Edited by Machiavelli, 29 October 2013 - 03:41 PM.
I need testers, please!
Started by
Machiavelli
, Oct 27 2013 01:28 PM
#16
Posted 29 October 2013 - 03:40 PM
#17
Posted 29 October 2013 - 06:26 PM
Are you tweaking the registry for 64bit or does it only look at the 32bit.....bit
MVS Logfile created on: 30/10/2013 00:24:08 Logfile saved under = C:\Users\Nutloaf\Desktop\MVS\MVS.txt
Running from C:\Users\Nutloaf\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 32 bit
=== Processes ===
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
C:\Program Files (x86)\Intel\AMT\LMS.exe (Intel Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Users\Nutloaf\Desktop\MVS\MVS.exe ()
C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe - [02/05/2012 23:27:40 | 257416 | (Adobe Systems Incorporated)]
SRV - [ Apple Mobile Device | Apple Mobile Device | Running] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - [07/09/2013 09:13:38 | 55624 | (Apple Inc.)]
SRV - [ avast! Antivirus | avast! Antivirus | Running] - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - [20/10/2013 00:25:36 | 50344 | (AVAST Software)]
SRV - [ Bonjour Service | Bonjour Service | Running] - C:\Program Files\Bonjour\mDNSResponder.exe - [31/08/2011 00:05:32 | 462184 | (Apple Inc.)]
SRV - [ Creative Audio Engine Licensing Service | Creative Audio Engine Licensing Service | Stopped] - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe - [02/05/2012 22:16:32 | 79360 | (Creative Labs)]
SRV - [ ehRecvr | Windows Media Center Receiver Service | Stopped] - C:\Windows\ehome\ehRecvr.exe - [03/05/2012 01:24:34 | 696832 | (Microsoft Corporation)]
SRV - [ ehSched | Windows Media Center Scheduler Service | Stopped] - C:\Windows\ehome\ehsched.exe - [14/07/2009 01:24:23 | 127488 | (Microsoft Corporation)]
SRV - [ gupdate | Google Update Service (gupdate) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc - [CTF | FSF | ()]
SRV - [ gupdatem | Google Update Service (gupdatem) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc - [CTF | FSF | ()]
SRV - [ Intel® PROSet Monitoring Service | Intel® PROSet Monitoring Service | Running] - C:\Windows\system32\IProsetMonitor.exe - [01/01/1601 00:00:00 | FSF | ()]
SRV - [ SbieSvc | Sandboxie Service | Running] - C:\Program Files\Sandboxie\SbieSvc.exe - [08/07/2013 12:29:02 | 183896 | (Sandboxie Holdings, LLC)]
SRV - [ Sony PC Companion | Sony PC Companion | Stopped] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe - [27/07/2013 02:27:34 | 155824 | (Avanquest Software)]
SRV - [ tvnserver | TightVNC Server | Stopped] - C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe" -service - [CTF | FSF | ()]
SRV - [ UNS | Intel® Management and Security Application User Notification Service | Running] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe - [04/05/2012 00:53:24 | 2066968 | (Intel Corporation)]
SRV - [ iPod Service | iPod Service | Running] - C:\Program Files\iPod\bin\iPodService.exe - [23/10/2013 18:31:10 | 641352 | (Apple Inc.)]
MVS Logfile created on: 30/10/2013 00:24:08 Logfile saved under = C:\Users\Nutloaf\Desktop\MVS\MVS.txt
Running from C:\Users\Nutloaf\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 32 bit
=== Processes ===
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
C:\Program Files (x86)\Intel\AMT\LMS.exe (Intel Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Users\Nutloaf\Desktop\MVS\MVS.exe ()
C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe - [02/05/2012 23:27:40 | 257416 | (Adobe Systems Incorporated)]
SRV - [ Apple Mobile Device | Apple Mobile Device | Running] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - [07/09/2013 09:13:38 | 55624 | (Apple Inc.)]
SRV - [ avast! Antivirus | avast! Antivirus | Running] - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - [20/10/2013 00:25:36 | 50344 | (AVAST Software)]
SRV - [ Bonjour Service | Bonjour Service | Running] - C:\Program Files\Bonjour\mDNSResponder.exe - [31/08/2011 00:05:32 | 462184 | (Apple Inc.)]
SRV - [ Creative Audio Engine Licensing Service | Creative Audio Engine Licensing Service | Stopped] - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe - [02/05/2012 22:16:32 | 79360 | (Creative Labs)]
SRV - [ ehRecvr | Windows Media Center Receiver Service | Stopped] - C:\Windows\ehome\ehRecvr.exe - [03/05/2012 01:24:34 | 696832 | (Microsoft Corporation)]
SRV - [ ehSched | Windows Media Center Scheduler Service | Stopped] - C:\Windows\ehome\ehsched.exe - [14/07/2009 01:24:23 | 127488 | (Microsoft Corporation)]
SRV - [ gupdate | Google Update Service (gupdate) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc - [CTF | FSF | ()]
SRV - [ gupdatem | Google Update Service (gupdatem) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc - [CTF | FSF | ()]
SRV - [ Intel® PROSet Monitoring Service | Intel® PROSet Monitoring Service | Running] - C:\Windows\system32\IProsetMonitor.exe - [01/01/1601 00:00:00 | FSF | ()]
SRV - [ SbieSvc | Sandboxie Service | Running] - C:\Program Files\Sandboxie\SbieSvc.exe - [08/07/2013 12:29:02 | 183896 | (Sandboxie Holdings, LLC)]
SRV - [ Sony PC Companion | Sony PC Companion | Stopped] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe - [27/07/2013 02:27:34 | 155824 | (Avanquest Software)]
SRV - [ tvnserver | TightVNC Server | Stopped] - C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe" -service - [CTF | FSF | ()]
SRV - [ UNS | Intel® Management and Security Application User Notification Service | Running] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe - [04/05/2012 00:53:24 | 2066968 | (Intel Corporation)]
SRV - [ iPod Service | iPod Service | Running] - C:\Program Files\iPod\bin\iPodService.exe - [23/10/2013 18:31:10 | 641352 | (Apple Inc.)]
#18
Posted 30 October 2013 - 03:35 AM
I try to make two versions - one for 32bit the other for 64bit. But I have to earn experience about the registry - so probably it will endure some time until I'll publish it here I wonder.Are you tweaking the registry for 64bit or does it only look at the 32bit.....bit
Back to topic, I try to explain why there are some Errors in the file paths under the Service Section.
Example Line:
SRV - [ Steam Client Service | Steam Client Service | Stopped] - C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService - [CTF | FSF | ()]
There are two - three errors:
- CTF = CreationTime Failure
- FSF = FileSize Failure
- () = No company Name (but this can be also normal)
If three errors occur on one line these can be the possible reasons:
- the most probability is that the file path contains some illegal expressions like " or like the above shows /RunAsService. The creation date, file size and company name can only be identified if there is a path without any illegal expression - to fix this I have probably to read some Regex Stuff.
- No rights (if the User didn't run it as Administrator)
- File is protected by something?!
- File doesn't exist.
If one - two errors occur on one line:
- Probably no rights (User didn't run as Administrator or the file is protected by something [System File, etc.])
- The file doesn'tg have a company name
The next update will contain a summary about the Hosts File. And I like to begin writing a tutorial for that tool. At the end stage I'll also include some fix functions
Edited by Machiavelli, 30 October 2013 - 06:21 AM.
#19
Posted 30 October 2013 - 01:45 PM
Update 30.10.2013
ServicePaths should work now (with some exceptions!)
ServicePaths should work now (with some exceptions!)
#20
Posted 30 October 2013 - 02:36 PM
Here it is ..... and thanks to the scan I realise that Windows Defender was running as I have been messing about with Systweak, thanks Macca
MVS - Machiavelli's Scanner - Version 1.0.0.0
MVS Logfile created on: 30/10/2013 20:33:38 Logfile saved under = C:\Users\Nutloaf\Desktop\MVS\MVS.txt
Running from C:\Users\Nutloaf\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 64 bit Service Pack 1
=== Processes ===
C:\Program Files (x86)\iTunes\iTunesHelper.exe [ 3708 ] (Apple Inc.)
C:\Windows\system32\DllHost.exe [ 496 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 1728 ] (Microsoft Corporation)
C:\Windows\system32\taskhost.exe [ 1684 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1148 ] (Microsoft Corporation)
C:\Windows\system32\IProsetMonitor.exe [ 1456 ] (Intel Corporation)
C:\Users\Nutloaf\Desktop\MVS\MVS.exe [ 2332 ] ()
C:\Windows\system32\NOTEPAD.EXE [ 3636 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1588 ] (Microsoft Corporation)
C:\Windows\system32\wbem\wmiprvse.exe [ 1104 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 932 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 3640 ] (Google Inc.)
C:\Program Files\Windows Media Player\wmpnetwk.exe [ 2296 ] (Microsoft Corporation)
C:\Windows\system32\smss.exe [ 336 ] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [ 1848 ] (Adobe Systems Incorporated)
C:\Windows\system32\SearchProtocolHost.exe [ 3280 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 2320 ] (Google Inc.)
C:\Windows\system32\csrss.exe [ 420 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 3532 ] (Microsoft Corporation)
C:\Program Files\AVAST Software\Avast\avastui.exe [ 3680 ] (AVAST Software)
C:\Windows\system32\csrss.exe [ 504 ] (Microsoft Corporation)
C:\Windows\system32\SearchFilterHost.exe [ 2040 ] (Microsoft Corporation)
C:\Program Files\Sandboxie\SbieSvc.exe [ 1036 ] (Sandboxie Holdings, LLC)
C:\Windows\system32\svchost.exe [ 856 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1172 ] (Microsoft Corporation)
C:\Program Files (x86)\Intel\AMT\LMS.exe [ 1344 ] (Intel Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe [ 1920 ] (Apple Inc.)
C:\Program Files\iPod\bin\iPodService.exe [ 3880 ] (Apple Inc.)
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [ 1944 ] (Intel Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 852 ] (Google Inc.)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe [ 1380 ] (AVAST Software)
C:\Windows\system32\lsm.exe [ 576 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 124 ] (Microsoft Corporation)
C:\Windows\system32\SearchIndexer.exe [ 2352 ] (Microsoft Corporation)
C:\Windows\system32\winlogon.exe [ 660 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 924 ] (Google Inc.)
C:\Windows\system32\wininit.exe [ 480 ] (Microsoft Corporation)
C:\Windows\system32\lsass.exe [ 568 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 744 ] (Microsoft Corporation)
C:\Windows\system32\nvvsvc.exe [ 1188 ] (NVIDIA Corporation)
C:\Windows\system32\svchost.exe [ 564 ] (Microsoft Corporation)
C:\Windows\System32\spoolsv.exe [ 1540 ] (Microsoft Corporation)
C:\Windows\system32\Dwm.exe [ 1748 ] (Microsoft Corporation)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [ 1180 ] (NVIDIA Corporation)
C:\Windows\Explorer.EXE [ 1800 ] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [ 1888 ] (Apple Inc.)
C:\Windows\System32\svchost.exe [ 3756 ] (Microsoft Corporation)
C:\Windows\system32\nvvsvc.exe [ 816 ] (NVIDIA Corporation)
C:\Windows\System32\svchost.exe [ 2148 ] (Microsoft Corporation)
C:\Windows\system32\services.exe [ 544 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 2056 ] (Microsoft Corporation)
C:\Windows\System32\WUDFHost.exe [ 3480 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 1964 ] (Google Inc.)
C:\Windows\System32\svchost.exe [ 984 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 2228 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 2244 ] (Google Inc.)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe - [02/05/2012 23:27:40 | 257416 | (Adobe Systems Incorporated)]
SRV - [ Apple Mobile Device | Apple Mobile Device | Running] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - [07/09/2013 09:13:38 | 55624 | (Apple Inc.)]
SRV - [ avast! Antivirus | avast! Antivirus | Running] - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - [20/10/2013 00:25:36 | 50344 | (AVAST Software)]
SRV - [ Bonjour Service | Bonjour Service | Running] - C:\Program Files\Bonjour\mDNSResponder.exe - [31/08/2011 00:05:32 | 462184 | (Apple Inc.)]
SRV - [ Creative Audio Engine Licensing Service | Creative Audio Engine Licensing Service | Stopped] - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe - [02/05/2012 22:16:32 | 79360 | (Creative Labs)]
SRV - [ ehRecvr | Windows Media Center Receiver Service | Stopped] - C:\Windows\ehome\ehRecvr.exe - [03/05/2012 01:24:34 | 696832 | (Microsoft Corporation)]
SRV - [ ehSched | Windows Media Center Scheduler Service | Stopped] - C:\Windows\ehome\ehsched.exe - [14/07/2009 01:24:23 | 127488 | (Microsoft Corporation)]
SRV - [ gupdate | Google Update Service (gupdate) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - [05/06/2013 01:34:52 | 116648 | (Google Inc.)]
SRV - [ gupdatem | Google Update Service (gupdatem) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - [05/06/2013 01:34:52 | 116648 | (Google Inc.)]
SRV - [ Intel® PROSet Monitoring Service | Intel® PROSet Monitoring Service | Running] - C:\Windows\system32\IProsetMonitor.exe - [04/05/2012 00:43:09 | 189608 | (Intel Corporation)]
SRV - [ iPod Service | iPod Service | Running] - C:\Program Files\iPod\bin\iPodService.exe - [23/10/2013 18:31:10 | 641352 | (Apple Inc.)]
SRV - [ SbieSvc | Sandboxie Service | Running] - C:\Program Files\Sandboxie\SbieSvc.exe - [08/07/2013 12:29:02 | 183896 | (Sandboxie Holdings, LLC)]
SRV - [ Sony PC Companion | Sony PC Companion | Stopped] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe - [27/07/2013 02:27:34 | 155824 | (Avanquest Software)]
SRV - [ tvnserver | TightVNC Server | Stopped] - C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe - [01/01/1601 00:00:00 | FSF | ()] => File not found
SRV - [ UNS | Intel® Management and Security Application User Notification Service | Running] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe - [04/05/2012 00:53:24 | 2066968 | (Intel Corporation)]
SRV - [ WinDefend | Windows Defender | Running] - C:\Windows\System32\svchost.exe -k secsvcs - [01/01/1601 00:00:00 | FSF | ()] => File not found
MVS - Machiavelli's Scanner - Version 1.0.0.0
MVS Logfile created on: 30/10/2013 20:33:38 Logfile saved under = C:\Users\Nutloaf\Desktop\MVS\MVS.txt
Running from C:\Users\Nutloaf\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 64 bit Service Pack 1
=== Processes ===
C:\Program Files (x86)\iTunes\iTunesHelper.exe [ 3708 ] (Apple Inc.)
C:\Windows\system32\DllHost.exe [ 496 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 1728 ] (Microsoft Corporation)
C:\Windows\system32\taskhost.exe [ 1684 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1148 ] (Microsoft Corporation)
C:\Windows\system32\IProsetMonitor.exe [ 1456 ] (Intel Corporation)
C:\Users\Nutloaf\Desktop\MVS\MVS.exe [ 2332 ] ()
C:\Windows\system32\NOTEPAD.EXE [ 3636 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1588 ] (Microsoft Corporation)
C:\Windows\system32\wbem\wmiprvse.exe [ 1104 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 932 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 3640 ] (Google Inc.)
C:\Program Files\Windows Media Player\wmpnetwk.exe [ 2296 ] (Microsoft Corporation)
C:\Windows\system32\smss.exe [ 336 ] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [ 1848 ] (Adobe Systems Incorporated)
C:\Windows\system32\SearchProtocolHost.exe [ 3280 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 2320 ] (Google Inc.)
C:\Windows\system32\csrss.exe [ 420 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 3532 ] (Microsoft Corporation)
C:\Program Files\AVAST Software\Avast\avastui.exe [ 3680 ] (AVAST Software)
C:\Windows\system32\csrss.exe [ 504 ] (Microsoft Corporation)
C:\Windows\system32\SearchFilterHost.exe [ 2040 ] (Microsoft Corporation)
C:\Program Files\Sandboxie\SbieSvc.exe [ 1036 ] (Sandboxie Holdings, LLC)
C:\Windows\system32\svchost.exe [ 856 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1172 ] (Microsoft Corporation)
C:\Program Files (x86)\Intel\AMT\LMS.exe [ 1344 ] (Intel Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe [ 1920 ] (Apple Inc.)
C:\Program Files\iPod\bin\iPodService.exe [ 3880 ] (Apple Inc.)
C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [ 1944 ] (Intel Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 852 ] (Google Inc.)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe [ 1380 ] (AVAST Software)
C:\Windows\system32\lsm.exe [ 576 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 124 ] (Microsoft Corporation)
C:\Windows\system32\SearchIndexer.exe [ 2352 ] (Microsoft Corporation)
C:\Windows\system32\winlogon.exe [ 660 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 924 ] (Google Inc.)
C:\Windows\system32\wininit.exe [ 480 ] (Microsoft Corporation)
C:\Windows\system32\lsass.exe [ 568 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 744 ] (Microsoft Corporation)
C:\Windows\system32\nvvsvc.exe [ 1188 ] (NVIDIA Corporation)
C:\Windows\system32\svchost.exe [ 564 ] (Microsoft Corporation)
C:\Windows\System32\spoolsv.exe [ 1540 ] (Microsoft Corporation)
C:\Windows\system32\Dwm.exe [ 1748 ] (Microsoft Corporation)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [ 1180 ] (NVIDIA Corporation)
C:\Windows\Explorer.EXE [ 1800 ] (Microsoft Corporation)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [ 1888 ] (Apple Inc.)
C:\Windows\System32\svchost.exe [ 3756 ] (Microsoft Corporation)
C:\Windows\system32\nvvsvc.exe [ 816 ] (NVIDIA Corporation)
C:\Windows\System32\svchost.exe [ 2148 ] (Microsoft Corporation)
C:\Windows\system32\services.exe [ 544 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 2056 ] (Microsoft Corporation)
C:\Windows\System32\WUDFHost.exe [ 3480 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 1964 ] (Google Inc.)
C:\Windows\System32\svchost.exe [ 984 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 2228 ] (Microsoft Corporation)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [ 2244 ] (Google Inc.)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe - [02/05/2012 23:27:40 | 257416 | (Adobe Systems Incorporated)]
SRV - [ Apple Mobile Device | Apple Mobile Device | Running] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - [07/09/2013 09:13:38 | 55624 | (Apple Inc.)]
SRV - [ avast! Antivirus | avast! Antivirus | Running] - C:\Program Files\AVAST Software\Avast\AvastSvc.exe - [20/10/2013 00:25:36 | 50344 | (AVAST Software)]
SRV - [ Bonjour Service | Bonjour Service | Running] - C:\Program Files\Bonjour\mDNSResponder.exe - [31/08/2011 00:05:32 | 462184 | (Apple Inc.)]
SRV - [ Creative Audio Engine Licensing Service | Creative Audio Engine Licensing Service | Stopped] - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe - [02/05/2012 22:16:32 | 79360 | (Creative Labs)]
SRV - [ ehRecvr | Windows Media Center Receiver Service | Stopped] - C:\Windows\ehome\ehRecvr.exe - [03/05/2012 01:24:34 | 696832 | (Microsoft Corporation)]
SRV - [ ehSched | Windows Media Center Scheduler Service | Stopped] - C:\Windows\ehome\ehsched.exe - [14/07/2009 01:24:23 | 127488 | (Microsoft Corporation)]
SRV - [ gupdate | Google Update Service (gupdate) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - [05/06/2013 01:34:52 | 116648 | (Google Inc.)]
SRV - [ gupdatem | Google Update Service (gupdatem) | Stopped] - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - [05/06/2013 01:34:52 | 116648 | (Google Inc.)]
SRV - [ Intel® PROSet Monitoring Service | Intel® PROSet Monitoring Service | Running] - C:\Windows\system32\IProsetMonitor.exe - [04/05/2012 00:43:09 | 189608 | (Intel Corporation)]
SRV - [ iPod Service | iPod Service | Running] - C:\Program Files\iPod\bin\iPodService.exe - [23/10/2013 18:31:10 | 641352 | (Apple Inc.)]
SRV - [ SbieSvc | Sandboxie Service | Running] - C:\Program Files\Sandboxie\SbieSvc.exe - [08/07/2013 12:29:02 | 183896 | (Sandboxie Holdings, LLC)]
SRV - [ Sony PC Companion | Sony PC Companion | Stopped] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe - [27/07/2013 02:27:34 | 155824 | (Avanquest Software)]
SRV - [ tvnserver | TightVNC Server | Stopped] - C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe - [01/01/1601 00:00:00 | FSF | ()] => File not found
SRV - [ UNS | Intel® Management and Security Application User Notification Service | Running] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe - [04/05/2012 00:53:24 | 2066968 | (Intel Corporation)]
SRV - [ WinDefend | Windows Defender | Running] - C:\Windows\System32\svchost.exe -k secsvcs - [01/01/1601 00:00:00 | FSF | ()] => File not found
#21
Posted 31 October 2013 - 01:54 AM
C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe
Could you search after that file and tell me if the file exists?
#22
Posted 31 October 2013 - 06:19 AM
I've also tested.
MVS - Machiavelli's Scanner - Version 1.0.0.0
MVS Logfile created on: 2013-10-31 13:18:41 Logfile saved under = C:\Users\Radek\Desktop\MVS\MVS.txt
Running from C:\Users\Radek\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 32 bit Service Pack 1
=== Processes ===
C:\Program Files\Windows Media Player\wmpnetwk.exe [ 2936 ] (Microsoft Corporation)
C:\Windows\system32\lsm.exe [ 532 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 976 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 708 ] (Microsoft Corporation)
C:\Windows\system32\SearchIndexer.exe [ 2756 ] (Microsoft Corporation)
C:\Program Files\Microsoft Security Client\msseces.exe [ 2336 ] (Microsoft Corporation)
C:\Windows\system32\lsass.exe [ 524 ] (Microsoft Corporation)
D:\FirefoxPortable\App\firefox\firefox.exe [ 3900 ] (Mozilla Corporation)
C:\Windows\System32\igfxpers.exe [ 2208 ] (Intel Corporation)
C:\Windows\system32\svchost.exe [ 1228 ] (Microsoft Corporation)
C:\Windows\system32\Dwm.exe [ 960 ] (Microsoft Corporation)
C:\Program Files\Microsoft Security Client\MsMpEng.exe [ 776 ] (Microsoft Corporation)
D:\FirefoxPortable\FirefoxPortable.exe [ 3856 ] (PortableApps.com)
C:\Windows\system32\RunDll32.exe [ 2376 ] (Microsoft Corporation)
C:\Windows\system32\csrss.exe [ 416 ] (Microsoft Corporation)
C:\Windows\system32\igfxsrvc.exe [ 2284 ] (Intel Corporation)
C:\Windows\system32\wuauclt.exe [ 3796 ] (Microsoft Corporation)
C:\Windows\System32\igfxtray.exe [ 2192 ] (Intel Corporation)
C:\Windows\system32\services.exe [ 500 ] (Microsoft Corporation)
C:\Windows\system32\wbem\wmiprvse.exe [ 860 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 2544 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 2980 ] (Microsoft Corporation)
C:\Windows\system32\wininit.exe [ 404 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 936 ] (Microsoft Corporation)
C:\Windows\System32\hkcmd.exe [ 2200 ] (Intel Corporation)
C:\Program Files\HP\HP Officejet Pro 8600\bin\HPNetworkCommunicator.exe [ 2552 ] (Hewlett-Packard Co.)
C:\Windows\system32\svchost.exe [ 1368 ] (Microsoft Corporation)
C:\Windows\system32\taskhost.exe [ 1276 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1008 ] (Microsoft Corporation)
C:\Windows\system32\winlogon.exe [ 472 ] (Microsoft Corporation)
C:\Windows\Explorer.EXE [ 1272 ] (Microsoft Corporation)
C:\Windows\system32\WUDFHost.exe [ 3620 ] (Microsoft Corporation)
C:\Program Files\HP\HP Software Update\hpwuschd2.exe [ 2248 ] (Hewlett-Packard)
C:\Program Files\Microsoft Security Client\NisSrv.exe [ 1980 ] (Microsoft Corporation)
C:\Windows\System32\spoolsv.exe [ 1444 ] (Microsoft Corporation)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [ 1532 ] (Adobe Systems Incorporated)
C:\Windows\system32\svchost.exe [ 1708 ] (Microsoft Corporation)
C:\Users\Radek\AppData\Roaming\Dropbox\bin\Dropbox.exe [ 2344 ] (Dropbox, Inc.)
C:\Users\Radek\Desktop\MVS\MVS.exe [ 3444 ] ()
C:\Program Files\Common Files\Java\Java Update\jusched.exe [ 2328 ] (Oracle Corporation)
C:\Windows\system32\svchost.exe [ 632 ] (Microsoft Corporation)
C:\Windows\system32\csrss.exe [ 364 ] (Microsoft Corporation)
C:\Windows\system32\SearchProtocolHost.exe [ 3300 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 896 ] (Microsoft Corporation)
F:\Lupo_PenSuite_v2013.04_Zero\Launcher\ASuite.exe [ 3496 ] (SalvadorSoftware)
C:\Windows\system32\SearchFilterHost.exe [ 2768 ] (Microsoft Corporation)
C:\Windows\system32\smss.exe [ 268 ] (Microsoft Corporation)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe - [2012-10-15 08:42:44 | 257416 | (Adobe Systems Incorporated)]
SRV - [ ehRecvr | Usługa Odbiornik Windows Media Center | Stopped] - C:\Windows\ehome\ehRecvr.exe - [2010-11-20 22:29:29 | 556544 | (Microsoft Corporation)]
SRV - [ ehSched | Usługa harmonogramu programu Windows Media Center | Stopped] - C:\Windows\ehome\ehsched.exe - [2009-07-14 02:09:49 | 94720 | (Microsoft Corporation)]
SRV - [ MsMpSvc | Microsoft Antimalware Service | Running] - C:\Program Files\Microsoft Security Client\MsMpEng.exe - [2013-08-12 10:12:38 | 22208 | (Microsoft Corporation)]
SRV - [ WinDefend | Windows Defender | Stopped] - C:\Windows\System32\svchost.exe -k secsvcs - [1601-01-01 01:00:00 | FSF | ()] => File not found
MVS - Machiavelli's Scanner - Version 1.0.0.0
MVS Logfile created on: 2013-10-31 13:18:41 Logfile saved under = C:\Users\Radek\Desktop\MVS\MVS.txt
Running from C:\Users\Radek\Desktop\MVS\MVS.exe
SYSTEM => Microsoft Windows 7 Home Premium 32 bit Service Pack 1
=== Processes ===
C:\Program Files\Windows Media Player\wmpnetwk.exe [ 2936 ] (Microsoft Corporation)
C:\Windows\system32\lsm.exe [ 532 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 976 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 708 ] (Microsoft Corporation)
C:\Windows\system32\SearchIndexer.exe [ 2756 ] (Microsoft Corporation)
C:\Program Files\Microsoft Security Client\msseces.exe [ 2336 ] (Microsoft Corporation)
C:\Windows\system32\lsass.exe [ 524 ] (Microsoft Corporation)
D:\FirefoxPortable\App\firefox\firefox.exe [ 3900 ] (Mozilla Corporation)
C:\Windows\System32\igfxpers.exe [ 2208 ] (Intel Corporation)
C:\Windows\system32\svchost.exe [ 1228 ] (Microsoft Corporation)
C:\Windows\system32\Dwm.exe [ 960 ] (Microsoft Corporation)
C:\Program Files\Microsoft Security Client\MsMpEng.exe [ 776 ] (Microsoft Corporation)
D:\FirefoxPortable\FirefoxPortable.exe [ 3856 ] (PortableApps.com)
C:\Windows\system32\RunDll32.exe [ 2376 ] (Microsoft Corporation)
C:\Windows\system32\csrss.exe [ 416 ] (Microsoft Corporation)
C:\Windows\system32\igfxsrvc.exe [ 2284 ] (Intel Corporation)
C:\Windows\system32\wuauclt.exe [ 3796 ] (Microsoft Corporation)
C:\Windows\System32\igfxtray.exe [ 2192 ] (Intel Corporation)
C:\Windows\system32\services.exe [ 500 ] (Microsoft Corporation)
C:\Windows\system32\wbem\wmiprvse.exe [ 860 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 2544 ] (Microsoft Corporation)
C:\Windows\system32\DllHost.exe [ 2980 ] (Microsoft Corporation)
C:\Windows\system32\wininit.exe [ 404 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 936 ] (Microsoft Corporation)
C:\Windows\System32\hkcmd.exe [ 2200 ] (Intel Corporation)
C:\Program Files\HP\HP Officejet Pro 8600\bin\HPNetworkCommunicator.exe [ 2552 ] (Hewlett-Packard Co.)
C:\Windows\system32\svchost.exe [ 1368 ] (Microsoft Corporation)
C:\Windows\system32\taskhost.exe [ 1276 ] (Microsoft Corporation)
C:\Windows\system32\svchost.exe [ 1008 ] (Microsoft Corporation)
C:\Windows\system32\winlogon.exe [ 472 ] (Microsoft Corporation)
C:\Windows\Explorer.EXE [ 1272 ] (Microsoft Corporation)
C:\Windows\system32\WUDFHost.exe [ 3620 ] (Microsoft Corporation)
C:\Program Files\HP\HP Software Update\hpwuschd2.exe [ 2248 ] (Hewlett-Packard)
C:\Program Files\Microsoft Security Client\NisSrv.exe [ 1980 ] (Microsoft Corporation)
C:\Windows\System32\spoolsv.exe [ 1444 ] (Microsoft Corporation)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [ 1532 ] (Adobe Systems Incorporated)
C:\Windows\system32\svchost.exe [ 1708 ] (Microsoft Corporation)
C:\Users\Radek\AppData\Roaming\Dropbox\bin\Dropbox.exe [ 2344 ] (Dropbox, Inc.)
C:\Users\Radek\Desktop\MVS\MVS.exe [ 3444 ] ()
C:\Program Files\Common Files\Java\Java Update\jusched.exe [ 2328 ] (Oracle Corporation)
C:\Windows\system32\svchost.exe [ 632 ] (Microsoft Corporation)
C:\Windows\system32\csrss.exe [ 364 ] (Microsoft Corporation)
C:\Windows\system32\SearchProtocolHost.exe [ 3300 ] (Microsoft Corporation)
C:\Windows\System32\svchost.exe [ 896 ] (Microsoft Corporation)
F:\Lupo_PenSuite_v2013.04_Zero\Launcher\ASuite.exe [ 3496 ] (SalvadorSoftware)
C:\Windows\system32\SearchFilterHost.exe [ 2768 ] (Microsoft Corporation)
C:\Windows\system32\smss.exe [ 268 ] (Microsoft Corporation)
=== Services ===
SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe - [2012-10-15 08:42:44 | 257416 | (Adobe Systems Incorporated)]
SRV - [ ehRecvr | Usługa Odbiornik Windows Media Center | Stopped] - C:\Windows\ehome\ehRecvr.exe - [2010-11-20 22:29:29 | 556544 | (Microsoft Corporation)]
SRV - [ ehSched | Usługa harmonogramu programu Windows Media Center | Stopped] - C:\Windows\ehome\ehsched.exe - [2009-07-14 02:09:49 | 94720 | (Microsoft Corporation)]
SRV - [ MsMpSvc | Microsoft Antimalware Service | Running] - C:\Program Files\Microsoft Security Client\MsMpEng.exe - [2013-08-12 10:12:38 | 22208 | (Microsoft Corporation)]
SRV - [ WinDefend | Windows Defender | Stopped] - C:\Windows\System32\svchost.exe -k secsvcs - [1601-01-01 01:00:00 | FSF | ()] => File not found
#23
Posted 31 October 2013 - 06:29 AM
Thanks! You are great!
#24
Posted 31 October 2013 - 06:33 AM
One thing makes me wonder. Comparing your tool to OTL:
Are you whitelisting more svcs than OTL? Or it's a bug?
=== Services === SRV - [ AdobeFlashPlayerUpdateSvc | Adobe Flash Player Update Service | Stopped] - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe - [2012-10-15 08:42:44 | 257416 | (Adobe Systems Incorporated)] SRV - [ ehRecvr | Usługa Odbiornik Windows Media Center | Stopped] - C:\Windows\ehome\ehRecvr.exe - [2010-11-20 22:29:29 | 556544 | (Microsoft Corporation)] SRV - [ ehSched | Usługa harmonogramu programu Windows Media Center | Stopped] - C:\Windows\ehome\ehsched.exe - [2009-07-14 02:09:49 | 94720 | (Microsoft Corporation)] SRV - [ MsMpSvc | Microsoft Antimalware Service | Running] - C:\Program Files\Microsoft Security Client\MsMpEng.exe - [2013-08-12 10:12:38 | 22208 | (Microsoft Corporation)] SRV - [ WinDefend | Windows Defender | Stopped] - C:\Windows\System32\svchost.exe -k secsvcs - [1601-01-01 01:00:00 | FSF | ()] => File not found
[color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2013-10-14 07:55:37 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-08-12 09:12:38 | 000,295,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2013-08-12 09:12:38 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2013-05-27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2013-05-11 11:37:26 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2012-10-16 14:38:42 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
Are you whitelisting more svcs than OTL? Or it's a bug?
#25
Posted 31 October 2013 - 06:52 AM
I'm whitelisting more things than OTL. It's because you have a long log - I don't only whitelist Windows Services, also some Services by AMD and Microsoft etc. Do you understand?
#26
Posted 31 October 2013 - 06:54 AM
Sure
Let me know if I can be helpful later
Let me know if I can be helpful later
#27
Posted 01 November 2013 - 09:43 AM
Hello,
new version released:
- No new functions
- Only made the Code looking better => easier and shorter to understand
I need now to research how I manage listing drivers. This is , I think, pretty hard and difficult.
new version released:
- No new functions
- Only made the Code looking better => easier and shorter to understand
I need now to research how I manage listing drivers. This is , I think, pretty hard and difficult.
#28
Posted 02 November 2013 - 02:17 PM
C:\Users\Nutloaf\AppData\Local\CrossLoop\tvnserver.exe
Nope not there. I did have Crossloop installed for a one off fix a while back.
#29
Posted 04 November 2013 - 08:00 AM
You could delete this service if you like. Thanks!
#30
Posted 08 November 2013 - 07:55 AM
Update! Tool lists also Drivers now! Please test!
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users