This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.EXE

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks in advance for any help given. Last night my anti-virus program began giving me alerts telling me it was blocking something called a black hole exploit from a program located at c:\syswow64\ping.exe. I commenced a scan with the anti-virus but it did not highlight that file or seem to think there were any viruses on my computer at all. I found the file manually and tried to delete it, but was informed that I needed the permission of something called "trusted installer" to make changes to it. I also found it in my resource monitor using an inordinate amount of CPU. I tried ending the process but it only restarted a few minutes later, so I suspended it, and it seems to be staying disabled for now. Also, and I'm not sure if this is related, but it seems like it is, when I perform google searches and select a link I would like to view the destination website loads for a split second before being redirected to an advertisement. I noticed on the self help portion of these forums that someone had posted instructions for getting rid of google redirects, and I'm planning on looking into that, but I felt I should mention this here as well because it seems that when I have the ping.exe process either ended or suspended the redirects stop. So please let me know if I should go ahead with trying to fix the redirect or let you handle it as part of the ping.exe problem. I am not entirely computer illiterate, but on this matter I am frankly lost. So I'm going to play babe-in-arms and let you step me through it. Also, as I was looking around your (seemingly very helpful) forums, I noticed that common procedure seems to be to post logs of some sort with a post. I'm sure this makes your jobs easier, unfortunately however I have no idea what sort of logs I'm supposed to be posting, so please forgive their omission. I'll be happy to include them as soon as I know what it is you're looking for. Thanks again. Mikey
One other thing I forgot to mention, and once again, I'm not completely sure this is related other than for the fact that it started happening around the same time. Windows' Action Center keeps telling me my firewall is off, so I tell it to turn it on, it says it can't and I have to turn it on manually, but when I go into control panel to do it the only option it gives me is to update firewall's settings, and the only option it gives me for THAT is to restore defaults, when I click on restore defaults it tells me it cna't change some of my settings, error code 0x8007042c. Like I said, I don't know if it's connected, but I figured I'd mention it since all three of these things started happening at the same time.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Here is TDSSKiller's log; I have to go to work, so it may not be till later tonight that I can get you OTL's log. 17:17:30.0852 4276 TDSS rootkit removing tool [removed] Oct 10 2011 09:40:06 17:17:31.0361 4276 ============================================================ 17:17:31.0361 4276 Current date / time: 2011/10/10 17:17:31.0361 17:17:31.0361 4276 SystemInfo: 17:17:31.0361 4276 17:17:31.0361 4276 OS Version: 6.1.7601 ServicePack: 1.0 17:17:31.0362 4276 Product type: Workstation 17:17:31.0362 4276 ComputerName: LAPTRAP 17:17:31.0362 4276 UserName: The Tapdancing Ninja 17:17:31.0362 4276 Windows directory: C:\Windows 17:17:31.0362 4276 System windows directory: C:\Windows 17:17:31.0362 4276 Running under WOW64 17:17:31.0362 4276 Processor architecture: Intel x64 17:17:31.0362 4276 Number of processors: 2 17:17:31.0362 4276 Page size: 0x1000 17:17:31.0362 4276 Boot type: Normal boot 17:17:31.0362 4276 ============================================================ 17:17:32.0017 4276 Initialize success 17:18:03.0640 6732 ============================================================ 17:18:03.0640 6732 Scan started 17:18:03.0640 6732 Mode: Manual; 17:18:03.0640 6732 ============================================================ 17:18:04.0408 6732 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 17:18:04.0418 6732 1394ohci - ok 17:18:04.0552 6732 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 17:18:04.0573 6732 ACPI - ok 17:18:04.0625 6732 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 17:18:04.0629 6732 AcpiPmi - ok 17:18:04.0695 6732 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 17:18:04.0718 6732 adp94xx - ok 17:18:04.0818 6732 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 17:18:04.0830 6732 adpahci - ok 17:18:04.0931 6732 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 17:18:04.0939 6732 adpu320 - ok 17:18:05.0028 6732 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 17:18:05.0050 6732 AFD - ok 17:18:05.0172 6732 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 17:18:05.0177 6732 agp440 - ok 17:18:05.0288 6732 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 17:18:05.0291 6732 aliide - ok 17:18:05.0324 6732 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 17:18:05.0328 6732 amdide - ok 17:18:05.0379 6732 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 17:18:05.0384 6732 AmdK8 - ok 17:18:05.0409 6732 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys 17:18:05.0414 6732 AmdPPM - ok 17:18:05.0456 6732 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 17:18:05.0463 6732 amdsata - ok 17:18:05.0548 6732 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 17:18:05.0557 6732 amdsbs - ok 17:18:05.0584 6732 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 17:18:05.0588 6732 amdxata - ok 17:18:05.0653 6732 ApfiltrService (d80cb25d90474c731c0d1312a6de3b13) C:\Windows\system32\drivers\Apfiltr.sys 17:18:05.0713 6732 ApfiltrService - ok 17:18:05.0824 6732 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 17:18:05.0829 6732 AppID - ok 17:18:05.0910 6732 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 17:18:05.0915 6732 arc - ok 17:18:05.0984 6732 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 17:18:05.0991 6732 arcsas - ok 17:18:06.0085 6732 ArcSoftKsUFilter (c130bc4a51b1382b2be8e44579ec4c0a) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys 17:18:06.0089 6732 ArcSoftKsUFilter - ok 17:18:06.0191 6732 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 17:18:06.0196 6732 AsyncMac - ok 17:18:06.0244 6732 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 17:18:06.0249 6732 atapi - ok 17:18:06.0422 6732 athr (c8679a07267f030704168e45e27c3d43) C:\Windows\system32\DRIVERS\athrx.sys 17:18:06.0563 6732 athr - ok 17:18:06.0714 6732 AVGIDSDriver (e29ea1a0ec7ab9fa2dc7e75a03f12a4f) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 17:18:06.0720 6732 AVGIDSDriver - ok 17:18:06.0758 6732 AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 17:18:06.0762 6732 AVGIDSEH - ok 17:18:06.0788 6732 AVGIDSFilter (ed2b25bd7fe35d1944211968842d30da) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 17:18:06.0792 6732 AVGIDSFilter - ok 17:18:06.0858 6732 Avgldx64 (dadfccfb036da99fa83e7e1d29290a6c) C:\Windows\system32\DRIVERS\avgldx64.sys 17:18:06.0868 6732 Avgldx64 - ok 17:18:06.0918 6732 Avgmfx64 (36b1a5843695766eac714daffc5b84d1) C:\Windows\system32\DRIVERS\avgmfx64.sys 17:18:06.0923 6732 Avgmfx64 - ok 17:18:06.0991 6732 Avgrkx64 (1102239fb724527f1febbbbccf6bf313) C:\Windows\system32\DRIVERS\avgrkx64.sys 17:18:07.0008 6732 Avgrkx64 - ok 17:18:07.0062 6732 Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 17:18:07.0075 6732 Avgtdia - ok 17:18:07.0192 6732 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 17:18:07.0215 6732 b06bdrv - ok 17:18:07.0318 6732 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 17:18:07.0328 6732 b57nd60a - ok 17:18:07.0388 6732 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 17:18:07.0394 6732 Beep - ok 17:18:07.0460 6732 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys 17:18:07.0465 6732 blbdrive - ok 17:18:07.0509 6732 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 17:18:07.0515 6732 bowser - ok 17:18:07.0555 6732 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 17:18:07.0559 6732 BrFiltLo - ok 17:18:07.0597 6732 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 17:18:07.0601 6732 BrFiltUp - ok 17:18:07.0659 6732 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 17:18:07.0671 6732 Brserid - ok 17:18:07.0703 6732 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 17:18:07.0708 6732 BrSerWdm - ok 17:18:07.0743 6732 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:18:07.0747 6732 BrUsbMdm - ok 17:18:07.0795 6732 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 17:18:07.0799 6732 BrUsbSer - ok 17:18:07.0909 6732 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 17:18:07.0914 6732 BTHMODEM - ok 17:18:07.0960 6732 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 17:18:07.0966 6732 cdfs - ok 17:18:08.0064 6732 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys 17:18:08.0072 6732 cdrom - ok 17:18:08.0188 6732 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 17:18:08.0193 6732 circlass - ok 17:18:08.0238 6732 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 17:18:08.0250 6732 CLFS - ok 17:18:08.0372 6732 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys 17:18:08.0377 6732 CmBatt - ok 17:18:08.0419 6732 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 17:18:08.0423 6732 cmdide - ok 17:18:08.0496 6732 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 17:18:08.0519 6732 CNG - ok 17:18:08.0681 6732 CnxtHdAudService (1f394df3714ed4280047810790e6df69) C:\Windows\system32\drivers\CHDRT64.sys 17:18:08.0803 6732 CnxtHdAudService - ok 17:18:08.0908 6732 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys 17:18:08.0912 6732 Compbatt - ok 17:18:08.0956 6732 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 17:18:08.0962 6732 CompositeBus - ok 17:18:09.0024 6732 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 17:18:09.0028 6732 crcdisk - ok 17:18:09.0107 6732 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 17:18:09.0113 6732 DfsC - ok 17:18:09.0159 6732 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 17:18:09.0161 6732 discache - ok 17:18:09.0229 6732 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 17:18:09.0234 6732 Disk - ok 17:18:09.0344 6732 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 17:18:09.0347 6732 drmkaud - ok 17:18:09.0405 6732 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 17:18:09.0439 6732 DXGKrnl - ok 17:18:09.0497 6732 e1yexpress (50ad8fc1dc800ff36087994c8f7fdff2) C:\Windows\system32\DRIVERS\e1y60x64.sys 17:18:09.0507 6732 e1yexpress - ok 17:18:09.0637 6732 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 17:18:09.0750 6732 ebdrv - ok 17:18:09.0898 6732 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 17:18:09.0921 6732 elxstor - ok 17:18:09.0952 6732 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 17:18:09.0956 6732 ErrDev - ok 17:18:10.0083 6732 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 17:18:10.0092 6732 exfat - ok 17:18:10.0113 6732 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 17:18:10.0122 6732 fastfat - ok 17:18:10.0180 6732 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 17:18:10.0185 6732 fdc - ok 17:18:10.0309 6732 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 17:18:10.0315 6732 FileInfo - ok 17:18:10.0349 6732 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 17:18:10.0354 6732 Filetrace - ok 17:18:10.0388 6732 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 17:18:10.0392 6732 flpydisk - ok 17:18:10.0461 6732 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 17:18:10.0472 6732 FltMgr - ok 17:18:10.0526 6732 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 17:18:10.0531 6732 FsDepends - ok 17:18:10.0559 6732 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 17:18:10.0564 6732 Fs_Rec - ok 17:18:10.0606 6732 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 17:18:10.0614 6732 fvevol - ok 17:18:10.0653 6732 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 17:18:10.0658 6732 gagp30kx - ok 17:18:10.0702 6732 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 17:18:10.0706 6732 hcw85cir - ok 17:18:10.0757 6732 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 17:18:10.0769 6732 HdAudAddService - ok 17:18:10.0892 6732 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 17:18:10.0898 6732 HDAudBus - ok 17:18:10.0941 6732 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 17:18:10.0945 6732 HidBatt - ok 17:18:10.0980 6732 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 17:18:10.0986 6732 HidBth - ok 17:18:11.0026 6732 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 17:18:11.0030 6732 HidIr - ok 17:18:11.0100 6732 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys 17:18:11.0105 6732 HidUsb - ok 17:18:11.0156 6732 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 17:18:11.0161 6732 HpSAMD - ok 17:18:11.0272 6732 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 17:18:11.0306 6732 HTTP - ok 17:18:11.0366 6732 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 17:18:11.0367 6732 hwpolicy - ok 17:18:11.0489 6732 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 17:18:11.0496 6732 i8042prt - ok 17:18:11.0544 6732 iaStor (f7ce9be72edac499b713eca6dae5d26f) C:\Windows\system32\drivers\iaStor.sys 17:18:11.0551 6732 iaStor - ok 17:18:11.0672 6732 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 17:18:11.0695 6732 iaStorV - ok 17:18:12.0147 6732 igfx (efe5a0af39a8e179624117c521f1e012) C:\Windows\system32\DRIVERS\igdkmd64.sys 17:18:12.0501 6732 igfx - ok 17:18:12.0578 6732 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 17:18:12.0582 6732 iirsp - ok 17:18:12.0658 6732 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys 17:18:12.0697 6732 IntcDAud - ok 17:18:12.0758 6732 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 17:18:12.0762 6732 intelide - ok 17:18:12.0820 6732 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys 17:18:12.0824 6732 intelppm - ok 17:18:12.0914 6732 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:18:12.0919 6732 IpFilterDriver - ok 17:18:12.0983 6732 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 17:18:12.0988 6732 IPMIDRV - ok 17:18:13.0027 6732 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 17:18:13.0033 6732 IPNAT - ok 17:18:13.0076 6732 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 17:18:13.0080 6732 IRENUM - ok 17:18:13.0123 6732 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 17:18:13.0137 6732 isapnp - ok 17:18:13.0180 6732 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 17:18:13.0190 6732 iScsiPrt - ok 17:18:13.0228 6732 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys 17:18:13.0232 6732 kbdclass - ok 17:18:13.0277 6732 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 17:18:13.0281 6732 kbdhid - ok 17:18:13.0339 6732 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 17:18:13.0345 6732 KSecDD - ok 17:18:13.0364 6732 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 17:18:13.0371 6732 KSecPkg - ok 17:18:13.0391 6732 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 17:18:13.0395 6732 ksthunk - ok 17:18:13.0455 6732 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 17:18:13.0461 6732 lltdio - ok 17:18:13.0610 6732 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 17:18:13.0616 6732 LSI_FC - ok 17:18:13.0654 6732 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 17:18:13.0660 6732 LSI_SAS - ok 17:18:13.0699 6732 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 17:18:13.0703 6732 LSI_SAS2 - ok 17:18:13.0740 6732 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 17:18:13.0746 6732 LSI_SCSI - ok 17:18:13.0785 6732 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 17:18:13.0791 6732 luafv - ok 17:18:13.0831 6732 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 17:18:13.0836 6732 megasas - ok 17:18:13.0864 6732 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 17:18:13.0875 6732 MegaSR - ok 17:18:13.0963 6732 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\drivers\HECIx64.sys 17:18:13.0967 6732 MEIx64 - ok 17:18:14.0044 6732 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 17:18:14.0049 6732 Modem - ok 17:18:14.0124 6732 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 17:18:14.0129 6732 monitor - ok 17:18:14.0173 6732 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys 17:18:14.0178 6732 mouclass - ok 17:18:14.0228 6732 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\drivers\mouhid.sys 17:18:14.0232 6732 mouhid - ok 17:18:14.0284 6732 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 17:18:14.0288 6732 mountmgr - ok 17:18:14.0342 6732 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 17:18:14.0349 6732 mpio - ok 17:18:14.0426 6732 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 17:18:14.0431 6732 mpsdrv - ok 17:18:14.0477 6732 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 17:18:14.0485 6732 MRxDAV - ok 17:18:14.0518 6732 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:18:14.0537 6732 mrxsmb - ok 17:18:14.0580 6732 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:18:14.0591 6732 mrxsmb10 - ok 17:18:14.0622 6732 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:18:14.0628 6732 mrxsmb20 - ok 17:18:14.0665 6732 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 17:18:14.0669 6732 msahci - ok 17:18:14.0709 6732 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 17:18:14.0716 6732 msdsm - ok 17:18:14.0778 6732 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 17:18:14.0782 6732 Msfs - ok 17:18:14.0861 6732 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 17:18:14.0864 6732 mshidkmdf - ok 17:18:14.0924 6732 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 17:18:14.0929 6732 msisadrv - ok 17:18:15.0025 6732 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 17:18:15.0029 6732 MSKSSRV - ok 17:18:15.0046 6732 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 17:18:15.0049 6732 MSPCLOCK - ok 17:18:15.0071 6732 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 17:18:15.0074 6732 MSPQM - ok 17:18:15.0109 6732 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 17:18:15.0132 6732 MsRPC - ok 17:18:15.0174 6732 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 17:18:15.0178 6732 mssmbios - ok 17:18:15.0267 6732 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 17:18:15.0270 6732 MSTEE - ok 17:18:15.0297 6732 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 17:18:15.0301 6732 MTConfig - ok 17:18:15.0332 6732 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 17:18:15.0337 6732 Mup - ok 17:18:15.0404 6732 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 17:18:15.0415 6732 NativeWifiP - ok 17:18:15.0519 6732 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 17:18:15.0551 6732 NDIS - ok 17:18:15.0602 6732 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 17:18:15.0606 6732 NdisCap - ok 17:18:15.0639 6732 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 17:18:15.0643 6732 NdisTapi - ok 17:18:15.0686 6732 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 17:18:15.0691 6732 Ndisuio - ok 17:18:15.0730 6732 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 17:18:15.0738 6732 NdisWan - ok 17:18:15.0774 6732 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 17:18:15.0779 6732 NDProxy - ok 17:18:15.0854 6732 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 17:18:15.0858 6732 NetBIOS - ok 17:18:15.0911 6732 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 17:18:15.0919 6732 NetBT - ok 17:18:16.0069 6732 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 17:18:16.0073 6732 nfrd960 - ok 17:18:16.0126 6732 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 17:18:16.0131 6732 Npfs - ok 17:18:16.0163 6732 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 17:18:16.0165 6732 nsiproxy - ok 17:18:16.0254 6732 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 17:18:16.0322 6732 Ntfs - ok 17:18:16.0367 6732 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 17:18:16.0370 6732 Null - ok 17:18:16.0734 6732 nvlddmkm (dd81fbc57ab9134cddc5ce90880bfd80) C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:18:17.0054 6732 nvlddmkm - ok 17:18:17.0143 6732 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 17:18:17.0150 6732 nvraid - ok 17:18:17.0185 6732 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 17:18:17.0192 6732 nvstor - ok 17:18:17.0290 6732 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 17:18:17.0296 6732 nv_agp - ok 17:18:17.0394 6732 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 17:18:17.0400 6732 ohci1394 - ok 17:18:17.0457 6732 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys 17:18:17.0463 6732 Parport - ok 17:18:17.0490 6732 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 17:18:17.0495 6732 partmgr - ok 17:18:17.0545 6732 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 17:18:17.0553 6732 pci - ok 17:18:17.0598 6732 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 17:18:17.0603 6732 pciide - ok 17:18:17.0651 6732 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 17:18:17.0659 6732 pcmcia - ok 17:18:17.0704 6732 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 17:18:17.0709 6732 pcw - ok 17:18:17.0745 6732 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 17:18:17.0777 6732 PEAUTH - ok 17:18:17.0970 6732 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 17:18:17.0976 6732 PptpMiniport - ok 17:18:18.0016 6732 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 17:18:18.0021 6732 Processor - ok 17:18:18.0150 6732 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 17:18:18.0155 6732 Psched - ok 17:18:18.0237 6732 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 17:18:18.0316 6732 ql2300 - ok 17:18:18.0354 6732 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 17:18:18.0360 6732 ql40xx - ok 17:18:18.0390 6732 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 17:18:18.0394 6732 QWAVEdrv - ok 17:18:18.0439 6732 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 17:18:18.0443 6732 RasAcd - ok 17:18:18.0491 6732 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:18:18.0496 6732 RasAgileVpn - ok 17:18:18.0540 6732 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:18:18.0548 6732 Rasl2tp - ok 17:18:18.0632 6732 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 17:18:18.0638 6732 RasPppoe - ok 17:18:18.0665 6732 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 17:18:18.0670 6732 RasSstp - ok 17:18:18.0716 6732 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 17:18:18.0727 6732 rdbss - ok 17:18:18.0767 6732 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys 17:18:18.0772 6732 rdpbus - ok 17:18:18.0819 6732 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:18:18.0820 6732 RDPCDD - ok 17:18:18.0870 6732 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 17:18:18.0871 6732 RDPENCDD - ok 17:18:18.0920 6732 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 17:18:18.0921 6732 RDPREFMP - ok 17:18:18.0968 6732 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 17:18:18.0976 6732 RDPWD - ok 17:18:19.0070 6732 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 17:18:19.0078 6732 rdyboost - ok 17:18:19.0159 6732 RSPCIESTOR (546d7f426776090b90ef5f195b6ae662) C:\Windows\system32\DRIVERS\RtsPStor.sys 17:18:19.0170 6732 RSPCIESTOR - ok 17:18:19.0265 6732 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 17:18:19.0271 6732 rspndr - ok 17:18:19.0329 6732 RTL8167 (ea5532868ba76923d75bcb2a1448d810) C:\Windows\system32\DRIVERS\Rt64win7.sys 17:18:19.0353 6732 RTL8167 - ok 17:18:19.0465 6732 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 17:18:19.0470 6732 sbp2port - ok 17:18:19.0572 6732 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 17:18:19.0577 6732 scfilter - ok 17:18:19.0656 6732 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\DRIVERS\sdbus.sys 17:18:19.0662 6732 sdbus - ok 17:18:19.0703 6732 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 17:18:19.0707 6732 secdrv - ok 17:18:19.0808 6732 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys 17:18:19.0812 6732 Serenum - ok 17:18:19.0838 6732 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys 17:18:19.0844 6732 Serial - ok 17:18:19.0879 6732 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 17:18:19.0884 6732 sermouse - ok 17:18:19.0958 6732 SFEP (286d3889e6ab5589646ff8a63cb928ae) C:\Windows\system32\drivers\SFEP.sys 17:18:19.0972 6732 SFEP - ok 17:18:20.0014 6732 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 17:18:20.0019 6732 sffdisk - ok 17:18:20.0072 6732 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 17:18:20.0076 6732 sffp_mmc - ok 17:18:20.0111 6732 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 17:18:20.0115 6732 sffp_sd - ok 17:18:20.0172 6732 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 17:18:20.0176 6732 sfloppy - ok 17:18:20.0263 6732 Sftfs (a40abfdcb75f835fdf3ce0cc64e4250d) C:\Windows\system32\DRIVERS\Sftfslh.sys 17:18:20.0297 6732 Sftfs - ok 17:18:20.0398 6732 Sftplay (411769ed1cb12d2b44217734347bdb7a) C:\Windows\system32\DRIVERS\Sftplaylh.sys 17:18:20.0408 6732 Sftplay - ok 17:18:20.0437 6732 Sftredir (a14d0df34bbb00ea94da16193d0c7957) C:\Windows\system32\DRIVERS\Sftredirlh.sys 17:18:20.0442 6732 Sftredir - ok 17:18:20.0486 6732 Sftvol (393b22addd89979eb1c60898f51c3648) C:\Windows\system32\DRIVERS\Sftvollh.sys 17:18:20.0490 6732 Sftvol - ok 17:18:20.0580 6732 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 17:18:20.0584 6732 SiSRaid2 - ok 17:18:20.0635 6732 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 17:18:20.0640 6732 SiSRaid4 - ok 17:18:20.0691 6732 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 17:18:20.0696 6732 Smb - ok 17:18:20.0829 6732 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 17:18:20.0833 6732 spldr - ok 17:18:20.0907 6732 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 17:18:20.0930 6732 srv - ok 17:18:20.0966 6732 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 17:18:20.0979 6732 srv2 - ok 17:18:21.0011 6732 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 17:18:21.0019 6732 srvnet - ok 17:18:21.0069 6732 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 17:18:21.0074 6732 stexstor - ok 17:18:21.0132 6732 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 17:18:21.0135 6732 swenum - ok 17:18:21.0268 6732 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys 17:18:21.0329 6732 Tcpip - ok 17:18:21.0466 6732 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys 17:18:21.0495 6732 TCPIP6 - ok 17:18:21.0542 6732 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 17:18:21.0546 6732 tcpipreg - ok 17:18:21.0581 6732 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 17:18:21.0586 6732 TDPIPE - ok 17:18:21.0606 6732 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 17:18:21.0611 6732 TDTCP - ok 17:18:21.0642 6732 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 17:18:21.0648 6732 tdx - ok 17:18:21.0686 6732 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 17:18:21.0691 6732 TermDD - ok 17:18:21.0806 6732 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:18:21.0810 6732 tssecsrv - ok 17:18:21.0840 6732 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 17:18:21.0845 6732 TsUsbFlt - ok 17:18:21.0877 6732 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 17:18:21.0881 6732 TsUsbGD - ok 17:18:21.0929 6732 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 17:18:21.0935 6732 tunnel - ok 17:18:21.0974 6732 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 17:18:21.0979 6732 uagp35 - ok 17:18:22.0033 6732 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 17:18:22.0064 6732 udfs - ok 17:18:22.0175 6732 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 17:18:22.0179 6732 uliagpkx - ok 17:18:22.0267 6732 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 17:18:22.0272 6732 umbus - ok 17:18:22.0311 6732 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 17:18:22.0315 6732 UmPass - ok 17:18:22.0362 6732 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 17:18:22.0368 6732 usbccgp - ok 17:18:22.0413 6732 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 17:18:22.0419 6732 usbcir - ok 17:18:22.0463 6732 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys 17:18:22.0480 6732 usbehci - ok 17:18:22.0576 6732 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 17:18:22.0588 6732 usbhub - ok 17:18:22.0642 6732 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 17:18:22.0646 6732 usbohci - ok 17:18:22.0696 6732 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 17:18:22.0701 6732 usbprint - ok 17:18:22.0798 6732 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 17:18:22.0803 6732 usbscan - ok 17:18:22.0860 6732 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:18:22.0866 6732 USBSTOR - ok 17:18:22.0898 6732 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 17:18:22.0902 6732 usbuhci - ok 17:18:22.0944 6732 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys 17:18:22.0952 6732 usbvideo - ok 17:18:23.0136 6732 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 17:18:23.0140 6732 vdrvroot - ok 17:18:23.0205 6732 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 17:18:23.0209 6732 vga - ok 17:18:23.0254 6732 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 17:18:23.0258 6732 VgaSave - ok 17:18:23.0310 6732 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 17:18:23.0319 6732 vhdmp - ok 17:18:23.0364 6732 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 17:18:23.0368 6732 viaide - ok 17:18:23.0423 6732 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 17:18:23.0429 6732 volmgr - ok 17:18:23.0480 6732 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 17:18:23.0491 6732 volmgrx - ok 17:18:23.0530 6732 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 17:18:23.0542 6732 volsnap - ok 17:18:23.0581 6732 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 17:18:23.0588 6732 vsmraid - ok 17:18:23.0700 6732 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 17:18:23.0704 6732 vwifibus - ok 17:18:23.0745 6732 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 17:18:23.0749 6732 vwififlt - ok 17:18:23.0798 6732 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 17:18:23.0802 6732 WacomPen - ok 17:18:23.0876 6732 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:18:23.0882 6732 WANARP - ok 17:18:23.0900 6732 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:18:23.0902 6732 Wanarpv6 - ok 17:18:24.0039 6732 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 17:18:24.0043 6732 Wd - ok 17:18:24.0090 6732 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 17:18:24.0122 6732 Wdf01000 - ok 17:18:24.0274 6732 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 17:18:24.0278 6732 WfpLwf - ok 17:18:24.0305 6732 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 17:18:24.0309 6732 WIMMount - ok 17:18:24.0431 6732 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 17:18:24.0435 6732 WmiAcpi - ok 17:18:24.0499 6732 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 17:18:24.0504 6732 ws2ifsl - ok 17:18:24.0554 6732 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 17:18:24.0561 6732 WudfPf - ok 17:18:24.0610 6732 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:18:24.0618 6732 WUDFRd - ok 17:18:24.0711 6732 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:18:24.0734 6732 \Device\Harddisk0\DR0 - ok 17:18:24.0745 6732 Boot (0x1200) (f3f4d70cf5529c813a5a9ee2c1adec93) \Device\Harddisk0\DR0\Partition0 17:18:24.0747 6732 \Device\Harddisk0\DR0\Partition0 - ok 17:18:24.0759 6732 Boot (0x1200) (5c85b7132166071becbd72c42d3e7602) \Device\Harddisk0\DR0\Partition1 17:18:24.0761 6732 \Device\Harddisk0\DR0\Partition1 - ok 17:18:24.0762 6732 ============================================================ 17:18:24.0762 6732 Scan finished 17:18:24.0762 6732 ============================================================ 17:18:24.0783 4456 Detected object count: 0 17:18:24.0783 4456 Actual detected object count: 0
Ok, so OTL keeps freezing, or, at least it appears to. It keeps stopping when it's progress bar says "manual file scan - looking at folder: C:\program files\windows sidebar…". It was like that when I got home from work , and I figured eight hours would be enough time for it to be frozen there so I don't think it's impatience on my part, but if it is let me know and I'll start it again.
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hey, not to be a dick, but seriously, are we just skipping over the OTL you told me to run right to the combofix you're telling…um, everyone…to…uh run? I guess what I'm asking is are you a real person? Forgive my naivete, but y'all post DON'T RUN COMBOFIX all over the place as if it's the computer equivalent of the bubonic plague. But here we are in my case the first tool found nothing, second tool only froze, and here we go hopping into combofix like you seem to tell everyone. I'm sorry if I'm overstepping my bounds but forgive me for being thorough. Until I get a response that I am satisfied is from an actual human being I refuse to download or run any more programs. Call me a dick or…something, just let me know I'm dealing with a real person. Thank you. Mikey
Try this,if it won't disable AVG,try to run Combofix anyway. Open the AVG 2011 Control Center, by right clicking on the AVG icon on task bar. Click on Open AVG User Interface. On the Menu Bar, click on Tools Click Advanced Settings In the new screen which opens, scroll down to Temporarily disable AVG protection. Click on it to highlight it. In the right hand pane, tick the box for Temporarily disable AVG protection Click Apply In the next screen which opens, select 15 minutes from the drop down menu, then click the Disable real time protection button. Click OK
Combofix also appears to have frozen, it's exactly where it was when I went to bed, like, six hours ago. Also in that time AVG seems to have started working again and is now warning me that Combofix\regt.3xe is a threat and I should move it to the vault I'm also noticing a lot of new folders that weren't there when we started this process, stuff called Qoobox, a locked recycle bin file with a dollar sign in front of it, lots of file beginning with NTuser.dat.
Sorry, spoke a little to soon, I guess. I reran combofix, this time it updated and then ran without a hitch. Except that after it restarted and gave me the log nothing else would open, firefox, notepad, nothing, kept telling me something about a directory that had been marked for deletion, had to restart just to be able to get online to tell you this. Anyway, here's your log. ComboFix 11-10-11.05 - The Tapdancing Ninja 10/11/2011 21:43:03.4.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.2541 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\The Tapdancing Ninja\AppData\Local\Temp\1.tmp\F_IN_BOX.dll c:\users\THETAP~1\AppData\Local\Temp\1.tmp\F_IN_BOX.dll c:\windows\system32\drivers\etc\lmhosts . . ((((((((((((((((((((((((( Files Created from 2011-09-12 to 2011-10-12 ))))))))))))))))))))))))))))))) . . . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-09 01:52 . 2011-09-09 01:52 94208 —-a-w- c:\windows\DIIUnin.exe 2011-09-09 01:52 . 2011-09-09 01:52 2829 —-a-w- c:\windows\DIIUnin.pif 2011-08-24 09:47 . 2010-06-24 18:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-08-08 10:08 . 2011-08-08 10:08 46672 —-a-w- c:\windows\system32\drivers\avgmfx64.sys 2011-07-22 05:22 . 2011-08-23 07:08 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-22 04:54 . 2011-08-23 07:08 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-07-16 05:41 . 2011-08-23 07:08 362496 —-a-w- c:\windows\system32\wow64win.dll 2011-07-16 05:41 . 2011-08-23 07:08 243200 —-a-w- c:\windows\system32\wow64.dll 2011-07-16 05:41 . 2011-08-23 07:08 13312 —-a-w- c:\windows\system32\wow64cpu.dll 2011-07-16 05:39 . 2011-08-23 07:08 16384 —-a-w- c:\windows\system32\ntvdm64.dll 2011-07-16 05:37 . 2011-08-23 07:08 421888 —-a-w- c:\windows\system32\KernelBase.dll 2011-07-16 05:21 . 2011-08-23 07:08 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2011-07-16 05:21 . 2011-08-23 07:08 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2011-07-16 04:29 . 2011-08-23 07:08 14336 —-a-w- c:\windows\SysWow64\ntvdm64.dll 2011-07-16 04:26 . 2011-08-23 07:08 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-07-16 04:25 . 2011-08-23 07:08 25600 —-a-w- c:\windows\SysWow64\setup16.exe 2011-07-16 04:24 . 2011-08-23 07:08 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-07-16 04:24 . 2011-08-23 07:08 272384 —-a-w- c:\windows\SysWow64\KernelBase.dll 2011-07-16 04:15 . 2011-08-23 07:08 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 5120 —ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll 2011-07-16 04:15 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll 2011-07-16 02:21 . 2011-08-23 07:08 7680 —-a-w- c:\windows\SysWow64\instnm.exe 2011-07-16 02:21 . 2011-08-23 07:08 2048 —-a-w- c:\windows\SysWow64\user.exe 2011-07-16 02:17 . 2011-08-23 07:08 6144 —ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17 . 2011-08-23 07:08 4608 —ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17 . 2011-08-23 07:08 3584 —ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17 . 2011-08-23 07:08 3072 —ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312] "PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032] "InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-07-28 1485208] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-09-23 2404704] . c:\users\The Tapdancing Ninja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-02-19 99104] R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe [2011-02-14 44736] R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe [2011-03-30 1021112] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [x] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [x] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [x] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-09-12 5265248] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-29 2361344] S2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [2011-02-15 47104] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2010-11-27 398176] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2011-02-23 105024] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-01-20 887000] S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-02-19 546608] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2011-02-28 852160] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] S3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-01-20 286936] . . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418328] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://sony.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\The Tapdancing Ninja\AppData\Roaming\Mozilla\Firefox\Profiles\7o8aghgr.default\ . - - - - ORPHANS REMOVED - - - - . HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgr.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe c:\windows\SysWOW64\DllHost.exe c:\windows\SysWOW64\DllHost.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2011-10-11 22:02:03 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-12 02:02 . Pre-Run: 291,833,511,936 bytes free Post-Run: 291,400,388,608 bytes free . - - End Of File - - 9491D32C33E5072F6328C06A0036FD5F
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Here's the log from malwarebytes…does it make a difference if I ran the program i already had or did you need me to download it anew? If so let me know and I will. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7928 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 10/12/2011 6:03:30 AM mbam-log-2011-10-12 (06-03-30).txt Scan type: Quick scan Objects scanned: 178047 Time elapsed: 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI