I was quite surprised to see so many threads about these particular infections in various tech support boards. Clicking any google search results redirects to a shopping website or some random website that dosen't look like it's registered (soandso Free Search Now!) I can also see PING.EXE in the task manager, it reopens automatically. ESET Smart Security detects an infected file at bootup and requests reboot to complete cleaning the infection, but however many times I restart the infection reappears.
C:\Windows\assembly\GAC_32\Desktop.ini - a variant of Win32/Sirefef.DN trojan - cleaned by deleting (after the next restart)
There were approx. 7 infections detected with M'Bytes Anti Malware, all of which were cleaned, scans come out clean as of today.
I also noticed that the hosts file is deleted at machine boot or shutdown, not sure which excatly.
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 20:46:21 on 2011-11-23
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.6127 [GMT 0:00]
.
AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
C:\ASUS.SYS\config\DVMExportService.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE
C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
L:\Program Files (x86)\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Windows\system32\wbem\wmiprvse.exe
L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\ASUS\Turbo Key\TurboKey.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\SysWOW64\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Logitech Scroll App: {e11db59d-5008-42ff-9069-535843bc0be1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - Yontoo Layers
uRun: [AdobeBridge]
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
mRun: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Filip\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
LSP: mswsock.dll
LSP: %SystemRoot%\system32\vsocklib.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{8242B4E1-B488-439F-A5FE-D4C3C23C4495} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{E2E466DE-8EB3-4A94-99D8-1DB2698E39BD} : DhcpNameServer = 192.168.55.2
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Logitech Scroll App: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
BHO-X64: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - Yontoo Layers
BHO-X64: Yontoo Layers - No File
mRun-x64: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe"
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 MDFSYSNT;MacDrive file system driver;C:\Windows\system32\drivers\MDFSYSNT.sys –> C:\Windows\system32\drivers\MDFSYSNT.sys [?]
R0 MDPMGRNT;MacDrive Partition Driver;C:\Windows\system32\DRIVERS\MDPMGRNT.SYS –> C:\Windows\system32\DRIVERS\MDPMGRNT.SYS [?]
R1 CBDisk;CBDisk;\??\C:\Windows\system32\drivers\CBDisk.sys –> C:\Windows\system32\drivers\CBDisk.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2011-4-26 90112]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys –> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 DvmMDES;DeviceVM Meta Data Export Service;C:\ASUS.SYS\config\DVMExportService.exe [2009-10-14 319488]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-5-14 731840]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys –> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-15 2329480]
R2 M4LIC;Mediafour M4LIC service;C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-7-29 205312]
R2 MacDrive8Service;MacDrive 8 service;C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-1-7 218112]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-13 366152]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-1 2253120]
R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\system32\DRIVERS\RtNdPt60.sys –> C:\Windows\system32\DRIVERS\RtNdPt60.sys [?]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-4-27 2280312]
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-3-9 92592]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-21 846448]
R2 VMwareHostd;VMware Workstation Server;L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440]
R3 DKRtWrt;DKRtWrt;C:\Windows\system32\DRIVERS\DKRtWrt.sys –> C:\Windows\system32\DRIVERS\DKRtWrt.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 V0260VID;Live! Cam Vista IM;C:\Windows\system32\DRIVERS\V0260Vid.sys –> C:\Windows\system32\DRIVERS\V0260Vid.sys [?]
S2 AMService;AMService;C:\Windows\TEMP\dbnwjd\setup.exe run –> C:\Windows\TEMP\dbnwjd\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-5-25 8192]
S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys –> C:\Windows\system32\DRIVERS\ggflt.sys [?]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys –> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);C:\Windows\system32\DRIVERS\RtTeam60.sys –> C:\Windows\system32\DRIVERS\RtTeam60.sys [?]
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);C:\Windows\system32\DRIVERS\RtVlan60.sys –> C:\Windows\system32\DRIVERS\RtVlan60.sys [?]
S3 SaiK0836;SaiK0836;C:\Windows\system32\DRIVERS\SaiK0836.sys –> C:\Windows\system32\DRIVERS\SaiK0836.sys [?]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-6-5 152064]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);C:\Windows\system32\DRIVERS\RtTeam60.sys –> C:\Windows\system32\DRIVERS\RtTeam60.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys –> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== File Associations ===============
.
txtfile="C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
.
=============== Created Last 30 ================
.
2011-11-23 16:03:07 ——– d—–w- C:\Users\Filip\AppData\Local\{6BC45846-2F67-4C15-BDD1-C5D2A2FBC217}
2011-11-23 16:01:55 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll
2011-11-23 16:01:53 8570192 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll
2011-11-22 20:00:23 ——– d—–w- C:\Program Files (x86)\Algodoo
2011-11-22 16:17:21 ——– d—–w- C:\Users\Filip\AppData\Local\{5BBBAA24-90DC-4480-B395-3D9BFB8CA64D}
2011-11-21 11:37:37 ——– d—–w- C:\Users\Filip\AppData\Local\{93B1615B-A5E3-4B30-B9B2-5D4DB12D7A28}
2011-11-21 11:37:20 ——– d—–w- C:\Users\Filip\AppData\Local\{BAFAB55A-00BE-4B8A-84F5-7907B0ECA4E4}
2011-11-20 12:12:00 ——– d—–w- C:\Users\Filip\AppData\Local\{7A24CF98-A65E-49E5-ADF6-B44547BF6966}
2011-11-20 12:11:38 ——– d—–w- C:\Users\Filip\AppData\Local\{17350408-A3DC-4C50-B653-753D232313A6}
2011-11-20 12:06:10 ——– d—–w- C:\Users\Filip\AppData\Local\{6D42D460-61A4-4437-8BAE-BF616E563E38}
2011-11-19 13:18:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\ESET
2011-11-19 13:16:48 ——– d—–w- C:\Program Files\ESET
2011-11-19 09:42:18 ——– d—–w- C:\Users\Filip\AppData\Local\{754C8F4A-1768-4214-9CE0-015947FBB78B}
2011-11-19 09:41:53 ——– d—–w- C:\Users\Filip\AppData\Local\{0EA356A3-4CF1-48A1-8CBF-39CC02C53E52}
2011-11-18 22:41:50 ——– d—–w- C:\Users\Filip\AppData\Roaming\.minecraft
2011-11-18 21:56:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\mctechnick
2011-11-18 17:55:32 ——– d—–w- C:\Users\Filip\AppData\Local\{51A67855-334F-4988-8A54-7FAECA7FDC98}
2011-11-18 17:55:08 ——– d—–w- C:\Users\Filip\AppData\Local\{8E705346-414A-40F1-88BE-B68530E1DB1A}
2011-11-17 22:45:37 ——– d—–w- C:\Users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC
2011-11-17 20:33:13 ——– d—–w- C:\Users\Filip\AppData\Local\{FAC9AAF4-5818-4705-B8F2-F8ACECC002B5}
2011-11-17 20:33:01 ——– d—–w- C:\Users\Filip\AppData\Local\{1E3435A7-79C4-4D93-A3AD-AEF27CE372DC}
2011-11-17 16:10:46 ——– d—–w- C:\Users\Filip\AppData\Local\{CF990AF9-4577-41AB-84F6-270626A0E3E1}
2011-11-16 18:49:37 ——– d—–w- C:\Program Files (x86)\Sol Edit
2011-11-16 16:05:46 ——– d—–w- C:\Users\Filip\AppData\Local\{5C4CBAC7-3F2F-4C53-BBA0-7E1382060F78}
2011-11-16 16:05:27 ——– d—–w- C:\Users\Filip\AppData\Local\{DAE489E5-3501-40D8-88A5-257297D5757B}
2011-11-15 21:17:23 ——– d—–w- C:\Users\Filip\AppData\Local\{C0A35800-646A-447B-98A2-792B0946E6CC}
2011-11-15 21:17:11 ——– d—–w- C:\Users\Filip\AppData\Local\{18E86E3F-F2F2-4A16-A642-B9DB76A4C4E2}
2011-11-15 18:35:27 ——– d—–w- C:\ProgramData\ALM
2011-11-14 21:18:55 ——– d—–w- C:\Users\Filip\AppData\Roaming\Blender Foundation
2011-11-14 21:09:52 ——– d—–w- C:\Users\Filip\AppData\Roaming\inkscape
2011-11-14 20:59:48 ——– d—–w- C:\Users\Filip\.thumbnails
2011-11-14 20:59:35 ——– d—–w- C:\Program Files\Blender Foundation
2011-11-14 19:33:25 ——– d—–w- C:\Users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-11-14 18:38:56 32256 —-a-w- C:\ProgramData\l9gfqw6lai.exe
2011-11-13 21:44:58 235 —-a-w- C:\Windows\SysWow64\nxEuUninstall.bat
2011-11-13 21:44:53 446464 —-a-w- C:\Windows\NEXON_EU_DownloaderUpdater.exe
2011-11-13 21:24:38 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll
2011-11-13 21:02:08 ——– d—–w- C:\Nexon
2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\Spam Monitor
2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\PCToolsFirewallPlus
2011-11-13 12:57:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools
2011-11-13 12:39:06 ——– d—–w- C:\Users\Filip\AppData\Roaming\pymclevel
2011-11-13 12:38:37 ——– d—–w- C:\Users\Filip\AppData\Local\MCEdit-64bit
2011-11-13 12:33:19 ——– d—–w- C:\ProgramData\PC Tools
2011-11-13 10:18:45 ——– d—–w- C:\Users\Filip\AppData\Local\{B5EE657B-F0BD-42FE-A8DA-35125B472AE8}
2011-11-13 10:18:30 ——– d—–w- C:\Users\Filip\AppData\Local\{449B85E7-D03A-4EB9-9F04-79FE4D84C1B0}
2011-11-12 17:37:43 ——– d—–w- C:\Users\Filip\AppData\Local\{310251F6-4F2F-4954-AF79-C65579238B1A}
2011-11-12 17:37:24 ——– d—–w- C:\Users\Filip\AppData\Local\{2227EF0A-927F-487C-9320-EE263E5C3122}
2011-11-12 13:03:21 ——– d—–w- C:\Users\Filip\AppData\Local\{891C11B5-3B35-48B6-A551-0F9651572B8F}
2011-11-11 22:30:43 ——– d—–w- C:\Users\Filip\AppData\Local\Skyrim
2011-11-11 19:45:23 21992 —-a-w- C:\Windows\System32\drivers\cpuz135_x64.sys
2011-11-11 19:45:23 ——– d—–w- C:\Program Files\CPUID
2011-11-11 19:27:10 ——– d—–w- C:\ProgramData\Comodo Downloader
2011-11-11 16:27:45 ——– d—–we C:\Windows\system64
2011-11-11 16:23:43 ——– d—–w- C:\Users\Filip\AppData\Local\{706470F3-146E-4A5D-96E8-870585A8B18F}
2011-11-11 16:23:32 ——– d—–w- C:\Users\Filip\AppData\Local\{C5CA3EEB-5573-470F-962B-B703B3F39A72}
2011-11-10 18:40:16 ——– d—–w- C:\Users\Filip\AppData\Local\GForce
2011-11-10 18:40:12 ——– d—–w- C:\Program Files (x86)\ASIO4ALL v2
2011-11-10 18:39:11 ——– d—–w- C:\Program Files (x86)\VstPlugins
2011-11-10 18:39:08 ——– d—–w- C:\Program Files (x86)\GForce
2011-11-10 16:25:13 ——– d—–w- C:\Users\Filip\AppData\Local\{528B5662-1B42-40DE-A826-127DA9D55516}
2011-11-10 16:25:02 ——– d—–w- C:\Users\Filip\AppData\Local\{AF5194A8-B56B-480E-BF0D-BE37F9EC0632}
2011-11-09 17:41:59 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 17:41:59 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 17:41:56 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 17:41:52 3144704 —-a-w- C:\Windows\System32\win32k.sys
2011-11-09 15:46:24 ——– d—–w- C:\Users\Filip\AppData\Local\{95575238-7D0A-47A5-AD6D-096B1C6C4046}
2011-11-09 15:46:11 ——– d—–w- C:\Users\Filip\AppData\Local\{639CC487-6A09-4958-8591-CCA7D3298004}
2011-11-08 17:35:57 ——– d—–w- C:\Users\Filip\AppData\Local\{8B64D692-7869-4B14-AB6D-4A15BF51DF1D}
2011-11-08 17:35:43 ——– d—–w- C:\Users\Filip\AppData\Local\{A4BADC77-D106-4CC7-A2F9-7F0A084F871B}
2011-11-07 19:50:49 ——– d—–w- C:\Program Files (x86)\Yontoo Layers Runtime
2011-11-07 19:50:04 ——– d—–w- C:\Downloads
2011-11-07 19:40:30 ——– d—–w- C:\Users\Filip\AppData\Roaming\Free Download Manager
2011-11-07 16:22:43 ——– d—–w- C:\Users\Filip\AppData\Local\{3DCBC98D-27E5-4B8D-A611-B35BE9430A9D}
2011-11-07 16:22:32 ——– d—–w- C:\Users\Filip\AppData\Local\{D40E7156-DFAF-4089-A1AD-A74C206DC980}
2011-11-06 19:13:12 3074368 —-a-w- C:\Windows\System32\nvsvcr.dll
2011-11-05 20:55:59 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll
2011-11-05 16:16:15 ——– d—–w- C:\Users\Filip\AppData\Roaming\Polynomial
2011-11-05 16:16:06 ——– d—–w- C:\Program Files (x86)\The Polynomial
2011-11-05 13:36:25 ——– d—–w- C:\data
2011-11-05 10:40:46 ——– d—–w- C:\Users\Filip\AppData\Local\{6C5390A8-344E-4E2A-B7C7-AC06A3AB689F}
2011-11-05 10:40:33 ——– d—–w- C:\Users\Filip\AppData\Local\{A2388B35-93A8-4701-A6F5-9A1C4B83A05B}
2011-11-04 20:18:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\AtomZombieData
2011-11-04 20:11:53 ——– d—–w- C:\Users\Filip\AppData\Roaming\Voxatron
2011-11-04 18:21:14 ——– d—–w- C:\Users\Filip\AppData\Local\{A30D4DB5-D91E-4F5A-B511-12AF3135EBC6}
2011-11-04 18:21:03 ——– d—–w- C:\Users\Filip\AppData\Local\{8A0A44CF-9CBD-43D4-A7E2-E89399B60E4F}
2011-11-03 18:48:24 ——– d—–w- C:\Users\Filip\AppData\Local\Apple Computer
2011-11-03 18:40:39 ——– d—–w- C:\Program Files (x86)\Combined Community Codec Pack
2011-11-03 18:20:18 ——– d—–w- C:\Program Files\Media Player Classic - Home Cinema
2011-11-03 17:31:18 ——– d—–w- C:\Users\Filip\AppData\Local\{2FBDCE59-96F8-4B3D-BD95-B63221E308D0}
2011-11-03 17:31:05 ——– d—–w- C:\Users\Filip\AppData\Local\{6C1F5BBB-05C8-4F73-A254-2F7E45931266}
2011-11-03 08:11:07 ——– d—–w- C:\Users\Filip\AppData\Local\{65C9E9D2-262C-4EE2-B508-9823D3B12F4E}
2011-11-02 17:56:03 ——– d—–w- C:\Users\Filip\AppData\Local\Nero_AG
2011-11-02 17:55:28 ——– d—–w- C:\Users\Filip\AppData\Local\Nero
2011-11-02 17:54:19 ——– d—–w- C:\Users\Filip\AppData\Local\{473ECC4E-454E-41F5-8B6B-05A5E88D32FD}
2011-11-02 17:54:08 ——– d—–w- C:\Users\Filip\AppData\Local\{2C438F03-51E5-4AB5-B8F0-02400A9E134D}
2011-11-01 17:09:46 ——– d—–w- C:\Users\Filip\AppData\Local\{D47D465E-6BB0-4322-BE5D-8055AFFBC669}
2011-11-01 17:09:28 ——– d—–w- C:\Users\Filip\AppData\Local\{007A31D0-E416-42BD-B6AD-FFC9E101DF2F}
2011-10-31 18:06:52 ——– d—–w- C:\Users\Filip\AppData\Local\{106CC801-F100-43FA-A1D3-9C88F8462D06}
2011-10-31 18:06:29 ——– d—–w- C:\Users\Filip\AppData\Local\{284BB6A4-2BF1-4840-AD9B-B024BB34FF58}
2011-10-30 09:14:27 ——– d—–w- C:\Users\Filip\AppData\Local\{49828ABD-0040-49AE-9229-E5546FFE1E33}
2011-10-30 09:14:02 ——– d—–w- C:\Users\Filip\AppData\Local\{4C981980-300D-4C97-8F76-C4BF52901C14}
2011-10-29 17:35:56 ——– d—–w- C:\Users\Filip\AppData\Local\{73DF0A1B-FEBC-40B6-8254-763A32AC06A5}
2011-10-29 17:35:35 ——– d—–w- C:\Users\Filip\AppData\Local\{3A2FDC50-6705-4E61-BF4B-9A4629DF56DA}
2011-10-29 09:47:00 ——– d—–w- C:\Users\Filip\AppData\Local\APN
2011-10-29 09:46:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\ManyCam
2011-10-29 09:46:36 ——– d—–w- C:\ProgramData\Ask
2011-10-29 09:36:52 ——– d—–w- C:\Users\Filip\AppData\Local\{276925AF-CF6F-4F49-AAD3-6637D70FA15E}
2011-10-28 17:33:34 810496 —-a-w- C:\Windows\System32\xvidcore.dll
2011-10-28 17:33:34 80896 —-a-w- C:\Windows\System32\ff_vfw.dll
2011-10-28 17:33:34 183808 —-a-w- C:\Windows\System32\xvidvfw.dll
2011-10-28 17:33:00 389120 —-a-w- C:\Windows\SysWow64\actskn43.ocx
2011-10-28 17:33:00 389120 —-a-w- C:\Windows\System32\actskn43.ocx
2011-10-28 10:28:10 ——– d—–w- C:\Users\Filip\AppData\Local\{864C829F-D53A-4B18-83E0-99B752BD7993}
2011-10-28 10:27:58 ——– d—–w- C:\Users\Filip\AppData\Local\{2351F912-0E2A-4175-99DA-87B0AB8A0671}
2011-10-27 08:59:16 ——– d—–w- C:\Users\Filip\AppData\Local\{7BCEF7FF-0A87-4A05-AA91-597DEC255EC6}
2011-10-27 08:58:51 ——– d—–w- C:\Users\Filip\AppData\Local\{EA6EE90D-F77D-4896-BC8C-48F3B149E1C9}
2011-10-26 12:36:20 6144 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll
2011-10-26 12:36:20 6144 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-10-26 12:26:36 ——– d—–w- C:\Users\Filip\AppData\Local\{6C2BE5E5-01B8-4D6E-85B6-12164301E01E}
2011-10-26 12:26:22 ——– d—–w- C:\Users\Filip\AppData\Local\{F43BD921-F76E-487B-9E77-8CDC92C93491}
2011-10-25 09:27:25 ——– d—–w- C:\Users\Filip\AppData\Local\{853493E7-6E58-4E16-82D7-73BCEA87972F}
2011-10-25 09:27:04 ——– d—–w- C:\Users\Filip\AppData\Local\{35050DF5-5C72-4FF5-B22D-457BA09F8839}
.
==================== Find3M ====================
.
2011-11-14 18:06:57 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-11 19:50:11 6656 —-a-w- C:\Windows\System32\lpcio.dll
2011-11-09 18:25:38 850152 —-a-w- C:\Windows\SysWow64\SpoonUninstall.exe
2011-11-05 12:59:55 466456 —-a-w- C:\Windows\System32\wrap_oal.dll
2011-11-05 12:59:55 444952 —-a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-11-05 12:59:55 122904 —-a-w- C:\Windows\System32\OpenAL32.dll
2011-11-05 12:59:55 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-10-15 00:54:52 321856 —-a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-10-04 20:29:42 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-04 16:38:17 75136 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-10-03 05:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-02 11:58:11 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-10-01 03:25:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:42:56 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-31 17:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll
.
============= FINISH: 20:47:14.40 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 24/04/2011 15:55:58
System Uptime: 23/11/2011 15:58:10 (5 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P5G41TD-M PRO
Processor: Intel® Core™2 Duo CPU E8400 @ 3.00GHz | LGA775 | 3003/333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 186 GiB total, 58.885 GiB free.
D: is FIXED (NTFS) - 373 GiB total, 11.06 GiB free.
E: is CDROM ()
F: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is FIXED (HFSJ) - 233 GiB total, 156.503 GiB free.
L: is FIXED (NTFS) - 140 GiB total, 19.192 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VMware Virtual Ethernet Adapter for VMnet1
Device ID: ROOT\VMWARE\0000
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet1
PNP Device ID: ROOT\VMWARE\0000
Service: VMnetAdapter
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VMware Virtual Ethernet Adapter for VMnet8
Device ID: ROOT\VMWARE\0001
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet8
PNP Device ID: ROOT\VMWARE\0001
Service: VMnetAdapter
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: TeamViewer VPN Adapter
Device ID: ROOT\NET\0001
Manufacturer: TeamViewer GmbH
Name: TeamViewer VPN Adapter
PNP Device ID: ROOT\NET\0001
Service: teamviewervpn
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VirtualBox Host-Only Ethernet Adapter
Device ID: ROOT\NET\0002
Manufacturer: Oracle Corporation
Name: VirtualBox Host-Only Ethernet Adapter
PNP Device ID: ROOT\NET\0002
Service: VBoxNetAdp
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Windows Firewall Authorization Driver
Device ID: ROOT\LEGACY_MPSDRV\0000
Manufacturer:
Name: Windows Firewall Authorization Driver
PNP Device ID: ROOT\LEGACY_MPSDRV\0000
Service: mpsdrv
.
==== System Restore Points ===================
.
RP254: 23/11/2011 16:01:35 - Windows Update
.
==== Installed Programs ======================
.
.sol Editor 1.1.0.1
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Illustrator CS5.1
Adobe Photoshop CS5.1
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.6
Aerosoft's - Aerosoft Launcher
Algodoo v2.0.0
Apple Application Support
Apple Software Update
ASIO4ALL
Assassin's Creed Brotherhood
ASUSUpdate
Audacity 1.3.13 (Unicode)
Audiograbber 1.83 SE
Audiograbber MP3 Plugin
AutoHotkey 1.1.04.01
Bandisoft MPEG-1 Decoder
Bastion
Call of Juarez - Bound in Blood
Cheat Engine 6.0
Combined Community Codec Pack 2011-07-30
CraftBukkit
Crysis® 2
D3DX10
dBpoweramp [Calculate Audio CRC] Codec
dBpoweramp [ID Tag Update] Codec
dBpoweramp Dalet Codec
dBpoweramp DSP Effects
dBpoweramp FLAC Codec
dBpoweramp m4a Codec
dBpoweramp Monkeys Audio Codec
dBpoweramp Mp2 and BwfMp2 codec
dBpoweramp mp3 (Fraunhofer IIS) Codec
dBpoweramp Music Converter
dBpoweramp Ogg Vorbis Codec
dBpoweramp Real Audio (Helix) Encoder
dBPoweramp tooLame MP2 codec
dBpoweramp Wave64 Codec
dBpoweramp WavPack Codec
Dead Rising 2: OTR
Deus Ex
Deus Ex - Human Revolution version 1.0
Dev-C++ 5 beta 9 release (4.9.9.2)
Diagnostic Utility
Drift City
Driver San Francisco
Driver San Francisco version 1.0
Dropbox
Dungeon Defenders
EasyBCD 2.0
EPU-4 Engine
eReg
Express Gate
Fable III
Flight Simulator X
Flight Simulator X Service Pack 1
FOTONICA version 1.2
Freespace 2
Freespace with Silent Threat Expansion
From Dust
Gadu-Gadu 10
Garry's Mod
gedit 2.30.1
Google Chrome
Grand Theft Auto IV
HandBrake 0.9.5
Hard Reset
High-Definition Video Playback
IrfanView (remove only)
Java Auto Updater
Java™ 6 Update 29
JDownloader 0.9
LAME v3.98.3 for Audacity
League of Legends
Left 4 Dead 2
LogMeIn Hamachi
Magic The Gathering - Duels of the Planeswalkers 2012
Malwarebytes' Anti-Malware version 1.51.2.1300
ManiaPlanet
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft Flight Simulator X
Microsoft Flight Simulator X Service Pack 1
Microsoft Flight Simulator X: Acceleration
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFCLOC_x86
Might and Magic: Clash of Heroes
Miners4k
Mozilla Firefox 5.0 (x86 en-GB)
Mp3tag v2.49
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 10 Menu TemplatePack Basic
Nero 10 Movie ThemePack Basic
Nero BackItUp 10
Nero Burning ROM 10
Nero BurnRights 10
Nero Control Center 10
Nero Core Components 10
Nero CoverDesigner 10
Nero DiscSpeed 10
Nero Dolby Files 10
Nero Express 10
Nero InfoTool 10
Nero Kwik Media
Nero Multimedia Suite 10
Nero Recode 10
Nero RescueAgent 10
Nero SoundTrax 10
Nero StartSmart 10
Nero Update
Nero Vision 10
Nero WaveEditor 10
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
Oblivion
Oblivion - Horse Armor Pack
Oblivion - Knights of the Nine
Oblivion - Mehrunes Razor
Oblivion - Orrery
Oblivion - Spell Tomes
Oblivion - Thieves Den
Oblivion - Vile Lair
Oblivion - Wizard's Tower
Octoshape add-in for Adobe Flash Player
OnLive
OpenAL
Pando Media Booster
PC Probe II
PDF Settings CS5
PowerISO
PSPad editor
PunkBuster Services
QuickTime
Realtek High Definition Audio Driver
Rock of Ages
SanDiskSecureAccess_Manager.exe
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Sentinel System Driver
Skype Toolbars
Skype™ 5.5
Sony Ericsson PC Companion 2.01.192
Sony Ericsson Update Engine
Sony Ericsson Update Service
Spotify
Steam
Steam Engine Simulator
Stronghold 3
System Requirements Lab CYRI
System Requirements Lab for Intel
Tag - IGF Professional 2008
Team Fortress 2
TeamViewer 6
Terraria
TES Construction Set
TmUnitedForever
TomTom HOME 2.8.1.2218
TomTom HOME Visual Studio Merge Modules
tools-freebsd
tools-linux
tools-netware
tools-solaris
tools-windows
tools-winPre2k
TrackMania Nations Forever
Turbo Key
Twierdza Krzy¿owiec (Warchest)
Twierdza Warchest
Ubisoft Game Launcher
Unity Web Player
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
VMware Workstation
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
WinX DVD Ripper Platinum 6.5.0
.
==== Event Viewer Messages From Past Week ========
.
23/11/2011 18:09:08, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
23/11/2011 16:02:46, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
23/11/2011 15:58:58, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TFSysMon
23/11/2011 15:58:39, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists.
23/11/2011 15:58:39, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists.
23/11/2011 15:58:39, Error: Service Control Manager [7000] - The Sentinel service failed to start due to the following error: This driver has been blocked from loading
23/11/2011 15:58:39, Error: Application Popup [1060] - \SystemRoot\SysWow64\Drivers\SENTINEL.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
22/11/2011 17:42:14, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
22/11/2011 16:13:49, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
21/11/2011 11:36:50, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware Workstation Server service to connect.
21/11/2011 11:36:50, Error: Service Control Manager [7000] - The VMware Workstation Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
19/11/2011 13:28:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
19/11/2011 13:28:51, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
19/11/2011 13:28:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
19/11/2011 13:28:48, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
19/11/2011 13:28:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
19/11/2011 13:28:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AsIO AsUpIO CBDisk discache ehdrv MDFSYSNT SCDEmu spldr TfFsMon TFSysMon VBoxDrv VBoxUSBMon vmm Wanarpv6
19/11/2011 13:02:51, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff88007f3a1d0, 0xfffff88007f3a270, 0xfffff8000210f590). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 111911-15397-01.
.
==== End Of File ===========================
Hi,
1. Download
TDSSKiller and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
2. Execute the file TDSSKiller.exe.
3. Click Start Scan. If threats are found, select
skip and click Continue (tool may prompt for a reboot).
4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)
I did forget to add that I did scan with TDSSkiller before and it did not detect anything, here's the new log
17:30:11.0232 6640 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
17:30:11.0982 6640 ============================================================
17:30:11.0982 6640 Current date / time: 2011/11/24 17:30:11.0982
17:30:11.0982 6640 SystemInfo:
17:30:11.0982 6640
17:30:11.0982 6640 OS Version: 6.1.7601 ServicePack: 1.0
17:30:11.0982 6640 Product type: Workstation
17:30:11.0982 6640 ComputerName: FILIP-PC
17:30:11.0982 6640 UserName: Filip
17:30:11.0982 6640 Windows directory: C:\Windows
17:30:11.0982 6640 System windows directory: C:\Windows
17:30:11.0982 6640 Running under WOW64
17:30:11.0982 6640 Processor architecture: Intel x64
17:30:11.0982 6640 Number of processors: 2
17:30:11.0982 6640 Page size: 0x1000
17:30:11.0982 6640 Boot type: Normal boot
17:30:11.0982 6640 ============================================================
17:30:13.0691 6640 Initialize success
17:30:24.0832 7064 ============================================================
17:30:24.0832 7064 Scan started
17:30:24.0832 7064 Mode: Manual;
17:30:24.0832 7064 ============================================================
17:30:26.0926 7064 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
17:30:26.0929 7064 1394ohci - ok
17:30:26.0985 7064 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
17:30:26.0988 7064 ACPI - ok
17:30:27.0024 7064 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
17:30:27.0025 7064 AcpiPmi - ok
17:30:27.0151 7064 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
17:30:27.0156 7064 adp94xx - ok
17:30:27.0211 7064 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
17:30:27.0215 7064 adpahci - ok
17:30:27.0237 7064 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
17:30:27.0240 7064 adpu320 - ok
17:30:27.0312 7064 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
17:30:27.0317 7064 AFD - ok
17:30:27.0355 7064 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
17:30:27.0356 7064 agp440 - ok
17:30:27.0385 7064 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
17:30:27.0385 7064 aliide - ok
17:30:27.0408 7064 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
17:30:27.0409 7064 amdide - ok
17:30:27.0430 7064 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
17:30:27.0432 7064 AmdK8 - ok
17:30:27.0441 7064 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
17:30:27.0443 7064 AmdPPM - ok
17:30:27.0476 7064 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
17:30:27.0478 7064 amdsata - ok
17:30:27.0500 7064 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
17:30:27.0503 7064 amdsbs - ok
17:30:27.0525 7064 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
17:30:27.0526 7064 amdxata - ok
17:30:27.0623 7064 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
17:30:27.0625 7064 AppID - ok
17:30:27.0666 7064 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
17:30:27.0668 7064 arc - ok
17:30:27.0681 7064 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
17:30:27.0683 7064 arcsas - ok
17:30:27.0700 7064 AsIO - ok
17:30:27.0748 7064 AsUpIO - ok
17:30:27.0766 7064 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
17:30:27.0767 7064 AsyncMac - ok
17:30:27.0806 7064 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
17:30:27.0807 7064 atapi - ok
17:30:27.0863 7064 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
17:30:27.0868 7064 b06bdrv - ok
17:30:27.0885 7064 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
17:30:27.0889 7064 b57nd60a - ok
17:30:27.0917 7064 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
17:30:27.0917 7064 Beep - ok
17:30:27.0983 7064 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
17:30:27.0984 7064 blbdrive - ok
17:30:28.0023 7064 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
17:30:28.0024 7064 bowser - ok
17:30:28.0031 7064 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:30:28.0033 7064 BrFiltLo - ok
17:30:28.0042 7064 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:30:28.0043 7064 BrFiltUp - ok
17:30:28.0055 7064 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
17:30:28.0059 7064 Brserid - ok
17:30:28.0066 7064 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
17:30:28.0067 7064 BrSerWdm - ok
17:30:28.0079 7064 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
17:30:28.0080 7064 BrUsbMdm - ok
17:30:28.0087 7064 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
17:30:28.0088 7064 BrUsbSer - ok
17:30:28.0097 7064 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
17:30:28.0099 7064 BTHMODEM - ok
17:30:28.0129 7064 CBDisk (b99d91e4cd9017f213645aa2e80eb425) C:\Windows\system32\drivers\CBDisk.sys
17:30:28.0130 7064 CBDisk - ok
17:30:28.0148 7064 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
17:30:28.0149 7064 cdfs - ok
17:30:28.0189 7064 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
17:30:28.0191 7064 cdrom - ok
17:30:28.0202 7064 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
17:30:28.0203 7064 circlass - ok
17:30:28.0240 7064 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
17:30:28.0245 7064 CLFS - ok
17:30:28.0260 7064 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
17:30:28.0261 7064 CmBatt - ok
17:30:28.0278 7064 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
17:30:28.0279 7064 cmdide - ok
17:30:28.0323 7064 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
17:30:28.0329 7064 CNG - ok
17:30:28.0370 7064 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
17:30:28.0370 7064 Compbatt - ok
17:30:28.0412 7064 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
17:30:28.0413 7064 CompositeBus - ok
17:30:28.0473 7064 cpuz135 (76355d5eafdfa3e9b7580b9153de1f30) C:\Windows\system32\drivers\cpuz135_x64.sys
17:30:28.0474 7064 cpuz135 - ok
17:30:28.0488 7064 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
17:30:28.0489 7064 crcdisk - ok
17:30:28.0570 7064 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
17:30:28.0576 7064 CSC - ok
17:30:28.0640 7064 dc3d (15c2afd86d8a58354fc100434c78b621) C:\Windows\system32\DRIVERS\dc3d.sys
17:30:28.0641 7064 dc3d - ok
17:30:28.0685 7064 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
17:30:28.0687 7064 DfsC - ok
17:30:28.0709 7064 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
17:30:28.0709 7064 discache - ok
17:30:28.0756 7064 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
17:30:28.0757 7064 Disk - ok
17:30:28.0833 7064 DKRtWrt (20c394c80113d77406df8f1adc720b01) C:\Windows\system32\DRIVERS\DKRtWrt.sys
17:30:28.0834 7064 DKRtWrt - ok
17:30:28.0882 7064 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
17:30:28.0882 7064 drmkaud - ok
17:30:28.0897 7064 dump_wmimmc - ok
17:30:28.0946 7064 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
17:30:28.0952 7064 DXGKrnl - ok
17:30:28.0990 7064 E1G60 (edc6e9c057c9d7f83eea22b4cef5dcad) C:\Windows\system32\DRIVERS\E1G6032E.sys
17:30:28.0992 7064 E1G60 - ok
17:30:29.0013 7064 EagleX64 - ok
17:30:29.0042 7064 eamon (55851f4864f8ad6e98b02307eca29db4) C:\Windows\system32\DRIVERS\eamon.sys
17:30:29.0043 7064 eamon - ok
17:30:29.0112 7064 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
17:30:29.0170 7064 ebdrv - ok
17:30:29.0244 7064 ehdrv (62c96b617ac7c4c8a9c29d57a36aa874) C:\Windows\system32\DRIVERS\ehdrv.sys
17:30:29.0245 7064 ehdrv - ok
17:30:29.0333 7064 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
17:30:29.0339 7064 elxstor - ok
17:30:29.0393 7064 epfw (9c4476159ccdef1a9b3f91dc580f1c46) C:\Windows\system32\DRIVERS\epfw.sys
17:30:29.0394 7064 epfw - ok
17:30:29.0421 7064 Epfwndis (34f666bf6387210034e4bcc5be6a3e45) C:\Windows\system32\DRIVERS\Epfwndis.sys
17:30:29.0421 7064 Epfwndis - ok
17:30:29.0455 7064 epfwwfp (bf2cb1efb98a888d6f676683cd48936f) C:\Windows\system32\DRIVERS\epfwwfp.sys
17:30:29.0456 7064 epfwwfp - ok
17:30:29.0491 7064 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
17:30:29.0492 7064 ErrDev - ok
17:30:29.0537 7064 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
17:30:29.0539 7064 exfat - ok
17:30:29.0557 7064 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
17:30:29.0560 7064 fastfat - ok
17:30:29.0591 7064 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
17:30:29.0592 7064 fdc - ok
17:30:29.0611 7064 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
17:30:29.0612 7064 FileInfo - ok
17:30:29.0632 7064 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
17:30:29.0633 7064 Filetrace - ok
17:30:29.0641 7064 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
17:30:29.0642 7064 flpydisk - ok
17:30:29.0697 7064 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
17:30:29.0700 7064 FltMgr - ok
17:30:29.0717 7064 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
17:30:29.0718 7064 FsDepends - ok
17:30:29.0731 7064 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
17:30:29.0731 7064 Fs_Rec - ok
17:30:29.0794 7064 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
17:30:29.0796 7064 fvevol - ok
17:30:29.0820 7064 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
17:30:29.0821 7064 gagp30kx - ok
17:30:29.0887 7064 ggflt (a4198f2bd8aa592cb90476277a81b5e1) C:\Windows\system32\DRIVERS\ggflt.sys
17:30:29.0888 7064 ggflt - ok
17:30:29.0923 7064 ggsemc (d266350bdaab9eb6c1aec370eeaaff3a) C:\Windows\system32\DRIVERS\ggsemc.sys
17:30:29.0924 7064 ggsemc - ok
17:30:29.0968 7064 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
17:30:29.0968 7064 hamachi - ok
17:30:30.0031 7064 hcmon (5bf776abedea06b0779c82e9d54b58d7) C:\Windows\system32\drivers\hcmon.sys
17:30:30.0031 7064 hcmon - ok
17:30:30.0048 7064 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
17:30:30.0049 7064 hcw85cir - ok
17:30:30.0111 7064 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
17:30:30.0115 7064 HdAudAddService - ok
17:30:30.0159 7064 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
17:30:30.0176 7064 HDAudBus - ok
17:30:30.0195 7064 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
17:30:30.0196 7064 HidBatt - ok
17:30:30.0210 7064 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
17:30:30.0212 7064 HidBth - ok
17:30:30.0225 7064 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
17:30:30.0226 7064 HidIr - ok
17:30:30.0245 7064 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
17:30:30.0246 7064 HidUsb - ok
17:30:30.0285 7064 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
17:30:30.0287 7064 HpSAMD - ok
17:30:30.0351 7064 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
17:30:30.0359 7064 HTTP - ok
17:30:30.0398 7064 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
17:30:30.0398 7064 hwpolicy - ok
17:30:30.0437 7064 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
17:30:30.0438 7064 i8042prt - ok
17:30:30.0463 7064 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
17:30:30.0468 7064 iaStorV - ok
17:30:30.0516 7064 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
17:30:30.0517 7064 iirsp - ok
17:30:30.0613 7064 IntcAzAudAddService (f04d22d7a49a1b2210dbadf0b803e870) C:\Windows\system32\drivers\RTKVHD64.sys
17:30:30.0625 7064 IntcAzAudAddService - ok
17:30:30.0646 7064 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
17:30:30.0646 7064 intelide - ok
17:30:30.0667 7064 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
17:30:30.0668 7064 intelppm - ok
17:30:30.0720 7064 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:30:30.0722 7064 IpFilterDriver - ok
17:30:30.0755 7064 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
17:30:30.0757 7064 IPMIDRV - ok
17:30:30.0779 7064 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
17:30:30.0781 7064 IPNAT - ok
17:30:30.0829 7064 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
17:30:30.0830 7064 IRENUM - ok
17:30:30.0862 7064 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
17:30:30.0863 7064 isapnp - ok
17:30:30.0892 7064 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
17:30:30.0895 7064 iScsiPrt - ok
17:30:30.0933 7064 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
17:30:30.0933 7064 kbdclass - ok
17:30:30.0969 7064 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
17:30:30.0970 7064 kbdhid - ok
17:30:31.0012 7064 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
17:30:31.0013 7064 KSecDD - ok
17:30:31.0050 7064 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
17:30:31.0052 7064 KSecPkg - ok
17:30:31.0070 7064 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
17:30:31.0071 7064 ksthunk - ok
17:30:31.0171 7064 LHidFilt (1074c77a47835e03c15bf92452f9a750) C:\Windows\system32\DRIVERS\LHidFilt.Sys
17:30:31.0172 7064 LHidFilt - ok
17:30:31.0223 7064 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
17:30:31.0225 7064 lltdio - ok
17:30:31.0268 7064 LMouFilt (96999c364c649e2866a268f7420a304a) C:\Windows\system32\DRIVERS\LMouFilt.Sys
17:30:31.0269 7064 LMouFilt - ok
17:30:31.0304 7064 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
17:30:31.0306 7064 LSI_FC - ok
17:30:31.0324 7064 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
17:30:31.0326 7064 LSI_SAS - ok
17:30:31.0348 7064 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:30:31.0350 7064 LSI_SAS2 - ok
17:30:31.0363 7064 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:30:31.0365 7064 LSI_SCSI - ok
17:30:31.0411 7064 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
17:30:31.0413 7064 luafv - ok
17:30:31.0492 7064 ManyCam (d33e2b74cf8b3a652bf0a9fbd068e87a) C:\Windows\system32\DRIVERS\ManyCam_x64.sys
17:30:31.0493 7064 ManyCam - ok
17:30:31.0544 7064 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\Windows\system32\drivers\mbam.sys
17:30:31.0545 7064 MBAMProtector - ok
17:30:31.0616 7064 MDFSYSNT (72040607e6e4115c154d730219bafab3) C:\Windows\system32\drivers\MDFSYSNT.sys
17:30:31.0619 7064 MDFSYSNT - ok
17:30:31.0652 7064 MDPMGRNT (f2ef49c3e47bd3fb6ee71371e7eee0af) C:\Windows\system32\DRIVERS\MDPMGRNT.SYS
17:30:31.0652 7064 MDPMGRNT - ok
17:30:31.0671 7064 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
17:30:31.0672 7064 megasas - ok
17:30:31.0695 7064 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
17:30:31.0699 7064 MegaSR - ok
17:30:31.0743 7064 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
17:30:31.0744 7064 Modem - ok
17:30:31.0775 7064 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
17:30:31.0775 7064 monitor - ok
17:30:32.0123 7064 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
17:30:32.0123 7064 mouclass - ok
17:30:32.0187 7064 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
17:30:32.0187 7064 mouhid - ok
17:30:32.0227 7064 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
17:30:32.0228 7064 mountmgr - ok
17:30:32.0267 7064 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
17:30:32.0269 7064 mpio - ok
17:30:32.0286 7064 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
17:30:32.0287 7064 mpsdrv - ok
17:30:32.0322 7064 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
17:30:32.0324 7064 MRxDAV - ok
17:30:32.0360 7064 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:30:32.0362 7064 mrxsmb - ok
17:30:32.0392 7064 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:30:32.0396 7064 mrxsmb10 - ok
17:30:32.0421 7064 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:30:32.0422 7064 mrxsmb20 - ok
17:30:32.0445 7064 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
17:30:32.0446 7064 msahci - ok
17:30:32.0467 7064 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
17:30:32.0469 7064 msdsm - ok
17:30:32.0498 7064 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
17:30:32.0499 7064 Msfs - ok
17:30:32.0518 7064 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
17:30:32.0518 7064 mshidkmdf - ok
17:30:32.0530 7064 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
17:30:32.0531 7064 msisadrv - ok
17:30:32.0570 7064 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
17:30:32.0571 7064 MSKSSRV - ok
17:30:32.0589 7064 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
17:30:32.0590 7064 MSPCLOCK - ok
17:30:32.0600 7064 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
17:30:32.0601 7064 MSPQM - ok
17:30:32.0637 7064 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
17:30:32.0641 7064 MsRPC - ok
17:30:32.0683 7064 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
17:30:32.0684 7064 mssmbios - ok
17:30:32.0701 7064 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
17:30:32.0702 7064 MSTEE - ok
17:30:32.0710 7064 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
17:30:32.0711 7064 MTConfig - ok
17:30:32.0752 7064 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
17:30:32.0753 7064 MTsensor - ok
17:30:32.0780 7064 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
17:30:32.0780 7064 Mup - ok
17:30:32.0821 7064 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
17:30:32.0825 7064 NativeWifiP - ok
17:30:32.0892 7064 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
17:30:32.0902 7064 NDIS - ok
17:30:32.0937 7064 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
17:30:32.0938 7064 NdisCap - ok
17:30:32.0975 7064 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
17:30:32.0976 7064 NdisTapi - ok
17:30:33.0024 7064 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
17:30:33.0026 7064 Ndisuio - ok
17:30:33.0066 7064 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
17:30:33.0068 7064 NdisWan - ok
17:30:33.0099 7064 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
17:30:33.0100 7064 NDProxy - ok
17:30:33.0111 7064 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
17:30:33.0112 7064 NetBIOS - ok
17:30:33.0159 7064 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
17:30:33.0162 7064 NetBT - ok
17:30:33.0232 7064 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
17:30:33.0233 7064 nfrd960 - ok
17:30:33.0271 7064 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
17:30:33.0271 7064 Npfs - ok
17:30:33.0294 7064 NPPTNT2 - ok
17:30:33.0305 7064 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
17:30:33.0305 7064 nsiproxy - ok
17:30:33.0373 7064 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
17:30:33.0406 7064 Ntfs - ok
17:30:33.0463 7064 NuidFltr (317020d31f1696334679b9d0416eb62e) C:\Windows\system32\DRIVERS\NuidFltr.sys
17:30:33.0464 7064 NuidFltr - ok
17:30:33.0486 7064 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
17:30:33.0487 7064 Null - ok
17:30:33.0724 7064 nvlddmkm (b15258b1f45f9571758ac6bb2f043b01) C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:30:33.0802 7064 nvlddmkm - ok
17:30:33.0855 7064 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
17:30:33.0858 7064 nvraid - ok
17:30:33.0878 7064 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
17:30:33.0880 7064 nvstor - ok
17:30:33.0942 7064 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
17:30:33.0944 7064 nv_agp - ok
17:30:33.0973 7064 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
17:30:33.0973 7064 ohci1394 - ok
17:30:34.0053 7064 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
17:30:34.0054 7064 Parport - ok
17:30:34.0102 7064 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
17:30:34.0103 7064 partmgr - ok
17:30:34.0134 7064 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
17:30:34.0136 7064 pci - ok
17:30:34.0162 7064 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
17:30:34.0163 7064 pciide - ok
17:30:34.0191 7064 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
17:30:34.0194 7064 pcmcia - ok
17:30:34.0223 7064 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
17:30:34.0224 7064 pcw - ok
17:30:34.0248 7064 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
17:30:34.0257 7064 PEAUTH - ok
17:30:34.0364 7064 Point64 (33328fa8a580885ab0065be6db266e9f) C:\Windows\system32\DRIVERS\point64.sys
17:30:34.0365 7064 Point64 - ok
17:30:34.0432 7064 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
17:30:34.0434 7064 PptpMiniport - ok
17:30:34.0450 7064 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
17:30:34.0451 7064 Processor - ok
17:30:34.0517 7064 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
17:30:34.0518 7064 Psched - ok
17:30:34.0567 7064 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
17:30:34.0596 7064 ql2300 - ok
17:30:34.0629 7064 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
17:30:34.0631 7064 ql40xx - ok
17:30:34.0654 7064 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
17:30:34.0655 7064 QWAVEdrv - ok
17:30:34.0683 7064 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
17:30:34.0684 7064 RasAcd - ok
17:30:34.0743 7064 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
17:30:34.0744 7064 RasAgileVpn - ok
17:30:34.0774 7064 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:30:34.0776 7064 Rasl2tp - ok
17:30:34.0824 7064 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
17:30:34.0825 7064 RasPppoe - ok
17:30:34.0864 7064 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
17:30:34.0865 7064 RasSstp - ok
17:30:34.0906 7064 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
17:30:34.0909 7064 rdbss - ok
17:30:34.0927 7064 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
17:30:34.0927 7064 rdpbus - ok
17:30:34.0939 7064 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:30:34.0939 7064 RDPCDD - ok
17:30:34.0983 7064 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
17:30:34.0986 7064 RDPDR - ok
17:30:35.0014 7064 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
17:30:35.0015 7064 RDPENCDD - ok
17:30:35.0034 7064 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
17:30:35.0035 7064 RDPREFMP - ok
17:30:35.0094 7064 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
17:30:35.0095 7064 RdpVideoMiniport - ok
17:30:35.0120 7064 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
17:30:35.0123 7064 RDPWD - ok
17:30:35.0148 7064 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
17:30:35.0151 7064 rdyboost - ok
17:30:35.0220 7064 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
17:30:35.0221 7064 rspndr - ok
17:30:35.0271 7064 RTL8167 (4fe1cef69d36e913738234303986fbb3) C:\Windows\system32\DRIVERS\Rt64win7.sys
17:30:35.0274 7064 RTL8167 - ok
17:30:35.0320 7064 RtNdPt60 (5532c4bf15173270757a75b46baeb960) C:\Windows\system32\DRIVERS\RtNdPt60.sys
17:30:35.0321 7064 RtNdPt60 - ok
17:30:35.0378 7064 RTTEAMPT (bc85bdc1c30066c78b8c67af1241d0b7) C:\Windows\system32\DRIVERS\RtTeam60.sys
17:30:35.0379 7064 RTTEAMPT - ok
17:30:35.0401 7064 RTVLANPT (8b6b42d782202363a562f82b0e13b1c0) C:\Windows\system32\DRIVERS\RtVlan60.sys
17:30:35.0402 7064 RTVLANPT - ok
17:30:35.0450 7064 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
17:30:35.0451 7064 s3cap - ok
17:30:35.0499 7064 SaiK0836 (2b44ff231cac210a32904c310fb476cd) C:\Windows\system32\DRIVERS\SaiK0836.sys
17:30:35.0501 7064 SaiK0836 - ok
17:30:35.0560 7064 SaiMini (9e7e53891d1747a01f491ab25b95135d) C:\Windows\system32\DRIVERS\SaiMini.sys
17:30:35.0560 7064 SaiMini - ok
17:30:35.0596 7064 SaiNtBus (b3b86be19a0caf025f679c39fd21e735) C:\Windows\system32\drivers\SaiBus.sys
17:30:35.0597 7064 SaiNtBus - ok
17:30:35.0648 7064 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
17:30:35.0649 7064 sbp2port - ok
17:30:35.0687 7064 SCDEmu (4dfe7adb4188f01ace51f9aa7c6a2924) C:\Windows\system32\drivers\SCDEmu.sys
17:30:35.0688 7064 SCDEmu - ok
17:30:35.0722 7064 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
17:30:35.0723 7064 scfilter - ok
17:30:35.0767 7064 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
17:30:35.0768 7064 secdrv - ok
17:30:35.0795 7064 Sentinel - ok
17:30:35.0820 7064 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
17:30:35.0821 7064 Serenum - ok
17:30:35.0834 7064 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
17:30:35.0836 7064 Serial - ok
17:30:35.0874 7064 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
17:30:35.0875 7064 sermouse - ok
17:30:35.0923 7064 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
17:30:35.0924 7064 sffdisk - ok
17:30:35.0943 7064 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
17:30:35.0944 7064 sffp_mmc - ok
17:30:35.0959 7064 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
17:30:35.0960 7064 sffp_sd - ok
17:30:35.0980 7064 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
17:30:35.0982 7064 sfloppy - ok
17:30:36.0024 7064 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:30:36.0025 7064 SiSRaid2 - ok
17:30:36.0052 7064 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
17:30:36.0053 7064 SiSRaid4 - ok
17:30:36.0068 7064 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
17:30:36.0069 7064 Smb - ok
17:30:36.0128 7064 Sntnlusb - ok
17:30:36.0164 7064 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
17:30:36.0165 7064 spldr - ok
17:30:36.0225 7064 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
17:30:36.0230 7064 srv - ok
17:30:36.0261 7064 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
17:30:36.0265 7064 srv2 - ok
17:30:36.0280 7064 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
17:30:36.0282 7064 srvnet - ok
17:30:36.0402 7064 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
17:30:36.0403 7064 stexstor - ok
17:30:36.0445 7064 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
17:30:36.0446 7064 storflt - ok
17:30:36.0469 7064 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
17:30:36.0470 7064 storvsc - ok
17:30:36.0504 7064 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
17:30:36.0505 7064 swenum - ok
17:30:36.0557 7064 Synth3dVsc - ok
17:30:36.0644 7064 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
17:30:36.0677 7064 Tcpip - ok
17:30:36.0717 7064 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
17:30:36.0729 7064 TCPIP6 - ok
17:30:36.0772 7064 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
17:30:36.0773 7064 tcpipreg - ok
17:30:36.0807 7064 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
17:30:36.0808 7064 TDPIPE - ok
17:30:36.0817 7064 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
17:30:36.0818 7064 TDTCP - ok
17:30:36.0855 7064 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
17:30:36.0858 7064 tdx - ok
17:30:36.0889 7064 TEAM (bc85bdc1c30066c78b8c67af1241d0b7) C:\Windows\system32\DRIVERS\RtTeam60.sys
17:30:36.0890 7064 TEAM - ok
17:30:36.0955 7064 teamviewervpn (f5520dbb47c60ee83024b38720abda24) C:\Windows\system32\DRIVERS\teamviewervpn.sys
17:30:36.0956 7064 teamviewervpn - ok
17:30:36.0988 7064 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
17:30:36.0989 7064 TermDD - ok
17:30:37.0030 7064 TfFsMon - ok
17:30:37.0039 7064 TfNetMon - ok
17:30:37.0061 7064 TFSysMon - ok
17:30:37.0107 7064 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:30:37.0107 7064 tssecsrv - ok
17:30:37.0170 7064 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
17:30:37.0593 7064 TsUsbFlt - ok
17:30:37.0613 7064 tsusbhub - ok
17:30:37.0837 7064 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
17:30:37.0839 7064 tunnel - ok
17:30:37.0870 7064 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
17:30:37.0872 7064 uagp35 - ok
17:30:37.0920 7064 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
17:30:37.0924 7064 udfs - ok
17:30:37.0956 7064 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
17:30:37.0958 7064 uliagpkx - ok
17:30:38.0014 7064 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
17:30:38.0015 7064 umbus - ok
17:30:38.0025 7064 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
17:30:38.0026 7064 UmPass - ok
17:30:38.0091 7064 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
17:30:38.0092 7064 usbaudio - ok
17:30:38.0105 7064 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
17:30:38.0105 7064 usbccgp - ok
17:30:38.0157 7064 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
17:30:38.0159 7064 usbcir - ok
17:30:38.0205 7064 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
17:30:38.0206 7064 usbehci - ok
17:30:38.0222 7064 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
17:30:38.0226 7064 usbhub - ok
17:30:38.0250 7064 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
17:30:38.0251 7064 usbohci - ok
17:30:38.0287 7064 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
17:30:38.0288 7064 usbprint - ok
17:30:38.0322 7064 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
17:30:38.0323 7064 usbscan - ok
17:30:38.0410 7064 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\DRIVERS\usbser.sys
17:30:38.0412 7064 usbser - ok
17:30:38.0439 7064 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:30:38.0440 7064 USBSTOR - ok
17:30:38.0482 7064 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
17:30:38.0483 7064 usbuhci - ok
17:30:38.0520 7064 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
17:30:38.0523 7064 usbvideo - ok
17:30:38.0556 7064 V0260VID (49834961fcf5480f41496ce284e2b462) C:\Windows\system32\DRIVERS\V0260Vid.sys
17:30:38.0558 7064 V0260VID - ok
17:30:38.0617 7064 VBoxDrv (f8eb6f3a0a2ddf25be87bb934eaa7e74) C:\Windows\system32\DRIVERS\VBoxDrv.sys
17:30:38.0619 7064 VBoxDrv - ok
17:30:38.0652 7064 VBoxNetAdp (776e07b4248a19decc8642a81bc189cc) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys
17:30:38.0655 7064 VBoxNetAdp - ok
17:30:38.0679 7064 VBoxNetFlt (ffc9f0c1efb3a7f9a9f46d675396c59c) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
17:30:38.0681 7064 VBoxNetFlt - ok
17:30:38.0734 7064 VBoxUSBMon (b42d50aa0904954758b89d8dec92b034) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
17:30:38.0735 7064 VBoxUSBMon - ok
17:30:38.0779 7064 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
17:30:38.0780 7064 vdrvroot - ok
17:30:38.0811 7064 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
17:30:38.0813 7064 vga - ok
17:30:38.0835 7064 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
17:30:38.0836 7064 VgaSave - ok
17:30:38.0843 7064 VGPU - ok
17:30:38.0881 7064 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
17:30:38.0884 7064 vhdmp - ok
17:30:38.0908 7064 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
17:30:38.0909 7064 viaide - ok
17:30:38.0948 7064 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
17:30:38.0951 7064 vmbus - ok
17:30:38.0975 7064 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
17:30:38.0976 7064 VMBusHID - ok
17:30:39.0029 7064 vmci (87fc1dd880e8cac4faebb84af61a87c4) C:\Windows\system32\DRIVERS\vmci.sys
17:30:39.0030 7064 vmci - ok
17:30:39.0066 7064 vmkbd (76306d9523bc16baf01f1b71e3e174a9) C:\Windows\system32\drivers\VMkbd.sys
17:30:39.0067 7064 vmkbd - ok
17:30:39.0116 7064 vmm (b2e25db5a6a178c056342abd747b7326) C:\Windows\system32\Drivers\vmm.sys
17:30:39.0118 7064 vmm - ok
17:30:39.0133 7064 VMnetAdapter (b259c31378bc855afd1b53f59311c251) C:\Windows\system32\DRIVERS\vmnetadapter.sys
17:30:39.0133 7064 VMnetAdapter - ok
17:30:39.0185 7064 VMnetBridge (dec4ce720ffeda939cf1ba315cfbd993) C:\Windows\system32\DRIVERS\vmnetbridge.sys
17:30:39.0185 7064 VMnetBridge - ok
17:30:39.0260 7064 VMnetuserif (227982e986c02b710630d7fc570caa77) C:\Windows\system32\drivers\vmnetuserif.sys
17:30:39.0261 7064 VMnetuserif - ok
17:30:39.0280 7064 VMparport (7f0bd2ce08cbe993c539d237661050b4) C:\Windows\system32\drivers\VMparport.sys
17:30:39.0281 7064 VMparport - ok
17:30:39.0333 7064 vmx86 (86aa5eae57e2eaef3b6f5c16b27e0ec4) C:\Windows\system32\drivers\vmx86.sys
17:30:39.0334 7064 vmx86 - ok
17:30:39.0366 7064 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
17:30:39.0367 7064 volmgr - ok
17:30:39.0405 7064 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
17:30:39.0409 7064 volmgrx - ok
17:30:39.0442 7064 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
17:30:39.0445 7064 volsnap - ok
17:30:39.0484 7064 VPCNetS2 (6bdca00fc57cc40da3c8e88b2cea21ab) C:\Windows\system32\DRIVERS\VMNetSrv.sys
17:30:39.0485 7064 VPCNetS2 - ok
17:30:39.0516 7064 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
17:30:39.0519 7064 vsmraid - ok
17:30:39.0544 7064 vstor2-mntapi10-shared - ok
17:30:39.0574 7064 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
17:30:39.0575 7064 vwifibus - ok
17:30:39.0602 7064 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
17:30:39.0603 7064 WacomPen - ok
17:30:39.0643 7064 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
17:30:39.0644 7064 WANARP - ok
17:30:39.0658 7064 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
17:30:39.0659 7064 Wanarpv6 - ok
17:30:39.0690 7064 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
17:30:39.0691 7064 Wd - ok
17:30:39.0714 7064 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
17:30:39.0721 7064 Wdf01000 - ok
17:30:39.0770 7064 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
17:30:39.0771 7064 WfpLwf - ok
17:30:39.0802 7064 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
17:30:39.0803 7064 WIMMount - ok
17:30:39.0896 7064 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
17:30:39.0898 7064 WinUsb - ok
17:30:39.0946 7064 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
17:30:39.0947 7064 WmiAcpi - ok
17:30:39.0993 7064 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
17:30:39.0994 7064 ws2ifsl - ok
17:30:40.0041 7064 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
17:30:40.0043 7064 WudfPf - ok
17:30:40.0060 7064 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:30:40.0062 7064 WUDFRd - ok
17:30:40.0104 7064 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
17:30:40.0109 7064 \Device\Harddisk0\DR0 - ok
17:30:40.0112 7064 Boot (0x1200) (d834e2a95c98c795ebe37d435fc59a56) \Device\Harddisk0\DR0\Partition0
17:30:40.0113 7064 \Device\Harddisk0\DR0\Partition0 - ok
17:30:40.0128 7064 Boot (0x1200) (f5aeae6e620a7b77264483ac812a49ee) \Device\Harddisk0\DR0\Partition1
17:30:40.0128 7064 \Device\Harddisk0\DR0\Partition1 - ok
17:30:40.0129 7064 ============================================================
17:30:40.0129 7064 Scan finished
17:30:40.0129 7064 ============================================================
17:30:40.0137 7052 Detected object count: 0
17:30:40.0137 7052 Actual detected object count: 0
17:30:44.0218 6624 Deinitialize success
Also, I cannot start Windows Firewall as one of the drivers seem to be missing (Windows Firewall Authorization Driver i think)
Hi
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully first.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix , link
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New dds log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
Here is the log:
ComboFix 11-11-24.01 - Filip 24/11/2011 18:10:27.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.5898 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
SP: ESET Smart Security 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\data
c:\data\cmdline.cfg
c:\programdata\l9gfqw6lai.exe
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setup.dll
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.dat
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.exe
c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.ico
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\users\Filip\AppData\Roaming\cacaoweb
c:\users\Filip\AppData\Roaming\cacaoweb\cacaoweb.exe
c:\users\Filip\AppData\Roaming\cacaoweb\npdfile.dat
c:\users\Filip\AppData\Roaming\cacaoweb\storage.db
c:\users\Filip\AppData\Roaming\chrtmp
c:\users\Filip\AppData\Roaming\Love
c:\users\Filip\AppData\Roaming\Love\not_tetris_2\highscoresA.txt
c:\users\Filip\AppData\Roaming\Love\not_tetris_2\highscoresB.txt
c:\users\Filip\AppData\Roaming\Love\not_tetris_2\options.txt
c:\users\Filip\AppData\Roaming\SQLite3.dll
c:\windows\system32\consrv.dll
c:\windows\System64
.
.
((((((((((((((((((((((((( Files Created from 2011-10-24 to 2011-11-24 )))))))))))))))))))))))))))))))
.
.
2011-11-24 18:16 . 2011-11-24 18:16 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp
2011-11-24 18:16 . 2011-11-24 18:16 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-23 16:01 . 2011-11-24 15:49 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll
2011-11-23 16:01 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll
2011-11-22 20:00 . 2011-11-22 20:00 ——– d—–w- c:\program files (x86)\Algodoo
2011-11-19 13:16 . 2011-11-19 13:16 ——– d—–w- c:\program files\ESET
2011-11-18 22:41 . 2011-11-18 22:41 ——– d—–w- c:\users\Filip\AppData\Roaming\.minecraft
2011-11-18 21:56 . 2011-11-18 22:01 ——– d—–w- c:\users\Filip\AppData\Roaming\mctechnick
2011-11-17 22:48 . 2011-11-17 22:48 ——– d—–w- c:\users\Public\Roaming
2011-11-17 22:45 . 2011-11-17 22:45 ——– d—–w- c:\users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC
2011-11-16 18:49 . 2011-11-16 18:49 ——– d—–w- c:\program files (x86)\Sol Edit
2011-11-15 18:35 . 2011-11-15 18:35 ——– d—–w- c:\programdata\ALM
2011-11-14 21:18 . 2011-11-14 21:18 ——– d—–w- c:\users\Filip\AppData\Roaming\Blender Foundation
2011-11-14 21:09 . 2011-11-15 22:22 ——– d—–w- c:\users\Filip\AppData\Roaming\inkscape
2011-11-14 20:59 . 2011-11-14 20:59 ——– d—–w- c:\users\Filip\.thumbnails
2011-11-14 20:59 . 2011-11-14 20:59 ——– d—–w- c:\program files\Blender Foundation
2011-11-14 19:33 . 2011-11-14 19:33 ——– d—–w- c:\users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-11-13 21:44 . 2011-11-13 21:44 235 —-a-w- c:\windows\SysWow64\nxEuUninstall.bat
2011-11-13 21:44 . 2011-11-13 21:44 446464 —-a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2011-11-13 21:24 . 2011-11-13 21:24 1700352 —-a-w- c:\windows\SysWow64\gdiplus.dll
2011-11-13 21:02 . 2011-11-16 16:08 ——– d—–w- C:\Nexon
2011-11-13 18:16 . 2011-11-13 18:18 ——– d—–w- c:\program files\Common Files\Adobe
2011-11-13 13:06 . 2011-11-13 13:06 ——– d—–w- c:\users\Filip\AppData\Roaming\Spam Monitor
2011-11-13 13:06 . 2011-11-13 13:06 ——– d—–w- c:\users\Filip\AppData\Roaming\PCToolsFirewallPlus
2011-11-13 12:57 . 2011-11-14 11:22 ——– d—–w- c:\program files (x86)\Common Files\PC Tools
2011-11-13 12:39 . 2011-11-13 12:39 ——– d—–w- c:\users\Filip\AppData\Roaming\pymclevel
2011-11-13 12:38 . 2011-11-13 12:38 ——– d—–w- c:\users\Filip\AppData\Local\MCEdit-64bit
2011-11-13 12:33 . 2011-11-13 21:25 ——– d—–w- c:\programdata\PC Tools
2011-11-11 22:30 . 2011-11-11 22:30 ——– d—–w- c:\users\Filip\AppData\Local\Skyrim
2011-11-11 19:45 . 2011-11-11 19:45 ——– d—–w- c:\program files\CPUID
2011-11-11 19:45 . 2010-12-27 14:36 21992 —-a-w- c:\windows\system32\drivers\cpuz135_x64.sys
2011-11-11 19:27 . 2011-11-13 21:24 ——– d—–w- c:\programdata\Comodo Downloader
2011-11-11 17:14 . 2011-11-11 17:14 ——– d—–w- c:\windows\Sun
2011-11-10 18:40 . 2011-11-10 18:40 ——– d—–w- c:\users\Filip\AppData\Local\GForce
2011-11-10 18:40 . 2011-11-10 18:40 ——– d—–w- c:\program files (x86)\ASIO4ALL v2
2011-11-10 18:39 . 2011-11-10 18:39 ——– d—–w- c:\program files (x86)\VstPlugins
2011-11-10 18:39 . 2011-11-10 18:39 ——– d—–w- c:\program files (x86)\GForce
2011-11-09 17:41 . 2011-10-01 05:45 886784 —-a-w- c:\program files\Common Files\System\wab32.dll
2011-11-09 17:41 . 2011-10-01 04:37 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll
2011-11-09 17:41 . 2011-09-29 16:29 1923952 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 17:41 . 2011-09-29 04:03 3144704 —-a-w- c:\windows\system32\win32k.sys
2011-11-07 19:50 . 2011-11-19 13:41 ——– d—–w- c:\program files (x86)\Yontoo Layers Runtime
2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- C:\Downloads
2011-11-07 19:40 . 2011-11-18 22:32 ——– d—–w- c:\users\Filip\AppData\Roaming\Free Download Manager
2011-11-06 19:13 . 2011-10-15 08:53 3074368 —-a-w- c:\windows\system32\nvsvcr.dll
2011-11-06 18:25 . 2011-11-06 18:25 ——– d—–w- c:\program files (x86)\Common Files\Java
2011-11-05 20:55 . 2008-03-05 16:03 238088 —-a-w- c:\windows\SysWow64\xactengine3_0.dll
2011-11-05 16:16 . 2011-11-05 16:29 ——– d—–w- c:\users\Filip\AppData\Roaming\Polynomial
2011-11-05 16:16 . 2011-11-05 16:16 ——– d—–w- c:\program files (x86)\The Polynomial
2011-11-04 20:18 . 2011-11-04 20:19 ——– d—–w- c:\users\Filip\AppData\Roaming\AtomZombieData
2011-11-04 20:11 . 2011-11-04 20:11 ——– d—–w- c:\users\Filip\AppData\Roaming\Voxatron
2011-11-03 18:48 . 2011-11-03 18:48 ——– d—–w- c:\users\Filip\AppData\Local\Apple Computer
2011-11-03 18:40 . 2011-11-03 18:40 ——– d—–w- c:\program files (x86)\Combined Community Codec Pack
2011-11-03 18:26 . 2011-11-03 18:26 ——– d—–w- c:\users\Filip\AppData\Roaming\Media Player Classic
2011-11-03 18:20 . 2011-11-03 18:20 ——– d—–w- c:\program files\Media Player Classic - Home Cinema
2011-11-02 17:55 . 2011-11-02 18:14 ——– d—–w- c:\users\Filip\AppData\Local\Nero
2011-10-29 09:47 . 2011-10-29 09:47 ——– d—–w- c:\users\Filip\AppData\Local\APN
2011-10-29 09:46 . 2011-10-29 09:47 ——– d—–w- c:\users\Filip\AppData\Roaming\ManyCam
2011-10-29 09:46 . 2011-10-29 09:46 ——– d—–w- c:\programdata\Ask
2011-10-28 17:33 . 2011-03-25 11:24 810496 —-a-w- c:\windows\system32\xvidcore.dll
2011-10-28 17:33 . 2011-03-25 11:24 80896 —-a-w- c:\windows\system32\ff_vfw.dll
2011-10-28 17:33 . 2011-03-25 11:24 183808 —-a-w- c:\windows\system32\xvidvfw.dll
2011-10-28 17:33 . 2011-03-11 15:06 389120 —-a-w- c:\windows\SysWow64\actskn43.ocx
2011-10-28 17:33 . 2011-03-11 15:06 389120 —-a-w- c:\windows\system32\actskn43.ocx
2011-10-26 12:36 . 2011-08-13 05:27 6144 —-a-w- c:\program files\Internet Explorer\iecompat.dll
2011-10-26 12:36 . 2011-08-13 04:18 6144 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 18:06 . 2011-05-17 16:24 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-11 19:50 . 2011-08-13 11:19 6656 —-a-w- c:\windows\system32\lpcio.dll
2011-11-09 18:25 . 2011-09-04 14:58 850152 —-a-w- c:\windows\SysWow64\SpoonUninstall.exe
2011-11-05 12:59 . 2011-05-21 13:12 466456 —-a-w- c:\windows\system32\wrap_oal.dll
2011-11-05 12:59 . 2011-05-21 13:12 444952 —-a-w- c:\windows\SysWow64\wrap_oal.dll
2011-11-05 12:59 . 2011-05-21 13:12 122904 —-a-w- c:\windows\system32\OpenAL32.dll
2011-11-05 12:59 . 2011-05-21 13:12 109080 —-a-w- c:\windows\SysWow64\OpenAL32.dll
2011-10-15 08:53 . 2011-10-08 14:06 2458432 —-a-w- c:\windows\SysWow64\nvapi.dll
2011-10-15 08:53 . 2011-10-01 10:16 837952 —-a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-10-15 08:53 . 2011-10-01 10:16 5067584 —-a-w- c:\windows\system32\nvsvc64.dll
2011-10-15 08:53 . 2011-10-01 10:16 222528 —-a-w- c:\windows\system32\nvmctray.dll
2011-10-15 08:53 . 2011-10-01 10:16 1640768 —-a-w- c:\windows\system32\nvvsvc.exe
2011-10-15 08:53 . 2011-10-01 10:16 137536 —-a-w- c:\windows\system32\nvshext.dll
2011-10-15 08:53 . 2011-10-01 10:16 10406208 —-a-w- c:\windows\system32\nvcpl.dll
2011-10-15 08:53 . 2011-10-01 10:15 2808128 —-a-w- c:\windows\system32\nvapi64.dll
2011-10-15 08:53 . 2011-10-01 10:15 15693120 —-a-w- c:\windows\system32\nvd3dumx.dll
2011-10-15 08:53 . 2011-10-01 10:15 1533248 —-a-w- c:\windows\system32\nvdispco64.dll
2011-10-15 08:53 . 2011-10-01 10:15 1454400 —-a-w- c:\windows\system32\nvgenco64.dll
2011-10-15 08:53 . 2009-07-13 21:59 8791360 —-a-w- c:\windows\system32\nvwgf2umx.dll
2011-10-15 08:53 . 2009-06-10 20:37 13205312 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2011-10-15 00:54 . 2011-10-15 00:54 321856 —-a-w- c:\windows\SysWow64\nvStreaming.exe
2011-10-05 17:43 . 2011-10-04 16:37 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-10-05 17:43 . 2011-10-02 17:45 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-10-04 20:29 . 2011-10-02 17:45 270408 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-10-04 16:38 . 2011-10-02 17:45 75136 —-a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-10-03 05:06 . 2011-04-27 17:48 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2011-10-02 12:56 . 2011-10-02 12:56 2301208 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-10-02 12:56 . 2011-10-02 12:56 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-10-02 12:56 . 2011-10-02 12:56 710976 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-10-02 12:21 . 2011-10-02 12:21 53248 —-a-w- c:\users\Filip\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-10-02 11:58 . 2011-10-02 11:58 18960 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-10-01 03:25 . 2011-10-13 15:49 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-01 02:42 . 2011-10-13 15:49 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb
2011-08-31 17:00 . 2011-10-07 20:10 25416 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 05:37 . 2011-10-13 15:48 861696 —-a-w- c:\windows\system32\oleaut32.dll
2011-08-27 05:37 . 2011-10-13 15:48 331776 —-a-w- c:\windows\system32\oleacc.dll
2011-08-27 04:26 . 2011-10-13 15:48 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll
2011-08-27 04:26 . 2011-10-13 15:48 233472 —-a-w- c:\windows\SysWow64\oleacc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-09-16 02:46 367384 —-a-w- c:\program files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-06-02 1769472]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-10-31 24241928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R2 AMService;AMService;c:\windows\TEMP\dbnwjd\setup.exe run [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 dump_wmimmc;dump_wmimmc;l:\gamescampus\DriftCity\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam_x64.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [x]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtVlan60.sys [x]
R3 SaiK0836;SaiK0836;c:\windows\system32\DRIVERS\SaiK0836.sys [x]
R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-04-20 152064]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [x]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [x]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 MDFSYSNT;MacDrive file system driver; [x]
S0 MDPMGRNT;MacDrive Partition Driver;c:\windows\system32\DRIVERS\MDPMGRNT.SYS [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 CBDisk;CBDisk;c:\windows\system32\drivers\CBDisk.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [x]
S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-14 319488]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2009-05-14 731840]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
S2 M4LIC;Mediafour M4LIC service;c:\program files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-07-29 205312]
S2 MacDrive8Service;MacDrive 8 service;c:\program files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-01-07 218112]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-15 2280312]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-21 846448]
S2 VMwareHostd;VMware Workstation Server;l:\program files (x86)\VMware Workstation\vmware-hostd.exe [2011-08-22 11837440]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [x]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1597807966-2542162096-940782561-1001Core.job
- c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-30 16:02]
.
2011-11-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1597807966-2542162096-940782561-1001UA.job
- c:\users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-30 16:02]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E11DB59D-5008-42ff-9069-535843BC0BE1}]
2011-09-16 02:46 435992 —-a-w- c:\program files\Logitech\ScrollApp\LogiSmooth.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 —-a-w- c:\users\Filip\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MacDrive 8 application"="c:\program files\Mediafour\MacDrive 8\MacDrive.exe" [2010-02-04 345688]
"Getting started with MacDrive 8"="c:\program files\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 151040]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-18 8067616]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2010-07-29 158208]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-11-19 2692520]
"combofix"="c:\combofix\CF2187.3XE" [2010-11-20 345088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
LSP: %SystemRoot%\system32\vsocklib.dll
TCP: DhcpNameServer = 192.168.1.254
.
.
——- File Associations ——-
.
txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1"
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
SafeBoot-95649713.sys
ShellIconOverlayIdentifiers-MacDrive volume icons - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-CraftBukkit - 0:\users\Filip\CraftBukkit Server\Uninstall.exe
AddRemove-dBpoweramp Dalet Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp FLAC Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp m4a Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Monkeys Audio Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Mp2 and BwfMp2 codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp mp3 (Fraunhofer IIS) Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Real Audio (Helix) Encoder - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBPoweramp tooLame MP2 codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Wave64 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp WavPack Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp [Calculate Audio CRC] Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp [ID Tag Update] Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-Dungeon Defenders_is1 - l:\program files (x86)\Trendy Entertainment\Dungeon Defenders\unins000.exe
AddRemove-Rainbow Sentinel Driver - c:\windows\SYSTEM32\RNBOSENT\SETUPX86.EXE
AddRemove-Steam App 105600 - c:\pacsteamt\steam.exe
AddRemove-Steam App 11020 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 12210 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 22230 - c:\pacsteamt\steam.exe
AddRemove-Steam App 4000 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 440 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 550 - c:\program files (x86)\Steam\steam.exe
AddRemove-UnityWebPlayer - c:\users\Filip\AppData\Local\Unity\WebPlayer\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1597807966-2542162096-940782561-1001\Software\SecuROM\License information*]
"datasecu"=hex:7f,a0,e3,1b,e4,c7,a4,67,7e,26,ec,70,c4,ea,4d,64,78,46,1a,1a,21,
25,f9,cc,2e,e0,5c,9d,35,08,0c,28,40,e7,ba,d9,cf,6e,5c,cb,7f,db,cd,4b,79,6b,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
[HKEY_USERS\S-1-5-21-1597807966-2542162096-940782561-1001_Classes\vid386vw*]
@Allowed: (Read) (RestrictedCode)
"F7289ADB-F0FA-11D3-851E-00600857F6CE"="4CDE 65C5 F954 4080 3EA4 7A9B 8CA0 A30D 8987 680E 2952 9FCC F934 9B65 4F96 E76E "
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10w.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET Smart Security\\"
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:00000000
"ProductBase"=dword:00000001
"ProductCode"="{6378ABCE-F816-4330-A7B1-FBEBCD50B746}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="4.0.437.0"
"UniqueId"="000DD2D84EC7AC71"
"ScannerBuild"=dword:00001329
"ScannerVersionId"=dword:00000feb
"ScannerVersion"="ready"
"FixId"=dword:00000009
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\vmnat.exe
l:\program files (x86)\VMware Workstation\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe
c:\program files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
.
**************************************************************************
.
Completion time: 2011-11-24 18:25:41 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-24 18:25
.
Pre-Run: 61,695,336,448 bytes free
Post-Run: 65,913,376,768 bytes free
.
- - End Of File - - 1500E7A35A2EC181BC54BA70E885172E
There is a slight problem, I can only launch applications as administrator, otherwise this error pops up
C:/pathtoapplication/example.exe
Illegal operation attempted on a registry key that has been marked for deletion
Not the worst I've seen, but if that can be fixed in any way then please offer some advice.
Here are the dds logs:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 18:38:07.22 on 24/11/2011
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.8191.6186 [GMT 0:00]
.
AV: ESET Smart Security 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET Smart Security 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
C:\ASUS.SYS\config\DVMExportService.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE
C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
L:\Program Files (x86)\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Logitech Scroll App: {e11db59d-5008-42ff-9069-535843bc0be1} - C:\Program Files\Logitech\ScrollApp\32-bit\LogiSmooth.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - Yontoo Layers
mRun: [Turbo Key] "C:\Program Files\ASUS\Turbo Key\TurboKey.exe"
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Filip\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
LSP: %SystemRoot%\system32\vsocklib.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15116/CTPID.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
BHO-X64: Logitech Scroll App: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\LogiSmooth.dll
mRun-x64: [MacDrive 8 application] "C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe"
mRun-x64: [Getting started with MacDrive 8] "C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe" /auto
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
mRun-x64: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
mRun-x64: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
mRun-x64: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 MDFSYSNT;MacDrive file system driver;C:\Windows\System32\drivers\MDFSYSNT.SYS [2010-2-4 304232]
R0 MDPMGRNT;MacDrive Partition Driver;C:\Windows\System32\drivers\MDPMGRNT.SYS [2011-4-25 32352]
R1 CBDisk;CBDisk;C:\Windows\System32\drivers\CBDisk.sys [2011-4-25 70344]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2011-4-26 90112]
R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-11-11 21992]
R2 DvmMDES;DeviceVM Meta Data Export Service;C:\ASUS.SYS\config\DVMExportService.exe [2009-10-14 319488]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-5-14 731840]
R2 epfwwfp;epfwwfp;C:\Windows\System32\drivers\epfwwfp.sys [2009-5-14 44944]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-8-15 2329480]
R2 M4LIC;Mediafour M4LIC service;C:\Program Files (x86)\Common Files\Mediafour\M4LIC.EXE [2009-7-29 205312]
R2 MacDrive8Service;MacDrive 8 service;C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe [2010-1-7 218112]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-13 366152]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-1 2253120]
R2 RtNdPt60;Realtek NDIS Protocol Driver;C:\Windows\System32\drivers\RtNdPt60.sys [2011-4-26 26624]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-4-27 2280312]
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-3-9 92592]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-21 846448]
R2 VMwareHostd;VMware Workstation Server;L:\Program Files (x86)\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440]
R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2011-9-8 44624]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-10-7 25416]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-1-21 413800]
R3 V0260VID;Live! Cam Vista IM;C:\Windows\System32\drivers\V0260Vid.sys [2011-5-8 189664]
S2 AMService;AMService;C:\Windows\TEMP\dbnwjd\setup.exe run –> C:\Windows\TEMP\dbnwjd\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\system32\srvany.exe –> C:\Windows\system32\srvany.exe [?]
S2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\System32\drivers\ggflt.sys [2011-6-5 13352]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\System32\drivers\ManyCam_x64.sys [2008-3-13 27136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-6-7 20992]
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);C:\Windows\System32\drivers\RtTeam60.sys [2011-4-26 43008]
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.0);C:\Windows\System32\drivers\RtVlan60.sys [2011-4-26 24064]
S3 SaiK0836;SaiK0836;C:\Windows\System32\drivers\SaiK0836.sys [2010-6-17 172040]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-6-5 152064]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);C:\Windows\System32\drivers\RtTeam60.sys [2011-4-26 43008]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\System32\drivers\teamviewervpn.sys [2011-4-27 35112]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-7 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-4-24 1255736]
.
=============== File Associations ===============
.
txtfile="C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
.
=============== Created Last 30 ================
.
2011-11-24 18:20:08 ——– d—–w- C:\$RECYCLE.BIN
2011-11-24 18:09:05 98816 —-a-w- C:\Windows\sed.exe
2011-11-24 18:09:05 518144 —-a-w- C:\Windows\SWREG.exe
2011-11-24 18:09:05 256000 —-a-w- C:\Windows\PEV.exe
2011-11-24 18:09:05 208896 —-a-w- C:\Windows\MBR.exe
2011-11-24 15:51:35 ——– d—–w- C:\Users\Filip\AppData\Local\{0A2968BC-4E7B-4FD7-B9D3-D03A9330DABC}
2011-11-24 15:51:10 ——– d—–w- C:\Users\Filip\AppData\Local\{E3BD6A57-093D-47F9-8EA5-4D8B9AD9A87E}
2011-11-23 16:03:07 ——– d—–w- C:\Users\Filip\AppData\Local\{6BC45846-2F67-4C15-BDD1-C5D2A2FBC217}
2011-11-23 16:01:55 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\offreg.dll
2011-11-23 16:01:53 8570192 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{14E48DAD-F420-47E7-A345-82D39BDF958B}\mpengine.dll
2011-11-22 20:00:23 ——– d—–w- C:\Program Files (x86)\Algodoo
2011-11-22 16:17:21 ——– d—–w- C:\Users\Filip\AppData\Local\{5BBBAA24-90DC-4480-B395-3D9BFB8CA64D}
2011-11-21 11:37:37 ——– d—–w- C:\Users\Filip\AppData\Local\{93B1615B-A5E3-4B30-B9B2-5D4DB12D7A28}
2011-11-21 11:37:20 ——– d—–w- C:\Users\Filip\AppData\Local\{BAFAB55A-00BE-4B8A-84F5-7907B0ECA4E4}
2011-11-20 12:12:00 ——– d—–w- C:\Users\Filip\AppData\Local\{7A24CF98-A65E-49E5-ADF6-B44547BF6966}
2011-11-20 12:11:38 ——– d—–w- C:\Users\Filip\AppData\Local\{17350408-A3DC-4C50-B653-753D232313A6}
2011-11-20 12:06:10 ——– d—–w- C:\Users\Filip\AppData\Local\{6D42D460-61A4-4437-8BAE-BF616E563E38}
2011-11-19 13:18:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\ESET
2011-11-19 13:16:48 ——– d—–w- C:\Program Files\ESET
2011-11-19 09:42:18 ——– d—–w- C:\Users\Filip\AppData\Local\{754C8F4A-1768-4214-9CE0-015947FBB78B}
2011-11-19 09:41:53 ——– d—–w- C:\Users\Filip\AppData\Local\{0EA356A3-4CF1-48A1-8CBF-39CC02C53E52}
2011-11-18 22:41:50 ——– d—–w- C:\Users\Filip\AppData\Roaming\.minecraft
2011-11-18 21:56:13 ——– d—–w- C:\Users\Filip\AppData\Roaming\mctechnick
2011-11-18 17:55:32 ——– d—–w- C:\Users\Filip\AppData\Local\{51A67855-334F-4988-8A54-7FAECA7FDC98}
2011-11-18 17:55:08 ——– d—–w- C:\Users\Filip\AppData\Local\{8E705346-414A-40F1-88BE-B68530E1DB1A}
2011-11-17 22:45:37 ——– d—–w- C:\Users\Filip\AppData\Roaming\com.adobe.DC3Module.AdobeADC
2011-11-17 20:33:13 ——– d—–w- C:\Users\Filip\AppData\Local\{FAC9AAF4-5818-4705-B8F2-F8ACECC002B5}
2011-11-17 20:33:01 ——– d—–w- C:\Users\Filip\AppData\Local\{1E3435A7-79C4-4D93-A3AD-AEF27CE372DC}
2011-11-17 16:10:46 ——– d—–w- C:\Users\Filip\AppData\Local\{CF990AF9-4577-41AB-84F6-270626A0E3E1}
2011-11-16 18:49:37 ——– d—–w- C:\Program Files (x86)\Sol Edit
2011-11-16 16:05:46 ——– d—–w- C:\Users\Filip\AppData\Local\{5C4CBAC7-3F2F-4C53-BBA0-7E1382060F78}
2011-11-16 16:05:27 ——– d—–w- C:\Users\Filip\AppData\Local\{DAE489E5-3501-40D8-88A5-257297D5757B}
2011-11-15 21:17:23 ——– d—–w- C:\Users\Filip\AppData\Local\{C0A35800-646A-447B-98A2-792B0946E6CC}
2011-11-15 21:17:11 ——– d—–w- C:\Users\Filip\AppData\Local\{18E86E3F-F2F2-4A16-A642-B9DB76A4C4E2}
2011-11-15 18:35:27 ——– d—–w- C:\PROGRA~3\ALM
2011-11-14 21:18:55 ——– d—–w- C:\Users\Filip\AppData\Roaming\Blender Foundation
2011-11-14 21:09:52 ——– d—–w- C:\Users\Filip\AppData\Roaming\inkscape
2011-11-14 20:59:48 ——– d—–w- C:\Users\Filip\.thumbnails
2011-11-14 20:59:35 ——– d—–w- C:\Program Files\Blender Foundation
2011-11-14 19:33:25 ——– d—–w- C:\Users\Filip\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-11-13 21:44:58 235 —-a-w- C:\Windows\SysWow64\nxEuUninstall.bat
2011-11-13 21:44:53 446464 —-a-w- C:\Windows\NEXON_EU_DownloaderUpdater.exe
2011-11-13 21:24:38 1700352 —-a-w- C:\Windows\SysWow64\gdiplus.dll
2011-11-13 21:02:08 ——– d—–w- C:\Nexon
2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\Spam Monitor
2011-11-13 13:06:29 ——– d—–w- C:\Users\Filip\AppData\Roaming\PCToolsFirewallPlus
2011-11-13 12:57:40 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools
2011-11-13 12:39:06 ——– d—–w- C:\Users\Filip\AppData\Roaming\pymclevel
2011-11-13 12:38:37 ——– d—–w- C:\Users\Filip\AppData\Local\MCEdit-64bit
2011-11-13 12:33:19 ——– d—–w- C:\PROGRA~3\PC Tools
2011-11-13 10:18:45 ——– d—–w- C:\Users\Filip\AppData\Local\{B5EE657B-F0BD-42FE-A8DA-35125B472AE8}
2011-11-13 10:18:30 ——– d—–w- C:\Users\Filip\AppData\Local\{449B85E7-D03A-4EB9-9F04-79FE4D84C1B0}
2011-11-12 17:37:43 ——– d—–w- C:\Users\Filip\AppData\Local\{310251F6-4F2F-4954-AF79-C65579238B1A}
2011-11-12 17:37:24 ——– d—–w- C:\Users\Filip\AppData\Local\{2227EF0A-927F-487C-9320-EE263E5C3122}
2011-11-12 13:03:21 ——– d—–w- C:\Users\Filip\AppData\Local\{891C11B5-3B35-48B6-A551-0F9651572B8F}
2011-11-11 22:30:43 ——– d—–w- C:\Users\Filip\AppData\Local\Skyrim
2011-11-11 19:45:23 21992 —-a-w- C:\Windows\System32\drivers\cpuz135_x64.sys
2011-11-11 19:45:23 ——– d—–w- C:\Program Files\CPUID
2011-11-11 19:27:10 ——– d—–w- C:\PROGRA~3\Comodo Downloader
2011-11-11 16:23:43 ——– d—–w- C:\Users\Filip\AppData\Local\{706470F3-146E-4A5D-96E8-870585A8B18F}
2011-11-11 16:23:32 ——– d—–w- C:\Users\Filip\AppData\Local\{C5CA3EEB-5573-470F-962B-B703B3F39A72}
2011-11-10 18:40:16 ——– d—–w- C:\Users\Filip\AppData\Local\GForce
2011-11-10 18:40:12 ——– d—–w- C:\Program Files (x86)\ASIO4ALL v2
2011-11-10 18:39:11 ——– d—–w- C:\Program Files (x86)\VstPlugins
2011-11-10 18:39:08 ——– d—–w- C:\Program Files (x86)\GForce
2011-11-10 16:25:13 ——– d—–w- C:\Users\Filip\AppData\Local\{528B5662-1B42-40DE-A826-127DA9D55516}
2011-11-10 16:25:02 ——– d—–w- C:\Users\Filip\AppData\Local\{AF5194A8-B56B-480E-BF0D-BE37F9EC0632}
2011-11-09 17:41:59 886784 —-a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 17:41:59 708608 —-a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 17:41:56 1923952 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 17:41:52 3144704 —-a-w- C:\Windows\System32\win32k.sys
2011-11-09 15:46:24 ——– d—–w- C:\Users\Filip\AppData\Local\{95575238-7D0A-47A5-AD6D-096B1C6C4046}
2011-11-09 15:46:11 ——– d—–w- C:\Users\Filip\AppData\Local\{639CC487-6A09-4958-8591-CCA7D3298004}
2011-11-08 17:35:57 ——– d—–w- C:\Users\Filip\AppData\Local\{8B64D692-7869-4B14-AB6D-4A15BF51DF1D}
2011-11-08 17:35:43 ——– d—–w- C:\Users\Filip\AppData\Local\{A4BADC77-D106-4CC7-A2F9-7F0A084F871B}
2011-11-07 19:50:49 ——– d—–w- C:\Program Files (x86)\Yontoo Layers Runtime
2011-11-07 19:50:04 ——– d—–w- C:\Downloads
2011-11-07 19:40:30 ——– d—–w- C:\Users\Filip\AppData\Roaming\Free Download Manager
2011-11-07 16:22:43 ——– d—–w- C:\Users\Filip\AppData\Local\{3DCBC98D-27E5-4B8D-A611-B35BE9430A9D}
2011-11-07 16:22:32 ——– d—–w- C:\Users\Filip\AppData\Local\{D40E7156-DFAF-4089-A1AD-A74C206DC980}
2011-11-06 19:13:12 3074368 —-a-w- C:\Windows\System32\nvsvcr.dll
2011-11-05 20:55:59 529424 —-a-w- C:\Windows\System32\d3dx10_37.dll
2011-11-05 16:16:15 ——– d—–w- C:\Users\Filip\AppData\Roaming\Polynomial
2011-11-05 16:16:06 ——– d—–w- C:\Program Files (x86)\The Polynomial
2011-11-05 10:40:46 ——– d—–w- C:\Users\Filip\AppData\Local\{6C5390A8-344E-4E2A-B7C7-AC06A3AB689F}
2011-11-05 10:40:33 ——– d—–w- C:\Users\Filip\AppData\Local\{A2388B35-93A8-4701-A6F5-9A1C4B83A05B}
2011-11-04 20:18:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\AtomZombieData
2011-11-04 20:11:53 ——– d—–w- C:\Users\Filip\AppData\Roaming\Voxatron
2011-11-04 18:21:14 ——– d—–w- C:\Users\Filip\AppData\Local\{A30D4DB5-D91E-4F5A-B511-12AF3135EBC6}
2011-11-04 18:21:03 ——– d—–w- C:\Users\Filip\AppData\Local\{8A0A44CF-9CBD-43D4-A7E2-E89399B60E4F}
2011-11-03 18:48:24 ——– d—–w- C:\Users\Filip\AppData\Local\Apple Computer
2011-11-03 18:40:39 ——– d—–w- C:\Program Files (x86)\Combined Community Codec Pack
2011-11-03 18:20:18 ——– d—–w- C:\Program Files\Media Player Classic - Home Cinema
2011-11-03 17:31:18 ——– d—–w- C:\Users\Filip\AppData\Local\{2FBDCE59-96F8-4B3D-BD95-B63221E308D0}
2011-11-03 17:31:05 ——– d—–w- C:\Users\Filip\AppData\Local\{6C1F5BBB-05C8-4F73-A254-2F7E45931266}
2011-11-03 08:11:07 ——– d—–w- C:\Users\Filip\AppData\Local\{65C9E9D2-262C-4EE2-B508-9823D3B12F4E}
2011-11-02 17:56:03 ——– d—–w- C:\Users\Filip\AppData\Local\Nero_AG
2011-11-02 17:55:28 ——– d—–w- C:\Users\Filip\AppData\Local\Nero
2011-11-02 17:54:19 ——– d—–w- C:\Users\Filip\AppData\Local\{473ECC4E-454E-41F5-8B6B-05A5E88D32FD}
2011-11-02 17:54:08 ——– d—–w- C:\Users\Filip\AppData\Local\{2C438F03-51E5-4AB5-B8F0-02400A9E134D}
2011-11-01 17:09:46 ——– d—–w- C:\Users\Filip\AppData\Local\{D47D465E-6BB0-4322-BE5D-8055AFFBC669}
2011-11-01 17:09:28 ——– d—–w- C:\Users\Filip\AppData\Local\{007A31D0-E416-42BD-B6AD-FFC9E101DF2F}
2011-10-31 18:06:52 ——– d—–w- C:\Users\Filip\AppData\Local\{106CC801-F100-43FA-A1D3-9C88F8462D06}
2011-10-31 18:06:29 ——– d—–w- C:\Users\Filip\AppData\Local\{284BB6A4-2BF1-4840-AD9B-B024BB34FF58}
2011-10-30 09:14:27 ——– d—–w- C:\Users\Filip\AppData\Local\{49828ABD-0040-49AE-9229-E5546FFE1E33}
2011-10-30 09:14:02 ——– d—–w- C:\Users\Filip\AppData\Local\{4C981980-300D-4C97-8F76-C4BF52901C14}
2011-10-29 17:35:56 ——– d—–w- C:\Users\Filip\AppData\Local\{73DF0A1B-FEBC-40B6-8254-763A32AC06A5}
2011-10-29 17:35:35 ——– d—–w- C:\Users\Filip\AppData\Local\{3A2FDC50-6705-4E61-BF4B-9A4629DF56DA}
2011-10-29 09:47:00 ——– d—–w- C:\Users\Filip\AppData\Local\APN
2011-10-29 09:46:44 ——– d—–w- C:\Users\Filip\AppData\Roaming\ManyCam
2011-10-29 09:46:36 ——– d—–w- C:\PROGRA~3\Ask
2011-10-29 09:36:52 ——– d—–w- C:\Users\Filip\AppData\Local\{276925AF-CF6F-4F49-AAD3-6637D70FA15E}
2011-10-28 17:33:34 810496 —-a-w- C:\Windows\System32\xvidcore.dll
2011-10-28 17:33:34 80896 —-a-w- C:\Windows\System32\ff_vfw.dll
2011-10-28 17:33:34 183808 —-a-w- C:\Windows\System32\xvidvfw.dll
2011-10-28 17:33:00 389120 —-a-w- C:\Windows\SysWow64\actskn43.ocx
2011-10-28 17:33:00 389120 —-a-w- C:\Windows\System32\actskn43.ocx
2011-10-28 10:28:10 ——– d—–w- C:\Users\Filip\AppData\Local\{864C829F-D53A-4B18-83E0-99B752BD7993}
2011-10-28 10:27:58 ——– d—–w- C:\Users\Filip\AppData\Local\{2351F912-0E2A-4175-99DA-87B0AB8A0671}
2011-10-27 08:59:16 ——– d—–w- C:\Users\Filip\AppData\Local\{7BCEF7FF-0A87-4A05-AA91-597DEC255EC6}
2011-10-27 08:58:51 ——– d—–w- C:\Users\Filip\AppData\Local\{EA6EE90D-F77D-4896-BC8C-48F3B149E1C9}
2011-10-26 12:36:20 6144 —-a-w- C:\Program Files\Internet Explorer\iecompat.dll
2011-10-26 12:36:20 6144 —-a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2011-10-26 12:26:36 ——– d—–w- C:\Users\Filip\AppData\Local\{6C2BE5E5-01B8-4D6E-85B6-12164301E01E}
2011-10-26 12:26:22 ——– d—–w- C:\Users\Filip\AppData\Local\{F43BD921-F76E-487B-9E77-8CDC92C93491}
.
==================== Find3M ====================
.
2011-11-14 18:06:57 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-11 19:50:11 6656 —-a-w- C:\Windows\System32\lpcio.dll
2011-11-09 18:25:38 850152 —-a-w- C:\Windows\SysWow64\SpoonUninstall.exe
2011-11-05 12:59:55 466456 —-a-w- C:\Windows\System32\wrap_oal.dll
2011-11-05 12:59:55 444952 —-a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-11-05 12:59:55 122904 —-a-w- C:\Windows\System32\OpenAL32.dll
2011-11-05 12:59:55 109080 —-a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-10-15 00:54:52 321856 —-a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-10-05 17:43:38 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-10-04 20:29:42 270408 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-04 16:38:17 75136 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-10-03 05:06:03 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-02 11:58:11 18960 —-a-w- C:\Windows\System32\drivers\LNonPnP.sys
2011-10-01 03:25:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:42:56 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-31 17:00:50 25416 —-a-w- C:\Windows\System32\drivers\mbam.sys
2011-08-27 05:37:49 861696 —-a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:37:48 331776 —-a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:26:27 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:26:27 233472 —-a-w- C:\Windows\SysWow64\oleacc.dll
.
============= FINISH: 18:38:29.63 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 24/04/2011 15:55:58
System Uptime: 24/11/2011 18:18:24 (0 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P5G41TD-M PRO
Processor: Intel® Core™2 Duo CPU E8400 @ 3.00GHz | LGA775 | 3003/333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 186 GiB total, 57.092 GiB free.
D: is FIXED (NTFS) - 373 GiB total, 11.063 GiB free.
E: is CDROM ()
F: is Removable
H: is Removable
I: is Removable
J: is Removable
K: is FIXED (HFSJ) - 233 GiB total, 156.503 GiB free.
L: is FIXED (NTFS) - 140 GiB total, 19.192 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VMware Virtual Ethernet Adapter for VMnet1
Device ID: ROOT\VMWARE\0000
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet1
PNP Device ID: ROOT\VMWARE\0000
Service: VMnetAdapter
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VMware Virtual Ethernet Adapter for VMnet8
Device ID: ROOT\VMWARE\0001
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet8
PNP Device ID: ROOT\VMWARE\0001
Service: VMnetAdapter
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: TeamViewer VPN Adapter
Device ID: ROOT\NET\0001
Manufacturer: TeamViewer GmbH
Name: TeamViewer VPN Adapter
PNP Device ID: ROOT\NET\0001
Service: teamviewervpn
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: VirtualBox Host-Only Ethernet Adapter
Device ID: ROOT\NET\0002
Manufacturer: Oracle Corporation
Name: VirtualBox Host-Only Ethernet Adapter
PNP Device ID: ROOT\NET\0002
Service: VBoxNetAdp
.
==== System Restore Points ===================
.
RP254: 23/11/2011 16:01:35 - Windows Update
.
==== Installed Programs ======================
.
.sol Editor 1.1.0.1
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Illustrator CS5.1
Adobe Photoshop CS5.1
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.6
Aerosoft's - Aerosoft Launcher
Algodoo v2.0.0
Apple Application Support
Apple Software Update
ASIO4ALL
Assassin's Creed Brotherhood
ASUSUpdate
Audacity 1.3.13 (Unicode)
Audiograbber 1.83 SE
Audiograbber MP3 Plugin
AutoHotkey 1.1.04.01
Bandisoft MPEG-1 Decoder
Bastion
Call of Juarez - Bound in Blood
Cheat Engine 6.0
Combined Community Codec Pack 2011-07-30
CraftBukkit
Crysis® 2
D3DX10
dBpoweramp [Calculate Audio CRC] Codec
dBpoweramp [ID Tag Update] Codec
dBpoweramp Dalet Codec
dBpoweramp DSP Effects
dBpoweramp FLAC Codec
dBpoweramp m4a Codec
dBpoweramp Monkeys Audio Codec
dBpoweramp Mp2 and BwfMp2 codec
dBpoweramp mp3 (Fraunhofer IIS) Codec
dBpoweramp Music Converter
dBpoweramp Ogg Vorbis Codec
dBpoweramp Real Audio (Helix) Encoder
dBPoweramp tooLame MP2 codec
dBpoweramp Wave64 Codec
dBpoweramp WavPack Codec
Dead Rising 2: OTR
Deus Ex
Deus Ex - Human Revolution version 1.0
Dev-C++ 5 beta 9 release (4.9.9.2)
Diagnostic Utility
Drift City
Driver San Francisco
Driver San Francisco version 1.0
Dropbox
Dungeon Defenders
EasyBCD 2.0
EPU-4 Engine
eReg
Express Gate
Fable III
Flight Simulator X
Flight Simulator X Service Pack 1
FOTONICA version 1.2
Freespace 2
Freespace with Silent Threat Expansion
From Dust
Gadu-Gadu 10
Garry's Mod
gedit 2.30.1
Google Chrome
Grand Theft Auto IV
HandBrake 0.9.5
Hard Reset
High-Definition Video Playback
IrfanView (remove only)
Java Auto Updater
Java™ 6 Update 29
JDownloader 0.9
LAME v3.98.3 for Audacity
League of Legends
Left 4 Dead 2
LogMeIn Hamachi
Magic The Gathering - Duels of the Planeswalkers 2012
Malwarebytes' Anti-Malware version 1.51.2.1300
ManiaPlanet
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft Flight Simulator X
Microsoft Flight Simulator X Service Pack 1
Microsoft Flight Simulator X: Acceleration
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFCLOC_x86
Might and Magic: Clash of Heroes
Miners4k
Mozilla Firefox 5.0 (x86 en-GB)
Mp3tag v2.49
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 10 Menu TemplatePack Basic
Nero 10 Movie ThemePack Basic
Nero BackItUp 10
Nero Burning ROM 10
Nero BurnRights 10
Nero Control Center 10
Nero Core Components 10
Nero CoverDesigner 10
Nero DiscSpeed 10
Nero Dolby Files 10
Nero Express 10
Nero InfoTool 10
Nero Kwik Media
Nero Multimedia Suite 10
Nero Recode 10
Nero RescueAgent 10
Nero SoundTrax 10
Nero StartSmart 10
Nero Update
Nero Vision 10
Nero WaveEditor 10
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
Oblivion
Oblivion - Horse Armor Pack
Oblivion - Knights of the Nine
Oblivion - Mehrunes Razor
Oblivion - Orrery
Oblivion - Spell Tomes
Oblivion - Thieves Den
Oblivion - Vile Lair
Oblivion - Wizard's Tower
Octoshape add-in for Adobe Flash Player
OnLive
OpenAL
Pando Media Booster
PC Probe II
PDF Settings CS5
PowerISO
PSPad editor
PunkBuster Services
QuickTime
Realtek High Definition Audio Driver
Rock of Ages
SanDiskSecureAccess_Manager.exe
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Sentinel System Driver
Skype Toolbars
Skype™ 5.5
Sony Ericsson PC Companion 2.01.192
Sony Ericsson Update Engine
Sony Ericsson Update Service
Spotify
Steam
Steam Engine Simulator
Stronghold 3
System Requirements Lab CYRI
System Requirements Lab for Intel
Tag - IGF Professional 2008
Team Fortress 2
TeamViewer 6
Terraria
TES Construction Set
TmUnitedForever
TomTom HOME 2.8.1.2218
TomTom HOME Visual Studio Merge Modules
tools-freebsd
tools-linux
tools-netware
tools-solaris
tools-windows
tools-winPre2k
TrackMania Nations Forever
Turbo Key
Twierdza Krzy¿owiec (Warchest)
Twierdza Warchest
Ubisoft Game Launcher
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
VMware Workstation
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
WinX DVD Ripper Platinum 6.5.0
.
==== Event Viewer Messages From Past Week ========
.
3 is not a valid Win32 application.
24/11/2011 18:19:07, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TFSysMon
24/11/2011 18:18:51, Error: Service Control Manager [7000] - The Sentinel service failed to start due to the following error: This driver has been blocked from loading
24/11/2011 18:18:51, Error: Application Popup [1060] - \SystemRoot\SysWow64\Drivers\SENTINEL.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
24/11/2011 18:17:16, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
24/11/2011 18:16:45, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Run the configured recovery program) after the unexpected termination of the VMware Workstation Server service, but this action failed with the following error:
24/11/2011 18:16:18, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
24/11/2011 18:15:44, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Run the configured recovery program.
24/11/2011 18:14:39, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
24/11/2011 18:10:26, Error: Service Control Manager [7034] - The ASUS System Control Service service terminated unexpectedly. It has done this 1 time(s).
24/11/2011 18:10:26, Error: Service Control Manager [7031] - The VMware Workstation Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
24/11/2011 18:09:55, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
24/11/2011 15:50:55, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
24/11/2011 15:47:04, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Windows Firewall Authorization Driver service which failed to start because of the following error: Cannot create a file when that file already exists.
24/11/2011 15:47:04, Error: Service Control Manager [7000] - The Windows Firewall Authorization Driver service failed to start due to the following error: Cannot create a file when that file already exists.
22/11/2011 17:42:14, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
22/11/2011 16:13:49, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
21/11/2011 11:36:50, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the VMware Workstation Server service to connect.
21/11/2011 11:36:50, Error: Service Control Manager [7000] - The VMware Workstation Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
19/11/2011 13:29:04, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
19/11/2011 13:28:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
19/11/2011 13:28:51, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
19/11/2011 13:28:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
19/11/2011 13:28:48, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
19/11/2011 13:28:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
19/11/2011 13:28:31, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AsIO AsUpIO CBDisk discache ehdrv MDFSYSNT SCDEmu spldr TfFsMon TFSysMon VBoxDrv VBoxUSBMon vmm Wanarpv6
19/11/2011 13:02:51, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff88007f3a1d0, 0xfffff88007f3a270, 0xfffff8000210f590). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 111911-15397-01.
.
==== End Of File ===========================
Sorry, seems that a reboot solved the previous issue with the apps not launching. Looks like all the problems are gone, from an intermediate user's point of view. Hosts file is back too.
Hi again,
A few more steps left to take.
Uninstall vulnerable
Flash versions by following instructions
here . Fresh version can be obtained here.
* Go
here to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scanTick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activex control to install Click Start Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked. Click Scan Wait for the scan to finish.
Post back its report & a fresh dds.txt log.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic