6:00:26 PM - Windows Update
    RP822: 25/11/2009 3:00:26 AM - Windows Update
    RP823: 26/11/2009 10:55:00 AM - Windows Update
    RP824: 27/11/2009 1:44:32 AM - Scheduled Checkpoint
    RP825: 28/11/2009 12:35:00 PM - Scheduled Checkpoint
    RP826: 29/11/2009 4:50:02 PM - Scheduled Checkpoint
    RP827: 30/11/2009 3:46:51 PM - Scheduled Checkpoint
    RP828: 01/12/2009 8:53:15 AM - Windows Update
    RP829: 02/12/2009 9:05:28 AM - Scheduled Checkpoint
    RP830: 03/12/2009 8:36:14 AM - Scheduled Checkpoint
    RP831: 04/12/2009 12:22:52 AM - Scheduled Checkpoint
    RP832: 04/12/2009 8:19:35 AM - Windows Update
    RP833: 05/12/2009 3:17:29 AM - Scheduled Checkpoint
    RP834: 06/12/2009 12:20:00 AM - Scheduled Checkpoint

    ==== Installed Programs ======================

    Activation Assistant for the 2007 Microsoft Office suites
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Recommended Settings
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe ExtendScript Toolkit 2
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Reader 8.1.3
    Adobe Setup
    Adobe Shockwave Player 11
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    AppCore
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft PhotoImpression 5
    AV
    Bonjour
    Canon MP Navigator EX 1.0
    Canon MP210 series
    Canon My Printer
    Canon Utilities Easy-PhotoPrint EX
    Canon Utilities Solution Menu
    ccCommon
    CCleaner (remove only)
    DNA
    Enhanced Multimedia Keyboard Solution
    EPSON CX 4200 4800 Guide
    EPSON Printer Software
    EPSON Scan
    Google Earth
    Google Update Helper
    Google Updater
    Hardware Diagnostic Tools
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Customer Experience Enhancements
    HP Customer Feedback
    HP Easy Setup - Frontend
    HP On-Screen Cap/Num/Scroll Lock Indicator
    HP Photosmart Essential 2.0
    HP Photosmart Essential2.5
    HP Picasso Media Center Add-In
    HP Total Care Advisor
    HP Update
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) Matrix Storage Manager
    Intel® Viiv™ Software
    iTunes
    Java(TM) 6 Update 7
    LightScribe 1.4.142.1
    LimeWire 4.18.8
    Linksys Wireless-G PCI Network Adapter with SpeedBooster
    LiveUpdate 3.2 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional Edition 2003
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.0.15)
    MSRedist
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    My HP Games
    NetZero Internet and Voice Offer
    Norton AntiVirus
    Norton Confidential Browser Component
    Norton Confidential Web Protection Component
    Norton Internet Security
    Norton Internet Security (Symantec Corporation)
    Norton Protection Center
    Norton Security Scan
    Norton Security Scan (Symantec Corporation)
    OpenOffice.org Installer 1.0
    PDF Settings
    Print Perfect Clip Art Deluxe DVD
    PSSWCORE
    Python 2.4.3
    QuickTime
    RealPlayer
    Realtek High Definition Audio Driver
    Rhapsody
    Rhapsody Player Engine
    Roxio Activation Module
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator EasyArchive
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio MyDVD Basic v9
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Snapfish Media Detector
    Soft Data Fax Modem with SmartCP
    SPBBC 32bit
    Spelling Dictionaries Support For Adobe Reader 8
    Spybot - Search & Destroy
    Symantec Real Time Storage Protection Component
    SymNet
    System Requirements Lab
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Player Firefox Plugin
    Xvid 1.2.1 final uninstall

    ==== End Of File ===========================

  5. #5
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hi,

    Nothing really jumping out at me.

    LimeWire 4.18.8 <--P2P Programs have become the latest source of infections, your downloading a file from and unknown source, bad idea, its like playing Russian roulette malwarewise.



    Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean






    Please download Malwarebytes from Here or Here

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected .
    • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
    Post the report and also a new HJT log please
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  6. #6
    Member
    Join Date
    Jul 2009
    Posts
    74

    Default

    i should be doing this in a day or so but i cant now seeing as my brother needs thigns open for his final exams

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •