This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus or spyware infection

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was surfing the web when I got hit by something. It changed my back ground to a warning stating the my computer is infected with spyware. BLAh Blah blah, Secre yourself right away. Remove all spyware from your PC. Now it keeps showing a pop up from the tool bar ststing that about anything I try is infected. Also wants me to run a System Tool Protect your PC. It wouldn't allow me to download the itmes I needed for Hijack this. Thanks.
Hi racin9m, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Let's try downloading a tool in a slightly different manner. Before you download this tool rename it to OTL.scr

Download OTL to your desktop.
  • Double click on OTL.scr to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Hi racin9m,

Locate the OTL.scr icon on your desktop and rename it to iexplore.exe Try running it now.
Hi racin9m,

The files will automatically be saved to the same location as the tool. If you saved OTL to your desktop the files would also be saved there. Please attach the files to your reply.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on the icon with the green + sign
Please do this wih both OTL.txt and Extra.txt

Thanks
Hi racin9m,

FrostWire and Limewire
You have FrostWire and LimeWire, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall FrostWire and LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


I see traces of Symantec (Norton) in your logs. Are you finished using this program?


Let's see if we can get some of this tidied up and get some other tools to run.

Next, Double click on OTL.exe (renamed iexplore.exe)
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
PRC - C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\oCmEjEl01805.exe ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:29775
O4 - HKCU..\Run: [A9YA3MI1CF]  File not found
O4 - HKCU..\RunOnce: [oCmEjEl01805] C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\oCmEjEl01805.exe ()
[2011/03/19 08:45:49 | 000,000,282 | -H– | M] () – C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2011/03/19 08:45:49 | 000,000,282 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/03/19 08:45:49 | 000,000,246 | -H– | M] () – C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2011/03/19 08:45:40 | 000,000,300 | -HS- | M] () – C:\WINDOWS\tasks\mqoyuwwdi.job
[2011/03/19 07:26:41 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2011/03/18 22:54:17 | 000,155,648 | RHS- | C] () – C:\WINDOWS\System32\w32tmh.dll

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

I need some information on a unidentified file. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box

C:\WINDOWS\Iruqya.exe


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete.


Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will a two notepad window, OTL.Txt

Please try to use copy and paste this time.

Please post bcak with
  • OTL fix log
  • VirusTotal results
  • OTL.txt
Can you open programs now without a warning?

Thanks
I don't use Norton. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Process oCmEjEl01805.exe killed successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\A9YA3MI1CF deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\oCmEjEl01805 deleted successfully. C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\oCmEjEl01805.exe moved successfully. C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job moved successfully. C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job moved successfully. C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job moved successfully. C:\WINDOWS\tasks\mqoyuwwdi.job moved successfully. C:\fsqwr.bmp moved successfully. C:\WINDOWS\system32\w32tmh.dll moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: admin ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 7140 bytes ->FireFox cache emptied: 110071113 bytes ->Flash cache emptied: 57598 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 83 bytes User: All Users User: alyssa ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 7140 bytes ->FireFox cache emptied: 60191169 bytes ->Flash cache emptied: 1229 bytes User: Application Data User: Chrissy User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56585 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 94567223 bytes ->Flash cache emptied: 2061 bytes User: KIDS !!!! User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 300 bytes User: Owner ->Temp folder emptied: 62849442 bytes ->Temporary Internet Files folder emptied: 3667030 bytes ->Java cache emptied: 1 bytes ->FireFox cache emptied: 54872638 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 9654 bytes User: Phone ->Temp folder emptied: 49988 bytes ->Temporary Internet Files folder emptied: 213126 bytes ->Java cache emptied: 463242 bytes ->FireFox cache emptied: 47369163 bytes ->Flash cache emptied: 57857 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1139607 bytes %systemroot%\System32 .tmp files removed: 21197993 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 474839 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91237356 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 172676 bytes RecycleBin emptied: 820672 bytes Total Files Cleaned = 524.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03192011_142609 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi racin9m, Please continue with the rest of the instructions. Let me know if you can open files/programs without recieving a warning. Thanks
VT Community Sign in ▼ My account ▼ Sign out Signing out… Languages ▼
VirusTotal's website has changed, we need new translations, do you feel like helping the community?
[removed]
Sign in to VT Community

Safety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.
email
password
Keep me logged in

Sign in
Signing in, please wait…
Login failed, please try again
Forgot your password? Create an account
Edit my profile
View my profile
Inbox
Virus Total
Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
iruq.txt
Submission date:
2011-03-19 19:15:49 (UTC)
Current status:
queued queued analysing finished
Result:
0/ 37 (0.0%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.03.20.00 2011.03.19 -
AntiVir 7.11.5.1 2011.03.18 -
Antiy-AVL 2.0.3.7 2011.03.19 -
Avast 4.8.1351.0 2011.03.19 -
Avast5 5.0.677.0 2011.03.19 -
BitDefender 7.2 2011.03.19 -
CAT-QuickHeal 11.00 2011.03.19 -
ClamAV 0.96.4.0 2011.03.19 -
Commtouch 5.2.11.5 2011.03.19 -
Comodo 8038 2011.03.19 -
Emsisoft 5.1.0.2 2011.03.19 -
eSafe 7.0.17.0 2011.03.17 -
eTrust-Vet 36.1.8223 2011.03.18 -
F-Prot 4.6.2.117 2011.03.19 -
Fortinet 4.2.254.0 2011.03.19 -
GData 21 2011.03.19 -
Ikarus T3.1.1.97.0 2011.03.19 -
Jiangmin 13.0.900 2011.03.18 -
K7AntiVirus 9.94.4155 2011.03.19 -
Kaspersky 7.0.0.125 2011.03.19 -
McAfee-GW-Edition 2010.1C 2011.03.19 -
Microsoft 1.6603 2011.03.19 -
NOD32 5968 2011.03.19 -
Norman 6.07.03 2011.03.19 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.19 -
PCTools 7.0.3.5 2011.03.19 -
Prevx 3.0 2011.03.19 -
Rising 23.49.04.05 2011.03.18 -
Sophos 4.63.0 2011.03.19 -
SUPERAntiSpyware 4.40.0.1006 2011.03.19 -
TheHacker 6.7.0.1.151 2011.03.18 -
TrendMicro 9.200.0.1012 2011.03.19 -
VBA32 3.12.14.3 2011.03.18 -
VIPRE 8755 2011.03.19 -
ViRobot 2011.3.19.4366 2011.03.19 -
VirusBuster 13.6.258.0 2011.03.19 -
Additional information
Show all
MD5 : 6726f544e11f27b89ef5775b0b211130
SHA1 : 93322694f60d562e0a4c55d5a41a72e56fc3ebd8
SHA256: e87fbb79f5c98d1c4f0d23fb92487533c4f51925edd2b1fe76dd235ea3c278ca
ssdeep: 3:oN3zaELAC:oRoC
File size : 21 bytes
First seen: 2011-03-19 19:15:49
Last seen : 2011-03-19 19:15:49
TrID:
Unknown!
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

VT Community

0

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team
Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?
You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

Goodware
Malware
Spam attachment/link

P2P download
Propagating via IM
Network worm

Drive-by-download


Anonymous limit exceeded: anonymous users can only make one comment per file or URL, either sign in or register in order to continue making reviews on this item. Note that anonymous user discrimination is based on IP addresses, hence, it may be possible that another user behind your same proxy or NAT connection already made a review.
Preview comment Edit comment
Post comment
Posting comment…
Comment successfully posted




ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
VirusTotal © Hispasec Sistemas - Blog - Twitter - Contact: [removed] - TOS & Privacy Policy
OTL logfile created on: 3/19/2011 3:21:39 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.97 Gb Total Space | 101.46 Gb Free Space | 69.99% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.71 Gb Free Space | 17.53% Space Free | Partition Type: FAT32
Drive N: | 3.63 Gb Total Space | 3.30 Gb Free Space | 90.97% Space Free | Partition Type: FAT32

Computer Name: CHRISMARK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MyFunCards_3v\bar\1.bin\3vmedint.exe (MyFunCards)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Philips\Philips Device Manager\bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll (SupportSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Symantec Core LC) – File not found
SRV - (HidServ) – File not found
SRV - (HauppaugeTVServer) – File not found
SRV - (getPlusHelper) getPlus® – File not found
SRV - (AppMgmt) – File not found
SRV - (MyFunCards_3vService) – C:\Program Files\MyFunCards_3v\bar\1.bin\3vbarsvc.exe (MyFunCards)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (hcwAVD2) – C:\WINDOWS\system32\drivers\HCWUSB2AV.sys (Conexant Systems, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SQTECH905C) – C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI