Jump to content

Webhp infection (2nd PC)


Magikvw

Recommended Posts

I know I already have a topic running for this but I have a second infected machine as well. So any help here is greatly appreciated.

Malwarbytes and Endpoint seemed to find part of it (or possibly a different "bug") - but webhp still shows in the URL when using Google and redirects search results. I am experiencing no other symptoms at this time.

Thank you!

Here are the DDS Logs:

DDS:

DDS (Ver_2012-11-07.01) - NTFS_AMD64

Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.7.2

Run by jlincoln at 11:48:15 on 2012-11-19

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.1384 [GMT -5:00]

.

AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe

C:\Windows\system32\atieclxx.exe

C:\Program Files\Common Files\SPBA\upeksvr.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe

C:\Windows\system32\IProsetMonitor.exe

C:\Windows\system32\Dwm.exe

C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe

C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe

C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe

C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Startel Administrative Controls\sac.exe

C:\Windows\splwow64.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.acculormemberservices.com/

mWinlogon: Userinit = userinit.exe,

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

mRun: [uSB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"

mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"

mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"

mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-System: PromptOnSecureDesktop = dword:0

mPolicies-System: DisableCAD = dword:1

IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

TCP: NameServer = 192.128.101.2 216.171.129.13

TCP: Interfaces\{EE03ECAE-1EE9-4EFD-923C-C85440EB6A15} : DHCPNameServer = 192.128.101.2 216.171.129.13

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

LSA: Authentication Packages = msv1_0 wvauth

x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe

x64-Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe

x64-Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe

x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"

x64-RunOnce: [DBRMTray] C:\Dell\DBRM\Reminder\TrayApp.exe

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll

x64-SSODL: WebCheck - <orphaned>

.

============= SERVICES / DRIVERS ===============

.

R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-9-19 19264]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-9-19 204288]

R2 EmbassyService;EmbassyService;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [2012-1-17 218504]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-9-19 13632]

R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-9-19 189608]

R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-7-5 375728]

R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2012-6-8 15928]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-9-24 72216]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-13 399432]

R2 Sentinel64;Sentinel64;C:\Windows\System32\drivers\sentinel64.sys [2012-9-25 145448]

R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2011-3-22 1831024]

R2 Wave Authentication Manager Service;Wave Authentication Manager Service;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2012-1-5 1679872]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-9-19 95248]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-9-24 138912]

R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-9-19 357184]

R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-9-19 789824]

R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;C:\Windows\System32\drivers\SNTUSB64.SYS [2011-5-27 63528]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-13 676936]

S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]

S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-26 1255736]

S3 WvPCR;WvPCR;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [2012-1-16 198144]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2012-11-13 19:19:46 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui

2012-11-13 19:19:45 9728 ----a-w- C:\Windows\System32\Wdfres.dll

2012-11-13 19:19:45 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys

2012-11-13 19:19:45 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys

2012-11-13 19:14:17 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys

2012-11-13 19:14:16 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys

2012-11-13 19:14:15 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll

2012-11-13 19:14:15 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll

2012-11-13 19:14:14 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll

2012-11-13 19:14:13 744448 ----a-w- C:\Windows\System32\WUDFx.dll

2012-11-13 19:14:13 229888 ----a-w- C:\Windows\System32\WUDFHost.exe

2012-11-13 16:35:22 -------- d-----w- C:\Users\jlincoln\AppData\Roaming\Malwarebytes

2012-11-13 16:34:33 -------- d-----w- C:\ProgramData\Malwarebytes

2012-11-13 16:34:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-11-07 14:11:33 -------- d--h--w- C:\ProgramData\Teorex

2012-11-07 14:10:31 -------- d-----w- C:\Program Files\FolderIco

2012-11-07 14:09:03 -------- d--h--w- C:\ProgramData\blekko toolbars

2012-11-05 20:20:50 -------- d-----w- C:\Users\jlincoln\AppData\Roaming\Avery

2012-11-05 20:19:30 -------- d-----w- C:\Program Files (x86)\Avery

2012-10-22 19:48:18 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll

2012-10-22 19:48:17 366592 ----a-w- C:\Windows\System32\qdvd.dll

.

==================== Find3M ====================

.

2012-11-06 14:05:08 88008 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll

2012-11-06 14:04:54 35240 ----a-w- C:\Windows\System32\LMIport.dll

2012-11-06 14:04:52 83880 ----a-w- C:\Windows\System32\LMIinit.dll

2012-10-18 18:25:58 3149824 ----a-w- C:\Windows\System32\win32k.sys

2012-10-10 15:39:37 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-10 15:39:36 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2012-10-10 15:39:36 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2012-10-10 13:02:25 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-10-10 13:02:25 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-10-09 18:17:13 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll

2012-10-09 18:17:13 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll

2012-10-09 17:40:31 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll

2012-10-09 17:40:31 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll

2012-10-08 11:31:03 2312704 ----a-w- C:\Windows\System32\jscript9.dll

2012-10-08 11:23:52 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-10-08 11:22:55 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-10-08 11:18:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-10-08 11:17:35 599040 ----a-w- C:\Windows\System32\vbscript.dll

2012-10-08 11:13:33 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-10-08 07:56:24 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-10-08 07:48:03 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-10-08 07:47:44 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-10-08 07:44:05 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-10-08 07:43:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2012-10-08 07:40:56 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-10-03 17:56:54 1914248 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2012-10-03 17:44:21 70656 ----a-w- C:\Windows\System32\nlaapi.dll

2012-10-03 17:44:21 303104 ----a-w- C:\Windows\System32\nlasvc.dll

2012-10-03 17:44:17 246272 ----a-w- C:\Windows\System32\netcorehc.dll

2012-10-03 17:44:17 18944 ----a-w- C:\Windows\System32\netevent.dll

2012-10-03 17:44:16 216576 ----a-w- C:\Windows\System32\ncsi.dll

2012-10-03 17:42:16 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll

2012-10-03 16:42:24 18944 ----a-w- C:\Windows\SysWow64\netevent.dll

2012-10-03 16:42:24 175104 ----a-w- C:\Windows\SysWow64\netcorehc.dll

2012-10-03 16:42:23 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll

2012-10-03 16:07:26 45568 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys

2012-10-02 16:19:43 233120 ----a-w- C:\Windows\System32\drivers\wpshelper.sys

2012-09-29 01:42:04 2177704 ----a-w- C:\Windows\System32\coin92.dll

2012-09-25 22:47:43 78336 ----a-w- C:\Windows\SysWow64\synceng.dll

2012-09-25 22:46:17 95744 ----a-w- C:\Windows\System32\synceng.dll

2012-09-24 20:47:10 172592 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS

2012-09-19 09:03:59 81408 ----a-w- C:\Windows\System32\imagehlp.dll

2012-09-19 08:43:16 91648 ----a-w- C:\Windows\System32\SetIEInstalledDate.exe

2012-09-19 07:40:12 0 ----a-w- C:\Windows\ativpsrm.bin

2012-09-19 07:25:53 81904 ----a-w- C:\Windows\System32\pbadrvdll.dll

2012-09-19 07:25:53 80368 ----a-w- C:\Windows\SysWow64\pbadrvdll.dll

2012-09-19 07:25:53 32240 ----a-w- C:\Windows\System32\drivers\PBADRV.SYS

2012-09-19 07:25:53 239104 ----a-w- C:\Windows\System32\bioapi_mds300.dll

2012-09-19 07:25:53 155136 ----a-w- C:\Windows\System32\bioapi100.dll

2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll

2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2012-08-31 18:19:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys

2012-08-30 18:03:45 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll

2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll

2012-08-22 18:12:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys

2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys

2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

2012-08-21 21:01:00 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe

.

============= FINISH: 11:51:12.79 ===============

Attach

Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition

Upek Touchchip Fingerprint Reader

Wave Crypto Runtime 2.0.7.0 x86

Wave Infrastructure Installer

Wave Support Software Installer

Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6)

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

.

==== Event Viewer Messages From Past Week ========

.

11/16/2012 7:10:00 AM, Error: NetBT [4321] - The name "PCC :1d" could not be registered on the interface with IP address 192.128.101.126. The computer with the IP address 192.128.101.113 did not allow the name to be claimed by this computer.

11/15/2012 5:13:07 PM, Error: Service Control Manager [7001] - The MBAMService service depends on the MBAMProtector service which failed to start because of the following error: The system cannot find the file specified.

11/15/2012 5:12:40 PM, Error: Service Control Manager [7001] - The NTRU TSS v1.2.1.37 TCS service depends on the TPM Base Services service which failed to start because of the following error: The operation completed successfully.

11/15/2012 5:12:08 PM, Error: Service Control Manager [7000] - The MBAMProtector service failed to start due to the following error: The system cannot find the file specified.

11/15/2012 5:08:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TdmService with arguments "" in order to run the server: {2F723A84-FD6F-4C32-9477-391FA6EA0BB6}

11/15/2012 5:08:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}

11/15/2012 5:08:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}

11/15/2012 5:06:24 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

11/15/2012 4:38:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

11/15/2012 4:38:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

11/15/2012 4:38:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

11/15/2012 4:38:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

11/15/2012 4:35:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache eeCtrl spldr SRTSP SRTSPX vpcvmm Wanarpv6

11/12/2012 12:27:10 PM, Error: Microsoft-Windows-GroupPolicy [1129] - The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.

11/12/2012 12:27:05 PM, Error: Microsoft-Windows-GroupPolicy [1055] - The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

11/12/2012 12:27:03 PM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain PCC due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.

.

==== End Of File ===========================

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the contents of C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

Link to post
Share on other sites

OK -

MBAM Log is below - Combodix and DDS to follow:

Malwarebytes Anti-Malware (Trial) 1.65.1.1000

www.malwarebytes.org

Database version: v2012.11.19.08

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

jlincoln :: OPSMGR [administrator]

Protection: Disabled

11/19/2012 1:56:24 PM

mbam-log-2012-11-19 (13-56-24).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 246409

Time elapsed: 1 minute(s), 57 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Link to post
Share on other sites

I am sorry this is taking so long - I cannot figure out how to disable the active scanning for my Endpoint software. It is server controlled so I cannot run it off at the client side.

I do have the admin user and password and have been looking in the Server control but I cannot sifugre out how to disable it. Combofix saus it needs to be disabled before continuing

Link to post
Share on other sites

OK - here is the Combo fix log and a new DDS log. I could not disable the Endpoint active protection and I had already started the Combo fix process - Combofix ended up running with the active Endpoint still running - I hope that's not a problem.

ComboFix

ComboFix 12-11-19.02 - jlincoln 11/19/2012 17:02:59.1.4 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.6304 [GMT -5:00]

Running from: c:\users\jlincoln\Desktop\ComboFix.exe

AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}

SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\DDa03of0DXejIW

.

.

((((((((((((((((((((((((( Files Created from 2012-10-20 to 2012-11-20 )))))))))))))))))))))))))))))))

.

.

2012-11-19 22:35 . 2012-11-19 22:35 -------- d-----w- c:\users\Jeff Lincoln\AppData\Local\temp

2012-11-19 22:35 . 2012-11-19 22:35 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-11-19 22:35 . 2012-11-19 22:35 -------- d-----w- c:\users\administrator\AppData\Local\temp

2012-11-13 19:19 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui

2012-11-13 19:19 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2012-11-13 19:19 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2012-11-13 19:19 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll

2012-11-13 19:14 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys

2012-11-13 19:14 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys

2012-11-13 19:14 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll

2012-11-13 19:14 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll

2012-11-13 19:14 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll

2012-11-13 19:14 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe

2012-11-13 19:14 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll

2012-11-13 16:35 . 2012-11-13 16:35 -------- d-----w- c:\users\jlincoln\AppData\Roaming\Malwarebytes

2012-11-13 16:34 . 2012-11-13 16:34 -------- d-----w- c:\programdata\Malwarebytes

2012-11-13 16:34 . 2012-11-13 17:54 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-11-07 14:11 . 2012-11-07 14:11 -------- d--h--w- c:\programdata\Teorex

2012-11-07 14:10 . 2012-11-13 17:45 -------- d-----w- c:\program files\FolderIco

2012-11-07 14:09 . 2012-11-07 21:01 -------- d--h--w- c:\programdata\blekko toolbars

2012-11-05 20:20 . 2012-11-05 20:20 -------- d-----w- c:\users\jlincoln\AppData\Roaming\Avery

2012-11-05 20:19 . 2012-11-13 17:31 -------- d-----w- c:\program files (x86)\Avery

2012-10-22 19:48 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

2012-10-22 19:48 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-11-13 19:14 . 2012-09-24 23:27 66395536 ----a-w- c:\windows\system32\MRT.exe

2012-11-06 14:05 . 2012-09-24 22:16 88008 ----a-w- c:\windows\system32\LMIRfsClientNP.dll

2012-11-06 14:04 . 2012-09-24 22:16 35240 ----a-w- c:\windows\system32\LMIport.dll

2012-11-06 14:04 . 2012-09-24 22:16 83880 ----a-w- c:\windows\system32\LMIinit.dll

2012-10-10 15:39 . 2012-10-10 15:39 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-10 15:39 . 2012-10-10 15:40 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll

2012-10-10 15:39 . 2012-10-10 15:40 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll

2012-10-10 13:02 . 2012-09-19 07:13 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-10-10 13:02 . 2012-09-19 07:13 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-10-02 16:19 . 2012-09-24 20:48 233120 ----a-w- c:\windows\system32\drivers\wpshelper.sys

2012-09-29 01:42 . 2012-09-29 01:42 2177704 ----a-w- c:\windows\system32\coin92.dll

2012-09-24 20:47 . 2012-09-24 20:47 172592 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS

2012-09-24 20:40 . 2010-06-24 16:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2012-09-19 09:04 . 2012-09-19 09:04 360832 ----a-w- c:\windows\system32\drivers\vpcvmm.sys

2012-09-19 09:04 . 2012-09-19 09:04 936448 ----a-w- c:\windows\system32\vmsal.exe

2012-09-19 09:04 . 2012-09-19 09:04 793600 ----a-w- c:\windows\SysWow64\vmsal.exe

2012-09-19 09:04 . 2012-09-19 09:04 59392 ----a-w- c:\windows\system32\drivers\vpcnfltr.sys

2012-09-19 09:04 . 2012-09-19 09:04 562176 ----a-w- c:\windows\system32\VMCPropertyHandler.dll

2012-09-19 09:04 . 2012-09-19 09:04 4514816 ----a-w- c:\windows\system32\vpc.exe

2012-09-19 09:04 . 2012-09-19 09:04 2264064 ----a-w- c:\windows\system32\VPCWizard.exe

2012-09-19 09:04 . 2012-09-19 09:04 1369600 ----a-w- c:\windows\system32\VPCSettings.exe

2012-09-19 09:04 . 2012-09-19 09:04 1210368 ----a-w- c:\windows\system32\VMWindow.exe

2012-09-19 09:04 . 2012-09-19 09:04 95232 ----a-w- c:\windows\system32\drivers\vpcusb.sys

2012-09-19 09:04 . 2012-09-19 09:04 194944 ----a-w- c:\windows\system32\drivers\vpchbus.sys

2012-09-19 09:04 . 2012-09-19 09:04 15872 ----a-w- c:\windows\system32\vpchbuspipe.dll

2012-09-19 09:04 . 2012-09-19 09:04 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe

2012-09-19 09:04 . 2012-09-19 09:04 778752 ----a-w- c:\windows\system32\mssvp.dll

2012-09-19 09:04 . 2012-09-19 09:04 75264 ----a-w- c:\windows\system32\msscntrs.dll

2012-09-19 09:04 . 2012-09-19 09:04 666624 ----a-w- c:\windows\SysWow64\mssvp.dll

2012-09-19 09:04 . 2012-09-19 09:04 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll

2012-09-19 09:04 . 2012-09-19 09:04 591872 ----a-w- c:\windows\system32\SearchIndexer.exe

2012-09-19 09:04 . 2012-09-19 09:04 491520 ----a-w- c:\windows\system32\mssph.dll

2012-09-19 09:04 . 2012-09-19 09:04 427520 ----a-w- c:\windows\SysWow64\SearchIndexer.exe

2012-09-19 09:04 . 2012-09-19 09:04 337408 ----a-w- c:\windows\SysWow64\mssph.dll

2012-09-19 09:04 . 2012-09-19 09:04 31232 ----a-w- c:\windows\SysWow64\prevhost.exe

2012-09-19 09:04 . 2012-09-19 09:04 31232 ----a-w- c:\windows\system32\prevhost.exe

2012-09-19 09:04 . 2012-09-19 09:04 288256 ----a-w- c:\windows\system32\mssphtb.dll

2012-09-19 09:04 . 2012-09-19 09:04 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe

2012-09-19 09:04 . 2012-09-19 09:04 2315776 ----a-w- c:\windows\system32\tquery.dll

2012-09-19 09:04 . 2012-09-19 09:04 2223616 ----a-w- c:\windows\system32\mssrch.dll

2012-09-19 09:04 . 2012-09-19 09:04 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll

2012-09-19 09:04 . 2012-09-19 09:04 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe

2012-09-19 09:04 . 2012-09-19 09:04 1549312 ----a-w- c:\windows\SysWow64\tquery.dll

2012-09-19 09:04 . 2012-09-19 09:04 1401344 ----a-w- c:\windows\SysWow64\mssrch.dll

2012-09-19 09:04 . 2012-09-19 09:04 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe

2012-09-19 09:04 . 2012-09-19 09:04 976896 ----a-w- c:\windows\system32\inetcomm.dll

2012-09-19 09:04 . 2012-09-19 09:04 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys

2012-09-19 09:04 . 2012-09-19 09:04 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll

2012-09-19 09:04 . 2012-09-19 09:04 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll

2012-09-19 09:04 . 2012-09-19 09:04 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll

2012-09-19 09:04 . 2012-09-19 09:04 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys

2012-09-19 09:04 . 2012-09-19 09:04 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax

2012-09-19 09:04 . 2012-09-19 09:04 613888 ----a-w- c:\windows\system32\psisdecd.dll

2012-09-19 09:04 . 2012-09-19 09:04 498688 ----a-w- c:\windows\system32\drivers\afd.sys

2012-09-19 09:04 . 2012-09-19 09:04 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll

2012-09-19 09:04 . 2012-09-19 09:04 1395712 ----a-w- c:\windows\system32\mfc42.dll

2012-09-19 09:04 . 2012-09-19 09:04 1359872 ----a-w- c:\windows\system32\mfc42u.dll

2012-09-19 09:04 . 2012-09-19 09:04 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll

2012-09-19 09:04 . 2012-09-19 09:04 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll

2012-09-19 09:04 . 2012-09-19 09:04 108032 ----a-w- c:\windows\system32\psisrndr.ax

2012-09-19 09:04 . 2012-09-19 09:04 96768 ----a-w- c:\windows\SysWow64\sspicli.dll

2012-09-19 09:04 . 2012-09-19 09:04 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2012-09-19 09:04 . 2012-09-19 09:04 70656 ----a-w- c:\windows\SysWow64\fontsub.dll

2012-09-19 09:04 . 2012-09-19 09:04 64512 ----a-w- c:\windows\SysWow64\devobj.dll

2012-09-19 09:04 . 2012-09-19 09:04 509952 ----a-w- c:\windows\system32\ntshrui.dll

2012-09-19 09:04 . 2012-09-19 09:04 46080 ----a-w- c:\windows\system32\atmlib.dll

2012-09-19 09:04 . 2012-09-19 09:04 458704 ----a-w- c:\windows\system32\drivers\cng.sys

2012-09-19 09:04 . 2012-09-19 09:04 44544 ----a-w- c:\windows\SysWow64\devrtl.dll

2012-09-19 09:04 . 2012-09-19 09:04 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll

2012-09-19 09:04 . 2012-09-19 09:04 404480 ----a-w- c:\windows\system32\umpnpmgr.dll

2012-09-19 09:04 . 2012-09-19 09:04 367616 ----a-w- c:\windows\system32\atmfd.dll

2012-09-19 09:04 . 2012-09-19 09:04 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2012-09-19 09:04 . 2012-09-19 09:04 340992 ----a-w- c:\windows\system32\schannel.dll

2012-09-19 09:04 . 2012-09-19 09:04 31232 ----a-w- c:\windows\system32\lsass.exe

2012-09-19 09:04 . 2012-09-19 09:04 307200 ----a-w- c:\windows\system32\ncrypt.dll

2012-09-19 09:04 . 2012-09-19 09:04 294912 ----a-w- c:\windows\SysWow64\atmfd.dll

2012-09-19 09:04 . 2012-09-19 09:04 29184 ----a-w- c:\windows\system32\sspisrv.dll

2012-09-19 09:04 . 2012-09-19 09:04 2871808 ----a-w- c:\windows\explorer.exe

2012-09-19 09:04 . 2012-09-19 09:04 28160 ----a-w- c:\windows\system32\secur32.dll

2012-09-19 09:04 . 2012-09-19 09:04 2616320 ----a-w- c:\windows\SysWow64\explorer.exe

2012-09-19 09:04 . 2012-09-19 09:04 252928 ----a-w- c:\windows\SysWow64\drvinst.exe

2012-09-19 09:04 . 2012-09-19 09:04 225280 ----a-w- c:\windows\SysWow64\schannel.dll

2012-09-19 09:04 . 2012-09-19 09:04 22016 ----a-w- c:\windows\SysWow64\secur32.dll

2012-09-19 09:04 . 2012-09-19 09:04 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll

2012-09-19 09:04 . 2012-09-19 09:04 197120 ----a-w- c:\windows\system32\d3d10_1.dll

2012-09-19 09:04 . 2012-09-19 09:04 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll

2012-09-19 09:04 . 2012-09-19 09:04 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys

2012-09-19 09:04 . 2012-09-19 09:04 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll

2012-09-19 09:04 . 2012-09-19 09:04 1447936 ----a-w- c:\windows\system32\lsasrv.dll

2012-09-19 09:04 . 2012-09-19 09:04 136192 ----a-w- c:\windows\system32\sspicli.dll

2012-09-19 09:04 . 2012-09-19 09:04 100864 ----a-w- c:\windows\system32\fontsub.dll

2012-09-19 09:04 . 2012-09-19 09:04 902656 ----a-w- c:\windows\system32\d2d1.dll

2012-09-19 09:04 . 2012-09-19 09:04 77312 ----a-w- c:\windows\system32\packager.dll

2012-09-19 09:04 . 2012-09-19 09:04 739840 ----a-w- c:\windows\SysWow64\d2d1.dll

2012-09-19 09:04 . 2012-09-19 09:04 723456 ----a-w- c:\windows\system32\EncDec.dll

2012-09-19 09:04 . 2012-09-19 09:04 67072 ----a-w- c:\windows\SysWow64\packager.dll

2012-09-19 09:04 . 2012-09-19 09:04 534528 ----a-w- c:\windows\SysWow64\EncDec.dll

2012-09-19 09:04 . 2012-09-19 09:04 3216384 ----a-w- c:\windows\system32\msi.dll

2012-09-19 09:04 . 2012-09-19 09:04 2342400 ----a-w- c:\windows\SysWow64\msi.dll

2012-09-19 09:04 . 2012-09-19 09:04 1139200 ----a-w- c:\windows\system32\FntCache.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-09-25 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-21 291648]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-07 343168]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" [2012-06-07 56128]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-07-27 36800]

"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-07-27 823224]

"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2011-03-22 115560]

"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files (x86)\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"DisableCAD"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux1"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys [2010-11-21 168448]

R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys [2010-11-21 22528]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-26 1255736]

R3 WvPCR;WvPCR;c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [2012-01-16 198144]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-05-21 19264]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-07 204288]

S2 EmbassyService;EmbassyService;c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [2012-01-17 218504]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-05-30 13632]

S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe [2011-11-09 189608]

S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-06 375728]

S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-06-08 15928]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-30 399432]

S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [2009-09-17 145448]

S2 Wave Authentication Manager Service;Wave Authentication Manager Service;c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2012-01-05 1679872]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-12-06 95248]

S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 47616]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-09-24 138912]

S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-05-21 357184]

S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-05-21 789824]

S3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;c:\windows\system32\DRIVERS\SNTUSB64.SYS [2011-05-27 63528]

.

.

Contents of the 'Scheduled Tasks' folder

.

2012-11-20 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-19 13:02]

.

2012-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-25 17:08]

.

2012-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-25 17:08]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]

@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"

[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]

2011-12-08 15:45 139128 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]

@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"

[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]

2011-12-08 15:45 139128 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtDCpl64.exe" [2011-07-21 2907240]

"TdmNotify"="c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe" [2011-12-08 381296]

"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2011-03-08 227328]

"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2012-06-08 57928]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.acculormemberservices.com/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

TCP: DhcpNameServer = 192.128.101.2 216.171.129.13

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

SafeBoot-Symantec Antvirus

Toolbar-Locked - (no file)

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe

c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe

c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe

.

**************************************************************************

.

Completion time: 2012-11-20 09:17:01 - machine was rebooted

ComboFix-quarantined-files.txt 2012-11-20 14:16

.

Pre-Run: 415,330,324,480 bytes free

Post-Run: 414,376,665,088 bytes free

.

- - End Of File - - FBEEDB4FAF4B3EC93A19FC3889D8DC01

DDS

DDS (Ver_2012-11-07.01) - NTFS_AMD64

Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.7.2

Run by jlincoln at 9:22:28 on 2012-11-20

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8175.5737 [GMT -5:00]

.

AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe

C:\Windows\system32\atieclxx.exe

C:\Program Files\Common Files\SPBA\upeksvr.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe

C:\Windows\system32\IProsetMonitor.exe

C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe

C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe

C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe

C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.acculormemberservices.com/

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

mRun: [uSB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"

mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"

mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"

mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-System: PromptOnSecureDesktop = dword:0

mPolicies-System: DisableCAD = dword:1

IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

TCP: NameServer = 192.128.101.2 216.171.129.13

TCP: Interfaces\{EE03ECAE-1EE9-4EFD-923C-C85440EB6A15} : DHCPNameServer = 192.128.101.2 216.171.129.13

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll

x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtDCpl64.exe

x64-Run: [TdmNotify] C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe

x64-Run: [DBRMTray] C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe

x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll

x64-SSODL: WebCheck - <orphaned>

.

============= SERVICES / DRIVERS ===============

.

R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-9-19 19264]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-9-19 204288]

R2 EmbassyService;EmbassyService;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [2012-1-17 218504]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-9-19 13632]

R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-9-19 189608]

R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-7-5 375728]

R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2012-6-8 15928]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-9-24 72216]

R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-13 399432]

R2 Sentinel64;Sentinel64;C:\Windows\System32\drivers\sentinel64.sys [2012-9-25 145448]

R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2011-3-22 1831024]

R2 Wave Authentication Manager Service;Wave Authentication Manager Service;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [2012-1-5 1679872]

R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-9-19 95248]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-9-24 138912]

R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-9-19 357184]

R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-9-19 789824]

R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;C:\Windows\System32\drivers\SNTUSB64.SYS [2011-5-27 63528]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-13 676936]

S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]

S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-21 168448]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-21 22528]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-26 1255736]

S3 WvPCR;WvPCR;C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [2012-1-16 198144]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2012-11-19 21:51:05 98816 ----a-w- C:\Windows\sed.exe

2012-11-19 21:51:05 256000 ----a-w- C:\Windows\PEV.exe

2012-11-19 21:51:05 208896 ----a-w- C:\Windows\MBR.exe

2012-11-19 21:45:38 -------- d-----w- C:\ComboFix

2012-11-13 19:19:46 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui

2012-11-13 19:19:45 9728 ----a-w- C:\Windows\System32\Wdfres.dll

2012-11-13 19:19:45 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys

2012-11-13 19:19:45 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys

2012-11-13 19:14:17 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys

2012-11-13 19:14:16 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys

2012-11-13 19:14:15 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll

2012-11-13 19:14:15 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll

2012-11-13 19:14:14 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll

2012-11-13 19:14:13 744448 ----a-w- C:\Windows\System32\WUDFx.dll

2012-11-13 19:14:13 229888 ----a-w- C:\Windows\System32\WUDFHost.exe

2012-11-13 16:35:22 -------- d-----w- C:\Users\jlincoln\AppData\Roaming\Malwarebytes

2012-11-13 16:34:33 -------- d-----w- C:\ProgramData\Malwarebytes

2012-11-13 16:34:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-11-07 14:11:33 -------- d--h--w- C:\ProgramData\Teorex

2012-11-07 14:10:31 -------- d-----w- C:\Program Files\FolderIco

2012-11-07 14:09:03 -------- d--h--w- C:\ProgramData\blekko toolbars

2012-11-05 20:20:50 -------- d-----w- C:\Users\jlincoln\AppData\Roaming\Avery

2012-11-05 20:19:30 -------- d-----w- C:\Program Files (x86)\Avery

2012-10-22 19:48:18 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll

2012-10-22 19:48:17 366592 ----a-w- C:\Windows\System32\qdvd.dll

.

==================== Find3M ====================

.

2012-11-06 14:05:08 88008 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll

2012-11-06 14:04:54 35240 ----a-w- C:\Windows\System32\LMIport.dll

2012-11-06 14:04:52 83880 ----a-w- C:\Windows\System32\LMIinit.dll

2012-10-18 18:25:58 3149824 ----a-w- C:\Windows\System32\win32k.sys

2012-10-10 15:39:37 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2012-10-10 15:39:36 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2012-10-10 15:39:36 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2012-10-10 13:02:25 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-10-10 13:02:25 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-10-09 18:17:13 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll

2012-10-09 18:17:13 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll

2012-10-09 17:40:31 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll

2012-10-09 17:40:31 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll

2012-10-08 11:31:03 2312704 ----a-w- C:\Windows\System32\jscript9.dll

2012-10-08 11:23:52 1392128 ----a-w- C:\Windows\System32\wininet.dll

2012-10-08 11:22:55 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl

2012-10-08 11:18:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe

2012-10-08 11:17:35 599040 ----a-w- C:\Windows\System32\vbscript.dll

2012-10-08 11:13:33 2382848 ----a-w- C:\Windows\System32\mshtml.tlb

2012-10-08 07:56:24 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll

2012-10-08 07:48:03 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll

2012-10-08 07:47:44 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl

2012-10-08 07:44:05 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe

2012-10-08 07:43:21 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll

2012-10-08 07:40:56 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2012-10-03 17:56:54 1914248 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2012-10-03 17:44:21 70656 ----a-w- C:\Windows\System32\nlaapi.dll

2012-10-03 17:44:21 303104 ----a-w- C:\Windows\System32\nlasvc.dll

2012-10-03 17:44:17 246272 ----a-w- C:\Windows\System32\netcorehc.dll

2012-10-03 17:44:17 18944 ----a-w- C:\Windows\System32\netevent.dll

2012-10-03 17:44:16 216576 ----a-w- C:\Windows\System32\ncsi.dll

2012-10-03 17:42:16 569344 ----a-w- C:\Windows\System32\iphlpsvc.dll

2012-10-03 16:42:24 18944 ----a-w- C:\Windows\SysWow64\netevent.dll

2012-10-03 16:42:24 175104 ----a-w- C:\Windows\SysWow64\netcorehc.dll

2012-10-03 16:42:23 156672 ----a-w- C:\Windows\SysWow64\ncsi.dll

2012-10-03 16:07:26 45568 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys

2012-10-02 16:19:43 233120 ----a-w- C:\Windows\System32\drivers\wpshelper.sys

2012-09-29 01:42:04 2177704 ----a-w- C:\Windows\System32\coin92.dll

2012-09-25 22:47:43 78336 ----a-w- C:\Windows\SysWow64\synceng.dll

2012-09-25 22:46:17 95744 ----a-w- C:\Windows\System32\synceng.dll

2012-09-24 20:47:10 172592 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS

2012-09-19 09:03:59 81408 ----a-w- C:\Windows\System32\imagehlp.dll

2012-09-19 08:43:16 91648 ----a-w- C:\Windows\System32\SetIEInstalledDate.exe

2012-09-19 07:40:12 0 ----a-w- C:\Windows\ativpsrm.bin

2012-09-19 07:25:53 81904 ----a-w- C:\Windows\System32\pbadrvdll.dll

2012-09-19 07:25:53 80368 ----a-w- C:\Windows\SysWow64\pbadrvdll.dll

2012-09-19 07:25:53 32240 ----a-w- C:\Windows\System32\drivers\PBADRV.SYS

2012-09-19 07:25:53 239104 ----a-w- C:\Windows\System32\bioapi_mds300.dll

2012-09-19 07:25:53 155136 ----a-w- C:\Windows\System32\bioapi100.dll

2012-09-14 19:19:29 2048 ----a-w- C:\Windows\System32\tzres.dll

2012-09-14 18:28:53 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2012-08-31 18:19:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys

2012-08-30 18:03:45 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe

2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll

2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll

2012-08-22 18:12:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys

2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys

2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

.

============= FINISH: 9:25:14.52 ===============

Attach

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-07.01)

.

Microsoft Windows 7 Professional

Boot Device: \Device\HarddiskVolume2

Install Date: 9/24/2012 3:22:37 PM

System Uptime: 11/19/2012 5:37:47 PM (16 hours ago)

.

Motherboard: Dell Inc. | | 0KRC95

Processor: Intel® Core i5-3470 CPU @ 3.20GHz | CPU 1 | 3201/100mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 450 GiB total, 386.004 GiB free.

D: is CDROM ()

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP30: 11/13/2012 2:13:11 PM - Windows Update

.

==== Installed Programs ======================

.

TASbiller

Adobe Acrobat X Standard - English, Français, Deutsch

Adobe Flash Player 11 ActiveX

AMD APP SDK Runtime

AMD Catalyst Install Manager

Avery Wizard 4.0

BioAPI Framework

Catalyst Control Center

Catalyst Control Center - Branding

Catalyst Control Center Graphics Previews Common

Catalyst Control Center InstallProxy

Catalyst Control Center Localization All

Catalyst Control Center Profiles Desktop

ccc-utility64

CCC Help Chinese Standard

CCC Help Chinese Traditional

CCC Help Czech

CCC Help Danish

CCC Help Dutch

CCC Help English

CCC Help Finnish

CCC Help French

CCC Help German

CCC Help Greek

CCC Help Hungarian

CCC Help Italian

CCC Help Japanese

CCC Help Korean

CCC Help Norwegian

CCC Help Polish

CCC Help Portuguese

CCC Help Russian

CCC Help Spanish

CCC Help Swedish

CCC Help Thai

CCC Help Turkish

Custom

D3DX10

Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

Dell Backup and Recovery Manager

Dell Client System Update

Dell Data Protection | Access

Dell Edoc Viewer

DellAccess

EMBASSY Client Core

FolderIco 1.0

Gemalto

Google Gmail Notifier

Google Toolbar for Internet Explorer

Google Update Helper

Intel® Control Center

Intel® Network Connections 16.8.45.00

Intel® Rapid Storage Technology

Intel® USB 3.0 eXtensible Host Controller Driver

Java 7 Update 7

Java Auto Updater

Junk Mail filter update

LiveUpdate 3.3 (Symantec Corporation)

LogMeIn

Malwarebytes Anti-Malware version 1.65.1.1000

Mesh Runtime

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Application Error Reporting

Microsoft Office 2010 Service Pack 1 (SP1)

Microsoft Office Access MUI (English) 2010

Microsoft Office Access Setup Metadata MUI (English) 2010

Microsoft Office Excel MUI (English) 2010

Microsoft Office Home and Business 2010

Microsoft Office Office 64-bit Components 2010

Microsoft Office OneNote MUI (English) 2010

Microsoft Office Outlook MUI (English) 2010

Microsoft Office PowerPoint MUI (English) 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Publisher MUI (English) 2010

Microsoft Office Shared 64-bit MUI (English) 2010

Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Single Image 2010

Microsoft Office Word MUI (English) 2010

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

MSVCRT

MSVCRT_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP2 Parser and SDK

NTRU TCG Software Stack

PC-CCID

Preboot Manager

Private Information Manager

Realtek High Definition Audio Driver

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition

Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553091)

Security Update for Microsoft Office 2010 (KB2553096)

Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition

Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition

Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition

Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition

Security Update for Microsoft Word 2010 (KB2553488) 32-Bit Edition

Sentinel System Driver Installer 7.5.7

SPBA 5.9

Symantec Endpoint Protection

toolkit32for64bit

Trusted Drive Manager

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Update for Microsoft Office 2010 (KB2553065)

Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition

Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

Update for Microsoft Office 2010 (KB2566458)

Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition

Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition

Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition

Upek Touchchip Fingerprint Reader

Wave Crypto Runtime 2.0.7.0 x86

Wave Infrastructure Installer

Wave Support Software Installer

Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6)

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Language Selector

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live MIME IFilter

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live Remote Client

Windows Live Remote Client Resources

Windows Live Remote Service

Windows Live Remote Service Resources

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

.

==== Event Viewer Messages From Past Week ========

.

11/19/2012 5:38:07 PM, Error: Service Control Manager [7001] - The MBAMService service depends on the MBAMProtector service which failed to start because of the following error: The system cannot find the file specified.

11/19/2012 5:38:04 PM, Error: Service Control Manager [7001] - The NTRU TSS v1.2.1.37 TCS service depends on the TPM Base Services service which failed to start because of the following error: The operation completed successfully.

11/19/2012 5:37:59 PM, Error: Service Control Manager [7000] - The MBAMProtector service failed to start due to the following error: The system cannot find the file specified.

11/19/2012 5:36:56 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

11/19/2012 5:33:43 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

11/16/2012 7:10:00 AM, Error: NetBT [4321] - The name "PCC :1d" could not be registered on the interface with IP address 192.128.101.126. The computer with the IP address 192.128.101.113 did not allow the name to be claimed by this computer.

11/15/2012 5:08:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TdmService with arguments "" in order to run the server: {2F723A84-FD6F-4C32-9477-391FA6EA0BB6}

11/15/2012 5:08:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}

11/15/2012 5:08:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}

11/15/2012 5:06:24 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

11/15/2012 4:38:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

11/15/2012 4:38:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

11/15/2012 4:38:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

11/15/2012 4:38:02 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

11/15/2012 4:35:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache eeCtrl spldr SRTSP SRTSPX vpcvmm Wanarpv6

.

==== End Of File ===========================

Link to post
Share on other sites

  • Staff

Hi,

Run TFC by OldTimer to clear temporary files:

  • Please download TFC from here and save it to your desktop.
  • Close any open programs and Internet browsers.
  • Double click TFC.exe to run it and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.
  • Please be patient as clearing out temp files may take a while.
  • Once it completes you may be prompted to restart your computer, please do so.
  • Once it's finished you may delete TFC.exe from your Desktop or save it for later use for the cleaning of temporary files.

  • Download the file TDSSKiller.zip and extract it into a folder on the infected PC.
  • Execute the file TDSSKiller.exe by double-clicking on it.
  • Wait for the scan and disinfection process to be over.
  • When its work is over, the utility prompts for a reboot to complete the disinfection.

By default, the utility outputs runtime log into the system disk root directory (the disk where the operating system is installed, C:\ as a rule).

The log is like UtilityName.Version_Date_Time_log.txt.

for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt.

Please post that log here.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Export the threats found (if any), and post them here.

Next, please download AdwCleaner by Xplode onto your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

Next, download my Security Check from here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

-screen317

Link to post
Share on other sites

Ok here is what I have for you:

I ran TFC as instructed.

I Downloaded TDS killer but it wouldn't run when I clicked on it - I just got a very brief hour glass and then nothing. I waited a while and nothing happened. So I deleted TDS Killer and re-downloaded it. Same results. SO I have no log from that utility.

I ran ESET Scanner - no infections were found - no report given.

I downloaded and ran AdwCleaner - I have 2 logs listed below. The first is the log from after AdwCleaner finished scanning and the second is the log from AdwCLeaner after I instructed it to delete the files it found and it ran that process and rebooted.

ADWCleaner before reboot:

# AdwCleaner v2.009 - Logfile created 11/26/2012 at 11:59:14

# Updated 24/11/2012 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : jlincoln - OPSMGR

# Boot Mode : Normal

# Running from : C:\Users\jlincoln\Desktop\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

Folder Found : C:\ProgramData\blekko toolbars

***** [Registry] *****

Key Found : HKLM\Software\Description

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [605 octets] - [26/11/2012 11:59:14]

########## EOF - C:\AdwCleaner[R1].txt - [664 octets] ##########

ADWCleaner after Delete and Reboot:

# AdwCleaner v2.009 - Logfile created 11/26/2012 at 12:01:07

# Updated 24/11/2012 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : jlincoln - OPSMGR

# Boot Mode : Normal

# Running from : C:\Users\jlincoln\Desktop\adwcleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

Folder Deleted : C:\ProgramData\blekko toolbars

***** [Registry] *****

Key Deleted : HKLM\Software\Description

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [732 octets] - [26/11/2012 11:59:14]

AdwCleaner[s1].txt - [668 octets] - [26/11/2012 12:01:07]

########## EOF - C:\AdwCleaner[s1].txt - [727 octets] ##########

Downloaded and Ran Security Check

Security Check Log:

Results of screen317's Security Check version 0.99.56

Windows 7 Service Pack 1 x64 (UAC is disabled!)

Internet Explorer 9

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

Symantec Endpoint Protection

WMI entry may not exist for antivirus; attempting automatic update.

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.65.1.1000

Java 7 Update 7

Java version out of Date!

Google Chrome 22.0.1229.95

````````Process Check: objlist.exe by Laurent````````

Norton ccSvcHst.exe

Malwarebytes' Anti-Malware mbamscheduler.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C: 0%

````````````````````End of Log``````````````````````

Link to post
Share on other sites

  • Staff

Hi,

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck and TDSSKiller.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following program (if present):

Java 7 Update 7

Restart your computer.

Get the latest version of Java.

Click Start, type in Windows Update, and click on Windows Update when it appears. Install all available updates.

Let me know what issues remain.

Link to post
Share on other sites

OK - I did all of that. THe first time I tried to Install Java I received the following:

Downloaded FIle

c:\Users\jtlincoln\AppData\LocalLow\Sun\Java\jre1.7.0_09\java_sp.dll is corrupt

Then I save the install fiel to the Desktop and ran it from there and it seemd to work fine.

Windows Update will not run properly - I get the following error:

An error occured while searching for updates on your computer

Error(s) Found:

Code 80070005 WIndows Update Encountered an Unknown Error

Webhp still in the Google URL. Search results are still slow to display but I am not seeing any redirects today (I did yesterday and the day before).

Link to post
Share on other sites

  • Staff

Hi,

We have an advanced product in development that is now in public Beta: Malwarebytes Anti-Rootkit. This tool has been designed to address the specific type of infection(s) identified on your system. At this stage Malwarebytes Anti-Rootkit has been heavily tested and we are confident in it's capabilities and stability. That being said, this is a Beta product and certain disclaimers need to be made. All Beta versions are not final products. Malwarebytes does not guarantee the absence of errors which might lead to interruption in normal computer operations or data loss. Precautions should be taken. The types of infections targeted by Malwarebytes Anti-Rootkit can be very difficult to remove. Please be sure you have any valued data backed up before proceeding, just as a precaution.

While we encourage and invite participation, Malwarebytes Anti-Rootkit Beta users run the tool at their own risk. Malwarebytes bears no responsibility for issues that may arise during use of this tool, however all reasonable efforts will be made by Malwarebytes to assist in recovery should the need arise.

If you agree to these terms, please let us know and we will provide a download link and instructions for you.

Link to post
Share on other sites

  • 2 weeks later...

OK - I installed and ran MBAR as you instructed. I ran it once and it found 4 infections - cleaned them - rebooted and then ran it again. The second time no infections were found. Redirects when using Google appear to be gone, it does however still say Webhp in the URL when I go to Google. My internet connection is fine - Windows FIrewall seems OK - I cannot get Windows Updates.

When I run Update is searches for updates and then give me the folloing error:

An error occured while checking for new updates on your computer.

Error found: 8007005

Here is Log that Mbar produced - I think this contains both scans:

Malwarebytes Anti-Rootkit BETA 1.01.0.1011

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED

CPU speed: 3.192000 GHz

Memory total: 8571793408, free: 6577319936

------------ Kernel report ------------

12/12/2012 10:53:06

------------ Loaded modules -----------

\SystemRoot\system32\ntoskrnl.exe

\SystemRoot\system32\hal.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\drivers\ACPI.sys

\SystemRoot\system32\drivers\WMILIB.SYS

\SystemRoot\system32\drivers\msisadrv.sys

\SystemRoot\system32\drivers\pci.sys

\SystemRoot\system32\drivers\vdrvroot.sys

\SystemRoot\system32\DRIVERS\iusb3hcs.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\drivers\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\drivers\iaStor.sys

\SystemRoot\system32\drivers\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\drivers\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\system32\DRIVERS\PBADRV.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\drivers\disk.sys

\SystemRoot\system32\drivers\CLASSPNP.SYS

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\SRTSP64.SYS

\??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS

\SystemRoot\System32\Drivers\SRTSPX64.SYS

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\??\C:\Windows\system32\drivers\wpsdrvnt.sys

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vpcnfltr.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\serial.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\SystemRoot\system32\drivers\vpcvmm.sys

\SystemRoot\system32\DRIVERS\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\DRIVERS\mssmbios.sys

\??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys

\??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\system32\drivers\csc.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\atikmpag.sys

\SystemRoot\system32\DRIVERS\atikmdag.sys

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\HDAudBus.sys

\SystemRoot\system32\DRIVERS\iusb3xhc.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\DRIVERS\e1c62x64.sys

\SystemRoot\system32\DRIVERS\usbehci.sys

\SystemRoot\system32\DRIVERS\USBPORT.SYS

\SystemRoot\system32\DRIVERS\serenum.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\CompositeBus.sys

\SystemRoot\system32\DRIVERS\lmimirr.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\rdpbus.sys

\SystemRoot\system32\DRIVERS\kbdclass.sys

\SystemRoot\system32\DRIVERS\mouclass.sys

\SystemRoot\system32\DRIVERS\teefer2.sys

\SystemRoot\system32\DRIVERS\swenum.sys

\SystemRoot\system32\DRIVERS\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\vpcusb.sys

\SystemRoot\system32\DRIVERS\usbrpm.sys

\SystemRoot\system32\DRIVERS\vpchbus.sys

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\drivers\AtihdW76.sys

\SystemRoot\system32\drivers\portcls.sys

\SystemRoot\system32\drivers\drmk.sys

\SystemRoot\system32\drivers\ksthunk.sys

\SystemRoot\system32\DRIVERS\iusb3hub.sys

\SystemRoot\system32\drivers\RTDVHD64.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\system32\DRIVERS\dc3d.sys

\SystemRoot\system32\DRIVERS\HIDPARSE.SYS

\SystemRoot\system32\DRIVERS\hidusb.sys

\SystemRoot\system32\DRIVERS\HIDCLASS.SYS

\SystemRoot\system32\DRIVERS\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\system32\DRIVERS\SNTUSB64.SYS

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\System32\cdd.dll

\SystemRoot\system32\drivers\luafv.sys

\SystemRoot\system32\drivers\WudfPf.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\System32\drivers\mpsdrv.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\SystemRoot\System32\Drivers\Sentinel64.sys

\??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys

\??\C:\Windows\system32\drivers\LMIRfsDriver.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\System32\drivers\tcpipreg.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\System32\Drivers\fastfat.SYS

\SystemRoot\system32\DRIVERS\asyncmac.sys

\SystemRoot\System32\ATMFD.DLL

\??\C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20121211.019\EX64.SYS

\??\C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20121211.019\ENG64.SYS

\SystemRoot\system32\DRIVERS\USBSTOR.SYS

\??\C:\Windows\system32\drivers\mbamchameleon.sys

\??\C:\Windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

\Windows\System32\autochk.exe

\Windows\System32\psapi.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xfffffa8009a07060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xfffffa8007185050

Lower Device Driver Name: \Driver\iaStor\

Driver name found: iaStor

DriverEntry returned 0x0

Function returned 0x0

Downloaded database version: v2012.12.12.08

Initializing...

Done!

<<<2>>>

Device number: 0, partition: 3

Physical Sector Size: 512

Drive: 0, DevicePointer: 0xfffffa8009a07060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa8009a07b90, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa8009a07060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa800714c690, DeviceName: Unknown, DriverName: \Driver\ACPI\

DevicePointer: 0xfffffa8007185050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\

------------ End ----------

Upper DeviceData: 0xfffff8a0017c5df0, 0xfffffa8009a07060, 0xfffffa800695e2e0

Lower DeviceData: 0xfffff8a01033d590, 0xfffffa8007185050, 0xfffffa800d6e9d00

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Scanning directory: C:\Windows\system32\drivers...

Done!

Drive 0

Scanning MBR on drive 0...

MBR buffers are not equal

MBR is forged! [4333f673a96dbe57f4d0023e55e5303d]

Inspecting partition table:

MBR Signature: 55AA

Disk Signature: 4A1E3F57

Partition information:

Partition 0 type is Other (0xde)

Partition is NOT ACTIVE.

Partition starts at LBA: 63 Numsec = 80262

Partition 1 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 81920 Numsec = 32800768

Partition 2 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 32882688 Numsec = 943859760

Partition 3 type is HIDDEN (0x17)

Partition is ACTIVE.

Partition starts at LBA: 976744448 Numsec = 20480

Partition is not bootable

Infected: VBR on Hidden active partition --> [Rootkit.Alureon.F.VBR]

Changing partition to empty and not active. New active partition is 1 on drive 0 ...

Partition 3 type is Empty (0x0)

Partition is NOT ACTIVE.

Partition starts at LBA: 0 Numsec = 0

MBR infection found on drive 0

Disk Size: 500107862016 bytes

Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)...

Sector 976753168 --> [Forged physical sector]

Sector 976753169 --> [Forged physical sector]

Sector 976753170 --> [Forged physical sector]

Sector 976753171 --> [Forged physical sector]

Sector 976753172 --> [Forged physical sector]

Sector 976753173 --> [Forged physical sector]

Sector 976753174 --> [Forged physical sector]

Sector 976753175 --> [Forged physical sector]

Sector 976753176 --> [Forged physical sector]

Sector 976753177 --> [Forged physical sector]

Sector 976753178 --> [Forged physical sector]

Sector 976753179 --> [Forged physical sector]

Sector 976753180 --> [Forged physical sector]

Sector 976753181 --> [Forged physical sector]

Sector 976753182 --> [Forged physical sector]

Sector 976753183 --> [Forged physical sector]

Sector 976753184 --> [Forged physical sector]

Sector 976753185 --> [Forged physical sector]

Sector 976753186 --> [Forged physical sector]

Sector 976753187 --> [Forged physical sector]

Sector 976753188 --> [Forged physical sector]

Sector 976753189 --> [Forged physical sector]

Sector 976753190 --> [Forged physical sector]

Sector 976753191 --> [Forged physical sector]

Sector 976753192 --> [Forged physical sector]

Sector 976753193 --> [Forged physical sector]

Sector 976753194 --> [Forged physical sector]

Sector 976753195 --> [Forged physical sector]

Sector 976753196 --> [Forged physical sector]

Sector 976753197 --> [Forged physical sector]

Sector 976753198 --> [Forged physical sector]

Sector 976753199 --> [Forged physical sector]

Sector 976753200 --> [Forged physical sector]

Sector 976753201 --> [Forged physical sector]

Sector 976753202 --> [Forged physical sector]

Sector 976753203 --> [Forged physical sector]

Sector 976753204 --> [Forged physical sector]

Sector 976753205 --> [Forged physical sector]

Sector 976753206 --> [Forged physical sector]

Sector 976753207 --> [Forged physical sector]

Sector 976753208 --> [Forged physical sector]

Sector 976753209 --> [Forged physical sector]

Sector 976753210 --> [Forged physical sector]

Sector 976753211 --> [Forged physical sector]

Sector 976753212 --> [Forged physical sector]

Sector 976753213 --> [Forged physical sector]

Sector 976753214 --> [Forged physical sector]

Sector 976753215 --> [Forged physical sector]

Sector 976753216 --> [Forged physical sector]

Sector 976753217 --> [Forged physical sector]

Sector 976753218 --> [Forged physical sector]

Sector 976753219 --> [Forged physical sector]

Sector 976753220 --> [Forged physical sector]

Sector 976753221 --> [Forged physical sector]

Sector 976753222 --> [Forged physical sector]

Sector 976753223 --> [Forged physical sector]

Sector 976753224 --> [Forged physical sector]

Sector 976753225 --> [Forged physical sector]

Sector 976753226 --> [Forged physical sector]

Sector 976753227 --> [Forged physical sector]

Sector 976753228 --> [Forged physical sector]

Sector 976753229 --> [Forged physical sector]

Sector 976753230 --> [Forged physical sector]

Sector 976753231 --> [Forged physical sector]

Sector 976753232 --> [Forged physical sector]

Sector 976753233 --> [Forged physical sector]

Sector 976753234 --> [Forged physical sector]

Sector 976753235 --> [Forged physical sector]

Sector 976753236 --> [Forged physical sector]

Sector 976753237 --> [Forged physical sector]

Sector 976753238 --> [Forged physical sector]

Sector 976753239 --> [Forged physical sector]

Sector 976753240 --> [Forged physical sector]

Sector 976753241 --> [Forged physical sector]

Sector 976753242 --> [Forged physical sector]

Sector 976753243 --> [Forged physical sector]

Sector 976753244 --> [Forged physical sector]

Sector 976753245 --> [Forged physical sector]

Sector 976753246 --> [Forged physical sector]

Sector 976753247 --> [Forged physical sector]

Sector 976753248 --> [Forged physical sector]

Sector 976753249 --> [Forged physical sector]

Sector 976753250 --> [Forged physical sector]

Sector 976753251 --> [Forged physical sector]

Sector 976753252 --> [Forged physical sector]

Sector 976753253 --> [Forged physical sector]

Sector 976753254 --> [Forged physical sector]

Sector 976753255 --> [Forged physical sector]

Sector 976753256 --> [Forged physical sector]

Sector 976753257 --> [Forged physical sector]

Sector 976753258 --> [Forged physical sector]

Sector 976753259 --> [Forged physical sector]

Sector 976753260 --> [Forged physical sector]

Sector 976753261 --> [Forged physical sector]

Sector 976753262 --> [Forged physical sector]

Sector 976753263 --> [Forged physical sector]

Sector 976753264 --> [Forged physical sector]

Sector 976753265 --> [Forged physical sector]

Sector 976753266 --> [Forged physical sector]

Sector 976753267 --> [Forged physical sector]

Sector 976753268 --> [Forged physical sector]

Sector 976753269 --> [Forged physical sector]

Sector 976753270 --> [Forged physical sector]

Sector 976753271 --> [Forged physical sector]

Sector 976753272 --> [Forged physical sector]

Sector 976753273 --> [Forged physical sector]

Sector 976753274 --> [Forged physical sector]

Sector 976753275 --> [Forged physical sector]

Sector 976753276 --> [Forged physical sector]

Sector 976753277 --> [Forged physical sector]

Sector 976753278 --> [Forged physical sector]

Sector 976753279 --> [Forged physical sector]

Sector 976753280 --> [Forged physical sector]

Sector 976753281 --> [Forged physical sector]

Sector 976753282 --> [Forged physical sector]

Sector 976753283 --> [Forged physical sector]

Sector 976753284 --> [Forged physical sector]

Sector 976753285 --> [Forged physical sector]

Sector 976753286 --> [Forged physical sector]

Sector 976753287 --> [Forged physical sector]

Sector 976753288 --> [Forged physical sector]

Sector 976753289 --> [Forged physical sector]

Sector 976753290 --> [Forged physical sector]

Sector 976753291 --> [Forged physical sector]

Sector 976753292 --> [Forged physical sector]

Sector 976753293 --> [Forged physical sector]

Sector 976753294 --> [Forged physical sector]

Sector 976753295 --> [Forged physical sector]

Sector 976753296 --> [Forged physical sector]

Sector 976753297 --> [Forged physical sector]

Sector 976753298 --> [Forged physical sector]

Sector 976753299 --> [Forged physical sector]

Sector 976753300 --> [Forged physical sector]

Sector 976753301 --> [Forged physical sector]

Sector 976753302 --> [Forged physical sector]

Sector 976753303 --> [Forged physical sector]

Sector 976753304 --> [Forged physical sector]

Sector 976753305 --> [Forged physical sector]

Sector 976753306 --> [Forged physical sector]

Sector 976753307 --> [Forged physical sector]

Sector 976753308 --> [Forged physical sector]

Sector 976753309 --> [Forged physical sector]

Sector 976753310 --> [Forged physical sector]

Sector 976753311 --> [Forged physical sector]

Sector 976753312 --> [Forged physical sector]

Sector 976753313 --> [Forged physical sector]

Sector 976753314 --> [Forged physical sector]

Sector 976753315 --> [Forged physical sector]

Sector 976753316 --> [Forged physical sector]

Sector 976753317 --> [Forged physical sector]

Sector 976753318 --> [Forged physical sector]

Sector 976753319 --> [Forged physical sector]

Sector 976753320 --> [Forged physical sector]

Sector 976753321 --> [Forged physical sector]

Sector 976753322 --> [Forged physical sector]

Sector 976753323 --> [Forged physical sector]

Sector 976753324 --> [Forged physical sector]

Sector 976753325 --> [Forged physical sector]

Sector 976753326 --> [Forged physical sector]

Sector 976753327 --> [Forged physical sector]

Sector 976753328 --> [Forged physical sector]

Sector 976753329 --> [Forged physical sector]

Sector 976753330 --> [Forged physical sector]

Sector 976753331 --> [Forged physical sector]

Sector 976753332 --> [Forged physical sector]

Sector 976753333 --> [Forged physical sector]

Sector 976753334 --> [Forged physical sector]

Sector 976753335 --> [Forged physical sector]

Sector 976753336 --> [Forged physical sector]

Sector 976753337 --> [Forged physical sector]

Sector 976753338 --> [Forged physical sector]

Sector 976753339 --> [Forged physical sector]

Sector 976753340 --> [Forged physical sector]

Sector 976753341 --> [Forged physical sector]

Sector 976753342 --> [Forged physical sector]

Sector 976753343 --> [Forged physical sector]

Sector 976753344 --> [Forged physical sector]

Sector 976753345 --> [Forged physical sector]

Sector 976753346 --> [Forged physical sector]

Sector 976753347 --> [Forged physical sector]

Sector 976753348 --> [Forged physical sector]

Sector 976753349 --> [Forged physical sector]

Sector 976753350 --> [Forged physical sector]

Sector 976753351 --> [Forged physical sector]

Sector 976753352 --> [Forged physical sector]

Sector 976753353 --> [Forged physical sector]

Sector 976753354 --> [Forged physical sector]

Sector 976753355 --> [Forged physical sector]

Sector 976753356 --> [Forged physical sector]

Sector 976753357 --> [Forged physical sector]

Sector 976753358 --> [Forged physical sector]

Sector 976753359 --> [Forged physical sector]

Sector 976753360 --> [Forged physical sector]

Sector 976753361 --> [Forged physical sector]

Sector 976753362 --> [Forged physical sector]

Sector 976753363 --> [Forged physical sector]

Sector 976753364 --> [Forged physical sector]

Sector 976753365 --> [Forged physical sector]

Sector 976753366 --> [Forged physical sector]

Sector 976753367 --> [Forged physical sector]

Sector 976753368 --> [Forged physical sector]

Sector 976753369 --> [Forged physical sector]

Sector 976753370 --> [Forged physical sector]

Sector 976753371 --> [Forged physical sector]

Sector 976753372 --> [Forged physical sector]

Sector 976753373 --> [Forged physical sector]

Sector 976753374 --> [Forged physical sector]

Sector 976753375 --> [Forged physical sector]

Sector 976753376 --> [Forged physical sector]

Sector 976753377 --> [Forged physical sector]

Sector 976753378 --> [Forged physical sector]

Sector 976753379 --> [Forged physical sector]

Sector 976753380 --> [Forged physical sector]

Sector 976753381 --> [Forged physical sector]

Sector 976753382 --> [Forged physical sector]

Sector 976753383 --> [Forged physical sector]

Sector 976753384 --> [Forged physical sector]

Sector 976753385 --> [Forged physical sector]

Sector 976753386 --> [Forged physical sector]

Sector 976753387 --> [Forged physical sector]

Sector 976753388 --> [Forged physical sector]

Sector 976753389 --> [Forged physical sector]

Sector 976753390 --> [Forged physical sector]

Sector 976753391 --> [Forged physical sector]

Sector 976753392 --> [Forged physical sector]

Sector 976753393 --> [Forged physical sector]

Sector 976753394 --> [Forged physical sector]

Sector 976753395 --> [Forged physical sector]

Sector 976753396 --> [Forged physical sector]

Sector 976753397 --> [Forged physical sector]

Sector 976753398 --> [Forged physical sector]

Sector 976753399 --> [Forged physical sector]

Sector 976753400 --> [Forged physical sector]

Sector 976753401 --> [Forged physical sector]

Sector 976753402 --> [Forged physical sector]

Sector 976753403 --> [Forged physical sector]

Sector 976753404 --> [Forged physical sector]

Sector 976753405 --> [Forged physical sector]

Sector 976753406 --> [Forged physical sector]

Sector 976753407 --> [Forged physical sector]

Sector 976753408 --> [Forged physical sector]

Sector 976753409 --> [Forged physical sector]

Sector 976753410 --> [Forged physical sector]

Sector 976753411 --> [Forged physical sector]

Sector 976753412 --> [Forged physical sector]

Sector 976753413 --> [Forged physical sector]

Sector 976753414 --> [Forged physical sector]

Sector 976753415 --> [Forged physical sector]

Sector 976753416 --> [Forged physical sector]

Sector 976753417 --> [Forged physical sector]

Sector 976753418 --> [Forged physical sector]

Sector 976753419 --> [Forged physical sector]

Sector 976753420 --> [Forged physical sector]

Sector 976753421 --> [Forged physical sector]

Sector 976753422 --> [Forged physical sector]

Sector 976753423 --> [Forged physical sector]

Sector 976753424 --> [Forged physical sector]

Sector 976753425 --> [Forged physical sector]

Sector 976753426 --> [Forged physical sector]

Sector 976753427 --> [Forged physical sector]

Sector 976753428 --> [Forged physical sector]

Sector 976753429 --> [Forged physical sector]

Sector 976753430 --> [Forged physical sector]

Sector 976753431 --> [Forged physical sector]

Sector 976753432 --> [Forged physical sector]

Sector 976753433 --> [Forged physical sector]

Sector 976753434 --> [Forged physical sector]

Sector 976753435 --> [Forged physical sector]

Sector 976753436 --> [Forged physical sector]

Sector 976753437 --> [Forged physical sector]

Sector 976753438 --> [Forged physical sector]

Sector 976753439 --> [Forged physical sector]

Sector 976753440 --> [Forged physical sector]

Sector 976753441 --> [Forged physical sector]

Sector 976753442 --> [Forged physical sector]

Sector 976753443 --> [Forged physical sector]

Sector 976753444 --> [Forged physical sector]

Sector 976753445 --> [Forged physical sector]

Sector 976753446 --> [Forged physical sector]

Sector 976753447 --> [Forged physical sector]

Sector 976753448 --> [Forged physical sector]

Sector 976753449 --> [Forged physical sector]

Sector 976753450 --> [Forged physical sector]

Sector 976753451 --> [Forged physical sector]

Sector 976753452 --> [Forged physical sector]

Sector 976753453 --> [Forged physical sector]

Sector 976753454 --> [Forged physical sector]

Sector 976753455 --> [Forged physical sector]

Sector 976753456 --> [Forged physical sector]

Sector 976753457 --> [Forged physical sector]

Sector 976753458 --> [Forged physical sector]

Sector 976753459 --> [Forged physical sector]

Sector 976753460 --> [Forged physical sector]

Sector 976753461 --> [Forged physical sector]

Sector 976753462 --> [Forged physical sector]

Sector 976753463 --> [Forged physical sector]

Sector 976753464 --> [Forged physical sector]

Sector 976753465 --> [Forged physical sector]

Sector 976753466 --> [Forged physical sector]

Sector 976753467 --> [Forged physical sector]

Sector 976753468 --> [Forged physical sector]

Sector 976753469 --> [Forged physical sector]

Sector 976753470 --> [Forged physical sector]

Sector 976753471 --> [Forged physical sector]

Sector 976753472 --> [Forged physical sector]

Sector 976753473 --> [Forged physical sector]

Sector 976753474 --> [Forged physical sector]

Sector 976753475 --> [Forged physical sector]

Sector 976753476 --> [Forged physical sector]

Sector 976753477 --> [Forged physical sector]

Sector 976753478 --> [Forged physical sector]

Sector 976753479 --> [Forged physical sector]

Sector 976753480 --> [Forged physical sector]

Sector 976753481 --> [Forged physical sector]

Sector 976753482 --> [Forged physical sector]

Sector 976753483 --> [Forged physical sector]

Sector 976753484 --> [Forged physical sector]

Sector 976753485 --> [Forged physical sector]

Sector 976753486 --> [Forged physical sector]

Sector 976753487 --> [Forged physical sector]

Sector 976753488 --> [Forged physical sector]

Sector 976753489 --> [Forged physical sector]

Sector 976753490 --> [Forged physical sector]

Sector 976753491 --> [Forged physical sector]

Sector 976753492 --> [Forged physical sector]

Sector 976753493 --> [Forged physical sector]

Sector 976753494 --> [Forged physical sector]

Sector 976753495 --> [Forged physical sector]

Sector 976753496 --> [Forged physical sector]

Sector 976753497 --> [Forged physical sector]

Sector 976753498 --> [Forged physical sector]

Sector 976753499 --> [Forged physical sector]

Sector 976753500 --> [Forged physical sector]

Sector 976753501 --> [Forged physical sector]

Sector 976753502 --> [Forged physical sector]

Sector 976753503 --> [Forged physical sector]

Sector 976753504 --> [Forged physical sector]

Sector 976753505 --> [Forged physical sector]

Sector 976753506 --> [Forged physical sector]

Sector 976753507 --> [Forged physical sector]

Sector 976753508 --> [Forged physical sector]

Sector 976753509 --> [Forged physical sector]

Sector 976753510 --> [Forged physical sector]

Sector 976753511 --> [Forged physical sector]

Sector 976753512 --> [Forged physical sector]

Sector 976753513 --> [Forged physical sector]

Sector 976753514 --> [Forged physical sector]

Sector 976753515 --> [Forged physical sector]

Sector 976753516 --> [Forged physical sector]

Sector 976753517 --> [Forged physical sector]

Sector 976753518 --> [Forged physical sector]

Sector 976753519 --> [Forged physical sector]

Sector 976753520 --> [Forged physical sector]

Sector 976753521 --> [Forged physical sector]

Sector 976753522 --> [Forged physical sector]

Sector 976753523 --> [Forged physical sector]

Sector 976753524 --> [Forged physical sector]

Sector 976753525 --> [Forged physical sector]

Sector 976753526 --> [Forged physical sector]

Sector 976753527 --> [Forged physical sector]

Sector 976753528 --> [Forged physical sector]

Sector 976753529 --> [Forged physical sector]

Sector 976753530 --> [Forged physical sector]

Sector 976753531 --> [Forged physical sector]

Sector 976753532 --> [Forged physical sector]

Sector 976753533 --> [Forged physical sector]

Sector 976753534 --> [Forged physical sector]

Sector 976753535 --> [Forged physical sector]

Sector 976753536 --> [Forged physical sector]

Sector 976753537 --> [Forged physical sector]

Sector 976753538 --> [Forged physical sector]

Sector 976753539 --> [Forged physical sector]

Sector 976753540 --> [Forged physical sector]

Sector 976753541 --> [Forged physical sector]

Sector 976753542 --> [Forged physical sector]

Sector 976753543 --> [Forged physical sector]

Sector 976753544 --> [Forged physical sector]

Sector 976753545 --> [Forged physical sector]

Sector 976753546 --> [Forged physical sector]

Sector 976753547 --> [Forged physical sector]

Sector 976753548 --> [Forged physical sector]

Sector 976753549 --> [Forged physical sector]

Sector 976753550 --> [Forged physical sector]

Sector 976753551 --> [Forged physical sector]

Sector 976753552 --> [Forged physical sector]

Sector 976753553 --> [Forged physical sector]

Sector 976753554 --> [Forged physical sector]

Sector 976753555 --> [Forged physical sector]

Sector 976753556 --> [Forged physical sector]

Sector 976753557 --> [Forged physical sector]

Sector 976753558 --> [Forged physical sector]

Sector 976753559 --> [Forged physical sector]

Sector 976753560 --> [Forged physical sector]

Sector 976753561 --> [Forged physical sector]

Sector 976753562 --> [Forged physical sector]

Sector 976753563 --> [Forged physical sector]

Sector 976753564 --> [Forged physical sector]

Sector 976753565 --> [Forged physical sector]

Sector 976753566 --> [Forged physical sector]

Sector 976753567 --> [Forged physical sector]

Sector 976753568 --> [Forged physical sector]

Sector 976753569 --> [Forged physical sector]

Sector 976753570 --> [Forged physical sector]

Sector 976753571 --> [Forged physical sector]

Sector 976753572 --> [Forged physical sector]

Sector 976753573 --> [Forged physical sector]

Sector 976753574 --> [Forged physical sector]

Sector 976753575 --> [Forged physical sector]

Sector 976753576 --> [Forged physical sector]

Sector 976753577 --> [Forged physical sector]

Sector 976753578 --> [Forged physical sector]

Sector 976753579 --> [Forged physical sector]

Sector 976753580 --> [Forged physical sector]

Sector 976753581 --> [Forged physical sector]

Sector 976753582 --> [Forged physical sector]

Sector 976753583 --> [Forged physical sector]

Sector 976753584 --> [Forged physical sector]

Sector 976753585 --> [Forged physical sector]

Sector 976753586 --> [Forged physical sector]

Sector 976753587 --> [Forged physical sector]

Sector 976753588 --> [Forged physical sector]

Sector 976753589 --> [Forged physical sector]

Sector 976753590 --> [Forged physical sector]

Sector 976753591 --> [Forged physical sector]

Sector 976753592 --> [Forged physical sector]

Sector 976753593 --> [Forged physical sector]

Sector 976753594 --> [Forged physical sector]

Sector 976753595 --> [Forged physical sector]

Sector 976753596 --> [Forged physical sector]

Sector 976753597 --> [Forged physical sector]

Sector 976753598 --> [Forged physical sector]

Sector 976753599 --> [Forged physical sector]

Sector 976753600 --> [Forged physical sector]

Sector 976753601 --> [Forged physical sector]

Sector 976753602 --> [Forged physical sector]

Sector 976753603 --> [Forged physical sector]

Sector 976753604 --> [Forged physical sector]

Sector 976753605 --> [Forged physical sector]

Sector 976753606 --> [Forged physical sector]

Sector 976753607 --> [Forged physical sector]

Sector 976753608 --> [Forged physical sector]

Sector 976753609 --> [Forged physical sector]

Sector 976753610 --> [Forged physical sector]

Sector 976753611 --> [Forged physical sector]

Sector 976753612 --> [Forged physical sector]

Sector 976753613 --> [Forged physical sector]

Sector 976753614 --> [Forged physical sector]

Sector 976753615 --> [Forged physical sector]

Sector 976753616 --> [Forged physical sector]

Sector 976753617 --> [Forged physical sector]

Sector 976753618 --> [Forged physical sector]

Sector 976753619 --> [Forged physical sector]

Sector 976753620 --> [Forged physical sector]

Sector 976753621 --> [Forged physical sector]

Sector 976753622 --> [Forged physical sector]

Sector 976753623 --> [Forged physical sector]

Sector 976753624 --> [Forged physical sector]

Sector 976753625 --> [Forged physical sector]

Sector 976753626 --> [Forged physical sector]

Sector 976753627 --> [Forged physical sector]

Sector 976753628 --> [Forged physical sector]

Sector 976753629 --> [Forged physical sector]

Sector 976753630 --> [Forged physical sector]

Sector 976753631 --> [Forged physical sector]

Sector 976753632 --> [Forged physical sector]

Sector 976753633 --> [Forged physical sector]

Sector 976753634 --> [Forged physical sector]

Sector 976753635 --> [Forged physical sector]

Sector 976753636 --> [Forged physical sector]

Sector 976753637 --> [Forged physical sector]

Sector 976753638 --> [Forged physical sector]

Sector 976753639 --> [Forged physical sector]

Sector 976753640 --> [Forged physical sector]

Sector 976753641 --> [Forged physical sector]

Sector 976753642 --> [Forged physical sector]

Sector 976753643 --> [Forged physical sector]

Sector 976753644 --> [Forged physical sector]

Sector 976753645 --> [Forged physical sector]

Sector 976753646 --> [Forged physical sector]

Sector 976753647 --> [Forged physical sector]

Sector 976753648 --> [Forged physical sector]

Sector 976753649 --> [Forged physical sector]

Sector 976753650 --> [Forged physical sector]

Sector 976753651 --> [Forged physical sector]

Sector 976753652 --> [Forged physical sector]

Sector 976753653 --> [Forged physical sector]

Sector 976753654 --> [Forged physical sector]

Sector 976753655 --> [Forged physical sector]

Sector 976753656 --> [Forged physical sector]

Sector 976753657 --> [Forged physical sector]

Sector 976753658 --> [Forged physical sector]

Sector 976753659 --> [Forged physical sector]

Sector 976753660 --> [Forged physical sector]

Sector 976753661 --> [Forged physical sector]

Sector 976753662 --> [Forged physical sector]

Sector 976753663 --> [Forged physical sector]

Sector 976753664 --> [Forged physical sector]

Sector 976753665 --> [Forged physical sector]

Sector 976753666 --> [Forged physical sector]

Sector 976753667 --> [Forged physical sector]

Sector 976753668 --> [Forged physical sector]

Sector 976753669 --> [Forged physical sector]

Sector 976753670 --> [Forged physical sector]

Sector 976753671 --> [Forged physical sector]

Sector 976753672 --> [Forged physical sector]

Sector 976753673 --> [Forged physical sector]

Sector 976753674 --> [Forged physical sector]

Sector 976753675 --> [Forged physical sector]

Sector 976753676 --> [Forged physical sector]

Sector 976753677 --> [Forged physical sector]

Sector 976753678 --> [Forged physical sector]

Sector 976753679 --> [Forged physical sector]

Sector 976753680 --> [Forged physical sector]

Sector 976753681 --> [Forged physical sector]

Sector 976753682 --> [Forged physical sector]

Sector 976753683 --> [Forged physical sector]

Sector 976753684 --> [Forged physical sector]

Sector 976753685 --> [Forged physical sector]

Sector 976753686 --> [Forged physical sector]

Sector 976753687 --> [Forged physical sector]

Sector 976753688 --> [Forged physical sector]

Sector 976753689 --> [Forged physical sector]

Sector 976753690 --> [Forged physical sector]

Sector 976753691 --> [Forged physical sector]

Sector 976753692 --> [Forged physical sector]

Sector 976753693 --> [Forged physical sector]

Sector 976753694 --> [Forged physical sector]

Sector 976753695 --> [Forged physical sector]

Sector 976753696 --> [Forged physical sector]

Sector 976753697 --> [Forged physical sector]

Sector 976753698 --> [Forged physical sector]

Sector 976753699 --> [Forged physical sector]

Sector 976753700 --> [Forged physical sector]

Sector 976753701 --> [Forged physical sector]

Sector 976753702 --> [Forged physical sector]

Sector 976753703 --> [Forged physical sector]

Sector 976753704 --> [Forged physical sector]

Sector 976753705 --> [Forged physical sector]

Sector 976753706 --> [Forged physical sector]

Sector 976753707 --> [Forged physical sector]

Sector 976753708 --> [Forged physical sector]

Sector 976753709 --> [Forged physical sector]

Sector 976753710 --> [Forged physical sector]

Sector 976753711 --> [Forged physical sector]

Sector 976753712 --> [Forged physical sector]

Sector 976753713 --> [Forged physical sector]

Sector 976753714 --> [Forged physical sector]

Sector 976753715 --> [Forged physical sector]

Sector 976753716 --> [Forged physical sector]

Sector 976753717 --> [Forged physical sector]

Sector 976753718 --> [Forged physical sector]

Sector 976753719 --> [Forged physical sector]

Sector 976753720 --> [Forged physical sector]

Sector 976753721 --> [Forged physical sector]

Sector 976753722 --> [Forged physical sector]

Sector 976753723 --> [Forged physical sector]

Sector 976753724 --> [Forged physical sector]

Sector 976753725 --> [Forged physical sector]

Sector 976753726 --> [Forged physical sector]

Sector 976753727 --> [Forged physical sector]

Sector 976753728 --> [Forged physical sector]

Sector 976753729 --> [Forged physical sector]

Sector 976753730 --> [Forged physical sector]

Sector 976753731 --> [Forged physical sector]

Sector 976753732 --> [Forged physical sector]

Sector 976753733 --> [Forged physical sector]

Sector 976753734 --> [Forged physical sector]

Sector 976753735 --> [Forged physical sector]

Sector 976753736 --> [Forged physical sector]

Sector 976753737 --> [Forged physical sector]

Sector 976753738 --> [Forged physical sector]

Sector 976753739 --> [Forged physical sector]

Sector 976753740 --> [Forged physical sector]

Sector 976753741 --> [Forged physical sector]

Sector 976753742 --> [Forged physical sector]

Sector 976753743 --> [Forged physical sector]

Sector 976753744 --> [Forged physical sector]

Sector 976753745 --> [Forged physical sector]

Sector 976753746 --> [Forged physical sector]

Sector 976753747 --> [Forged physical sector]

Sector 976753748 --> [Forged physical sector]

Sector 976753749 --> [Forged physical sector]

Sector 976753750 --> [Forged physical sector]

Sector 976753751 --> [Forged physical sector]

Sector 976753752 --> [Forged physical sector]

Sector 976753753 --> [Forged physical sector]

Sector 976753754 --> [Forged physical sector]

Sector 976753755 --> [Forged physical sector]

Sector 976753756 --> [Forged physical sector]

Sector 976753757 --> [Forged physical sector]

Sector 976753758 --> [Forged physical sector]

Sector 976753759 --> [Forged physical sector]

Sector 976753760 --> [Forged physical sector]

Sector 976753761 --> [Forged physical sector]

Sector 976753762 --> [Forged physical sector]

Sector 976753763 --> [Forged physical sector]

Sector 976753764 --> [Forged physical sector]

Sector 976753765 --> [Forged physical sector]

Sector 976753766 --> [Forged physical sector]

Sector 976753767 --> [Forged physical sector]

Sector 976753768 --> [Forged physical sector]

Sector 976753769 --> [Forged physical sector]

Sector 976753770 --> [Forged physical sector]

Sector 976753771 --> [Forged physical sector]

Sector 976753772 --> [Forged physical sector]

Sector 976753773 --> [Forged physical sector]

Sector 976753774 --> [Forged physical sector]

Sector 976753775 --> [Forged physical sector]

Sector 976753776 --> [Forged physical sector]

Sector 976753777 --> [Forged physical sector]

Sector 976753778 --> [Forged physical sector]

Sector 976753779 --> [Forged physical sector]

Sector 976753780 --> [Forged physical sector]

Sector 976753781 --> [Forged physical sector]

Sector 976753782 --> [Forged physical sector]

Sector 976753783 --> [Forged physical sector]

Sector 976753784 --> [Forged physical sector]

Sector 976753785 --> [Forged physical sector]

Sector 976753786 --> [Forged physical sector]

Sector 976753787 --> [Forged physical sector]

Sector 976753788 --> [Forged physical sector]

Sector 976753789 --> [Forged physical sector]

Sector 976753790 --> [Forged physical sector]

Sector 976753791 --> [Forged physical sector]

Sector 976753792 --> [Forged physical sector]

Sector 976753793 --> [Forged physical sector]

Sector 976753794 --> [Forged physical sector]

Sector 976753795 --> [Forged physical sector]

Sector 976753796 --> [Forged physical sector]

Sector 976753797 --> [Forged physical sector]

Sector 976753798 --> [Forged physical sector]

Sector 976753799 --> [Forged physical sector]

Sector 976753800 --> [Forged physical sector]

Sector 976753801 --> [Forged physical sector]

Sector 976753802 --> [Forged physical sector]

Sector 976753803 --> [Forged physical sector]

Sector 976753804 --> [Forged physical sector]

Sector 976753805 --> [Forged physical sector]

Sector 976753806 --> [Forged physical sector]

Sector 976753807 --> [Forged physical sector]

Sector 976753808 --> [Forged physical sector]

Sector 976753809 --> [Forged physical sector]

Sector 976753810 --> [Forged physical sector]

Sector 976753811 --> [Forged physical sector]

Sector 976753812 --> [Forged physical sector]

Sector 976753813 --> [Forged physical sector]

Sector 976753814 --> [Forged physical sector]

Sector 976753815 --> [Forged physical sector]

Sector 976753816 --> [Forged physical sector]

Sector 976753817 --> [Forged physical sector]

Sector 976753818 --> [Forged physical sector]

Sector 976753819 --> [Forged physical sector]

Sector 976753820 --> [Forged physical sector]

Sector 976753821 --> [Forged physical sector]

Sector 976753822 --> [Forged physical sector]

Sector 976753823 --> [Forged physical sector]

Sector 976753824 --> [Forged physical sector]

Sector 976753825 --> [Forged physical sector]

Sector 976753826 --> [Forged physical sector]

Sector 976753827 --> [Forged physical sector]

Sector 976753828 --> [Forged physical sector]

Sector 976753829 --> [Forged physical sector]

Sector 976753830 --> [Forged physical sector]

Sector 976753831 --> [Forged physical sector]

Sector 976753832 --> [Forged physical sector]

Sector 976753833 --> [Forged physical sector]

Sector 976753834 --> [Forged physical sector]

Sector 976753835 --> [Forged physical sector]

Sector 976753836 --> [Forged physical sector]

Sector 976753837 --> [Forged physical sector]

Sector 976753838 --> [Forged physical sector]

Sector 976753839 --> [Forged physical sector]

Sector 976753840 --> [Forged physical sector]

Sector 976753841 --> [Forged physical sector]

Sector 976753842 --> [Forged physical sector]

Sector 976753843 --> [Forged physical sector]

Sector 976753844 --> [Forged physical sector]

Sector 976753845 --> [Forged physical sector]

Sector 976753846 --> [Forged physical sector]

Sector 976753847 --> [Forged physical sector]

Sector 976753848 --> [Forged physical sector]

Sector 976753849 --> [Forged physical sector]

Sector 976753850 --> [Forged physical sector]

Sector 976753851 --> [Forged physical sector]

Sector 976753852 --> [Forged physical sector]

Sector 976753853 --> [Forged physical sector]

Sector 976753854 --> [Forged physical sector]

Sector 976753855 --> [Forged physical sector]

Sector 976753856 --> [Forged physical sector]

Sector 976753857 --> [Forged physical sector]

Sector 976753858 --> [Forged physical sector]

Sector 976753859 --> [Forged physical sector]

Sector 976753860 --> [Forged physical sector]

Sector 976753861 --> [Forged physical sector]

Sector 976753862 --> [Forged physical sector]

Sector 976753863 --> [Forged physical sector]

Sector 976753864 --> [Forged physical sector]

Sector 976753865 --> [Forged physical sector]

Sector 976753866 --> [Forged physical sector]

Sector 976753867 --> [Forged physical sector]

Sector 976753868 --> [Forged physical sector]

Sector 976753869 --> [Forged physical sector]

Sector 976753870 --> [Forged physical sector]

Sector 976753871 --> [Forged physical sector]

Sector 976753872 --> [Forged physical sector]

Sector 976753873 --> [Forged physical sector]

Sector 976753874 --> [Forged physical sector]

Sector 976753875 --> [Forged physical sector]

Sector 976753876 --> [Forged physical sector]

Sector 976753877 --> [Forged physical sector]

Sector 976753878 --> [Forged physical sector]

Sector 976753879 --> [Forged physical sector]

Sector 976753880 --> [Forged physical sector]

Sector 976753881 --> [Forged physical sector]

Sector 976753882 --> [Forged physical sector]

Sector 976753883 --> [Forged physical sector]

Sector 976753884 --> [Forged physical sector]

Sector 976753885 --> [Forged physical sector]

Sector 976753886 --> [Forged physical sector]

Sector 976753887 --> [Forged physical sector]

Sector 976753888 --> [Forged physical sector]

Sector 976753889 --> [Forged physical sector]

Sector 976753890 --> [Forged physical sector]

Sector 976753891 --> [Forged physical sector]

Sector 976753892 --> [Forged physical sector]

Sector 976753893 --> [Forged physical sector]

Sector 976753894 --> [Forged physical sector]

Sector 976753895 --> [Forged physical sector]

Sector 976753896 --> [Forged physical sector]

Sector 976753897 --> [Forged physical sector]

Sector 976753898 --> [Forged physical sector]

Sector 976753899 --> [Forged physical sector]

Sector 976753900 --> [Forged physical sector]

Sector 976753901 --> [Forged physical sector]

Sector 976753902 --> [Forged physical sector]

Sector 976753903 --> [Forged physical sector]

Sector 976753904 --> [Forged physical sector]

Sector 976753905 --> [Forged physical sector]

Sector 976753906 --> [Forged physical sector]

Sector 976753907 --> [Forged physical sector]

Sector 976753908 --> [Forged physical sector]

Sector 976753909 --> [Forged physical sector]

Sector 976753910 --> [Forged physical sector]

Sector 976753911 --> [Forged physical sector]

Sector 976753912 --> [Forged physical sector]

Sector 976753913 --> [Forged physical sector]

Sector 976753914 --> [Forged physical sector]

Sector 976753915 --> [Forged physical sector]

Sector 976753916 --> [Forged physical sector]

Sector 976753917 --> [Forged physical sector]

Sector 976753918 --> [Forged physical sector]

Sector 976753919 --> [Forged physical sector]

Sector 976753920 --> [Forged physical sector]

Sector 976753921 --> [Forged physical sector]

Sector 976753922 --> [Forged physical sector]

Sector 976753923 --> [Forged physical sector]

Sector 976753924 --> [Forged physical sector]

Sector 976753925 --> [Forged physical sector]

Sector 976753926 --> [Forged physical sector]

Sector 976753927 --> [Forged physical sector]

Sector 976753928 --> [Forged physical sector]

Sector 976753929 --> [Forged physical sector]

Sector 976753930 --> [Forged physical sector]

Sector 976753931 --> [Forged physical sector]

Sector 976753932 --> [Forged physical sector]

Sector 976753933 --> [Forged physical sector]

Sector 976753934 --> [Forged physical sector]

Sector 976753935 --> [Forged physical sector]

Sector 976753936 --> [Forged physical sector]

Sector 976753937 --> [Forged physical sector]

Sector 976753938 --> [Forged physical sector]

Sector 976753939 --> [Forged physical sector]

Sector 976753940 --> [Forged physical sector]

Sector 976753941 --> [Forged physical sector]

Sector 976753942 --> [Forged physical sector]

Sector 976753943 --> [Forged physical sector]

Sector 976753944 --> [Forged physical sector]

Sector 976753945 --> [Forged physical sector]

Sector 976753946 --> [Forged physical sector]

Sector 976753947 --> [Forged physical sector]

Sector 976753948 --> [Forged physical sector]

Sector 976753949 --> [Forged physical sector]

Sector 976753950 --> [Forged physical sector]

Sector 976753951 --> [Forged physical sector]

Sector 976753952 --> [Forged physical sector]

Sector 976753953 --> [Forged physical sector]

Sector 976753954 --> [Forged physical sector]

Sector 976753955 --> [Forged physical sector]

Sector 976753956 --> [Forged physical sector]

Sector 976753957 --> [Forged physical sector]

Sector 976753958 --> [Forged physical sector]

Sector 976753959 --> [Forged physical sector]

Sector 976753960 --> [Forged physical sector]

Sector 976753961 --> [Forged physical sector]

Sector 976753962 --> [Forged physical sector]

Sector 976753963 --> [Forged physical sector]

Sector 976753964 --> [Forged physical sector]

Sector 976753965 --> [Forged physical sector]

Sector 976753966 --> [Forged physical sector]

Sector 976753967 --> [Forged physical sector]

Sector 976753968 --> [Forged physical sector]

Sector 976753969 --> [Forged physical sector]

Sector 976753970 --> [Forged physical sector]

Sector 976753971 --> [Forged physical sector]

Sector 976753972 --> [Forged physical sector]

Sector 976753973 --> [Forged physical sector]

Sector 976753974 --> [Forged physical sector]

Sector 976753975 --> [Forged physical sector]

Sector 976753976 --> [Forged physical sector]

Sector 976753977 --> [Forged physical sector]

Sector 976753978 --> [Forged physical sector]

Sector 976753979 --> [Forged physical sector]

Sector 976753980 --> [Forged physical sector]

Sector 976753981 --> [Forged physical sector]

Sector 976753982 --> [Forged physical sector]

Sector 976753983 --> [Forged physical sector]

Sector 976753984 --> [Forged physical sector]

Sector 976753985 --> [Forged physical sector]

Sector 976753986 --> [Forged physical sector]

Sector 976753987 --> [Forged physical sector]

Sector 976753988 --> [Forged physical sector]

Sector 976753989 --> [Forged physical sector]

Sector 976753990 --> [Forged physical sector]

Sector 976753991 --> [Forged physical sector]

Sector 976753992 --> [Forged physical sector]

Sector 976753993 --> [Forged physical sector]

Sector 976753994 --> [Forged physical sector]

Sector 976753995 --> [Forged physical sector]

Sector 976753996 --> [Forged physical sector]

Sector 976753997 --> [Forged physical sector]

Sector 976753998 --> [Forged physical sector]

Sector 976753999 --> [Forged physical sector]

Sector 976754000 --> [Forged physical sector]

Sector 976754001 --> [Forged physical sector]

Sector 976754002 --> [Forged physical sector]

Sector 976754003 --> [Forged physical sector]

Sector 976754004 --> [Forged physical sector]

Sector 976754005 --> [Forged physical sector]

Sector 976754006 --> [Forged physical sector]

Sector 976754007 --> [Forged physical sector]

Sector 976754008 --> [Forged physical sector]

Sector 976754009 --> [Forged physical sector]

Sector 976754010 --> [Forged physical sector]

Sector 976754011 --> [Forged physical sector]

Sector 976754012 --> [Forged physical sector]

Sector 976754013 --> [Forged physical sector]

Sector 976754014 --> [Forged physical sector]

Sector 976754015 --> [Forged physical sector]

Sector 976754016 --> [Forged physical sector]

Sector 976754017 --> [Forged physical sector]

Sector 976754018 --> [Forged physical sector]

Sector 976754019 --> [Forged physical sector]

Sector 976754020 --> [Forged physical sector]

Sector 976754021 --> [Forged physical sector]

Sector 976754022 --> [Forged physical sector]

Sector 976754023 --> [Forged physical sector]

Sector 976754024 --> [Forged physical sector]

Sector 976754025 --> [Forged physical sector]

Sector 976754026 --> [Forged physical sector]

Sector 976754027 --> [Forged physical sector]

Sector 976754028 --> [Forged physical sector]

Sector 976754029 --> [Forged physical sector]

Sector 976754030 --> [Forged physical sector]

Sector 976754031 --> [Forged physical sector]

Sector 976754032 --> [Forged physical sector]

Sector 976754033 --> [Forged physical sector]

Sector 976754034 --> [Forged physical sector]

Sector 976754035 --> [Forged physical sector]

Sector 976754036 --> [Forged physical sector]

Sector 976754037 --> [Forged physical sector]

Sector 976754038 --> [Forged physical sector]

Sector 976754039 --> [Forged physical sector]

Sector 976754040 --> [Forged physical sector]

Sector 976754041 --> [Forged physical sector]

Sector 976754042 --> [Forged physical sector]

Sector 976754043 --> [Forged physical sector]

Sector 976754044 --> [Forged physical sector]

Sector 976754045 --> [Forged physical sector]

Sector 976754046 --> [Forged physical sector]

Sector 976754047 --> [Forged physical sector]

Sector 976754048 --> [Forged physical sector]

Sector 976754049 --> [Forged physical sector]

Sector 976754050 --> [Forged physical sector]

Sector 976754051 --> [Forged physical sector]

Sector 976754052 --> [Forged physical sector]

Sector 976754053 --> [Forged physical sector]

Sector 976754054 --> [Forged physical sector]

Sector 976754055 --> [Forged physical sector]

Sector 976754056 --> [Forged physical sector]

Sector 976754057 --> [Forged physical sector]

Sector 976754058 --> [Forged physical sector]

Sector 976754059 --> [Forged physical sector]

Sector 976754060 --> [Forged physical sector]

Sector 976754061 --> [Forged physical sector]

Sector 976754062 --> [Forged physical sector]

Sector 976754063 --> [Forged physical sector]

Sector 976754064 --> [Forged physical sector]

Sector 976754065 --> [Forged physical sector]

Sector 976754066 --> [Forged physical sector]

Sector 976754067 --> [Forged physical sector]

Sector 976754068 --> [Forged physical sector]

Sector 976754069 --> [Forged physical sector]

Sector 976754070 --> [Forged physical sector]

Sector 976754071 --> [Forged physical sector]

Sector 976754072 --> [Forged physical sector]

Sector 976754073 --> [Forged physical sector]

Sector 976754074 --> [Forged physical sector]

Sector 976754075 --> [Forged physical sector]

Sector 976754076 --> [Forged physical sector]

Sector 976754077 --> [Forged physical sector]

Sector 976754078 --> [Forged physical sector]

Sector 976754079 --> [Forged physical sector]

Sector 976754080 --> [Forged physical sector]

Sector 976754081 --> [Forged physical sector]

Sector 976754082 --> [Forged physical sector]

Sector 976754083 --> [Forged physical sector]

Sector 976754084 --> [Forged physical sector]

Sector 976754085 --> [Forged physical sector]

Sector 976754086 --> [Forged physical sector]

Sector 976754087 --> [Forged physical sector]

Sector 976754088 --> [Forged physical sector]

Sector 976754089 --> [Forged physical sector]

Sector 976754090 --> [Forged physical sector]

Sector 976754091 --> [Forged physical sector]

Sector 976754092 --> [Forged physical sector]

Sector 976754093 --> [Forged physical sector]

Sector 976754094 --> [Forged physical sector]

Sector 976754095 --> [Forged physical sector]

Sector 976754096 --> [Forged physical sector]

Sector 976754097 --> [Forged physical sector]

Sector 976754098 --> [Forged physical sector]

Sector 976754099 --> [Forged physical sector]

Sector 976754100 --> [Forged physical sector]

Sector 976754101 --> [Forged physical sector]

Sector 976754102 --> [Forged physical sector]

Sector 976754103 --> [Forged physical sector]

Sector 976754104 --> [Forged physical sector]

Sector 976754105 --> [Forged physical sector]

Sector 976754106 --> [Forged physical sector]

Sector 976754107 --> [Forged physical sector]

Sector 976754108 --> [Forged physical sector]

Sector 976754109 --> [Forged physical sector]

Sector 976754110 --> [Forged physical sector]

Sector 976754111 --> [Forged physical sector]

Sector 976754112 --> [Forged physical sector]

Sector 976754113 --> [Forged physical sector]

Sector 976754114 --> [Forged physical sector]

Sector 976754115 --> [Forged physical sector]

Sector 976754116 --> [Forged physical sector]

Sector 976754117 --> [Forged physical sector]

Sector 976754118 --> [Forged physical sector]

Sector 976754119 --> [Forged physical sector]

Sector 976754120 --> [Forged physical sector]

Sector 976754121 --> [Forged physical sector]

Sector 976754122 --> [Forged physical sector]

Sector 976754123 --> [Forged physical sector]

Sector 976754124 --> [Forged physical sector]

Sector 976754125 --> [Forged physical sector]

Sector 976754126 --> [Forged physical sector]

Sector 976754127 --> [Forged physical sector]

Sector 976754128 --> [Forged physical sector]

Sector 976754129 --> [Forged physical sector]

Sector 976754130 --> [Forged physical sector]

Sector 976754131 --> [Forged physical sector]

Sector 976754132 --> [Forged physical sector]

Sector 976754133 --> [Forged physical sector]

Sector 976754134 --> [Forged physical sector]

Sector 976754135 --> [Forged physical sector]

Sector 976754136 --> [Forged physical sector]

Sector 976754137 --> [Forged physical sector]

Sector 976754138 --> [Forged physical sector]

Sector 976754139 --> [Forged physical sector]

Sector 976754140 --> [Forged physical sector]

Sector 976754141 --> [Forged physical sector]

Sector 976754142 --> [Forged physical sector]

Sector 976754143 --> [Forged physical sector]

Sector 976754144 --> [Forged physical sector]

Sector 976754145 --> [Forged physical sector]

Sector 976754146 --> [Forged physical sector]

Sector 976754147 --> [Forged physical sector]

Sector 976754148 --> [Forged physical sector]

Sector 976754149 --> [Forged physical sector]

Sector 976754150 --> [Forged physical sector]

Sector 976754151 --> [Forged physical sector]

Sector 976754152 --> [Forged physical sector]

Sector 976754153 --> [Forged physical sector]

Sector 976754154 --> [Forged physical sector]

Sector 976754155 --> [Forged physical sector]

Sector 976754156 --> [Forged physical sector]

Sector 976754157 --> [Forged physical sector]

Sector 976754158 --> [Forged physical sector]

Sector 976754159 --> [Forged physical sector]

Sector 976754160 --> [Forged physical sector]

Sector 976754161 --> [Forged physical sector]

Sector 976754162 --> [Forged physical sector]

Sector 976754163 --> [Forged physical sector]

Sector 976754164 --> [Forged physical sector]

Sector 976754165 --> [Forged physical sector]

Sector 976754166 --> [Forged physical sector]

Sector 976754167 --> [Forged physical sector]

Sector 976754168 --> [Forged physical sector]

Sector 976754169 --> [Forged physical sector]

Sector 976754170 --> [Forged physical sector]

Sector 976754171 --> [Forged physical sector]

Sector 976754172 --> [Forged physical sector]

Sector 976754173 --> [Forged physical sector]

Sector 976754174 --> [Forged physical sector]

Sector 976754175 --> [Forged physical sector]

Sector 976754176 --> [Forged physical sector]

Sector 976754177 --> [Forged physical sector]

Sector 976754178 --> [Forged physical sector]

Sector 976754179 --> [Forged physical sector]

Sector 976754180 --> [Forged physical sector]

Sector 976754181 --> [Forged physical sector]

Sector 976754182 --> [Forged physical sector]

Sector 976754183 --> [Forged physical sector]

Sector 976754184 --> [Forged physical sector]

Sector 976754185 --> [Forged physical sector]

Sector 976754186 --> [Forged physical sector]

Sector 976754187 --> [Forged physical sector]

Sector 976754188 --> [Forged physical sector]

Sector 976754189 --> [Forged physical sector]

Sector 976754190 --> [Forged physical sector]

Sector 976754191 --> [Forged physical sector]

Sector 976754192 --> [Forged physical sector]

Sector 976754193 --> [Forged physical sector]

Sector 976754194 --> [Forged physical sector]

Sector 976754195 --> [Forged physical sector]

Sector 976754196 --> [Forged physical sector]

Sector 976754197 --> [Forged physical sector]

Sector 976754198 --> [Forged physical sector]

Sector 976754199 --> [Forged physical sector]

Sector 976754200 --> [Forged physical sector]

Sector 976754201 --> [Forged physical sector]

Sector 976754202 --> [Forged physical sector]

Sector 976754203 --> [Forged physical sector]

Sector 976754204 --> [Forged physical sector]

Sector 976754205 --> [Forged physical sector]

Sector 976754206 --> [Forged physical sector]

Sector 976754207 --> [Forged physical sector]

Sector 976754208 --> [Forged physical sector]

Sector 976754209 --> [Forged physical sector]

Sector 976754210 --> [Forged physical sector]

Sector 976754211 --> [Forged physical sector]

Sector 976754212 --> [Forged physical sector]

Sector 976754213 --> [Forged physical sector]

Sector 976754214 --> [Forged physical sector]

Sector 976754215 --> [Forged physical sector]

Sector 976754216 --> [Forged physical sector]

Sector 976754217 --> [Forged physical sector]

Sector 976754218 --> [Forged physical sector]

Sector 976754219 --> [Forged physical sector]

Sector 976754220 --> [Forged physical sector]

Sector 976754221 --> [Forged physical sector]

Sector 976754222 --> [Forged physical sector]

Sector 976754223 --> [Forged physical sector]

Sector 976754224 --> [Forged physical sector]

Sector 976754225 --> [Forged physical sector]

Sector 976754226 --> [Forged physical sector]

Sector 976754227 --> [Forged physical sector]

Sector 976754228 --> [Forged physical sector]

Sector 976754229 --> [Forged physical sector]

Sector 976754230 --> [Forged physical sector]

Sector 976754231 --> [Forged physical sector]

Sector 976754232 --> [Forged physical sector]

Sector 976754233 --> [Forged physical sector]

Sector 976754234 --> [Forged physical sector]

Sector 976754235 --> [Forged physical sector]

Sector 976754236 --> [Forged physical sector]

Sector 976754237 --> [Forged physical sector]

Sector 976754238 --> [Forged physical sector]

Sector 976754239 --> [Forged physical sector]

Sector 976754240 --> [Forged physical sector]

Sector 976754241 --> [Forged physical sector]

Sector 976754242 --> [Forged physical sector]

Sector 976754243 --> [Forged physical sector]

Sector 976754244 --> [Forged physical sector]

Sector 976754245 --> [Forged physical sector]

Sector 976754246 --> [Forged physical sector]

Sector 976754247 --> [Forged physical sector]

Sector 976754248 --> [Forged physical sector]

Sector 976754249 --> [Forged physical sector]

Sector 976754250 --> [Forged physical sector]

Sector 976754251 --> [Forged physical sector]

Sector 976754252 --> [Forged physical sector]

Sector 976754253 --> [Forged physical sector]

Sector 976754254 --> [Forged physical sector]

Sector 976754255 --> [Forged physical sector]

Sector 976754256 --> [Forged physical sector]

Sector 976754257 --> [Forged physical sector]

Sector 976754258 --> [Forged physical sector]

Sector 976754259 --> [Forged physical sector]

Sector 976754260 --> [Forged physical sector]

Sector 976754261 --> [Forged physical sector]

Sector 976754262 --> [Forged physical sector]

Sector 976754263 --> [Forged physical sector]

Sector 976754264 --> [Forged physical sector]

Sector 976754265 --> [Forged physical sector]

Sector 976754266 --> [Forged physical sector]

Sector 976754267 --> [Forged physical sector]

Sector 976754268 --> [Forged physical sector]

Sector 976754269 --> [Forged physical sector]

Sector 976754270 --> [Forged physical sector]

Sector 976754271 --> [Forged physical sector]

Sector 976754272 --> [Forged physical sector]

Sector 976754273 --> [Forged physical sector]

Sector 976754274 --> [Forged physical sector]

Sector 976754275 --> [Forged physical sector]

Sector 976754276 --> [Forged physical sector]

Sector 976754277 --> [Forged physical sector]

Sector 976754278 --> [Forged physical sector]

Sector 976754279 --> [Forged physical sector]

Sector 976754280 --> [Forged physical sector]

Sector 976754281 --> [Forged physical sector]

Sector 976754282 --> [Forged physical sector]

Sector 976754283 --> [Forged physical sector]

Sector 976754284 --> [Forged physical sector]

Sector 976754285 --> [Forged physical sector]

Sector 976754286 --> [Forged physical sector]

Sector 976754287 --> [Forged physical sector]

Sector 976754288 --> [Forged physical sector]

Sector 976754289 --> [Forged physical sector]

Sector 976754290 --> [Forged physical sector]

Sector 976754291 --> [Forged physical sector]

Sector 976754292 --> [Forged physical sector]

Sector 976754293 --> [Forged physical sector]

Sector 976754294 --> [Forged physical sector]

Sector 976754295 --> [Forged physical sector]

Sector 976754296 --> [Forged physical sector]

Sector 976754297 --> [Forged physical sector]

Sector 976754298 --> [Forged physical sector]

Sector 976754299 --> [Forged physical sector]

Sector 976754300 --> [Forged physical sector]

Sector 976754301 --> [Forged physical sector]

Sector 976754302 --> [Forged physical sector]

Sector 976754303 --> [Forged physical sector]

Sector 976754304 --> [Forged physical sector]

Sector 976754305 --> [Forged physical sector]

Sector 976754306 --> [Forged physical sector]

Sector 976754307 --> [Forged physical sector]

Sector 976754308 --> [Forged physical sector]

Sector 976754309 --> [Forged physical sector]

Sector 976754310 --> [Forged physical sector]

Sector 976754311 --> [Forged physical sector]

Sector 976754312 --> [Forged physical sector]

Sector 976754313 --> [Forged physical sector]

Sector 976754314 --> [Forged physical sector]

Sector 976754315 --> [Forged physical sector]

Sector 976754316 --> [Forged physical sector]

Sector 976754317 --> [Forged physical sector]

Sector 976754318 --> [Forged physical sector]

Sector 976754319 --> [Forged physical sector]

Sector 976754320 --> [Forged physical sector]

Sector 976754321 --> [Forged physical sector]

Sector 976754322 --> [Forged physical sector]

Sector 976754323 --> [Forged physical sector]

Sector 976754324 --> [Forged physical sector]

Sector 976754325 --> [Forged physical sector]

Sector 976754326 --> [Forged physical sector]

Sector 976754327 --> [Forged physical sector]

Sector 976754328 --> [Forged physical sector]

Sector 976754329 --> [Forged physical sector]

Sector 976754330 --> [Forged physical sector]

Sector 976754331 --> [Forged physical sector]

Sector 976754332 --> [Forged physical sector]

Sector 976754333 --> [Forged physical sector]

Sector 976754334 --> [Forged physical sector]

Sector 976754335 --> [Forged physical sector]

Sector 976754336 --> [Forged physical sector]

Sector 976754337 --> [Forged physical sector]

Sector 976754338 --> [Forged physical sector]

Sector 976754339 --> [Forged physical sector]

Sector 976754340 --> [Forged physical sector]

Sector 976754341 --> [Forged physical sector]

Sector 976754342 --> [Forged physical sector]

Sector 976754343 --> [Forged physical sector]

Sector 976754344 --> [Forged physical sector]

Sector 976754345 --> [Forged physical sector]

Sector 976764927 --> [Forged physical sector]

Sector 976773167 --> [Forged physical sector]

Done!

Performing system, memory and registry scan...

Done!

Scan finished

Creating System Restore point...

Scheduling clean up...

<<<2>>>

Device number: 0, partition: 3

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

BCD Entry for BOOTEMS is missing

Malicious Entry 26000022 for BOOTEMS present!

Removal scheduling successful. System shutdown needed.

System shutdown occurred

=======================================

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1011

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED

CPU speed: 3.192000 GHz

Memory total: 8571793408, free: 7216726016

---------------------------------------

Malwarebytes Anti-Rootkit BETA 1.01.0.1011

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS

Disk drives: C:\ DRIVE_FIXED

CPU speed: 3.192000 GHz

Memory total: 8571793408, free: 7035146240

------------ Kernel report ------------

12/12/2012 11:06:33

------------ Loaded modules -----------

\SystemRoot\system32\ntoskrnl.exe

\SystemRoot\system32\hal.dll

\SystemRoot\system32\kdcom.dll

\SystemRoot\system32\mcupdate_GenuineIntel.dll

\SystemRoot\system32\PSHED.dll

\SystemRoot\system32\CLFS.SYS

\SystemRoot\system32\CI.dll

\SystemRoot\system32\drivers\Wdf01000.sys

\SystemRoot\system32\drivers\WDFLDR.SYS

\SystemRoot\system32\drivers\ACPI.sys

\SystemRoot\system32\drivers\WMILIB.SYS

\SystemRoot\system32\drivers\msisadrv.sys

\SystemRoot\system32\drivers\pci.sys

\SystemRoot\system32\drivers\vdrvroot.sys

\SystemRoot\system32\DRIVERS\iusb3hcs.sys

\SystemRoot\System32\drivers\partmgr.sys

\SystemRoot\system32\drivers\volmgr.sys

\SystemRoot\System32\drivers\volmgrx.sys

\SystemRoot\System32\drivers\mountmgr.sys

\SystemRoot\system32\drivers\iaStor.sys

\SystemRoot\system32\drivers\amdxata.sys

\SystemRoot\system32\drivers\fltmgr.sys

\SystemRoot\system32\drivers\fileinfo.sys

\SystemRoot\System32\Drivers\Ntfs.sys

\SystemRoot\System32\Drivers\msrpc.sys

\SystemRoot\System32\Drivers\ksecdd.sys

\SystemRoot\System32\Drivers\cng.sys

\SystemRoot\System32\drivers\pcw.sys

\SystemRoot\System32\Drivers\Fs_Rec.sys

\SystemRoot\system32\drivers\ndis.sys

\SystemRoot\system32\drivers\NETIO.SYS

\SystemRoot\System32\Drivers\ksecpkg.sys

\SystemRoot\System32\drivers\tcpip.sys

\SystemRoot\System32\drivers\fwpkclnt.sys

\SystemRoot\system32\drivers\volsnap.sys

\SystemRoot\System32\Drivers\spldr.sys

\SystemRoot\System32\drivers\rdyboost.sys

\SystemRoot\system32\DRIVERS\PBADRV.sys

\SystemRoot\System32\Drivers\mup.sys

\SystemRoot\System32\drivers\hwpolicy.sys

\SystemRoot\System32\DRIVERS\fvevol.sys

\SystemRoot\system32\drivers\disk.sys

\SystemRoot\system32\drivers\CLASSPNP.SYS

\SystemRoot\system32\DRIVERS\cdrom.sys

\SystemRoot\System32\Drivers\SRTSP64.SYS

\??\C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20121211.019\EX64.SYS

\??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS

\??\C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20121211.019\ENG64.SYS

\SystemRoot\System32\Drivers\SRTSPX64.SYS

\SystemRoot\System32\Drivers\Null.SYS

\SystemRoot\System32\Drivers\Beep.SYS

\SystemRoot\System32\drivers\vga.sys

\SystemRoot\System32\drivers\VIDEOPRT.SYS

\SystemRoot\System32\drivers\watchdog.sys

\SystemRoot\System32\DRIVERS\RDPCDD.sys

\SystemRoot\system32\drivers\rdpencdd.sys

\SystemRoot\system32\drivers\rdprefmp.sys

\SystemRoot\System32\Drivers\Msfs.SYS

\SystemRoot\System32\Drivers\Npfs.SYS

\SystemRoot\system32\DRIVERS\tdx.sys

\SystemRoot\system32\DRIVERS\TDI.SYS

\??\C:\Windows\system32\drivers\wpsdrvnt.sys

\SystemRoot\system32\drivers\afd.sys

\SystemRoot\System32\DRIVERS\netbt.sys

\SystemRoot\system32\drivers\ws2ifsl.sys

\SystemRoot\system32\DRIVERS\wfplwf.sys

\SystemRoot\system32\DRIVERS\pacer.sys

\SystemRoot\system32\DRIVERS\vpcnfltr.sys

\SystemRoot\system32\DRIVERS\netbios.sys

\SystemRoot\system32\DRIVERS\serial.sys

\SystemRoot\system32\DRIVERS\wanarp.sys

\SystemRoot\system32\drivers\vpcvmm.sys

\SystemRoot\system32\DRIVERS\termdd.sys

\SystemRoot\system32\DRIVERS\rdbss.sys

\SystemRoot\system32\drivers\nsiproxy.sys

\SystemRoot\system32\DRIVERS\mssmbios.sys

\??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys

\??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

\SystemRoot\System32\drivers\discache.sys

\SystemRoot\system32\drivers\csc.sys

\SystemRoot\System32\Drivers\dfsc.sys

\SystemRoot\system32\DRIVERS\blbdrive.sys

\SystemRoot\system32\DRIVERS\tunnel.sys

\SystemRoot\system32\DRIVERS\atikmpag.sys

\SystemRoot\system32\DRIVERS\atikmdag.sys

\SystemRoot\System32\drivers\dxgkrnl.sys

\SystemRoot\System32\drivers\dxgmms1.sys

\SystemRoot\system32\DRIVERS\HDAudBus.sys

\SystemRoot\system32\DRIVERS\iusb3xhc.sys

\SystemRoot\system32\DRIVERS\USBD.SYS

\SystemRoot\system32\DRIVERS\e1c62x64.sys

\SystemRoot\system32\DRIVERS\usbehci.sys

\SystemRoot\system32\DRIVERS\USBPORT.SYS

\SystemRoot\system32\DRIVERS\serenum.sys

\SystemRoot\system32\DRIVERS\intelppm.sys

\SystemRoot\system32\DRIVERS\CompositeBus.sys

\SystemRoot\system32\DRIVERS\lmimirr.sys

\SystemRoot\system32\DRIVERS\AgileVpn.sys

\SystemRoot\system32\DRIVERS\rasl2tp.sys

\SystemRoot\system32\DRIVERS\ndistapi.sys

\SystemRoot\system32\DRIVERS\ndiswan.sys

\SystemRoot\system32\DRIVERS\raspppoe.sys

\SystemRoot\system32\DRIVERS\raspptp.sys

\SystemRoot\system32\DRIVERS\rassstp.sys

\SystemRoot\system32\DRIVERS\rdpbus.sys

\SystemRoot\system32\DRIVERS\kbdclass.sys

\SystemRoot\system32\DRIVERS\mouclass.sys

\SystemRoot\system32\DRIVERS\teefer2.sys

\SystemRoot\system32\DRIVERS\swenum.sys

\SystemRoot\system32\DRIVERS\ks.sys

\SystemRoot\system32\DRIVERS\umbus.sys

\SystemRoot\system32\DRIVERS\vpcusb.sys

\SystemRoot\system32\DRIVERS\usbrpm.sys

\SystemRoot\system32\DRIVERS\vpchbus.sys

\SystemRoot\system32\DRIVERS\usbhub.sys

\SystemRoot\System32\Drivers\NDProxy.SYS

\SystemRoot\system32\drivers\AtihdW76.sys

\SystemRoot\system32\drivers\portcls.sys

\SystemRoot\system32\drivers\drmk.sys

\SystemRoot\system32\drivers\ksthunk.sys

\SystemRoot\system32\DRIVERS\iusb3hub.sys

\SystemRoot\system32\drivers\RTDVHD64.sys

\SystemRoot\System32\Drivers\crashdmp.sys

\SystemRoot\System32\Drivers\dump_iaStor.sys

\SystemRoot\System32\Drivers\dump_dumpfve.sys

\SystemRoot\System32\win32k.sys

\SystemRoot\System32\drivers\Dxapi.sys

\SystemRoot\system32\DRIVERS\usbccgp.sys

\SystemRoot\system32\DRIVERS\dc3d.sys

\SystemRoot\system32\DRIVERS\HIDPARSE.SYS

\SystemRoot\system32\DRIVERS\hidusb.sys

\SystemRoot\system32\DRIVERS\HIDCLASS.SYS

\SystemRoot\system32\DRIVERS\kbdhid.sys

\SystemRoot\system32\DRIVERS\mouhid.sys

\SystemRoot\system32\DRIVERS\monitor.sys

\SystemRoot\System32\TSDDD.dll

\SystemRoot\System32\cdd.dll

\SystemRoot\system32\DRIVERS\SNTUSB64.SYS

\SystemRoot\system32\drivers\luafv.sys

\SystemRoot\system32\DRIVERS\lltdio.sys

\SystemRoot\system32\DRIVERS\rspndr.sys

\SystemRoot\system32\drivers\HTTP.sys

\SystemRoot\system32\DRIVERS\bowser.sys

\SystemRoot\System32\drivers\mpsdrv.sys

\SystemRoot\system32\DRIVERS\mrxsmb.sys

\SystemRoot\system32\DRIVERS\mrxsmb10.sys

\SystemRoot\system32\DRIVERS\mrxsmb20.sys

\SystemRoot\System32\Drivers\Sentinel64.sys

\??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys

\??\C:\Windows\system32\drivers\LMIRfsDriver.sys

\SystemRoot\system32\drivers\peauth.sys

\SystemRoot\System32\Drivers\secdrv.SYS

\SystemRoot\System32\DRIVERS\srvnet.sys

\SystemRoot\System32\drivers\tcpipreg.sys

\SystemRoot\System32\DRIVERS\srv2.sys

\SystemRoot\System32\DRIVERS\srv.sys

\SystemRoot\System32\Drivers\fastfat.SYS

\SystemRoot\system32\drivers\spsys.sys

\??\C:\Windows\system32\drivers\mbamchameleon.sys

\??\C:\Windows\system32\drivers\mbamswissarmy.sys

\Windows\System32\ntdll.dll

\Windows\System32\smss.exe

\Windows\System32\apisetschema.dll

\Windows\System32\autochk.exe

\Windows\System32\msvcrt.dll

\Windows\System32\imm32.dll

\Windows\System32\oleaut32.dll

----------- End -----------

<<<1>>>

Upper Device Name: \Device\Harddisk0\DR0

Upper Device Object: 0xfffffa8009a25060

Upper Device Driver Name: \Driver\Disk\

Lower Device Name: \Device\Ide\IAAStorageDevice-1\

Lower Device Object: 0xfffffa80071aa050

Lower Device Driver Name: \Driver\iaStor\

Driver name found: iaStor

DriverEntry returned 0x0

Function returned 0x0

Initializing...

Done!

<<<2>>>

Device number: 0, partition: 3

Physical Sector Size: 512

Drive: 0, DevicePointer: 0xfffffa8009a25060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

--------- Disk Stack ------

DevicePointer: 0xfffffa8009a25ab0, DeviceName: Unknown, DriverName: \Driver\partmgr\

DevicePointer: 0xfffffa8009a25060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\

DevicePointer: 0xfffffa80071a48c0, DeviceName: Unknown, DriverName: \Driver\ACPI\

DevicePointer: 0xfffffa80071aa050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\

------------ End ----------

Upper DeviceData: 0xfffff8a00d58bbc0, 0xfffffa8009a25060, 0xfffffa8006eb8790

Lower DeviceData: 0xfffff8a008e49280, 0xfffffa80071aa050, 0xfffffa8006e5e790

<<<3>>>

Volume: C:

File system type: NTFS

SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes

Scanning directory: C:\Windows\system32\drivers...

Done!

Drive 0

Scanning MBR on drive 0...

Inspecting partition table:

MBR Signature: 55AA

Disk Signature: 4A1E3F57

Partition information:

Partition 0 type is Other (0xde)

Partition is NOT ACTIVE.

Partition starts at LBA: 63 Numsec = 80262

Partition 1 type is Primary (0x7)

Partition is ACTIVE.

Partition starts at LBA: 81920 Numsec = 32800768

Partition file system is NTFS

Partition is bootable

Partition 2 type is Primary (0x7)

Partition is NOT ACTIVE.

Partition starts at LBA: 32882688 Numsec = 943859760

Partition 3 type is Empty (0x0)

Partition is NOT ACTIVE.

Partition starts at LBA: 0 Numsec = 0

Disk Size: 500107862016 bytes

Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)...

Done!

Performing system, memory and registry scan...

Done!

Scan finished

=======================================

Link to post
Share on other sites

Thank you - I ran the Windows Fix from the link provided. It ran through its process and said it corrected the problem. I still cannot do windows updates and get the same error when I try. It alwasy errors at the check for updates part of the process - so it doesn't even provide a list of available updates.

Link to post
Share on other sites

OK, I tried this and Windows Update doesn't do anything when I click on it from the programs menu - nothing at all. So I tired to navigate there in IE and when I get to the windows upodate page it just tells me how to start windows updates from the program menu if it doesn't start automatically in the browser (which it does not start in the browser either).

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.