Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Problem removing Tidserv.Activity.2


  • Please log in to reply

#76
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Also a request from one of the gurus on the forum to uninstall IE9 so that it reverts to IE8.

Ron
  • 0

Advertisements


#77
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Running Combofix. As soon as it is done and I reboot, I will uninstall IE9
  • 0

#78
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Not sure what Combofix did, but I am at least able to connect with IE9 right now. Not out of the woods yet, because there are still some issues, but things are looking a bit better.

Here is the log file from ComboFix:

ComboFix 11-10-10.01 - Tim 10/11/2011 14:01:08.4.2 - x64
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.4062.2327 [GMT -5:00]
Running from: d:\downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\users\Tim\Opera_1151_int_Setup.exe
c:\windows\assembly\tmp\U
.
.
((((((((((((((((((((((((( Files Created from 2011-09-11 to 2011-10-11 )))))))))))))))))))))))))))))))
.
.
2011-10-11 19:14 . 2011-10-11 19:14 -------- d-----w- c:\users\tedins\AppData\Local\temp
2011-10-11 19:14 . 2011-10-11 19:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-11 19:14 . 2011-10-11 19:14 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2011-10-11 18:57 . 2011-10-11 18:57 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0C4D95AB-E25A-4F62-8BEB-14BC44DEB1EE}\offreg.dll
2011-10-11 02:28 . 2011-10-11 02:28 -------- d-----w- c:\users\Tim\AppData\Local\Opera
2011-10-11 02:28 . 2011-10-11 02:28 -------- d-----w- c:\program files (x86)\Opera
2011-10-10 23:49 . 2011-10-10 23:49 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72B1D00D-E847-40CB-85B3-1C73051469D7}\gapaengine.dll
2011-10-10 23:49 . 2011-09-12 22:26 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0C4D95AB-E25A-4F62-8BEB-14BC44DEB1EE}\mpengine.dll
2011-10-10 23:42 . 2011-10-10 23:42 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-10-10 23:42 . 2011-10-10 23:42 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-10 23:41 . 2010-04-06 08:34 345984 ----a-w- c:\windows\system32\drivers\netio.sys
2011-10-10 19:46 . 2011-10-10 19:46 -------- d-----w- c:\users\Tim\AppData\Local\CrashDumps
2011-10-10 19:12 . 2011-10-10 19:12 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-10-10 16:28 . 2011-10-10 16:28 -------- d-----w- c:\programdata\Malwarebytes
2011-10-09 23:13 . 2011-10-10 01:08 -------- d-----w- c:\users\Tim\AppData\Local\NPE
2011-10-09 19:32 . 2010-08-21 04:59 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-10-09 19:29 . 2011-10-10 18:21 -------- d-----w- c:\programdata\Norton
2011-10-09 17:52 . 2011-10-11 03:52 -------- d-----w- c:\users\Tim\AppData\Roaming\QuickScan
2011-10-09 14:25 . 2011-10-09 14:25 -------- d-----w- C:\found.000
2011-10-07 14:34 . 2011-10-07 14:33 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-10-07 14:28 . 2011-10-10 15:15 -------- d-----w- c:\programdata\Lavasoft
2011-10-07 13:34 . 2011-10-07 13:34 25160 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-10-07 13:34 . 2011-10-07 13:34 -------- d-----w- c:\programdata\Hitman Pro
2011-10-07 12:35 . 2011-09-21 14:00 9049936 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{ABD3A28E-F82C-40CD-B3CB-9B912AFECB36}\mpengine.dll
2011-09-30 21:26 . 2011-09-30 21:26 -------- d-----w- c:\program files\iPod
2011-09-30 21:26 . 2011-09-30 21:28 -------- d-----w- c:\program files\iTunes
2011-09-30 19:36 . 2011-09-30 19:36 -------- d-----w- c:\users\Tim\AppData\Roaming\AVG2012
2011-09-30 19:35 . 2011-10-04 14:10 -------- d-----w- c:\programdata\AVG2012
2011-09-30 18:03 . 2011-09-30 18:03 -------- d-----w- c:\users\Tim\AppData\Roaming\Intel
2011-09-30 17:33 . 2011-09-30 17:33 -------- d-----w- c:\users\Default\AppData\Roaming\Apple Computer
2011-09-30 17:33 . 2011-09-30 17:33 -------- d-----w- c:\users\Default\AppData\Local\Apple Computer
2011-09-30 13:53 . 2009-08-20 04:50 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2011-09-30 00:29 . 2011-09-29 06:53 134104 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2011-09-25 15:38 . 2011-09-25 15:38 -------- d-----w- C:\Update
2011-09-25 14:48 . 2011-09-25 15:01 -------- d-----w- c:\users\Tim\AppData\Roaming\Auslogics
2011-09-19 19:07 . 2008-08-08 07:09 108032 ----a-w- c:\windows\system32\E_ILMFCA.DLL
2011-09-19 19:07 . 2007-12-07 07:01 81408 ----a-w- c:\windows\system32\E_IBCBFCA.DLL
2011-09-19 19:01 . 2006-10-20 05:10 80024 ----a-w- c:\windows\SysWow64\PICSDK.dll
2011-09-19 19:01 . 2006-10-20 05:10 501912 ----a-w- c:\windows\SysWow64\PICSDK2.dll
2011-09-19 19:01 . 2006-10-31 05:10 51360 ----a-w- c:\windows\SysWow64\EpPicPrt.dll
2011-09-19 19:01 . 2006-10-31 05:10 51360 ----a-w- c:\windows\SysWow64\EpPicMgr.dll
2011-09-19 19:01 . 2006-10-20 05:10 108704 ----a-w- c:\windows\SysWow64\PICEntry.dll
2011-09-19 19:01 . 2011-09-30 19:50 -------- d-----w- c:\programdata\EPSON
2011-09-19 18:59 . 2011-09-30 14:29 -------- d-----w- c:\program files (x86)\epson
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-11 01:46 . 2010-12-24 17:06 8892928 ----a-w- c:\programdata\atscie.msi
2011-10-10 19:11 . 2010-07-10 16:17 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-04 19:39 . 2011-06-25 03:16 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-31 22:00 . 2010-07-01 19:54 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-25 02:53 . 2011-08-25 02:53 56408 ----a-w- c:\windows\system32\drivers\stdriver64.sys
2011-07-22 05:42 . 2011-08-11 04:27 2303488 ----a-w- c:\windows\system32\jscript9.dll
2011-07-22 05:36 . 2011-08-11 04:27 1389056 ----a-w- c:\windows\system32\wininet.dll
2011-07-22 05:32 . 2011-08-11 04:27 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-22 02:54 . 2011-08-11 04:27 1797632 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-07-22 02:48 . 2011-08-11 04:27 1126912 ----a-w- c:\windows\SysWow64\wininet.dll
2011-07-22 02:44 . 2011-08-11 04:27 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-08-20 152064]
"Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"VMpTtray.exe"="c:\program files (x86)\Sony\VAIO Media plus\VMpTtray.exe" [2008-05-25 86016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]
"VAIORegistration"="c:\program files\Sony\First Experience\WelcomeLauncher.exe" [2008-06-26 16384]
"VAIOSurvey"="c:\program files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe" [2008-07-25 385024]
"VWLASU"="c:\program files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe" [2008-05-20 24576]
"AML"="c:\program files (x86)\Sony\VAIO Launcher\AML.exe" [2008-06-13 1097728]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-09-07 40376]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Lexmark S300-S400 Series"="c:\program files (x86)\Lexmark S300-S400 Series\fm3032.exe" [2011-01-24 316072]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="d:\joans itunes\iTunesHelper.exe" [2011-08-19 421736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe" [2010-07-15 231888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AVer HID Receiver.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2010-11-30 159744]
AVerQuick.lnk - c:\program files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-11-30 679936]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-21 1048616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-07-29 00:45 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-839522115-1390067357-682003330-1224\Scripts\Logon\0\0]
"Script"=LOGON.BAT
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-839522115-1390067357-682003330-1224\Scripts\Logon\1\0]
"Script"=logonhelper.bat
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxeaserv.exe [2010-04-14 45736]
R3 AVerFx2hbtv64;AVerMedia USB Pure ATSC Tuner;c:\windows\system32\drivers\AVerFx2hbtv64.sys [x]
R3 DIRECTIO;DIRECTIO;H:\DirectIo.sys [x]
R3 echo1394;Onyx F Series service;c:\windows\system32\Drivers\echo1394.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;d:\adaware\KernExplorer64.sys [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 RoxMediaDBVHS;RoxMediaDBVHS;c:\program files (x86)\Common Files\Roxio Shared\VHStoDVD\SharedCOM\RoxMediaDBVHS.exe [2010-02-19 1116656]
R3 SampleCollector;Intel® Sample Collector;c:\program files\Sony\VAIO Care\collsvc.exe [2008-09-29 167424]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2008-06-12 107808]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S2 atashost;WebEx Service Host for Support Center;c:\windows\SysWOW64\atashost.exe [2009-03-06 20376]
S2 AVerRemote;AVerRemote;c:\program files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2008-06-08 352256]
S2 AVerScheduleService;AVerScheduleService;c:\program files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-10-17 409600]
S2 dlbk_device;dlbk_device;c:\windows\system32\dlbkcoms.exe [x]
S2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe [2010-04-14 1052328]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
S2 RtkAudioService;Realtek Audio Service;c:\windows\RtkAudioService.exe [2008-07-13 133120]
S2 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Sony\VAIO Media plus\SOHCImp.exe [2008-05-21 103712]
S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Sony\VAIO Media plus\SOHDms.exe [2008-05-21 353568]
S2 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Sony\VAIO Media plus\SOHDs.exe [2008-05-21 62752]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2008-03-25 104960]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2008-08-07 407392]
S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2008-06-20 415744]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-06-12 337184]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 AVerAVF2;AVerAVF2;c:\windows\system32\DRIVERS\AVerAVF2.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x]
S3 JMCR_CFS;JMCR_CFS;c:\windows\system32\DRIVERS\jmcr_cfs.sys [x]
S3 NETw5v64;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;c:\windows\system32\DRIVERS\NETw5v64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [x]
S3 stdriver;Sound tap driver Upper Class Filter Driver v2.0.0.0;c:\windows\system32\DRIVERS\stdriver64.sys [x]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-27 20:48]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2008-06-19 20:00 3380736 ----a-w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2008-06-19 20:00 3380736 ----a-w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RAVCpl64.exe" [2008-07-13 6407200]
"Skytel"="Skytel.exe" [2008-07-13 1826816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-20 1220392]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2008-06-19 66824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-09 15867936]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-09 82464]
"lxeamon.exe"="c:\program files (x86)\Lexmark S300-S400 Series\lxeamon.exe" [2011-01-24 770728]
"EzPrint"="c:\program files (x86)\Lexmark S300-S400 Series\ezprint.exe" [2011-01-24 148280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.atssb.org/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1 192.168.2.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\bzm625f8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.atssb.org
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Notify-psfus - (no file)
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\collsvc.exe\" \"/service\" \"/counter=\Processor(_Total)\% Processor Time:5\" \"/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:5\" \"/counter=\Network Interface(*)\Bytes Total/sec:5\" \"/directory=inteldata\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90,
43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}"=hex:51,66,7a,6c,4c,1d,38,12,62,ab,04,
14,3b,21,26,00,d7,5b,ae,96,a9,cb,61,e4
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{53707962-6F74-2D53-2644-206D7942484F}"=hex:51,66,7a,6c,4c,1d,38,12,0c,7a,63,
57,46,21,3d,68,59,52,63,2d,7c,1c,0c,5b
"{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}"=hex:51,66,7a,6c,4c,1d,38,12,da,39,34,
5d,e1,a9,97,05,de,be,2c,e9,c9,ff,c2,38
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f,
aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04
"{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}"=hex:51,66,7a,6c,4c,1d,38,12,2d,dd,7a,
ab,6a,33,56,03,c9,ec,8d,26,b0,f3,64,49
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}"=hex:51,66,7a,6c,4c,1d,38,12,7e,e6,d6,
d6,5f,f0,a2,07,e0,77,a7,b9,3c,59,c0,60
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{E33CF602-D945-461A-83F0-819F76A199F8}"=hex:51,66,7a,6c,4c,1d,38,12,6c,f5,2f,
e7,77,97,74,03,fc,e6,c2,df,73,ff,dd,ec
"{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84,
f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:53,29,eb,1d,7d,86,cc,01
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-10-11 14:36:29
ComboFix-quarantined-files.txt 2011-10-11 19:36
.
Pre-Run: 22,759,473,152 bytes free
Post-Run: 22,485,958,656 bytes free
.
- - End Of File - - 248A7AF48205CFE4F34AE8207272F40E
  • 0

#79
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
At this point, IE9 is the ONLY program that is working network-wise. Opera, Firefox, Seamonkey are all still not connecting.
  • 0

#80
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Progress anyway.

Use IE and go to http://eset.com/onlinescan and click on ESET online Scanner. Accept the terms then press Start (If you get a warning from your browser tell it you want to run it).

# Check Scan Archives
# Push the Start button.
# ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
# When the scan completes, push LIST OF THREATS FOUND
# Push EXPORT TO TEXT FILE , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
# Push the BACK button.
# Push Finish
# Once the scan is completed, you may close the window.
# Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
# Copy and paste that log as a reply.


Let's also try the bitdefender quickscan.

http://quickscan.bitdefender.com/

When it finishes there is a report option. Click on it and copy and paste the report (even if it says nothing found).

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs. Right click on System and Clear Log, Clear. Repeat for Application. Reboot.


Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Ron
  • 0

#81
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
The ESET software cannot gain access to update itself.
  • 0

#82
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
One side note. It appears that the ONLY IE9 that will work is listed as specific 64 bit.
  • 0

#83
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Sometimes it helps to start IE by right clicking and Run As Administrator but you can't do that from the Icon. You have to do Start, Programs, then right click on Internet Explorer and Run As Administrator.

IF it won't work then try the bitdefender.

See if you are able to download DDS from http://download.blee...om/sUBs/dds.com or http://download.blee...om/sUBs/dds.scr
and save it to your desktop.

* Disable any script blocking protection
* Double click dds.pif to run the tool.
* When done, two DDS.txt's will open.
* Save both reports to your desktop.

---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

If that won't work then go on with the other stuff. Let's add a new OTL quickscan to the list.

Ron
  • 0

#84
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Opening IE and running as admin didnt work.... tried running Bit Defender, and it has crashed IE twice.
  • 0

#85
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Go on with the other stuff then. When you finish that download a new copy of TDSSKiller and run it and post the log.

Also run MBAM (let it update first if it can)

See if you can download the free Avast.

http://www.avast.com...ivirus-download

Download, Save to your desktop.

Uninstall Microsoft Security Essentials

reboot. Then right click on the avast installer and Run As Administrator.

Once you have it installed and it has updated:

Click on the Avast ball. Then click on Scan Computer, then on
Boot-Time Scan then on Settings. Change the Ask at the bottom to Move to Chest. OK then Schedule Now. Reboot and let it run a scan. It may take hours.
Once it finishes it should load windows. Click on the Avast ball and then on Scan Logs, select the Boot-time scan report then View Results. How many did it find?
Look in C:\ProgramData\Alwil Software\Avast5\report\aswboot.txt and that should be a text version you can copy and paste into a reply.

I'm going to be away from the PC for a few hours but that should keep you busy until I get back.

Ron
  • 0

Advertisements


#86
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Here is the first DDS log

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_27
Run by Tim at 16:12:22 on 2011-10-11
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.4062.2080 [GMT -5:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\RtkAudioService.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\atashost.exe
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\system32\dlbkcoms.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Windows\system32\lxeacoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe
C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe
C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Lexmark S300-S400 Series\lxeamon.exe
C:\Program Files (x86)\Lexmark S300-S400 Series\ezprint.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Sony\VAIO Media plus\VMpTtray.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Protector Suite QL\psqltray.exe
D:\Joans Itunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\Sony\VAIO Care\VCsystray.exe
C:\Windows\splwow64.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.atssb.org/
uInternet Settings,ProxyOverride = *.local;<local>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - C:\Program Files\Lexmark Toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - C:\Program Files\Lexmark Toolbar\toolband.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet
uRun: [VMpTtray.exe] C:\Program Files (x86)\Sony\VAIO Media plus\VMpTtray.exe
mRun: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
mRun: [VAIORegistration] "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
mRun: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
mRun: [VWLASU] "C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe"
mRun: [AML] "C:\Program Files (x86)\Sony\VAIO Launcher\AML.exe" InitApp
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun: [Lexmark S300-S400 Series] "C:\Program Files (x86)\Lexmark S300-S400 Series\fm3032.exe" /s
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "D:\Joans Itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe -update activex
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERHI~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AVERQU~1.LNK - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1 192.168.2.1
TCP: Interfaces\{7702BF8E-EF73-483D-A40E-5A2B1BD30996} : DhcpNameServer = 192.168.0.1 192.168.2.1
TCP: Interfaces\{EB5C9DDC-490A-458A-B066-3F6C53B032A2} : DhcpNameServer = 192.168.0.1 192.168.2.1
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
Notify: VESWinlogon - VESWinlogon.dll
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
BHO-X64: Lexmark Printable Web: {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: Lexmark Toolbar: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
mRun-x64: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
mRun-x64: [VAIORegistration] "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
mRun-x64: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
mRun-x64: [VWLASU] "C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe"
mRun-x64: [AML] "C:\Program Files (x86)\Sony\VAIO Launcher\AML.exe" InitApp
mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
mRun-x64: [Lexmark S300-S400 Series] "C:\Program Files (x86)\Lexmark S300-S400 Series\fm3032.exe" /s
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "D:\Joans Itunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\aut1oevv.default\
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 atashost;WebEx Service Host for Support Center;C:\Windows\SysWOW64\atashost.exe [2010-12-24 20376]
R2 AVerRemote;AVerRemote;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [2010-11-30 352256]
R2 AVerScheduleService;AVerScheduleService;C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [2010-11-30 409600]
R2 dlbk_device;dlbk_device;C:\Windows\system32\dlbkcoms.exe -service --> C:\Windows\system32\dlbkcoms.exe -service [?]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 lxea_device;lxea_device;C:\Windows\system32\lxeacoms.exe -service --> C:\Windows\system32\lxeacoms.exe -service [?]
R2 regi;regi;\??\C:\Windows\system32\drivers\regi.sys --> C:\Windows\system32\drivers\regi.sys [?]
R2 RtkAudioService;Realtek Audio Service;C:\Windows\RTKAUDIOSERVICE.EXE [2008-8-20 133120]
R2 SOHCImp;VAIO Media plus Content Importer;C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe [2008-9-3 103712]
R2 SOHDms;VAIO Media plus Digital Media Server;C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe [2008-9-3 353568]
R2 SOHDs;VAIO Media plus Device Searcher;C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe [2008-9-3 62752]
R2 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2008-9-3 104960]
R2 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2008-8-20 407392]
R2 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2008-6-20 415744]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-9-3 337184]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys --> C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [?]
R3 AVerAVF2;AVerAVF2;C:\Windows\system32\DRIVERS\AVerAVF2.sys --> C:\Windows\system32\DRIVERS\AVerAVF2.sys [?]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 JMCR_CFS;JMCR_CFS;C:\Windows\system32\DRIVERS\jmcr_cfs.sys --> C:\Windows\system32\DRIVERS\jmcr_cfs.sys [?]
R3 NETw5v64;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys --> C:\Windows\system32\DRIVERS\SFEP.sys [?]
R3 stdriver;Sound tap driver Upper Class Filter Driver v2.0.0.0;C:\Windows\system32\DRIVERS\stdriver64.sys --> C:\Windows\system32\DRIVERS\stdriver64.sys [?]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x64.sys --> C:\Windows\system32\DRIVERS\yk60x64.sys [?]
S2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;C:\Windows\System32\spool\drivers\x64\3\lxeaserv.exe [2011-7-22 45736]
S3 AVerFx2hbtv64;AVerMedia USB Pure ATSC Tuner;C:\Windows\system32\drivers\AVerFx2hbtv64.sys --> C:\Windows\system32\drivers\AVerFx2hbtv64.sys [?]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-18 89920]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 RoxMediaDBVHS;RoxMediaDBVHS;C:\Program Files (x86)\Common Files\Roxio Shared\VHStoDVD\SharedCOM\RoxMediaDBVHS.exe [2010-2-19 1116656]
S3 SampleCollector;Intel® Sample Collector;C:\Program Files\Sony\VAIO Care\collsvc.exe [2009-6-22 167424]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2008-9-3 107808]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-10-11 20:41:14 -------- d-----w- C:\Program Files (x86)\ESET
2011-10-11 20:30:47 -------- d-sh--w- C:\$RECYCLE.BIN
2011-10-11 20:29:44 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0C4D95AB-E25A-4F62-8BEB-14BC44DEB1EE}\offreg.dll
2011-10-11 18:25:24 98816 ----a-w- C:\Windows\sed.exe
2011-10-11 18:25:24 518144 ----a-w- C:\Windows\SWREG.exe
2011-10-11 18:25:24 256000 ----a-w- C:\Windows\PEV.exe
2011-10-11 18:25:24 208896 ----a-w- C:\Windows\MBR.exe
2011-10-11 02:28:38 -------- d-----w- C:\Users\Tim\AppData\Local\Opera
2011-10-10 23:49:13 917840 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{72B1D00D-E847-40CB-85B3-1C73051469D7}\gapaengine.dll
2011-10-10 23:49:06 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0C4D95AB-E25A-4F62-8BEB-14BC44DEB1EE}\mpengine.dll
2011-10-10 23:42:15 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-10-10 23:42:04 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-10-10 23:41:38 345984 ----a-w- C:\Windows\System32\drivers\netio.sys
2011-10-10 19:46:06 -------- d-----w- C:\Users\Tim\AppData\Local\CrashDumps
2011-10-10 16:28:39 -------- d-----w- C:\ProgramData\Malwarebytes
2011-10-09 23:13:34 -------- d-----w- C:\Users\Tim\AppData\Local\NPE
2011-10-09 19:32:28 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-10-09 19:29:13 -------- d-----w- C:\ProgramData\Norton
2011-10-09 19:27:29 -------- d-----w- C:\ProgramData\NortonInstaller
2011-10-09 17:52:10 -------- d-----w- C:\Users\Tim\AppData\Roaming\QuickScan
2011-10-09 14:25:19 -------- d-----w- C:\found.000
2011-10-07 14:34:20 55384 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys
2011-10-07 13:34:36 25160 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys
2011-10-07 13:34:12 -------- d-----w- C:\ProgramData\Hitman Pro
2011-10-07 12:35:38 9049936 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ABD3A28E-F82C-40CD-B3CB-9B912AFECB36}\mpengine.dll
2011-09-30 21:26:37 -------- d-----w- C:\Program Files\iPod
2011-09-30 21:26:14 -------- d-----w- C:\Program Files\iTunes
2011-09-30 19:36:15 -------- d-----w- C:\Users\Tim\AppData\Roaming\AVG2012
2011-09-30 19:35:10 -------- d-----w- C:\ProgramData\AVG2012
2011-09-30 18:03:06 -------- d-----w- C:\Users\Tim\AppData\Roaming\Intel
2011-09-30 13:53:24 24416 ----a-r- C:\Windows\System32\AdobePDFUI.dll
2011-09-25 15:38:30 -------- d-----w- C:\Update
2011-09-25 14:48:20 -------- d-----w- C:\Users\Tim\AppData\Roaming\Auslogics
2011-09-19 19:07:33 81408 ----a-w- C:\Windows\System32\E_IBCBFCA.DLL
2011-09-19 19:07:33 108032 ----a-w- C:\Windows\System32\E_ILMFCA.DLL
2011-09-19 19:01:16 80024 ----a-w- C:\Windows\SysWow64\PICSDK.dll
2011-09-19 19:01:16 501912 ----a-w- C:\Windows\SysWow64\PICSDK2.dll
2011-09-19 19:01:15 51360 ----a-w- C:\Windows\SysWow64\EpPicPrt.dll
2011-09-19 19:01:15 51360 ----a-w- C:\Windows\SysWow64\EpPicMgr.dll
2011-09-19 19:01:15 108704 ----a-w- C:\Windows\SysWow64\PICEntry.dll
2011-09-19 19:01:03 -------- d-----w- C:\ProgramData\EPSON
2011-09-19 18:59:26 -------- d-----w- C:\Program Files (x86)\epson
.
==================== Find3M ====================
.
2011-10-11 01:46:56 8892928 ----a-w- C:\ProgramData\atscie.msi
2011-10-10 19:11:02 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-04 19:39:48 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-31 22:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-25 02:53:49 56408 ----a-w- C:\Windows\System32\drivers\stdriver64.sys
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 16:12:54.27 ===============
  • 0

#87
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Here is the second:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume2
Install Date: 2/3/2009 02:48:12 PM
System Uptime: 10/11/2011 03:29:11 PM (1 hours ago)
.
Motherboard: Sony Corporation | | VAIO
Processor: Intel® Core™2 Duo CPU T9600 @ 2.80GHz | N/A | 1600/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 108 GiB total, 20.513 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 406.411 GiB free.
E: is Removable
F: is Removable
G: is Removable
H: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Bluetooth Peripheral Device
Device ID: BTHENUM\{00000000-DECA-FADE-DECA-DEAFDECACAFE}_VID&000205AC_PID&1292\7&494DA9B&0&D49A20A0A828_C00000001
Manufacturer:
Name: Bluetooth Peripheral Device
PNP Device ID: BTHENUM\{00000000-DECA-FADE-DECA-DEAFDECACAFE}_VID&000205AC_PID&1292\7&494DA9B&0&D49A20A0A828_C00000001
Service:
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: R5C592
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&4&STORAGE#VOLUME#1&19F7E59C&0&_??_RIMSPTSK#DISK&VEN_RICOH&PROD_MEMORYSTICKSTORAGE&REV_1.00#MS0001#
Manufacturer: RICOH
Name: R5C592
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&4&STORAGE#VOLUME#1&19F7E59C&0&_??_RIMSPTSK#DISK&VEN_RICOH&PROD_MEMORYSTICKSTORAGE&REV_1.00#MS0001#
Service: WUDFRd
.
==== System Restore Points ===================
.
RP966: 10/11/2011 11:22:31 AM - Removed Cisco Network Magic
RP967: 10/11/2011 11:22:49 AM - Removed Pure Networks Platform
RP968: 10/11/2011 03:21:32 PM - First after IE9 operation
.
==== Installed Programs ======================
.
.
Update for Microsoft Office 2007 (KB2508958)
ABBYY FineReader 6.0 Sprint
Acrobat.com
Add or Remove Adobe Creative Suite 3 Master Collection
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe Acrobat 9.4.6 - CPSID_83708
Adobe After Effects CS3 Presets
Adobe After Effects CS3 Template Projects & Footage
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe BridgeTalk Plugin CS3
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe InDesign CS3 Icon Handler
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Premiere Pro CS3 Functional Content
Adobe Reader 9.3
Adobe Setup
Adobe SING CS3
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Video Profiles
Adobe WAS CS3
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
AHV content for Acrobat and Flash
Apple Application Support
Apple Software Update
ArcSoft Magic-i Visual Effects
ArcSoft WebCam Companion 2
Audacity 1.2.6
AVer Media Center
AVerMedia H826 series driver 1.0.64.88
Business Contact Manager for Outlook 2007 SP2
Click to Disc
Click to Disc Editor
Compatibility Pack for the 2007 Office system
DirectX 9 Runtime
ESET Online Scanner v3
FileMaker Pro 11
Finale 2009
Google Updater
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
iPod to Computer Transfer 4.8.2
Ipswitch WS_FTP Pro
Java Auto Updater
Java™ 6 Update 27
JMicron JMB368 ExpressCard CF Adapter
LAME v3.98.3 for Audacity
LaserJet 1020 series
Lexmark Printable Web
Lexmark Toolbar
Lexmark Tools for Office
Macromedia Extension Manager
Magic DVD Copier Version 5.0.0
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Application Error Reporting
Microsoft Office 2003 Web Components
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Mozilla Firefox 7.0.1 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Music Transfer
OpenMG Secure Module 5.1.00
Opera 11.51
Paint Shop Pro 7
PDF Settings
Primo
QuickBooks Simple Start 2008
QuickTime
Realtek High Definition Audio Driver
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer Decoder Pack
Roxio Easy Media Creator 10 LJ
Roxio Easy Media Creator Home
Roxio Easy VHS to DVD
Roxio Express Labeler
Roxio Video Capture USB
SeaMonkey (1.1.16)
SeaMonkey (2.0.6)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Setting Utility Series
Sibelius Scorch (Firefox, Opera, Netscape only)
Sony Image Data Suite
Sony Picture Utility
Sony Video Shared Library
SoundTap Streaming Audio Recorder
SupportSoft Assisted Service
Switch Sound File Converter
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB957244)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB957241)
Update for Microsoft Office Excel 2007 Help (KB957242)
Update for Microsoft Office InfoPath 2007 Help (KB957243)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB957246)
Update for Microsoft Office PowerPoint 2007 Help (KB957247)
Update for Microsoft Office Publisher 2007 Help (KB957249)
Update for Microsoft Office Word 2007 Help (KB957252)
Update for Microsoft Script Editor Help (KB957253)
Update for Outlook 2007 Junk Email Filter (KB2553110)
VAIO BD Menu Data
VAIO Care
VAIO Content Folder Setting
VAIO Content Metadata Intelligent Analyzing Manager
VAIO Content Metadata Manager Setting
VAIO Content Metadata XML Interface Library
VAIO Control Center
VAIO Data Restore Tool
VAIO DVD Menu Data Basic
VAIO Entertainment Platform
VAIO Event Service
VAIO Help and Support
VAIO Launcher
VAIO Media plus
VAIO Movie Story
VAIO Movie Story Template Data
VAIO MusicBox
VAIO My Memory Center
VAIO OOBE and Welcome Center
VAIO Original Function Setting
VAIO Power Management
VAIO Startup Assistant
VAIO Survey
VAIO Update 4
VAIO Wallpaper Contents
VAIO Wireless Wizard
Visual Studio 2008 x64 Redistributables
WavePad Sound Editor
WebEx Support Manager for Internet Explorer
Windows Media Player Firefox Plugin
WinDVD BD for VAIO
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
10/11/2011 12:48:25 PM, Error: Service Control Manager [7034] - The lxea_device service terminated unexpectedly. It has done this 2 time(s).
10/11/2011 12:48:11 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
10/11/2011 12:48:10 PM, Error: Service Control Manager [7034] - The lxea_device service terminated unexpectedly. It has done this 1 time(s).
10/11/2011 11:10:00 AM, Error: Service Control Manager [7024] - The Pure Networks Platform Service service terminated with service-specific error 2147953403 (0x80072AFB).
10/11/2011 09:50:59 AM, Error: Service Control Manager [7034] - The VAIO Media plus Content Importer service terminated unexpectedly. It has done this 1 time(s).
10/11/2011 09:50:52 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
10/11/2011 09:00:23 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
10/11/2011 08:53:12 AM, Error: Microsoft-Windows-TerminalServices-RemoteConnectionManager [1067] - The terminal server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: The specified domain either does not exist or could not be contacted. .
10/11/2011 08:50:52 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
10/11/2011 08:50:50 AM, Error: Microsoft-Windows-GroupPolicy [1129] - The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
10/11/2011 08:50:31 AM, Error: NETLOGON [5719] - This computer was not able to set up a secure session with a domain controller in domain CAMPUS due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
10/11/2011 03:30:06 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep DMICall
10/11/2011 03:30:05 PM, Error: Service Control Manager [7024] - The Bonjour Service service terminated with service-specific error 11003 (0x2AFB).
10/11/2011 03:30:05 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the lxeaCATSCustConnectService service to connect.
10/11/2011 03:30:05 PM, Error: Service Control Manager [7000] - The lxeaCATSCustConnectService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/11/2011 03:29:34 PM, Error: Application Popup [1060] - \SystemRoot\SysWow64\DRIVERS\DMICall.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
10/11/2011 02:15:00 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
10/11/2011 01:59:58 PM, Error: Microsoft-Windows-WMPNSS-Service [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2711'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
10/11/2011 01:37:24 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
10/10/2011 11:22:03 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
.
==== End Of File ===========================
  • 0

#88
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
TDSSKiller Log
16:19:57.0952 1764 TDSS rootkit removing tool 2.6.7.0 Oct 10 2011 09:40:06
16:19:57.0962 1764 ============================================================
16:19:57.0962 1764 Current date / time: 2011/10/11 16:19:57.0962
16:19:57.0962 1764 SystemInfo:
16:19:57.0962 1764
16:19:57.0962 1764 OS Version: 6.0.6002 ServicePack: 2.0
16:19:57.0962 1764 Product type: Workstation
16:19:57.0962 1764 ComputerName: TIM-PC
16:19:57.0962 1764 UserName: Tim
16:19:57.0963 1764 Windows directory: C:\Windows
16:19:57.0963 1764 System windows directory: C:\Windows
16:19:57.0963 1764 Running under WOW64
16:19:57.0963 1764 Processor architecture: Intel x64
16:19:57.0963 1764 Number of processors: 2
16:19:57.0963 1764 Page size: 0x1000
16:19:57.0963 1764 Boot type: Normal boot
16:19:57.0963 1764 ============================================================
16:19:58.0241 1764 Initialize success
16:20:01.0495 1468 ============================================================
16:20:01.0495 1468 Scan started
16:20:01.0495 1468 Mode: Manual;
16:20:01.0495 1468 ============================================================
16:20:02.0025 1468 61883 (78e902fb660bd5003fe726b9bef300b6) C:\Windows\system32\DRIVERS\61883.sys
16:20:02.0026 1468 61883 - ok
16:20:02.0045 1468 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
16:20:02.0049 1468 ACPI - ok
16:20:02.0072 1468 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
16:20:02.0078 1468 adp94xx - ok
16:20:02.0096 1468 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
16:20:02.0100 1468 adpahci - ok
16:20:02.0116 1468 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
16:20:02.0117 1468 adpu160m - ok
16:20:02.0134 1468 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
16:20:02.0136 1468 adpu320 - ok
16:20:02.0160 1468 AFD (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys
16:20:02.0165 1468 AFD - ok
16:20:02.0179 1468 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
16:20:02.0180 1468 agp440 - ok
16:20:02.0195 1468 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
16:20:02.0196 1468 aic78xx - ok
16:20:02.0210 1468 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
16:20:02.0211 1468 aliide - ok
16:20:02.0224 1468 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
16:20:02.0225 1468 amdide - ok
16:20:02.0239 1468 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
16:20:02.0240 1468 AmdK8 - ok
16:20:02.0261 1468 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
16:20:02.0262 1468 arc - ok
16:20:02.0276 1468 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
16:20:02.0277 1468 arcsas - ok
16:20:02.0290 1468 ArcSoftKsUFilter (59d2ba1b18f14d0b49b830dc452261b0) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
16:20:02.0291 1468 ArcSoftKsUFilter - ok
16:20:02.0305 1468 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
16:20:02.0306 1468 AsyncMac - ok
16:20:02.0320 1468 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
16:20:02.0320 1468 atapi - ok
16:20:02.0341 1468 Avc (295fa2878ff499c0edfa0ebcc8c6ec66) C:\Windows\system32\DRIVERS\avc.sys
16:20:02.0342 1468 Avc - ok
16:20:02.0373 1468 AVerAVF2 (1b1db2ff2168742d9195e483b7d41de6) C:\Windows\system32\DRIVERS\AVerAVF2.sys
16:20:02.0391 1468 AVerAVF2 - ok
16:20:02.0409 1468 AVerFx2hbtv64 (7c62316c8c040235ee63f77fc85813ed) C:\Windows\system32\drivers\AVerFx2hbtv64.sys
16:20:02.0413 1468 AVerFx2hbtv64 - ok
16:20:02.0438 1468 Beep - ok
16:20:02.0456 1468 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
16:20:02.0457 1468 blbdrive - ok
16:20:02.0473 1468 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
16:20:02.0474 1468 bowser - ok
16:20:02.0487 1468 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
16:20:02.0488 1468 BrFiltLo - ok
16:20:02.0501 1468 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
16:20:02.0503 1468 BrFiltUp - ok
16:20:02.0520 1468 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
16:20:02.0521 1468 Brserid - ok
16:20:02.0534 1468 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
16:20:02.0535 1468 BrSerWdm - ok
16:20:02.0548 1468 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
16:20:02.0549 1468 BrUsbMdm - ok
16:20:02.0563 1468 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
16:20:02.0564 1468 BrUsbSer - ok
16:20:02.0578 1468 BthEnum (09f926a0d9c0bafd8417a4307d2ed13c) C:\Windows\system32\DRIVERS\BthEnum.sys
16:20:02.0579 1468 BthEnum - ok
16:20:02.0594 1468 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
16:20:02.0595 1468 BTHMODEM - ok
16:20:02.0609 1468 BthPan (befc5311736b475ac5b60c14ff7c775a) C:\Windows\system32\DRIVERS\bthpan.sys
16:20:02.0611 1468 BthPan - ok
16:20:02.0635 1468 BTHPORT (e1466882252ff51edde48c3f7eda2591) C:\Windows\system32\Drivers\BTHport.sys
16:20:02.0647 1468 BTHPORT - ok
16:20:02.0663 1468 BTHUSB (970192cded77a128e7e30722e5ee6b9c) C:\Windows\system32\Drivers\BTHUSB.sys
16:20:02.0664 1468 BTHUSB - ok
16:20:02.0679 1468 btwaudio (243661bc849eb1a7ad141680ae62886a) C:\Windows\system32\drivers\btwaudio.sys
16:20:02.0680 1468 btwaudio - ok
16:20:02.0694 1468 btwavdt (89c6567ebd92bbd2961c634604d6670f) C:\Windows\system32\drivers\btwavdt.sys
16:20:02.0696 1468 btwavdt - ok
16:20:02.0711 1468 btwl2cap (09baf40735007bde7dd95830afcefd26) C:\Windows\system32\DRIVERS\btwl2cap.sys
16:20:02.0712 1468 btwl2cap - ok
16:20:02.0725 1468 btwrchid (2bbf56e2114fabf63c3d00828fc3c86c) C:\Windows\system32\DRIVERS\btwrchid.sys
16:20:02.0726 1468 btwrchid - ok
16:20:02.0731 1468 catchme - ok
16:20:02.0754 1468 CAXHWAZL (fdb53a8d3bc52dc29884587e768e3388) C:\Windows\system32\DRIVERS\CAXHWAZL.sys
16:20:02.0756 1468 CAXHWAZL - ok
16:20:02.0771 1468 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
16:20:02.0772 1468 cdfs - ok
16:20:02.0787 1468 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
16:20:02.0788 1468 cdrom - ok
16:20:02.0806 1468 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\DRIVERS\circlass.sys
16:20:02.0807 1468 circlass - ok
16:20:02.0824 1468 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
16:20:02.0828 1468 CLFS - ok
16:20:02.0849 1468 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys
16:20:02.0849 1468 CmBatt - ok
16:20:02.0865 1468 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
16:20:02.0865 1468 cmdide - ok
16:20:02.0880 1468 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys
16:20:02.0880 1468 Compbatt - ok
16:20:02.0897 1468 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
16:20:02.0897 1468 crcdisk - ok
16:20:02.0924 1468 CSC (f60f50c8ed3fcbe358430b95fe27d09c) C:\Windows\system32\drivers\csc.sys
16:20:02.0929 1468 CSC - ok
16:20:02.0950 1468 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
16:20:02.0951 1468 DfsC - ok
16:20:02.0960 1468 DIRECTIO - ok
16:20:02.0975 1468 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
16:20:02.0976 1468 disk - ok
16:20:02.0990 1468 DMICall - ok
16:20:03.0012 1468 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
16:20:03.0013 1468 drmkaud - ok
16:20:03.0041 1468 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
16:20:03.0058 1468 DXGKrnl - ok
16:20:03.0076 1468 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
16:20:03.0078 1468 E1G60 - ok
16:20:03.0097 1468 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
16:20:03.0099 1468 Ecache - ok
16:20:03.0112 1468 echo1394 - ok
16:20:03.0141 1468 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
16:20:03.0146 1468 elxstor - ok
16:20:03.0163 1468 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
16:20:03.0164 1468 ErrDev - ok
16:20:03.0193 1468 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
16:20:03.0195 1468 exfat - ok
16:20:03.0215 1468 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
16:20:03.0217 1468 fastfat - ok
16:20:03.0239 1468 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
16:20:03.0240 1468 fdc - ok
16:20:03.0260 1468 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
16:20:03.0261 1468 FileInfo - ok
16:20:03.0280 1468 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
16:20:03.0281 1468 Filetrace - ok
16:20:03.0296 1468 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
16:20:03.0297 1468 flpydisk - ok
16:20:03.0315 1468 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
16:20:03.0319 1468 FltMgr - ok
16:20:03.0340 1468 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
16:20:03.0341 1468 Fs_Rec - ok
16:20:03.0360 1468 fvevol (849e38db7d829962d0233a0a252b60c3) C:\Windows\system32\DRIVERS\fvevol.sys
16:20:03.0361 1468 fvevol - ok
16:20:03.0378 1468 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
16:20:03.0379 1468 gagp30kx - ok
16:20:03.0397 1468 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:20:03.0398 1468 GEARAspiWDM - ok
16:20:03.0424 1468 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
16:20:03.0427 1468 HdAudAddService - ok
16:20:03.0456 1468 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:20:03.0475 1468 HDAudBus - ok
16:20:03.0490 1468 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
16:20:03.0490 1468 HidBth - ok
16:20:03.0512 1468 HidIr (5f47839455d01ff6403b008d481a6f5b) C:\Windows\system32\DRIVERS\hidir.sys
16:20:03.0512 1468 HidIr - ok
16:20:03.0528 1468 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
16:20:03.0528 1468 HidUsb - ok
16:20:03.0544 1468 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
16:20:03.0545 1468 HpCISSs - ok
16:20:03.0563 1468 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
16:20:03.0567 1468 HSFHWAZL - ok
16:20:03.0600 1468 HSF_DPV (e90d0e3d9715f3bec7db2d6321dddee8) C:\Windows\system32\DRIVERS\CAX_DPV.sys
16:20:03.0620 1468 HSF_DPV - ok
16:20:03.0643 1468 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
16:20:03.0653 1468 HTTP - ok
16:20:03.0666 1468 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
16:20:03.0667 1468 i2omp - ok
16:20:03.0682 1468 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
16:20:03.0683 1468 i8042prt - ok
16:20:03.0704 1468 iaStor (8d58627fef3f8767665d9f4dc91cbd97) C:\Windows\system32\DRIVERS\iaStor.sys
16:20:03.0707 1468 iaStor - ok
16:20:03.0727 1468 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
16:20:03.0731 1468 iaStorV - ok
16:20:03.0746 1468 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
16:20:03.0747 1468 iirsp - ok
16:20:03.0787 1468 IntcAzAudAddService (e6ad224a57cfc3dbf4ea10c801a09630) C:\Windows\system32\drivers\RTKVHD64.sys
16:20:03.0813 1468 IntcAzAudAddService - ok
16:20:03.0827 1468 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
16:20:03.0828 1468 intelide - ok
16:20:03.0842 1468 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
16:20:03.0843 1468 intelppm - ok
16:20:03.0859 1468 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:20:03.0860 1468 IpFilterDriver - ok
16:20:03.0874 1468 IpInIp - ok
16:20:03.0891 1468 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
16:20:03.0892 1468 IPMIDRV - ok
16:20:03.0907 1468 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
16:20:03.0908 1468 IPNAT - ok
16:20:03.0924 1468 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
16:20:03.0924 1468 IRENUM - ok
16:20:03.0940 1468 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
16:20:03.0941 1468 isapnp - ok
16:20:03.0958 1468 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
16:20:03.0960 1468 iScsiPrt - ok
16:20:03.0974 1468 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
16:20:03.0975 1468 iteatapi - ok
16:20:03.0988 1468 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
16:20:03.0991 1468 iteraid - ok
16:20:04.0007 1468 JMCR_CFS (35a1646897a9113f563634cb33b15f23) C:\Windows\system32\DRIVERS\jmcr_cfs.sys
16:20:04.0008 1468 JMCR_CFS - ok
16:20:04.0021 1468 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
16:20:04.0022 1468 kbdclass - ok
16:20:04.0035 1468 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
16:20:04.0036 1468 kbdhid - ok
16:20:04.0063 1468 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
16:20:04.0069 1468 KSecDD - ok
16:20:04.0083 1468 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
16:20:04.0084 1468 ksthunk - ok
16:20:04.0094 1468 Lavasoft Kernexplorer - ok
16:20:04.0111 1468 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
16:20:04.0112 1468 lltdio - ok
16:20:04.0132 1468 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
16:20:04.0133 1468 LSI_FC - ok
16:20:04.0146 1468 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
16:20:04.0148 1468 LSI_SAS - ok
16:20:04.0163 1468 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
16:20:04.0164 1468 LSI_SCSI - ok
16:20:04.0178 1468 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
16:20:04.0179 1468 luafv - ok
16:20:04.0199 1468 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
16:20:04.0199 1468 mdmxsdk - ok
16:20:04.0214 1468 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
16:20:04.0215 1468 megasas - ok
16:20:04.0237 1468 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
16:20:04.0244 1468 MegaSR - ok
16:20:04.0259 1468 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
16:20:04.0260 1468 Modem - ok
16:20:04.0275 1468 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
16:20:04.0276 1468 monitor - ok
16:20:04.0291 1468 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
16:20:04.0291 1468 mouclass - ok
16:20:04.0305 1468 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
16:20:04.0305 1468 mouhid - ok
16:20:04.0320 1468 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
16:20:04.0321 1468 MountMgr - ok
16:20:04.0339 1468 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys
16:20:04.0341 1468 MpFilter - ok
16:20:04.0356 1468 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
16:20:04.0357 1468 mpio - ok
16:20:04.0371 1468 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys
16:20:04.0372 1468 MpNWMon - ok
16:20:04.0387 1468 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
16:20:04.0388 1468 mpsdrv - ok
16:20:04.0404 1468 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
16:20:04.0405 1468 Mraid35x - ok
16:20:04.0422 1468 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
16:20:04.0423 1468 MRxDAV - ok
16:20:04.0438 1468 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:20:04.0440 1468 mrxsmb - ok
16:20:04.0457 1468 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:20:04.0460 1468 mrxsmb10 - ok
16:20:04.0476 1468 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:20:04.0477 1468 mrxsmb20 - ok
16:20:04.0491 1468 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
16:20:04.0492 1468 msahci - ok
16:20:04.0509 1468 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
16:20:04.0511 1468 msdsm - ok
16:20:04.0528 1468 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
16:20:04.0528 1468 Msfs - ok
16:20:04.0545 1468 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
16:20:04.0545 1468 msisadrv - ok
16:20:04.0566 1468 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
16:20:04.0567 1468 MSKSSRV - ok
16:20:04.0584 1468 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
16:20:04.0584 1468 MSPCLOCK - ok
16:20:04.0602 1468 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
16:20:04.0603 1468 MSPQM - ok
16:20:04.0623 1468 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
16:20:04.0626 1468 MsRPC - ok
16:20:04.0643 1468 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
16:20:04.0643 1468 mssmbios - ok
16:20:04.0661 1468 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
16:20:04.0661 1468 MSTEE - ok
16:20:04.0676 1468 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
16:20:04.0677 1468 Mup - ok
16:20:04.0695 1468 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
16:20:04.0697 1468 NativeWifiP - ok
16:20:04.0722 1468 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
16:20:04.0736 1468 NDIS - ok
16:20:04.0749 1468 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
16:20:04.0750 1468 NdisTapi - ok
16:20:04.0764 1468 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
16:20:04.0764 1468 Ndisuio - ok
16:20:04.0781 1468 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
16:20:04.0783 1468 NdisWan - ok
16:20:04.0796 1468 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
16:20:04.0797 1468 NDProxy - ok
16:20:04.0811 1468 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
16:20:04.0812 1468 NetBIOS - ok
16:20:04.0830 1468 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
16:20:04.0832 1468 netbt - ok
16:20:04.0926 1468 NETw5v64 (93915c41a0dbbd121a0fad2835e43776) C:\Windows\system32\DRIVERS\NETw5v64.sys
16:20:05.0016 1468 NETw5v64 - ok
16:20:05.0033 1468 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
16:20:05.0034 1468 nfrd960 - ok
16:20:05.0049 1468 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
16:20:05.0050 1468 NisDrv - ok
16:20:05.0070 1468 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
16:20:05.0071 1468 Npfs - ok
16:20:05.0086 1468 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
16:20:05.0087 1468 nsiproxy - ok
16:20:05.0125 1468 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
16:20:05.0153 1468 Ntfs - ok
16:20:05.0166 1468 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
16:20:05.0167 1468 Null - ok
16:20:05.0182 1468 NVHDA (29a70ad61fb913b4e6c587924b23b62c) C:\Windows\system32\drivers\nvhda64v.sys
16:20:05.0183 1468 NVHDA - ok
16:20:05.0369 1468 nvlddmkm (45ace5d0f8ca2685e1fada8f90eb048f) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:20:05.0555 1468 nvlddmkm - ok
16:20:05.0572 1468 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
16:20:05.0573 1468 nvraid - ok
16:20:05.0589 1468 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
16:20:05.0590 1468 nvstor - ok
16:20:05.0608 1468 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
16:20:05.0609 1468 nv_agp - ok
16:20:05.0623 1468 NwlnkFlt - ok
16:20:05.0637 1468 NwlnkFwd - ok
16:20:05.0656 1468 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
16:20:05.0657 1468 ohci1394 - ok
16:20:05.0681 1468 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
16:20:05.0683 1468 Parport - ok
16:20:05.0696 1468 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
16:20:05.0697 1468 partmgr - ok
16:20:05.0714 1468 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
16:20:05.0716 1468 pci - ok
16:20:05.0728 1468 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
16:20:05.0729 1468 pciide - ok
16:20:05.0746 1468 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
16:20:05.0748 1468 pcmcia - ok
16:20:05.0763 1468 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys
16:20:05.0764 1468 pcouffin - ok
16:20:05.0788 1468 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
16:20:05.0801 1468 PEAUTH - ok
16:20:05.0846 1468 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
16:20:05.0848 1468 PptpMiniport - ok
16:20:05.0861 1468 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
16:20:05.0862 1468 Processor - ok
16:20:05.0880 1468 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
16:20:05.0881 1468 PSched - ok
16:20:05.0895 1468 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys
16:20:05.0896 1468 PxHlpa64 - ok
16:20:05.0929 1468 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
16:20:05.0951 1468 ql2300 - ok
16:20:05.0966 1468 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
16:20:05.0967 1468 ql40xx - ok
16:20:05.0982 1468 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
16:20:05.0983 1468 QWAVEdrv - ok
16:20:05.0996 1468 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
16:20:05.0997 1468 RasAcd - ok
16:20:06.0015 1468 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:20:06.0016 1468 Rasl2tp - ok
16:20:06.0031 1468 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
16:20:06.0032 1468 RasPppoe - ok
16:20:06.0047 1468 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
16:20:06.0048 1468 RasSstp - ok
16:20:06.0065 1468 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
16:20:06.0068 1468 rdbss - ok
16:20:06.0081 1468 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:20:06.0081 1468 RDPCDD - ok
16:20:06.0103 1468 rdpdr (ae23e79b13feb62939e2ca1189e71735) C:\Windows\system32\DRIVERS\rdpdr.sys
16:20:06.0106 1468 rdpdr - ok
16:20:06.0119 1468 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
16:20:06.0119 1468 RDPENCDD - ok
16:20:06.0138 1468 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
16:20:06.0141 1468 RDPWD - ok
16:20:06.0155 1468 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\Windows\system32\drivers\regi.sys
16:20:06.0155 1468 regi - ok
16:20:06.0180 1468 RFCOMM (cd71e053d7260e4102d99a28f9196070) C:\Windows\system32\DRIVERS\rfcomm.sys
16:20:06.0182 1468 RFCOMM - ok
16:20:06.0197 1468 rimsptsk (d345ae15fa0ad4bd8d647c5509714858) C:\Windows\system32\DRIVERS\rimssn64.sys
16:20:06.0198 1468 rimsptsk - ok
16:20:06.0214 1468 risdptsk (c45cd294458fed92e9cc1c68768e9356) C:\Windows\system32\DRIVERS\risdsn64.sys
16:20:06.0215 1468 risdptsk - ok
16:20:06.0235 1468 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
16:20:06.0236 1468 rspndr - ok
16:20:06.0257 1468 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
16:20:06.0258 1468 sbp2port - ok
16:20:06.0281 1468 sdbus (b42ee50f7d24f837f925332eb349eca5) C:\Windows\system32\DRIVERS\sdbus.sys
16:20:06.0282 1468 sdbus - ok
16:20:06.0297 1468 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
16:20:06.0298 1468 secdrv - ok
16:20:06.0316 1468 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
16:20:06.0317 1468 Serenum - ok
16:20:06.0332 1468 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
16:20:06.0333 1468 Serial - ok
16:20:06.0346 1468 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
16:20:06.0347 1468 sermouse - ok
16:20:06.0369 1468 SFEP (70f9c476b62de4f2823e918a6c181ade) C:\Windows\system32\DRIVERS\SFEP.sys
16:20:06.0370 1468 SFEP - ok
16:20:06.0384 1468 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
16:20:06.0385 1468 sffdisk - ok
16:20:06.0399 1468 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
16:20:06.0400 1468 sffp_mmc - ok
16:20:06.0414 1468 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
16:20:06.0415 1468 sffp_sd - ok
16:20:06.0430 1468 sfloppy (40567781f0785c4a69411d1b40da8987) C:\Windows\system32\DRIVERS\sfloppy.sys
16:20:06.0431 1468 sfloppy - ok
16:20:06.0448 1468 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
16:20:06.0449 1468 SiSRaid2 - ok
16:20:06.0464 1468 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
16:20:06.0465 1468 SiSRaid4 - ok
16:20:06.0483 1468 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
16:20:06.0484 1468 Smb - ok
16:20:06.0507 1468 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
16:20:06.0508 1468 spldr - ok
16:20:06.0538 1468 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
16:20:06.0543 1468 srv - ok
16:20:06.0560 1468 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
16:20:06.0562 1468 srv2 - ok
16:20:06.0578 1468 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
16:20:06.0580 1468 srvnet - ok
16:20:06.0598 1468 stdriver (50aadc94ba90dc3de1ae0020c877baae) C:\Windows\system32\DRIVERS\stdriver64.sys
16:20:06.0599 1468 stdriver - ok
16:20:06.0617 1468 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
16:20:06.0618 1468 swenum - ok
16:20:06.0636 1468 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
16:20:06.0637 1468 Symc8xx - ok
16:20:06.0653 1468 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
16:20:06.0654 1468 Sym_hi - ok
16:20:06.0671 1468 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
16:20:06.0671 1468 Sym_u3 - ok
16:20:06.0695 1468 SynTP (465e1231adf3cb6e0be5372c0fa83462) C:\Windows\system32\DRIVERS\SynTP.sys
16:20:06.0700 1468 SynTP - ok
16:20:06.0745 1468 Tcpip (19a7321e3a5f1ddb215d2815dcc8f8e4) C:\Windows\system32\drivers\tcpip.sys
16:20:06.0774 1468 Tcpip - ok
16:20:06.0816 1468 Tcpip6 (19a7321e3a5f1ddb215d2815dcc8f8e4) C:\Windows\system32\DRIVERS\tcpip.sys
16:20:06.0829 1468 Tcpip6 - ok
16:20:06.0846 1468 tcpipreg (2aa1b7ebc271e995f3358c1fa7a1d35b) C:\Windows\system32\drivers\tcpipreg.sys
16:20:06.0847 1468 tcpipreg - ok
16:20:06.0863 1468 TcUsb (cbd13e809e81b07116c8d51aa199f69b) C:\Windows\system32\Drivers\tcusb.sys
16:20:06.0864 1468 TcUsb - ok
16:20:06.0879 1468 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
16:20:06.0880 1468 TDPIPE - ok
16:20:06.0898 1468 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
16:20:06.0899 1468 TDTCP - ok
16:20:06.0916 1468 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
16:20:06.0917 1468 tdx - ok
16:20:06.0933 1468 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
16:20:06.0934 1468 TermDD - ok
16:20:06.0966 1468 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:20:06.0966 1468 tssecsrv - ok
16:20:06.0982 1468 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
16:20:06.0983 1468 tunmp - ok
16:20:07.0004 1468 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
16:20:07.0005 1468 tunnel - ok
16:20:07.0021 1468 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
16:20:07.0022 1468 uagp35 - ok
16:20:07.0042 1468 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
16:20:07.0046 1468 udfs - ok
16:20:07.0072 1468 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
16:20:07.0073 1468 uliagpkx - ok
16:20:07.0094 1468 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
16:20:07.0098 1468 uliahci - ok
16:20:07.0115 1468 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
16:20:07.0117 1468 UlSata - ok
16:20:07.0133 1468 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
16:20:07.0135 1468 ulsata2 - ok
16:20:07.0148 1468 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
16:20:07.0149 1468 umbus - ok
16:20:07.0182 1468 USB28xxBGA (1e1786e15f91183be26732e89adc1817) C:\Windows\system32\DRIVERS\emBDA64.sys
16:20:07.0193 1468 USB28xxBGA - ok
16:20:07.0218 1468 USB28xxOEM (e97f0e00adbc1bcef691c71dbee77041) C:\Windows\system32\DRIVERS\emOEM64.sys
16:20:07.0231 1468 USB28xxOEM - ok
16:20:07.0246 1468 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
16:20:07.0247 1468 USBAAPL64 - ok
16:20:07.0263 1468 usbaudio (c6ba890de6e41857fbe84175519cae7d) C:\Windows\system32\drivers\usbaudio.sys
16:20:07.0264 1468 usbaudio - ok
16:20:07.0279 1468 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
16:20:07.0280 1468 usbccgp - ok
16:20:07.0294 1468 usbcir (8c39d53e1a343f4c47ee8f3c052126d8) C:\Windows\system32\DRIVERS\usbcir.sys
16:20:07.0296 1468 usbcir - ok
16:20:07.0310 1468 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
16:20:07.0311 1468 usbehci - ok
16:20:07.0328 1468 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
16:20:07.0332 1468 usbhub - ok
16:20:07.0345 1468 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
16:20:07.0346 1468 usbohci - ok
16:20:07.0361 1468 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
16:20:07.0362 1468 usbprint - ok
16:20:07.0376 1468 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
16:20:07.0377 1468 usbscan - ok
16:20:07.0395 1468 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:20:07.0396 1468 USBSTOR - ok
16:20:07.0413 1468 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
16:20:07.0413 1468 usbuhci - ok
16:20:07.0430 1468 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
16:20:07.0432 1468 usbvideo - ok
16:20:07.0468 1468 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
16:20:07.0469 1468 vga - ok
16:20:07.0483 1468 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
16:20:07.0484 1468 VgaSave - ok
16:20:07.0497 1468 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
16:20:07.0498 1468 viaide - ok
16:20:07.0513 1468 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
16:20:07.0514 1468 volmgr - ok
16:20:07.0534 1468 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
16:20:07.0539 1468 volmgrx - ok
16:20:07.0556 1468 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
16:20:07.0559 1468 volsnap - ok
16:20:07.0575 1468 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
16:20:07.0576 1468 vsmraid - ok
16:20:07.0600 1468 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
16:20:07.0601 1468 WacomPen - ok
16:20:07.0616 1468 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
16:20:07.0617 1468 Wanarp - ok
16:20:07.0621 1468 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
16:20:07.0622 1468 Wanarpv6 - ok
16:20:07.0641 1468 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
16:20:07.0642 1468 Wd - ok
16:20:07.0669 1468 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
16:20:07.0684 1468 Wdf01000 - ok
16:20:07.0714 1468 WimFltr (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
16:20:07.0716 1468 WimFltr - ok
16:20:07.0739 1468 winachsf (057b062cf9a11e04db45b8c3afc28b11) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
16:20:07.0751 1468 winachsf - ok
16:20:07.0783 1468 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
16:20:07.0784 1468 WmiAcpi - ok
16:20:07.0808 1468 WpdUsb (6329d1990db931073b86ab5946d8e317) C:\Windows\system32\DRIVERS\wpdusb.sys
16:20:07.0809 1468 WpdUsb - ok
16:20:07.0825 1468 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
16:20:07.0825 1468 ws2ifsl - ok
16:20:07.0850 1468 XAudio (638c99d993afab0e1fab226e2bbe6d79) C:\Windows\system32\DRIVERS\xaudio64.sys
16:20:07.0851 1468 XAudio - ok
16:20:07.0875 1468 yukonx64 (3c5b0410faba5b1014eefeee77e1296a) C:\Windows\system32\DRIVERS\yk60x64.sys
16:20:07.0880 1468 yukonx64 - ok
16:20:07.0893 1468 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
16:20:07.0898 1468 \Device\Harddisk0\DR0 - ok
16:20:07.0902 1468 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
16:20:07.0907 1468 \Device\Harddisk1\DR1 - ok
16:20:07.0910 1468 Boot (0x1200) (3767ef98aa3b26765d91e26f3351930c) \Device\Harddisk0\DR0\Partition0
16:20:07.0911 1468 \Device\Harddisk0\DR0\Partition0 - ok
16:20:07.0914 1468 Boot (0x1200) (a70fe0b0c7e7c300265f9c9732629f9a) \Device\Harddisk1\DR1\Partition0
16:20:07.0917 1468 \Device\Harddisk1\DR1\Partition0 - ok
16:20:07.0917 1468 ============================================================
16:20:07.0917 1468 Scan finished
16:20:07.0917 1468 ============================================================
16:20:07.0927 4800 Detected object count: 0
16:20:07.0927 4800 Actual detected object count: 0
  • 0

#89
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Here is the Quick Scan log from MBam. It would not allow updating.

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7917

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

10/11/2011 04:24:14 PM
mbam-log-2011-10-11 (16-24-14).txt

Scan type: Quick scan
Objects scanned: 220722
Time elapsed: 1 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#90
tedins

tedins

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 122 posts
Here isthe Avast report. It found two problems.

10/11/2011 17:01
Scan of all local drives

File C:\Windows\assembly\tmp\kwrd.dll is infected by Win32:Malware-gen, Moved to chest
File D:\ATSSB\Area_West\ATSSB CD Files\pgbreeze.exe|>Wise0016.bin Error 42145 {Installer archive is corrupted.}
File D:\ATSSB\Region18\default.htm.orig is infected by VBS:Malware-gen, Moved to chest
File D:\ATSSB\Region4\wp\REGION 4 RULES|>[Content_Types].xml Error 42125 {ZIP archive is corrupted.}
Number of searched folders: 51319
Number of tested files: 1267864
Number of infected files: 2
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP