This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.BHO

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI



HI Jeff:

Combofix has been running for 10 and 1/2 hours with the message on the screen:

"Preparing Log Report

Do not run any programs until Combofix has finished"


Can Combofix take that long to generate a report?

If somethings wrong, how do I stop the program?

Any suggestions??

~James



Hi James,

Go ahead and shut down your computer. Reboot into Safe Mode and attempt to run ComboFix again. :)

Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode with Networking menu item
  • Press Enter.


Hey Jeff: I rebooted into SAFE MODE and scanned with a fresh copy of COMBOFix.EXE

Here's the output file:

ComboFix 11-11-09.02 - Admin 11/09/2011 21:34:19.4.8 - x64 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6134.5397 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus Plus *Disabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
FW: CA Personal Firewall *Disabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591}
SP: CA Anti-Virus Plus *Disabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
.
.
2011-11-10 02:45 . 2011-11-10 02:45 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-10 02:45 . 2011-11-10 02:45 ——– d—–w- c:\users\Admin\AppData\Local\temp
2011-11-09 21:41 . 2011-09-20 21:06 1426304 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 21:41 . 2011-09-30 16:16 893440 —-a-w- c:\program files\Common Files\System\wab32.dll
2011-11-09 21:41 . 2011-09-30 16:16 50688 —-a-w- c:\program files\Windows Mail\wabimp.dll
2011-11-09 21:41 . 2011-09-30 15:57 707584 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-07 18:20 . 2011-11-07 18:20 ——– d—–w- c:\program files\Java
2011-11-07 00:09 . 2011-11-07 00:09 525544 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-06 16:30 . 2010-05-26 16:41 2106216 —-a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2011-11-06 16:30 . 2010-05-26 16:41 1868128 —-a-w- c:\windows\SysWow64\d3dcsx_43.dll
2011-11-06 16:30 . 2010-05-26 16:41 470880 —-a-w- c:\windows\SysWow64\d3dx10_43.dll
2011-11-06 16:30 . 2010-05-26 16:41 248672 —-a-w- c:\windows\SysWow64\d3dx11_43.dll
2011-11-06 16:30 . 2010-05-26 16:41 1998168 —-a-w- c:\windows\SysWow64\D3DX9_43.dll
2011-11-05 01:10 . 2011-11-05 01:10 ——– d—–w- C:\_OTL
2011-11-05 00:57 . 2011-11-05 00:57 ——– d—–w- c:\program files (x86)\ERUNT
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\users\Admin\AppData\Roaming\Malwarebytes
2011-10-30 04:20 . 2011-10-30 04:20 ——– d—–w- c:\programdata\Malwarebytes
2011-10-30 04:20 . 2011-10-31 18:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-10-30 04:20 . 2011-08-31 21:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-10-29 18:34 . 2011-10-29 18:34 388096 —-a-r- c:\users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-29 18:34 . 2011-10-29 18:34 ——– d—–w- c:\program files (x86)\Trend Micro
2011-10-14 23:54 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A8D30E98-67CE-4263-A46B-1E88087603AA}\mpengine.dll
2011-10-13 00:10 . 2011-09-06 13:56 2764288 —-a-w- c:\windows\system32\win32k.sys
2011-10-13 00:09 . 2011-08-25 16:20 735744 —-a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:19 847360 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:19 332288 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 00:09 . 2011-08-25 16:15 555520 —-a-w- c:\windows\SysWow64\UIAutomationCore.dll
2011-10-13 00:09 . 2011-08-25 16:14 563712 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-10-13 00:09 . 2011-08-25 16:14 238080 —-a-w- c:\windows\SysWow64\oleacc.dll
2011-10-13 00:09 . 2011-08-25 13:54 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 00:09 . 2011-08-25 13:31 4096 —-a-w- c:\windows\SysWow64\oleaccrc.dll
2011-10-13 00:08 . 2011-07-29 16:08 375808 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:08 289792 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:06 73216 —-a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:06 100352 —-a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 00:08 . 2011-07-29 16:01 293376 —-a-w- c:\windows\SysWow64\psisdecd.dll
2011-10-13 00:08 . 2011-07-29 16:01 217088 —-a-w- c:\windows\SysWow64\psisrndr.ax
2011-10-13 00:08 . 2011-07-29 16:00 57856 —-a-w- c:\windows\SysWow64\MSDvbNP.ax
2011-10-13 00:08 . 2011-07-29 16:00 69632 —-a-w- c:\windows\SysWow64\Mpeg2Data.ax
2011-10-12 00:03 . 2011-10-12 00:03 ——– d—–w- c:\program files\iPod
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files\iTunes
2011-10-12 00:02 . 2011-10-12 00:03 ——– d—–w- c:\program files (x86)\iTunes
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files\Bonjour
2011-10-11 23:54 . 2011-10-11 23:54 ——– d—–w- c:\program files (x86)\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-16 09:41 . 2011-06-07 10:25 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-16 08:23 . 2010-12-26 00:43 2524176 —-a-w- c:\windows\system32\winsflt.dll
2011-09-16 08:23 . 2010-12-26 00:43 1744912 —-a-w- c:\windows\SysWow64\winsflt.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\SysWow64\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 1422672 —-a-w- c:\windows\system32\cfgmig32.dll
2011-09-16 08:19 . 2010-12-26 00:43 263504 —-a-w- c:\windows\SysWow64\cfgmig32.exe
2011-09-16 08:19 . 2011-09-16 08:20 95568 —-a-w- c:\windows\system32\vetredir.dll
2011-09-16 08:19 . 2011-09-16 08:20 128336 —-a-w- c:\windows\system32\isafeif.dll
2011-09-16 08:19 . 2010-01-21 13:34 141136 —-a-w- c:\windows\system32\isafeif64.dll
2011-09-16 08:19 . 2010-01-21 13:34 103760 —-a-w- c:\windows\system32\vetredir64.dll
2011-09-14 15:47 . 2011-09-14 15:47 60416 —-a-w- c:\windows\system32\OVDecode64.dll
2011-09-14 15:47 . 2011-09-14 15:47 53760 —-a-w- c:\windows\SysWow64\OVDecode.dll
2011-09-14 15:47 . 2011-09-14 15:47 16652288 —-a-w- c:\windows\system32\amdocl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 44032 —-a-w- c:\windows\system32\amdoclcl64.dll
2011-09-14 15:38 . 2011-09-14 15:38 37376 —-a-w- c:\windows\SysWow64\amdoclcl.dll
2011-09-08 18:27 . 2011-09-08 18:27 10203648 —-a-w- c:\windows\system32\drivers\atikmdag.sys
2011-09-08 17:59 . 2011-09-08 17:59 24229376 —-a-w- c:\windows\system32\atio6axx.dll
2011-09-08 17:39 . 2011-09-08 17:39 18534912 —-a-w- c:\windows\SysWow64\atioglxx.dll
2011-09-08 17:34 . 2011-09-08 17:34 151552 —-a-w- c:\windows\system32\atiapfxx.exe
2011-09-08 17:34 . 2011-09-08 17:34 732672 —-a-w- c:\windows\SysWow64\aticfx32.dll
2011-09-08 17:32 . 2011-07-28 21:39 862720 —-a-w- c:\windows\system32\aticfx64.dll
2011-09-08 17:30 . 2011-09-08 17:30 466944 —-a-w- c:\windows\system32\ATIDEMGX.dll
2011-09-08 17:30 . 2011-09-08 17:30 486912 —-a-w- c:\windows\system32\atieclxx.exe
2011-09-08 17:29 . 2011-09-08 17:29 204288 —-a-w- c:\windows\system32\atiesrxx.exe
2011-09-08 17:28 . 2011-09-08 17:28 120320 —-a-w- c:\windows\system32\atitmm64.dll
2011-09-08 17:28 . 2011-09-08 17:28 423424 —-a-w- c:\windows\system32\atipdl64.dll
2011-09-08 17:28 . 2011-09-08 17:28 356352 —-a-w- c:\windows\SysWow64\atipdlxx.dll
2011-09-08 17:28 . 2011-09-08 17:28 278528 —-a-w- c:\windows\SysWow64\Oemdspif.dll
2011-09-08 17:28 . 2011-09-08 17:28 21504 —-a-w- c:\windows\system32\atimuixx.dll
2011-09-08 17:28 . 2011-09-08 17:28 59392 —-a-w- c:\windows\system32\atiedu64.dll
2011-09-08 17:28 . 2011-09-08 17:28 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll
2011-09-08 17:24 . 2011-09-08 17:24 4204032 —-a-w- c:\windows\SysWow64\atidxx32.dll
2011-09-08 17:18 . 2011-09-08 17:18 1113088 —-a-w- c:\windows\system32\atiumd6v.dll
2011-09-08 17:18 . 2011-09-08 17:18 1828864 —-a-w- c:\windows\SysWow64\atiumdmv.dll
2011-09-08 17:18 . 2011-07-28 21:11 3888640 —-a-w- c:\windows\system32\atiumd6a.dll
2011-09-08 17:16 . 2011-09-08 17:16 4944896 —-a-w- c:\windows\system32\atidxx64.dll
2011-09-08 17:09 . 2011-09-08 17:09 51200 —-a-w- c:\windows\system32\aticalrt64.dll
2011-09-08 17:09 . 2011-09-08 17:09 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll
2011-09-08 17:09 . 2011-09-08 17:09 44544 —-a-w- c:\windows\system32\aticalcl64.dll
2011-09-08 17:09 . 2011-09-08 17:09 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll
2011-09-08 17:09 . 2011-09-08 17:09 8723456 —-a-w- c:\windows\system32\aticaldd64.dll
2011-09-08 17:08 . 2011-09-08 17:08 4064768 —-a-w- c:\windows\SysWow64\atiumdva.dll
2011-09-08 17:05 . 2011-09-08 17:05 7331840 —-a-w- c:\windows\SysWow64\aticaldd.dll
2011-09-08 17:05 . 2011-09-08 17:05 4289024 —-a-w- c:\windows\SysWow64\atiumdag.dll
2011-09-08 17:00 . 2011-07-28 21:02 5428736 —-a-w- c:\windows\system32\atiumd64.dll
2011-09-08 16:59 . 2011-07-28 21:01 58880 —-a-w- c:\windows\system32\coinst.dll
2011-09-08 16:53 . 2011-09-08 16:53 381952 —-a-w- c:\windows\system32\atiadlxx.dll
2011-09-08 16:53 . 2011-09-08 16:53 270336 —-a-w- c:\windows\SysWow64\atiadlxy.dll
2011-09-08 16:52 . 2011-09-08 16:52 15360 —-a-w- c:\windows\system32\atig6pxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\SysWow64\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 13312 —-a-w- c:\windows\system32\atiglpxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 39936 —-a-w- c:\windows\system32\atig6txx.dll
2011-09-08 16:52 . 2011-09-08 16:52 32768 —-a-w- c:\windows\SysWow64\atigktxx.dll
2011-09-08 16:52 . 2011-09-08 16:52 310784 —-a-w- c:\windows\system32\drivers\atikmpag.sys
2011-09-08 16:52 . 2011-09-08 16:52 40960 —-a-w- c:\windows\system32\atiuxp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 31744 —-a-w- c:\windows\SysWow64\atiuxpag.dll
2011-09-08 16:51 . 2011-07-28 20:53 38912 —-a-w- c:\windows\system32\atiu9p64.dll
2011-09-08 16:51 . 2011-09-08 16:51 29184 —-a-w- c:\windows\SysWow64\atiu9pag.dll
2011-09-08 16:51 . 2011-07-28 20:52 45056 —-a-w- c:\windows\system32\atitmp64.dll
2011-09-08 16:51 . 2011-09-08 16:51 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\atimpc64.dll
2011-09-08 16:51 . 2011-09-08 16:51 54784 —-a-w- c:\windows\system32\amdpcom64.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\atimpc32.dll
2011-09-08 16:50 . 2011-09-08 16:50 53760 —-a-w- c:\windows\SysWow64\amdpcom32.dll
2011-08-31 03:05 . 2011-08-31 03:05 96104 —-a-w- c:\windows\system32\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 85864 —-a-w- c:\windows\system32\dnssd.dll
2011-08-31 03:05 . 2011-08-31 03:05 83816 —-a-w- c:\windows\SysWow64\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 73064 —-a-w- c:\windows\SysWow64\dnssd.dll
2011-08-25 00:19 . 2011-08-25 00:19 56320 —-a-w- c:\windows\SysWow64\OpenVideo.dll
2011-08-25 00:18 . 2011-08-25 00:18 13601280 —-a-w- c:\windows\SysWow64\amdocl.dll
2011-08-25 00:17 . 2011-08-25 00:17 43520 —-a-w- c:\windows\SysWow64\OpenCL.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-02_01.45.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-11 06:58 . 2011-06-11 06:58 51024 c:\windows\SysWOW64\vcomp100.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 81744 c:\windows\SysWOW64\mfcm100u.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 81744 c:\windows\SysWOW64\mfcm100.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 60752 c:\windows\SysWOW64\mfc100rus.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 43344 c:\windows\SysWOW64\mfc100kor.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 43856 c:\windows\SysWOW64\mfc100jpn.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 62288 c:\windows\SysWOW64\mfc100ita.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 64336 c:\windows\SysWOW64\mfc100fra.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 63824 c:\windows\SysWOW64\mfc100esn.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 55120 c:\windows\SysWOW64\mfc100enu.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 64336 c:\windows\SysWOW64\mfc100deu.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 36176 c:\windows\SysWOW64\mfc100cht.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 36176 c:\windows\SysWOW64\mfc100chs.dll
+ 2006-11-02 15:45 . 2011-11-09 21:33 88388 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-11-17 18:07 . 2011-11-09 21:33 28932 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4027082081-1360438707-2940866900-1000_UserData.bin
+ 2009-11-17 17:36 . 2011-11-09 21:31 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-17 17:36 . 2011-11-01 15:58 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-05 15:12 . 2011-11-08 01:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-01 03:12 . 2011-11-01 03:12 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-17 17:36 . 2011-11-01 03:12 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-17 17:36 . 2011-11-08 01:35 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-23 16:51 . 2011-11-06 16:35 75048 c:\windows\Installer\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}\ScWaveEditorStartM_3939FC794F8E448CB7E44465B4F58E0D.exe
- 2011-02-23 16:51 . 2011-02-23 16:51 75048 c:\windows\Installer\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}\ScWaveEditorStartM_3939FC794F8E448CB7E44465B4F58E0D.exe
- 2011-02-23 16:51 . 2011-02-23 16:51 75048 c:\windows\Installer\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}\ARPPRODUCTICON.exe
+ 2011-02-23 16:51 . 2011-11-06 16:35 75048 c:\windows\Installer\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}\ARPPRODUCTICON.exe
- 2010-06-19 01:38 . 2010-06-19 01:38 9560 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_48.bin
+ 2010-06-19 01:38 . 2011-11-04 00:55 9560 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_48.bin
+ 2010-06-19 01:38 . 2011-11-04 00:55 4280 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_32.bin
- 2010-06-19 01:38 . 2010-06-19 01:38 4280 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_32.bin
+ 2010-06-19 01:38 . 2011-11-04 00:55 2456 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_24.bin
- 2010-06-19 01:38 . 2010-06-19 01:38 2456 c:\windows\system32\networklist\icons\{56FCE789-9F89-4CF2-85CB-99724CE83A7C}_24.bin
- 2011-10-31 19:16 . 2011-11-01 15:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-10 02:20 . 2011-11-10 02:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-11-10 02:20 . 2011-11-10 02:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-31 19:16 . 2011-11-01 15:58 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-06-11 06:58 . 2011-06-11 06:58 773968 c:\windows\SysWOW64\msvcr100.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 421200 c:\windows\SysWOW64\msvcp100.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 138056 c:\windows\SysWOW64\atl100.dll
+ 2008-01-21 02:23 . 2011-11-08 17:56 104646 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 12:46 . 2011-11-10 02:32 619382 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2011-11-10 02:32 108826 c:\windows\system32\perfc009.dat
+ 2006-11-02 15:17 . 2011-11-10 00:30 262144 c:\windows\system32\config\systemprofile\ntuser.dat
- 2006-11-02 15:17 . 2011-09-02 01:21 262144 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2011-11-06 14:09 . 2011-11-07 04:36 390872 c:\windows\ServiceProfiles\LocalService\AppData\Local\WPFFontCache_v0400-System.dat
+ 2011-11-07 04:36 . 2011-11-07 04:36 390872 c:\windows\ServiceProfiles\LocalService\AppData\Local\WPFFontCache_v0400-S-1-5-21-4027082081-1360438707-2940866900-1000-8192.dat
+ 2011-03-11 06:51 . 2011-11-10 00:10 377624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-03-11 06:51 . 2011-10-31 19:05 377624 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-11-06 12:33 . 2011-11-06 12:33 913920 c:\windows\Installer\c67e3.msi
+ 2011-11-06 16:29 . 2011-11-06 16:29 160768 c:\windows\Installer\7a27a2.msi
+ 2011-02-23 16:49 . 2011-11-06 12:35 587048 c:\windows\Installer\{FCF00A6E-FB58-477A-ABE9-232907105521}\NeroCoverDesigner_EF89736D5D4B4006B5966729E642699E.exe
- 2011-02-23 16:49 . 2011-02-23 17:03 587048 c:\windows\Installer\{FCF00A6E-FB58-477A-ABE9-232907105521}\NeroCoverDesigner_EF89736D5D4B4006B5966729E642699E.exe
- 2011-02-23 16:49 . 2011-02-23 17:03 587048 c:\windows\Installer\{FCF00A6E-FB58-477A-ABE9-232907105521}\ARPPRODUCTICON.exe
+ 2011-02-23 16:49 . 2011-11-06 12:35 587048 c:\windows\Installer\{FCF00A6E-FB58-477A-ABE9-232907105521}\ARPPRODUCTICON.exe
- 2011-02-23 16:52 . 2011-02-23 17:04 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\ScStartSmartDeskto_3AF47A4E14DF4546B1449D27245505A0.exe
+ 2011-02-23 16:52 . 2011-11-06 12:40 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\ScStartSmartDeskto_3AF47A4E14DF4546B1449D27245505A0.exe
- 2011-02-23 16:52 . 2011-02-23 17:04 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\NeroStartSmart.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:52 . 2011-11-06 12:40 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\NeroStartSmart.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
- 2011-02-23 16:52 . 2011-02-23 17:04 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\ARPPRODUCTICON.exe
+ 2011-02-23 16:52 . 2011-11-06 12:40 587048 c:\windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\ARPPRODUCTICON.exe
- 2011-02-23 16:47 . 2011-02-23 16:47 312616 c:\windows\Installer\{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}\ARPPRODUCTICON.exe
+ 2011-02-23 16:47 . 2011-11-06 12:28 312616 c:\windows\Installer\{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}\ARPPRODUCTICON.exe
- 2011-02-23 16:49 . 2011-02-23 16:49 587048 c:\windows\Installer\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}\NeroInfoTool.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:49 . 2011-11-06 12:33 587048 c:\windows\Installer\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}\NeroInfoTool.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:49 . 2011-11-06 12:33 587048 c:\windows\Installer\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}\ARPPRODUCTICON.exe
- 2011-02-23 16:49 . 2011-02-23 16:49 587048 c:\windows\Installer\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}\ARPPRODUCTICON.exe
+ 2011-03-21 05:33 . 2011-11-06 12:31 312616 c:\windows\Installer\{EF3A4DAE-F16F-4AC1-87BB-FE00A784084F}\ARPPRODUCTICON.exe
- 2011-03-21 05:33 . 2011-03-21 05:33 312616 c:\windows\Installer\{EF3A4DAE-F16F-4AC1-87BB-FE00A784084F}\ARPPRODUCTICON.exe
- 2011-02-23 16:50 . 2011-02-23 17:05 587048 c:\windows\Installer\{E337E787-CF61-4B7B-B84F-509202A54023}\NeroRescueAgent.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:50 . 2011-11-06 12:33 587048 c:\windows\Installer\{E337E787-CF61-4B7B-B84F-509202A54023}\NeroRescueAgent.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:50 . 2011-11-06 12:33 587048 c:\windows\Installer\{E337E787-CF61-4B7B-B84F-509202A54023}\ARPPRODUCTICON.exe
- 2011-02-23 16:50 . 2011-02-23 17:05 587048 c:\windows\Installer\{E337E787-CF61-4B7B-B84F-509202A54023}\ARPPRODUCTICON.exe
- 2011-02-23 16:51 . 2011-02-23 16:51 587048 c:\windows\Installer\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}\ScSoundTraxStartMe_92F39C657A3840139A47B92C3EFBBBBB.exe
+ 2011-02-23 16:51 . 2011-11-06 12:38 587048 c:\windows\Installer\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}\ScSoundTraxStartMe_92F39C657A3840139A47B92C3EFBBBBB.exe
- 2011-02-23 16:51 . 2011-02-23 16:51 587048 c:\windows\Installer\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}\ARPPRODUCTICON.exe
+ 2011-02-23 16:51 . 2011-11-06 12:38 587048 c:\windows\Installer\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}\ARPPRODUCTICON.exe
+ 2011-03-21 05:32 . 2011-11-06 12:31 312616 c:\windows\Installer\{DD238642-14C7-4D54-8BD7-FAD6DEA9999B}\ARPPRODUCTICON.exe
- 2011-03-21 05:32 . 2011-03-21 05:32 312616 c:\windows\Installer\{DD238642-14C7-4D54-8BD7-FAD6DEA9999B}\ARPPRODUCTICON.exe
+ 2011-11-06 16:32 . 2011-11-06 16:32 300328 c:\windows\Installer\{C82C515A-CAE3-44B3-B5CC-81C5E4A92E8F}\ARPPRODUCTICON.exe
+ 2011-11-06 16:39 . 2011-11-06 16:39 582952 c:\windows\Installer\{BE814218-3919-4EA3-868A-2F60BC135CB4}\ScKwikMediaStar_594597E2768645E1995B7F203ACC4488.exe
+ 2011-11-06 16:39 . 2011-11-06 16:39 582952 c:\windows\Installer\{BE814218-3919-4EA3-868A-2F60BC135CB4}\ScKwikMediaDesk_DAE4ED9540AC4C38962344CC52ED8A73.exe
+ 2011-11-06 16:39 . 2011-11-06 16:39 582952 c:\windows\Installer\{BE814218-3919-4EA3-868A-2F60BC135CB4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe
+ 2011-11-06 12:25 . 2011-11-06 12:25 300328 c:\windows\Installer\{A7A0BF2E-31CC-49E3-9913-52C503EB969D}\ARPPRODUCTICON.exe
+ 2011-03-21 05:33 . 2011-11-06 12:32 312616 c:\windows\Installer\{A70B0C7B-3527-4D53-A694-E9492ECE9EE1}\ARPPRODUCTICON.exe
- 2011-03-21 05:33 . 2011-03-21 05:33 312616 c:\windows\Installer\{A70B0C7B-3527-4D53-A694-E9492ECE9EE1}\ARPPRODUCTICON.exe
+ 2011-02-23 16:51 . 2011-11-06 12:39 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\NewShortcut1_28CF345AD4354131AA47B77D4165D813.exe
- 2011-02-23 16:51 . 2011-03-21 05:16 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\NewShortcut1_28CF345AD4354131AA47B77D4165D813.exe
+ 2011-02-23 16:51 . 2011-11-06 12:39 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\NeroVision.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
- 2011-02-23 16:51 . 2011-03-21 05:16 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\NeroVision.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:51 . 2011-11-06 12:39 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\ARPPRODUCTICON.exe
- 2011-02-23 16:51 . 2011-03-21 05:16 587048 c:\windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\ARPPRODUCTICON.exe
- 2011-02-23 16:48 . 2011-02-23 17:05 587048 c:\windows\Installer\{943CFD7D-5336-47AF-9418-E02473A5A517}\ARPPRODUCTICON.exe
+ 2011-02-23 16:48 . 2011-11-06 12:34 587048 c:\windows\Installer\{943CFD7D-5336-47AF-9418-E02473A5A517}\ARPPRODUCTICON.exe
+ 2011-11-06 12:25 . 2011-11-06 12:25 300328 c:\windows\Installer\{9193490D-5229-4FC4-9BB9-A6D63C09574A}\ARPPRODUCTICON.exe
- 2011-02-23 16:50 . 2011-02-23 16:50 587048 c:\windows\Installer\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}\ScRecodeStartMenu_563A75F05683422E8C558ED3B6DA617D.exe
+ 2011-02-23 16:50 . 2011-11-06 12:36 587048 c:\windows\Installer\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}\ScRecodeStartMenu_563A75F05683422E8C558ED3B6DA617D.exe
- 2011-02-23 16:50 . 2011-02-23 16:50 587048 c:\windows\Installer\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}\ARPPRODUCTICON.exe
+ 2011-02-23 16:50 . 2011-11-06 12:36 587048 c:\windows\Installer\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}\ARPPRODUCTICON.exe
- 2011-03-21 05:34 . 2011-03-21 05:34 312616 c:\windows\Installer\{85BEC8F6-9AA3-43FF-B56B-8276277137B3}\ARPPRODUCTICON.exe
+ 2011-03-21 05:34 . 2011-11-06 12:31 312616 c:\windows\Installer\{85BEC8F6-9AA3-43FF-B56B-8276277137B3}\ARPPRODUCTICON.exe
+ 2011-02-23 16:48 . 2011-11-06 12:34 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ScBurningROMStartM_FF88F478D1E748AC86035D457D563142.exe
- 2011-02-23 16:48 . 2011-03-21 05:14 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ScBurningROMStartM_FF88F478D1E748AC86035D457D563142.exe
+ 2011-02-23 16:48 . 2011-11-06 12:34 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ScBurningROMStartM_7533AE23D677474387D2A66427FA7052.exe
- 2011-02-23 16:48 . 2011-03-21 05:14 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ScBurningROMStartM_7533AE23D677474387D2A66427FA7052.exe
- 2011-02-23 16:48 . 2011-03-21 05:14 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ARPPRODUCTICON.exe
+ 2011-02-23 16:48 . 2011-11-06 12:34 587048 c:\windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ARPPRODUCTICON.exe
- 2011-02-23 16:49 . 2011-03-21 05:15 587048 c:\windows\Installer\{70550193-1C22-445C-8FA4-564E155DB1A7}\NeroExpress.exe_81A8FD91A6494AD5B4998149EAAC7E7C.exe
+ 2011-02-23 16:49 . 2011-11-06 12:36 587048 c:\windows\Installer\{70550193-1C22-445C-8FA4-564E155DB1A7}\NeroExpress.exe_81A8FD91A6494AD5B4998149EAAC7E7C.exe
- 2011-02-23 16:49 . 2011-03-21 05:15 587048 c:\windows\Installer\{70550193-1C22-445C-8FA4-564E155DB1A7}\ARPPRODUCTICON.exe
+ 2011-02-23 16:49 . 2011-11-06 12:35 587048 c:\windows\Installer\{70550193-1C22-445C-8FA4-564E155DB1A7}\ARPPRODUCTICON.exe
- 2011-02-23 16:47 . 2011-02-23 17:06 587048 c:\windows\Installer\{6DFB899F-17A2-48F0-A533-ED8D6866CF38}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe
+ 2011-02-23 16:47 . 2011-11-06 12:25 587048 c:\windows\Installer\{6DFB899F-17A2-48F0-A533-ED8D6866CF38}\ScControlCenterSta_FC2653898C5047A6A872CAF6433C43A8.exe
+ 2011-02-23 16:47 . 2011-11-06 12:25 587048 c:\windows\Installer\{6DFB899F-17A2-48F0-A533-ED8D6866CF38}\ARPPRODUCTICON.exe
- 2011-02-23 16:47 . 2011-02-23 17:06 587048 c:\windows\Installer\{6DFB899F-17A2-48F0-A533-ED8D6866CF38}\ARPPRODUCTICON.exe
+ 2011-02-23 16:48 . 2011-11-06 12:26 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\BackItUp._AB9F1F47710540918A47B78D2BED5DAD.exe
- 2011-02-23 16:48 . 2011-02-23 17:05 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\BackItUp._AB9F1F47710540918A47B78D2BED5DAD.exe
+ 2011-02-23 16:48 . 2011-11-06 12:26 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\BackItUp._6DE631547FD24BC5962A4E5F07A1BE20.exe
- 2011-02-23 16:48 . 2011-02-23 17:05 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\BackItUp._6DE631547FD24BC5962A4E5F07A1BE20.exe
- 2011-02-23 16:48 . 2011-02-23 17:05 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\ARPPRODUCTICON.exe
+ 2011-02-23 16:48 . 2011-11-06 12:26 587048 c:\windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\ARPPRODUCTICON.exe
- 2011-02-23 16:47 . 2011-02-23 16:47 312616 c:\windows\Installer\{63AA3EAB-23BB-48B2-9AD0-44F878075604}\ARPPRODUCTICON.exe
+ 2011-02-23 16:47 . 2011-11-06 12:28 312616 c:\windows\Installer\{63AA3EAB-23BB-48B2-9AD0-44F878075604}\ARPPRODUCTICON.exe
- 2011-02-23 16:49 . 2011-02-23 17:05 587048 c:\windows\Installer\{34490F4E-48D0-492E-8249-B48BECF0537C}\NeroDiscSpeed.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:49 . 2011-11-06 12:34 587048 c:\windows\Installer\{34490F4E-48D0-492E-8249-B48BECF0537C}\NeroDiscSpeed.ex_2882597C6E684EBDA23F3CF2CA0CBC30.exe
+ 2011-02-23 16:49 . 2011-11-06 12:34 587048 c:\windows\Installer\{34490F4E-48D0-492E-8249-B48BECF0537C}\ARPPRODUCTICON.exe
- 2011-02-23 16:49 . 2011-02-23 17:05 587048 c:\windows\Installer\{34490F4E-48D0-492E-8249-B48BECF0537C}\ARPPRODUCTICON.exe
+ 2011-11-06 16:32 . 2011-11-06 16:32 300328 c:\windows\Installer\{01E9B2FF-DAF4-4529-9CC9-2101625517C7}\ARPPRODUCTICON.exe
+ 2011-11-05 01:06 . 2011-11-05 01:06 634880 c:\windows\ERDNT\11-4-2011\Users\00000002\UsrClass.dat
+ 2011-11-05 01:06 . 2005-10-20 16:02 163328 c:\windows\ERDNT\11-4-2011\ERDNT.EXE
+ 2011-06-11 06:58 . 2011-06-11 06:58 4422992 c:\windows\SysWOW64\mfc100u.dll
+ 2011-06-11 06:58 . 2011-06-11 06:58 4397384 c:\windows\SysWOW64\mfc100.dll
+ 2009-12-26 06:40 . 2011-11-09 23:21 1749352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-12-26 06:40 . 2011-10-31 19:05 1749352 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-09-01 21:13 . 2011-11-08 05:12 1699692 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-12288.dat
- 2011-09-01 21:13 . 2011-10-31 17:12 1699692 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-12288.dat
+ 2011-09-16 16:13 . 2011-11-07 13:28 1060864 c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
+ 2011-11-06 12:40 . 2011-11-06 12:40 3003904 c:\windows\Installer\c6f2b.msi
+ 2011-11-06 12:39 . 2011-11-06 12:39 3620864 c:\windows\Installer\c6e55.msi
+ 2011-11-06 12:38 . 2011-11-06 12:38 8176128 c:\windows\Installer\c6c3a.msi
+ 2011-11-06 12:35 . 2011-11-06 12:35 8783872 c:\windows\Installer\c6ac3.msi
+ 2011-11-06 12:35 . 2011-11-06 12:35 2870272 c:\windows\Installer\c69eb.msi
+ 2011-11-06 12:34 . 2011-11-06 12:34 2141184 c:\windows\Installer\c68dd.msi
+ 2011-11-06 12:34 . 2011-11-06 12:34 1380352 c:\windows\Installer\c68d0.msi
+ 2011-11-06 12:33 . 2011-11-06 12:33 2141184 c:\windows\Installer\c6803.msi
+ 2011-11-06 12:33 . 2011-11-06 12:33 2140672 c:\windows\Installer\c67ef.msi
+ 2011-11-06 12:32 . 2011-11-06 12:32 1781760 c:\windows\Installer\c67bc.msi
+ 2011-11-06 12:31 . 2011-11-06 12:31 1643008 c:\windows\Installer\c63ec.msi
+ 2011-11-06 12:31 . 2011-11-06 12:31 1703424 c:\windows\Installer\c637d.msi
+ 2011-11-06 12:31 . 2011-11-06 12:31 1824768 c:\windows\Installer\c61c2.msi
+ 2011-11-06 12:28 . 2011-11-06 12:28 1222656 c:\windows\Installer\c5c88.msi
+ 2011-11-06 12:28 . 2011-11-06 12:28 1204224 c:\windows\Installer\c5b8d.msi
+ 2011-11-06 12:26 . 2011-11-06 12:26 6250496 c:\windows\Installer\c5820.msi
+ 2011-11-06 12:25 . 2011-11-06 12:25 1062912 c:\windows\Installer\c572f.msi
+ 2011-11-06 12:25 . 2011-11-06 12:25 2051072 c:\windows\Installer\c571e.msi
+ 2011-11-06 12:25 . 2011-11-06 12:25 7725568 c:\windows\Installer\c5712.msi
+ 2011-11-06 12:25 . 2011-11-06 12:25 2820608 c:\windows\Installer\c56f8.msi
+ 2011-11-06 16:39 . 2011-11-06 16:39 4499456 c:\windows\Installer\7c0fc1.msi
+ 2011-11-06 16:35 . 2011-11-06 16:35 1956864 c:\windows\Installer\7c0b3e.msi
+ 2011-11-06 16:32 . 2011-11-06 16:32 2501120 c:\windows\Installer\7c0aae.msi
+ 2011-11-06 16:32 . 2011-11-06 16:32 1060864 c:\windows\Installer\7c0aa6.msi
+ 2011-11-06 16:32 . 2011-11-06 16:32 1875456 c:\windows\Installer\7c0aa0.msi
+ 2011-06-29 02:27 . 2011-06-29 02:27 4028928 c:\windows\Installer\109721f.msp
+ 2011-11-05 01:06 . 2011-11-05 01:06 5341184 c:\windows\ERDNT\11-4-2011\Users\00000001\ntuser.dat
+ 2006-11-02 12:33 . 2011-11-09 23:30 11272192 c:\windows\system32\SMI\Store\Machine\schema.dat
- 2006-11-02 12:33 . 2011-10-13 07:48 11272192 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:35 . 2011-11-09 23:09 52174280 c:\windows\system32\mrt.exe
+ 2011-05-29 05:41 . 2011-11-09 23:21 27374200 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-8192.dat
+ 2011-08-07 00:14 . 2011-11-08 17:42 20812520 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4027082081-1360438707-2940866900-1000-4096.dat
+ 2011-11-06 12:36 . 2011-11-06 12:36 20583424 c:\windows\Installer\c6b6b.msi
+ 2011-11-06 12:34 . 2011-11-06 12:34 11746816 c:\windows\Installer\c68b1.msi
- 2011-09-16 16:13 . 2011-11-01 11:18 196624384 c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
+ 2011-09-16 16:13 . 2011-11-04 13:17 196624384 c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LchDrvKey"="LchDrvKey.exe" [2007-03-28 36864]
"LedKey"="CNYHKey.exe" [2008-04-23 339968]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-04-28 1406248]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"StartMSu"="c:\program files (x86)\Creative\MediaSource5\Startmsu.exe" [2006-10-02 81920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2011-02-24 18:33 79368 —-a-w- c:\windows\System32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R0 KmxFw;KmxFw;c:\windows\System32\DRIVERS\kmxfw.sys [x]
R1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [x]
R1 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [x]
R1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [x]
R1 KmxFilter;HIPS Core Filter Driver;c:\windows\system32\DRIVERS\KmxFilter.sys [x]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
R2 CAAMSvc;CAAMSvc;c:\program files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe [2011-10-17 291656]
R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [2011-09-16 286032]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 DiskDoctorService;Norton Disk Doctor Service;c:\program files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [2010-11-30 1029480]
R2 ETService;Empowering Technology Service;c:\program files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-06-11 24576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [x]
R2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [x]
R2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-09-23 641832]
R2 SpeedDiskService;Norton SpeedDisk Service;c:\program files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [2010-11-30 1037672]
R2 UmxEngine;TM Engine;c:\program files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-04-04 920656]
R2 WinExtManager;WinSock Extention Manager;c:\windows\SysWOW64\mdmcls32.exe [2011-06-29 3207184]
R2 WinSvchostManager;WinSock Svchost Manager;c:\windows\SysWOW64\svcprs32.exe [2011-06-29 2760720]
R2 WinSvchostManagerSrv;WinSvchostManagerSrv;c:\windows\SysWOW64\cfgmig32.exe [2011-09-16 263504]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-01-10 79360]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 136176]
R3 gwfilt64;gwfilt64;c:\windows\system32\drivers\gwfilt64.sys [x]
R3 HPEWSFXBULK;HPEWSFXBULK;c:\windows\system32\drivers\hpfx64bulk.sys [x]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys [x]
R3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 SymDSMon;SymDSMon;c:\windows\system32\drivers\SymDSMon.sys [x]
R3 SYMSpeedDisk;SYMSpeedDisk;c:\windows\system32\drivers\SymSpeedDisk.sys [2010-11-30 163384]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 KmxAMRT;KmxAMRT;c:\windows\system32\DRIVERS\KmxAMRT.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ECACHE
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-23 19:57]
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
2011-11-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
- c:\users\Admin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 18:14]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2006-11-02 46592]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"RtHDVCpl"="RAVCpl64.exe" [2008-09-19 6495264]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2011-09-16 2658128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\UmxSbxExA64.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
LSP: winsflt.dll
TCP: DhcpNameServer = 192.168.0.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2011-11-09 21:47:55
ComboFix-quarantined-files.txt 2011-11-10 02:47
ComboFix2.txt 2011-11-03 02:48
ComboFix3.txt 2011-11-02 02:01
.
Pre-Run: 36,531,920,896 bytes free
Post-Run: 36,219,219,968 bytes free
.
- - End Of File - - 09D8559504F1CBAB58014027DD958ED8


~James

Using ComboFix, a message was displayed on the program at least three times as it scanned: "Access Denied. Administrator permission needed to use the selected options. Use an administrator command prompt to complete these tasks." Even though I right-clicked on COMBOFIX.EXE and used 'Run as Administrator' to execute the program. Is there an error here? ~James
Hi James,

I am so sorry about the lapse in time for my response.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-


Thanks I will do this.

To help aid in this effort, I've been monitoring my PC and almost every session i have the following two errors that pop up:

Message window
mdmcls.exe has stopped

Check online for a solution
Close the program

Message window
Microsoft Windows Search Indexer has stopped

Check online for a solution
Close the program

I had to do a system restore after a crash once

Thanks for staying with me on this

~James
Hi Jeff The results of the KDSS Killer scan: 14:13:08.0084 5636 TDSS rootkit removing tool [removed] Nov 11 2011 15:47:15 14:13:08.0740 5636 ============================================================ 14:13:08.0740 5636 Current date / time: 2011/11/12 14:13:08.0740 14:13:08.0755 5636 SystemInfo: 14:13:08.0755 5636 14:13:08.0755 5636 OS Version: 6.0.6002 ServicePack: 2.0 14:13:08.0755 5636 Product type: Workstation 14:13:08.0755 5636 ComputerName: ADMIN-PC 14:13:08.0755 5636 UserName: Admin 14:13:08.0755 5636 Windows directory: C:\Windows 14:13:08.0755 5636 System windows directory: C:\Windows 14:13:08.0755 5636 Running under WOW64 14:13:08.0755 5636 Processor architecture: Intel x64 14:13:08.0755 5636 Number of processors: 8 14:13:08.0755 5636 Page size: 0x1000 14:13:08.0755 5636 Boot type: Normal boot 14:13:08.0755 5636 ============================================================ 14:13:09.0894 5636 Initialize success 14:13:23.0856 2784 ============================================================ 14:13:23.0856 2784 Scan started 14:13:23.0856 2784 Mode: Manual; 14:13:23.0856 2784 ============================================================ 14:13:25.0416 2784 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys 14:13:25.0478 2784 ACPI - ok 14:13:26.0648 2784 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys 14:13:26.0758 2784 adp94xx - ok 14:13:27.0257 2784 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys 14:13:27.0288 2784 adpahci - ok 14:13:27.0335 2784 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys 14:13:27.0350 2784 adpu160m - ok 14:13:27.0631 2784 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys 14:13:27.0662 2784 adpu320 - ok 14:13:28.0208 2784 AFD (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys 14:13:28.0302 2784 AFD - ok 14:13:29.0144 2784 AgereSoftModem (ddf52c4c92d831a4cdb7788b37585e36) C:\Windows\system32\DRIVERS\agrsm64.sys 14:13:29.0332 2784 AgereSoftModem - ok 14:13:29.0690 2784 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys 14:13:29.0706 2784 agp440 - ok 14:13:29.0862 2784 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys 14:13:29.0878 2784 aic78xx - ok 14:13:29.0956 2784 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys 14:13:29.0971 2784 aliide - ok 14:13:30.0018 2784 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys 14:13:30.0034 2784 amdide - ok 14:13:30.0127 2784 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys 14:13:30.0143 2784 AmdK8 - ok 14:13:31.0126 2784 amdkmdag (446a1aad34191665a8df6092bd8eb5a8) C:\Windows\system32\DRIVERS\atikmdag.sys 14:13:31.0328 2784 amdkmdag - ok 14:13:32.0249 2784 amdkmdap (f8f8a908fdb005a65ddf7238c814eea5) C:\Windows\system32\DRIVERS\atikmpag.sys 14:13:32.0249 2784 amdkmdap - ok 14:13:32.0826 2784 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys 14:13:32.0826 2784 arc - ok 14:13:33.0107 2784 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys 14:13:33.0122 2784 arcsas - ok 14:13:33.0216 2784 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys 14:13:33.0294 2784 AsyncMac - ok 14:13:33.0450 2784 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys 14:13:33.0450 2784 atapi - ok 14:13:34.0230 2784 atikmdag (446a1aad34191665a8df6092bd8eb5a8) C:\Windows\system32\DRIVERS\atikmdag.sys 14:13:34.0277 2784 atikmdag - ok 14:13:34.0682 2784 Beep - ok 14:13:34.0979 2784 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys 14:13:34.0979 2784 blbdrive - ok 14:13:35.0228 2784 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys 14:13:35.0228 2784 bowser - ok 14:13:35.0369 2784 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys 14:13:35.0369 2784 BrFiltLo - ok 14:13:35.0462 2784 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys 14:13:35.0462 2784 BrFiltUp - ok 14:13:35.0556 2784 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys 14:13:35.0572 2784 Brserid - ok 14:13:35.0728 2784 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys 14:13:35.0743 2784 BrSerWdm - ok 14:13:35.0806 2784 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys 14:13:35.0821 2784 BrUsbMdm - ok 14:13:35.0868 2784 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys 14:13:35.0884 2784 BrUsbSer - ok 14:13:35.0962 2784 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys 14:13:35.0962 2784 BTHMODEM - ok 14:13:36.0071 2784 catchme - ok 14:13:36.0149 2784 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys 14:13:36.0149 2784 cdfs - ok 14:13:36.0367 2784 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys 14:13:36.0367 2784 cdrom - ok 14:13:36.0508 2784 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\DRIVERS\circlass.sys 14:13:36.0523 2784 circlass - ok 14:13:36.0632 2784 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys 14:13:36.0695 2784 CLFS - ok 14:13:36.0804 2784 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys 14:13:36.0820 2784 cmdide - ok 14:13:36.0851 2784 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys 14:13:36.0866 2784 Compbatt - ok 14:13:36.0960 2784 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys 14:13:36.0960 2784 crcdisk - ok 14:13:37.0054 2784 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys 14:13:37.0054 2784 DfsC - ok 14:13:37.0132 2784 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys 14:13:37.0132 2784 disk - ok 14:13:37.0210 2784 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys 14:13:37.0210 2784 drmkaud - ok 14:13:37.0319 2784 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys 14:13:37.0319 2784 DXGKrnl - ok 14:13:37.0459 2784 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys 14:13:37.0475 2784 E1G60 - ok 14:13:37.0537 2784 e1yexpress (b37f6853d6e0c6f5f8efde33e831b5f8) C:\Windows\system32\DRIVERS\e1y60x64.sys 14:13:37.0553 2784 e1yexpress - ok 14:13:37.0600 2784 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys 14:13:37.0600 2784 Ecache - ok 14:13:37.0646 2784 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys 14:13:37.0662 2784 elxstor - ok 14:13:37.0724 2784 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys 14:13:37.0740 2784 ErrDev - ok 14:13:37.0818 2784 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys 14:13:37.0834 2784 exfat - ok 14:13:37.0912 2784 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys 14:13:37.0927 2784 fastfat - ok 14:13:37.0958 2784 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys 14:13:37.0958 2784 fdc - ok 14:13:38.0005 2784 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys 14:13:38.0005 2784 FileInfo - ok 14:13:38.0036 2784 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys 14:13:38.0052 2784 Filetrace - ok 14:13:38.0099 2784 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 14:13:38.0114 2784 flpydisk - ok 14:13:38.0192 2784 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys 14:13:38.0192 2784 FltMgr - ok 14:13:38.0442 2784 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys 14:13:38.0458 2784 fssfltr - ok 14:13:38.0504 2784 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys 14:13:38.0504 2784 Fs_Rec - ok 14:13:38.0536 2784 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys 14:13:38.0551 2784 gagp30kx - ok 14:13:38.0645 2784 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\Drivers\GEARAspiWDM.sys 14:13:38.0660 2784 GEARAspiWDM - ok 14:13:38.0770 2784 gwfilt64 (5e114600f350f3bee3f92516e51144f1) C:\Windows\system32\drivers\gwfilt64.sys 14:13:38.0770 2784 gwfilt64 - ok 14:13:38.0832 2784 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys 14:13:38.0879 2784 HdAudAddService - ok 14:13:38.0988 2784 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys 14:13:39.0082 2784 HDAudBus - ok 14:13:39.0128 2784 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys 14:13:39.0128 2784 HidBth - ok 14:13:39.0175 2784 HidIr (5f47839455d01ff6403b008d481a6f5b) C:\Windows\system32\DRIVERS\hidir.sys 14:13:39.0206 2784 HidIr - ok 14:13:39.0269 2784 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys 14:13:39.0269 2784 HidUsb - ok 14:13:39.0316 2784 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys 14:13:39.0331 2784 HpCISSs - ok 14:13:39.0456 2784 HPEWSFXBULK (dbd2bb97a574fc565b1eb5c0a03f917a) C:\Windows\system32\drivers\hpfx64bulk.sys 14:13:39.0456 2784 HPEWSFXBULK - ok 14:13:39.0550 2784 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys 14:13:39.0565 2784 HTTP - ok 14:13:39.0596 2784 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys 14:13:39.0612 2784 i2omp - ok 14:13:39.0674 2784 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys 14:13:39.0674 2784 i8042prt - ok 14:13:39.0768 2784 iaStor (fc28e90f2204d8fd147fa9bfa8a51c01) C:\Windows\system32\DRIVERS\iaStor.sys 14:13:39.0768 2784 iaStor - ok 14:13:39.0924 2784 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys 14:13:39.0955 2784 iaStorV - ok 14:13:40.0033 2784 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys 14:13:40.0033 2784 iirsp - ok 14:13:40.0096 2784 int15 (8c7fa71cb1ebcd3ede8958d27b1bf0b4) C:\Windows\SysWOW64\drivers\int15_64.sys 14:13:40.0096 2784 int15 - ok 14:13:40.0454 2784 IntcAzAudAddService (6fdf709500c20362ffc5057f0d1e0c8d) C:\Windows\system32\drivers\RTKVHD64.sys 14:13:40.0470 2784 IntcAzAudAddService - ok 14:13:40.0673 2784 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys 14:13:40.0688 2784 intelide - ok 14:13:40.0751 2784 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys 14:13:40.0751 2784 intelppm - ok 14:13:40.0844 2784 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys 14:13:40.0844 2784 IpFilterDriver - ok 14:13:40.0876 2784 IpInIp - ok 14:13:40.0922 2784 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys 14:13:40.0922 2784 IPMIDRV - ok 14:13:40.0969 2784 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys 14:13:40.0985 2784 IPNAT - ok 14:13:41.0016 2784 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys 14:13:41.0032 2784 IRENUM - ok 14:13:41.0063 2784 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys 14:13:41.0063 2784 isapnp - ok 14:13:41.0156 2784 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys 14:13:41.0156 2784 iScsiPrt - ok 14:13:41.0266 2784 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys 14:13:41.0266 2784 iteatapi - ok 14:13:41.0312 2784 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys 14:13:41.0328 2784 iteraid - ok 14:13:41.0390 2784 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys 14:13:41.0406 2784 kbdclass - ok 14:13:41.0453 2784 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys 14:13:41.0453 2784 kbdhid - ok 14:13:41.0546 2784 KmxAgent (7594e8799fa212576c93bfdf54583452) C:\Windows\system32\DRIVERS\kmxagent.sys 14:13:41.0562 2784 KmxAgent - ok 14:13:41.0640 2784 KmxAMRT (e5bb08fcf05ef7333be3b5b35295c4c0) C:\Windows\system32\DRIVERS\KmxAMRT.sys 14:13:41.0656 2784 KmxAMRT - ok 14:13:41.0718 2784 KmxCF (54721e47b8350770332128fcffc7a460) C:\Windows\system32\DRIVERS\KmxCF.sys 14:13:41.0718 2784 KmxCF - ok 14:13:41.0843 2784 KmxCfg (174a70fd5367388f6f378cbc6dd723ee) C:\Windows\system32\DRIVERS\kmxcfg.sys 14:13:41.0858 2784 KmxCfg - ok 14:13:41.0952 2784 KmxFile (dc77781ab8cf3043da60187a1511fef6) C:\Windows\system32\DRIVERS\KmxFile.sys 14:13:41.0952 2784 KmxFile - ok 14:13:42.0046 2784 KmxFilter (87da5afc8950ec34d0cddf3438370727) C:\Windows\system32\DRIVERS\KmxFilter.sys 14:13:42.0046 2784 KmxFilter - ok 14:13:42.0139 2784 KmxFw (15260d1b5bb6ba8e5079e758fce88207) C:\Windows\system32\DRIVERS\kmxfw.sys 14:13:42.0139 2784 KmxFw - ok 14:13:42.0186 2784 KmxSbx (9ea56ddeeb080727ff448a0c6e37de08) C:\Windows\system32\DRIVERS\KmxSbx.sys 14:13:42.0202 2784 KmxSbx - ok 14:13:42.0358 2784 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys 14:13:42.0467 2784 KSecDD - ok 14:13:42.0529 2784 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys 14:13:42.0545 2784 ksthunk - ok 14:13:42.0576 2784 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys 14:13:42.0592 2784 lltdio - ok 14:13:42.0685 2784 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys 14:13:42.0716 2784 LSI_FC - ok 14:13:42.0810 2784 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys 14:13:42.0826 2784 LSI_SAS - ok 14:13:43.0044 2784 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys 14:13:43.0044 2784 LSI_SCSI - ok 14:13:43.0106 2784 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys 14:13:43.0106 2784 luafv - ok 14:13:43.0200 2784 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys 14:13:43.0200 2784 megasas - ok 14:13:43.0262 2784 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys 14:13:43.0294 2784 MegaSR - ok 14:13:43.0340 2784 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys 14:13:43.0340 2784 Modem - ok 14:13:43.0543 2784 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys 14:13:43.0543 2784 monitor - ok 14:13:43.0606 2784 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys 14:13:43.0621 2784 mouclass - ok 14:13:43.0668 2784 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys 14:13:43.0684 2784 mouhid - ok 14:13:43.0730 2784 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys 14:13:43.0730 2784 MountMgr - ok 14:13:43.0808 2784 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys 14:13:43.0824 2784 mpio - ok 14:13:44.0011 2784 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys 14:13:44.0011 2784 mpsdrv - ok 14:13:44.0074 2784 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys 14:13:44.0089 2784 Mraid35x - ok 14:13:44.0152 2784 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys 14:13:44.0167 2784 MRxDAV - ok 14:13:44.0292 2784 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys 14:13:44.0292 2784 mrxsmb - ok 14:13:44.0370 2784 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys 14:13:44.0432 2784 mrxsmb10 - ok 14:13:44.0682 2784 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys 14:13:44.0682 2784 mrxsmb20 - ok 14:13:44.0791 2784 msahci (aa459f2ab3ab603c357ff117cae3d818) C:\Windows\system32\drivers\msahci.sys 14:13:44.0791 2784 msahci - ok 14:13:44.0854 2784 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys 14:13:44.0869 2784 msdsm - ok 14:13:44.0900 2784 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys 14:13:44.0916 2784 Msfs - ok 14:13:44.0947 2784 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys 14:13:44.0947 2784 msisadrv - ok 14:13:45.0025 2784 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys 14:13:45.0041 2784 MSKSSRV - ok 14:13:45.0072 2784 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys 14:13:45.0088 2784 MSPCLOCK - ok 14:13:45.0119 2784 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys 14:13:45.0134 2784 MSPQM - ok 14:13:45.0166 2784 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys 14:13:45.0181 2784 MsRPC - ok 14:13:45.0228 2784 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys 14:13:45.0228 2784 mssmbios - ok 14:13:45.0259 2784 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys 14:13:45.0275 2784 MSTEE - ok 14:13:45.0337 2784 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys 14:13:45.0353 2784 Mup - ok 14:13:45.0743 2784 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys 14:13:45.0774 2784 NativeWifiP - ok 14:13:46.0273 2784 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys 14:13:46.0460 2784 NDIS - ok 14:13:47.0584 2784 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys 14:13:47.0599 2784 NdisTapi - ok 14:13:48.0083 2784 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys 14:13:48.0083 2784 Ndisuio - ok 14:13:49.0019 2784 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys 14:13:49.0050 2784 NdisWan - ok 14:13:49.0284 2784 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys 14:13:49.0284 2784 NDProxy - ok 14:13:49.0424 2784 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys 14:13:49.0440 2784 NetBIOS - ok 14:13:49.0643 2784 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys 14:13:49.0690 2784 netbt - ok 14:13:49.0846 2784 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys 14:13:49.0846 2784 nfrd960 - ok 14:13:50.0002 2784 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys 14:13:50.0002 2784 Npfs - ok 14:13:50.0048 2784 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys 14:13:50.0064 2784 nsiproxy - ok 14:13:50.0688 2784 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys 14:13:50.0844 2784 Ntfs - ok 14:13:51.0593 2784 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys 14:13:51.0608 2784 Null - ok 14:13:51.0780 2784 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys 14:13:51.0796 2784 nvraid - ok 14:13:51.0858 2784 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys 14:13:51.0874 2784 nvstor - ok 14:13:51.0920 2784 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys 14:13:51.0936 2784 nv_agp - ok 14:13:51.0967 2784 NwlnkFlt - ok 14:13:51.0983 2784 NwlnkFwd - ok 14:13:52.0076 2784 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys 14:13:52.0092 2784 ohci1394 - ok 14:13:52.0170 2784 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys 14:13:52.0186 2784 Parport - ok 14:13:52.0232 2784 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys 14:13:52.0248 2784 partmgr - ok 14:13:52.0373 2784 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys 14:13:52.0373 2784 pci - ok 14:13:52.0420 2784 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys 14:13:52.0435 2784 pciide - ok 14:13:52.0482 2784 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys 14:13:52.0544 2784 pcmcia - ok 14:13:52.0747 2784 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys 14:13:52.0841 2784 PEAUTH - ok 14:13:52.0919 2784 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys 14:13:52.0981 2784 PptpMiniport - ok 14:13:53.0028 2784 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys 14:13:53.0044 2784 Processor - ok 14:13:53.0122 2784 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys 14:13:53.0137 2784 PSched - ok 14:13:53.0231 2784 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys 14:13:53.0246 2784 PxHlpa64 - ok 14:13:54.0650 2784 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys 14:13:54.0791 2784 ql2300 - ok 14:13:55.0477 2784 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys 14:13:55.0493 2784 ql40xx - ok 14:13:55.0774 2784 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys 14:13:55.0789 2784 QWAVEdrv - ok 14:13:55.0852 2784 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys 14:13:55.0867 2784 RasAcd - ok 14:13:55.0961 2784 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys 14:13:55.0976 2784 Rasl2tp - ok 14:13:56.0195 2784 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys 14:13:56.0242 2784 RasPppoe - ok 14:13:56.0413 2784 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys 14:13:56.0429 2784 RasSstp - ok 14:13:56.0554 2784 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys 14:13:56.0647 2784 rdbss - ok 14:13:56.0710 2784 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys 14:13:56.0710 2784 RDPCDD - ok 14:13:56.0881 2784 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys 14:13:57.0006 2784 rdpdr - ok 14:13:57.0053 2784 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys 14:13:57.0053 2784 RDPENCDD - ok 14:13:57.0209 2784 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys 14:13:57.0240 2784 RDPWD - ok 14:13:57.0365 2784 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys 14:13:57.0380 2784 rspndr - ok 14:13:57.0396 2784 RSUSBSTOR - ok 14:13:57.0630 2784 RTHDMIAzAudService (f8da8fc39ce5859c0d8c0fe6524ce465) C:\Windows\system32\drivers\RtHDMIVX.sys 14:13:57.0646 2784 RTHDMIAzAudService - ok 14:13:58.0550 2784 RTL8187Se (462308d94e4e3318503267991b0cdc7f) C:\Windows\system32\DRIVERS\RTL8187Se.sys 14:13:58.0706 2784 RTL8187Se - ok 14:13:59.0174 2784 Rts516xIR - ok 14:13:59.0689 2784 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys 14:13:59.0705 2784 sbp2port - ok 14:14:00.0688 2784 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 14:14:00.0688 2784 secdrv - ok 14:14:02.0232 2784 Serenum (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys 14:14:02.0248 2784 Serenum - ok 14:14:02.0747 2784 Serial (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys 14:14:02.0762 2784 Serial - ok 14:14:02.0965 2784 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys 14:14:03.0090 2784 sermouse - ok 14:14:03.0137 2784 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys 14:14:03.0152 2784 sffdisk - ok 14:14:03.0230 2784 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys 14:14:03.0246 2784 sffp_mmc - ok 14:14:03.0277 2784 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys 14:14:03.0293 2784 sffp_sd - ok 14:14:03.0340 2784 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys 14:14:03.0340 2784 sfloppy - ok 14:14:03.0418 2784 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys 14:14:03.0433 2784 SiSRaid2 - ok 14:14:03.0620 2784 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys 14:14:03.0636 2784 SiSRaid4 - ok 14:14:03.0714 2784 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys 14:14:03.0745 2784 Smb - ok 14:14:03.0823 2784 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys 14:14:03.0839 2784 spldr - ok 14:14:04.0338 2784 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys 14:14:04.0432 2784 srv - ok 14:14:05.0414 2784 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys 14:14:05.0430 2784 srv2 - ok 14:14:06.0007 2784 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys 14:14:06.0054 2784 srvnet - ok 14:14:06.0304 2784 StillCam (14b4db4381e4a55f570d8bb699b791d6) C:\Windows\system32\DRIVERS\serscan.sys 14:14:06.0319 2784 StillCam - ok 14:14:06.0444 2784 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys 14:14:06.0444 2784 swenum - ok 14:14:06.0756 2784 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys 14:14:06.0772 2784 Symc8xx - ok 14:14:06.0928 2784 SymDSMon (e7b1bcb70355a84d6dfee12702b588d0) C:\Windows\system32\drivers\SymDSMon.sys 14:14:07.0021 2784 SymDSMon - ok 14:14:07.0099 2784 SYMSpeedDisk (f0268941519d73658199ecb1bb712be1) C:\Windows\system32\drivers\SymSpeedDisk.sys 14:14:07.0130 2784 SYMSpeedDisk - ok 14:14:07.0177 2784 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys 14:14:07.0193 2784 Sym_hi - ok 14:14:07.0240 2784 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys 14:14:07.0255 2784 Sym_u3 - ok 14:14:07.0832 2784 Tcpip (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\drivers\tcpip.sys 14:14:07.0926 2784 Tcpip - ok 14:14:08.0176 2784 Tcpip6 (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\DRIVERS\tcpip.sys 14:14:08.0191 2784 Tcpip6 - ok 14:14:08.0472 2784 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys 14:14:08.0488 2784 tcpipreg - ok 14:14:08.0831 2784 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys 14:14:08.0846 2784 TDPIPE - ok 14:14:08.0987 2784 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys 14:14:09.0002 2784 TDTCP - ok 14:14:09.0283 2784 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys 14:14:09.0299 2784 tdx - ok 14:14:09.0502 2784 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys 14:14:09.0517 2784 TermDD - ok 14:14:09.0782 2784 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys 14:14:09.0798 2784 tssecsrv - ok 14:14:09.0845 2784 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys 14:14:09.0860 2784 tunmp - ok 14:14:09.0954 2784 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys 14:14:09.0954 2784 tunnel - ok 14:14:10.0032 2784 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys 14:14:10.0048 2784 uagp35 - ok 14:14:10.0360 2784 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys 14:14:10.0406 2784 udfs - ok 14:14:10.0453 2784 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys 14:14:10.0469 2784 uliagpkx - ok 14:14:10.0890 2784 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys 14:14:10.0968 2784 uliahci - ok 14:14:11.0311 2784 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys 14:14:11.0327 2784 UlSata - ok 14:14:11.0998 2784 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys 14:14:12.0044 2784 ulsata2 - ok 14:14:12.0700 2784 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys 14:14:12.0731 2784 umbus - ok 14:14:13.0324 2784 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 14:14:13.0355 2784 USBAAPL64 - ok 14:14:13.0573 2784 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys 14:14:13.0589 2784 usbccgp - ok 14:14:13.0901 2784 USBCCID - ok 14:14:14.0447 2784 usbcir (8c39d53e1a343f4c47ee8f3c052126d8) C:\Windows\system32\DRIVERS\usbcir.sys 14:14:14.0462 2784 usbcir - ok 14:14:15.0476 2784 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys 14:14:15.0492 2784 usbehci - ok 14:14:16.0584 2784 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys 14:14:16.0678 2784 usbhub - ok 14:14:17.0052 2784 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys 14:14:17.0068 2784 usbohci - ok 14:14:17.0395 2784 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys 14:14:17.0395 2784 usbprint - ok 14:14:17.0770 2784 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys 14:14:17.0770 2784 usbscan - ok 14:14:18.0737 2784 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS 14:14:18.0737 2784 USBSTOR - ok 14:14:19.0626 2784 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys 14:14:19.0657 2784 usbuhci - ok 14:14:19.0954 2784 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys 14:14:19.0969 2784 vga - ok 14:14:20.0203 2784 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys 14:14:20.0219 2784 VgaSave - ok 14:14:20.0312 2784 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys 14:14:20.0328 2784 viaide - ok 14:14:20.0515 2784 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys 14:14:20.0531 2784 volmgr - ok 14:14:20.0562 2784 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys 14:14:20.0578 2784 volmgrx - ok 14:14:20.0749 2784 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys 14:14:20.0796 2784 volsnap - ok 14:14:20.0843 2784 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys 14:14:20.0858 2784 vsmraid - ok 14:14:20.0921 2784 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys 14:14:20.0921 2784 WacomPen - ok 14:14:21.0514 2784 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 14:14:21.0529 2784 Wanarp - ok 14:14:21.0529 2784 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 14:14:21.0545 2784 Wanarpv6 - ok 14:14:22.0450 2784 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys 14:14:22.0465 2784 Wd - ok 14:14:22.0949 2784 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys 14:14:22.0996 2784 Wdf01000 - ok 14:14:23.0276 2784 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys 14:14:23.0292 2784 WmiAcpi - ok 14:14:23.0432 2784 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys 14:14:23.0448 2784 WpdUsb - ok 14:14:23.0542 2784 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys 14:14:23.0573 2784 ws2ifsl - ok 14:14:23.0682 2784 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys 14:14:23.0698 2784 WUDFRd - ok 14:14:23.0744 2784 MBR (0x1B8) (b751af1acddd7a1a71313731839f4ecb) \Device\Harddisk0\DR0 14:14:24.0259 2784 \Device\Harddisk0\DR0 - ok 14:14:24.0275 2784 Boot (0x1200) (e63af501442e01a7bfdf3c05983355c1) \Device\Harddisk0\DR0\Partition0 14:14:24.0275 2784 \Device\Harddisk0\DR0\Partition0 - ok 14:14:24.0275 2784 ============================================================ 14:14:24.0275 2784 Scan finished 14:14:24.0275 2784 ============================================================ 14:14:24.0290 6428 Detected object count: 0 14:14:24.0290 6428 Actual detected object count: 0 ~James
Hi James,

Those two errors are related to a problem with Windows itself. I do not presently see any signs of malware on your system.

You may be better served posting a new topic in the Windows forum found here. They will be better able to help you there than I am at this point. Be sure to let them know what the two error messages are as well as posting a link to the topic we have worked on here so that they are able to see what we have done. :)
Hi Jeff

Paws in Windows forum recommended I rejoin the malware forum to figure out if the recent discoveries of malware are "false positives" being generated in my CA Technologies Internet Security Suite Plus antivirus software.

"BTW my malware and anti virus software detected the following rogue security software and backdoor software in the system files: WinAntivirus Pro 2006, WinSpyware Protect and Bifrost"

Please refer to this link for information from Paws in the windows forum

== > http://forums.whatthetech.com/index.php?sh…21112&st=15


thanks

~James
Hi James,

:wavey: Lets get a fresh look at your system.

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please post both of the logs created by DDS into your next reply and we will get going. :)
Hey Jeff: Posted files… DDS.TXT. DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 15:10:04 on 2011-11-21 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.6134.3994 [GMT -5:00] . AV: CA Anti-Virus Plus *Disabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA} SP: CA Anti-Virus Plus *Disabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: CA Personal Firewall *Enabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agr64svc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\SysWOW64\mdmcls32.exe C:\Windows\SysWOW64\svcprs32.exe C:\Windows\SysWOW64\cfgmig32.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\MHotKey.exe C:\Windows\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\ChiFuncExt.exe C:\Windows\RAVCpl64.exe C:\Program Files\CA\CA Internet Security Suite\casc.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Windows\CNYHKey.exe C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ModLedKey.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\CA\CA Internet Security Suite\ccprovep.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamscanner.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = Preserve uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: CA Anti-Phishing Toolbar Helper: {45011cf5-e4a9-4f13-9093-f30a784eb9b2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: WinZip Courier BHO: {a8fb70fa-0fdf-4601-9dc4-bfa1b357204f} - C:\PROGRA~2\WINZIP~2\wzwmcie.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe mRun: [LchDrvKey] LchDrvKey.exe mRun: [LedKey] CNYHKey.exe mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" dRunOnce: [StartMSu] "C:\Program Files (x86)\Creative\MediaSource5\Startmsu.exe" /s mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL LSP: winsflt.dll DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E} : DhcpNameServer = 192.168.0.1 Notify: PFW - UmxWnp.Dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: CA Anti-Phishing Toolbar Helper: {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: WinZip Courier BHO: {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\PROGRA~2\WINZIP~2\wzwmcie.dll BHO-X64: WinZip Courier BHO - No File BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO-X64: SmartSelect - No File TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB-X64: CA Anti-Phishing Toolbar: {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll mRun-x64: [LchDrvKey] LchDrvKey.exe mRun-x64: [LedKey] CNYHKey.exe mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" . ============= SERVICES / DRIVERS =============== . R0 KmxAMRT;KmxAMRT;C:\Windows\system32\DRIVERS\KmxAMRT.sys –> C:\Windows\system32\DRIVERS\KmxAMRT.sys [?] R0 KmxFw;KmxFw;C:\Windows\system32\DRIVERS\kmxfw.sys –> C:\Windows\system32\DRIVERS\kmxfw.sys [?] R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R1 KmxAgent;KmxAgent;C:\Windows\system32\DRIVERS\kmxagent.sys –> C:\Windows\system32\DRIVERS\kmxagent.sys [?] R1 KmxCfg;KmxCfg;C:\Windows\system32\DRIVERS\kmxcfg.sys –> C:\Windows\system32\DRIVERS\kmxcfg.sys [?] R1 KmxFile;KmxFile;C:\Windows\system32\DRIVERS\KmxFile.sys –> C:\Windows\system32\DRIVERS\KmxFile.sys [?] R1 KmxFilter;HIPS Core Filter Driver;C:\Windows\system32\DRIVERS\KmxFilter.sys –> C:\Windows\system32\DRIVERS\KmxFilter.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 CAAMSvc;CAAMSvc;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe [2010-10-28 291656] R2 CAISafe;CAISafe;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe [2010-1-21 312656] R2 ccSchedulerSVC;CA Common Scheduler Service;C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe [2010-1-21 286032] R2 ETService;Empowering Technology Service;C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2009-11-17 24576] R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 KmxCF;KmxCF;C:\Windows\system32\DRIVERS\KmxCF.sys –> C:\Windows\system32\DRIVERS\KmxCF.sys [?] R2 KmxSbx;KmxSbx;C:\Windows\system32\DRIVERS\KmxSbx.sys –> C:\Windows\system32\DRIVERS\KmxSbx.sys [?] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-9-23 641832] R2 UmxEngine;TM Engine;C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-4-4 920656] R2 WinExtManager;WinSock Extention Manager;C:\Windows\SysWOW64\mdmcls32.exe [2010-12-25 3207184] R2 WinSvchostManager;WinSock Svchost Manager;C:\Windows\SysWOW64\svcprs32.exe [2010-12-25 2760720] R2 WinSvchostManagerSrv;WinSvchostManagerSrv;C:\Windows\SysWOW64\cfgmig32.exe [2010-12-25 263504] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 e1yexpress;Intel® Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys –> C:\Windows\system32\DRIVERS\e1y60x64.sys [?] R3 gwfilt64;gwfilt64;C:\Windows\system32\drivers\gwfilt64.sys –> C:\Windows\system32\drivers\gwfilt64.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-23 136176] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2008-1-9 79360] S3 fssfltr;FssFltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-1-23 136176] S3 HPEWSFXBULK;HPEWSFXBULK;C:\Windows\system32\drivers\hpfx64bulk.sys –> C:\Windows\system32\drivers\hpfx64bulk.sys [?] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 Symantec Core LC;Symantec Core LC;C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-1-9 1245064] S3 SymDSMon;SymDSMon;\??\C:\Windows\system32\drivers\SymDSMon.sys –> C:\Windows\system32\drivers\SymDSMon.sys [?] S3 SYMSpeedDisk;SYMSpeedDisk;C:\Windows\System32\drivers\SymSpeedDisk.sys [2010-12-27 108800] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-11-18 89920] S4 DiskDoctorService;Norton Disk Doctor Service;C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [2010-12-27 1029480] S4 SpeedDiskService;Norton SpeedDisk Service;C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [2010-12-27 1037672] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== File Associations =============== . JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2011-11-19 19:39:49 ——– d—–w- C:\Program Files\iPod 2011-11-19 19:39:48 ——– d—–w- C:\Program Files\iTunes 2011-11-17 17:26:49 ——– d—–w- C:\Program Files (x86)\Seagate 2011-11-17 17:24:16 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2011-11-12 18:02:21 60296 —h–w- C:\Windows\System32\drivers\PROCMON20.SYS 2011-11-10 03:42:44 ——– d-sh–w- C:\$RECYCLE.BIN 2011-11-10 02:47:56 ——– d—–w- C:\Users\Admin\AppData\Local\temp 2011-11-10 02:33:10 98816 —-a-w- C:\Windows\sed.exe 2011-11-10 02:33:10 518144 —-a-w- C:\Windows\SWREG.exe 2011-11-10 02:33:10 256000 —-a-w- C:\Windows\PEV.exe 2011-11-10 02:33:10 208896 —-a-w- C:\Windows\MBR.exe 2011-11-09 21:41:19 1426304 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-11-09 21:41:18 893440 —-a-w- C:\Program Files\Common Files\System\wab32.dll 2011-11-09 21:41:17 707584 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll 2011-11-09 21:41:17 50688 —-a-w- C:\Program Files\Windows Mail\wabimp.dll 2011-11-07 00:09:24 525544 —-a-w- C:\Windows\System32\deployJava1.dll 2011-11-06 16:30:16 2106216 —-a-w- C:\Windows\SysWow64\D3DCompiler_43.dll 2011-11-06 16:30:16 1868128 —-a-w- C:\Windows\SysWow64\d3dcsx_43.dll 2011-11-06 16:30:15 470880 —-a-w- C:\Windows\SysWow64\d3dx10_43.dll 2011-11-06 16:30:15 248672 —-a-w- C:\Windows\SysWow64\d3dx11_43.dll 2011-11-06 16:30:15 1998168 —-a-w- C:\Windows\SysWow64\D3DX9_43.dll 2011-11-05 01:10:41 ——– d—–w- C:\_OTL 2011-10-30 04:20:55 ——– d—–w- C:\Users\Admin\AppData\Roaming\Malwarebytes 2011-10-30 04:20:39 ——– d—–w- C:\ProgramData\Malwarebytes 2011-10-30 04:20:34 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-10-30 04:20:34 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-10-29 18:34:34 388096 —-a-r- C:\Users\Admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-10-29 18:34:32 ——– d—–w- C:\Program Files (x86)\Trend Micro . ==================== Find3M ==================== . 2011-10-16 09:41:04 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-16 08:23:07 2524176 —-a-w- C:\Windows\System32\winsflt.dll 2011-09-16 08:23:07 1744912 —-a-w- C:\Windows\SysWow64\winsflt.dll 2011-09-16 08:19:45 1422672 —-a-w- C:\Windows\SysWow64\cfgmig32.dll 2011-09-16 08:19:45 1422672 —-a-w- C:\Windows\System32\cfgmig32.dll 2011-09-16 08:19:44 263504 —-a-w- C:\Windows\SysWow64\cfgmig32.exe 2011-09-16 08:19:36 95568 —-a-w- C:\Windows\System32\vetredir.dll 2011-09-16 08:19:36 141136 —-a-w- C:\Windows\System32\isafeif64.dll 2011-09-16 08:19:36 128336 —-a-w- C:\Windows\System32\isafeif.dll 2011-09-16 08:19:36 103760 —-a-w- C:\Windows\System32\vetredir64.dll 2011-09-14 15:47:42 60416 —-a-w- C:\Windows\System32\OVDecode64.dll 2011-09-14 15:47:40 53760 —-a-w- C:\Windows\SysWow64\OVDecode.dll 2011-09-14 15:47:10 16652288 —-a-w- C:\Windows\System32\amdocl64.dll 2011-09-14 15:38:30 44032 —-a-w- C:\Windows\System32\amdoclcl64.dll 2011-09-14 15:38:28 37376 —-a-w- C:\Windows\SysWow64\amdoclcl.dll 2011-09-08 18:27:22 10203648 —-a-w- C:\Windows\System32\drivers\atikmdag.sys 2011-09-08 17:59:44 24229376 —-a-w- C:\Windows\System32\atio6axx.dll 2011-09-08 17:39:44 18534912 —-a-w- C:\Windows\SysWow64\atioglxx.dll 2011-09-08 17:34:20 151552 —-a-w- C:\Windows\System32\atiapfxx.exe 2011-09-08 17:34:10 732672 —-a-w- C:\Windows\SysWow64\aticfx32.dll 2011-09-08 17:32:58 862720 —-a-w- C:\Windows\System32\aticfx64.dll 2011-09-08 17:30:38 466944 —-a-w- C:\Windows\System32\ATIDEMGX.dll 2011-09-08 17:30:26 486912 —-a-w- C:\Windows\System32\atieclxx.exe 2011-09-08 17:29:56 204288 —-a-w- C:\Windows\System32\atiesrxx.exe 2011-09-08 17:28:54 120320 —-a-w- C:\Windows\System32\atitmm64.dll 2011-09-08 17:28:38 423424 —-a-w- C:\Windows\System32\atipdl64.dll 2011-09-08 17:28:32 356352 —-a-w- C:\Windows\SysWow64\atipdlxx.dll 2011-09-08 17:28:22 278528 —-a-w- C:\Windows\SysWow64\Oemdspif.dll 2011-09-08 17:28:18 21504 —-a-w- C:\Windows\System32\atimuixx.dll 2011-09-08 17:28:14 59392 —-a-w- C:\Windows\System32\atiedu64.dll 2011-09-08 17:28:10 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll 2011-09-08 17:24:38 4204032 —-a-w- C:\Windows\SysWow64\atidxx32.dll 2011-09-08 17:18:56 1113088 —-a-w- C:\Windows\System32\atiumd6v.dll 2011-09-08 17:18:22 1828864 —-a-w- C:\Windows\SysWow64\atiumdmv.dll 2011-09-08 17:18:08 3888640 —-a-w- C:\Windows\System32\atiumd6a.dll 2011-09-08 17:16:00 4944896 —-a-w- C:\Windows\System32\atidxx64.dll 2011-09-08 17:09:42 51200 —-a-w- C:\Windows\System32\aticalrt64.dll 2011-09-08 17:09:40 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll 2011-09-08 17:09:30 44544 —-a-w- C:\Windows\System32\aticalcl64.dll 2011-09-08 17:09:28 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll 2011-09-08 17:09:18 8723456 —-a-w- C:\Windows\System32\aticaldd64.dll 2011-09-08 17:08:24 4064768 —-a-w- C:\Windows\SysWow64\atiumdva.dll 2011-09-08 17:05:52 7331840 —-a-w- C:\Windows\SysWow64\aticaldd.dll 2011-09-08 17:05:44 4289024 —-a-w- C:\Windows\SysWow64\atiumdag.dll 2011-09-08 17:00:02 5428736 —-a-w- C:\Windows\System32\atiumd64.dll 2011-09-08 16:59:48 58880 —-a-w- C:\Windows\System32\coinst.dll 2011-09-08 16:53:20 381952 —-a-w- C:\Windows\System32\atiadlxx.dll 2011-09-08 16:53:12 270336 —-a-w- C:\Windows\SysWow64\atiadlxy.dll 2011-09-08 16:52:58 15360 —-a-w- C:\Windows\System32\atig6pxx.dll 2011-09-08 16:52:56 13312 —-a-w- C:\Windows\SysWow64\atiglpxx.dll 2011-09-08 16:52:56 13312 —-a-w- C:\Windows\System32\atiglpxx.dll 2011-09-08 16:52:54 39936 —-a-w- C:\Windows\System32\atig6txx.dll 2011-09-08 16:52:46 32768 —-a-w- C:\Windows\SysWow64\atigktxx.dll 2011-09-08 16:52:40 310784 —-a-w- C:\Windows\System32\drivers\atikmpag.sys 2011-09-08 16:52:00 40960 —-a-w- C:\Windows\System32\atiuxp64.dll 2011-09-08 16:51:54 31744 —-a-w- C:\Windows\SysWow64\atiuxpag.dll 2011-09-08 16:51:50 38912 —-a-w- C:\Windows\System32\atiu9p64.dll 2011-09-08 16:51:44 29184 —-a-w- C:\Windows\SysWow64\atiu9pag.dll 2011-09-08 16:51:28 45056 —-a-w- C:\Windows\System32\atitmp64.dll 2011-09-08 16:51:12 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll 2011-09-08 16:51:02 54784 —-a-w- C:\Windows\System32\atimpc64.dll 2011-09-08 16:51:02 54784 —-a-w- C:\Windows\System32\amdpcom64.dll 2011-09-08 16:50:54 53760 —-a-w- C:\Windows\SysWow64\atimpc32.dll 2011-09-08 16:50:54 53760 —-a-w- C:\Windows\SysWow64\amdpcom32.dll 2011-09-06 13:56:50 2764288 —-a-w- C:\Windows\System32\win32k.sys 2011-09-01 05:24:07 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-09-01 05:17:57 1389056 —-a-w- C:\Windows\System32\wininet.dll 2011-09-01 05:12:04 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-09-01 02:35:59 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-09-01 02:28:15 1126912 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-09-01 02:22:54 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 03:05:32 96104 —-a-w- C:\Windows\System32\dns-sd.exe 2011-08-31 03:05:32 85864 —-a-w- C:\Windows\System32\dnssd.dll 2011-08-31 03:05:04 83816 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-08-31 03:05:04 73064 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-08-25 16:20:38 735744 —-a-w- C:\Windows\System32\UIAutomationCore.dll 2011-08-25 16:19:32 847360 —-a-w- C:\Windows\System32\oleaut32.dll 2011-08-25 16:19:32 332288 —-a-w- C:\Windows\System32\oleacc.dll 2011-08-25 16:15:04 555520 —-a-w- C:\Windows\SysWow64\UIAutomationCore.dll 2011-08-25 16:14:01 563712 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-08-25 16:14:01 238080 —-a-w- C:\Windows\SysWow64\oleacc.dll 2011-08-25 13:54:14 4096 —-a-w- C:\Windows\System32\oleaccrc.dll 2011-08-25 13:31:01 4096 —-a-w- C:\Windows\SysWow64\oleaccrc.dll 2011-08-25 00:19:10 56320 —-a-w- C:\Windows\SysWow64\OpenVideo.dll 2011-08-25 00:18:30 13601280 —-a-w- C:\Windows\SysWow64\amdocl.dll 2011-08-25 00:17:52 43520 —-a-w- C:\Windows\SysWow64\OpenCL.dll . ============= FINISH: 15:11:44.00 =============== ATTACH.TXT . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 9/10/2009 5:36:39 PM System Uptime: 11/21/2011 12:46:23 PM (3 hours ago) . Motherboard: Gateway | | TBGM01 Processor: Intel® Core™ i7 CPU 920 @ 2.67GHz | CPU 1 | 2667/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 689 GiB total, 174.306 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft 6to4 Adapter Device ID: ROOT\*6TO4MP\0001 Manufacturer: Microsoft Name: Microsoft 6to4 Adapter #2 PNP Device ID: ROOT\*6TO4MP\0001 Service: tunnel . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft 6to4 Adapter Device ID: ROOT\*6TO4MP\0002 Manufacturer: Microsoft Name: Microsoft 6to4 Adapter #3 PNP Device ID: ROOT\*6TO4MP\0002 Service: tunnel . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&6730480&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&6730480&0 Service: i8042prt . ==== System Restore Points =================== . RP990: 11/20/2011 12:40:51 AM - Scheduled Checkpoint RP991: 11/21/2011 1:47:32 PM - Scheduled Checkpoint . ==== Installed Programs ====================== . . Update for Microsoft Office 2007 (KB2508958) 2008 National Repair and Remodeling Estimator Download 2011 National Repair and Remodeling Estimator 2011 National Repair and Remodeling Estimator License Adobe Acrobat 9 Pro - English, Français, Deutsch Adobe Acrobat 9.1.2 - CPSID_49166 Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Creative Suite Adobe Flash Player 10 Plugin Adobe Flash Player 11 ActiveX Adobe Illustrator CS Adobe Photoshop CS Adobe Shockwave Player 11.5 Adobe SVG Viewer 6.0 Advertising Center Apple Application Support Apple Software Update Application Profiles AVerMedia M791 PCIe Combo NTSC/ATSC 6.104.64.5 CA Anti-Spam CA Backup and Migration CA Parental Controls Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy CCC Help English Compatibility Pack for the 2007 Office system Conduit Engine CyberLink LabelPrint D3DX10 DNAMigrator DolbyFiles EPSON Scan ERUNT 1.1j Forté Agent Gateway Recovery Management GearDrvs Google Earth Plug-in Google Talk Plugin Google Update Helper GoToAssist Corporate GoToMeeting 4.8.0.723 High-Definition Video Playback HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) ImagXpress Intuit SiteBuilder Java Auto Updater Java™ 6 Update 22 Java™ 6 Update 5 Junk Mail filter update KB0817 Keyboard Driver Lane Guide Online Launcher version 1.0 Malwarebytes' Anti-Malware version 1.51.2.1300 Menu Templates - Starter Kit Mesh Runtime Messenger Companion Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual J# 2.0 Redistributable Package Monkey's Audio Movie Templates - Starter Kit MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 10 Creative CollectionPack 1 Nero 10 Kwik Themes 3 Nero 10 Kwik Themes 4 Nero 10 Menu TemplatePack Basic Nero 10 Movie ThemePack Basic Nero 10 PiP EffectPack 1 Nero 10 Video TransitionPack 1 Nero 9 Nero Audio Pack 1 Nero BackItUp 10 Nero BackItUp 10 Help (CHM) Nero Burning ROM 10 Nero BurningROM 10 Help (CHM) Nero BurnRights Nero BurnRights 10 Nero BurnRights 10 Help (CHM) Nero Control Center 10 Nero ControlCenter Nero ControlCenter 10 Help (CHM) Nero Core Components 10 Nero Core Components 11 Nero CoverDesigner Nero CoverDesigner 10 Nero CoverDesigner 10 Help (CHM) Nero Disc Copy Gadget Nero DiscSpeed Nero DiscSpeed 10 Nero DiscSpeed 10 Help (CHM) Nero DriveSpeed Nero Express 10 Nero Express 10 Help (CHM) Nero InfoTool Nero InfoTool 10 Nero InfoTool 10 Help (CHM) Nero Installer Nero Kwik Media Nero Kwik Media Help (CHM) Nero Live Nero Move it Nero Move it Help Nero Move it Trial Nero Multimedia Suite 10 Nero PhotoSnap Nero Prerequisite Installer 1.0 Nero Recode Nero Recode 10 Nero Recode 10 Help (CHM) Nero Rescue Agent Nero RescueAgent 10 Nero RescueAgent 10 Help (CHM) Nero ShowTime Nero SoundTrax 10 Nero SoundTrax 10 Help (CHM) Nero StartSmart Nero StartSmart 10 Nero StartSmart 10 Help (CHM) Nero Update Nero Vision Nero Vision 10 Nero Vision 10 Help (CHM) Nero WaveEditor Nero WaveEditor 10 Nero WaveEditor 10 Help (CHM) nero.prerequisites.msi NeroBurningROM NeroExpress NeroLiveGadget neroxml Norton Utilities 15 Picasa 3 QuickTime RapidShare Manager 2 Realtek High Definition Audio Driver SeaTools for Windows Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Segoe UI Sound Blaster X-Fi MB SoundTrax Symantec Technical Support Web Controls The National Estimator TWC Customer Controls Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (KB2596560) VLC media player 1.1.11 VuePrint VueScan Vuze Remote Toolbar WebEx Record and Playback Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinZip 15.5 WinZip Courier WinZip Self-Extractor . ==== Event Viewer Messages From Past Week ======== . 11/21/2011 12:48:23 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep 11/20/2011 9:17:56 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {5F36DC27-B076-4D0C-BD8C-7AEE14022193} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 11/19/2011 8:44:16 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioSrv service. 11/19/2011 8:43:46 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the stisvc service. 11/19/2011 4:03:25 AM, Error: Service Control Manager [7034] - The Creative Audio Service service terminated unexpectedly. It has done this 1 time(s). 11/19/2011 2:38:34 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Apple Mobile Device service, but this action failed with the following error: An instance of the service is already running. 11/19/2011 2:37:34 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/19/2011 2:37:20 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/18/2011 9:38:35 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {5F36DC27-B076-4D0C-BD8C-7AEE14022193} to the user Admin-PC\Admin SID (S-1-5-21-4027082081-1360438707-2940866900-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 11/18/2011 2:19:39 PM, Error: EventLog [6008] - The previous system shutdown at 2:12:28 PM on 11/18/2011 was unexpected. 11/18/2011 10:12:10 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the CaCCProvSP service to connect. 11/18/2011 10:12:10 PM, Error: Service Control Manager [7000] - The CaCCProvSP service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 11/18/2011 10:11:10 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service CaCCProvSP with arguments "" in order to run the server: {AACF4A1C-BC69-4359-9518-DF3F77E462BF} 11/18/2011 10:09:15 PM, Error: EventLog [6008] - The previous system shutdown at 9:55:31 PM on 11/18/2011 was unexpected. 11/16/2011 11:39:17 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom0. 11/15/2011 6:40:23 PM, Error: Microsoft-Windows-Bits-Client [16392] - The BITS service failed to start. Error 2147943515. 11/15/2011 6:13:01 PM, Error: Service Control Manager [7031] - The Norton SpeedDisk Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/15/2011 2:19:29 PM, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Beep DfsC KmxAgent KmxCfg KmxFile KmxFilter KmxFw NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6 ws2ifsl 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Creative Audio Service service depends on the Windows Audio service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 2:17:55 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 11/15/2011 12:22:56 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep KmxAgent KmxCfg KmxFile KmxFilter KmxFw spldr Wanarpv6 11/15/2011 12:22:46 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 11/15/2011 12:22:07 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 11/15/2011 12:22:01 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 11/15/2011 12:21:53 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 11/15/2011 11:43:05 PM, Error: Service Control Manager [7031] - The Norton Disk Doctor Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/15/2011 1:18:26 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 11/14/2011 9:52:07 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: An instance of the service is already running. 11/14/2011 9:52:07 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23). 11/14/2011 9:52:07 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. 11/14/2011 9:52:07 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 11/14/2011 9:51:26 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 11/14/2011 9:47:40 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 11/14/2011 10:29:49 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. . ==== End Of File ===========================
Hi James,

Sorry for the lat response…

I found something interesting on a CA forum that I would like to try first.

Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode with Networking menu item
  • Press Enter.
  • Now run a full scan of your system with your antivirus program (CA).
  • Once the scan has completed remove the quarantined items.
Let me know how that works for you. If it does not than we can go another route.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI