This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vista Infected....very slow [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer started running slower and slower. McAfee will not complete a scan without hanging up. I tried to uninstall and reinstall McAfee and it is still running slow very slow and will not complete a scan. Also, Mcafee will not allow me to pause it or cancel it. Everything seems to point to a infection. When I type in a search engine I have to pause a couple of seconds between each letter. Running both Chrome and IE. I am also getting a lot of "page not responding" when on the internet. Any help you can give will be appreciated. Thanks


ogfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:14:02 AM, on 3/16/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Motive\BellSouthBrowser.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Kascus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kascus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kascus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kascus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Kascus\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kascus\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120217112911.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [MotiveReportAgent] "C:\Program Files\Common Files\Motive\McciBootStrapper.exe" /url="-url=file://C:\Program Files\Common Files\Motive\ReportAgent.html" /browsertype=CustomMSIE /browserpath="C:\Program Files\Common Files\Motive\BellSouthBrowser.exe" /hidden
O4 - HKLM\..\Run: [RecoverFromReboot] C:\Windows\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "C:\Users\Kascus\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.3.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/instal…osticsVista.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/popca…aploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://akamaicdn.webex.com/client/WBXclien…nt/ieatgpc1.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate1c99f891ab596f0) (gupdate1c99f891ab596f0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 12954 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

I'll be back to you in a few minutes with further instructions.
HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.

I did look at your HijackThis scan and although I found one adware type item, I did not see anything to explain the symptoms you are having. Sso i definitely want to look with a scan that will give us a better look at what we might be dealing with.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt



Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Here we go- DDS text . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 18:39:11 on 2012-03-16 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3060.1264 [GMT -5:00] . AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\Motive\McciCMService.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Motive\BellSouthBrowser.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\wpcumi.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Windows\system32\mfevtps.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\Windows\system32\rundll32.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\McAfee\VirusScan\mcods.exe C:\Program Files\Windows Mail\WinMail.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Common Files\McAfee\Core\mchost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\RacAgent.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.att.net/ uWindow Title = Internet Explorer provided by Dell uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: PopKill Class: {3c060ea2-e6a9-4e49-a530-d4657b8c449a} - c:\program files\at&t\at&t internet security suite\pkR.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20120316163724.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Google Update] "c:\users\kascus\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode mRun: [MotiveReportAgent] "c:\program files\common files\motive\mccibootstrapper.exe" /url="-url=file://c:\program files\common files\motive\reportagent.html" /browsertype=custommsie /browserpath="c:\program files\common files\motive\BellSouthBrowser.exe" /hidden mRun: [RecoverFromReboot] c:\windows\temp\RecoverFromReboot.exe mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey StartupFolder: c:\users\kascus\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm LSP: c:\windows\system32\wpclsp.dll Trusted Zone: internet Trusted Zone: mcafee.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 10.0.0.1 TCP: Interfaces\{9C358407-18F2-4523-81AA-FEDF5B13F1D3} : DhcpNameServer = 10.0.0.1 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-10-15 464176] R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2012-3-16 64880] R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-3-16 165680] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-3-16 150856] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-3-16 57600] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2012-3-16 180816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2012-3-16 59456] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-3-16 338176] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-3-16 87656] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate1c99f891ab596f0;Google Update Service (gupdate1c99f891ab596f0);c:\program files\google\update\GoogleUpdate.exe [2009-3-7 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-7 133104] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-10-20 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-10-20 40552] . =============== Created Last 30 ================ . 2012-03-16 21:37:21 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-03-16 21:36:46 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-16 21:36:46 64880 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2012-03-16 21:36:46 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2012-03-16 21:36:46 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-03-16 21:36:46 338176 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-03-16 21:36:46 180816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-03-16 21:36:46 165680 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-03-16 21:36:29 ——– d—–w- c:\program files\McAfee.com 2012-03-16 21:36:29 ——– d—–w- c:\program files\common files\Mcafee 2012-03-16 21:20:35 150856 —-a-w- c:\windows\system32\mfevtps.exe.24cd.deleteme 2012-03-16 21:20:35 150856 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-16 20:45:10 ——– d—–w- c:\users\kascus\appdata\local\Citrix 2012-03-16 20:45:06 103784 —-a-w- c:\users\kascus\GoToAssistDownloadHelper.exe 2012-03-16 20:14:21 ——– d—–w- c:\users\kascus\appdata\roaming\McAfee 2012-03-16 04:16:32 ——– d—–w- c:\users\kascus\appdata\roaming\Malwarebytes 2012-03-16 04:16:13 ——– d—–w- c:\programdata\Malwarebytes 2012-03-16 02:04:51 ——– d—–w- c:\users\kascus\appdata\roaming\PCPro 2012-03-16 02:04:51 ——– d—–w- c:\users\kascus\appdata\roaming\PC Cleaners 2012-03-16 02:04:43 ——– d—–w- c:\programdata\PC1Data 2012-03-16 02:04:43 ——– d—–w- c:\program files\PC Cleaners 2012-03-16 01:36:26 ——– d—–w- c:\program files\iPod(214) 2012-03-16 01:36:20 ——– d—–w- c:\program files\iTunes(215) 2012-03-16 01:28:57 ——– d—–w- c:\program files\Bonjour(7) 2012-03-16 01:21:27 ——– d—–w- c:\program files\Apple Software Update(6) 2012-03-16 00:26:20 ——– d—–w- c:\users\kascus\appdata\roaming\QuickScan 2012-03-15 23:25:57 ——– d—–w- c:\program files\Panda Security 2012-03-14 06:15:28 2044416 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 06:15:25 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-03-14 06:15:25 1068544 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 06:15:23 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-03-14 06:15:22 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-03-14 06:15:22 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-03-14 06:15:02 613376 —-a-w- c:\windows\system32\rdpencom.dll 2012-03-14 06:15:01 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 06:14:58 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2012-02-16 03:24:58 680448 —-a-w- c:\windows\system32\msvcrt.dll . ==================== Find3M ==================== . 2012-03-14 12:53:28 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ============= FINISH: 18:44:28.71 =============== And the last one (it did not find any errors): 19:05:23.0322 1032 TDSS rootkit removing tool [removed] Mar 9 2012 17:10:43 19:05:25.0324 1032 ============================================================ 19:05:25.0324 1032 Current date / time: 2012/03/16 19:05:25.0324 19:05:25.0324 1032 SystemInfo: 19:05:25.0324 1032 19:05:25.0324 1032 OS Version: 6.0.6002 ServicePack: 2.0 19:05:25.0324 1032 Product type: Workstation 19:05:25.0324 1032 ComputerName: KASCUS-PC 19:05:25.0324 1032 UserName: Kascus 19:05:25.0324 1032 Windows directory: C:\Windows 19:05:25.0324 1032 System windows directory: C:\Windows 19:05:25.0324 1032 Processor architecture: Intel x86 19:05:25.0324 1032 Number of processors: 2 19:05:25.0324 1032 Page size: 0x1000 19:05:25.0324 1032 Boot type: Normal boot 19:05:25.0324 1032 ============================================================ 19:05:32.0374 1032 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 19:05:32.0446 1032 \Device\Harddisk0\DR0: 19:05:32.0451 1032 MBR used 19:05:32.0451 1032 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000 19:05:32.0451 1032 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x236CE2B0 19:05:32.0617 1032 Initialize success 19:05:32.0617 1032 ============================================================ 19:05:35.0920 4672 ============================================================ 19:05:35.0920 4672 Scan started 19:05:35.0920 4672 Mode: Manual; 19:05:35.0920 4672 ============================================================ 19:05:50.0050 4672 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 19:05:50.0107 4672 ACPI - ok 19:05:50.0421 4672 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 19:05:50.0491 4672 adp94xx - ok 19:05:50.0646 4672 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 19:05:50.0697 4672 adpahci - ok 19:05:50.0856 4672 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 19:05:50.0870 4672 adpu160m - ok 19:05:51.0083 4672 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 19:05:51.0097 4672 adpu320 - ok 19:05:51.0355 4672 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 19:05:51.0360 4672 AFD - ok 19:05:51.0499 4672 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 19:05:51.0501 4672 agp440 - ok 19:05:51.0599 4672 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 19:05:51.0600 4672 aic78xx - ok 19:05:51.0658 4672 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 19:05:51.0664 4672 aliide - ok 19:05:51.0701 4672 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 19:05:51.0712 4672 amdagp - ok 19:05:51.0727 4672 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 19:05:51.0729 4672 amdide - ok 19:05:51.0779 4672 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 19:05:51.0798 4672 AmdK7 - ok 19:05:51.0980 4672 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 19:05:52.0008 4672 AmdK8 - ok19:05:52.0315 4672 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 19:05:52.0328 4672 arc - ok 19:05:52.0434 4672 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 19:05:52.0453 4672 arcsas - ok 19:05:52.0572 4672 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 19:05:52.0586 4672 AsyncMac - ok 19:05:52.0698 4672 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 19:05:52.0699 4672 atapi - ok 19:05:52.0966 4672 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 19:05:52.0980 4672 Beep - ok 19:05:53.0234 4672 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 19:05:53.0257 4672 blbdrive - ok 19:05:53.0452 4672 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 19:05:53.0479 4672 bowser - ok 19:05:53.0644 4672 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 19:05:53.0651 4672 BrFiltLo - ok 19:05:53.0736 4672 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 19:05:53.0751 4672 BrFiltUp - ok 19:05:53.0890 4672 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 19:05:53.0907 4672 Brserid - ok 19:05:53.0958 4672 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 19:05:53.0970 4672 BrSerWdm - ok 19:05:54.0066 4672 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 19:05:54.0089 4672 BrUsbMdm - ok 19:05:54.0166 4672 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 19:05:54.0183 4672 BrUsbSer - ok 19:05:54.0456 4672 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys 19:05:54.0473 4672 BthEnum - ok 19:05:54.0644 4672 BTHMODEM (9a966a8e86d1771911ae34a20d11bff3) C:\Windows\system32\DRIVERS\bthmodem.sys 19:05:54.0656 4672 BTHMODEM - ok 19:05:54.0852 4672 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys 19:05:54.0883 4672 BthPan - ok 19:05:55.0171 4672 BTHPORT (611ff3f2f095c8d4a6d4cfd9dcc09793) C:\Windows\system32\Drivers\BTHport.sys 19:05:55.0229 4672 BTHPORT - ok 19:05:55.0360 4672 BTHUSB (d330803eab2a15caec7f011f1d4cb30e) C:\Windows\system32\Drivers\BTHUSB.sys 19:05:55.0370 4672 BTHUSB - ok 19:05:55.0461 4672 btwaudio (fc23e3a7ae18b02dcc1a34cbef3f80af) C:\Windows\system32\drivers\btwaudio.sys 19:05:55.0528 4672 btwaudio - ok 19:05:55.0662 4672 btwavdt (5e14c92763e51130bfb9a670afd7eddf) C:\Windows\system32\drivers\btwavdt.sys 19:05:55.0676 4672 btwavdt - ok 19:05:55.0793 4672 btwrchid (ac3fd5a3bbfa114098f75b80c4c1f3e7) C:\Windows\system32\DRIVERS\btwrchid.sys 19:05:55.0833 4672 btwrchid - ok 19:05:56.0020 4672 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\Windows\system32\drivers\BVRPMPR5.SYS 19:05:56.0030 4672 BVRPMPR5 - ok 19:05:56.0203 4672 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 19:05:56.0234 4672 cdfs - ok 19:05:56.0384 4672 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 19:05:56.0402 4672 cdrom - ok 19:05:56.0534 4672 cfwids (1dcb5209601a70e36c70fe8d197d62cb) C:\Windows\system32\drivers\cfwids.sys 19:05:56.0555 4672 cfwids - ok 19:05:56.0689 4672 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 19:05:56.0711 4672 circlass - ok 19:05:56.0873 4672 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 19:05:56.0949 4672 CLFS - ok 19:05:57.0240 4672 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 19:05:57.0246 4672 cmdide - ok 19:05:57.0283 4672 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 19:05:57.0294 4672 Compbatt - ok 19:05:57.0410 4672 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 19:05:57.0422 4672 crcdisk - ok 19:05:57.0451 4672 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 19:05:57.0453 4672 Crusoe - ok 19:05:57.0560 4672 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 19:05:57.0608 4672 DfsC - ok 19:05:57.0980 4672 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 19:05:57.0991 4672 disk - ok 19:05:58.0226 4672 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 19:05:58.0253 4672 Dot4 - ok 19:05:58.0408 4672 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 19:05:58.0420 4672 Dot4Print - ok 19:05:58.0458 4672 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 19:05:58.0473 4672 dot4usb - ok 19:05:58.0703 4672 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 19:05:58.0735 4672 drmkaud - ok 19:05:58.0979 4672 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 19:05:59.0085 4672 DXGKrnl - ok 19:05:59.0473 4672 e1express (04944f4fc4f0477185f5d26ae0ddb90e) C:\Windows\system32\DRIVERS\e1e6032.sys 19:05:59.0477 4672 e1express - ok 19:05:59.0528 4672 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 19:05:59.0545 4672 E1G60 - ok 19:06:00.0105 4672 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 19:06:00.0279 4672 Ecache - ok 19:06:00.0581 4672 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 19:06:00.0644 4672 elxstor - ok 19:06:00.0830 4672 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 19:06:00.0846 4672 ErrDev - ok 19:06:01.0019 4672 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 19:06:01.0031 4672 exfat - ok 19:06:01.0193 4672 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 19:06:01.0213 4672 fastfat - ok 19:06:01.0317 4672 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 19:06:01.0353 4672 fdc - ok 19:06:01.0579 4672 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 19:06:01.0594 4672 FileInfo - ok 19:06:01.0670 4672 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 19:06:01.0682 4672 Filetrace - ok 19:06:01.0845 4672 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 19:06:01.0847 4672 flpydisk - ok 19:06:02.0049 4672 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 19:06:02.0072 4672 FltMgr - ok 19:06:02.0504 4672 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 19:06:02.0519 4672 Fs_Rec - ok 19:06:02.0561 4672 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 19:06:02.0563 4672 gagp30kx - ok 19:06:02.0768 4672 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:06:02.0784 4672 GEARAspiWDM - ok 19:06:03.0226 4672 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 19:06:03.0335 4672 HDAudBus - ok 19:06:03.0444 4672 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 19:06:03.0449 4672 HidBth - ok 19:06:03.0578 4672 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 19:06:03.0603 4672 HidIr - ok 19:06:03.0734 4672 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 19:06:03.0755 4672 HidUsb - ok 19:06:03.0882 4672 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 19:06:03.0883 4672 HpCISSs - ok 19:06:04.0165 4672 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 19:06:04.0201 4672 HTTP - ok 19:06:04.0461 4672 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 19:06:04.0483 4672 i2omp - ok 19:06:04.0638 4672 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 19:06:04.0661 4672 i8042prt - ok 19:06:04.0918 4672 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\Windows\system32\drivers\iastor.sys 19:06:04.0957 4672 iaStor - ok 19:06:05.0171 4672 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 19:06:05.0217 4672 iaStorV - ok 19:06:06.0107 4672 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 19:06:06.0457 4672 igfx - ok 19:06:06.0807 4672 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 19:06:06.0826 4672 iirsp - ok 19:06:07.0546 4672 IntcAzAudAddService (f8f53c5449f15b23d4c61d51d2701da8) C:\Windows\system32\drivers\RTKVHDA.sys 19:06:07.0719 4672 IntcAzAudAddService - ok 19:06:07.0966 4672 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\DRIVERS\intelide.sys 19:06:07.0968 4672 intelide - ok 19:06:08.0098 4672 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 19:06:08.0099 4672 intelppm - ok 19:06:08.0269 4672 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:06:08.0279 4672 IpFilterDriver - ok 19:06:08.0351 4672 IpInIp - ok 19:06:08.0399 4672 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 19:06:08.0417 4672 IPMIDRV - ok 19:06:08.0526 4672 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 19:06:08.0543 4672 IPNAT - ok 19:06:08.0802 4672 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 19:06:08.0817 4672 IRENUM - ok 19:06:08.0903 4672 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 19:06:08.0916 4672 isapnp - ok 19:06:09.0145 4672 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 19:06:09.0149 4672 iScsiPrt - ok 19:06:09.0201 4672 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 19:06:09.0212 4672 iteatapi - ok 19:06:09.0379 4672 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 19:06:09.0400 4672 iteraid - ok 19:06:09.0552 4672 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 19:06:09.0574 4672 kbdclass - ok 19:06:09.0654 4672 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 19:06:09.0671 4672 kbdhid - ok 19:06:09.0937 4672 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys 19:06:10.0015 4672 KSecDD - ok 19:06:10.0123 4672 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 19:06:10.0152 4672 lltdio - ok 19:06:10.0229 4672 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 19:06:10.0239 4672 LSI_FC - ok 19:06:10.0272 4672 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 19:06:10.0308 4672 LSI_SAS - ok 19:06:10.0441 4672 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 19:06:10.0457 4672 LSI_SCSI - ok 19:06:10.0534 4672 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 19:06:10.0569 4672 luafv - ok 19:06:11.0085 4672 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 19:06:11.0104 4672 megasas - ok 19:06:11.0407 4672 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 19:06:11.0463 4672 MegaSR - ok 19:06:11.0613 4672 mfeapfk (36b47b1e9c537f8f2b4481084b8f7d22) C:\Windows\system32\drivers\mfeapfk.sys 19:06:11.0636 4672 mfeapfk - ok 19:06:11.0778 4672 mfeapfk01 - ok 19:06:12.0051 4672 mfeavfk (cde41293db871a75cd99eb0ce781356b) C:\Windows\system32\drivers\mfeavfk.sys 19:06:12.0090 4672 mfeavfk - ok 19:06:12.0159 4672 mfeavfk01 - ok 19:06:12.0343 4672 mfebopk (e22385f64bdf0ad81157479496e33c4a) C:\Windows\system32\drivers\mfebopk.sys 19:06:12.0389 4672 mfebopk - ok 19:06:12.0676 4672 mfefirek (215666a8a85023ef019b510cbb67f678) C:\Windows\system32\drivers\mfefirek.sys 19:06:12.0724 4672 mfefirek - ok 19:06:12.0971 4672 mfehidk (56d330981866a72f061dd16cc5004513) C:\Windows\system32\drivers\mfehidk.sys 19:06:13.0066 4672 mfehidk - ok 19:06:13.0239 4672 mfenlfk (b41bacc049cdb916a52b1448bf30d6ab) C:\Windows\system32\DRIVERS\mfenlfk.sys 19:06:13.0260 4672 mfenlfk - ok 19:06:13.0408 4672 mferkdet (89b564d63c53fc0c6782ab07eea63acf) C:\Windows\system32\drivers\mferkdet.sys 19:06:13.0443 4672 mferkdet - ok 19:06:13.0618 4672 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\Windows\system32\drivers\mferkdk.sys 19:06:13.0646 4672 mferkdk - ok 19:06:13.0852 4672 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\Windows\system32\drivers\mfesmfk.sys 19:06:13.0880 4672 mfesmfk - ok 19:06:14.0113 4672 mfewfpk (c2ff7473a60c0fb2df145ab686889653) C:\Windows\system32\drivers\mfewfpk.sys 19:06:14.0142 4672 mfewfpk - ok 19:06:14.0321 4672 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 19:06:14.0351 4672 Modem - ok 19:06:14.0496 4672 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 19:06:14.0507 4672 monitor - ok 19:06:14.0606 4672 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 19:06:14.0630 4672 mouclass - ok 19:06:14.0718 4672 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 19:06:14.0754 4672 mouhid - ok 19:06:14.0900 4672 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 19:06:14.0912 4672 MountMgr - ok 19:06:15.0045 4672 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 19:06:15.0063 4672 mpio - ok 19:06:15.0161 4672 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 19:06:15.0162 4672 mpsdrv - ok 19:06:15.0238 4672 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 19:06:15.0239 4672 Mraid35x - ok 19:06:15.0489 4672 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS 19:06:15.0527 4672 MREMP50 - ok 19:06:15.0590 4672 MREMP50a64 - ok 19:06:15.0680 4672 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS 19:06:15.0692 4672 MRESP50 - ok 19:06:15.0733 4672 MRESP50a64 - ok 19:06:16.0218 4672 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 19:06:16.0238 4672 MRxDAV - ok 19:06:16.0369 4672 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 19:06:16.0420 4672 mrxsmb - ok 19:06:16.0486 4672 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:06:16.0490 4672 mrxsmb10 - ok 19:06:16.0587 4672 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:06:16.0605 4672 mrxsmb20 - ok 19:06:16.0786 4672 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys 19:06:16.0793 4672 msahci - ok 19:06:16.0930 4672 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 19:06:16.0951 4672 msdsm - ok 19:06:17.0092 4672 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 19:06:17.0114 4672 Msfs - ok 19:06:17.0252 4672 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 19:06:17.0253 4672 msisadrv - ok 19:06:17.0478 4672 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 19:06:17.0486 4672 MSKSSRV - ok 19:06:17.0592 4672 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 19:06:17.0595 4672 MSPCLOCK - ok 19:06:17.0722 4672 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 19:06:17.0723 4672 MSPQM - ok 19:06:17.0982 4672 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 19:06:17.0985 4672 MsRPC - ok 19:06:18.0106 4672 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 19:06:18.0122 4672 mssmbios - ok 19:06:18.0258 4672 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 19:06:18.0285 4672 MSTEE - ok 19:06:18.0444 4672 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 19:06:18.0461 4672 Mup - ok 19:06:18.0642 4672 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 19:06:18.0662 4672 NativeWifiP - ok 19:06:18.0799 4672 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 19:06:18.0859 4672 NDIS - ok 19:06:18.0917 4672 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 19:06:18.0928 4672 NdisTapi - ok 19:06:19.0061 4672 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 19:06:19.0084 4672 Ndisuio - ok 19:06:19.0266 4672 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 19:06:19.0290 4672 NdisWan - ok 19:06:19.0436 4672 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 19:06:19.0474 4672 NDProxy - ok 19:06:19.0595 4672 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 19:06:19.0624 4672 NetBIOS - ok 19:06:19.0843 4672 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 19:06:19.0877 4672 netbt - ok 19:06:20.0048 4672 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 19:06:20.0062 4672 nfrd960 - ok 19:06:20.0126 4672 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 19:06:20.0174 4672 Npfs - ok 19:06:20.0304 4672 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 19:06:20.0326 4672 nsiproxy - ok 19:06:20.0776 4672 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 19:06:20.0955 4672 Ntfs - ok 19:06:21.0281 4672 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 19:06:21.0317 4672 ntrigdigi - ok 19:06:21.0380 4672 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 19:06:21.0399 4672 Null - ok 19:06:21.0521 4672 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 19:06:21.0534 4672 nvraid - ok 19:06:21.0673 4672 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 19:06:21.0684 4672 nvstor - ok 19:06:21.0818 4672 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 19:06:21.0859 4672 nv_agp - ok 19:06:22.0065 4672 NwlnkFlt - ok 19:06:22.0100 4672 NwlnkFwd - ok 19:06:22.0303 4672 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 19:06:22.0319 4672 ohci1394 - ok 19:06:22.0624 4672 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 19:06:22.0663 4672 Parport - ok 19:06:22.0828 4672 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 19:06:22.0866 4672 partmgr - ok 19:06:22.0974 4672 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 19:06:22.0981 4672 Parvdm - ok 19:06:23.0140 4672 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 19:06:23.0153 4672 pci - ok 19:06:23.0494 4672 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 19:06:23.0512 4672 pciide - ok 19:06:23.0642 4672 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 19:06:23.0660 4672 pcmcia - ok 19:06:24.0530 4672 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 19:06:24.0596 4672 PEAUTH - ok 19:06:24.0741 4672 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 19:06:24.0750 4672 PptpMiniport - ok 19:06:24.0909 4672 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 19:06:24.0924 4672 Processor - ok 19:06:25.0063 4672 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 19:06:25.0090 4672 PSched - ok 19:06:25.0226 4672 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\Windows\system32\Drivers\PxHelp20.sys 19:06:25.0253 4672 PxHelp20 - ok 19:06:25.0611 4672 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 19:06:25.0773 4672 ql2300 - ok 19:06:26.0091 4672 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 19:06:26.0102 4672 ql40xx - ok 19:06:26.0244 4672 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 19:06:26.0258 4672 QWAVEdrv - ok 19:06:26.0715 4672 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys 19:06:27.0035 4672 R300 - ok 19:06:27.0326 4672 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 19:06:27.0343 4672 RasAcd - ok 19:06:27.0503 4672 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 19:06:27.0544 4672 Rasl2tp - ok 19:06:27.0627 4672 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 19:06:27.0648 4672 RasPppoe - ok 19:06:27.0744 4672 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 19:06:27.0775 4672 RasSstp - ok 19:06:28.0120 4672 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 19:06:28.0160 4672 rdbss - ok 19:06:28.0240 4672 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 19:06:28.0262 4672 RDPCDD - ok 19:06:28.0458 4672 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 19:06:28.0494 4672 rdpdr - ok 19:06:28.0640 4672 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 19:06:28.0655 4672 RDPENCDD - ok 19:06:28.0875 4672 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys 19:06:28.0910 4672 RDPWD - ok 19:06:29.0084 4672 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys 19:06:29.0095 4672 RFCOMM - ok 19:06:29.0228 4672 RimUsb - ok 19:06:29.0387 4672 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 19:06:29.0398 4672 RimVSerPort - ok 19:06:29.0538 4672 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys 19:06:29.0565 4672 ROOTMODEM - ok 19:06:29.0739 4672 RPSKT - ok 19:06:29.0881 4672 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 19:06:29.0890 4672 rspndr - ok 19:06:30.0021 4672 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 19:06:30.0036 4672 sbp2port - ok 19:06:30.0123 4672 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 19:06:30.0142 4672 secdrv - ok 19:06:30.0283 4672 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 19:06:30.0296 4672 Serenum - ok 19:06:30.0427 4672 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 19:06:30.0444 4672 Serial - ok 19:06:30.0536 4672 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 19:06:30.0545 4672 sermouse - ok 19:06:30.0620 4672 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 19:06:30.0632 4672 sffdisk - ok 19:06:30.0745 4672 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 19:06:30.0772 4672 sffp_mmc - ok 19:06:30.0896 4672 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 19:06:30.0915 4672 sffp_sd - ok 19:06:31.0062 4672 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 19:06:31.0070 4672 sfloppy - ok 19:06:31.0130 4672 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 19:06:31.0148 4672 sisagp - ok 19:06:31.0281 4672 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 19:06:31.0302 4672 SiSRaid2 - ok 19:06:31.0376 4672 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 19:06:31.0414 4672 SiSRaid4 - ok 19:06:31.0585 4672 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 19:06:31.0602 4672 Smb - ok 19:06:31.0793 4672 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 19:06:31.0814 4672 spldr - ok 19:06:32.0166 4672 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 19:06:32.0204 4672 srv - ok 19:06:32.0306 4672 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 19:06:32.0335 4672 srv2 - ok 19:06:32.0431 4672 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 19:06:32.0473 4672 srvnet - ok 19:06:32.0516 4672 sscdbus (d5dffeaa1e15d4effabb9d9a3068ac5b) C:\Windows\system32\DRIVERS\sscdbus.sys 19:06:32.0526 4672 sscdbus - ok 19:06:32.0608 4672 sscdmdfl (8a1be0c347814f482f493aea619d57f6) C:\Windows\system32\DRIVERS\sscdmdfl.sys 19:06:32.0624 4672 sscdmdfl - ok 19:06:32.0752 4672 sscdmdm (5ab0b1987f682a59b15b78f84c6ad7d0) C:\Windows\system32\DRIVERS\sscdmdm.sys 19:06:32.0765 4672 sscdmdm - ok 19:06:32.0877 4672 sscdserd (751e66eb32efa80633b80f5d7ff0a1d8) C:\Windows\system32\DRIVERS\sscdserd.sys 19:06:32.0898 4672 sscdserd - ok 19:06:33.0052 4672 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 19:06:33.0061 4672 swenum - ok 19:06:33.0164 4672 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 19:06:33.0173 4672 Symc8xx - ok 19:06:33.0223 4672 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 19:06:33.0229 4672 Sym_hi - ok 19:06:33.0323 4672 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 19:06:33.0346 4672 Sym_u3 - ok 19:06:33.0708 4672 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 19:06:34.0053 4672 Tcpip - ok 19:06:34.0230 4672 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 19:06:34.0236 4672 Tcpip6 - ok 19:06:34.0379 4672 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 19:06:34.0393 4672 tcpipreg - ok 19:06:34.0508 4672 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 19:06:34.0530 4672 TDPIPE - ok 19:06:34.0641 4672 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 19:06:34.0652 4672 TDTCP - ok 19:06:34.0848 4672 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 19:06:34.0900 4672 tdx - ok 19:06:35.0110 4672 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 19:06:35.0119 4672 TermDD - ok 19:06:35.0252 4672 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 19:06:35.0260 4672 tssecsrv - ok 19:06:35.0373 4672 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 19:06:35.0374 4672 tunmp - ok 19:06:35.0470 4672 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 19:06:35.0481 4672 tunnel - ok 19:06:35.0646 4672 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 19:06:35.0661 4672 uagp35 - ok 19:06:35.0899 4672 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 19:06:35.0951 4672 udfs - ok 19:06:36.0052 4672 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 19:06:36.0062 4672 uliagpkx - ok 19:06:36.0127 4672 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 19:06:36.0158 4672 uliahci - ok 19:06:36.0311 4672 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 19:06:36.0333 4672 UlSata - ok 19:06:36.0417 4672 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 19:06:36.0429 4672 ulsata2 - ok 19:06:36.0518 4672 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 19:06:36.0530 4672 umbus - ok 19:06:36.0656 4672 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys 19:06:36.0657 4672 USBAAPL - ok 19:06:36.0754 4672 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 19:06:36.0767 4672 usbccgp - ok 19:06:36.0837 4672 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 19:06:36.0848 4672 usbcir - ok 19:06:37.0017 4672 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 19:06:37.0027 4672 usbehci - ok 19:06:37.0182 4672 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 19:06:37.0229 4672 usbhub - ok 19:06:37.0380 4672 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 19:06:37.0396 4672 usbohci - ok 19:06:37.0558 4672 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 19:06:37.0575 4672 usbprint - ok 19:06:37.0652 4672 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 19:06:37.0677 4672 usbscan - ok 19:06:37.0794 4672 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:06:37.0803 4672 USBSTOR - ok 19:06:37.0887 4672 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 19:06:37.0899 4672 usbuhci - ok 19:06:37.0989 4672 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 19:06:38.0002 4672 vga - ok 19:06:38.0110 4672 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 19:06:38.0112 4672 VgaSave - ok 19:06:38.0216 4672 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 19:06:38.0217 4672 viaagp - ok 19:06:38.0302 4672 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 19:06:38.0303 4672 ViaC7 - ok 19:06:38.0461 4672 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 19:06:38.0462 4672 viaide - ok 19:06:38.0597 4672 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 19:06:38.0612 4672 volmgr - ok 19:06:38.0773 4672 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 19:06:38.0815 4672 volmgrx - ok 19:06:38.0966 4672 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 19:06:39.0004 4672 volsnap - ok 19:06:39.0136 4672 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 19:06:39.0146 4672 vsmraid - ok 19:06:39.0247 4672 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 19:06:39.0249 4672 WacomPen - ok 19:06:39.0453 4672 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 19:06:39.0480 4672 Wanarp - ok 19:06:39.0519 4672 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 19:06:39.0520 4672 Wanarpv6 - ok 19:06:39.0638 4672 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 19:06:39.0646 4672 Wd - ok 19:06:39.0873 4672 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 19:06:39.0962 4672 Wdf01000 - ok 19:06:40.0152 4672 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 19:06:40.0163 4672 WmiAcpi - ok 19:06:40.0406 4672 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 19:06:40.0444 4672 WpdUsb - ok 19:06:40.0628 4672 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 19:06:40.0641 4672 ws2ifsl - ok 19:06:40.0826 4672 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 19:06:40.0859 4672 WUDFRd - ok 19:06:40.0950 4672 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0 19:06:41.0047 4672 \Device\Harddisk0\DR0 - ok 19:06:41.0077 4672 Boot (0x1200) (8764b3c3f7a393ce54b9e188dc70ecb6) \Device\Harddisk0\DR0\Partition0 19:06:41.0091 4672 \Device\Harddisk0\DR0\Partition0 - ok 19:06:41.0107 4672 Boot (0x1200) (a7cb1bef0880e15502509fd602cf507f) \Device\Harddisk0\DR0\Partition1 19:06:41.0108 4672 \Device\Harddisk0\DR0\Partition1 - ok 19:06:41.0115 4672 ============================================================ 19:06:41.0115 4672 Scan finished 19:06:41.0115 4672 ============================================================ 19:06:41.0150 4864 Detected object count: 0 19:06:41.0150 4864 Actual detected object count: 0
_Update- The Mcafee scan that has been running forever finally finished with a error message. With only 17% scanned it said it had an "unexpected error" and would need to close.
I'm not seeing any obvious signs of infection in your logs, but that certainly does not mean we don't have something going on. It just means we aren't seeing it in the logs. Different tools look in different places so I'd like to move forward with some other tools to see what we find.

One problem "could" be that your McAfee is corrupted somehow. McAfee is known for bogging down a system even in the best of situations. If it's gone a little amiss, who knows what might be going on.

Let's try booting into safe mode with networking to run our next scan, so that McAfee won't be running and see how the machine behaves when that is disabled and you can give me some feedback. (This won't narrow the problem entirely to McAfee, so please don't uninstall anything yet!)


Boot your computer in Safe Mode with Networking
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode with Networking menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode with Networking
  • Log into your usual account
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would. Note that your McAfee won't be running so please be careful and don't do any real web browsing and you won't be properly protected during this time.



I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



In your next post, can you please include the attach.txt from your original DDS scan, the Malwarebytes log, and tell me if the machine ran any faster in Safe Mode with networking than it has been in regular mode?

I'm very hopeful that the answers from these will give us some clearer direction :) Sometimes it takes patience to track these things down, but if you stick with me, I'll do my best to help you figure this out. I know how frustrating it can be when you rmachine isn't working properly. I'm sure that together we can figure this out.
Another update: My Mcafee did it scheduled scan again while I was not at home. This time it found a virus JS/Exploit-Blacolep!htm. It automatically quarantined it. Do you want me to proceed with the directions on your prior post or do we need to do something different now?
I went ahead and performed the test . The computer seems to be running faster in both modes now (safe and regular)

Here is the original Attach.txt log
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 2/25/2009 8:41:00 AM
System Uptime: 3/16/2012 4:23:10 PM (2 hours ago)
.
Motherboard: Dell Inc. | | 0FM586
Processor: Pentium® Dual-Core CPU E5200 @ 2.50GHz | Socket 775 | 2500/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 283 GiB total, 135.358 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 6.547 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
32 Bit HP CIO Components Installer
7-Zip 4.65
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.2)
AIO_Scan
Any Video Converter 3.0.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATT-PRT22
Avery Wizard 3.1
BellSouth FastAccess DSL Report Agent
Bonjour
BufferChm
Canon Digital Camera Solution Disk 40-46 Software Starter Guide
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MOV Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon Personal Printing Guide
Canon PowerShot SD1200 IS_IXUS 95 IS Camera User Guide
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities Digital Photo Professional 3.8
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities Original Data Security Tools
Canon Utilities PhotoStitch
Canon Utilities Picture Style Editor
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities WFT Utility
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
CDBurnerXP
Choice Guard
Compatibility Pack for the 2007 Office system
Copy
Coupon Printer for Windows
CustomerResearchQFolder
Dell Dock
Dell Driver Download Manager
Dell Support Center (Support Software)
DELL0604
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
EDocs
eSupportQFolder
F4100
F4100_doccd
F4100_Help
Google Chrome
Google Earth
Google Quick Search Box
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GoToAssist 8.0.0.514
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 9.0
HP Deskjet All-In-One Software 9.0
HP Driver Diagnostics
HP Imaging Device Functions 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Product Assistant
HP Smart Web Printing
HP Solution Center 9.0
HP Update
HPDiagnosticAlert
HPProductAssistant
HPSSupply
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections 12.1.11.0
iTunes
Java™ 6 Update 7
Junk Mail filter update
K-Lite Codec Pack 4.0.0 (Full)
Legacy 7.0
Legacy Charting 7.0
MarketResearch
McAfee SecurityCenter
McAfee Virtual Technician
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
OGA Notifier 2.0.0048.0
Paint.NET v3.5.10
PhotoScape
PrimoPDF
PrimoPDF – by Nitro PDF Software
PSSWCORE
QuickTime
Radialpoint Security Services
Realtek High Definition Audio Driver
RehanFX Reflection Effects for Vista
Safari
Scan
Scan2PDF 1.6
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
SolutionCenter
Spelling Dictionaries Support For Adobe Reader 9
Status
The Sims Deluxe Edition
Toolbox
TrayApp
UnloadSupport
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VideoToolkit01
WebEx
WebReg
WIDCOMM Bluetooth Software 6.0.1.4300
WildTangent Games
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
.
==== Event Viewer Messages From Past Week ========
.
3/9/2012 9:04:11 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.199 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/9/2012 8:04:05 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.196 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/9/2012 6:04:13 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.198 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/9/2012 11:26:17 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.197 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/16/2012 4:36:28 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
3/16/2012 4:36:28 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/16/2012 4:36:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/16/2012 4:25:44 PM, Error: Service Control Manager [7001] - The Windows Media Player Network Sharing Service service depends on the UPnP Device Host service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/16/2012 4:25:35 PM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
3/16/2012 4:25:11 PM, Error: Service Control Manager [7000] - The Security Services Driver (x86) service failed to start due to the following error: The system cannot find the file specified.
3/15/2012 8:54:51 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.214 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/15/2012 8:32:03 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/14/2012 7:53:54 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.209 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/14/2012 6:16:42 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.211 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/14/2012 3:00:23 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.208 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/14/2012 11:52:21 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.210 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/14/2012 10:19:43 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.213 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/13/2012 7:06:20 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.207 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/13/2012 12:27:54 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.206 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/12/2012 8:45:17 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.205 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/12/2012 2:11:15 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.204 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/11/2012 12:10:54 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.203 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/10/2012 7:54:30 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.201 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/10/2012 4:53:24 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.202 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
3/10/2012 12:13:43 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.0.0.200 for the Network Card with network address 00219B1C97C7 has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================


Here is the new MB log:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.17.06

Windows Vista Service Pack 2 x86 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Kascus :: KASCUS-PC [administrator]

3/17/2012 12:19:30 PM
mbam-log-2012-03-17 (12-19-30).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 214266
Time elapsed: 5 minute(s), 51 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
I'm glad your McAfee caught and took care of this. Java is one of the programs you want to keep up to date because it is easily exploited. From the attach.txt file, I can see yours is an older version so we do want to get that up to date. Emptying all the cache files can cause you to lose game scores and things like that but given what McAfee found there, I would recommend you do complete that step in this case.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 update 3 and Save it to your Desktop.
  • Scroll down to where it says Java SE 7
  • Click the Download JRE button to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u3-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are three options in the window to clear the cache - check them ALL
      Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. If you have any objection to doing this please omit this step
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Mcafee has no way to turn off the real time scan function that I know of I am almost positive that i did a end process on it to stop it and then started the scan. However, i noticed the icon was in the right corner at the end of the scan so I am not sure if I killed it correctly or something else happened. The scan took just under 12 hours to complete with no other use of the computer.Here are the results: C:\Users\Kascus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2JZF9QYZ\jquery-1.4.2.min[1].htm HTML/Iframe.B.Gen virus C:\Users\Kascus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4SKSM9UQ\2cdyf5h0[1].htm HTML/ScrInject.B.Gen virus C:\Users\Kascus\AppData\Local\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2568.exe Win32/OpenCandy application
It doesn't surprise me that McAfee wanted to turn itself back on. It''s doing what you want it to really - to try and protect you! While that can be troublesome when you want it to stay off for something like this, most of the time that's precisely what it should do - so we can't really get to picky about that. And actually, I've seen this scan take 12 hours or longer for some users so that doesn't surprise me either. At least it finished and we know what files we want to target for removal.

Given the item that your McAfee found previously, and what ESET just found, I would like to go ahead and run Combofix at this point to ensure that we are going make sure your machine will be as clean as possible for you, and to make removing these items as painless as possible for you. This will involve an initial run of the tool to see what it finds and removes automaticaly for us, and if it doesn't grab those 3 items ESET just found then we will remove them in a second run to grab the specific files we want to remove. After that, I think we will be just about done if all goes according to plan! You are doing a great job!

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I finally figured out how to properly disable Mcafee so that the other scanners can work. It was a hidden a little from most of the instructions I have seen before. Here is the ComboFix log: ComboFix 12-03-17.01 - Kascus 03/18/2012 13:30:52.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3060.1928 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Kascus\GoToAssistDownloadHelper.exe c:\windows\Downloaded Program Files\f3initialsetup1.0.1.3.inf c:\windows\system32\AutoRun.inf c:\windows\system32\BSTIEPrintCtl1.dll . . ((((((((((((((((((((((((( Files Created from 2012-02-18 to 2012-03-18 ))))))))))))))))))))))))))))))) . . 2012-03-18 19:07 . 2012-03-18 19:07 ——– d—–w- c:\users\Kids\AppData\Local\temp 2012-03-18 19:07 . 2012-03-18 19:07 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-03-17 21:44 . 2012-03-17 21:44 ——– d—–w- c:\program files\ESET 2012-03-17 21:28 . 2012-03-17 21:28 ——– d—–w- c:\program files\Common Files\Java 2012-03-17 21:27 . 2012-03-17 21:27 637848 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-03-17 21:27 . 2012-03-17 21:27 567696 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-17 17:03 . 2012-03-17 17:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-03-17 17:03 . 2011-12-10 20:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-16 21:37 . 2011-10-15 17:16 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-03-16 21:36 . 2011-10-15 17:16 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-16 21:36 . 2011-10-15 17:16 64880 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2012-03-16 21:36 . 2011-10-15 17:16 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2012-03-16 21:36 . 2011-10-15 17:16 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-03-16 21:36 . 2011-10-15 17:16 338176 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-03-16 21:36 . 2011-10-15 17:16 180816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-03-16 21:36 . 2011-10-15 17:16 165680 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-03-16 21:36 . 2012-03-16 21:38 ——– d—–w- c:\program files\Common Files\Mcafee 2012-03-16 21:36 . 2012-03-16 21:36 ——– d—–w- c:\program files\McAfee.com 2012-03-16 21:20 . 2011-11-18 21:36 150856 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-16 20:45 . 2012-03-16 20:45 ——– d—–w- c:\users\Kascus\AppData\Local\Citrix 2012-03-16 20:14 . 2012-03-16 20:14 ——– d—–w- c:\users\Kascus\AppData\Roaming\McAfee 2012-03-16 04:16 . 2012-03-16 04:16 ——– d—–w- c:\users\Kascus\AppData\Roaming\Malwarebytes 2012-03-16 02:04 . 2012-03-16 02:04 ——– d—–w- c:\users\Kascus\AppData\Roaming\PCPro 2012-03-16 02:04 . 2012-03-16 02:04 ——– d—–w- c:\users\Kascus\AppData\Roaming\PC Cleaners 2012-03-16 02:04 . 2012-03-16 02:04 ——– d—–w- c:\program files\PC Cleaners 2012-03-16 01:36 . 2012-03-16 04:04 ——– d—–w- c:\program files\iPod(214) 2012-03-16 01:36 . 2012-03-16 01:37 ——– d—–w- c:\program files\iTunes(215) 2012-03-16 01:28 . 2012-03-16 04:04 ——– d—–w- c:\program files\Bonjour(7) 2012-03-16 01:21 . 2012-03-16 01:21 ——– d—–w- c:\program files\Apple Software Update(6) 2012-03-16 00:26 . 2012-03-16 00:26 ——– d—–w- c:\users\Kascus\AppData\Roaming\QuickScan 2012-03-15 23:25 . 2012-03-16 04:17 ——– d—–w- c:\program files\Panda Security 2012-03-14 06:15 . 2012-02-02 15:16 2044416 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 06:15 . 2012-02-14 15:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-03-14 06:15 . 2012-02-13 13:44 1068544 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 06:15 . 2012-02-13 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-03-14 06:15 . 2012-02-14 15:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-03-14 06:15 . 2012-02-13 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-03-14 06:15 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll 2012-03-14 06:15 . 2012-01-09 13:58 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 06:14 . 2012-01-31 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-14 12:53 . 2011-05-28 11:34 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-20 02:32 . 2011-12-20 02:32 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-12-20 02:32 . 2011-12-20 02:32 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-12-20 02:32 . 2011-12-20 02:32 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-12-20 02:32 . 2011-12-20 02:32 161792 —-a-w- c:\windows\system32\msls31.dll 2011-12-20 02:32 . 2011-12-20 02:32 86528 —-a-w- c:\windows\system32\iesysprep.dll 2011-12-20 02:32 . 2011-12-20 02:32 74752 —-a-w- c:\windows\system32\iesetup.dll 2011-12-20 02:32 . 2011-12-20 02:32 63488 —-a-w- c:\windows\system32\tdc.ocx 2011-12-20 02:32 . 2011-12-20 02:32 367104 —-a-w- c:\windows\system32\html.iec 2011-12-20 02:32 . 2011-12-20 02:32 23552 —-a-w- c:\windows\system32\licmgr10.dll 2011-12-20 02:32 . 2011-12-20 02:32 152064 —-a-w- c:\windows\system32\wextract.exe 2011-12-20 02:32 . 2011-12-20 02:32 150528 —-a-w- c:\windows\system32\iexpress.exe 2011-12-20 02:32 . 2011-12-20 02:32 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-12-20 02:32 . 2011-12-20 02:32 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2011-12-20 02:32 . 2011-12-20 02:32 11776 —-a-w- c:\windows\system32\mshta.exe 2011-12-20 02:32 . 2011-12-20 02:32 101888 —-a-w- c:\windows\system32\admparse.dll 2011-12-20 02:32 . 2011-12-20 02:32 35840 —-a-w- c:\windows\system32\imgutil.dll 2011-12-20 02:32 . 2011-12-20 02:32 110592 —-a-w- c:\windows\system32\IEAdvpack.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008] "Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-07 9728] "MotiveReportAgent"="c:\program files\Common Files\Motive\McciBootStrapper.exe" [2004-06-25 204800] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152] "Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-26 122368] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656] "WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-11-22 1318816] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] . c:\users\Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-13 715568] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2009-02-25 20:58 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2012-03-18 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-04 22:50] . 2012-03-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-08 00:59] . 2012-03-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-08 00:59] . 2012-03-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2762427528-1842137411-3322480476-1000Core.job - c:\users\Kascus\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-20 17:25] . 2012-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2762427528-1842137411-3322480476-1000UA.job - c:\users\Kascus\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-20 17:25] . 2012-03-18 c:\windows\Tasks\User_Feed_Synchronization-{03190161-8CF2-4479-858A-667223EAB7EF}.job - c:\windows\system32\msfeedssync.exe [2011-12-20 02:32] . 2012-03-18 c:\windows\Tasks\User_Feed_Synchronization-{CFEA9E18-3DA6-42D1-860A-6FF9B11609D6}.job - c:\windows\system32\msfeedssync.exe [2011-12-20 02:32] . 2012-03-16 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2012-03-16 17:14] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.att.net/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: c:\windows\system32\wpclsp.dll Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 10.0.0.1 . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2012-03-18 14:10:49 ComboFix-quarantined-files.txt 2012-03-18 19:10 . Pre-Run: 148,537,712,640 bytes free Post-Run: 149,607,555,072 bytes free . - - End Of File - - 36A5144306977102DAD97DC46884A4C6
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Users\Kascus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2JZF9QYZ\jquery-1.4.2.min[1].htm
C:\Users\Kascus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4SKSM9UQ\2cdyf5h0[1].htm
C:\Users\Kascus\AppData\Local\Temp\CDBurnerXP-updates\cdbxp_setup_4.3.8.2568.exe


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Please reboot the machine after this step and let me know how the machine is running now. Are there any more malware symptoms or does everything appear to be cleared up at this point? (Make sure McAfee is re-enabled now as well you do want to be fully protected again now.)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI