This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Backdoor - possible hupigon, poisonivy [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few months ago I was notified that something was blocked. I think by malware bytes. It was a poison.ivy backdoor "thing".

After several deeper scans it all appeared clean with no positives that I could see. As of a few days ago, spyware terminator told me it had blocked a backdoor virus "hupigon.hpr". I think I've got the .hpr right.

Anyway, needless to say I panicked. I've been careful about my family using this pc for banking stuff. Nothing so far has happened but this has me worried.
A day or two ago I found another forum and started following their steps to pre-post my results and have since found you guys. I'm sticking here and did not start there as we're supposed to use just one. However, I did run the usual registry clean ups, tune-ups and even removed a programs to clear space that no one is using. So changes have been made.

I'll not change anything during this process however. I ran gmap, but it crashed and the second time it paused after about 10 hours. So here we go again!

I understand that if this thing is heavily "infiltrated" by those kinds of backdoors (and I'm readying myself to hear it's hopeless-wow, reading up about that stuff is enough to give anyone a heart attack) and can't be cleaned without reformatting, can we still use the pc if we stay offline and use another pc for internet?

I appreciate your help very much and look forward to hopefully gutting this thing! :)



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:59:38 AM, on 4/4/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Nathan\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - Global Startup: Amazon Unbox.lnk = ?
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {28B66320-9687-4B13-8757-36F901887AB5} (CanvasX Class) - http://www.seehere.com/ips-opdata/layout/f…dan-canvasx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUplden-us.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mpix.com/customer/uploading/act…geUploader5.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-us.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Remote Access Media Server (Apache2.2) - Apache Software Foundation - C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Remote Access DB (dsl-db) - Unknown owner - C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe
O23 - Service: Remote Access File Sync Service (dsl-fs-sync) - SingleClick Systems - C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12462 bytes
Hi,

Please do the following:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • If Malicious objects are found then ensure Cure is selected
    • If TDLFS File System is found then ensure Delete is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Hi CatByte - Thanks for your help, here they are:

(Also, neither rebooted and the first didn't find either of the two problems, so maybe that's why no reboot on TDSS?)




08:05:31.0364 5412 TDSS rootkit removing tool [removed] Apr 4 2012 19:52:02
08:05:31.0822 5412 ============================================================
08:05:31.0822 5412 Current date / time: 2012/04/07 08:05:31.0822
08:05:31.0822 5412 SystemInfo:
08:05:31.0822 5412
08:05:31.0822 5412 OS Version: 6.0.6002 ServicePack: 2.0
08:05:31.0822 5412 Product type: Workstation
08:05:31.0822 5412 ComputerName: BAKER
08:05:31.0823 5412 UserName: Nathan
08:05:31.0823 5412 Windows directory: C:\Windows
08:05:31.0823 5412 System windows directory: C:\Windows
08:05:31.0823 5412 Processor architecture: Intel x86
08:05:31.0823 5412 Number of processors: 2
08:05:31.0823 5412 Page size: 0x1000
08:05:31.0823 5412 Boot type: Normal boot
08:05:31.0823 5412 ============================================================
08:07:58.0616 5412 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
08:07:58.0619 5412 \Device\Harddisk0\DR0:
08:07:58.0620 5412 MBR used
08:07:58.0620 5412 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1388000
08:07:58.0620 5412 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C000, BlocksNum 0x1B929168
08:07:58.0814 5412 Initialize success
08:07:58.0814 5412 ============================================================
08:08:18.0177 5960 ============================================================
08:08:18.0177 5960 Scan started
08:08:18.0177 5960 Mode: Manual; TDLFS;
08:08:18.0177 5960 ============================================================
08:08:20.0109 5960 ACDaemon (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
08:08:20.0115 5960 ACDaemon - ok
08:08:20.0262 5960 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
08:08:20.0270 5960 ACPI - ok
08:08:20.0353 5960 AdobeActiveFileMonitor5.0 (177ff6608b48638d4066726f3a3f8444) C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
08:08:20.0359 5960 AdobeActiveFileMonitor5.0 - ok
08:08:20.0448 5960 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
08:08:20.0459 5960 adp94xx - ok
08:08:20.0505 5960 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
08:08:20.0517 5960 adpahci - ok
08:08:20.0551 5960 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
08:08:20.0559 5960 adpu160m - ok
08:08:20.0604 5960 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
08:08:20.0609 5960 adpu320 - ok
08:08:20.0722 5960 AdvancedSystemCareService5 (b11c71b29fa69e4586f9b65560e6604d) C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
08:08:20.0757 5960 AdvancedSystemCareService5 - ok
08:08:20.0927 5960 ADVService (96a0ff09e226b023dc6aca253aacee2e) C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
08:08:20.0930 5960 ADVService - ok
08:08:21.0032 5960 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll
08:08:21.0035 5960 AeLookupSvc - ok
08:08:21.0083 5960 AESTFilters (ef1142512bec12f1c2c87735da1755be) C:\Windows\system32\aestsrv.exe
08:08:21.0086 5960 AESTFilters - ok
08:08:21.0116 5960 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\Windows\system32\drivers\Afc.sys
08:08:21.0119 5960 Afc - ok
08:08:21.0153 5960 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
08:08:21.0160 5960 AFD - ok
08:08:21.0189 5960 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
08:08:21.0192 5960 agp440 - ok
08:08:21.0225 5960 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
08:08:21.0229 5960 aic78xx - ok
08:08:21.0265 5960 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe
08:08:21.0268 5960 ALG - ok
08:08:21.0291 5960 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
08:08:21.0294 5960 aliide - ok
08:08:21.0319 5960 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
08:08:21.0322 5960 amdagp - ok
08:08:21.0346 5960 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
08:08:21.0350 5960 amdide - ok
08:08:21.0376 5960 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
08:08:21.0380 5960 AmdK7 - ok
08:08:21.0406 5960 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
08:08:21.0410 5960 AmdK8 - ok
08:08:21.0552 5960 Apache2.2 (ea504a3e708a37cda81d214d09b8a62f) C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
08:08:21.0558 5960 Apache2.2 - ok
08:08:21.0632 5960 ApfiltrService (a80230bd04f0b8bf05185b369bb1cbb8) C:\Windows\system32\DRIVERS\Apfiltr.sys
08:08:21.0638 5960 ApfiltrService - ok
08:08:21.0683 5960 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll
08:08:21.0686 5960 Appinfo - ok
08:08:21.0866 5960 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
08:08:21.0871 5960 Apple Mobile Device - ok
08:08:21.0936 5960 appliand (05eda44c080ebaf758f8a318488ffd75) C:\Windows\system32\DRIVERS\appliand.sys
08:08:21.0939 5960 appliand - ok
08:08:21.0943 5960 appliandMP (05eda44c080ebaf758f8a318488ffd75) C:\Windows\system32\DRIVERS\appliand.sys
08:08:21.0944 5960 appliandMP - ok
08:08:21.0995 5960 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
08:08:22.0000 5960 arc - ok
08:08:22.0026 5960 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
08:08:22.0030 5960 arcsas - ok
08:08:22.0070 5960 aswFsBlk (0ae43c6c411254049279c2ee55630f95) C:\Windows\system32\drivers\aswFsBlk.sys
08:08:22.0073 5960 aswFsBlk - ok
08:08:22.0097 5960 aswMonFlt (6693141560b1615d8dccf0d8eb00087e) C:\Windows\system32\drivers\aswMonFlt.sys
08:08:22.0100 5960 aswMonFlt - ok
08:08:22.0125 5960 aswRdr (da12626fd9a67f4e917e2f2fbe1e1764) C:\Windows\system32\drivers\aswRdr.sys
08:08:22.0128 5960 aswRdr - ok
08:08:22.0177 5960 aswSnx (dcb199b967375753b5019ec15f008f53) C:\Windows\system32\drivers\aswSnx.sys
08:08:22.0200 5960 aswSnx - ok
08:08:22.0245 5960 aswSP (b32873e5a1443c0a1e322266e203bf10) C:\Windows\system32\drivers\aswSP.sys
08:08:22.0252 5960 aswSP - ok
08:08:22.0276 5960 aswTdi (6ff544175a9180c5d88534d3d9c9a9f7) C:\Windows\system32\drivers\aswTdi.sys
08:08:22.0279 5960 aswTdi - ok
08:08:22.0314 5960 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
08:08:22.0317 5960 AsyncMac - ok
08:08:22.0359 5960 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
08:08:22.0361 5960 atapi - ok
08:08:22.0404 5960 atksgt (72bc628af75c4c3250f2a3bac260265a) C:\Windows\system32\DRIVERS\atksgt.sys
08:08:22.0410 5960 atksgt - ok
08:08:22.0450 5960 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
08:08:22.0454 5960 AudioEndpointBuilder - ok
08:08:22.0472 5960 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll
08:08:22.0477 5960 Audiosrv - ok
08:08:22.0552 5960 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
08:08:22.0555 5960 avast! Antivirus - ok
08:08:22.0629 5960 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
08:08:22.0633 5960 Beep - ok
08:08:22.0690 5960 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll
08:08:22.0695 5960 BFE - ok
08:08:22.0914 5960 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll
08:08:22.0959 5960 BITS - ok
08:08:23.0004 5960 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
08:08:23.0008 5960 blbdrive - ok
08:08:23.0085 5960 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
08:08:23.0088 5960 Bonjour Service - ok
08:08:23.0143 5960 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
08:08:23.0148 5960 bowser - ok
08:08:23.0196 5960 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
08:08:23.0198 5960 BrFiltLo - ok
08:08:23.0229 5960 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
08:08:23.0232 5960 BrFiltUp - ok
08:08:23.0281 5960 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll
08:08:23.0283 5960 Browser - ok
08:08:23.0314 5960 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
08:08:23.0317 5960 Brserid - ok
08:08:23.0337 5960 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
08:08:23.0340 5960 BrSerWdm - ok
08:08:23.0360 5960 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
08:08:23.0363 5960 BrUsbMdm - ok
08:08:23.0388 5960 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
08:08:23.0392 5960 BrUsbSer - ok
08:08:23.0429 5960 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
08:08:23.0432 5960 BTHMODEM - ok
08:08:23.0465 5960 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
08:08:23.0469 5960 cdfs - ok
08:08:23.0512 5960 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
08:08:23.0516 5960 cdrom - ok
08:08:23.0555 5960 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
08:08:23.0558 5960 CertPropSvc - ok
08:08:23.0597 5960 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
08:08:23.0600 5960 circlass - ok
08:08:23.0640 5960 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
08:08:23.0645 5960 CLFS - ok
08:08:23.0722 5960 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:08:23.0732 5960 clr_optimization_v2.0.50727_32 - ok
08:08:23.0974 5960 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:08:24.0020 5960 clr_optimization_v4.0.30319_32 - ok
08:08:24.0110 5960 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
08:08:24.0113 5960 CmBatt - ok
08:08:24.0168 5960 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
08:08:24.0176 5960 cmdide - ok
08:08:24.0205 5960 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
08:08:24.0209 5960 Compbatt - ok
08:08:24.0223 5960 COMSysApp - ok
08:08:24.0257 5960 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
08:08:24.0261 5960 crcdisk - ok
08:08:24.0319 5960 Creative Labs Licensing Service (0c629820aad9c90e456b221c94d640ca) C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
08:08:24.0322 5960 Creative Labs Licensing Service - ok
08:08:24.0386 5960 Creative Service for CDROM Access (3c8b6609712f4ff78e521f6dcfc4032b) C:\Windows\system32\CTsvcCDA.exe
08:08:24.0389 5960 Creative Service for CDROM Access - ok
08:08:24.0433 5960 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
08:08:24.0436 5960 Crusoe - ok
08:08:24.0477 5960 CryptSvc (fb27772beaf8e1d28ccd825c09da939b) C:\Windows\system32\cryptsvc.dll
08:08:24.0482 5960 CryptSvc - ok
08:08:24.0541 5960 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
08:08:24.0550 5960 DcomLaunch - ok
08:08:24.0596 5960 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
08:08:24.0602 5960 DfsC - ok
08:08:24.0706 5960 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe
08:08:24.0771 5960 DFSR - ok
08:08:24.0869 5960 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll
08:08:24.0873 5960 Dhcp - ok
08:08:24.0966 5960 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
08:08:24.0970 5960 disk - ok
08:08:25.0006 5960 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll
08:08:25.0011 5960 Dnscache - ok
08:08:25.0119 5960 DockLoginService (db29915209770d8b59654345ec2d943a) C:\Program Files\Dell\DellDock\DockLogin.exe
08:08:25.0123 5960 DockLoginService - ok
08:08:25.0246 5960 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll
08:08:25.0254 5960 dot3svc - ok
08:08:25.0420 5960 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys
08:08:25.0426 5960 Dot4 - ok
08:08:25.0515 5960 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys
08:08:25.0521 5960 Dot4Print - ok
08:08:25.0628 5960 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys
08:08:25.0639 5960 dot4usb - ok
08:08:25.0689 5960 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll
08:08:25.0693 5960 DPS - ok
08:08:25.0728 5960 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
08:08:25.0731 5960 drmkaud - ok
08:08:25.0768 5960 DrmRAudio (9c5f2493f502f95f49423085e699960e) C:\Windows\system32\drivers\DrmRAudio.sys
08:08:25.0771 5960 DrmRAudio - ok
08:08:25.0804 5960 DrmRVideo (a3145644169153b0344ebe5214e07f77) C:\Windows\system32\DRIVERS\DrmRVideo.sys
08:08:25.0806 5960 DrmRVideo - ok
08:08:26.0300 5960 dsl-db (0bb913f9f02677bd4ae96d4967cacfee) C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe
08:08:26.0455 5960 dsl-db - ok
08:08:26.0526 5960 dsl-fs-sync (d2b7d4bc4445c4ebe79d9d4308d54c42) C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe
08:08:26.0534 5960 dsl-fs-sync - ok
08:08:26.0652 5960 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
08:08:26.0679 5960 DXGKrnl - ok
08:08:26.0743 5960 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys
08:08:26.0749 5960 e1express - ok
08:08:26.0791 5960 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
08:08:26.0795 5960 E1G60 - ok
08:08:26.0834 5960 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll
08:08:26.0838 5960 EapHost - ok
08:08:26.0879 5960 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
08:08:26.0884 5960 Ecache - ok
08:08:27.0017 5960 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe
08:08:27.0024 5960 ehRecvr - ok
08:08:27.0049 5960 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe
08:08:27.0053 5960 ehSched - ok
08:08:27.0161 5960 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll
08:08:27.0163 5960 ehstart - ok
08:08:27.0218 5960 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
08:08:27.0228 5960 elxstor - ok
08:08:27.0292 5960 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll
08:08:27.0301 5960 EMDMgmt - ok
08:08:27.0398 5960 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
08:08:27.0402 5960 ErrDev - ok
08:08:27.0545 5960 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll
08:08:27.0552 5960 EventSystem - ok
08:08:27.0627 5960 EvtEng (e71b03ff6b819ae1a286aa27e956d523) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
08:08:27.0637 5960 EvtEng - ok
08:08:27.0722 5960 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
08:08:27.0726 5960 exfat - ok
08:08:27.0742 5960 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
08:08:27.0746 5960 fastfat - ok
08:08:27.0795 5960 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
08:08:27.0797 5960 fdc - ok
08:08:27.0831 5960 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll
08:08:27.0833 5960 fdPHost - ok
08:08:27.0850 5960 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll
08:08:27.0853 5960 FDResPub - ok
08:08:27.0876 5960 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
08:08:27.0879 5960 FileInfo - ok
08:08:28.0017 5960 FileMonitor (47b91551fe7489a323baf4904cad757a) C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys
08:08:28.0021 5960 FileMonitor - ok
08:08:28.0112 5960 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
08:08:28.0115 5960 Filetrace - ok
08:08:28.0157 5960 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
08:08:28.0161 5960 flpydisk - ok
08:08:28.0213 5960 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
08:08:28.0219 5960 FltMgr - ok
08:08:28.0277 5960 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll
08:08:28.0311 5960 FontCache - ok
08:08:28.0377 5960 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
08:08:28.0381 5960 FontCache3.0.0.0 - ok
08:08:28.0420 5960 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
08:08:28.0424 5960 Fs_Rec - ok
08:08:28.0462 5960 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
08:08:28.0466 5960 gagp30kx - ok
08:08:28.0514 5960 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:08:28.0518 5960 GEARAspiWDM - ok
08:08:28.0570 5960 giveio (77ebf3e9386daa51551af429052d88d0) C:\Windows\system32\giveio.sys
08:08:28.0576 5960 giveio - ok
08:08:28.0631 5960 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
08:08:28.0636 5960 GoToAssist - ok
08:08:28.0693 5960 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll
08:08:28.0721 5960 gpsvc - ok
08:08:28.0812 5960 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
08:08:28.0823 5960 HDAudBus - ok
08:08:28.0859 5960 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
08:08:28.0862 5960 HidBth - ok
08:08:28.0885 5960 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
08:08:28.0888 5960 HidIr - ok
08:08:28.0999 5960 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll
08:08:29.0004 5960 hidserv - ok
08:08:29.0042 5960 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
08:08:29.0045 5960 HidUsb - ok
08:08:29.0081 5960 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll
08:08:29.0087 5960 hkmsvc - ok
08:08:29.0220 5960 hnmsvc (11accb0d76e0fe109624224b6713893c) c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
08:08:29.0245 5960 hnmsvc - ok
08:08:29.0334 5960 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
08:08:29.0338 5960 HpCISSs - ok
08:08:29.0420 5960 HSF_DPV (99f85640054ba65190b860d878a7c9ae) C:\Windows\system32\DRIVERS\HSX_DPV.sys
08:08:29.0455 5960 HSF_DPV - ok
08:08:29.0501 5960 HSXHWAZL (cfbc2b81972e298f0e19ee68fa9e73da) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
08:08:29.0507 5960 HSXHWAZL - ok
08:08:29.0576 5960 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
08:08:29.0584 5960 HTTP - ok
08:08:29.0637 5960 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
08:08:29.0640 5960 i2omp - ok
08:08:29.0664 5960 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
08:08:29.0668 5960 i8042prt - ok
08:08:29.0764 5960 IAANTMON (ae38a12f79a4980ddb88f36514f8a1da) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
08:08:29.0771 5960 IAANTMON - ok
08:08:29.0824 5960 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\Windows\system32\drivers\iastor.sys
08:08:29.0828 5960 iaStor - ok
08:08:29.0873 5960 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
08:08:29.0887 5960 iaStorV - ok
08:08:29.0975 5960 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
08:08:29.0981 5960 IDriverT - ok
08:08:30.0072 5960 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
08:08:30.0098 5960 idsvc - ok
08:08:30.0186 5960 igfx (c134e69ce901422d1f2d7ea8d69098fe) C:\Windows\system32\DRIVERS\igdkmd32.sys
08:08:30.0243 5960 igfx - ok
08:08:30.0289 5960 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
08:08:30.0292 5960 iirsp - ok
08:08:30.0340 5960 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll
08:08:30.0351 5960 IKEEXT - ok
08:08:30.0455 5960 IMFservice (8ae99ebe30e8338907361018d9030835) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
08:08:30.0463 5960 IMFservice - ok
08:08:30.0532 5960 IntcHdmiAddService (98d303ccb3415e9202e82043b37d66dc) C:\Windows\system32\drivers\IntcHdmi.sys
08:08:30.0536 5960 IntcHdmiAddService - ok
08:08:30.0574 5960 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\DRIVERS\intelide.sys
08:08:30.0578 5960 intelide - ok
08:08:30.0611 5960 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
08:08:30.0616 5960 intelppm - ok
08:08:30.0656 5960 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll
08:08:30.0663 5960 IPBusEnum - ok
08:08:30.0707 5960 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:08:30.0752 5960 IpFilterDriver - ok
08:08:30.0797 5960 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll
08:08:30.0807 5960 iphlpsvc - ok
08:08:30.0823 5960 IpInIp - ok
08:08:30.0853 5960 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
08:08:30.0857 5960 IPMIDRV - ok
08:08:30.0886 5960 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
08:08:30.0891 5960 IPNAT - ok
08:08:30.0940 5960 iPod Service (b84a28b3984185eda8867541af14cddb) C:\Program Files\iPod\bin\iPodService.exe
08:08:30.0947 5960 iPod Service - ok
08:08:30.0969 5960 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
08:08:30.0972 5960 IRENUM - ok
08:08:31.0002 5960 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
08:08:31.0006 5960 isapnp - ok
08:08:31.0057 5960 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
08:08:31.0062 5960 iScsiPrt - ok
08:08:31.0093 5960 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
08:08:31.0097 5960 iteatapi - ok
08:08:31.0126 5960 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
08:08:31.0130 5960 iteraid - ok
08:08:31.0165 5960 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
08:08:31.0168 5960 kbdclass - ok
08:08:31.0193 5960 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
08:08:31.0196 5960 kbdhid - ok
08:08:31.0230 5960 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
08:08:31.0235 5960 KeyIso - ok
08:08:31.0291 5960 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys
08:08:31.0300 5960 KSecDD - ok
08:08:31.0447 5960 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll
08:08:31.0458 5960 KtmRm - ok
08:08:31.0529 5960 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll
08:08:31.0539 5960 LanmanServer - ok
08:08:31.0663 5960 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll
08:08:31.0678 5960 LanmanWorkstation - ok
08:08:31.0755 5960 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\Windows\system32\DRIVERS\lirsgt.sys
08:08:31.0759 5960 lirsgt - ok
08:08:31.0802 5960 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
08:08:31.0808 5960 lltdio - ok
08:08:31.0851 5960 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll
08:08:31.0861 5960 lltdsvc - ok
08:08:31.0898 5960 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll
08:08:31.0905 5960 lmhosts - ok
08:08:31.0950 5960 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
08:08:31.0957 5960 LSI_FC - ok
08:08:31.0995 5960 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
08:08:32.0008 5960 LSI_SAS - ok
08:08:32.0040 5960 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
08:08:32.0045 5960 LSI_SCSI - ok
08:08:32.0075 5960 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
08:08:32.0080 5960 luafv - ok
08:08:32.0125 5960 mbamchameleon (96c57f15a2b2015aa88d62a3e9daebc8) C:\Windows\system32\drivers\mbamchameleon.sys
08:08:32.0129 5960 mbamchameleon - ok
08:08:32.0173 5960 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys
08:08:32.0177 5960 MBAMProtector - ok
08:08:32.0258 5960 MBAMService (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
08:08:32.0268 5960 MBAMService - ok
08:08:32.0371 5960 MCSTRM - ok
08:08:32.0508 5960 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll
08:08:32.0515 5960 Mcx2Svc - ok
08:08:32.0549 5960 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
08:08:32.0552 5960 mdmxsdk - ok
08:08:32.0596 5960 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
08:08:32.0599 5960 megasas - ok
08:08:32.0639 5960 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
08:08:32.0661 5960 MegaSR - ok
08:08:32.0785 5960 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
08:08:32.0792 5960 MMCSS - ok
08:08:32.0839 5960 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
08:08:32.0843 5960 Modem - ok
08:08:32.0881 5960 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
08:08:32.0885 5960 monitor - ok
08:08:32.0916 5960 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
08:08:32.0920 5960 mouclass - ok
08:08:32.0947 5960 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
08:08:32.0950 5960 mouhid - ok
08:08:32.0983 5960 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
08:08:32.0987 5960 MountMgr - ok
08:08:33.0021 5960 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
08:08:33.0026 5960 mpio - ok
08:08:33.0061 5960 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
08:08:33.0066 5960 mpsdrv - ok
08:08:33.0160 5960 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll
08:08:33.0170 5960 MpsSvc - ok
08:08:33.0209 5960 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
08:08:33.0213 5960 Mraid35x - ok
08:08:33.0262 5960 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
08:08:33.0267 5960 MRxDAV - ok
08:08:33.0310 5960 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:08:33.0315 5960 mrxsmb - ok
08:08:33.0365 5960 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:08:33.0371 5960 mrxsmb10 - ok
08:08:33.0390 5960 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:08:33.0393 5960 mrxsmb20 - ok
08:08:33.0432 5960 msahci (f70590424eefbf5c27a40c67afdb8383) C:\Windows\system32\drivers\msahci.sys
08:08:33.0435 5960 msahci - ok
08:08:33.0463 5960 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
08:08:33.0467 5960 msdsm - ok
08:08:33.0504 5960 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe
08:08:33.0512 5960 MSDTC - ok
08:08:33.0563 5960 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
08:08:33.0567 5960 Msfs - ok
08:08:33.0587 5960 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
08:08:33.0590 5960 msisadrv - ok
08:08:33.0637 5960 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll
08:08:33.0643 5960 MSiSCSI - ok
08:08:33.0659 5960 msiserver - ok
08:08:33.0691 5960 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
08:08:33.0694 5960 MSKSSRV - ok
08:08:33.0720 5960 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
08:08:33.0735 5960 MSPCLOCK - ok
08:08:33.0760 5960 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
08:08:33.0763 5960 MSPQM - ok
08:08:33.0806 5960 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
08:08:33.0811 5960 MsRPC - ok
08:08:33.0862 5960 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
08:08:33.0865 5960 mssmbios - ok
08:08:33.0901 5960 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
08:08:33.0905 5960 MSTEE - ok
08:08:33.0951 5960 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
08:08:33.0954 5960 Mup - ok
08:08:34.0081 5960 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll
08:08:34.0092 5960 napagent - ok
08:08:34.0138 5960 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
08:08:34.0144 5960 NativeWifiP - ok
08:08:34.0193 5960 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
08:08:34.0203 5960 NDIS - ok
08:08:34.0241 5960 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
08:08:34.0244 5960 NdisTapi - ok
08:08:34.0277 5960 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
08:08:34.0280 5960 Ndisuio - ok
08:08:34.0317 5960 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
08:08:34.0321 5960 NdisWan - ok
08:08:34.0353 5960 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
08:08:34.0357 5960 NDProxy - ok
08:08:34.0398 5960 Net Driver HPZ12 (510c138564486ff926a3f773205c63d1) C:\Windows\system32\HPZinw12.dll
08:08:34.0404 5960 Net Driver HPZ12 - ok
08:08:34.0433 5960 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
08:08:34.0436 5960 NetBIOS - ok
08:08:34.0491 5960 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
08:08:34.0497 5960 netbt - ok
08:08:34.0528 5960 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
08:08:34.0532 5960 Netlogon - ok
08:08:34.0583 5960 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll
08:08:34.0593 5960 Netman - ok
08:08:34.0631 5960 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll
08:08:34.0653 5960 netprofm - ok
08:08:34.0744 5960 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
08:08:34.0758 5960 NetTcpPortSharing - ok
08:08:34.0946 5960 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys
08:08:35.0004 5960 NETw4v32 - ok
08:08:35.0182 5960 NETwLv32 (d4ef7a9767c05905500ec312cb29ef46) C:\Windows\system32\DRIVERS\NETwLv32.sys
08:08:35.0339 5960 NETwLv32 - ok
08:08:35.0421 5960 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
08:08:35.0425 5960 nfrd960 - ok
08:08:35.0484 5960 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll
08:08:35.0492 5960 NlaSvc - ok
08:08:35.0544 5960 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
08:08:35.0547 5960 Npfs - ok
08:08:35.0585 5960 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll
08:08:35.0590 5960 nsi - ok
08:08:35.0632 5960 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
08:08:35.0636 5960 nsiproxy - ok
08:08:35.0720 5960 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
08:08:35.0764 5960 Ntfs - ok
08:08:35.0800 5960 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
08:08:35.0803 5960 ntrigdigi - ok
08:08:35.0838 5960 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
08:08:35.0841 5960 Null - ok
08:08:35.0875 5960 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
08:08:35.0880 5960 nvraid - ok
08:08:35.0910 5960 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
08:08:35.0914 5960 nvstor - ok
08:08:35.0951 5960 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
08:08:35.0956 5960 nv_agp - ok
08:08:35.0977 5960 NwlnkFlt - ok
08:08:36.0003 5960 NwlnkFwd - ok
08:08:36.0086 5960 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:08:36.0094 5960 odserv - ok
08:08:36.0142 5960 OEM02Dev (19cac780b858822055f46c58a111723c) C:\Windows\system32\DRIVERS\OEM02Dev.sys
08:08:36.0148 5960 OEM02Dev - ok
08:08:36.0179 5960 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\Windows\system32\DRIVERS\OEM02Vfx.sys
08:08:36.0182 5960 OEM02Vfx - ok
08:08:36.0224 5960 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
08:08:36.0228 5960 ohci1394 - ok
08:08:36.0303 5960 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:08:36.0308 5960 ose - ok
08:08:36.0361 5960 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
08:08:36.0388 5960 p2pimsvc - ok
08:08:36.0428 5960 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
08:08:36.0437 5960 p2psvc - ok
08:08:36.0483 5960 Packet (9d80e0be979c3edaf2863f23b88f4de6) C:\Windows\system32\DRIVERS\packet.sys
08:08:36.0486 5960 Packet - ok
08:08:36.0528 5960 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
08:08:36.0533 5960 Parport - ok
08:08:36.0571 5960 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
08:08:36.0575 5960 partmgr - ok
08:08:36.0604 5960 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
08:08:36.0608 5960 Parvdm - ok
08:08:36.0658 5960 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll
08:08:36.0664 5960 PcaSvc - ok
08:08:36.0704 5960 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
08:08:36.0709 5960 pci - ok
08:08:36.0740 5960 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
08:08:36.0744 5960 pciide - ok
08:08:36.0775 5960 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
08:08:36.0781 5960 pcmcia - ok
08:08:36.0835 5960 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
08:08:36.0869 5960 PEAUTH - ok
08:08:37.0068 5960 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll
08:08:37.0112 5960 pla - ok
08:08:37.0159 5960 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll
08:08:37.0167 5960 PlugPlay - ok
08:08:37.0217 5960 Pml Driver HPZ12 (37e5e8ffbad35605daeec3224ea0e465) C:\Windows\system32\HPZipm12.dll
08:08:37.0226 5960 Pml Driver HPZ12 - ok
08:08:37.0283 5960 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
08:08:37.0292 5960 PNRPAutoReg - ok
08:08:37.0330 5960 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll
08:08:37.0339 5960 PNRPsvc - ok
08:08:37.0393 5960 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll
08:08:37.0416 5960 PolicyAgent - ok
08:08:37.0488 5960 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
08:08:37.0492 5960 PptpMiniport - ok
08:08:37.0543 5960 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
08:08:37.0546 5960 Processor - ok
08:08:37.0591 5960 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll
08:08:37.0599 5960 ProfSvc - ok
08:08:37.0637 5960 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
08:08:37.0642 5960 ProtectedStorage - ok
08:08:37.0687 5960 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
08:08:37.0691 5960 PSched - ok
08:08:37.0752 5960 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys
08:08:37.0755 5960 PxHelp20 - ok
08:08:37.0829 5960 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
08:08:37.0863 5960 ql2300 - ok
08:08:37.0896 5960 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
08:08:37.0901 5960 ql40xx - ok
08:08:37.0953 5960 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll
08:08:37.0964 5960 QWAVE - ok
08:08:37.0993 5960 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
08:08:37.0997 5960 QWAVEdrv - ok
08:08:38.0072 5960 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys
08:08:38.0127 5960 R300 - ok
08:08:38.0163 5960 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
08:08:38.0166 5960 RasAcd - ok
08:08:38.0210 5960 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll
08:08:38.0219 5960 RasAuto - ok
08:08:38.0342 5960 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:08:38.0347 5960 Rasl2tp - ok
08:08:38.0402 5960 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll
08:08:38.0416 5960 RasMan - ok
08:08:38.0468 5960 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
08:08:38.0473 5960 RasPppoe - ok
08:08:38.0578 5960 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
08:08:38.0591 5960 RasSstp - ok
08:08:38.0666 5960 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
08:08:38.0674 5960 rdbss - ok
08:08:38.0764 5960 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:08:38.0769 5960 RDPCDD - ok
08:08:38.0826 5960 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
08:08:38.0834 5960 rdpdr - ok
08:08:38.0873 5960 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
08:08:38.0877 5960 RDPENCDD - ok
08:08:38.0951 5960 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys
08:08:38.0957 5960 RDPWD - ok
08:08:39.0112 5960 RegFilter (bbe6ea838bffcfe7e27909545b237164) C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys
08:08:39.0115 5960 RegFilter - ok
08:08:39.0200 5960 RegSrvc (2cf574d0965f58e514a2dc94114d7eca) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
08:08:39.0206 5960 RegSrvc - ok
08:08:39.0366 5960 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll
08:08:39.0372 5960 RemoteAccess - ok
08:08:39.0410 5960 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll
08:08:39.0419 5960 RemoteRegistry - ok
08:08:39.0469 5960 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys
08:08:39.0472 5960 rimmptsk - ok
08:08:39.0507 5960 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys
08:08:39.0511 5960 rimsptsk - ok
08:08:39.0559 5960 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys
08:08:39.0563 5960 rismxdp - ok
08:08:39.0606 5960 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe
08:08:39.0611 5960 RpcLocator - ok
08:08:39.0664 5960 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll
08:08:39.0672 5960 RpcSs - ok
08:08:39.0719 5960 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
08:08:39.0723 5960 rspndr - ok
08:08:39.0758 5960 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe
08:08:39.0762 5960 SamSs - ok
08:08:39.0798 5960 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
08:08:39.0802 5960 sbp2port - ok
08:08:39.0854 5960 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll
08:08:39.0862 5960 SCardSvr - ok
08:08:39.0913 5960 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll
08:08:39.0923 5960 Schedule - ok
08:08:39.0954 5960 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll
08:08:39.0956 5960 SCPolicySvc - ok
08:08:40.0008 5960 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys
08:08:40.0012 5960 sdbus - ok
08:08:40.0060 5960 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll
08:08:40.0069 5960 SDRSVC - ok
08:08:40.0121 5960 SecDrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\SECDRV.SYS
08:08:40.0125 5960 SecDrv - ok
08:08:40.0197 5960 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll
08:08:40.0205 5960 seclogon - ok
08:08:40.0244 5960 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll
08:08:40.0250 5960 SENS - ok
08:08:40.0282 5960 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
08:08:40.0286 5960 Serenum - ok
08:08:40.0321 5960 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
08:08:40.0327 5960 Serial - ok
08:08:40.0361 5960 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
08:08:40.0366 5960 sermouse - ok
08:08:40.0546 5960 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll
08:08:40.0555 5960 SessionEnv - ok
08:08:40.0581 5960 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys
08:08:40.0585 5960 sffdisk - ok
08:08:40.0631 5960 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
08:08:40.0635 5960 sffp_mmc - ok
08:08:40.0685 5960 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys
08:08:40.0689 5960 sffp_sd - ok
08:08:40.0756 5960 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
08:08:40.0760 5960 sfloppy - ok
08:08:40.0894 5960 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll
08:08:40.0903 5960 SharedAccess - ok
08:08:41.0124 5960 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll
08:08:41.0132 5960 ShellHWDetection - ok
08:08:41.0200 5960 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
08:08:41.0204 5960 sisagp - ok
08:08:41.0260 5960 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
08:08:41.0264 5960 SiSRaid2 - ok
08:08:41.0399 5960 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
08:08:41.0404 5960 SiSRaid4 - ok
08:08:41.0541 5960 SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files\Skype\Updater\Updater.exe
08:08:41.0548 5960 SkypeUpdate - ok
08:08:41.0798 5960 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe
08:08:41.0944 5960 slsvc - ok
08:08:42.0003 5960 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll
08:08:42.0011 5960 SLUINotify - ok
08:08:42.0056 5960 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
08:08:42.0059 5960 Smb - ok
08:08:42.0138 5960 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe
08:08:42.0145 5960 SNMPTRAP - ok
08:08:42.0193 5960 sonypvs1 (dfadfc2c86662f40759bf02add27d569) C:\Windows\system32\DRIVERS\sonypvs1.sys
08:08:42.0197 5960 sonypvs1 - ok
08:08:42.0236 5960 speedfan (3fa2e254bfbce52b3c6f1bf23aab6911) C:\Windows\system32\speedfan.sys
08:08:42.0243 5960 speedfan - ok
08:08:42.0283 5960 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
08:08:42.0286 5960 spldr - ok
08:08:42.0335 5960 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe
08:08:42.0343 5960 Spooler - ok
08:08:42.0399 5960 sp_rsdrv2 (7b426b8e809edf081d771ef429345528) C:\Windows\system32\drivers\sp_rsdrv2.sys
08:08:42.0403 5960 sp_rsdrv2 - ok
08:08:42.0454 5960 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
08:08:42.0463 5960 srv - ok
08:08:42.0507 5960 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
08:08:42.0512 5960 srv2 - ok
08:08:42.0578 5960 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
08:08:42.0582 5960 srvnet - ok
08:08:42.0677 5960 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll
08:08:42.0688 5960 SSDPSRV - ok
08:08:42.0735 5960 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll
08:08:42.0749 5960 SstpSvc - ok
08:08:42.0840 5960 ST2012_Svc (94667f91af523042bde626690c3971a8) C:\Program Files\Spyware Terminator\st_rsser.exe
08:08:42.0846 5960 ST2012_Svc - ok
08:08:42.0926 5960 STacSV (7e6dd4b34acd36af6c711d2bde91b040) C:\Windows\system32\STacSV.exe
08:08:42.0936 5960 STacSV - ok
08:08:42.0997 5960 Steam Client Service - ok
08:08:43.0091 5960 STHDA (6a2a5e809c2c0178326d92b19ee4aad3) C:\Windows\system32\drivers\stwrt.sys
08:08:43.0100 5960 STHDA - ok
08:08:43.0166 5960 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll
08:08:43.0179 5960 stisvc - ok
08:08:43.0262 5960 stllssvr (1d0063597c3666404fcf97698abeb019) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
08:08:43.0268 5960 stllssvr - ok
08:08:43.0333 5960 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
08:08:43.0338 5960 swenum - ok
08:08:43.0479 5960 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll
08:08:43.0515 5960 swprv - ok
08:08:43.0570 5960 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
08:08:43.0574 5960 Symc8xx - ok
08:08:43.0627 5960 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
08:08:43.0632 5960 Sym_hi - ok
08:08:43.0673 5960 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
08:08:43.0676 5960 Sym_u3 - ok
08:08:43.0781 5960 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll
08:08:43.0790 5960 SysMain - ok
08:08:43.0834 5960 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll
08:08:43.0843 5960 TabletInputService - ok
08:08:43.0894 5960 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll
08:08:43.0905 5960 TapiSrv - ok
08:08:43.0954 5960 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll
08:08:43.0961 5960 TBS - ok
08:08:44.0028 5960 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
08:08:44.0062 5960 Tcpip - ok
08:08:44.0116 5960 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
08:08:44.0124 5960 Tcpip6 - ok
08:08:44.0170 5960 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
08:08:44.0173 5960 tcpipreg - ok
08:08:44.0226 5960 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
08:08:44.0230 5960 TDPIPE - ok
08:08:44.0269 5960 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
08:08:44.0273 5960 TDTCP - ok
08:08:44.0326 5960 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
08:08:44.0331 5960 tdx - ok
08:08:44.0389 5960 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
08:08:44.0393 5960 TermDD - ok
08:08:44.0453 5960 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll
08:08:44.0484 5960 TermService - ok
08:08:44.0610 5960 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll
08:08:44.0621 5960 Themes - ok
08:08:44.0687 5960 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll
08:08:44.0693 5960 THREADORDER - ok
08:08:44.0765 5960 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll
08:08:44.0775 5960 TrkWks - ok
08:08:44.0838 5960 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe
08:08:44.0841 5960 TrustedInstaller - ok
08:08:44.0912 5960 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:08:44.0917 5960 tssecsrv - ok
08:08:44.0981 5960 TuneUp.Defrag (fbc7d7a6f72bc231774b79735c888fa5) C:\Windows\System32\TuneUpDefragService.exe
08:08:45.0010 5960 TuneUp.Defrag - ok
08:08:45.0065 5960 TuneUp.ProgramStatisticsSvc (52b1899df89dfffc9c94f2214459c386) C:\Windows\System32\TUProgSt.exe
08:08:45.0097 5960 TuneUp.ProgramStatisticsSvc - ok
08:08:45.0186 5960 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
08:08:45.0198 5960 tunmp - ok
08:08:45.0271 5960 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
08:08:45.0276 5960 tunnel - ok
08:08:45.0352 5960 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
08:08:45.0357 5960 uagp35 - ok
08:08:45.0432 5960 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
08:08:45.0441 5960 udfs - ok
08:08:45.0570 5960 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe
08:08:45.0581 5960 UI0Detect - ok
08:08:45.0662 5960 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
08:08:45.0667 5960 uliagpkx - ok
08:08:45.0733 5960 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
08:08:45.0740 5960 uliahci - ok
08:08:45.0799 5960 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
08:08:45.0805 5960 UlSata - ok
08:08:45.0872 5960 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
08:08:45.0878 5960 ulsata2 - ok
08:08:45.0943 5960 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
08:08:45.0948 5960 umbus - ok
08:08:46.0052 5960 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll
08:08:46.0063 5960 upnphost - ok
08:08:46.0216 5960 UrlFilter (8d5437d41b868bb28403fe10d9a3fd51) C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys
08:08:46.0219 5960 UrlFilter - ok
08:08:46.0330 5960 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
08:08:46.0335 5960 USBAAPL - ok
08:08:46.0399 5960 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys
08:08:46.0403 5960 usbaudio - ok
08:08:46.0441 5960 usbbus (5aadc9297c39aa249cd994acdba19034) C:\Windows\system32\DRIVERS\lgusbbus.sys
08:08:46.0444 5960 usbbus - ok
08:08:46.0498 5960 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
08:08:46.0503 5960 usbccgp - ok
08:08:46.0563 5960 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
08:08:46.0568 5960 usbcir - ok
08:08:46.0620 5960 UsbDiag (4650ffe04e5922399b0e932319e6b215) C:\Windows\system32\DRIVERS\lgusbdiag.sys
08:08:46.0623 5960 UsbDiag - ok
08:08:46.0676 5960 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
08:08:46.0680 5960 usbehci - ok
08:08:46.0751 5960 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
08:08:46.0757 5960 usbhub - ok
08:08:46.0811 5960 USBModem (2666fe171e0c2e7085ccd5fe0bac09e3) C:\Windows\system32\DRIVERS\lgusbmodem.sys
08:08:46.0814 5960 USBModem - ok
08:08:46.0860 5960 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
08:08:46.0864 5960 usbohci - ok
08:08:47.0009 5960 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
08:08:47.0014 5960 usbprint - ok
08:08:47.0074 5960 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
08:08:47.0079 5960 usbscan - ok
08:08:47.0132 5960 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:08:47.0136 5960 USBSTOR - ok
08:08:47.0192 5960 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
08:08:47.0196 5960 usbuhci - ok
08:08:47.0250 5960 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll
08:08:47.0259 5960 UxSms - ok
08:08:47.0420 5960 UxTuneUp (ecd657c847fd73f62b8f16e000696704) C:\Windows\System32\uxtuneup.dll
08:08:47.0428 5960 UxTuneUp - ok
08:08:47.0490 5960 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe
08:08:47.0523 5960 vds - ok
08:08:47.0576 5960 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
08:08:47.0580 5960 vga - ok
08:08:47.0620 5960 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
08:08:47.0624 5960 VgaSave - ok
08:08:47.0664 5960 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
08:08:47.0667 5960 viaagp - ok
08:08:47.0694 5960 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
08:08:47.0697 5960 ViaC7 - ok
08:08:47.0732 5960 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
08:08:47.0743 5960 viaide - ok
08:08:47.0780 5960 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
08:08:47.0784 5960 volmgr - ok
08:08:47.0830 5960 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
08:08:47.0841 5960 volmgrx - ok
08:08:47.0888 5960 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
08:08:47.0893 5960 volsnap - ok
08:08:47.0933 5960 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
08:08:47.0939 5960 vsmraid - ok
08:08:48.0000 5960 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe
08:08:48.0036 5960 VSS - ok
08:08:48.0160 5960 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll
08:08:48.0169 5960 W32Time - ok
08:08:48.0235 5960 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
08:08:48.0239 5960 WacomPen - ok
08:08:48.0283 5960 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
08:08:48.0287 5960 Wanarp - ok
08:08:48.0310 5960 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
08:08:48.0313 5960 Wanarpv6 - ok
08:08:48.0371 5960 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll
08:08:48.0400 5960 wcncsvc - ok
08:08:48.0455 5960 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll
08:08:48.0464 5960 WcsPlugInService - ok
08:08:48.0509 5960 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
08:08:48.0514 5960 Wd - ok
08:08:48.0564 5960 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
08:08:48.0576 5960 Wdf01000 - ok
08:08:48.0644 5960 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
08:08:48.0654 5960 WdiServiceHost - ok
08:08:48.0697 5960 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll
08:08:48.0707 5960 WdiSystemHost - ok
08:08:48.0888 5960 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll
08:08:48.0898 5960 WebClient - ok
08:08:48.0952 5960 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll
08:08:48.0967 5960 Wecsvc - ok
08:08:49.0008 5960 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll
08:08:49.0015 5960 wercplsupport - ok
08:08:49.0079 5960 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll
08:08:49.0086 5960 WerSvc - ok
08:08:49.0157 5960 winachsf (72cc6a8ca7891031d6380db5025c773c) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
08:08:49.0270 5960 winachsf - ok
08:08:49.0342 5960 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll
08:08:49.0349 5960 WinDefend - ok
08:08:49.0391 5960 WinHttpAutoProxySvc - ok
08:08:49.0550 5960 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll
08:08:49.0556 5960 Winmgmt - ok
08:08:49.0635 5960 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll
08:08:49.0693 5960 WinRM - ok
08:08:49.0860 5960 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll
08:08:49.0870 5960 Wlansvc - ok
08:08:49.0980 5960 wlidsvc (0a70f4022ec2e14c159efc4f69aa2477) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:08:49.0993 5960 wlidsvc - ok
08:08:50.0071 5960 WmaCAudio (fc1de2cac8ce8197722f8551c29e9e88) C:\Windows\system32\drivers\WmaCAudio.sys
08:08:50.0075 5960 WmaCAudio - ok
08:08:50.0116 5960 WmaCVideo (5ac3c082d70a84ae34c88c8fb0be2dfb) C:\Windows\system32\DRIVERS\WmaCVideo.sys
08:08:50.0120 5960 WmaCVideo - ok
08:08:50.0213 5960 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
08:08:50.0217 5960 WmiAcpi - ok
08:08:50.0301 5960 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe
08:08:50.0307 5960 wmiApSrv - ok
08:08:50.0399 5960 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe
08:08:50.0433 5960 WMPNetworkSvc - ok
08:08:50.0526 5960 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll
08:08:50.0537 5960 WPCSvc - ok
08:08:50.0606 5960 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll
08:08:50.0616 5960 WPDBusEnum - ok
08:08:50.0671 5960 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
08:08:50.0675 5960 WpdUsb - ok
08:08:50.0864 5960 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
08:08:50.0931 5960 WPFFontCache_v0400 - ok
08:08:51.0039 5960 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
08:08:51.0043 5960 ws2ifsl - ok
08:08:51.0099 5960 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll
08:08:51.0107 5960 wscsvc - ok
08:08:51.0134 5960 WSearch - ok
08:08:51.0252 5960 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll
08:08:51.0276 5960 wuauserv - ok
08:08:51.0318 5960 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:08:51.0323 5960 WUDFRd - ok
08:08:51.0366 5960 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll
08:08:51.0374 5960 wudfsvc - ok
08:08:51.0415 5960 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys
08:08:51.0418 5960 XAudio - ok
08:08:51.0462 5960 XAudioService (cd5f291a1161f15896d1a4d63daff5df) C:\Windows\system32\DRIVERS\xaudio.exe
08:08:51.0466 5960 XAudioService - ok
08:08:51.0531 5960 yukonwlh (04e268adfc81964c49dc0c082d520f7e) C:\Windows\system32\DRIVERS\yk60x86.sys
08:08:51.0537 5960 yukonwlh - ok
08:08:51.0591 5960 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0
08:08:51.0859 5960 \Device\Harddisk0\DR0 - ok
08:08:51.0916 5960 Boot (0x1200) (1c87bb41b794aa77b498067de1159056) \Device\Harddisk0\DR0\Partition0
08:08:51.0918 5960 \Device\Harddisk0\DR0\Partition0 - ok
08:08:51.0923 5960 Boot (0x1200) (f805fa144e726ceaa4cf9a250587b283) \Device\Harddisk0\DR0\Partition1
08:08:51.0926 5960 \Device\Harddisk0\DR0\Partition1 - ok
08:08:51.0927 5960 ============================================================
08:08:51.0927 5960 Scan finished
08:08:51.0927 5960 ============================================================
08:08:51.0940 0308 Detected object count: 0
08:08:51.0940 0308 Actual detected object count: 0






ComboFix 12-04-07.02 - Nathan 04/07/2012 8:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1003 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Nathan\AppData\Local\assembly\tmp
c:\users\Nathan\g2mdlhlpx.exe
c:\users\Public\Logo.png
c:\windows\security\Database\tmp.edb
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\drivers\etc\hosts.txt
.
.
((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 )))))))))))))))))))))))))))))))
.
.
2012-04-07 13:37 . 2012-04-07 13:38 ——– d—–w- c:\users\Nathan\AppData\Local\temp
2012-04-07 13:37 . 2012-04-07 13:37 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2012-04-07 13:37 . 2012-04-07 13:37 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-02 19:06 . 2012-04-02 19:06 ——– d—–w- c:\program files\Common Files\Skype
2012-03-24 14:40 . 2012-03-24 14:40 ——– d—–w- c:\users\Nathan\AppData\Local\Vagex
2012-03-24 11:26 . 2012-03-24 11:26 ——– d—–w- c:\users\Default\AppData\Roaming\IObit
2012-03-16 01:56 . 2012-03-16 01:56 ——– d—–w- c:\programdata\Amazon
2012-03-16 01:19 . 2012-02-02 15:16 2044416 —-a-w- c:\windows\system32\win32k.sys
2012-03-16 01:19 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-03-16 01:19 . 2012-01-09 13:58 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-16 01:19 . 2012-02-13 13:44 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-03-16 01:19 . 2012-02-14 15:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-03-16 01:19 . 2012-02-13 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-03-16 01:19 . 2012-02-14 15:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-03-16 01:19 . 2012-02-13 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-03-16 01:19 . 2012-01-31 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-03-09 02:17 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-03-09 02:15 . 2011-11-17 06:48 440192 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-03-09 02:15 . 2011-11-16 16:23 278528 —-a-w- c:\windows\system32\schannel.dll
2012-03-09 02:15 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-03-09 02:15 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-03-09 02:15 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-03-09 02:15 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-24 11:09 . 2011-07-23 13:58 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-06 23:15 . 2011-01-31 23:09 41184 —-a-w- c:\windows\avastSS.scr
2012-03-06 23:15 . 2011-01-31 23:09 201352 —-a-w- c:\windows\system32\aswBoot.exe
2012-03-06 23:03 . 2011-02-26 12:51 612184 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-06 23:03 . 2011-01-31 23:11 337880 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-06 23:02 . 2011-01-31 23:11 35672 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-06 23:01 . 2011-01-31 23:11 53848 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-06 23:01 . 2011-01-31 23:11 57688 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-03-06 23:01 . 2011-01-31 23:11 20696 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-02-17 02:34 . 2010-09-27 16:15 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-01-12 20:24 . 2012-01-12 20:24 26224 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2011-12-21 07:24 . 2011-05-15 11:41 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-03-06 574296]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-12-23 3114496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2012-02-20 2786480]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2012-02-20 3669680]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-03-06 4241512]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-01-13 981680]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2011-11-23 97384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-12-15 09:44 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"Steam"="c:\program files\Steam\Steam.exe" -silent
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" /STARTUP
"Google Update"="c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
"ehTray.exe"=c:\windows\ehome\ehTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UpdReg"=c:\windows\UpdReg.EXE
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
"OEM02Mon.exe"=c:\windows\OEM02Mon.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" /autostart
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Persistence"=c:\windows\system32\igfxpers.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MMReminderService"=c:\program files\Mindjet\MindManager 8\MMReminderService.exe
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"Everything"="c:\program files\Everything\Everything.exe" -startup
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"AgentMonitor"=c:\program files\VTech\DownloadManager\System\AgentMonitor.exe
.
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [2012-03-14 913752]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-11-12 73728]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 61738554
*Deregistered* - 61738554
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 22:28]
.
2012-04-04 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-21 15:50]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-102791869-1721815395-4073960749-1000Core.job
- c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-21 15:27]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-102791869-1721815395-4073960749-1000UA.job
- c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-21 15:27]
.
2012-03-27 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-03-21 00:08]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath - c:\users\Nathan\AppData\Roaming\Mozilla\Firefox\Profiles\9goa9zdw.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z128&form=ZGAADF&install_date=20110911&q=
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
——- File Associations ——-
.
.txt=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-07 08:38
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,e8,65,78,06,11,1f,41,9e,b7,b8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,e8,65,78,06,11,1f,41,9e,b7,b8,\
.
[HKEY_USERS\S-1-5-21-102791869-1721815395-4073960749-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{89326CDD-FAF2-CB42-B9BE-6DC7C19D5D47}*]
"oalfhaablbalifnlbeblcegdgfohic"=hex:6a,61,61,62,63,6a,65,68,63,66,69,63,64,6e,
69,6a,67,6b,65,67,00,00
"nanfhlmoanbagnmbognfnhgieano"=hex:6a,61,61,62,63,6a,65,68,63,66,69,63,64,6e,
69,6a,67,6b,65,67,00,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-04-07 08:44:09
ComboFix-quarantined-files.txt 2012-04-07 13:43
.
Pre-Run: 38,433,062,912 bytes free
Post-Run: 38,371,016,704 bytes free
.
- - End Of File - - 10500511D1CA1659142965A7E5F31E0B
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

FireFox::
FF - ProfilePath - c:\users\Nathan\AppData\Roaming\Mozilla\Firefox\Profiles\9goa9zdw.default\
FF - prefs.js: browser.startup.homepage - about:home

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
ComboFix 12-04-07.02 - Nathan 04/07/2012 10:06:33.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1165 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Nathan\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\combofix\HarddiskVolumeShadowCopy2_!Windows!System32!userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 )))))))))))))))))))))))))))))))
.
.
2012-04-07 15:19 . 2012-04-07 15:23 ——– d—–w- c:\users\Nathan\AppData\Local\temp
2012-04-07 15:19 . 2012-04-07 15:19 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2012-04-07 15:19 . 2012-04-07 15:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-02 19:06 . 2012-04-02 19:06 ——– d—–w- c:\program files\Common Files\Skype
2012-03-24 14:40 . 2012-03-24 14:40 ——– d—–w- c:\users\Nathan\AppData\Local\Vagex
2012-03-24 11:26 . 2012-03-24 11:26 ——– d—–w- c:\users\Default\AppData\Roaming\IObit
2012-03-16 01:56 . 2012-03-16 01:56 ——– d—–w- c:\programdata\Amazon
2012-03-16 01:19 . 2012-02-02 15:16 2044416 —-a-w- c:\windows\system32\win32k.sys
2012-03-16 01:19 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-03-16 01:19 . 2012-01-09 13:58 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-16 01:19 . 2012-02-13 13:44 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-03-16 01:19 . 2012-02-14 15:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-03-16 01:19 . 2012-02-13 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-03-16 01:19 . 2012-02-14 15:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-03-16 01:19 . 2012-02-13 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-03-16 01:19 . 2012-01-31 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-03-09 02:17 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-03-09 02:15 . 2011-11-17 06:48 440192 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-03-09 02:15 . 2011-11-16 16:23 278528 —-a-w- c:\windows\system32\schannel.dll
2012-03-09 02:15 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-03-09 02:15 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-03-09 02:15 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-03-09 02:15 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-24 11:09 . 2011-07-23 13:58 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-06 23:15 . 2011-01-31 23:09 41184 —-a-w- c:\windows\avastSS.scr
2012-03-06 23:15 . 2011-01-31 23:09 201352 —-a-w- c:\windows\system32\aswBoot.exe
2012-03-06 23:03 . 2011-02-26 12:51 612184 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-06 23:03 . 2011-01-31 23:11 337880 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-06 23:02 . 2011-01-31 23:11 35672 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-06 23:01 . 2011-01-31 23:11 53848 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-06 23:01 . 2011-01-31 23:11 57688 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-03-06 23:01 . 2011-01-31 23:11 20696 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-02-17 02:34 . 2010-09-27 16:15 472808 —-a-w- c:\windows\system32\deployJava1.dll
2012-01-12 20:24 . 2012-01-12 20:24 26224 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2011-12-21 07:24 . 2011-05-15 11:41 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2012-03-06 574296]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-12-23 3114496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2012-02-20 2786480]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2012-02-20 3669680]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-03-06 4241512]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-01-13 981680]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2011-11-23 97384]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-12-15 09:44 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"Steam"="c:\program files\Steam\Steam.exe" -silent
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" /STARTUP
"Google Update"="c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
"ehTray.exe"=c:\windows\ehome\ehTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UpdReg"=c:\windows\UpdReg.EXE
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
"OEM02Mon.exe"=c:\windows\OEM02Mon.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" /autostart
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Persistence"=c:\windows\system32\igfxpers.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MMReminderService"=c:\program files\Mindjet\MindManager 8\MMReminderService.exe
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"Everything"="c:\program files\Everything\Everything.exe" -startup
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"AgentMonitor"=c:\program files\VTech\DownloadManager\System\AgentMonitor.exe
.
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [2012-03-14 913752]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-11-12 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 22:28]
.
2012-04-07 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-21 15:50]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-102791869-1721815395-4073960749-1000Core.job
- c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-21 15:27]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-102791869-1721815395-4073960749-1000UA.job
- c:\users\Nathan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-21 15:27]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-07 10:22
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,e8,65,78,06,11,1f,41,9e,b7,b8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,e8,65,78,06,11,1f,41,9e,b7,b8,\
.
[HKEY_USERS\S-1-5-21-102791869-1721815395-4073960749-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{89326CDD-FAF2-CB42-B9BE-6DC7C19D5D47}*]
"oalfhaablbalifnlbeblcegdgfohic"=hex:6a,61,61,62,63,6a,65,68,63,66,69,63,64,6e,
69,6a,67,6b,65,67,00,00
"nanfhlmoanbagnmbognfnhgieano"=hex:6a,61,61,62,63,6a,65,68,63,66,69,63,64,6e,
69,6a,67,6b,65,67,00,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\program files\Dell\DellDock\DockLogin.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\programdata\SingleClick Systems\MySQL\bin\mysqld.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\programdata\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Terminator\st_rsser.exe
c:\windows\system32\STacSV.exe
c:\windows\System32\TUProgSt.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\DellTPad\HidFind.exe
.
**************************************************************************
.
Completion time: 2012-04-07 10:30:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-07 15:30
ComboFix2.txt 2012-04-07 13:44
.
Pre-Run: 36,145,643,520 bytes free
Post-Run: 35,907,874,816 bytes free
.
- - End Of File - - 47FD064BEA0E99D565C8540E93734B2A



Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.07.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Nathan :: BAKER [administrator]

4/7/2012 10:41:44 AM
mbam-log-2012-04-07 (10-41-44).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 218296
Time elapsed: 12 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application
Hi,

Please do the following:

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java SE 6 Update 31
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u31-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please advise how the computer is running now and if there are any outstanding issues
Okay, I followed those last steps, got everything up to date. Computer is, of course, a bit slower than when I first got it a year or two, but I haven't seen or heard any warnings. So it's running fine I suppose? Would I have found anything deviously hidden so far if I was compromised as far as you can tell? Otherwise, things are running good!
Logs appear to be clean now,

try a defrag, that may assist:

First open an elevated Command Prompt
  • Go to Start > All Programs > Accessories
  • right click on the Command Prompt and choose “Run as administrator”
  • Type the following see how much your hard drive is fragmented (in this example, your C:\ drive):
  • defrag c: -a (be patient, this can take a while)
  • The resulting analysis will tell you a “Percent file fragmentation” and at the bottom, if you need to defragment the drive or not.
  • To fully defragment your C:\ drive type the following:
  • defrag c: -w
  • Give it time to run (it can take a while, best to leave the computer alone) and then you’re done!


now we just need to clean up our tools

please do the following:


You can delete the TDSSKiller logs and program from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Well, I'll be. Happy to hear I'm looking good. :) I very much appreciate your time and dedication to helping me resolve my problems. God bless you for it. I'll be reading those articles and adding on the various suggestions and so forth as I now don't consider that kind of protection just "for others". Thank you very much again for your time and help!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI