Mbar never completed its update/gave me the success: database successfully updated, log files: Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.06.01.01 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 6.0.2900.5512 JB :: JB-05AA7CF32685 [administrator] 7/13/2013 7:20:51 AM mbar-log-2013-07-13 (07-20-51).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 219753 Time elapsed: 14 minute(s), 15 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) System log: --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.06.0.1004 © Malwarebytes Corporation 2011-2012 OS version: 5.1.2600 Windows XP Service Pack 3 x86 System is currently in a safe mode Account is Administrative Internet Explorer version: 6.0.2900.5512 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED CPU speed: 1.464000 GHz Memory total: 1073201152, free: 646168576 Connection refused Initializing... Done! Scanning drivers directory: E:\WINDOWS\system32\drivers... Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6A7C6A7C Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 63 Numsec = 78140097 Partition file system is NTFS Partition is bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 40020664320 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-78145360-78165360)... Done! Drive 1 Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6D806D80 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 63 Numsec = 156280257 Partition file system is NTFS Partition is not bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 80026361856 bytes Sector size: 512 bytes Done! Scan finished ======================================= Removal queue found; removal started Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\bootstrap_0_0_63_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_r.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\bootstrap_1_0_63_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_r.mbam... Removal finished --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.06.0.1004 © Malwarebytes Corporation 2011-2012 OS version: 5.1.2600 Windows XP Service Pack 3 x86 Account is Administrative Internet Explorer version: 6.0.2900.5512 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED CPU speed: 1.464000 GHz Memory total: 1073201152, free: 681156608 ======================================= --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.06.0.1004 © Malwarebytes Corporation 2011-2012 OS version: 5.1.2600 Windows XP Service Pack 3 x86 System is currently in a safe mode Account is Administrative Internet Explorer version: 6.0.2900.5512 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED CPU speed: 1.464000 GHz Memory total: 1073201152, free: 854634496 Connection refused Connection refused Initializing... ------------ Kernel report ------------ 07/13/2013 07:20:31 ------------ Loaded modules ----------- \WINDOWS\system32\ntoskrnl.exe \WINDOWS\system32\hal.dll \WINDOWS\system32\KDCOM.DLL \WINDOWS\system32\BOOTVID.dll ACPI.sys \WINDOWS\system32\DRIVERS\WMILIB.SYS pci.sys isapnp.sys pciide.sys \WINDOWS\system32\DRIVERS\PCIIDEX.SYS MountMgr.sys ftdisk.sys dmload.sys dmio.sys PartMgr.sys VolSnap.sys atapi.sys SI3112r.sys \WINDOWS\system32\DRIVERS\SCSIPORT.SYS disk.sys \WINDOWS\system32\DRIVERS\CLASSPNP.SYS fltmgr.sys sr.sys SiWinAcc.sys KSecDD.sys Ntfs.sys NDIS.sys nv_agp.sys Mup.sys avgrkx86.sys avglogx.sys avgmfx86.sys avgidshx.sys \SystemRoot\system32\DRIVERS\usbohci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\NVENET.sys \SystemRoot\system32\DRIVERS\imapi.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\redbook.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\fdc.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\psched.sys \SystemRoot\system32\DRIVERS\msgpc.sys \SystemRoot\system32\DRIVERS\ptilink.sys \SystemRoot\system32\DRIVERS\raspti.sys \SystemRoot\system32\DRIVERS\rdpdr.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\update.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\flpydisk.sys \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\ipsec.sys \SystemRoot\system32\DRIVERS\tcpip.sys \SystemRoot\system32\DRIVERS\avgtdix.sys \SystemRoot\system32\DRIVERS\ipnat.sys \SystemRoot\system32\DRIVERS\netbt.sys \SystemRoot\System32\vsdatant.sys \SystemRoot\System32\drivers\afd.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\System32\Drivers\Udfs.SYS \SystemRoot\System32\Drivers\dump_atapi.sys \SystemRoot\System32\Drivers\dump_WMILIB.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\watchdog.sys \SystemRoot\System32\drivers\dxg.sys \SystemRoot\System32\drivers\dxgthk.sys \SystemRoot\System32\framebuf.dll \SystemRoot\System32\Drivers\Fastfat.SYS \SystemRoot\system32\DRIVERS\srv.sys \??\E:\WINDOWS\system32\drivers\mbamchameleon.sys \??\E:\WINDOWS\system32\drivers\mbamswissarmy.sys \WINDOWS\system32\ntdll.dll ----------- End ----------- Done! <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffffff86f26ab8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-f\ Lower Device Object: 0xffffffff86f00d98 Lower Device Driver Name: \Driver\atapi\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff86effab8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\ Lower Device Object: 0xffffffff86f00940 Lower Device Driver Name: \Driver\atapi\ <<<2>>> Device number: 0, partition: 1 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff86effab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff86f28b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\ DevicePointer: 0xffffffff86effab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff86f67910, DeviceName: \Device\00000068\, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff86f00940, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: E: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> Device number: 0, partition: 1 <<<3>>> Volume: E: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: E:\WINDOWS\system32\drivers... <<<2>>> Device number: 0, partition: 1 <<<3>>> Volume: E: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Read File: File "e:\WINDOWS\system32\drivers\acpiec.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\acpiec.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv01nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv01nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv02nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv02nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv05nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv05nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv07nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv07nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv08nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv08nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv09nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv09nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\adv11nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\adv11nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\agp440.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\agp440.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\agpcpq.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\agpcpq.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\alim1541.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\alim1541.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\amdagp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\amdagp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\amdk6.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\amdk6.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\arp1394.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\arp1394.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1btxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1btxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1mdxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1mdxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1pdxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1pdxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1raxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1raxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1rvxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1rvxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1snxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1snxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1ttxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1ttxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1tuxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1tuxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1xbxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1xbxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati1xsxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati1xsxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mtlmnt5.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mtlmnt5.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mtlstrm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mtlstrm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mtxparhm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mtxparhm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mup.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mup.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mutohpen.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mutohpen.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ndis.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ndis.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\netwlan5.img" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\netwlan5.img" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nic1394.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nic1394.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nikedrv.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nikedrv.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nmnt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nmnt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ntfs.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ntfs.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ntmtlfax.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ntmtlfax.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nwlnkipx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nwlnkipx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nwlnknb.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nwlnknb.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rdpwd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rdpwd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\recagent.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\recagent.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rfcomm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rfcomm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rio8drv.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rio8drv.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\riodrv.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\riodrv.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rmcast.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rmcast.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rndismp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rndismp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rndismpx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rndismpx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rootmdm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rootmdm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\s3gnbm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\s3gnbm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sdbus.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sdbus.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sffdisk.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sffdisk.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sffp_mmc.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sffp_mmc.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sffp_sd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sffp_sd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\siint5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\siint5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sisagp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sisagp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\slnt7554.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\slnt7554.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\slntamr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\slntamr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\slnthal.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\slnthal.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\slwdmsup.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\slwdmsup.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\smbali.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\smbali.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\fsvga.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\fsvga.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\gagp30kx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\gagp30kx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\gm.dls" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\gm.dls" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\gmreadme.txt" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\gmreadme.txt" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hidir.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hidir.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hsfbs2s2.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hsfbs2s2.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hsfcxts2.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hsfcxts2.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\hsfdpsp2.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\hsfdpsp2.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\sonydcam.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\sonydcam.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\stream.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\stream.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tape.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tape.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tcpip6.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tcpip6.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tdpipe.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tdpipe.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tdtcp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tdtcp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tosdvd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tosdvd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tsbvcap.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tsbvcap.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\tunmp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\tunmp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\uagp35.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\uagp35.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\udfs.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\udfs.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\irbus.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\irbus.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\jedih2rx.bin" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\jedih2rx.bin" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\jedireg.pat" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\jedireg.pat" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ksecdd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ksecdd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mbamcatchme.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mbamcatchme.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mcd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mcd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mdmxsdk.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mdmxsdk.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mf.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mf.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\modem.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\modem.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mountmgr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mountmgr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\mqac.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\mqac.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati2mtaa.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati2mtaa.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atv02nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atv02nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nwlnkspx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nwlnkspx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\rawwan.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\rawwan.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\smclib.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\smclib.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usb8023.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usb8023.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\nwrdr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\nwrdr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\oprghdlr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\oprghdlr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\p3.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\p3.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\partmgr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\partmgr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\processr.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\processr.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ramsed.bin" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ramsed.bin" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ch7xxnt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ch7xxnt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\cinemst2.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\cinemst2.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\classpnp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\classpnp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\cpqdap01.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\cpqdap01.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\crusoe.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\crusoe.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\cxthsfs2.cty" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\cxthsfs2.cty" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\diskdump.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\diskdump.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usb8023x.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usb8023x.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usbcamd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usbcamd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usbcamd2.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usbcamd2.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usbintel.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usbintel.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\usbvideo.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\usbvideo.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\vchnt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\vchnt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\vdmindvd.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\vdmindvd.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\viaagp.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\viaagp.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\wadv07nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\wadv07nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\wadv08nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\wadv08nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\wadv09nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\wadv09nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\wadv11nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\wadv11nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\watv06nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\watv06nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\watv10nt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\watv10nt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ws2ifsl.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ws2ifsl.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atv04nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atv04nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atv06nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atv06nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atv10nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atv10nt5.dll" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\avgntflt.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\avgntflt.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bridge.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bridge.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthenum.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthenum.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthpan.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthpan.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthport.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthport.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthprint.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthprint.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\bthusb.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\bthusb.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\cbidf2k.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\cbidf2k.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ati2mtag.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ati2mtag.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinbtxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinbtxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinmdxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinmdxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinpdxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinpdxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinraxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinraxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinrvxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinrvxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinsnxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinsnxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinttxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinttxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atintuxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atintuxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinxbxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinxbxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atinxsxx.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atinxsxx.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\ativmc20.cod" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\ativmc20.cod" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atmepvc.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atmepvc.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atmlane.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atmlane.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atmuni.sys" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atmuni.sys" is compressed (flags = 1) Read File: File "e:\WINDOWS\system32\drivers\atv01nt5.dll" is compressed (flags = 1) Read File: File "E:\WINDOWS\system32\drivers\atv01nt5.dll" is compressed (flags = 1) Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6A7C6A7C Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 63 Numsec = 78140097 Partition file system is NTFS Partition is bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 40020664320 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-78145360-78165360)... Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffffff86f26ab8, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xffffffff86f3eb70, DeviceName: Unknown, DriverName: \Driver\PartMgr\ DevicePointer: 0xffffffff86f26ab8, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff86f68f18, DeviceName: \Device\00000069\, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff86f00d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-f\, DriverName: \Driver\atapi\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: 6D806D80 Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 63 Numsec = 156280257 Partition file system is NTFS Partition is not bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 80026361856 bytes Sector size: 512 bytes Done! Read File: File "e:\Documents and Settings\JB\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1) Read File: File "e:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1) Scan finished ======================================= Removal queue found; removal started Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\bootstrap_0_0_63_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_r.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\bootstrap_1_0_63_i.mbam... Removing e:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_r.mbam... Removal finished I'm going to use the thumb drive to boot, & send that log next