Bill, seems to have worked well! Everything went per the procedure you gave me. Logs below.
2011/06/17 20:44:42.0671 1280 TDSS rootkit removing tool 2.5.5.0 Jun 16 2011 15:25:15
2011/06/17 20:44:42.0703 1280 ================================================================================
2011/06/17 20:44:42.0703 1280 SystemInfo:
2011/06/17 20:44:42.0703 1280
2011/06/17 20:44:42.0703 1280 OS Version: 5.1.2600 ServicePack: 3.0
2011/06/17 20:44:42.0703 1280 Product type: Workstation
2011/06/17 20:44:42.0703 1280 ComputerName: NEWOFFICE_4700
2011/06/17 20:44:42.0703 1280 UserName: Pete
2011/06/17 20:44:42.0703 1280 Windows directory: C:\WINDOWS
2011/06/17 20:44:42.0703 1280 System windows directory: C:\WINDOWS
2011/06/17 20:44:42.0703 1280 Processor architecture: Intel x86
2011/06/17 20:44:42.0703 1280 Number of processors: 2
2011/06/17 20:44:42.0703 1280 Page size: 0x1000
2011/06/17 20:44:42.0703 1280 Boot type: Safe boot
2011/06/17 20:44:42.0703 1280 ================================================================================
2011/06/17 20:44:50.0437 1280 Initialize success
2011/06/17 20:44:53.0578 1300 ================================================================================
2011/06/17 20:44:53.0578 1300 Scan started
2011/06/17 20:44:53.0578 1300 Mode: Manual;
2011/06/17 20:44:53.0578 1300 ================================================================================
2011/06/17 20:44:58.0031 1300 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/06/17 20:44:59.0015 1300 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/06/17 20:44:59.0578 1300 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/06/17 20:45:00.0125 1300 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/06/17 20:45:00.0687 1300 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
2011/06/17 20:45:01.0281 1300 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/06/17 20:45:01.0859 1300 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys
2011/06/17 20:45:02.0484 1300 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
2011/06/17 20:45:03.0062 1300 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/06/17 20:45:03.0593 1300 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/06/17 20:45:04.0156 1300 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/06/17 20:45:04.0671 1300 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/06/17 20:45:05.0218 1300 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/06/17 20:45:05.0812 1300 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/06/17 20:45:06.0359 1300 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/06/17 20:45:06.0890 1300 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/06/17 20:45:07.0437 1300 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/06/17 20:45:08.0171 1300 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/06/17 20:45:08.0703 1300 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/06/17 20:45:09.0359 1300 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/06/17 20:45:09.0968 1300 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/06/17 20:45:10.0515 1300 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/06/17 20:45:11.0828 1300 ati2mtag (f0d0b0cdec0be32d775f404cac2604bf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/06/17 20:45:12.0750 1300 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/06/17 20:45:13.0312 1300 ATWPKT2 (0d74d0aa2eccb5e2019b5e10c38afd19) C:\WINDOWS\system32\drivers\ATWPKT2.SYS
2011/06/17 20:45:13.0875 1300 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/06/17 20:45:14.0468 1300 bdfm (ced6717bd8b67284afcf692b9316b464) C:\WINDOWS\system32\drivers\bdfm.sys
2011/06/17 20:45:15.0078 1300 Bdfndisf (dd3a1af8bdacbf45919f087caa99579b) C:\WINDOWS\system32\DRIVERS\bdfndisf.sys
2011/06/17 20:45:15.0750 1300 bdfsfltr (70975049e22b2efec260816cf505e6e7) C:\WINDOWS\system32\drivers\bdfsfltr.sys
2011/06/17 20:45:16.0078 1300 bdftdif (a7bdb1958d9b8245a0ba83f46abb630c) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys
2011/06/17 20:45:16.0390 1300 BDSelfPr (5eaf583c0b1cc2499761ea3b065f5db2) C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys
2011/06/17 20:45:16.0687 1300 BDVEDISK (bc79b27bc351436b07f57d80bec76036) C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys
2011/06/17 20:45:17.0281 1300 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/06/17 20:45:18.0390 1300 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/06/17 20:45:18.0890 1300 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/06/17 20:45:19.0390 1300 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/06/17 20:45:19.0906 1300 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/06/17 20:45:20.0453 1300 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/06/17 20:45:21.0031 1300 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/06/17 20:45:21.0593 1300 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/06/17 20:45:22.0671 1300 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/06/17 20:45:23.0250 1300 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/06/17 20:45:23.0828 1300 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/06/17 20:45:24.0390 1300 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/06/17 20:45:24.0953 1300 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/06/17 20:45:25.0750 1300 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/06/17 20:45:26.0562 1300 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/06/17 20:45:27.0125 1300 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/06/17 20:45:27.0687 1300 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/06/17 20:45:28.0546 1300 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/06/17 20:45:29.0218 1300 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/06/17 20:45:29.0734 1300 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
2011/06/17 20:45:30.0312 1300 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
2011/06/17 20:45:30.0484 1300 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
2011/06/17 20:45:31.0000 1300 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
2011/06/17 20:45:31.0546 1300 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/06/17 20:45:32.0234 1300 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/06/17 20:45:32.0796 1300 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/06/17 20:45:33.0328 1300 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
2011/06/17 20:45:33.0921 1300 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/06/17 20:45:34.0453 1300 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/06/17 20:45:35.0015 1300 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/06/17 20:45:35.0578 1300 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/06/17 20:45:36.0156 1300 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/06/17 20:45:36.0703 1300 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/06/17 20:45:37.0234 1300 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/06/17 20:45:37.0796 1300 grmnusb (d956358054e99e6ffac69cd87e893a89) C:\WINDOWS\system32\drivers\grmnusb.sys
2011/06/17 20:45:38.0437 1300 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/06/17 20:45:38.0968 1300 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/06/17 20:45:39.0546 1300 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2011/06/17 20:45:40.0109 1300 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2011/06/17 20:45:40.0640 1300 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2011/06/17 20:45:41.0250 1300 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
2011/06/17 20:45:42.0125 1300 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
2011/06/17 20:45:43.0015 1300 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/06/17 20:45:43.0609 1300 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/06/17 20:45:44.0156 1300 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/06/17 20:45:44.0703 1300 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/06/17 20:45:45.0265 1300 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/06/17 20:45:45.0843 1300 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/06/17 20:45:46.0359 1300 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/06/17 20:45:46.0906 1300 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/06/17 20:45:47.0453 1300 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/06/17 20:45:48.0000 1300 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/06/17 20:45:48.0531 1300 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/06/17 20:45:49.0093 1300 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/06/17 20:45:49.0718 1300 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/06/17 20:45:50.0593 1300 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/06/17 20:45:51.0140 1300 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/06/17 20:45:51.0703 1300 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/06/17 20:45:52.0281 1300 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/06/17 20:45:52.0921 1300 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/06/17 20:45:54.0093 1300 lvpopflt (01f0e010acb61472163e9d02d3ff531a) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
2011/06/17 20:45:54.0671 1300 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
2011/06/17 20:45:55.0328 1300 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
2011/06/17 20:45:57.0968 1300 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
2011/06/17 20:46:00.0562 1300 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2011/06/17 20:46:01.0109 1300 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/06/17 20:46:01.0656 1300 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/06/17 20:46:02.0171 1300 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2011/06/17 20:46:02.0703 1300 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/06/17 20:46:03.0250 1300 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/06/17 20:46:03.0750 1300 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/06/17 20:46:04.0328 1300 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/06/17 20:46:05.0046 1300 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/06/17 20:46:05.0734 1300 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/06/17 20:46:06.0328 1300 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/06/17 20:46:06.0828 1300 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/06/17 20:46:07.0343 1300 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/06/17 20:46:07.0875 1300 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/06/17 20:46:08.0390 1300 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/06/17 20:46:08.0953 1300 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/06/17 20:46:09.0515 1300 MusCAudio (9cfdafe502c5d9efdb23cb55f32144b7) C:\WINDOWS\system32\drivers\MusCAudio.sys
2011/06/17 20:46:10.0093 1300 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/06/17 20:46:10.0703 1300 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/06/17 20:46:11.0296 1300 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/06/17 20:46:11.0828 1300 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/06/17 20:46:12.0359 1300 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/06/17 20:46:12.0921 1300 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/06/17 20:46:13.0500 1300 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/06/17 20:46:14.0078 1300 NEOFLTR_630_13725 (e6f4104575eb71b9ba53469f84ce7bbc) C:\WINDOWS\system32\Drivers\NEOFLTR_630_13725.SYS
2011/06/17 20:46:14.0687 1300 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/06/17 20:46:15.0296 1300 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/06/17 20:46:15.0968 1300 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/06/17 20:46:16.0656 1300 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/06/17 20:46:17.0359 1300 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/06/17 20:46:18.0484 1300 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/06/17 20:46:19.0609 1300 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/06/17 20:46:20.0125 1300 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/06/17 20:46:20.0687 1300 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
2011/06/17 20:46:21.0812 1300 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/06/17 20:46:22.0343 1300 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/06/17 20:46:22.0859 1300 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/06/17 20:46:23.0406 1300 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/06/17 20:46:24.0437 1300 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/06/17 20:46:24.0984 1300 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/06/17 20:46:27.0468 1300 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/06/17 20:46:27.0984 1300 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/06/17 20:46:28.0546 1300 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
2011/06/17 20:46:29.0625 1300 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/06/17 20:46:29.0781 1300 Profos (1bfe86c679a43994e36e623fb6898cdb) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys
2011/06/17 20:46:30.0343 1300 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/06/17 20:46:30.0875 1300 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/06/17 20:46:31.0406 1300 PxHelp20 (d970470f8f39470bdae94d313a1ccdce) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/06/17 20:46:31.0953 1300 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/06/17 20:46:32.0484 1300 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/06/17 20:46:33.0031 1300 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/06/17 20:46:33.0578 1300 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/06/17 20:46:34.0140 1300 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/06/17 20:46:34.0656 1300 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/06/17 20:46:35.0484 1300 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/06/17 20:46:36.0046 1300 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/06/17 20:46:36.0562 1300 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/06/17 20:46:37.0156 1300 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/06/17 20:46:37.0687 1300 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/06/17 20:46:38.0281 1300 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/06/17 20:46:38.0890 1300 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/06/17 20:46:39.0468 1300 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/06/17 20:46:40.0031 1300 RIOUNIV (f772c4ba29f4117d15c66f63d010d9f0) C:\WINDOWS\system32\Drivers\RIOUNIV.sys
2011/06/17 20:46:40.0718 1300 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/06/17 20:46:41.0281 1300 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/06/17 20:46:41.0812 1300 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/06/17 20:46:42.0421 1300 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/06/17 20:46:43.0484 1300 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/06/17 20:46:44.0046 1300 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/06/17 20:46:44.0750 1300 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys
2011/06/17 20:46:45.0437 1300 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/06/17 20:46:45.0968 1300 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/06/17 20:46:46.0546 1300 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/06/17 20:46:47.0234 1300 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/06/17 20:46:47.0843 1300 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
2011/06/17 20:46:48.0375 1300 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
2011/06/17 20:46:48.0937 1300 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/06/17 20:46:49.0468 1300 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/06/17 20:46:49.0984 1300 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/06/17 20:46:50.0531 1300 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/06/17 20:46:51.0093 1300 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/06/17 20:46:51.0656 1300 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/06/17 20:46:52.0187 1300 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/06/17 20:46:52.0734 1300 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/06/17 20:46:53.0390 1300 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/06/17 20:46:54.0031 1300 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/06/17 20:46:54.0531 1300 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/06/17 20:46:55.0046 1300 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/06/17 20:46:55.0546 1300 tfsnboio (75b30b9ea32fe7d8bbc332d3b944ad46) C:\WINDOWS\system32\dla\tfsnboio.sys
2011/06/17 20:46:56.0031 1300 tfsncofs (b811a431b14694d88eb5befaa55b4501) C:\WINDOWS\system32\dla\tfsncofs.sys
2011/06/17 20:46:56.0531 1300 tfsndrct (f5e2cf2144f1fe51dadd6e9063d311eb) C:\WINDOWS\system32\dla\tfsndrct.sys
2011/06/17 20:46:57.0031 1300 tfsndres (e32b32045b6b914fd4caae8be6ca7e8a) C:\WINDOWS\system32\dla\tfsndres.sys
2011/06/17 20:46:57.0515 1300 tfsnifs (43034b10a94d1c6f13a1a0e848f51226) C:\WINDOWS\system32\dla\tfsnifs.sys
2011/06/17 20:46:58.0062 1300 tfsnopio (f5ee0faafde37326ea35acbfa5defd3d) C:\WINDOWS\system32\dla\tfsnopio.sys
2011/06/17 20:46:58.0562 1300 tfsnpool (597348eb65b3e19709e9a45ca2b30b61) C:\WINDOWS\system32\dla\tfsnpool.sys
2011/06/17 20:46:59.0078 1300 tfsnudf (767affd52432a0f7e7d39f6ff64401f4) C:\WINDOWS\system32\dla\tfsnudf.sys
2011/06/17 20:46:59.0625 1300 tfsnudfa (2806b2fd00263ccd90cc0638c6139eb0) C:\WINDOWS\system32\dla\tfsnudfa.sys
2011/06/17 20:47:00.0187 1300 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/06/17 20:47:00.0359 1300 Trufos (b16d66a71de03285e14e9f165b59eda4) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys
2011/06/17 20:47:00.0953 1300 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/06/17 20:47:01.0484 1300 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/06/17 20:47:02.0140 1300 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/06/17 20:47:02.0828 1300 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys
2011/06/17 20:47:03.0421 1300 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/06/17 20:47:03.0984 1300 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/06/17 20:47:04.0515 1300 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/06/17 20:47:05.0062 1300 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/06/17 20:47:05.0593 1300 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/06/17 20:47:06.0125 1300 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/06/17 20:47:06.0640 1300 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/06/17 20:47:07.0140 1300 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/06/17 20:47:07.0671 1300 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
2011/06/17 20:47:08.0234 1300 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/06/17 20:47:08.0750 1300 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/06/17 20:47:09.0281 1300 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/06/17 20:47:09.0796 1300 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/06/17 20:47:10.0406 1300 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/06/17 20:47:10.0968 1300 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
2011/06/17 20:47:11.0984 1300 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/06/17 20:47:12.0578 1300 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\WINDOWS\system32\DRIVERS\wimfltr.sys
2011/06/17 20:47:13.0328 1300 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2011/06/17 20:47:14.0234 1300 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/06/17 20:47:14.0406 1300 MBR (0x1B8) (87f75abb087c82bee3a1fbec42bbabd0) \Device\Harddisk0\DR0
2011/06/17 20:47:14.0421 1300 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/06/17 20:47:14.0453 1300 MBR (0x1B8) (35c6b2fcde68facbefe0a4a7200bae58) \Device\Harddisk1\DR1
2011/06/17 20:47:14.0640 1300 ================================================================================
2011/06/17 20:47:14.0640 1300 Scan finished
2011/06/17 20:47:14.0640 1300 ================================================================================
2011/06/17 20:47:14.0687 1292 Detected object count: 1
2011/06/17 20:47:14.0687 1292 Actual detected object count: 1
2011/06/17 20:47:31.0468 1292 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/06/17 20:47:31.0468 1292 \Device\Harddisk0\DR0 - ok
2011/06/17 20:47:31.0468 1292 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/06/17 20:47:55.0828 1272 Deinitialize success
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 185):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x80700000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 aliide.sys
0xF798D000 cmdide.sys
0xF798F000 toside.sys
0xF7991000 viaide.sys
0xF7993000 intelide.sys
0xF7607000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF7995000 dmload.sys
0xF74B2000 dmio.sys
0xF770F000 PartMgr.sys
0xF7617000 VolSnap.sys
0xF789B000 cpqarray.sys
0xF749A000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF7482000 atapi.sys
0xF789F000 aha154x.sys
0xF7717000 sparrow.sys
0xF78A3000 symc810.sys
0xF7627000 aic78xx.sys
0xF78A7000 dac960nt.sys
0xF7637000 ql10wnt.sys
0xF78AB000 amsint.sys
0xF771F000 asc.sys
0xF78AF000 asc3550.sys
0xF7727000 mraid35x.sys
0xF772F000 i2omp.sys
0xF78B3000 ini910u.sys
0xF7647000 ql1240.sys
0xF7657000 aic78u2.sys
0xF7737000 symc8xx.sys
0xF773F000 sym_hi.sys
0xF7747000 sym_u3.sys
0xF774F000 ABP480N5.SYS
0xF7757000 asc3350p.sys
0xF7997000 cd20xrnt.sys
0xF7667000 ultra.sys
0xF786E000 adpu160m.sys
0xF775F000 dpti2o.sys
0xF7677000 ql1080.sys
0xF7687000 ql1280.sys
0xF7697000 ql12160.sys
0xF7767000 perc2.sys
0xF7999000 perc2hib.sys
0xF776F000 hpn.sys
0xF78B7000 cbidf2k.sys
0xF7842000 dac2w2k.sys
0xF76A7000 disk.sys
0xF76B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7967000 fltmgr.sys
0xF7830000 sr.sys
0xF7952000 drvmcdb.sys
0xF76C7000 PxHelp20.sys
0xF7A38000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7A0B000 NDIS.sys
0xF76D7000 sisagp.sys
0xF76E7000 viaagp.sys
0xF7B38000 Mup.sys
0xF76F7000 agp440.sys
0xF7587000 alim1541.sys
0xF7577000 amdagp.sys
0xF7567000 agpCPQ.sys
0xB9F5C000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB9760000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB974C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xBA68F000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB9728000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA687000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB96F4000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys
0xB96D1000 \SystemRoot\system32\DRIVERS\ks.sys
0xB95D2000 \SystemRoot\system32\DRIVERS\HSF_DP.sys
0xB952B000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0xBA67F000 \SystemRoot\System32\Drivers\Modem.SYS
0xB9505000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xB946F000 \SystemRoot\system32\drivers\smwdm.sys
0xB944B000 \SystemRoot\system32\drivers\portcls.sys
0xF7537000 \SystemRoot\system32\drivers\drmk.sys
0xF79C7000 \SystemRoot\system32\drivers\aeaudio.sys
0xF7527000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xBA677000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA66F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB9437000 \SystemRoot\system32\DRIVERS\parport.sys
0xF7517000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA6D7000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7507000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA667000 \SystemRoot\system32\drivers\Afc.sys
0xBA6D3000 \SystemRoot\system32\drivers\pfc.sys
0xF79CB000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF74F7000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF7472000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF7797000 \SystemRoot\SYSTEM32\DRIVERS\GEARAspiWDM.sys
0xF7AB3000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF7462000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA6C7000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB9420000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF7452000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF7442000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF779F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB940F000 \SystemRoot\system32\DRIVERS\psched.sys
0xF7432000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF77A7000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF77AF000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF77B7000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xB938F000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF7422000 \SystemRoot\system32\DRIVERS\termdd.sys
0xB9377000 \SystemRoot\system32\DRIVERS\bdfndisf.sys
0xF79CF000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB9319000 \SystemRoot\system32\DRIVERS\update.sys
0xBA0A3000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF77BF000 \SystemRoot\system32\DRIVERS\omci.sys
0xF7887000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA7F0000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79D3000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF794B000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xBA730000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xF79D7000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA41E000 \SystemRoot\System32\Drivers\Null.SYS
0xF79D9000 \SystemRoot\System32\Drivers\Beep.SYS
0xF77CF000 \SystemRoot\system32\drivers\ssrtln.sys
0xF77D7000 \SystemRoot\System32\drivers\vga.sys
0xF79DB000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79DD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF77DF000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF77E7000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA728000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xB1276000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xB121D000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xBA7C0000 \??\C:\WINDOWS\system32\Drivers\NEOFLTR_630_13725.SYS
0xB11F7000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xBA7B0000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xB11D7000 \??\C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys
0xB11AF000 \SystemRoot\system32\DRIVERS\netbt.sys
0xB118D000 \SystemRoot\System32\drivers\afd.sys
0xBA790000 \SystemRoot\system32\DRIVERS\netbios.sys
0xB1162000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xB10F2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA780000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA760000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB10DA000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF79F5000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB12E9000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA6A7000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA08B000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF04A000 \SystemRoot\System32\ati2cqag.dll
0xBF084000 \SystemRoot\System32\ati3duag.dll
0xBF2A7000 \SystemRoot\System32\ativvaxx.dll
0xBF31C000 \SystemRoot\System32\ATMFD.DLL
0xB9F8C000 \SystemRoot\system32\drivers\drvnddm.sys
0xF7A65000 \SystemRoot\system32\dla\tfsndres.sys
0xAFF5C000 \SystemRoot\system32\dla\tfsnifs.sys
0xAFFFA000 \SystemRoot\system32\dla\tfsnopio.sys
0xF79CD000 \SystemRoot\system32\dla\tfsnpool.sys
0xB93CF000 \SystemRoot\system32\dla\tfsnboio.sys
0xB9F7C000 \SystemRoot\system32\dla\tfsncofs.sys
0xF7A67000 \SystemRoot\system32\dla\tfsndrct.sys
0xAFF43000 \SystemRoot\system32\dla\tfsnudf.sys
0xAFF2A000 \SystemRoot\system32\dla\tfsnudfa.sys
0xAFE62000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAFBCD000 \SystemRoot\system32\drivers\wdmaud.sys
0xAFEAA000 \SystemRoot\system32\drivers\sysaudio.sys
0xAF9BA000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xAF867000 \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys
0xB9847000 \SystemRoot\system32\DRIVERS\dsunidrv.sys
0xAF567000 \SystemRoot\system32\DRIVERS\srv.sys
0xAFC02000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xAF005000 \SystemRoot\system32\drivers\bdfsfltr.sys
0xBA6AF000 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys
0xAEE15000 \SystemRoot\System32\Drivers\HTTP.sys
0xAEDD1000 \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys
0xAEB2B000 \SystemRoot\system32\drivers\bdfm.sys
0xAEB00000 \SystemRoot\system32\drivers\kmixer.sys
0xAEADC000 \SystemRoot\System32\Drivers\Fastfat.SYS
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 51):
0 System Idle Process
4 System
872 C:\WINDOWS\SYSTEM32\smss.exe
920 csrss.exe
944 C:\WINDOWS\SYSTEM32\winlogon.exe
988 C:\WINDOWS\SYSTEM32\services.exe
1000 C:\WINDOWS\SYSTEM32\lsass.exe
1196 C:\WINDOWS\SYSTEM32\svchost.exe
1260 svchost.exe
1384 C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
1436 C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
1524 C:\WINDOWS\SYSTEM32\svchost.exe
1596 svchost.exe
1680 svchost.exe
1872 C:\WINDOWS\SYSTEM32\spoolsv.exe
520 svchost.exe
604 C:\WINDOWS\explorer.exe
624 C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
648 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
892 C:\Program Files\Bonjour\mDNSResponder.exe
1360 C:\WINDOWS\SYSTEM32\svchost.exe
1488 C:\WINDOWS\SYSTEM32\svchost.exe
1556 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
1988 C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
180 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
204 C:\Program Files\QuickTime\QTTask.exe
1756 C:\Program Files\iTunes\iTunesHelper.exe
224 C:\Program Files\HP\HP Software Update\hpwuschd2.exe
1592 C:\WINDOWS\SYSTEM32\ctfmon.exe
284 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
308 C:\Program Files\Messenger\msmsgs.exe
416 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
768 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
2064 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
2324 C:\WINDOWS\SYSTEM32\svchost.exe
2520 C:\WINDOWS\SYSTEM32\svchost.exe
2668 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2908 C:\WINDOWS\SYSTEM32\svchost.exe
2988 wdfmgr.exe
3036 C:\WINDOWS\wanmpsvc.exe
3148 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
3376 C:\WINDOWS\SYSTEM32\wuauclt.exe
3460 C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
3532 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
2856 C:\Program Files\iPod\bin\iPodService.exe
904 alg.exe
1648 C:\WINDOWS\SYSTEM32\msiexec.exe
3096 C:\WINDOWS\SYSTEM32\wscntfy.exe
1248 wmiprvse.exe
3448 C:\Program Files\Google\Update\GoogleUpdate.exe
1420 C:\Documents and Settings\Pete\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02f10c00 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: ST380013AS, Rev: 8.12
PhysicalDrive1 Model Number: ST3120026AS, Rev: 3.56
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Dell MBR code detected
SHA1: 84B95CE8A54B7C5C3AAF149934FC46FB70FF8365
111 GB \\.\PhysicalDrive1 Legit MBR code detected
SHA1: 317A49A9E93F077F2D004734D2A7B6CA7E7B9495
Done!
ComboFix 11-06-17.04 - Pete 06/17/2011 21:20:50.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2581 [GMT -7:00]
Running from: c:\documents and settings\Pete\Desktop\ComboFix.exe
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Derek\Application Data\Mozilla\Firefox\Profiles\gq61dpo4.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}
c:\documents and settings\Derek\Application Data\Mozilla\Firefox\Profiles\gq61dpo4.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\chrome\xulcache.jar
c:\documents and settings\Derek\Application Data\Mozilla\Firefox\Profiles\gq61dpo4.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\defaults\preferences\xulcache.js
c:\documents and settings\Derek\Application Data\Mozilla\Firefox\Profiles\gq61dpo4.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\install.rdf
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\7l674wmo.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\7l674wmo.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\chrome\xulcache.jar
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\7l674wmo.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\defaults\preferences\xulcache.js
c:\documents and settings\LocalService\Application Data\Mozilla\Firefox\Profiles\7l674wmo.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\install.rdf
c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\4p0usagx.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}
c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\4p0usagx.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\chrome\xulcache.jar
c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\4p0usagx.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\defaults\preferences\xulcache.js
c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\4p0usagx.default\extensions\{00638964-a227-4a4a-9360-6a55b05751b7}\install.rdf
c:\documents and settings\Pete\g2mdlhlpx.exe
c:\documents and settings\Pete\WINDOWS
c:\program files\MyWaySA
.
.
((((((((((((((((((((((((( Files Created from 2011-05-18 to 2011-06-18 )))))))))))))))))))))))))))))))
.
.
2011-06-18 03:56 . 2011-06-18 03:56 -------- d-----w- c:\windows\LastGood
2011-06-15 03:51 . 2011-06-15 03:51 -------- d-----w- c:\program files\ERUNT
2011-06-14 04:34 . 2011-06-14 04:34 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-11 03:27 . 2011-06-11 03:27 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-06-11 03:03 . 2011-06-11 03:03 0 ---ha-w- c:\documents and settings\Pete\fjgbsydevb.tmp
2011-05-27 23:20 . 2011-05-27 23:20 -------- d-----w- c:\documents and settings\Pete\Local Settings\Application Data\Garmin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-03-26 23:02 . 2011-03-26 23:02 264768 ----a-w- c:\windows\system32\bda12F3.tmp
2003-03-05 05:59 . 2005-05-29 03:40 16204762 ------w- c:\program files\DVD Wizard Pro Complete.exe
2002-04-14 19:20 . 2005-05-29 03:40 3115916 ------w- c:\program files\dvdwpro.exe
2011-01-18 16:09 . 2009-08-09 03:50 65536 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-29 06:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-29 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-29 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\America Online 9.0a\AOL.EXE" [2005-07-12 50776]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-29 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2011-01-18 843144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
.
c:\documents and settings\Pete\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TotalMedia Backup Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk
backup=c:\windows\pss\TotalMedia Backup Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pete^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\Pete\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 06:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2005-07-12 05:17 50776 ------w- c:\program files\America Online 9.0a\aol.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-08-25 18:52 339968 ------w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDefender Antiphishing Helper]
2009-02-23 18:30 69632 ----a-w- c:\program files\BitDefender\BitDefender 2009\IEShow.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTransferAgent]
2007-11-13 21:46 135168 ------w- c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-11-16 09:05 127035 ------w- c:\windows\SYSTEM32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-08-24 00:19 57344 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GBMPro8Agent]
2008-09-11 12:27 189056 ------w- c:\program files\Genie-Soft\GBMPro8\GBMAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-09-26 00:52 50736 ------w- c:\program files\Common Files\AOL\1127796691\ee\aolsoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-06-10 03:55 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 23:08 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 18:35 2780432 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 23:12 26192168 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-01-05 04:03 136600 ------w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-09-29 18:17 68856 ------w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2004-01-07 07:01 110592 ------w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VSSERV"=2 (0x2)
"RioMSC"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IntuitUpdateService"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c9d129e73f31b4"=2 (0x2)
"EPSONStatusAgent2"=2 (0x2)
"DSBrokerService"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Canon\\CSCLIB\\CDPROCMN.exe"=
"c:\\Program Files\\Canon\\CSCLIB\\CDPROC.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1127796691\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1127796691\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\{B1054C0C-0C16-41E1-8A9D-35F065793E92}\\setup\\hpznui01.exe"=
.
R1 NEOFLTR_630_13725;Juniper Networks TDI Filter Driver (NEOFLTR_630_13725);c:\windows\SYSTEM32\DRIVERS\NEOFLTR_630_13725.sys [11/21/2008 1:37 AM 64480]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [10/6/2008 6:16 PM 82696]
R3 bdfm;BDFM;c:\windows\SYSTEM32\DRIVERS\bdfm.sys [9/18/2008 12:09 PM 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\SYSTEM32\DRIVERS\bdfndisf.sys [2/12/2009 4:52 PM 104456]
S2 gupdate1c9d129e73f31b4;Google Update Service (gupdate1c9d129e73f31b4);c:\program files\Google\Update\GoogleUpdate.exe [5/9/2009 9:43 PM 133104]
S2 portD;ABS PortIO Service;c:\windows\system32\DRIVERS\portd2k.sys --> c:\windows\system32\DRIVERS\portd2k.sys [?]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [1/20/2009 7:16 PM 172032]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2/28/2011 6:44 PM 183560]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/9/2009 9:43 PM 133104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
S3 MusCAudio;MusCAudio;c:\windows\SYSTEM32\DRIVERS\MusCAudio.sys [7/3/2009 9:36 PM 23096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]
.
2011-06-12 c:\windows\Tasks\GBM - New Backup Job-Full.job
- c:\program files\Genie-Soft\GBMPro8\GBM8.exe [2008-07-21 12:27]
.
2011-06-12 c:\windows\Tasks\GBM - Weekly started 6-23-09-Full.job
- c:\program files\Genie-Soft\GBMPro8\GBM8.exe [2008-07-21 12:27]
.
2011-06-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-25 23:15]
.
2011-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-10 04:43]
.
2011-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-10 04:43]
.
2011-06-18 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-29 06:44]
.
2011-06-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-29 05:18]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
TCP: DhcpNameServer = 192.168.1.1
DPF: {9B479D7B-916A-45B0-B042-D42865A60E21} - hxxp://192.168.1.100:8080/DvrOcx.cab
FF - ProfilePath - c:\documents and settings\Pete\Application Data\Mozilla\Firefox\Profiles\4p0usagx.default\
FF - prefs.js: browser.startup.homepage - hxxp://webmail.aol.com/28200/aol/en-us/Suite.aspx|
http://www.aol.com/
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-gStart - c:\garmin\gStart.exe
AddRemove-MapOverlay Plugin_is1 - c:\documents and settings\All Users\Application Data\ZoneFiveSoftware\SportTracks\2.0\Plugins\Installed\0d1e39ae-cd7f-4d03-a0a6-1cd3b9e0fa3e\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-17 21:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7CACDF5A-0E2D-A998-38B4B1D490EAE887}\{83892839-8EE2-C547-3E6DBF0265E34072}\{B9A8F094-A05A-7BFC-2DD781993331EE07}*]
"63AUOURV1X6YIYB2ELIFO4LTRC1"=hex:01,00,01,00,00,00,00,00,87,da,ad,38,2b,26,f8,
c3,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8CD4472C-E90F-9EEE-8658179FAD84CDE4}\{86C14694-A4A0-6014-B9D2B6867C4357D1}\{413E2BB7-2C4D-BBD1-7F39BC4CF716110E}*]
"63AUOURV1X6YIYB2ELIFO4LTRC1"=hex:01,00,01,00,00,00,00,00,87,da,ad,38,2b,26,f8,
c3,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
Completion time: 2011-06-17 21:32:32
ComboFix-quarantined-files.txt 2011-06-18 04:32
.
Pre-Run: 3,592,130,560 bytes free
Post-Run: 4,600,913,920 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - DD2788608EAA118543F8F47EF5ABEE86