Jump to content

Recommended Posts

hi,

My computer has been infected mostly. My Quickheal was disabled and the database got corrupted. So i was asked to uninstall and reinstall it. But Quickheal wouldnt install. So i tried downloading Malwarebytes and running. I successfully started the the quick scan. But then the scan stops after 3-4 seconds and Malwarebytes closed down. When i try reopening it I get the following error.

"Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

Please help me. I am using Windows 7 Ultimate edition.

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

  • Download the file TDSSKiller.zip and extract it into a folder on the infected PC.
  • Execute the file TDSSKiller.exe by double-clicking on it.
  • Wait for the scan and disinfection process to be over.
  • When its work is over, the utility prompts for a reboot to complete the disinfection.

By default, the utility outputs runtime log into the system disk root directory (the disk where the operating system is installed, C:\ as a rule).

The log is like UtilityName.Version_Date_Time_log.txt.

for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt.

Please post that log here.

Next, download DDS by sUBs and save it to your Desktop.

Double-click on the DDS icon and let the scan run. When it has run two logs will be produced, please post only DDS.txt directly into your reply.

-screen317

Link to post
Share on other sites

Hey thanks for the reply.. i just put on my laptop. And i figured now my wireless lan and ethernet driver is also having a problem. I was not able to access the internet. It showed me Limited Access. But i managed to download nd run the two files frm another PC. Below is the LOG

TDSSKiller.2.5.22.0_13.09.2011_20.14.15_log

2011/09/13 20:14:15.0664 2556 TDSS rootkit removing tool 2.5.22.0 Sep 13 2011 15:55:17

2011/09/13 20:14:15.0716 2556 ================================================================================

2011/09/13 20:14:15.0716 2556 SystemInfo:

2011/09/13 20:14:15.0716 2556

2011/09/13 20:14:15.0716 2556 OS Version: 6.1.7600 ServicePack: 0.0

2011/09/13 20:14:15.0717 2556 Product type: Workstation

2011/09/13 20:14:15.0717 2556 ComputerName: PRATIK-PC

2011/09/13 20:14:15.0717 2556 UserName: PRATIK

2011/09/13 20:14:15.0717 2556 Windows directory: C:\Windows

2011/09/13 20:14:15.0717 2556 System windows directory: C:\Windows

2011/09/13 20:14:15.0717 2556 Processor architecture: Intel x86

2011/09/13 20:14:15.0717 2556 Number of processors: 2

2011/09/13 20:14:15.0717 2556 Page size: 0x1000

2011/09/13 20:14:15.0717 2556 Boot type: Normal boot

2011/09/13 20:14:15.0717 2556 ================================================================================

2011/09/13 20:14:19.0928 2556 Initialize success

2011/09/13 20:14:22.0815 2840 ================================================================================

2011/09/13 20:14:22.0815 2840 Scan started

2011/09/13 20:14:22.0815 2840 Mode: Manual;

2011/09/13 20:14:22.0815 2840 ================================================================================

2011/09/13 20:14:23.0541 2840 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys

2011/09/13 20:14:23.0613 2840 18942b84 (8f2bb1827cac01aee6a16e30a1260199) C:\Windows\2217448472:3882603643.exe

2011/09/13 20:14:23.0614 2840 Suspicious file (Hidden): C:\Windows\2217448472:3882603643.exe. md5: 8f2bb1827cac01aee6a16e30a1260199

2011/09/13 20:14:23.0623 2840 18942b84 - detected HiddenFile.Multi.Generic (1)

2011/09/13 20:14:23.0669 2840 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys

2011/09/13 20:14:23.0796 2840 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys

2011/09/13 20:14:23.0883 2840 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys

2011/09/13 20:14:24.0048 2840 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys

2011/09/13 20:14:24.0098 2840 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys

2011/09/13 20:14:24.0133 2840 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys

2011/09/13 20:14:24.0199 2840 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys

2011/09/13 20:14:24.0241 2840 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys

2011/09/13 20:14:24.0361 2840 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys

2011/09/13 20:14:24.0417 2840 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys

2011/09/13 20:14:24.0441 2840 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys

2011/09/13 20:14:24.0467 2840 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys

2011/09/13 20:14:24.0526 2840 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys

2011/09/13 20:14:24.0629 2840 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys

2011/09/13 20:14:24.0675 2840 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys

2011/09/13 20:14:24.0708 2840 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys

2011/09/13 20:14:24.0740 2840 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys

2011/09/13 20:14:24.0807 2840 ApfiltrService (7c2f57bce81fa74933f0e1c84a97c9db) C:\Windows\system32\DRIVERS\Apfiltr.sys

2011/09/13 20:14:24.0863 2840 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys

2011/09/13 20:14:25.0015 2840 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys

2011/09/13 20:14:25.0044 2840 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys

2011/09/13 20:14:25.0084 2840 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys

2011/09/13 20:14:25.0117 2840 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys

2011/09/13 20:14:25.0184 2840 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys

2011/09/13 20:14:25.0318 2840 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys

2011/09/13 20:14:25.0403 2840 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys

2011/09/13 20:14:25.0540 2840 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys

2011/09/13 20:14:25.0574 2840 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys

2011/09/13 20:14:25.0598 2840 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys

2011/09/13 20:14:25.0636 2840 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys

2011/09/13 20:14:25.0680 2840 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys

2011/09/13 20:14:25.0707 2840 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys

2011/09/13 20:14:25.0731 2840 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys

2011/09/13 20:14:25.0773 2840 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys

2011/09/13 20:14:25.0796 2840 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys

2011/09/13 20:14:25.0851 2840 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys

2011/09/13 20:14:25.0964 2840 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys

2011/09/13 20:14:26.0035 2840 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys

2011/09/13 20:14:26.0099 2840 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys

2011/09/13 20:14:26.0236 2840 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys

2011/09/13 20:14:26.0264 2840 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys

2011/09/13 20:14:26.0315 2840 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys

2011/09/13 20:14:26.0367 2840 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys

2011/09/13 20:14:26.0399 2840 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys

2011/09/13 20:14:26.0449 2840 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys

2011/09/13 20:14:26.0604 2840 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys

2011/09/13 20:14:26.0693 2840 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys

2011/09/13 20:14:26.0734 2840 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys

2011/09/13 20:14:26.0787 2840 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys

2011/09/13 20:14:26.0955 2840 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys

2011/09/13 20:14:27.0027 2840 DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\Windows\System32\drivers\dxgkrnl.sys

2011/09/13 20:14:27.0221 2840 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys

2011/09/13 20:14:27.0442 2840 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys

2011/09/13 20:14:27.0531 2840 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys

2011/09/13 20:14:27.0706 2840 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys

2011/09/13 20:14:27.0742 2840 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys

2011/09/13 20:14:27.0789 2840 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys

2011/09/13 20:14:27.0916 2840 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys

2011/09/13 20:14:27.0959 2840 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys

2011/09/13 20:14:28.0026 2840 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys

2011/09/13 20:14:28.0086 2840 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys

2011/09/13 20:14:28.0212 2840 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys

2011/09/13 20:14:28.0248 2840 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys

2011/09/13 20:14:28.0304 2840 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys

2011/09/13 20:14:28.0364 2840 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys

2011/09/13 20:14:28.0495 2840 ggc (e33fe2b78431f69edec0be578942418e) C:\Windows\system32\DRIVERS\ggc.sys

2011/09/13 20:14:28.0563 2840 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys

2011/09/13 20:14:28.0651 2840 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys

2011/09/13 20:14:28.0757 2840 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys

2011/09/13 20:14:28.0803 2840 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys

2011/09/13 20:14:28.0832 2840 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys

2011/09/13 20:14:28.0864 2840 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys

2011/09/13 20:14:28.0909 2840 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys

2011/09/13 20:14:28.0971 2840 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys

2011/09/13 20:14:29.0123 2840 HSF_DPV (53229dcf431d76434816cd29251168a0) C:\Windows\system32\DRIVERS\HSX_DPV.sys

2011/09/13 20:14:29.0200 2840 HSXHWAZL (31f949d452201f2f0af0c88d7db512cd) C:\Windows\system32\DRIVERS\HSXHWAZL.sys

2011/09/13 20:14:29.0330 2840 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys

2011/09/13 20:14:29.0363 2840 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys

2011/09/13 20:14:29.0416 2840 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys

2011/09/13 20:14:29.0481 2840 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys

2011/09/13 20:14:29.0778 2840 igfx (ad626f6964f4d364d226c39e06872dd3) C:\Windows\system32\DRIVERS\igdkmd32.sys

2011/09/13 20:14:30.0080 2840 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys

2011/09/13 20:14:30.0126 2840 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys

2011/09/13 20:14:30.0168 2840 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys

2011/09/13 20:14:30.0220 2840 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys

2011/09/13 20:14:30.0253 2840 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys

2011/09/13 20:14:30.0280 2840 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys

2011/09/13 20:14:30.0309 2840 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys

2011/09/13 20:14:30.0369 2840 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys

2011/09/13 20:14:30.0460 2840 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys

2011/09/13 20:14:30.0506 2840 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys

2011/09/13 20:14:30.0566 2840 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys

2011/09/13 20:14:30.0604 2840 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys

2011/09/13 20:14:30.0649 2840 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys

2011/09/13 20:14:30.0787 2840 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys

2011/09/13 20:14:30.0857 2840 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys

2011/09/13 20:14:30.0883 2840 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys

2011/09/13 20:14:30.0911 2840 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys

2011/09/13 20:14:30.0956 2840 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys

2011/09/13 20:14:31.0004 2840 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys

2011/09/13 20:14:31.0146 2840 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\Windows\system32\drivers\mbam.sys

2011/09/13 20:14:31.0211 2840 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys

2011/09/13 20:14:31.0260 2840 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys

2011/09/13 20:14:31.0295 2840 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys

2011/09/13 20:14:31.0388 2840 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys

2011/09/13 20:14:31.0428 2840 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys

2011/09/13 20:14:31.0464 2840 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys

2011/09/13 20:14:31.0510 2840 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys

2011/09/13 20:14:31.0557 2840 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys

2011/09/13 20:14:31.0582 2840 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys

2011/09/13 20:14:31.0614 2840 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys

2011/09/13 20:14:31.0718 2840 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys

2011/09/13 20:14:31.0764 2840 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys

2011/09/13 20:14:31.0814 2840 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys

2011/09/13 20:14:31.0856 2840 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys

2011/09/13 20:14:31.0887 2840 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys

2011/09/13 20:14:31.0919 2840 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys

2011/09/13 20:14:31.0955 2840 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys

2011/09/13 20:14:31.0989 2840 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys

2011/09/13 20:14:32.0067 2840 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys

2011/09/13 20:14:32.0157 2840 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys

2011/09/13 20:14:32.0198 2840 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys

2011/09/13 20:14:32.0231 2840 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys

2011/09/13 20:14:32.0269 2840 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys

2011/09/13 20:14:32.0356 2840 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys

2011/09/13 20:14:32.0401 2840 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys

2011/09/13 20:14:32.0424 2840 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys

2011/09/13 20:14:32.0455 2840 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys

2011/09/13 20:14:32.0545 2840 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys

2011/09/13 20:14:32.0635 2840 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys

2011/09/13 20:14:32.0770 2840 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys

2011/09/13 20:14:32.0915 2840 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys

2011/09/13 20:14:32.0961 2840 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys

2011/09/13 20:14:33.0012 2840 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys

2011/09/13 20:14:33.0043 2840 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys

2011/09/13 20:14:33.0088 2840 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys

2011/09/13 20:14:33.0140 2840 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys

2011/09/13 20:14:33.0361 2840 NETw3v32 (acc6170d80c69e50145b370023b64ed3) C:\Windows\system32\DRIVERS\NETw3v32.sys

2011/09/13 20:14:33.0673 2840 netw5v32 (83f310bf50985f2a52121f2614787c38) C:\Windows\system32\DRIVERS\netw5v32.sys

2011/09/13 20:14:33.0947 2840 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys

2011/09/13 20:14:33.0987 2840 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys

2011/09/13 20:14:34.0025 2840 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys

2011/09/13 20:14:34.0105 2840 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys

2011/09/13 20:14:34.0191 2840 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys

2011/09/13 20:14:34.0279 2840 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys

2011/09/13 20:14:34.0312 2840 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys

2011/09/13 20:14:34.0351 2840 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys

2011/09/13 20:14:34.0382 2840 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys

2011/09/13 20:14:34.0456 2840 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys

2011/09/13 20:14:34.0519 2840 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys

2011/09/13 20:14:34.0582 2840 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys

2011/09/13 20:14:34.0646 2840 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys

2011/09/13 20:14:34.0678 2840 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys

2011/09/13 20:14:34.0716 2840 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys

2011/09/13 20:14:34.0748 2840 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys

2011/09/13 20:14:34.0800 2840 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys

2011/09/13 20:14:34.0978 2840 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys

2011/09/13 20:14:35.0039 2840 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys

2011/09/13 20:14:35.0112 2840 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys

2011/09/13 20:14:35.0240 2840 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys

2011/09/13 20:14:35.0336 2840 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys

2011/09/13 20:14:35.0382 2840 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys

2011/09/13 20:14:35.0451 2840 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys

2011/09/13 20:14:35.0517 2840 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys

2011/09/13 20:14:35.0564 2840 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys

2011/09/13 20:14:35.0663 2840 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys

2011/09/13 20:14:35.0733 2840 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys

2011/09/13 20:14:35.0777 2840 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys

2011/09/13 20:14:35.0803 2840 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys

2011/09/13 20:14:35.0840 2840 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys

2011/09/13 20:14:35.0878 2840 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys

2011/09/13 20:14:35.0962 2840 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys

2011/09/13 20:14:36.0037 2840 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys

2011/09/13 20:14:36.0065 2840 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys

2011/09/13 20:14:36.0124 2840 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys

2011/09/13 20:14:36.0210 2840 RimUsb (616eac1b0e48b236a5a9b8ae07fdb81c) C:\Windows\system32\Drivers\RimUsb.sys

2011/09/13 20:14:36.0304 2840 RimVSerPort (2c4fb2e9f039287767c384e46ee91030) C:\Windows\system32\DRIVERS\RimSerial.sys

2011/09/13 20:14:36.0432 2840 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys

2011/09/13 20:14:36.0546 2840 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys

2011/09/13 20:14:36.0591 2840 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys

2011/09/13 20:14:36.0703 2840 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys

2011/09/13 20:14:36.0745 2840 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys

2011/09/13 20:14:36.0804 2840 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys

2011/09/13 20:14:36.0873 2840 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys

2011/09/13 20:14:36.0934 2840 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys

2011/09/13 20:14:36.0958 2840 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys

2011/09/13 20:14:37.0007 2840 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys

2011/09/13 20:14:37.0035 2840 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys

2011/09/13 20:14:37.0060 2840 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys

2011/09/13 20:14:37.0086 2840 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys

2011/09/13 20:14:37.0139 2840 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys

2011/09/13 20:14:37.0232 2840 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys

2011/09/13 20:14:37.0263 2840 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys

2011/09/13 20:14:37.0313 2840 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys

2011/09/13 20:14:37.0403 2840 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys

2011/09/13 20:14:37.0485 2840 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys

2011/09/13 20:14:37.0564 2840 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys

2011/09/13 20:14:37.0638 2840 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS

2011/09/13 20:14:37.0754 2840 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS

2011/09/13 20:14:37.0884 2840 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS

2011/09/13 20:14:37.0992 2840 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys

2011/09/13 20:14:38.0087 2840 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys

2011/09/13 20:14:38.0145 2840 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys

2011/09/13 20:14:38.0225 2840 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys

2011/09/13 20:14:38.0268 2840 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys

2011/09/13 20:14:38.0377 2840 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys

2011/09/13 20:14:38.0506 2840 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys

2011/09/13 20:14:38.0591 2840 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys

2011/09/13 20:14:38.0639 2840 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys

2011/09/13 20:14:38.0661 2840 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys

2011/09/13 20:14:38.0720 2840 tdx (cd49c65a0518aeb71634ff40dd40e309) C:\Windows\system32\DRIVERS\tdx.sys

2011/09/13 20:14:38.0721 2840 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tdx.sys. Real md5: cd49c65a0518aeb71634ff40dd40e309, Fake md5: cb39e896a2a83702d1737bfd402b3542

2011/09/13 20:14:38.0728 2840 tdx - detected Rootkit.Win32.ZAccess.e (0)

2011/09/13 20:14:38.0773 2840 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys

2011/09/13 20:14:38.0885 2840 ti21sony (7c7445b4c2bd46c56abb3499da52b75c) C:\Windows\system32\drivers\ti21sony.sys

2011/09/13 20:14:38.0971 2840 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys

2011/09/13 20:14:39.0022 2840 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys

2011/09/13 20:14:39.0065 2840 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys

2011/09/13 20:14:39.0137 2840 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys

2011/09/13 20:14:39.0223 2840 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys

2011/09/13 20:14:39.0288 2840 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys

2011/09/13 20:14:39.0317 2840 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys

2011/09/13 20:14:39.0370 2840 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys

2011/09/13 20:14:39.0411 2840 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys

2011/09/13 20:14:39.0439 2840 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys

2011/09/13 20:14:39.0498 2840 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys

2011/09/13 20:14:39.0559 2840 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys

2011/09/13 20:14:39.0595 2840 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys

2011/09/13 20:14:39.0640 2840 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS

2011/09/13 20:14:39.0693 2840 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys

2011/09/13 20:14:39.0742 2840 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys

2011/09/13 20:14:39.0782 2840 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys

2011/09/13 20:14:39.0806 2840 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys

2011/09/13 20:14:39.0838 2840 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys

2011/09/13 20:14:39.0926 2840 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys

2011/09/13 20:14:39.0950 2840 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys

2011/09/13 20:14:39.0979 2840 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys

2011/09/13 20:14:40.0024 2840 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys

2011/09/13 20:14:40.0055 2840 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys

2011/09/13 20:14:40.0091 2840 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys

2011/09/13 20:14:40.0157 2840 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys

2011/09/13 20:14:40.0211 2840 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys

2011/09/13 20:14:40.0301 2840 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys

2011/09/13 20:14:40.0344 2840 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys

2011/09/13 20:14:40.0400 2840 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys

2011/09/13 20:14:40.0452 2840 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys

2011/09/13 20:14:40.0471 2840 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys

2011/09/13 20:14:40.0561 2840 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys

2011/09/13 20:14:40.0629 2840 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys

2011/09/13 20:14:40.0718 2840 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys

2011/09/13 20:14:40.0839 2840 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys

2011/09/13 20:14:40.0884 2840 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys

2011/09/13 20:14:40.0962 2840 winachsf (6d2350bb6e77e800fc4be4e5b7a2e89a) C:\Windows\system32\DRIVERS\HSX_CNXT.sys

2011/09/13 20:14:41.0165 2840 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys

2011/09/13 20:14:41.0237 2840 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys

2011/09/13 20:14:41.0340 2840 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys

2011/09/13 20:14:41.0375 2840 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys

2011/09/13 20:14:41.0500 2840 XAudio (5a7ff9a18ff6d7e0527fe3abf9204ef8) C:\Windows\system32\DRIVERS\xaudio.sys

2011/09/13 20:14:41.0589 2840 yukonw7 (b07c5b7efdf936ff93d4f540938725be) C:\Windows\system32\DRIVERS\yk62x86.sys

2011/09/13 20:14:41.0641 2840 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0

2011/09/13 20:14:41.0658 2840 Boot (0x1200) (913f19f2c20100bf70a313cc7f0bfe3c) \Device\Harddisk0\DR0\Partition0

2011/09/13 20:14:41.0689 2840 Boot (0x1200) (c7424fc38810989f91aeb5f2503c659a) \Device\Harddisk0\DR0\Partition1

2011/09/13 20:14:41.0718 2840 Boot (0x1200) (471e9eb229517a583729d7ec0146c78e) \Device\Harddisk0\DR0\Partition2

2011/09/13 20:14:41.0725 2840 ================================================================================

2011/09/13 20:14:41.0725 2840 Scan finished

2011/09/13 20:14:41.0726 2840 ================================================================================

2011/09/13 20:14:41.0744 2416 Detected object count: 2

2011/09/13 20:14:41.0744 2416 Actual detected object count: 2

2011/09/13 20:14:53.0628 2416 HiddenFile.Multi.Generic(18942b84) - User select action: Skip

2011/09/13 20:14:53.0765 2416 tdx (cd49c65a0518aeb71634ff40dd40e309) C:\Windows\system32\DRIVERS\tdx.sys

2011/09/13 20:14:53.0767 2416 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tdx.sys. Real md5: cd49c65a0518aeb71634ff40dd40e309, Fake md5: cb39e896a2a83702d1737bfd402b3542

2011/09/13 20:14:53.0884 2416 Backup copy found, using it..

2011/09/13 20:14:53.0896 2416 C:\Windows\system32\DRIVERS\tdx.sys - will be cured after reboot

2011/09/13 20:14:53.0896 2416 Rootkit.Win32.ZAccess.e(tdx) - User select action: Cure

2011/09/13 20:15:04.0840 3368 Deinitialize success

______________________________________________________________________________________

DDS

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26

Run by PRATIK at 20:18:16 on 2011-09-13

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2038.1422 [GMT 5.5:30]

.

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Windows\2217448472:3882603643.exe

C:\Program Files\Apoint\Apoint.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Users\PRATIK\AppData\Local\Google\Update\GoogleUpdate.exe

C:\Program Files\DAP\DAP.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\sppsvc.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Apoint\ApMsgFwd.exe

C:\Program Files\Apoint\Apntex.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL

uRun: [Google Update] "c:\users\pratik\appdata\local\google\update\GoogleUpdate.exe" /c

uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

uRun: [googletalk] c:\users\pratik\appdata\roaming\google\google talk\googletalk.exe /autostart

mRun: [Apoint] c:\program files\apoint\Apoint.exe

mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm

IE: &Download with &DAP - c:\program files\dap\dapextie.htm

IE: Download &all with DAP - c:\program files\dap\dapextie2.htm

IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll

LSP: mswsock.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab

TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 124.124.5.140

TCP: Interfaces\{4902FC85-2511-4E5A-BBE0-20B221CE386A} : DhcpNameServer = 208.67.220.220 208.67.222.222 124.124.5.140

TCP: Interfaces\{4902FC85-2511-4E5A-BBE0-20B221CE386A}\3557E64656B6 : DhcpNameServer = 192.168.1.1

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll

Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\pratik\appdata\roaming\mozilla\firefox\profiles\u2l2uc1u.default\

FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll

FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll

FF - plugin: c:\users\pratik\appdata\local\google\update\1.3.21.65\npGoogleUpdate3.dll

.

============= SERVICES / DRIVERS ===============

.

R1 ggc;ggc;c:\windows\system32\drivers\ggc.sys [2011-8-22 46672]

R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2011-8-13 227328]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-14 311296]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]

S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-10 366640]

S2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-8-13 2222376]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-10 22712]

S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2011-8-13 4232704]

S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]

S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360]

S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]

S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504]

S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]

.

=============== Created Last 30 ================

.

2011-09-13 14:46:09 50112 --sha-w- c:\windows\system32\c_80724.nl_

2011-09-13 14:31:39 -------- d-----w- c:\users\pratik\appdata\local\Diagnostics

2011-09-13 14:26:41 -------- d-----w- c:\users\pratik\appdata\local\ElevatedDiagnostics

2011-09-10 16:30:26 -------- d-----w- c:\users\pratik\appdata\roaming\Malwarebytes

2011-09-10 16:23:39 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-09-10 16:23:38 -------- d-----w- c:\programdata\Malwarebytes

2011-09-10 16:23:36 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-10 16:23:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-08-29 19:35:22 -------- d-----w- c:\program files\Innovative Solutions

2011-08-29 19:19:18 4194304 ----a-w- c:\windows\system32\xadqgnnk.dll

2011-08-29 19:14:41 -------- d-----w- c:\windows\pss

2011-08-29 19:08:33 -------- d-----w- c:\program files\e-Campaign 8

2011-08-29 19:01:40 -------- d-----w- c:\users\pratik\appdata\roaming\e-Campaign

2011-08-29 19:01:40 -------- d-----w- c:\users\pratik\appdata\local\e-Campaign

2011-08-29 18:10:19 -------- d-----w- c:\program files\Skype

2011-08-29 18:05:14 -------- d-----w- c:\users\pratik\appdata\roaming\Aella Mass Emailer

2011-08-29 18:05:09 -------- d-----w- c:\users\pratik\appdata\roaming\ctpo

2011-08-29 17:46:54 -------- d-----w- c:\windows\system32\appmgmt

2011-08-29 17:46:50 65536 ----a-r- c:\users\pratik\appdata\roaming\microsoft\installer\{0a311c1b-7571-40cf-a560-8c6810fd991e}\NewShortcut2_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:46:50 65536 ----a-r- c:\users\pratik\appdata\roaming\microsoft\installer\{0a311c1b-7571-40cf-a560-8c6810fd991e}\NewShortcut1_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:44:29 -------- d-----w- C:\New folder (2)

2011-08-29 17:41:59 -------- d-----w- c:\users\pratik\.spamassassin

2011-08-29 17:41:59 -------- d-----w- c:\users\pratik\.razor

2011-08-29 17:30:44 -------- d-----w- c:\users\pratik\appdata\roaming\SendBlaster2

2011-08-29 17:28:58 -------- d-----w- c:\program files\SendBlaster

2011-08-29 15:39:28 -------- d-----w- c:\program files\Youtube Downloader

2011-08-29 13:46:49 -------- d-----w- c:\users\pratik\appdata\roaming\Helios

2011-08-26 18:14:06 -------- d-----w- c:\program files\Macromedia

2011-08-26 18:14:06 -------- d-----w- c:\program files\common files\Macromedia

2011-08-26 18:13:46 180224 ------w- c:\program files\common files\installshield\driver\10\intel 32\iGdiCnv.dll

2011-08-26 18:13:45 409600 ------w- c:\program files\common files\installshield\driver\10\intel 32\ISRT.dll

2011-08-26 18:13:45 32768 ------w- c:\program files\common files\installshield\driver\10\intel 32\objpscnv.dll

2011-08-26 18:13:45 266240 ------w- c:\program files\common files\installshield\driver\10\intel 32\IScrCnv.dll

2011-08-26 18:13:45 172032 ------w- c:\program files\common files\installshield\driver\10\intel 32\IUserCnv.dll

2011-08-26 18:13:42 761856 ------w- c:\program files\common files\installshield\driver\10\intel 32\IDriver.exe

2011-08-26 18:13:42 540772 ------w- c:\program files\common files\installshield\driver\10\intel 32\_ISRES1033.dll

2011-08-26 18:13:36 -------- d-----w- c:\windows\Downloaded Installations

2011-08-26 14:16:50 -------- d-----w- C:\Picture

2011-08-22 12:43:01 -------- d-----w- C:\crm

2011-08-22 12:39:00 -------- d-----w- c:\users\pratik\Library

2011-08-22 12:39:00 -------- d-----w- c:\users\pratik\appdata\roaming\com.adobe.ExMan

2011-08-22 08:43:16 -------- d-----w- c:\windows\system32\gprodat

2011-08-22 08:43:09 46672 ----a-w- c:\windows\system32\drivers\ggc.sys

2011-08-20 09:57:38 3907640 ----a-w- c:\windows\system32\gsdll32.dll

2011-08-20 09:57:37 1712128 ----a-w- c:\windows\system32\gdiplus.dll

2011-08-20 09:57:35 -------- d-----w- c:\windows\system32\PS

2011-08-20 09:41:09 -------- d-----w- c:\users\pratik\appdata\roaming\AutoDWG

2011-08-20 09:36:38 -------- d-----w- c:\windows\system32\shxfont

2011-08-20 09:36:37 -------- d-----w- c:\program files\AutoDWG

2011-08-20 09:36:31 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll

2011-08-20 08:48:49 229888 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HP1006S.DLL

2011-08-19 19:05:03 -------- d-----w- c:\program files\Jasc Software Inc

2011-08-19 19:03:53 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll

2011-08-19 19:03:53 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll

2011-08-19 19:03:52 98304 ------w- c:\program files\common files\installshield\engine\6\intel 32\knlwrap.exe

2011-08-19 19:03:52 36864 ------w- c:\program files\common files\installshield\engine\6\intel 32\msihook.dll

2011-08-19 19:03:51 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe

2011-08-19 19:03:51 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll

2011-08-19 19:03:49 102400 ------w- c:\program files\common files\installshield\engine\6\intel 32\scpthdlr.dll

2011-08-19 18:42:25 -------- d-----w- C:\PowerPoint_Pro_Templates

2011-08-16 17:41:17 -------- d-----w- c:\users\pratik\appdata\local\BBScreenies

2011-08-16 07:56:18 -------- d-----w- C:\Certis

2011-08-15 16:37:10 -------- d-----w- c:\program files\Research In Motion Limited

2011-08-15 16:16:51 -------- d-----w- c:\program files\BBSAK

2011-08-15 14:56:45 -------- d-----w- c:\users\pratik\appdata\local\Research In Motion

2011-08-15 14:56:43 -------- d-----w- c:\users\pratik\appdata\roaming\Research In Motion

2011-08-15 14:55:35 -------- d-----w- c:\programdata\Research In Motion

2011-08-15 14:54:55 -------- d-----w- c:\program files\Research In Motion

2011-08-15 14:15:07 27136 ----a-w- c:\windows\system32\drivers\RimSerial.sys

2011-08-15 14:14:29 -------- d-----w- c:\program files\common files\Research In Motion

2011-08-15 13:41:43 -------- d-----w- C:\temp

2011-08-15 13:37:11 -------- d-----w- c:\programdata\SpeedBit

2011-08-15 13:37:04 172032 ----a-w- c:\windows\system32\AniGIF.ocx

2011-08-15 13:36:56 -------- d-----w- c:\program files\DAP

2011-08-15 10:41:49 -------- d-----w- c:\program files\BitTorrent

2011-08-15 10:41:28 -------- d-----w- c:\users\pratik\appdata\roaming\BitTorrent

2011-08-15 10:38:50 -------- d-----w- c:\users\pratik\appdata\roaming\Xilisoft

2011-08-15 08:27:09 -------- d-----w- C:\New folder

2011-08-14 16:53:10 81920 ----a-w- c:\windows\system32\cpwmon2k.dll

2011-08-14 16:53:10 49152 ----a-w- c:\windows\system32\uninscpw.exe

2011-08-14 16:53:10 225280 ----a-w- c:\windows\system32\cpwsave.exe

2011-08-14 16:53:08 -------- d-----w- c:\program files\Acro Software

2011-08-14 16:52:49 -------- d-----w- c:\program files\GPLGS

.

==================== Find3M ====================

.

2011-09-13 14:45:48 74240 ----a-w- c:\windows\system32\drivers\tdx.sys

2009-07-31 19:36:55 32256 ----a-w- c:\program files\common files\alq.exe

.

============= FINISH: 20:19:15.25 ===============

Link to post
Share on other sites

Hi,

I followed instructions for ComboFix. But i am still not able to connect to the internet from my laptop. The following are the two logs

________________________________________________________________________________________________________________________

ComboFix

ComboFix 11-09-15.05 - PRATIK 09/16/2011 20:50:06.1.2 - x86

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2038.1350 [GMT 5.5:30]

Running from: c:\users\PRATIK\Desktop\ComboFix.exe

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\PRATIK\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart

c:\windows\$NtUninstallKB52463$

c:\windows\$NtUninstallKB52463$\412363652\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}

c:\windows\$NtUninstallKB52463$\412363652\L\xadqgnnk

c:\windows\$NtUninstallKB52463$\875891755

c:\windows\system32\c_80724.nls

.

Infected copy of c:\windows\system32\drivers\dfsc.sys was found and disinfected

Restored copy from - The cat found it :)

Infected copy of c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe was found and disinfected

Restored copy from - c:\combofix\HarddiskVolumeShadowCopy6_!Program Files!Common Files!Adobe!ARM!1.0!armsvc.exe

.

Infected copy of c:\program files\TeamViewer\Version6\TeamViewer_Service.exe was found and disinfected

Restored copy from - c:\combofix\HarddiskVolumeShadowCopy6_!Program Files!TeamViewer!Version6!TeamViewer_Service.exe

.

Infected copy of c:\windows\system32\DRIVERS\xaudio.exe was found and disinfected

Restored copy from - c:\windows\System32\DriverStore\FileRepository\snszirxz.inf_x86_neutral_136588d215875ede\XAudio.exe

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Service_18942b84

.

.

((((((((((((((((((((((((( Files Created from 2011-08-16 to 2011-09-16 )))))))))))))))))))))))))))))))

.

.

2011-09-16 15:29 . 2011-09-16 15:31 -------- d-----w- c:\users\PRATIK\AppData\Local\temp

2011-09-16 15:29 . 2011-09-16 15:29 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-09-16 15:17 . 2009-07-13 23:14 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys

2011-09-13 14:46 . 2011-09-13 14:46 50112 --sha-w- c:\windows\system32\c_80724.nl_

2011-09-13 14:31 . 2011-09-13 14:31 -------- d-----w- c:\users\PRATIK\AppData\Local\Diagnostics

2011-09-13 14:26 . 2011-09-13 14:29 -------- d-----w- c:\users\PRATIK\AppData\Local\ElevatedDiagnostics

2011-09-10 16:30 . 2011-09-10 16:30 -------- d-----w- c:\users\PRATIK\AppData\Roaming\Malwarebytes

2011-09-10 16:23 . 2011-07-06 14:22 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-09-10 16:23 . 2011-09-10 16:23 -------- d-----w- c:\programdata\Malwarebytes

2011-09-10 16:23 . 2011-07-06 14:22 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-10 16:23 . 2011-09-10 16:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-08-29 19:40 . 2011-09-11 05:40 -------- d-----w- c:\users\Administrator

2011-08-29 19:35 . 2011-08-29 19:35 -------- d-----w- c:\program files\Innovative Solutions

2011-08-29 19:19 . 2011-08-29 19:19 4194304 ----a-w- c:\windows\system32\xadqgnnk.dll

2011-08-29 19:08 . 2011-08-29 19:08 -------- d-----w- c:\program files\e-Campaign 8

2011-08-29 19:01 . 2011-08-29 19:17 -------- d-----w- c:\users\PRATIK\AppData\Roaming\e-Campaign

2011-08-29 19:01 . 2011-08-29 19:01 -------- d-----w- c:\users\PRATIK\AppData\Local\e-Campaign

2011-08-29 18:10 . 2011-09-16 15:31 -------- d-----w- c:\users\PRATIK\AppData\Roaming\Skype

2011-08-29 18:10 . 2011-08-29 18:10 -------- d-----w- c:\program files\Skype

2011-08-29 18:10 . 2011-08-29 18:10 -------- d-----w- c:\program files\Common Files\Skype

2011-08-29 18:10 . 2011-08-29 18:10 -------- d-----w- c:\programdata\Skype

2011-08-29 18:05 . 2011-08-29 18:45 -------- d-----w- c:\users\PRATIK\AppData\Roaming\Aella Mass Emailer

2011-08-29 18:05 . 2011-08-29 18:05 -------- d-----w- c:\users\PRATIK\AppData\Roaming\ctpo

2011-08-29 17:46 . 2011-08-29 17:46 65536 ----a-r- c:\users\PRATIK\AppData\Roaming\Microsoft\Installer\{0A311C1B-7571-40CF-A560-8C6810FD991E}\NewShortcut2_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:46 . 2011-08-29 17:46 65536 ----a-r- c:\users\PRATIK\AppData\Roaming\Microsoft\Installer\{0A311C1B-7571-40CF-A560-8C6810FD991E}\NewShortcut1_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:44 . 2011-08-29 19:20 -------- d-----w- C:\New folder (2)

2011-08-29 17:41 . 2011-08-29 17:41 -------- d-----w- c:\users\PRATIK\.spamassassin

2011-08-29 17:41 . 2011-08-29 17:41 -------- d-----w- c:\users\PRATIK\.razor

2011-08-29 17:30 . 2011-08-29 17:31 -------- d-----w- c:\users\PRATIK\AppData\Roaming\SendBlaster2

2011-08-29 17:28 . 2011-08-29 18:57 -------- d-----w- c:\program files\SendBlaster

2011-08-29 15:39 . 2011-08-29 15:39 -------- d-----w- c:\program files\Youtube Downloader

2011-08-29 13:46 . 2011-08-29 13:46 -------- d-----w- c:\users\PRATIK\AppData\Roaming\Helios

2011-08-26 18:14 . 2011-08-26 18:16 -------- d-----w- c:\program files\Common Files\Macromedia

2011-08-26 18:14 . 2011-08-26 18:14 -------- d-----w- c:\program files\Macromedia

2011-08-26 18:13 . 2011-08-26 18:13 180224 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll

2011-08-26 18:13 . 2011-08-26 18:13 409600 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll

2011-08-26 18:13 . 2011-08-26 18:13 32768 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll

2011-08-26 18:13 . 2011-08-26 18:13 266240 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll

2011-08-26 18:13 . 2011-08-26 18:13 172032 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll

2011-08-26 18:13 . 2011-08-26 18:13 761856 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe

2011-08-26 18:13 . 2011-08-26 18:13 540772 ------w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll

2011-08-26 18:13 . 2011-08-26 18:13 -------- d-----w- c:\windows\Downloaded Installations

2011-08-26 14:16 . 2011-08-26 17:27 -------- d-----w- C:\Picture

2011-08-22 12:43 . 2011-08-22 12:49 -------- d-----w- C:\crm

2011-08-22 12:39 . 2011-08-29 14:38 -------- d-----w- c:\users\PRATIK\AppData\Roaming\FileZilla

2011-08-22 12:39 . 2011-08-22 12:39 -------- d-----w- c:\program files\FileZilla FTP Client

2011-08-22 12:39 . 2011-08-22 12:39 -------- d-----w- c:\users\PRATIK\Library

2011-08-22 12:39 . 2011-08-22 12:39 -------- d-----w- c:\users\PRATIK\AppData\Roaming\com.adobe.ExMan

2011-08-22 08:43 . 2011-09-10 16:11 -------- d-----w- c:\windows\system32\gprodat

2011-08-22 08:43 . 2011-03-23 07:24 46672 ----a-w- c:\windows\system32\drivers\ggc.sys

2011-08-20 09:57 . 2002-11-21 16:43 3907640 ----a-w- c:\windows\system32\gsdll32.dll

2011-08-20 09:57 . 2008-05-30 07:16 1712128 ----a-w- c:\windows\system32\gdiplus.dll

2011-08-20 09:57 . 2011-08-20 09:57 -------- d-----w- c:\windows\system32\PS

2011-08-20 09:41 . 2011-08-20 09:41 -------- d-----w- c:\users\PRATIK\AppData\Roaming\AutoDWG

2011-08-20 09:36 . 2011-08-20 09:57 -------- d-----w- c:\windows\system32\shxfont

2011-08-20 09:36 . 2011-08-20 09:36 -------- d-----w- c:\program files\AutoDWG

2011-08-20 09:36 . 2001-09-04 08:48 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll

2011-08-20 08:48 . 2007-09-10 09:42 229888 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HP1006S.DLL

2011-08-19 19:05 . 2011-08-19 19:05 -------- d-----w- c:\program files\Jasc Software Inc

2011-08-19 19:03 . 2001-09-04 08:48 225280 ------w- c:\program files\Common Files\InstallShield\IScript\iscript.dll

2011-08-19 19:03 . 2001-09-04 08:43 32768 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll

2011-08-19 19:03 . 2011-08-19 19:03 98304 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\knlwrap.exe

2011-08-19 19:03 . 2011-08-19 19:03 36864 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\msihook.dll

2011-08-19 19:03 . 2002-07-25 10:37 614532 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe

2011-08-19 19:03 . 2001-09-04 08:44 176128 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll

2011-08-19 19:03 . 2011-08-19 19:03 102400 ------w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\scpthdlr.dll

2011-08-19 18:42 . 2011-08-29 15:24 -------- d-----w- C:\PowerPoint_Pro_Templates

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-09-13 14:45 . 2009-07-13 23:12 74240 ----a-w- c:\windows\system32\drivers\tdx.sys

2011-08-15 13:37 . 2011-08-15 13:37 172032 ----a-w- c:\windows\system32\AniGIF.ocx

2011-07-20 04:14 . 2011-08-12 19:52 6881616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{23D4E454-E037-4244-8E43-A2297A8AB2FA}\mpengine.dll

2009-07-31 19:36 . 2009-07-30 07:00 32256 ----a-w- c:\program files\Common Files\alq.exe

2011-07-08 07:16 . 2011-08-12 20:30 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2010-09-07 3432098]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-01 21898024]

"googletalk"="c:\users\PRATIK\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2011-03-29 118784]

"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]

"RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup

backupExtension=.CommonStartup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Application Layer Gateway]

2009-07-31 19:36 32256 ----a-w- c:\program files\Common Files\alq.exe

.

R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-03-04 4232704]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]

R3 wsnfmp;Network Filter Miniport;c:\windows\system32\DRIVERS\wsnf.sys [x]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]

S1 ggc;ggc;c:\windows\system32\DRIVERS\ggc.sys [2011-03-23 46672]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]

S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]

S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2010-11-30 2222376]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]

S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-11-06 227328]

.

.

Contents of the 'Scheduled Tasks' folder

.

2011-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2599070989-140207698-3940485141-1001Core.job

- c:\users\PRATIK\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-12 20:19]

.

2011-09-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2599070989-140207698-3940485141-1001UA.job

- c:\users\PRATIK\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-12 20:19]

.

2011-09-13 c:\windows\Tasks\Quick Heal AntiMalware Scan.job

- c:\program files\Quick Heal\Quick Heal Internet Security\ASMAIN.EXE [2011-05-23 11:55]

.

2011-09-13 c:\windows\Tasks\Resume Quickup Download.job

- c:\program files\Quick Heal\Quick Heal Internet Security\ACAPPAA.EXE [2011-05-23 11:55]

.

.

------- Supplementary Scan -------

.

IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm

IE: &Download with &DAP - c:\program files\DAP\dapextie.htm

IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105

TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 124.124.5.140

Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll

Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll

DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab

FF - ProfilePath - c:\users\PRATIK\AppData\Roaming\Mozilla\Firefox\Profiles\u2l2uc1u.default\

.

- - - - ORPHANS REMOVED - - - -

.

SafeBoot-01457876.sys

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\taskhost.exe

c:\windows\system32\sppsvc.exe

c:\windows\system32\DRIVERS\xaudio.exe

c:\windows\system32\WUDFHost.exe

c:\windows\system32\conhost.exe

c:\program files\Apoint\ApMsgFwd.exe

c:\program files\Apoint\Apntex.exe

c:\windows\system32\conhost.exe

c:\program files\Windows Media Player\wmpnetwk.exe

.

**************************************************************************

.

Completion time: 2011-09-16 21:04:17 - machine was rebooted

ComboFix-quarantined-files.txt 2011-09-16 15:34

.

Pre-Run: 14,838,431,744 bytes free

Post-Run: 16,269,037,568 bytes free

.

- - End Of File - - 0053BC4E096C58A96E5E3D62BF0BBC6E

___________________________________________________________________________________________________

DDS

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26

Run by PRATIK at 21:10:00 on 2011-09-16

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2038.1298 [GMT 5.5:30]

.

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\sppsvc.exe

C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Apoint\Apoint.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Apoint\ApMsgFwd.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Apoint\Apntex.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\conhost.exe

.

============== Pseudo HJT Report ===============

.

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL

uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

uRun: [googletalk] c:\users\pratik\appdata\roaming\google\google talk\googletalk.exe /autostart

mRun: [Apoint] c:\program files\apoint\Apoint.exe

mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm

IE: &Download with &DAP - c:\program files\dap\dapextie.htm

IE: Download &all with DAP - c:\program files\dap\dapextie2.htm

IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab

TCP: DhcpNameServer = 208.67.220.220 208.67.222.222 124.124.5.140

TCP: Interfaces\{4902FC85-2511-4E5A-BBE0-20B221CE386A} : DhcpNameServer = 208.67.220.220 208.67.222.222 124.124.5.140

TCP: Interfaces\{4902FC85-2511-4E5A-BBE0-20B221CE386A}\3557E64656B6 : DhcpNameServer = 192.168.1.1

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll

Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\users\pratik\appdata\roaming\mozilla\firefox\profiles\u2l2uc1u.default\

FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll

FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll

FF - plugin: c:\users\pratik\appdata\local\google\update\1.3.21.65\npGoogleUpdate3.dll

.

============= SERVICES / DRIVERS ===============

.

R1 ggc;ggc;c:\windows\system32\drivers\ggc.sys [2011-8-22 46672]

R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]

R2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-8-13 2222376]

R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2011-8-13 227328]

S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-10 366640]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-10 22712]

S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2011-8-13 4232704]

S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]

S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360]

S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]

S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504]

S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-14 311296]

.

=============== Created Last 30 ================

.

2011-09-16 15:33:43 -------- d-sh--w- C:\$RECYCLE.BIN

2011-09-16 15:29:13 -------- d-----w- c:\users\pratik\appdata\local\temp

2011-09-16 15:17:40 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys

2011-09-16 15:15:39 98816 ----a-w- c:\windows\sed.exe

2011-09-16 15:15:39 518144 ----a-w- c:\windows\SWREG.exe

2011-09-16 15:15:39 256000 ----a-w- c:\windows\PEV.exe

2011-09-16 15:15:39 208896 ----a-w- c:\windows\MBR.exe

2011-09-16 15:15:34 -------- d-----w- C:\ComboFix

2011-09-13 14:46:09 50112 --sha-w- c:\windows\system32\c_80724.nl_

2011-09-13 14:31:39 -------- d-----w- c:\users\pratik\appdata\local\Diagnostics

2011-09-13 14:26:41 -------- d-----w- c:\users\pratik\appdata\local\ElevatedDiagnostics

2011-09-10 16:30:26 -------- d-----w- c:\users\pratik\appdata\roaming\Malwarebytes

2011-09-10 16:23:39 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-09-10 16:23:38 -------- d-----w- c:\programdata\Malwarebytes

2011-09-10 16:23:36 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-10 16:23:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-08-29 19:35:22 -------- d-----w- c:\program files\Innovative Solutions

2011-08-29 19:19:18 4194304 ----a-w- c:\windows\system32\xadqgnnk.dll

2011-08-29 19:14:41 -------- d-----w- c:\windows\pss

2011-08-29 19:08:33 -------- d-----w- c:\program files\e-Campaign 8

2011-08-29 19:01:40 -------- d-----w- c:\users\pratik\appdata\roaming\e-Campaign

2011-08-29 19:01:40 -------- d-----w- c:\users\pratik\appdata\local\e-Campaign

2011-08-29 18:10:19 -------- d-----w- c:\program files\Skype

2011-08-29 18:05:14 -------- d-----w- c:\users\pratik\appdata\roaming\Aella Mass Emailer

2011-08-29 18:05:09 -------- d-----w- c:\users\pratik\appdata\roaming\ctpo

2011-08-29 17:46:54 -------- d-----w- c:\windows\system32\appmgmt

2011-08-29 17:46:50 65536 ----a-r- c:\users\pratik\appdata\roaming\microsoft\installer\{0a311c1b-7571-40cf-a560-8c6810fd991e}\NewShortcut2_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:46:50 65536 ----a-r- c:\users\pratik\appdata\roaming\microsoft\installer\{0a311c1b-7571-40cf-a560-8c6810fd991e}\NewShortcut1_87081C521AB9485382449D7B131ECAFC.exe

2011-08-29 17:44:29 -------- d-----w- C:\New folder (2)

2011-08-29 17:41:59 -------- d-----w- c:\users\pratik\.spamassassin

2011-08-29 17:41:59 -------- d-----w- c:\users\pratik\.razor

2011-08-29 17:30:44 -------- d-----w- c:\users\pratik\appdata\roaming\SendBlaster2

2011-08-29 17:28:58 -------- d-----w- c:\program files\SendBlaster

2011-08-29 15:39:28 -------- d-----w- c:\program files\Youtube Downloader

2011-08-29 13:46:49 -------- d-----w- c:\users\pratik\appdata\roaming\Helios

2011-08-26 18:14:06 -------- d-----w- c:\program files\Macromedia

2011-08-26 18:14:06 -------- d-----w- c:\program files\common files\Macromedia

2011-08-26 18:13:46 180224 ------w- c:\program files\common files\installshield\driver\10\intel 32\iGdiCnv.dll

2011-08-26 18:13:45 409600 ------w- c:\program files\common files\installshield\driver\10\intel 32\ISRT.dll

2011-08-26 18:13:45 32768 ------w- c:\program files\common files\installshield\driver\10\intel 32\objpscnv.dll

2011-08-26 18:13:45 266240 ------w- c:\program files\common files\installshield\driver\10\intel 32\IScrCnv.dll

2011-08-26 18:13:45 172032 ------w- c:\program files\common files\installshield\driver\10\intel 32\IUserCnv.dll

2011-08-26 18:13:42 761856 ------w- c:\program files\common files\installshield\driver\10\intel 32\IDriver.exe

2011-08-26 18:13:42 540772 ------w- c:\program files\common files\installshield\driver\10\intel 32\_ISRES1033.dll

2011-08-26 18:13:36 -------- d-----w- c:\windows\Downloaded Installations

2011-08-26 14:16:50 -------- d-----w- C:\Picture

2011-08-22 12:43:01 -------- d-----w- C:\crm

2011-08-22 12:39:00 -------- d-----w- c:\users\pratik\Library

2011-08-22 12:39:00 -------- d-----w- c:\users\pratik\appdata\roaming\com.adobe.ExMan

2011-08-22 08:43:16 -------- d-----w- c:\windows\system32\gprodat

2011-08-22 08:43:09 46672 ----a-w- c:\windows\system32\drivers\ggc.sys

2011-08-20 09:57:38 3907640 ----a-w- c:\windows\system32\gsdll32.dll

2011-08-20 09:57:37 1712128 ----a-w- c:\windows\system32\gdiplus.dll

2011-08-20 09:57:35 -------- d-----w- c:\windows\system32\PS

2011-08-20 09:41:09 -------- d-----w- c:\users\pratik\appdata\roaming\AutoDWG

2011-08-20 09:36:38 -------- d-----w- c:\windows\system32\shxfont

2011-08-20 09:36:37 -------- d-----w- c:\program files\AutoDWG

2011-08-20 09:36:31 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll

2011-08-20 08:48:49 229888 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HP1006S.DLL

2011-08-19 19:05:03 -------- d-----w- c:\program files\Jasc Software Inc

2011-08-19 19:03:53 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll

2011-08-19 19:03:53 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll

2011-08-19 19:03:52 98304 ------w- c:\program files\common files\installshield\engine\6\intel 32\knlwrap.exe

2011-08-19 19:03:52 36864 ------w- c:\program files\common files\installshield\engine\6\intel 32\msihook.dll

2011-08-19 19:03:51 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe

2011-08-19 19:03:51 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll

2011-08-19 19:03:49 102400 ------w- c:\program files\common files\installshield\engine\6\intel 32\scpthdlr.dll

2011-08-19 18:42:25 -------- d-----w- C:\PowerPoint_Pro_Templates

.

==================== Find3M ====================

.

2011-09-13 14:45:48 74240 ----a-w- c:\windows\system32\drivers\tdx.sys

2011-08-15 13:37:04 172032 ----a-w- c:\windows\system32\AniGIF.ocx

2009-07-31 19:36:55 32256 ----a-w- c:\program files\common files\alq.exe

.

============= FINISH: 21:10:49.47 ===============

Link to post
Share on other sites

  • 3 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.