Hi,
Please help in fixing this problem.
I'm using win7 32 bit machine and my system got infected.
I followed the 8 step tutorial and generated logs.
My antivirus gives pop up message that w32.Crypt is quarantined (these messages did not stop)
I'm pasting my logs below.
Malwarebytes Anti-Malware log
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6443
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
25/04/2011 19:13:03
mbam-log-2011-04-25 (19-13-03).txt
Scan type: Quick scan
Objects scanned: 159516
Time elapsed: 14 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-04-25 19:21:33
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK3265GSX rev.GJ002F
Running: 4r91g79n.exe; Driver: C:\Users\giridhar\AppData\Local\Temp\kxldapod.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8B8720B8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8B8720CE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8B8720A4]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS log
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by giridhar at 19:37:30.36 on 25/04/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3070.1605 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
AV: Immunet Protect *Enabled/Updated* {E26D838D-778A-C93D-0B41-46E786995C11}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spyware Doctor *Enabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Immunet Protect\2.0.17\agent.exe
C:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\mfevtps.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\PC Tools Security\pctsAuxs.exe
C:\Program Files\PC Tools Security\pctsSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\Program Files\PC Tools Security\pctsGui.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Immunet Protect\2.0.17\iptray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\giridhar\Desktop\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uDefault_Page_URL = hxxp://samsung.msn.com
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
uURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
BHO: FileServeManager: {00000001-ab3b-4334-9da2-ec6b2a02afc6} - c:\program files\fileserve manager\FileServeBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110325201413.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: @c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [uTorrent] "c:\users\giridhar\downloads\utorrent.exe"
uRun: [Google Update] "c:\users\giridhar\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [googletalk] c:\users\giridhar\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [CLMLServer] "c:\program files\cyberlink\power2go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe"
mRun: [UpdatePPShortCut] "c:\program files\cyberlink\powerproducer\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerproducer" updatewithcreateonce "software\cyberlink\powerproducer\5.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ISTray] "c:\program files\pc tools security\pctsGui.exe" /hideGUI
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [FileServe Manager Task] "c:\program files\fileserve manager\FSStarter.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Immunet Protect] "c:\program files\immunet protect\2.0.17\iptray.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\giridhar\appdata\roaming\micros~1\windows\startm~1\programs\startup\foldin~1.lnk - c:\users\giridhar\appdata\roaming\microsoft\installer\{6a90c837-054e-44ae-b9bd-1b1f87986bbc}\_98830A63A82EB98D7BA198.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{51fb15f4-ad27-43bc-ad4b-dd0354fb6bbd}\Icon3E5562ED7.ico
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with FileServe Manager - c:\program files\fileserve manager\GetUrl.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\progra~1\google\google~3\GO36F4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\giridhar\appdata\roaming\mozilla\firefox\profiles\9dvu231c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2166.3772\npCIDetect14.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\giridhar\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\giridhar\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\giridhar\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-3-25 386840]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-3-25 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-3-25 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-3-25 656320]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-25 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-25 307288]
R1 ImmunetProtectDriver;ImmunetProtectDriver;c:\windows\system32\drivers\ImmunetProtect.sys [2011-4-25 41424]
R1 ImmunetSelfProtectDriver;ImmunetSelfProtectDriver;c:\windows\system32\drivers\ImmunetSelfProtect.sys [2011-4-25 31184]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2011-3-25 64304]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-3-25 164840]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsldbbae6b5;MpKsldbbae6b5;c:\programdata\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\MpKsldbbae6b5.sys [2011-4-25 28752]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-8-6 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-1-26 176128]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-1-26 284672]
R2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ati technologies\ati.ace\reservation manager\AMD Reservation Manager.exe [2010-6-17 140224]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-25 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-4-25 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-4-25 42184]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-3-25 22504]
R2 ImmunetProtect;Immunet Protect;c:\program files\immunet protect\2.0.17\agent.exe [2011-4-25 756680]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-8-6 203280]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-3-25 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-3-25 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-3-25 141792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-3-25 366840]
R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-3-25 1150936]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-3-25 37944]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-1-27 7566848]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-1-26 238592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-3-25 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-3-25 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-3-25 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-3-25 313288]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-6 30392]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-3-25 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-4-2 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2011-3-25 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-3-25 84264]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011.sp1a\RpcAgentSrv.exe [2011-3-25 93848]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-3 52224]
.
=============== Created Last 30 ================
.
2011-04-25 18:23:48 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\MpKsldbbae6b5.sys
2011-04-25 18:23:34 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\mpengine.dll
2011-04-25 17:57:32 -------- d-----w- c:\users\giridhar\appdata\roaming\Malwarebytes
2011-04-25 17:57:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-25 17:57:19 -------- d-----w- c:\progra~2\Malwarebytes
2011-04-25 17:57:13 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-25 17:57:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-25 15:03:53 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-25 14:23:37 -------- d-----w- c:\program files\common files\WebM Project
2011-04-25 14:20:46 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-25 14:19:59 40112 ----a-w- c:\windows\avastSS.scr
2011-04-25 14:19:33 -------- d-----w- c:\progra~2\Alwil Software
2011-04-25 14:16:05 439632 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{c42ba154-4657-4351-8aac-b948978a8e84}\gapaengine.dll
2011-04-25 14:16:05 -------- d-----w- c:\users\giridhar\appdata\local\Immunet
2011-04-25 14:16:05 -------- d-----w- c:\progra~2\Immunet
2011-04-25 14:15:40 31184 ----a-w- c:\windows\system32\drivers\ImmunetSelfProtect.sys
2011-04-25 14:15:34 41424 ----a-w- c:\windows\system32\drivers\ImmunetProtect.sys
2011-04-25 14:15:24 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-25 14:15:03 -------- d-----w- c:\program files\Immunet Protect
2011-04-25 14:09:13 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-25 11:47:41 -------- d-----w- c:\program files\Syser
2011-04-21 07:18:03 -------- d-----w- c:\users\giridhar\appdata\local\ElevatedDiagnostics
2011-04-20 23:17:24 -------- d-----w- c:\program files\common files\AMD
2011-04-20 23:16:41 -------- d-----w- c:\program files\AMD APP
2011-04-20 00:37:36 -------- d-----w- c:\users\giridhar\.vim-fuf-data
2011-04-19 23:41:08 -------- d-----w- c:\users\giridhar\appdata\roaming\Hummingbird
2011-04-19 23:41:08 -------- d-----w- c:\program files\Hummingbird
2011-04-16 14:04:28 -------- d-----w- c:\users\giridhar\cr3
2011-04-16 11:04:38 -------- d-----w- c:\users\giridhar\ChartNexus
2011-04-16 01:31:30 -------- d-----w- C:\ctags
2011-04-16 01:17:35 -------- d-----w- c:\program files\vim
2011-04-15 17:41:33 -------- d-----w- c:\users\giridhar\appdata\local\TSVNCache
2011-04-14 21:42:07 -------- d-----w- c:\users\giridhar\appdata\roaming\TortoiseSVN
2011-04-14 21:40:08 -------- d-----w- c:\users\giridhar\appdata\roaming\Subversion
2011-04-14 21:39:42 -------- d-----w- c:\program files\TortoiseSVN
2011-04-14 21:39:42 -------- d-----w- c:\program files\common files\TortoiseOverlays
2011-04-14 21:27:38 -------- d-----w- c:\users\giridhar\.idlerc
2011-04-13 21:25:49 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-13 21:25:49 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-13 21:25:49 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-13 21:25:02 2333184 ----a-w- c:\windows\system32\win32k.sys
2011-04-10 22:30:05 -------- d-----w- c:\program files\SyncToy 2.1
2011-04-10 22:20:38 -------- d-----w- c:\users\giridhar\appdata\roaming\calibre
2011-04-10 22:17:46 -------- d-----w- c:\program files\Calibre2
2011-04-10 19:22:38 125328 ----a-w- c:\windows\system32\drivers\dne2000.sys
2011-04-10 19:22:38 106768 ----a-w- c:\windows\system32\dneinobj.dll
2011-04-10 19:21:45 -------- d-----w- c:\program files\common files\Deterministic Networks
2011-04-10 19:21:34 -------- d-----w- c:\program files\Cisco Systems
2011-04-10 15:50:32 -------- d-----w- C:\Downloads
2011-04-10 15:48:28 -------- d-----w- c:\users\giridhar\appdata\local\FileServe Manager
2011-04-10 15:47:46 -------- d-----w- c:\program files\FileServe Manager
2011-04-10 15:47:46 -------- d-----w- c:\progra~2\FileServe Limited
2011-04-04 23:19:46 -------- d-----w- c:\program files\common files\iSpirit
2011-04-04 23:11:22 -------- d-----w- c:\users\giridhar\appdata\roaming\Free Download Manager
2011-04-04 23:11:15 -------- d-----w- c:\progra~2\FreeDownloadManager.ORG
2011-04-04 23:11:14 -------- d-----w- c:\program files\Free Download Manager
2011-04-03 14:59:09 -------- d-----w- c:\program files\QuoteTracker
2011-04-03 12:31:54 57056 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\pdfico.exe
2011-04-03 12:31:53 52960 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\sysaxico.exe
2011-04-03 12:31:53 52960 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\htmico.exe
2011-04-03 12:31:53 48864 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\chmico.exe
2011-04-03 12:31:38 -------- d-----w- c:\program files\SysaxServer
2011-04-03 12:31:38 -------- d-----w- c:\progra~2\Codeorigin
2011-04-03 00:06:27 -------- d-----w- c:\windows\system32\SPReview
2011-04-03 00:05:10 -------- d-----w- c:\windows\system32\EventProviders
2011-04-02 23:53:59 508904 ----a-w- c:\windows\system32\winload.exe
2011-04-02 23:52:59 67584 ----a-w- c:\windows\system32\certprop.dll
2011-04-02 23:51:35 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-04-02 23:51:35 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-04-02 23:51:35 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-04-02 23:51:34 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-02 23:51:09 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-04-02 23:50:51 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-02 23:50:51 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-04-02 23:49:42 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-04-02 23:49:41 257024 ----a-w- c:\windows\system32\dpx.dll
2011-04-02 23:06:34 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-02 22:58:53 -------- d-----w- c:\windows\en
2011-04-02 22:58:13 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-04-02 22:52:41 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-04-02 22:52:41 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-04-02 22:52:41 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-04-02 20:13:03 15712 ----a-w- c:\program files\common files\windows live\.cache\5f2970321cbf17220\MeshBetaRemover.exe
2011-04-02 20:12:39 94040 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\DSETUP.dll
2011-04-02 20:12:39 525656 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\DXSETUP.exe
2011-04-02 20:12:39 1691480 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\dsetup32.dll
2011-04-02 20:12:37 525656 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\DXSETUP.exe
2011-04-02 20:12:36 94040 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\DSETUP.dll
2011-04-02 20:12:36 1691480 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\dsetup32.dll
2011-04-02 20:11:33 -------- d-----w- c:\users\giridhar\appdata\local\Windows Live
2011-03-31 23:11:26 -------- d-----w- C:\Perl
2011-03-31 22:35:56 -------- d-----w- C:\Python27
2011-03-31 07:23:32 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-30 20:26:38 -------- d-----w- c:\program files\Veoh_Web_Player
2011-03-30 20:26:11 -------- d-----w- c:\program files\Veoh Networks
2011-03-29 18:52:12 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-03-29 18:52:12 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-03-29 18:52:11 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-03-28 19:48:07 -------- d-----w- c:\program files\Haali
2011-03-28 19:43:58 -------- d-----w- c:\program files\CoreCodec
2011-03-27 18:55:58 59904 ----a-w- c:\windows\system32\OVDecode.dll
2011-03-27 18:55:24 12385280 ----a-w- c:\windows\system32\amdocl.dll
2011-03-27 18:30:29 -------- d-----w- c:\users\giridhar\FAH
2011-03-27 13:07:53 -------- d-----w- c:\users\giridhar\appdata\roaming\Helios
2011-03-27 13:07:41 -------- d-----w- c:\program files\TextPad 5
2011-03-27 10:38:42 -------- d-----w- c:\users\giridhar\appdata\roaming\Folding@home-gpu
.
==================== Find3M ====================
.
2011-04-03 00:15:08 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-03-25 18:39:10 8114 ----a-w- c:\progra~2\xml982A.tmp
2011-03-25 18:39:10 2263 ----a-w- c:\progra~2\xml9DF6.tmp
2011-03-25 18:39:10 14007 ----a-w- c:\progra~2\xml9D4A.tmp
2011-03-15 05:01:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2011-03-11 05:33:59 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-08 05:28:29 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 05:38:01 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:36:16 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-24 05:38:54 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-19 06:30:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 04:34:54 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 16:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-12 05:35:31 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-02-07 10:48:26 353280 ----a-w- c:\windows\system32\pythoncom27.dll
2011-02-07 10:48:26 109568 ----a-w- c:\windows\system32\pywintypes27.dll
2011-02-07 10:48:22 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-07 10:47:56 2431488 ----a-w- c:\windows\system32\python27.dll
2011-01-26 23:00:44 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2011-01-26 23:00:30 596480 ----a-w- c:\windows\system32\aticfx32.dll
2011-01-26 22:59:46 17204736 ----a-w- c:\windows\system32\atioglxx.dll
2011-01-26 22:56:30 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-26 22:55:54 393216 ----a-w- c:\windows\system32\atieclxx.exe
2011-01-26 22:55:24 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-01-26 22:54:10 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-01-26 22:53:54 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-01-26 22:53:42 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-26 22:53:34 15872 ----a-w- c:\windows\system32\atimuixx.dll
2011-01-26 22:53:26 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-01-26 22:49:44 4105728 ----a-w- c:\windows\system32\atidxx32.dll
2011-01-26 22:32:12 1912832 ----a-w- c:\windows\system32\atiumdmv.dll
2011-01-26 22:28:52 4170752 ----a-w- c:\windows\system32\atiumdag.dll
2011-01-26 22:27:50 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-01-26 22:27:40 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-01-26 22:25:50 5580800 ----a-w- c:\windows\system32\aticaldd.dll
2011-01-26 22:24:18 3463680 ----a-w- c:\windows\system32\atiumdva.dll
2011-01-26 22:20:44 52736 ----a-w- c:\windows\system32\coinst.dll
2011-01-26 22:14:06 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-26 22:13:52 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-01-26 22:13:42 32768 ----a-w- c:\windows\system32\atigktxx.dll
2011-01-26 22:12:40 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2011-01-26 22:12:24 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2011-01-26 22:08:40 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-01-26 22:08:40 52736 ----a-w- c:\windows\system32\amdpcom32.dll
.
============= FINISH: 19:42:20.98 ===============
Attach log
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 25/03/2011 14:09:58
System Uptime: 25/04/2011 18:44:16 (1 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | R425/R525
Processor: AMD Athlon(tm) II Dual-Core M340 | Socket S1G3 | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 99 GiB total, 65.4 GiB free.
D: is FIXED (NTFS) - 184 GiB total, 146.912 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
==== System Restore Points ===================
.
RP71: 25/04/2011 14:35:53 - Installed calibre
RP72: 25/04/2011 14:47:06 - Windows Update
RP73: 25/04/2011 14:49:39 - Restore Operation
RP74: 25/04/2011 15:11:18 - Installed calibre
RP75: 25/04/2011 15:14:48 - Windows Update
RP76: 25/04/2011 15:18:36 - avast! Free Antivirus Setup
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
7-Zip 9.20
ActivePerl 5.12.3 Build 1204
ActiveState ActivePython 2.7.1.4 (32-bit)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Alice Greenfingers
AMD APP KernelAnalyzer 1.8
AMD APP Profiler 2.2
AMD APP SDK Developer
AMD APP SDK Runtime
AMD APP SDK Samples
AMD Fuel
AMD USB Filter Driver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Atheros Client Installation Program
ATI Catalyst Install Manager
µTorrent
avast! Free Antivirus
BatteryLifeExtender
Bing Bar
Bing Bar Platform
Bing Rewards Client Installer
Bonbon Quest
Bonjour
Cake Mania
calibre
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help English
Cisco Systems VPN Client 5.0.04.0300
Compatibility Pack for the 2007 Office system
Conduit Engine
CoreAVC Professional Edition (remove only)
CPUID CPU-Z 1.57
CyberLink DVD Suite
CyberLink LabelPrint
CyberLink Power2Go
CyberLink PowerDirector
CyberLink PowerDVD 8
CyberLink PowerProducer
CyberLink YouCam
D3DX10
Daycare Nightmare
Easy Display Manager
Easy Network Manager
Easy SpeedUp Manager
EasyBatteryManager
Exceed onDemand Client 6 (Web Deployed)
FileServe Manager 1.0.0.2428
Flip Words
Folding@home-gpu
Folding@home-x86
Fraps
Free Download Manager 3.0
Galapago
Game Pack
Gem Shop
Google Apps
Google Chrome
Google Desktop
Google Earth
Google Talk (remove only)
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GPU Caps Viewer 1.10.2
Haali Media Splitter
Hummingbird Component Deployment
Immunet Protect
Insaniquarium Deluxe
iTunes
Java Auto Updater
Java(TM) 6 Update 24
Junk Mail filter update
Mahjong Escape Ancient China
Malwarebytes' Anti-Malware
Marvell Miniport Driver
McAfee Security Scan Plus
McAfee SecurityCenter
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework 2.0 Core Components (x86) ENU
Microsoft Sync Framework 2.0 Provider Services (x86) ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
Mozilla Firefox 4.0 (x86 en-GB)
MSVCRT
NovaBench 3.0.2
Picasa 3
PuTTY version 0.60
QuickTime
QuoteTracker
Realtek High Definition Audio Driver
runtime
Samsung Recovery Solution 4
Samsung Support Center
Samsung Update Plus
SamsungMovie
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2466156)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft Office Excel 2007 (KB2464583)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SiSoftware Sandra Lite 2011.SP1a
Skype™ 5.1
Slingo
Spyware Doctor with AntiVirus 8.0
Synaptics Pointing Device Driver
SyncToy 2.1 (x86)
Sysax Multi Server 5
TextPad 5
The KMPlayer (remove only)
TortoiseSVN 1.6.15.21042 (32 bit)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
User Guide
uTorrentBar Toolbar
Veoh Web Player
Veoh Web Player Toolbar
Vim 7.3 (self-installing)
VLC media player 1.1.9
WebM Media Foundation Components
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.00 (32-bit)
WMV9/VC-1 Video Playback
.
==== Event Viewer Messages From Past Week ========
.
25/04/2011 18:46:43, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
25/04/2011 17:09:09, Error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
25/04/2011 16:15:05, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
25/04/2011 16:13:29, Error: Service Control Manager [7022] - The avast! Antivirus service hung on starting.
25/04/2011 16:11:48, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.
25/04/2011 14:56:08, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
25/04/2011 14:54:25, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
25/04/2011 13:01:19, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0x9f1d7e18, 0x00000001, 0x87040002, 0x00000002). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 042511-23337-01.
24/04/2011 18:45:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AMD FUEL Service service.
24/04/2011 06:38:09, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
22/04/2011 17:55:06, Error: bowser [8003] - The master browser has received a server announcement from the computer SRINISLAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7E684EA2-C0E4-436E-B396-FFF82. The master browser is stopping or an election is being forced.
21/04/2011 15:36:15, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
21/04/2011 08:28:32, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
21/04/2011 08:26:37, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
21/04/2011 08:25:43, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McShield service.
20/04/2011 00:15:38, Error: Service Control Manager [7000] - The McShield service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
20/04/2011 00:15:37, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the McShield service to connect.
20/04/2011 00:12:13, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.
20/04/2011 00:12:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the mcmscsvc service.
.
==== End Of File ===========================
Please help me.
Regards,
Giri
Please help in fixing this problem.
I'm using win7 32 bit machine and my system got infected.
I followed the 8 step tutorial and generated logs.
My antivirus gives pop up message that w32.Crypt is quarantined (these messages did not stop)
I'm pasting my logs below.
Malwarebytes Anti-Malware log
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6443
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
25/04/2011 19:13:03
mbam-log-2011-04-25 (19-13-03).txt
Scan type: Quick scan
Objects scanned: 159516
Time elapsed: 14 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit quick scan 2011-04-25 19:21:33
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK3265GSX rev.GJ002F
Running: 4r91g79n.exe; Driver: C:\Users\giridhar\AppData\Local\Temp\kxldapod.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8B8720B8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8B8720CE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8B8720A4]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS log
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by giridhar at 19:37:30.36 on 25/04/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3070.1605 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
AV: Immunet Protect *Enabled/Updated* {E26D838D-778A-C93D-0B41-46E786995C11}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spyware Doctor *Enabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Immunet Protect\2.0.17\agent.exe
C:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\mfevtps.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\PC Tools Security\pctsAuxs.exe
C:\Program Files\PC Tools Security\pctsSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\Program Files\PC Tools Security\pctsGui.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Immunet Protect\2.0.17\iptray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\giridhar\Desktop\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uDefault_Page_URL = hxxp://samsung.msn.com
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
uURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
BHO: FileServeManager: {00000001-ab3b-4334-9da2-ec6b2a02afc6} - c:\program files\fileserve manager\FileServeBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110325201413.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: @c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: Veoh Web Player Toolbar: {cd90bf73-20f6-44ef-993d-bb920303bd2e} - c:\program files\veoh_web_player\tbVeoh.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [uTorrent] "c:\users\giridhar\downloads\utorrent.exe"
uRun: [Google Update] "c:\users\giridhar\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [googletalk] c:\users\giridhar\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [CLMLServer] "c:\program files\cyberlink\power2go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe"
mRun: [UpdatePPShortCut] "c:\program files\cyberlink\powerproducer\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerproducer" updatewithcreateonce "software\cyberlink\powerproducer\5.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ISTray] "c:\program files\pc tools security\pctsGui.exe" /hideGUI
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [FileServe Manager Task] "c:\program files\fileserve manager\FSStarter.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Immunet Protect] "c:\program files\immunet protect\2.0.17\iptray.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\giridhar\appdata\roaming\micros~1\windows\startm~1\programs\startup\foldin~1.lnk - c:\users\giridhar\appdata\roaming\microsoft\installer\{6a90c837-054e-44ae-b9bd-1b1f87986bbc}\_98830A63A82EB98D7BA198.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{51fb15f4-ad27-43bc-ad4b-dd0354fb6bbd}\Icon3E5562ED7.ico
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with FileServe Manager - c:\program files\fileserve manager\GetUrl.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\progra~1\google\google~3\GO36F4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\giridhar\appdata\roaming\mozilla\firefox\profiles\9dvu231c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2166.3772\npCIDetect14.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\msn toolbar\platform\6.0.2237.0\npwinext.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\giridhar\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\giridhar\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\giridhar\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-3-25 386840]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-3-25 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-3-25 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-3-25 656320]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-25 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-25 307288]
R1 ImmunetProtectDriver;ImmunetProtectDriver;c:\windows\system32\drivers\ImmunetProtect.sys [2011-4-25 41424]
R1 ImmunetSelfProtectDriver;ImmunetSelfProtectDriver;c:\windows\system32\drivers\ImmunetSelfProtect.sys [2011-4-25 31184]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2011-3-25 64304]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-3-25 164840]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsldbbae6b5;MpKsldbbae6b5;c:\programdata\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\MpKsldbbae6b5.sys [2011-4-25 28752]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-8-6 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-1-26 176128]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-1-26 284672]
R2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ati technologies\ati.ace\reservation manager\AMD Reservation Manager.exe [2010-6-17 140224]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-25 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-4-25 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-4-25 42184]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-3-25 22504]
R2 ImmunetProtect;Immunet Protect;c:\program files\immunet protect\2.0.17\agent.exe [2011-4-25 756680]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-8-6 203280]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2011-3-25 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-3-25 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-3-25 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-3-25 141792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-3-25 366840]
R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-3-25 1150936]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2011-3-25 37944]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-1-27 7566848]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-1-26 238592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-3-25 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-3-25 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-3-25 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-3-25 313288]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-6 30392]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-3-25 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-4-2 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2011-3-25 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-3-25 84264]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011.sp1a\RpcAgentSrv.exe [2011-3-25 93848]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-3 52224]
.
=============== Created Last 30 ================
.
2011-04-25 18:23:48 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\MpKsldbbae6b5.sys
2011-04-25 18:23:34 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0cc8de26-fb67-4006-a5c6-58e90b6570fa}\mpengine.dll
2011-04-25 17:57:32 -------- d-----w- c:\users\giridhar\appdata\roaming\Malwarebytes
2011-04-25 17:57:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-25 17:57:19 -------- d-----w- c:\progra~2\Malwarebytes
2011-04-25 17:57:13 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-25 17:57:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-25 15:03:53 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-25 14:23:37 -------- d-----w- c:\program files\common files\WebM Project
2011-04-25 14:20:46 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-25 14:19:59 40112 ----a-w- c:\windows\avastSS.scr
2011-04-25 14:19:33 -------- d-----w- c:\progra~2\Alwil Software
2011-04-25 14:16:05 439632 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{c42ba154-4657-4351-8aac-b948978a8e84}\gapaengine.dll
2011-04-25 14:16:05 -------- d-----w- c:\users\giridhar\appdata\local\Immunet
2011-04-25 14:16:05 -------- d-----w- c:\progra~2\Immunet
2011-04-25 14:15:40 31184 ----a-w- c:\windows\system32\drivers\ImmunetSelfProtect.sys
2011-04-25 14:15:34 41424 ----a-w- c:\windows\system32\drivers\ImmunetProtect.sys
2011-04-25 14:15:24 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-25 14:15:03 -------- d-----w- c:\program files\Immunet Protect
2011-04-25 14:09:13 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-25 11:47:41 -------- d-----w- c:\program files\Syser
2011-04-21 07:18:03 -------- d-----w- c:\users\giridhar\appdata\local\ElevatedDiagnostics
2011-04-20 23:17:24 -------- d-----w- c:\program files\common files\AMD
2011-04-20 23:16:41 -------- d-----w- c:\program files\AMD APP
2011-04-20 00:37:36 -------- d-----w- c:\users\giridhar\.vim-fuf-data
2011-04-19 23:41:08 -------- d-----w- c:\users\giridhar\appdata\roaming\Hummingbird
2011-04-19 23:41:08 -------- d-----w- c:\program files\Hummingbird
2011-04-16 14:04:28 -------- d-----w- c:\users\giridhar\cr3
2011-04-16 11:04:38 -------- d-----w- c:\users\giridhar\ChartNexus
2011-04-16 01:31:30 -------- d-----w- C:\ctags
2011-04-16 01:17:35 -------- d-----w- c:\program files\vim
2011-04-15 17:41:33 -------- d-----w- c:\users\giridhar\appdata\local\TSVNCache
2011-04-14 21:42:07 -------- d-----w- c:\users\giridhar\appdata\roaming\TortoiseSVN
2011-04-14 21:40:08 -------- d-----w- c:\users\giridhar\appdata\roaming\Subversion
2011-04-14 21:39:42 -------- d-----w- c:\program files\TortoiseSVN
2011-04-14 21:39:42 -------- d-----w- c:\program files\common files\TortoiseOverlays
2011-04-14 21:27:38 -------- d-----w- c:\users\giridhar\.idlerc
2011-04-13 21:25:49 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-13 21:25:49 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-13 21:25:49 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-13 21:25:02 2333184 ----a-w- c:\windows\system32\win32k.sys
2011-04-10 22:30:05 -------- d-----w- c:\program files\SyncToy 2.1
2011-04-10 22:20:38 -------- d-----w- c:\users\giridhar\appdata\roaming\calibre
2011-04-10 22:17:46 -------- d-----w- c:\program files\Calibre2
2011-04-10 19:22:38 125328 ----a-w- c:\windows\system32\drivers\dne2000.sys
2011-04-10 19:22:38 106768 ----a-w- c:\windows\system32\dneinobj.dll
2011-04-10 19:21:45 -------- d-----w- c:\program files\common files\Deterministic Networks
2011-04-10 19:21:34 -------- d-----w- c:\program files\Cisco Systems
2011-04-10 15:50:32 -------- d-----w- C:\Downloads
2011-04-10 15:48:28 -------- d-----w- c:\users\giridhar\appdata\local\FileServe Manager
2011-04-10 15:47:46 -------- d-----w- c:\program files\FileServe Manager
2011-04-10 15:47:46 -------- d-----w- c:\progra~2\FileServe Limited
2011-04-04 23:19:46 -------- d-----w- c:\program files\common files\iSpirit
2011-04-04 23:11:22 -------- d-----w- c:\users\giridhar\appdata\roaming\Free Download Manager
2011-04-04 23:11:15 -------- d-----w- c:\progra~2\FreeDownloadManager.ORG
2011-04-04 23:11:14 -------- d-----w- c:\program files\Free Download Manager
2011-04-03 14:59:09 -------- d-----w- c:\program files\QuoteTracker
2011-04-03 12:31:54 57056 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\pdfico.exe
2011-04-03 12:31:53 52960 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\sysaxico.exe
2011-04-03 12:31:53 52960 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\htmico.exe
2011-04-03 12:31:53 48864 ----a-r- c:\users\giridhar\appdata\roaming\microsoft\installer\{748fbfc5-9d60-4058-9136-a862af552cc2}\chmico.exe
2011-04-03 12:31:38 -------- d-----w- c:\program files\SysaxServer
2011-04-03 12:31:38 -------- d-----w- c:\progra~2\Codeorigin
2011-04-03 00:06:27 -------- d-----w- c:\windows\system32\SPReview
2011-04-03 00:05:10 -------- d-----w- c:\windows\system32\EventProviders
2011-04-02 23:53:59 508904 ----a-w- c:\windows\system32\winload.exe
2011-04-02 23:52:59 67584 ----a-w- c:\windows\system32\certprop.dll
2011-04-02 23:51:35 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-04-02 23:51:35 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-04-02 23:51:35 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-04-02 23:51:34 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-02 23:51:09 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-04-02 23:50:51 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-02 23:50:51 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-04-02 23:49:42 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-04-02 23:49:41 257024 ----a-w- c:\windows\system32\dpx.dll
2011-04-02 23:06:34 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-02 22:58:53 -------- d-----w- c:\windows\en
2011-04-02 22:58:13 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-04-02 22:52:41 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-04-02 22:52:41 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-04-02 22:52:41 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-04-02 20:13:03 15712 ----a-w- c:\program files\common files\windows live\.cache\5f2970321cbf17220\MeshBetaRemover.exe
2011-04-02 20:12:39 94040 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\DSETUP.dll
2011-04-02 20:12:39 525656 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\DXSETUP.exe
2011-04-02 20:12:39 1691480 ----a-w- c:\program files\common files\windows live\.cache\5022050c1cbf17218\dsetup32.dll
2011-04-02 20:12:37 525656 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\DXSETUP.exe
2011-04-02 20:12:36 94040 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\DSETUP.dll
2011-04-02 20:12:36 1691480 ----a-w- c:\program files\common files\windows live\.cache\4e05acd31cbf17217\dsetup32.dll
2011-04-02 20:11:33 -------- d-----w- c:\users\giridhar\appdata\local\Windows Live
2011-03-31 23:11:26 -------- d-----w- C:\Perl
2011-03-31 22:35:56 -------- d-----w- C:\Python27
2011-03-31 07:23:32 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-30 20:26:38 -------- d-----w- c:\program files\Veoh_Web_Player
2011-03-30 20:26:11 -------- d-----w- c:\program files\Veoh Networks
2011-03-29 18:52:12 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-03-29 18:52:12 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-03-29 18:52:11 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-03-28 19:48:07 -------- d-----w- c:\program files\Haali
2011-03-28 19:43:58 -------- d-----w- c:\program files\CoreCodec
2011-03-27 18:55:58 59904 ----a-w- c:\windows\system32\OVDecode.dll
2011-03-27 18:55:24 12385280 ----a-w- c:\windows\system32\amdocl.dll
2011-03-27 18:30:29 -------- d-----w- c:\users\giridhar\FAH
2011-03-27 13:07:53 -------- d-----w- c:\users\giridhar\appdata\roaming\Helios
2011-03-27 13:07:41 -------- d-----w- c:\program files\TextPad 5
2011-03-27 10:38:42 -------- d-----w- c:\users\giridhar\appdata\roaming\Folding@home-gpu
.
==================== Find3M ====================
.
2011-04-03 00:15:08 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-03-25 18:39:10 8114 ----a-w- c:\progra~2\xml982A.tmp
2011-03-25 18:39:10 2263 ----a-w- c:\progra~2\xml9DF6.tmp
2011-03-25 18:39:10 14007 ----a-w- c:\progra~2\xml9D4A.tmp
2011-03-15 05:01:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2011-03-11 05:33:59 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-03-08 05:28:29 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 05:38:01 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:36:16 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-24 05:38:54 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-19 06:30:46 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 04:34:54 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 16:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-12 05:35:31 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-02-07 10:48:26 353280 ----a-w- c:\windows\system32\pythoncom27.dll
2011-02-07 10:48:26 109568 ----a-w- c:\windows\system32\pywintypes27.dll
2011-02-07 10:48:22 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-07 10:47:56 2431488 ----a-w- c:\windows\system32\python27.dll
2011-01-26 23:00:44 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2011-01-26 23:00:30 596480 ----a-w- c:\windows\system32\aticfx32.dll
2011-01-26 22:59:46 17204736 ----a-w- c:\windows\system32\atioglxx.dll
2011-01-26 22:56:30 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-26 22:55:54 393216 ----a-w- c:\windows\system32\atieclxx.exe
2011-01-26 22:55:24 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2011-01-26 22:54:10 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2011-01-26 22:53:54 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2011-01-26 22:53:42 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-26 22:53:34 15872 ----a-w- c:\windows\system32\atimuixx.dll
2011-01-26 22:53:26 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-01-26 22:49:44 4105728 ----a-w- c:\windows\system32\atidxx32.dll
2011-01-26 22:32:12 1912832 ----a-w- c:\windows\system32\atiumdmv.dll
2011-01-26 22:28:52 4170752 ----a-w- c:\windows\system32\atiumdag.dll
2011-01-26 22:27:50 46080 ----a-w- c:\windows\system32\aticalrt.dll
2011-01-26 22:27:40 44032 ----a-w- c:\windows\system32\aticalcl.dll
2011-01-26 22:25:50 5580800 ----a-w- c:\windows\system32\aticaldd.dll
2011-01-26 22:24:18 3463680 ----a-w- c:\windows\system32\atiumdva.dll
2011-01-26 22:20:44 52736 ----a-w- c:\windows\system32\coinst.dll
2011-01-26 22:14:06 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-26 22:13:52 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2011-01-26 22:13:42 32768 ----a-w- c:\windows\system32\atigktxx.dll
2011-01-26 22:12:40 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2011-01-26 22:12:24 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2011-01-26 22:08:40 52736 ----a-w- c:\windows\system32\atimpc32.dll
2011-01-26 22:08:40 52736 ----a-w- c:\windows\system32\amdpcom32.dll
.
============= FINISH: 19:42:20.98 ===============
Attach log
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 25/03/2011 14:09:58
System Uptime: 25/04/2011 18:44:16 (1 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | R425/R525
Processor: AMD Athlon(tm) II Dual-Core M340 | Socket S1G3 | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 99 GiB total, 65.4 GiB free.
D: is FIXED (NTFS) - 184 GiB total, 146.912 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
==== System Restore Points ===================
.
RP71: 25/04/2011 14:35:53 - Installed calibre
RP72: 25/04/2011 14:47:06 - Windows Update
RP73: 25/04/2011 14:49:39 - Restore Operation
RP74: 25/04/2011 15:11:18 - Installed calibre
RP75: 25/04/2011 15:14:48 - Windows Update
RP76: 25/04/2011 15:18:36 - avast! Free Antivirus Setup
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
7-Zip 9.20
ActivePerl 5.12.3 Build 1204
ActiveState ActivePython 2.7.1.4 (32-bit)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Alice Greenfingers
AMD APP KernelAnalyzer 1.8
AMD APP Profiler 2.2
AMD APP SDK Developer
AMD APP SDK Runtime
AMD APP SDK Samples
AMD Fuel
AMD USB Filter Driver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Atheros Client Installation Program
ATI Catalyst Install Manager
µTorrent
avast! Free Antivirus
BatteryLifeExtender
Bing Bar
Bing Bar Platform
Bing Rewards Client Installer
Bonbon Quest
Bonjour
Cake Mania
calibre
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help English
Cisco Systems VPN Client 5.0.04.0300
Compatibility Pack for the 2007 Office system
Conduit Engine
CoreAVC Professional Edition (remove only)
CPUID CPU-Z 1.57
CyberLink DVD Suite
CyberLink LabelPrint
CyberLink Power2Go
CyberLink PowerDirector
CyberLink PowerDVD 8
CyberLink PowerProducer
CyberLink YouCam
D3DX10
Daycare Nightmare
Easy Display Manager
Easy Network Manager
Easy SpeedUp Manager
EasyBatteryManager
Exceed onDemand Client 6 (Web Deployed)
FileServe Manager 1.0.0.2428
Flip Words
Folding@home-gpu
Folding@home-x86
Fraps
Free Download Manager 3.0
Galapago
Game Pack
Gem Shop
Google Apps
Google Chrome
Google Desktop
Google Earth
Google Talk (remove only)
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GPU Caps Viewer 1.10.2
Haali Media Splitter
Hummingbird Component Deployment
Immunet Protect
Insaniquarium Deluxe
iTunes
Java Auto Updater
Java(TM) 6 Update 24
Junk Mail filter update
Mahjong Escape Ancient China
Malwarebytes' Anti-Malware
Marvell Miniport Driver
McAfee Security Scan Plus
McAfee SecurityCenter
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework 2.0 Core Components (x86) ENU
Microsoft Sync Framework 2.0 Provider Services (x86) ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Works
Mozilla Firefox 4.0 (x86 en-GB)
MSVCRT
NovaBench 3.0.2
Picasa 3
PuTTY version 0.60
QuickTime
QuoteTracker
Realtek High Definition Audio Driver
runtime
Samsung Recovery Solution 4
Samsung Support Center
Samsung Update Plus
SamsungMovie
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2466156)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft Office Excel 2007 (KB2464583)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2464594)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SiSoftware Sandra Lite 2011.SP1a
Skype™ 5.1
Slingo
Spyware Doctor with AntiVirus 8.0
Synaptics Pointing Device Driver
SyncToy 2.1 (x86)
Sysax Multi Server 5
TextPad 5
The KMPlayer (remove only)
TortoiseSVN 1.6.15.21042 (32 bit)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
User Guide
uTorrentBar Toolbar
Veoh Web Player
Veoh Web Player Toolbar
Vim 7.3 (self-installing)
VLC media player 1.1.9
WebM Media Foundation Components
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.00 (32-bit)
WMV9/VC-1 Video Playback
.
==== Event Viewer Messages From Past Week ========
.
25/04/2011 18:46:43, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
25/04/2011 17:09:09, Error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
25/04/2011 16:15:05, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
25/04/2011 16:13:29, Error: Service Control Manager [7022] - The avast! Antivirus service hung on starting.
25/04/2011 16:11:48, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.
25/04/2011 14:56:08, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
25/04/2011 14:54:25, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
25/04/2011 13:01:19, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0x9f1d7e18, 0x00000001, 0x87040002, 0x00000002). A dump was saved in: C:\windows\MEMORY.DMP. Report Id: 042511-23337-01.
24/04/2011 18:45:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AMD FUEL Service service.
24/04/2011 06:38:09, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
22/04/2011 17:55:06, Error: bowser [8003] - The master browser has received a server announcement from the computer SRINISLAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7E684EA2-C0E4-436E-B396-FFF82. The master browser is stopping or an election is being forced.
21/04/2011 15:36:15, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
21/04/2011 08:28:32, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
21/04/2011 08:26:37, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
21/04/2011 08:25:43, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McShield service.
20/04/2011 00:15:38, Error: Service Control Manager [7000] - The McShield service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
20/04/2011 00:15:37, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the McShield service to connect.
20/04/2011 00:12:13, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.
20/04/2011 00:12:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the mcmscsvc service.
.
==== End Of File ===========================
Please help me.
Regards,
Giri