Inactive-A Event type mptlemetry, p1 80024402c p2 endsearch p3 search p4 1.1.1593.0 p5 mpsidwn.dll p6 1.1.1593.

Status
Not open for further replies.
[FONT=Times New Roman]========================= Devices: ================================[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Name: Video Controller (VGA Compatible)[/FONT]

[FONT=Times New Roman]Description: Video Controller (VGA Compatible)[/FONT]

[FONT=Times New Roman]Class Guid: [/FONT]

[FONT=Times New Roman]Manufacturer: [/FONT]

[FONT=Times New Roman]Service: [/FONT]

[FONT=Times New Roman]Problem: : The drivers for this device are not installed. (Code 28)[/FONT]

[FONT=Times New Roman]Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.[/FONT]
 
[FONT=Times New Roman]RogueKiller V8.5.4 [Mar 18 2013] by Tigzy[/FONT]

[FONT=Times New Roman]mail : tigzyRK<at>gmail<dot>com[/FONT]

[FONT=Times New Roman]Feedback : https://www.techspot.com/downloads/5562-roguekiller.html[/FONT]

[FONT=Times New Roman]Website : http://tigzy.geekstogo.com/roguekiller.php[/FONT]

[FONT=Times New Roman]Blog : http://tigzyrk.blogspot.com/[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version[/FONT]

[FONT=Times New Roman]Started in : Normal mode[/FONT]

[FONT=Times New Roman]User : home [Admin rights][/FONT]

[FONT=Times New Roman]Mode : Scan -- Date : 06/09/2013 01:51:37[/FONT]

[FONT=Times New Roman]| ARK || FAK || MBR |[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Bad processes : 0 ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Registry Entries : 5 ¤¤¤[/FONT]

[FONT=Times New Roman][Services][BLACKLIST] HKLM\[...]\ControlSet003\Services\BrowserProtect (C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [x] -> FOUND[/FONT]

[FONT=Times New Roman][STARTUP][SUSP PATH] Seagate Product Registration.lnk @home : C:\Documents and Settings\home\Application Data\Leadertech\PowerRegister\Seagate Product Registration.exe [7] -> FOUND[/FONT]

[FONT=Times New Roman][STARTUP][SUSP PATH] tcbhn.lnk @home : C:\Documents and Settings\home\Application Data\BrowserCompanion\tcbhn.exe -> FOUND[/FONT]

[FONT=Times New Roman][PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (169.254.103.158:80) -> FOUND[/FONT]

[FONT=Times New Roman][HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Particular Files / Folders: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Driver : [LOADED] ¤¤¤[/FONT]

[FONT=Times New Roman]SSDT[41] : NtCreateKey @ 0x80578ACE -> HOOKED (Unknown @ 0x8714597C)[/FONT]

[FONT=Times New Roman]SSDT[43] : NtCreateMutant @ 0x805840AD -> HOOKED (Unknown @ 0x8713E924)[/FONT]

[FONT=Times New Roman]SSDT[47] : NtCreateProcess @ 0x805B6DB5 -> HOOKED (Unknown @ 0x8704C884)[/FONT]

[FONT=Times New Roman]SSDT[48] : NtCreateProcessEx @ 0x8058BA0C -> HOOKED (Unknown @ 0x87186A3C)[/FONT]

[FONT=Times New Roman]SSDT[52] : NtCreateSymbolicLinkObject @ 0x805DFAEA -> HOOKED (Unknown @ 0x8713E8EC)[/FONT]

[FONT=Times New Roman]SSDT[53] : NtCreateThread @ 0x80584D59 -> HOOKED (Unknown @ 0x8714EE3C)[/FONT]

[FONT=Times New Roman]SSDT[63] : NtDeleteKey @ 0x8059978F -> HOOKED (Unknown @ 0x8714590C)[/FONT]

[FONT=Times New Roman]SSDT[65] : NtDeleteValueKey @ 0x805983AE -> HOOKED (Unknown @ 0x8715D9C4)[/FONT]

[FONT=Times New Roman]SSDT[68] : NtDuplicateObject @ 0x8057F1A9 -> HOOKED (Unknown @ 0x8713E8B4)[/FONT]

[FONT=Times New Roman]SSDT[97] : NtLoadDriver @ 0x805AF8B6 -> HOOKED (Unknown @ 0x8714ED7C)[/FONT]

[FONT=Times New Roman]SSDT[122] : NtOpenProcess @ 0x8057F956 -> HOOKED (Unknown @ 0x8714491C)[/FONT]

[FONT=Times New Roman]SSDT[125] : NtOpenSection @ 0x805791AE -> HOOKED (Unknown @ 0x8715D98C)[/FONT]

[FONT=Times New Roman]SSDT[128] : NtOpenThread @ 0x805E4831 -> HOOKED (Unknown @ 0x871448E4)[/FONT]

[FONT=Times New Roman]SSDT[192] : NtRenameKey @ 0x806569DE -> HOOKED (Unknown @ 0x8715DA34)[/FONT]

[FONT=Times New Roman]SSDT[204] : NtRestoreKey @ 0x80656ED1 -> HOOKED (Unknown @ 0x8715D9FC)[/FONT]

[FONT=Times New Roman]SSDT[240] : NtSetSystemInformation @ 0x805B14E8 -> HOOKED (Unknown @ 0x8713E87C)[/FONT]

[FONT=Times New Roman]SSDT[247] : NtSetValueKey @ 0x805800A4 -> HOOKED (Unknown @ 0x87145944)[/FONT]

[FONT=Times New Roman]SSDT[257] : NtTerminateProcess @ 0x8058E8D1 -> HOOKED (Unknown @ 0x871448AC)[/FONT]

[FONT=Times New Roman]SSDT[258] : NtTerminateThread @ 0x80584986 -> HOOKED (Unknown @ 0x871459B4)[/FONT]

[FONT=Times New Roman]SSDT[277] : NtWriteVirtualMemory @ 0x8058760F -> HOOKED (Unknown @ 0x8715D954)[/FONT]

[FONT=Times New Roman]S_SSDT[548] : NtUserSetWindowsHookAW -> HOOKED (Unknown @ 0x85D75A94)[/FONT]

[FONT=Times New Roman]S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x870B7FD4)[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ HOSTS File: ¤¤¤[/FONT]

[FONT=Times New Roman]--> C:\WINDOWS\system32\drivers\etc\hosts[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]127.0.0.1 localhost[/FONT]

[FONT=Times New Roman]127.0.0.1 www.007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008i.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 010402.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100sexlinks.com[/FONT]

[FONT=Times New Roman][...][/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ MBR Check: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive0: SAMSUNG HD502HI +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] 9c79fad6353dedef51d5c47d87588a1e[/FONT]

[FONT=Times New Roman][BSP] 6e3c3b93d3377cc12662a229aee850e1 : Windows XP MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476939 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]User = LL2 ... OK![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive1: SanDisk Ultra USB Device +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] a124dc1f32b91ceacb765c7a5ad6ec2e[/FONT]

[FONT=Times New Roman][BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 15266 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]Error reading LL2 MBR![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Finished : << RKreport[1]_S_06092013_02d0151.txt >>[/FONT]

[FONT=Times New Roman]RKreport[1]_S_06092013_02d0151.txt[/FONT]

[FONT=Times New Roman] [/FONT]
 
[FONT=Times New Roman]RogueKiller V8.5.4 [Mar 18 2013] by Tigzy[/FONT]

[FONT=Times New Roman]mail : tigzyRK<at>gmail<dot>com[/FONT]

[FONT=Times New Roman]Feedback : https://www.techspot.com/downloads/5562-roguekiller.html[/FONT]

[FONT=Times New Roman]Website : http://tigzy.geekstogo.com/roguekiller.php[/FONT]

[FONT=Times New Roman]Blog : http://tigzyrk.blogspot.com/[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version[/FONT]

[FONT=Times New Roman]Started in : Normal mode[/FONT]

[FONT=Times New Roman]User : home [Admin rights][/FONT]

[FONT=Times New Roman]Mode : Remove -- Date : 06/09/2013 01:54:25[/FONT]

[FONT=Times New Roman]| ARK || FAK || MBR |[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Bad processes : 0 ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Registry Entries : 5 ¤¤¤[/FONT]

[FONT=Times New Roman][Services][BLACKLIST] HKLM\[...]\ControlSet003\Services\BrowserProtect (C:\Documents and Settings\All Users\Application Data\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe) [x] -> DELETED[/FONT]

[FONT=Times New Roman][STARTUP][SUSP PATH] Seagate Product Registration.lnk @home : C:\Documents and Settings\home\Application Data\Leadertech\PowerRegister\Seagate Product Registration.exe [7] -> DELETED[/FONT]

[FONT=Times New Roman][STARTUP][SUSP PATH] tcbhn.lnk @home : C:\Documents and Settings\home\Application Data\BrowserCompanion\tcbhn.exe -> DELETED[/FONT]

[FONT=Times New Roman][PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (169.254.103.158:80) -> NOT REMOVED, USE PROXYFIX[/FONT]

[FONT=Times New Roman][HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Particular Files / Folders: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Driver : [LOADED] ¤¤¤[/FONT]

[FONT=Times New Roman]SSDT[41] : NtCreateKey @ 0x80578ACE -> HOOKED (Unknown @ 0x8714597C)[/FONT]

[FONT=Times New Roman]SSDT[43] : NtCreateMutant @ 0x805840AD -> HOOKED (Unknown @ 0x8713E924)[/FONT]

[FONT=Times New Roman]SSDT[47] : NtCreateProcess @ 0x805B6DB5 -> HOOKED (Unknown @ 0x8704C884)[/FONT]

[FONT=Times New Roman]SSDT[48] : NtCreateProcessEx @ 0x8058BA0C -> HOOKED (Unknown @ 0x87186A3C)[/FONT]

[FONT=Times New Roman]SSDT[52] : NtCreateSymbolicLinkObject @ 0x805DFAEA -> HOOKED (Unknown @ 0x8713E8EC)[/FONT]

[FONT=Times New Roman]SSDT[53] : NtCreateThread @ 0x80584D59 -> HOOKED (Unknown @ 0x8714EE3C)[/FONT]

[FONT=Times New Roman]SSDT[63] : NtDeleteKey @ 0x8059978F -> HOOKED (Unknown @ 0x8714590C)[/FONT]

[FONT=Times New Roman]SSDT[65] : NtDeleteValueKey @ 0x805983AE -> HOOKED (Unknown @ 0x8715D9C4)[/FONT]

[FONT=Times New Roman]SSDT[68] : NtDuplicateObject @ 0x8057F1A9 -> HOOKED (Unknown @ 0x8713E8B4)[/FONT]

[FONT=Times New Roman]SSDT[97] : NtLoadDriver @ 0x805AF8B6 -> HOOKED (Unknown @ 0x8714ED7C)[/FONT]

[FONT=Times New Roman]SSDT[122] : NtOpenProcess @ 0x8057F956 -> HOOKED (Unknown @ 0x8714491C)[/FONT]

[FONT=Times New Roman]SSDT[125] : NtOpenSection @ 0x805791AE -> HOOKED (Unknown @ 0x8715D98C)[/FONT]

[FONT=Times New Roman]SSDT[128] : NtOpenThread @ 0x805E4831 -> HOOKED (Unknown @ 0x871448E4)[/FONT]

[FONT=Times New Roman]SSDT[192] : NtRenameKey @ 0x806569DE -> HOOKED (Unknown @ 0x8715DA34)[/FONT]

[FONT=Times New Roman]SSDT[204] : NtRestoreKey @ 0x80656ED1 -> HOOKED (Unknown @ 0x8715D9FC)[/FONT]

[FONT=Times New Roman]SSDT[240] : NtSetSystemInformation @ 0x805B14E8 -> HOOKED (Unknown @ 0x8713E87C)[/FONT]

[FONT=Times New Roman]SSDT[247] : NtSetValueKey @ 0x805800A4 -> HOOKED (Unknown @ 0x87145944)[/FONT]

[FONT=Times New Roman]SSDT[257] : NtTerminateProcess @ 0x8058E8D1 -> HOOKED (Unknown @ 0x871448AC)[/FONT]

[FONT=Times New Roman]SSDT[258] : NtTerminateThread @ 0x80584986 -> HOOKED (Unknown @ 0x871459B4)[/FONT]

[FONT=Times New Roman]SSDT[277] : NtWriteVirtualMemory @ 0x8058760F -> HOOKED (Unknown @ 0x8715D954)[/FONT]

[FONT=Times New Roman]S_SSDT[548] : NtUserSetWindowsHookAW -> HOOKED (Unknown @ 0x85D75A94)[/FONT]

[FONT=Times New Roman]S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x870B7FD4)[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ HOSTS File: ¤¤¤[/FONT]

[FONT=Times New Roman]--> C:\WINDOWS\system32\drivers\etc\hosts[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]127.0.0.1 localhost[/FONT]

[FONT=Times New Roman]127.0.0.1 www.007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008i.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 010402.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100sexlinks.com[/FONT]

[FONT=Times New Roman][...][/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ MBR Check: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive0: SAMSUNG HD502HI +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] 9c79fad6353dedef51d5c47d87588a1e[/FONT]

[FONT=Times New Roman][BSP] 6e3c3b93d3377cc12662a229aee850e1 : Windows XP MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476939 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]User = LL2 ... OK![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive1: SanDisk Ultra USB Device +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] a124dc1f32b91ceacb765c7a5ad6ec2e[/FONT]

[FONT=Times New Roman][BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 15266 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]Error reading LL2 MBR![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Finished : << RKreport[2]_D_06092013_02d0154.txt >>[/FONT]

[FONT=Times New Roman]RKreport[1]_S_06092013_02d0151.txt ; RKreport[2]_D_06092013_02d0154.txt[/FONT]

[FONT=Times New Roman]RogueKiller V8.5.4 [Mar 18 2013] by Tigzy[/FONT]

[FONT=Times New Roman]mail : tigzyRK<at>gmail<dot>com[/FONT]

[FONT=Times New Roman]Feedback : https://www.techspot.com/downloads/5562-roguekiller.html[/FONT]

[FONT=Times New Roman]Website : http://tigzy.geekstogo.com/roguekiller.php[/FONT]

[FONT=Times New Roman]Blog : http://tigzyrk.blogspot.com/[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version[/FONT]

[FONT=Times New Roman]Started in : Normal mode[/FONT]

[FONT=Times New Roman]User : home [Admin rights][/FONT]

[FONT=Times New Roman]Mode : Scan -- Date : 06/09/2013 01:56:01[/FONT]

[FONT=Times New Roman]| ARK || FAK || MBR |[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Bad processes : 0 ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Registry Entries : 1 ¤¤¤[/FONT]

[FONT=Times New Roman][PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (169.254.103.158:80) -> FOUND[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Particular Files / Folders: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ Driver : [LOADED] ¤¤¤[/FONT]

[FONT=Times New Roman]SSDT[41] : NtCreateKey @ 0x80578ACE -> HOOKED (Unknown @ 0x8714597C)[/FONT]

[FONT=Times New Roman]SSDT[43] : NtCreateMutant @ 0x805840AD -> HOOKED (Unknown @ 0x8713E924)[/FONT]

[FONT=Times New Roman]SSDT[47] : NtCreateProcess @ 0x805B6DB5 -> HOOKED (Unknown @ 0x8704C884)[/FONT]

[FONT=Times New Roman]SSDT[48] : NtCreateProcessEx @ 0x8058BA0C -> HOOKED (Unknown @ 0x87186A3C)[/FONT]

[FONT=Times New Roman]SSDT[52] : NtCreateSymbolicLinkObject @ 0x805DFAEA -> HOOKED (Unknown @ 0x8713E8EC)[/FONT]

[FONT=Times New Roman]SSDT[53] : NtCreateThread @ 0x80584D59 -> HOOKED (Unknown @ 0x8714EE3C)[/FONT]

[FONT=Times New Roman]SSDT[63] : NtDeleteKey @ 0x8059978F -> HOOKED (Unknown @ 0x8714590C)[/FONT]

[FONT=Times New Roman]SSDT[65] : NtDeleteValueKey @ 0x805983AE -> HOOKED (Unknown @ 0x8715D9C4)[/FONT]

[FONT=Times New Roman]SSDT[68] : NtDuplicateObject @ 0x8057F1A9 -> HOOKED (Unknown @ 0x8713E8B4)[/FONT]

[FONT=Times New Roman]SSDT[97] : NtLoadDriver @ 0x805AF8B6 -> HOOKED (Unknown @ 0x8714ED7C)[/FONT]

[FONT=Times New Roman]SSDT[122] : NtOpenProcess @ 0x8057F956 -> HOOKED (Unknown @ 0x8714491C)[/FONT]

[FONT=Times New Roman]SSDT[125] : NtOpenSection @ 0x805791AE -> HOOKED (Unknown @ 0x8715D98C)[/FONT]

[FONT=Times New Roman]SSDT[128] : NtOpenThread @ 0x805E4831 -> HOOKED (Unknown @ 0x871448E4)[/FONT]

[FONT=Times New Roman]SSDT[192] : NtRenameKey @ 0x806569DE -> HOOKED (Unknown @ 0x8715DA34)[/FONT]

[FONT=Times New Roman]SSDT[204] : NtRestoreKey @ 0x80656ED1 -> HOOKED (Unknown @ 0x8715D9FC)[/FONT]

[FONT=Times New Roman]SSDT[240] : NtSetSystemInformation @ 0x805B14E8 -> HOOKED (Unknown @ 0x8713E87C)[/FONT]

[FONT=Times New Roman]SSDT[247] : NtSetValueKey @ 0x805800A4 -> HOOKED (Unknown @ 0x87145944)[/FONT]

[FONT=Times New Roman]SSDT[257] : NtTerminateProcess @ 0x8058E8D1 -> HOOKED (Unknown @ 0x871448AC)[/FONT]

[FONT=Times New Roman]SSDT[258] : NtTerminateThread @ 0x80584986 -> HOOKED (Unknown @ 0x871459B4)[/FONT]

[FONT=Times New Roman]SSDT[277] : NtWriteVirtualMemory @ 0x8058760F -> HOOKED (Unknown @ 0x8715D954)[/FONT]

[FONT=Times New Roman]S_SSDT[548] : NtUserSetWindowsHookAW -> HOOKED (Unknown @ 0x85D75A94)[/FONT]

[FONT=Times New Roman]S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x870B7FD4)[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ HOSTS File: ¤¤¤[/FONT]

[FONT=Times New Roman]--> C:\WINDOWS\system32\drivers\etc\hosts[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]127.0.0.1 localhost[/FONT]

[FONT=Times New Roman]127.0.0.1 www.007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 007guard.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008i.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 008k.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 00hq.com[/FONT]

[FONT=Times New Roman]127.0.0.1 010402.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 032439.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 0scan.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1000gratisproben.com[/FONT]

[FONT=Times New Roman]127.0.0.1 1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.1001namen.com[/FONT]

[FONT=Times New Roman]127.0.0.1 100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100888290cs.com[/FONT]

[FONT=Times New Roman]127.0.0.1 www.100sexlinks.com[/FONT]

[FONT=Times New Roman][...][/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]¤¤¤ MBR Check: ¤¤¤[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive0: SAMSUNG HD502HI +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] 9c79fad6353dedef51d5c47d87588a1e[/FONT]

[FONT=Times New Roman][BSP] 6e3c3b93d3377cc12662a229aee850e1 : Windows XP MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476939 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]User = LL2 ... OK![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]+++++ PhysicalDrive1: SanDisk Ultra USB Device +++++[/FONT]

[FONT=Times New Roman]--- User ---[/FONT]

[FONT=Times New Roman][MBR] a124dc1f32b91ceacb765c7a5ad6ec2e[/FONT]

[FONT=Times New Roman][BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code[/FONT]

[FONT=Times New Roman]Partition table:[/FONT]

[FONT=Times New Roman]0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 15266 Mo[/FONT]

[FONT=Times New Roman]User = LL1 ... OK![/FONT]

[FONT=Times New Roman]Error reading LL2 MBR![/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Finished : << RKreport[3]_S_06092013_02d0156.txt >>[/FONT]

[FONT=Times New Roman]RKreport[1]_S_06092013_02d0151.txt ; RKreport[2]_D_06092013_02d0154.txt ; RKreport[3]_S_06092013_02d0156.txt[/FONT]

[FONT=Times New Roman] [/FONT]
 
[FONT=Times New Roman]Malwarebytes Anti-Rootkit BETA 1.06.0.1003[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman](c) Malwarebytes Corporation 2011-2012[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]OS version: 5.1.2600 Windows XP Service Pack 3 x86[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Account is Administrative[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Internet Explorer version: 8.0.6001.18702[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]File system is: FAT32[/FONT]

[FONT=Times New Roman]Disk drives: C:\ DRIVE_FIXED[/FONT]

[FONT=Times New Roman]CPU speed: 2.992000 GHz[/FONT]

[FONT=Times New Roman]Memory total: 1072406528, free: 414441472[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Host not found[/FONT]

[FONT=Times New Roman]Host not found[/FONT]

[FONT=Times New Roman]Initializing...[/FONT]

[FONT=Times New Roman]------------ Kernel report ------------[/FONT]

[FONT=Times New Roman] 06/09/2013 02:11:48[/FONT]

[FONT=Times New Roman]------------ Loaded modules -----------[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\ntoskrnl.exe[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\hal.dll[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\KDCOM.DLL[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\BOOTVID.dll[/FONT]

[FONT=Times New Roman]sptd.sys[/FONT]

[FONT=Times New Roman]\WINDOWS\System32\Drivers\WMILIB.SYS[/FONT]

[FONT=Times New Roman]\WINDOWS\System32\Drivers\SCSIPORT.SYS[/FONT]

[FONT=Times New Roman]ACPI.sys[/FONT]

[FONT=Times New Roman]pci.sys[/FONT]

[FONT=Times New Roman]isapnp.sys[/FONT]

[FONT=Times New Roman]PCIIde.sys[/FONT]

[FONT=Times New Roman]\WINDOWS\System32\Drivers\PCIIDEX.SYS[/FONT]

[FONT=Times New Roman]intelide.sys[/FONT]

[FONT=Times New Roman]MountMgr.sys[/FONT]

[FONT=Times New Roman]ftdisk.sys[/FONT]

[FONT=Times New Roman]PartMgr.sys[/FONT]

[FONT=Times New Roman]VolSnap.sys[/FONT]

[FONT=Times New Roman]atapi.sys[/FONT]

[FONT=Times New Roman]disk.sys[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\DRIVERS\CLASSPNP.SYS[/FONT]

[FONT=Times New Roman]fltmgr.sys[/FONT]

[FONT=Times New Roman]sr.sys[/FONT]

[FONT=Times New Roman]KSecDD.sys[/FONT]

[FONT=Times New Roman]aswKbd.sys[/FONT]

[FONT=Times New Roman]Ntfs.sys[/FONT]

[FONT=Times New Roman]NDIS.sys[/FONT]

[FONT=Times New Roman]vvoice.sys[/FONT]

[FONT=Times New Roman]vpctcom.sys[/FONT]

[FONT=Times New Roman]vmodem.sys[/FONT]

[FONT=Times New Roman]Mup.sys[/FONT]

[FONT=Times New Roman]BMLoad.sys[/FONT]

[FONT=Times New Roman]agp440.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\intelppm.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\HDAudBus.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\usbuhci.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\USBPORT.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\usbehci.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\cmaudio.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\portcls.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\drmk.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\ks.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\i8042prt.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\kbdclass.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\fdc.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\serial.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\serenum.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\parport.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\cdrbsvsd.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\imapi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\cdrom.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\redbook.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\smwdm.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\aeaudio.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\sf.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\audstub.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\RootMdm.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Modem.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\rasl2tp.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ndistapi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ndiswan.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\raspppoe.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\raspptp.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\TDI.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\psched.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\msgpc.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ptilink.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\raspti.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\RimSerial.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\termdd.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\mouclass.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\swenum.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\update.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\mssmbios.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\NDProxy.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\AtiHdmi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\usbhub.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\USBD.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\gameenum.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\flpydisk.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Fs_Rec.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Null.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Beep.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\HIDPARSE.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\vga.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\VIDEOPRT.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\mnmdd.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\DRIVERS\RDPCDD.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Msfs.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Npfs.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\rasacd.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ipsec.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\tcpip.sys[/FONT]

[FONT=Times New Roman]\??\C:\WINDOWS\system32\drivers\tcpipBM.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\netbt.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ipnat.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\wanarp.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\ws2ifsl.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\afd.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\netbios.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\tmcomm.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\tmevtmgr.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\usbVM303.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\STREAM.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\tmactmon.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\vvftav303.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\tmtdi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\rdbss.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\mrxsmb.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Fips.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\hidusb.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\HIDCLASS.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\mouhid.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Cdfs.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\dump_atapi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\dump_WMILIB.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\win32k.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\Dxapi.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\watchdog.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\dxg.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\drivers\dxgthk.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\framebuf.dll[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\nwlnkipx.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\nwlnknb.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\ndisuio.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\ATMFD.DLL[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\mrxdav.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\ParVdm.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\wdmaud.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\sysaudio.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\nwlnkspx.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\srv.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\HTTP.sys[/FONT]

[FONT=Times New Roman]\??\C:\WINDOWS\system32\PCTINDIS5.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\System32\Drivers\Fastfat.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\fetnd5bv.sys[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\DRIVERS\USBSTOR.SYS[/FONT]

[FONT=Times New Roman]\SystemRoot\system32\drivers\kmixer.sys[/FONT]

[FONT=Times New Roman]\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys[/FONT]

[FONT=Times New Roman]\??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys[/FONT]

[FONT=Times New Roman]\WINDOWS\system32\ntdll.dll[/FONT]

[FONT=Times New Roman]----------- End -----------[/FONT]

[FONT=Times New Roman]Done![/FONT]
 
[FONT=Times New Roman]<<<1>>>[/FONT]

[FONT=Times New Roman]Upper Device Name: \Device\Harddisk1\DR12[/FONT]

[FONT=Times New Roman]Upper Device Object: 0xffffffff85c164e0[/FONT]

[FONT=Times New Roman]Upper Device Driver Name: \Driver\Disk\[/FONT]

[FONT=Times New Roman]Lower Device Name: \Device\0000008c\[/FONT]

[FONT=Times New Roman]Lower Device Object: 0xffffffff85cc3db0[/FONT]

[FONT=Times New Roman]Lower Device Driver Name: \Driver\USBSTOR\[/FONT]

[FONT=Times New Roman]IRP handler 0 of \Driver\USBSTOR points to an unknown module[/FONT]

[FONT=Times New Roman]Unhooking enabled.[/FONT]

[FONT=Times New Roman]<<<1>>>[/FONT]

[FONT=Times New Roman]Upper Device Name: \Device\Harddisk1\DR12[/FONT]

[FONT=Times New Roman]Upper Device Object: 0xffffffff85c164e0[/FONT]

[FONT=Times New Roman]Upper Device Driver Name: \Driver\Disk\[/FONT]

[FONT=Times New Roman]Lower Device Name: \Device\0000008c\[/FONT]

[FONT=Times New Roman]Lower Device Object: 0xffffffff85cc3db0[/FONT]

[FONT=Times New Roman]Lower Device Driver Name: \Driver\USBSTOR\[/FONT]

[FONT=Times New Roman]Driver name found: USBSTOR[/FONT]

[FONT=Times New Roman]Initialization returned 0x0[/FONT]

[FONT=Times New Roman]Load Function returned 0x0[/FONT]

[FONT=Times New Roman]<<<1>>>[/FONT]

[FONT=Times New Roman]Upper Device Name: \Device\Harddisk0\DR0[/FONT]

[FONT=Times New Roman]Upper Device Object: 0xffffffff87334ab8[/FONT]

[FONT=Times New Roman]Upper Device Driver Name: \Driver\Disk\[/FONT]

[FONT=Times New Roman]Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-5\[/FONT]

[FONT=Times New Roman]Lower Device Object: 0xffffffff872d3d98[/FONT]

[FONT=Times New Roman]Lower Device Driver Name: \Driver\atapi\[/FONT]

[FONT=Times New Roman]Driver name found: atapi[/FONT]

[FONT=Times New Roman]Initialization returned 0x0[/FONT]

[FONT=Times New Roman]Load Function returned 0x0[/FONT]

[FONT=Times New Roman]<<<2>>>[/FONT]

[FONT=Times New Roman]Device number: 0, partition: 1[/FONT]

[FONT=Times New Roman]Physical Sector Size: 512[/FONT]

[FONT=Times New Roman]Drive: 0, DevicePointer: 0xffffffff87334ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]--------- Disk Stack ------[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff872dc930, DeviceName: Unknown, DriverName: \Driver\PartMgr\[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff87334ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff872f69b8, DeviceName: \Device\0000006d\, DriverName: \Driver\ACPI\[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff872d3d98, DeviceName: \Device\Ide\IdeDeviceP2T0L0-5\, DriverName: \Driver\atapi\[/FONT]

[FONT=Times New Roman]------------ End ----------[/FONT]

[FONT=Times New Roman]Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]Upper DeviceData: 0xffffffffe4090ba8, 0xffffffff87334ab8, 0xffffffff859a0208[/FONT]

[FONT=Times New Roman]Lower DeviceData: 0xffffffffe30ac468, 0xffffffff872d3d98, 0xffffffff859c2040[/FONT]

[FONT=Times New Roman]<<<3>>>[/FONT]

[FONT=Times New Roman]Volume: C:[/FONT]

[FONT=Times New Roman]File system type: NTFS[/FONT]

[FONT=Times New Roman]SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes[/FONT]

[FONT=Times New Roman]<<<2>>>[/FONT]

[FONT=Times New Roman]Device number: 0, partition: 1[/FONT]

[FONT=Times New Roman]<<<3>>>[/FONT]

[FONT=Times New Roman]Volume: C:[/FONT]

[FONT=Times New Roman]File system type: NTFS[/FONT]

[FONT=Times New Roman]SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes[/FONT]

[FONT=Times New Roman]Scanning drivers directory: C:\WINDOWS\system32\drivers...[/FONT]

[FONT=Times New Roman]<<<2>>>[/FONT]

[FONT=Times New Roman]Device number: 0, partition: 1[/FONT]

[FONT=Times New Roman]<<<3>>>[/FONT]

[FONT=Times New Roman]Volume: C:[/FONT]

[FONT=Times New Roman]File system type: NTFS[/FONT]

[FONT=Times New Roman]SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes[/FONT]

[FONT=Times New Roman]File user open failed: C:\WINDOWS\system32\drivers\sptd.sys (0x00000020)[/FONT]

[FONT=Times New Roman]Done![/FONT]

[FONT=Times New Roman]Drive 0[/FONT]

[FONT=Times New Roman]Scanning MBR on drive 0...[/FONT]

[FONT=Times New Roman]Inspecting partition table:[/FONT]

[FONT=Times New Roman]MBR Signature: 55AA[/FONT]

[FONT=Times New Roman]Disk Signature: 23658E6F[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Partition information:[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 0 type is Primary (0x7)[/FONT]

[FONT=Times New Roman] Partition is ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 63 Numsec = 976773105[/FONT]

[FONT=Times New Roman] Partition file system is NTFS[/FONT]

[FONT=Times New Roman] Partition is bootable[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 1 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 2 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 3 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Disk Size: 500107862016 bytes[/FONT]

[FONT=Times New Roman]Sector size: 512 bytes[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)...[/FONT]

[FONT=Times New Roman]Done![/FONT]

[FONT=Times New Roman]Physical Sector Size: 512[/FONT]

[FONT=Times New Roman]Drive: 1, DevicePointer: 0xffffffff85c164e0, DeviceName: \Device\Harddisk1\DR12\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]--------- Disk Stack ------[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff8726a020, DeviceName: Unknown, DriverName: \Driver\PartMgr\[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff85c164e0, DeviceName: \Device\Harddisk1\DR12\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]DevicePointer: 0xffffffff85cc3db0, DeviceName: \Device\0000008c\, DriverName: \Driver\USBSTOR\[/FONT]

[FONT=Times New Roman]------------ End ----------[/FONT]

[FONT=Times New Roman]Alternate DeviceName: \Device\Harddisk1\DR12\, DriverName: \Driver\Disk\[/FONT]

[FONT=Times New Roman]Upper DeviceData: 0xffffffffe1d6e208, 0xffffffff85c164e0, 0xffffffff85af0ab8[/FONT]

[FONT=Times New Roman]Lower DeviceData: 0xffffffffe3380708, 0xffffffff85cc3db0, 0xffffffff85f3a4b8[/FONT]

[FONT=Times New Roman]Drive 1[/FONT]

[FONT=Times New Roman]Scanning MBR on drive 1...[/FONT]

[FONT=Times New Roman]Inspecting partition table:[/FONT]

[FONT=Times New Roman]MBR Signature: 55AA[/FONT]

[FONT=Times New Roman]Disk Signature: 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Partition information:[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 0 type is Other (0xc)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 32 Numsec = 31266784[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 1 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 2 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] Partition 3 type is Empty (0x0)[/FONT]

[FONT=Times New Roman] Partition is NOT ACTIVE.[/FONT]

[FONT=Times New Roman] Partition starts at LBA: 0 Numsec = 0[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Disk Size: 16008609792 bytes[/FONT]

[FONT=Times New Roman]Sector size: 512 bytes[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman]Done![/FONT]

[FONT=Times New Roman]Scan finished[/FONT]

[FONT=Times New Roman]Removal queue found; removal started[/FONT]

[FONT=Times New Roman]Removing c:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_i.mbam...[/FONT]

[FONT=Times New Roman]Removing c:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\bootstrap_0_0_63_i.mbam...[/FONT]

[FONT=Times New Roman]Removing c:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_0_r.mbam...[/FONT]

[FONT=Times New Roman]Removing c:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_i.mbam...[/FONT]

[FONT=Times New Roman]Removing c:\documents and settings\all users\application data\malwarebytes' anti-malware (portable)\mbr_1_r.mbam...[/FONT]

[FONT=Times New Roman]Removal finished[/FONT]

[FONT=Times New Roman]Host not found[/FONT]

[FONT=Times New Roman]=======================================[/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]

[FONT=Times New Roman] [/FONT]
 
Morning
Yesterday was a long day :(
And my desktop is still with no connectivity
Event Viewer
System
DATE:6/9/2013 SOURCE:Dhcp
TIME 11:19 CATEGORY:NONE
TYPE :WARNING EVENT ID:1007
user: n/a
Computer:Home-52DC6E4B98
Description:
Your computer has automatically configured the IP addres for the
Network Card with network addres 0040F4B1FF29. The IP address
being used is 169.254.103.158



Local Area connection
is sending but no receiving
 
redtarget.gif
Create new restore point before proceeding with the next step....
How to:
- Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
- Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
- Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
- XP: http://support.microsoft.com/kb/948247

redtarget.gif
Please download ComboFix from Here, Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    If the connection is not there use restore point you created prior to running Combofix.
  • Double click on combofix.exe & follow the prompts.

  • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
**Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try the following...

Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

Restart computer in safe mode

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

When the scan is done Notepad will open with rKill.txt log.
NOTE. rKill.txt log will also be present on your desktop.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
 
My desktop can't connect to the internet
how can I update the program if I need to, remember I am downloading from another computer
 
Download Windows Repair (All in One) from this site

Install the program then run it.

NOTE 1. In Windows Vista, 7 and 8 right click on the program, click "Run As Administrator".
NOTE 2. Disable your antivirus program before running Windows Repair.


Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:

p22002979.gif




Once that is done then go to Step 3 and allow it to run System File Check by clicking on Do It button:

p22002980.gif



Go to Step 4 and under "System Restore" click on Create button:

p22002982.gif



Go to Start Repairs tab and click Start button.

Leave all checkmarks as they're.
NOTE for Windows 8 users. Reset Registry Permissions is NOT checked by design.

Click on Start button.

p22003030.gif


Post Windows Repair log (_windows_repair_log.txt) which is located in the following folder:
64-bit systems - C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Logs
32-bit systems - C:\Program Files\Tweaking.com\Windows Repair (All in One)\Logs
 
Now I am ....
Windows file protection is asking me for my cd-rom of Winows XP Home Edition, and my computer is 8 years old I don't have the original cd of my computer
 
That indicates that there is a problem with some Windows files and this has to be fixed.
Ask around. Some friend may have the disk.
 
This topic is marked as abandoned and closed due to inactivity.
This member will NOT be eligible to receive any more help in malware removal forum.
 
Status
Not open for further replies.
Back