This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

zeroaccess/search engine redirect [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I don't know if these are related but Mcafee keeps telling me it's removed a Zeroaccess Trojan every few minutes, something is downloading roughly a gig an hour and uploading 200 mb and when I'm using any search engine and loading a page it will redirect me to a random site.
Angus


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:30:20 PM, on 13/04/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Apple Software Update\SoftwareUpdate.exe
C:\Users\angus\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120207161254.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…NPUplden-au.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Cccredmgr (hdthermal) - Unknown owner - \\.\globalrootC:\Windows\system32\svchost.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\Windows\system32\Hpservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 10810 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Computer now doesn't seem to be redirecting me and mcafee hasn't given me any bad notifications as of yet, is running faster as well.

Combofix log:

ComboFix 12-04-14.01 - angus 14/04/2012 19:22:56.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3580.2947 [GMT 10:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\windows
c:\programdata\Windows\dumd.dat
c:\programdata\windows\xdor.dat
c:\windows\$NtUninstallKB1275$
c:\windows\$NtUninstallKB1275$\2609946475\@
c:\windows\$NtUninstallKB1275$\2609946475\cfg.ini
c:\windows\$NtUninstallKB1275$\2609946475\Desktop.ini
c:\windows\$NtUninstallKB1275$\2609946475\L\xadqgnnk
c:\windows\$NtUninstallKB1275$\2609946475\oemid
c:\windows\$NtUninstallKB1275$\2609946475\U\00000001.@
c:\windows\$NtUninstallKB1275$\2609946475\U\00000002.@
c:\windows\$NtUninstallKB1275$\2609946475\U\00000004.@
c:\windows\$NtUninstallKB1275$\2609946475\U\80000000.@
c:\windows\$NtUninstallKB1275$\2609946475\U\80000004.@
c:\windows\$NtUninstallKB1275$\2609946475\U\80000032.@
c:\windows\$NtUninstallKB1275$\2609946475\version
c:\windows\$NtUninstallKB1275$\2697859274
c:\windows\system32\dds_trash_log.cmd
.
Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
Restored copy from - The cat found it :)
.
((((((((((((((((((((((((( Files Created from 2012-03-14 to 2012-04-14 )))))))))))))))))))))))))))))))
.
.
2012-04-14 08:08 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-14 08:08 . 2012-03-01 05:37 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-04-14 08:08 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-14 08:08 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-14 08:08 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-14 08:08 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-13 06:13 . 2012-04-13 06:13 ——– d—–w- c:\windows\en
2012-04-13 06:10 . 2012-04-13 06:10 537432 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DXSETUP.exe
2012-04-13 06:10 . 2012-04-13 06:10 1801048 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\dsetup32.dll
2012-04-13 06:10 . 2012-04-13 06:10 89944 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DSETUP.dll
2012-04-13 05:25 . 2012-04-13 05:25 ——– d—–w- c:\program files\iPod
2012-04-13 05:25 . 2012-04-13 05:26 ——– d—–w- c:\program files\iTunes
2012-04-13 04:44 . 2012-04-13 04:44 ——– d—–w- c:\program files\Synaptics
2012-04-02 05:42 . 2012-04-11 07:33 14664 —-a-w- c:\windows\stinger.sys
2012-04-02 05:41 . 2012-04-13 03:33 ——– d—–w- c:\program files\stinger
2012-04-01 02:50 . 2012-04-01 02:50 ——– d—–w- c:\programdata\Recovery
2012-03-31 14:33 . 2012-04-11 08:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2012-03-31 14:33 . 2012-03-31 14:33 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-03-31 10:22 . 2012-03-31 10:22 ——– d—–w- c:\users\angus\AppData\Roaming\Malwarebytes
2012-03-31 10:21 . 2012-03-31 10:21 ——– d—–w- c:\programdata\Malwarebytes
2012-03-31 10:21 . 2012-04-04 05:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-03-31 10:21 . 2012-04-13 01:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-03-31 09:51 . 2012-03-31 09:51 ——– d—–w- c:\program files\CCleaner
2012-03-29 16:01 . 2012-04-13 04:39 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-03-17 03:01 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys
2012-03-17 03:01 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll
2012-03-17 03:01 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-17 03:01 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-03-17 03:01 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-03-17 03:01 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll
2012-03-17 03:01 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-17 03:01 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 04:39 . 2011-08-07 07:25 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-02 05:41 . 2010-04-19 07:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2012-04-02 05:41 . 2010-01-05 08:04 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2012-03-08 08:50 . 2012-03-08 08:50 49016 —-a-w- c:\windows\system32\sirenacm.dll
2012-03-08 08:37 . 2012-03-08 08:37 302448 —-a-w- c:\windows\WLXPGSS.SCR
2012-02-07 01:02 . 2012-02-07 01:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2011-11-21 04:04 . 2011-12-09 09:59 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.271\SSScheduler.exe [2012-3-14 274328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"WallpaperStyle"= 2
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^angus^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\angus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-01-04 06:51 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 02:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-20 11:28 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 21:50 54576 —-a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-07-16 00:51 1668664 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2010-07-21 06:52 1797008 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-26 19:09 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-06-17 19:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 05:56 462408 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
2011-11-22 07:18 1318816 —-a-w- c:\program files\McAfee.com\Agent\mcagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 04:28 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2009-07-02 19:32 98304 —-a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-11-04 05:34 1242448 —-a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 03:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2010-05-27 05:31 1721640 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2009-07-22 01:33 458844 —-a-w- c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut]
2009-05-20 05:16 222504 ——w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2009-07-23 18:04 498744 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253600]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 116136]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.271\McCHSvc.exe [2012-03-13 237272]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-04-02 87656]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-09 1343400]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 165680]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 64880]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 160608]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2012-04-02 159608]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-07-17 29472]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 57600]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 59904]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 338176]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-23 167936]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 28344]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
NETSVCS REQUIRES REPAIRS - current entries shown
AeLookupSvc
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Ias
Irmon
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
SRService
Tapisrv
Wmi
WmdmPmSp
CBN
portmapper
TdmService
vclone
sfrem01
cpntsrv
SaiNtBus
servicemgr
lp6nds35
ATIBTCAP
klblmain
asuskeyboardservice
tifm21
caboagp
se44nd5
pilogsrv
VC4CB104
atiavpci
itchfltr
lusbaudio
freebsd
pdlnemsg
hpwirelessmgr
mgabg
osaio
messenger
ISAMSvc
ood2000
IntelC53
bobo
PAR1284
puscsrvc
wdmaud
icepack
ROB_A
ftsata2
dirms_defragmentation
tvtfilter
TIEHDUSB
proxyhostdriver
usbser
db2ntsecserver
teefer
hdthermal
LVBulk
dbmang
FireTDI
e1express
oracleorahomepagingserver
RTL8023xp
arrayssl_vpn_service3,0,1,9
sisperf
wmp54gssvc
Si3114r5
mqdmbus
bt
AR5416
lkclassads
WscNetDr
UNDPX2A
LUsbKbd
flashpnt
DELL_A02
dns4meclient
iksysflt
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
wercplsupport
EapHost
ProfSvc
schedule
hkmsvc
SessionEnv
winmgmt
browser
Themes
BDESVC
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 04:39]
.
2012-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44]
.
2012-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44]
.
2012-04-14 c:\windows\Tasks\vtscheduletask.job
- c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-02-21 04:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_AU&c;=94&bd;=Pavilion&pf;=cnnb
uInternet Settings,ProxyOverride = ;*.local
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\angus\AppData\Roaming\Mozilla\Firefox\Profiles\wxjv5vxp.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=937811&p;=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109985
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 049b126b00000000000006037f8ee659
FF - user.js: extensions.BabylonToolbar_i.hardId - 049b126b00000000000006037f8ee659
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15379
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1712:30
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-AdobeBridge - (no file)
MSConfigStartUp-Google Update - c:\users\angus\AppData\Local\Google\Update\GoogleUpdate.exe
AddRemove-LSI Soft Modem - c:\windows\agrsmdel
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2291357997-1775983430-1860472803-1000\Software\SecuROM\License information*]
"datasecu"=hex:bf,e9,a2,e9,f9,ff,a5,4e,bb,f3,9f,04,74,61,28,be,87,f9,59,76,1e,
02,26,26,30,99,33,5c,8a,89,b5,6a,35,6c,eb,0d,c8,dc,32,03,63,3a,9f,a6,64,99,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(2756)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe
c:\windows\system32\atieclxx.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\RunDll32.exe
.
**************************************************************************
.
Completion time: 2012-04-14 19:58:13 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-14 09:58
.
Pre-Run: 342,754,136,064 bytes free
Post-Run: 342,509,453,312 bytes free
.
- - End Of File - - 9DD2E52BC1E7D773BD939399528D8398








TDSS log:


TDSS rootkit removing tool [removed] Apr 10 2012 16:54:05
20:17:06.0023 4196 ============================================================
20:17:06.0023 4196 Current date / time: 2012/04/14 20:17:06.0023
20:17:06.0023 4196 SystemInfo:
20:17:06.0023 4196
20:17:06.0023 4196 OS Version: 6.1.7601 ServicePack: 1.0
20:17:06.0023 4196 Product type: Workstation
20:17:06.0023 4196 ComputerName: THEBOGUS-PC
20:17:06.0023 4196 UserName: angus
20:17:06.0023 4196 Windows directory: C:\Windows
20:17:06.0023 4196 System windows directory: C:\Windows
20:17:06.0023 4196 Processor architecture: Intel x86
20:17:06.0023 4196 Number of processors: 2
20:17:06.0023 4196 Page size: 0x1000
20:17:06.0023 4196 Boot type: Normal boot
20:17:06.0023 4196 ============================================================
20:17:07.0614 4196 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
20:17:07.0614 4196 \Device\Harddisk0\DR0:
20:17:07.0614 4196 MBR used
20:17:07.0614 4196 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
20:17:07.0614 4196 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x38B0A000
20:17:07.0614 4196 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38B6E000, BlocksNum 0x17E4000
20:17:07.0614 4196 \Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x3A352000, BlocksNum 0x33830
20:17:07.0677 4196 Initialize success
20:17:07.0677 4196 ============================================================
20:17:25.0617 3992 ============================================================
20:17:25.0617 3992 Scan started
20:17:25.0617 3992 Mode: Manual;
20:17:25.0617 3992 ============================================================
20:17:26.0163 3992 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\DRIVERS\1394ohci.sys
20:17:26.0163 3992 1394ohci - ok
20:17:26.0225 3992 Accelerometer (4df5e6215a102a192b2b6dbb61f2fba5) C:\Windows\system32\DRIVERS\Accelerometer.sys
20:17:26.0225 3992 Accelerometer - ok
20:17:26.0272 3992 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
20:17:26.0272 3992 ACPI - ok
20:17:26.0319 3992 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
20:17:26.0319 3992 AcpiPmi - ok
20:17:26.0412 3992 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:17:26.0506 3992 AdobeFlashPlayerUpdateSvc - ok
20:17:26.0568 3992 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
20:17:26.0584 3992 adp94xx - ok
20:17:26.0615 3992 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
20:17:26.0631 3992 adpahci - ok
20:17:26.0662 3992 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
20:17:26.0677 3992 adpu320 - ok
20:17:26.0709 3992 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll
20:17:26.0709 3992 AeLookupSvc - ok
20:17:26.0787 3992 AESTFilters (827dbc22c96eecf6d36a13162fabafd3) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe
20:17:26.0802 3992 AESTFilters - ok
20:17:26.0880 3992 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
20:17:26.0880 3992 AFD - ok
20:17:26.0943 3992 AgereModemAudio (6416f9b6b220f0a890525c38235afad7) C:\Program Files\LSI SoftModem\agrsmsvc.exe
20:17:26.0943 3992 AgereModemAudio - ok
20:17:26.0989 3992 AgereSoftModem (faa5a0b80e011464c7654851ce3d7fe7) C:\Windows\system32\DRIVERS\AGRSM.sys
20:17:27.0005 3992 AgereSoftModem - ok
20:17:27.0036 3992 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
20:17:27.0036 3992 agp440 - ok
20:17:27.0083 3992 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
20:17:27.0083 3992 aic78xx - ok
20:17:27.0145 3992 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe
20:17:27.0161 3992 ALG - ok
20:17:27.0208 3992 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
20:17:27.0208 3992 aliide - ok
20:17:27.0270 3992 AMD External Events Utility (92543da5bb9775978fdbc1650c24a058) C:\Windows\system32\atiesrxx.exe
20:17:27.0270 3992 AMD External Events Utility - ok
20:17:27.0317 3992 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
20:17:27.0317 3992 amdagp - ok
20:17:27.0348 3992 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
20:17:27.0348 3992 amdide - ok
20:17:27.0411 3992 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
20:17:27.0411 3992 AmdK8 - ok
20:17:27.0426 3992 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
20:17:27.0442 3992 AmdPPM - ok
20:17:27.0613 3992 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
20:17:27.0613 3992 amdsata - ok
20:17:27.0691 3992 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
20:17:27.0691 3992 amdsbs - ok
20:17:27.0723 3992 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
20:17:27.0723 3992 amdxata - ok
20:17:27.0785 3992 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
20:17:27.0785 3992 AppID - ok
20:17:27.0847 3992 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll
20:17:27.0847 3992 AppIDSvc - ok
20:17:27.0894 3992 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll
20:17:27.0894 3992 Appinfo - ok
20:17:28.0003 3992 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:17:28.0003 3992 Apple Mobile Device - ok
20:17:28.0050 3992 AR5416 - ok
20:17:28.0144 3992 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
20:17:28.0144 3992 arc - ok
20:17:28.0159 3992 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
20:17:28.0159 3992 arcsas - ok
20:17:28.0191 3992 arrayssl_vpn_service3,0,1,9 - ok
20:17:28.0206 3992 asuskeyboardservice - ok
20:17:28.0253 3992 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
20:17:28.0253 3992 AsyncMac - ok
20:17:28.0300 3992 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
20:17:28.0300 3992 atapi - ok
20:17:28.0393 3992 athr (ecf01c1e13591a1350fcf91d4197d9e2) C:\Windows\system32\DRIVERS\athr.sys
20:17:28.0409 3992 athr - ok
20:17:28.0425 3992 atiavpci - ok
20:17:28.0440 3992 ATIBTCAP - ok
20:17:28.0503 3992 AtiHdmiService (bb9e7c7f937714f05a4e05c287d6ddff) C:\Windows\system32\drivers\AtiHdmi.sys
20:17:28.0503 3992 AtiHdmiService - ok
20:17:28.0612 3992 atikmdag (632a5be70d168b84f658a82ac8dbbead) C:\Windows\system32\DRIVERS\atikmdag.sys
20:17:28.0674 3992 atikmdag - ok
20:17:28.0721 3992 AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\Windows\system32\DRIVERS\AtiPcie.sys
20:17:28.0721 3992 AtiPcie - ok
20:17:28.0783 3992 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
20:17:28.0799 3992 AudioEndpointBuilder - ok
20:17:28.0830 3992 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
20:17:28.0830 3992 Audiosrv - ok
20:17:28.0893 3992 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll
20:17:28.0893 3992 AxInstSV - ok
20:17:28.0971 3992 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
20:17:28.0971 3992 b06bdrv - ok
20:17:29.0017 3992 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
20:17:29.0017 3992 b57nd60x - ok
20:17:29.0095 3992 BCM43XX (eb7c2dadf52f50f69f198c14c3556dc1) C:\Windows\system32\DRIVERS\bcmwl6.sys
20:17:29.0111 3992 BCM43XX - ok
20:17:29.0142 3992 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll
20:17:29.0142 3992 BDESVC - ok
20:17:29.0173 3992 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
20:17:29.0173 3992 Beep - ok
20:17:29.0236 3992 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll
20:17:29.0251 3992 BFE - ok
20:17:29.0298 3992 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\system32\qmgr.dll
20:17:29.0314 3992 BITS - ok
20:17:29.0345 3992 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
20:17:29.0345 3992 blbdrive - ok
20:17:29.0392 3992 bobo - ok
20:17:29.0485 3992 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
20:17:29.0485 3992 Bonjour Service - ok
20:17:29.0548 3992 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
20:17:29.0548 3992 bowser - ok
20:17:29.0579 3992 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:17:29.0579 3992 BrFiltLo - ok
20:17:29.0610 3992 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:17:29.0610 3992 BrFiltUp - ok
20:17:29.0673 3992 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys
20:17:29.0673 3992 BridgeMP - ok
20:17:29.0719 3992 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll
20:17:29.0719 3992 Browser - ok
20:17:29.0751 3992 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
20:17:29.0751 3992 Brserid - ok
20:17:29.0782 3992 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
20:17:29.0782 3992 BrSerWdm - ok
20:17:29.0797 3992 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:17:29.0813 3992 BrUsbMdm - ok
20:17:29.0813 3992 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
20:17:29.0813 3992 BrUsbSer - ok
20:17:29.0844 3992 bt - ok
20:17:29.0907 3992 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys
20:17:29.0907 3992 BthEnum - ok
20:17:29.0953 3992 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
20:17:29.0953 3992 BTHMODEM - ok
20:17:30.0000 3992 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
20:17:30.0000 3992 BthPan - ok
20:17:30.0063 3992 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys
20:17:30.0063 3992 BTHPORT - ok
20:17:30.0125 3992 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll
20:17:30.0125 3992 bthserv - ok
20:17:30.0156 3992 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys
20:17:30.0156 3992 BTHUSB - ok
20:17:30.0219 3992 btwaudio (d57d29132efe13a83133d9bd449e0cf1) C:\Windows\system32\drivers\btwaudio.sys
20:17:30.0234 3992 btwaudio - ok
20:17:30.0281 3992 btwavdt (d282c14a69357d0e1bafaecc2ca98c3a) C:\Windows\system32\DRIVERS\btwavdt.sys
20:17:30.0297 3992 btwavdt - ok
20:17:30.0375 3992 btwdins (f7434401ae320bb97903a3c1865242fb) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
20:17:30.0390 3992 btwdins - ok
20:17:30.0421 3992 btwl2cap (aafd7cb76ba61fbb08e302da208c974a) C:\Windows\system32\DRIVERS\btwl2cap.sys
20:17:30.0421 3992 btwl2cap - ok
20:17:30.0468 3992 btwrchid (02eb4d2b05967df2d32f29c84ab1fb17) C:\Windows\system32\DRIVERS\btwrchid.sys
20:17:30.0468 3992 btwrchid - ok
20:17:30.0499 3992 caboagp - ok
20:17:30.0577 3992 catchme - ok
20:17:30.0624 3992 CBN - ok
20:17:30.0687 3992 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
20:17:30.0687 3992 cdfs - ok
20:17:30.0749 3992 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
20:17:30.0749 3992 cdrom - ok
20:17:30.0811 3992 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
20:17:30.0811 3992 CertPropSvc - ok
20:17:30.0874 3992 cfwids (1dcb5209601a70e36c70fe8d197d62cb) C:\Windows\system32\drivers\cfwids.sys
20:17:30.0874 3992 cfwids - ok
20:17:30.0936 3992 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
20:17:30.0936 3992 circlass - ok
20:17:30.0983 3992 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
20:17:30.0983 3992 CLFS - ok
20:17:31.0061 3992 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:17:31.0077 3992 clr_optimization_v2.0.50727_32 - ok
20:17:31.0155 3992 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:17:31.0248 3992 clr_optimization_v4.0.30319_32 - ok
20:17:31.0279 3992 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
20:17:31.0279 3992 CmBatt - ok
20:17:31.0311 3992 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
20:17:31.0311 3992 cmdide - ok
20:17:31.0357 3992 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys
20:17:31.0357 3992 CNG - ok
20:17:31.0420 3992 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
20:17:31.0420 3992 Compbatt - ok
20:17:31.0482 3992 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
20:17:31.0482 3992 CompositeBus - ok
20:17:31.0513 3992 COMSysApp - ok
20:17:31.0545 3992 cpntsrv - ok
20:17:31.0591 3992 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
20:17:31.0591 3992 crcdisk - ok
20:17:31.0669 3992 CryptSvc (a585bebf7d054bd9618eda0922d5484a) C:\Windows\system32\cryptsvc.dll
20:17:31.0669 3992 CryptSvc - ok
20:17:31.0701 3992 dbmang - ok
20:17:31.0763 3992 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
20:17:31.0779 3992 DcomLaunch - ok
20:17:31.0810 3992 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll
20:17:31.0810 3992 defragsvc - ok
20:17:31.0825 3992 DELL_A02 - ok
20:17:31.0857 3992 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
20:17:31.0857 3992 DfsC - ok
20:17:31.0888 3992 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll
20:17:31.0888 3992 Dhcp - ok
20:17:31.0935 3992 dirms_defragmentation - ok
20:17:31.0966 3992 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
20:17:31.0966 3992 discache - ok
20:17:32.0028 3992 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
20:17:32.0028 3992 Disk - ok
20:17:32.0044 3992 dns4meclient - ok
20:17:32.0091 3992 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll
20:17:32.0137 3992 Dnscache - ok
20:17:32.0184 3992 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll
20:17:32.0184 3992 dot3svc - ok
20:17:32.0200 3992 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll
20:17:32.0215 3992 DPS - ok
20:17:32.0262 3992 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
20:17:32.0262 3992 drmkaud - ok
20:17:32.0309 3992 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
20:17:32.0309 3992 DXGKrnl - ok
20:17:32.0387 3992 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll
20:17:32.0387 3992 EapHost - ok
20:17:32.0512 3992 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
20:17:32.0543 3992 ebdrv - ok
20:17:32.0574 3992 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe
20:17:32.0574 3992 EFS - ok
20:17:32.0715 3992 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe
20:17:32.0715 3992 ehRecvr - ok
20:17:32.0746 3992 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe
20:17:32.0746 3992 ehSched - ok
20:17:32.0777 3992 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
20:17:32.0793 3992 elxstor - ok
20:17:32.0808 3992 enecir (f13c945115b8a8c7c4427d5925f88f23) C:\Windows\system32\DRIVERS\enecir.sys
20:17:32.0808 3992 enecir - ok
20:17:32.0855 3992 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
20:17:32.0855 3992 ErrDev - ok
20:17:32.0917 3992 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll
20:17:32.0917 3992 EventSystem - ok
20:17:32.0964 3992 ewusbnet - ok
20:17:32.0980 3992 ew_hwusbdev - ok
20:17:33.0042 3992 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
20:17:33.0042 3992 exfat - ok
20:17:33.0073 3992 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
20:17:33.0073 3992 fastfat - ok
20:17:33.0151 3992 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe
20:17:33.0151 3992 Fax - ok
20:17:33.0183 3992 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
20:17:33.0183 3992 fdc - ok
20:17:33.0214 3992 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll
20:17:33.0214 3992 fdPHost - ok
20:17:33.0229 3992 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll
20:17:33.0229 3992 FDResPub - ok
20:17:33.0261 3992 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
20:17:33.0261 3992 FileInfo - ok
20:17:33.0276 3992 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
20:17:33.0276 3992 Filetrace - ok
20:17:33.0323 3992 FireTDI - ok
20:17:33.0339 3992 flashpnt - ok
20:17:33.0370 3992 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
20:17:33.0370 3992 flpydisk - ok
20:17:33.0417 3992 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
20:17:33.0432 3992 FltMgr - ok
20:17:33.0463 3992 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll
20:17:33.0479 3992 FontCache - ok
20:17:33.0557 3992 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
20:17:33.0557 3992 FontCache3.0.0.0 - ok
20:17:33.0573 3992 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
20:17:33.0588 3992 FsDepends - ok
20:17:33.0604 3992 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys
20:17:33.0682 3992 Fs_Rec - ok
20:17:33.0697 3992 ftsata2 - ok
20:17:33.0744 3992 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
20:17:33.0760 3992 fvevol - ok
20:17:33.0822 3992 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
20:17:33.0822 3992 gagp30kx - ok
20:17:33.0885 3992 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:17:33.0885 3992 GEARAspiWDM - ok
20:17:33.0947 3992 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll
20:17:34.0025 3992 gpsvc - ok
20:17:34.0150 3992 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
20:17:34.0259 3992 gupdate - ok
20:17:34.0290 3992 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe
20:17:34.0290 3992 gupdatem - ok
20:17:34.0337 3992 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
20:17:34.0337 3992 hcw85cir - ok
20:17:34.0399 3992 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
20:17:34.0415 3992 HdAudAddService - ok
20:17:34.0493 3992 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
20:17:34.0493 3992 HDAudBus - ok
20:17:34.0618 3992 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
20:17:34.0618 3992 HidBatt - ok
20:17:34.0680 3992 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
20:17:34.0680 3992 HidBth - ok
20:17:34.0758 3992 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
20:17:34.0758 3992 HidIr - ok
20:17:34.0789 3992 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll
20:17:34.0805 3992 hidserv - ok
20:17:34.0867 3992 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
20:17:34.0867 3992 HidUsb - ok
20:17:34.0914 3992 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll
20:17:34.0914 3992 hkmsvc - ok
20:17:34.0977 3992 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll
20:17:34.0992 3992 HomeGroupListener - ok
20:17:35.0055 3992 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll
20:17:35.0055 3992 HomeGroupProvider - ok
20:17:35.0148 3992 HP Health Check Service (0141816a095a3f5a83ffa5b4a47b8023) C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
20:17:35.0148 3992 HP Health Check Service - ok
20:17:35.0164 3992 hpdskflt (e1d82f0c8456abb03b7df5d623ca47d1) C:\Windows\system32\DRIVERS\hpdskflt.sys
20:17:35.0164 3992 hpdskflt - ok
20:17:35.0242 3992 HpqKbFiltr (1210960ff8928950d2a786895b0c424a) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
20:17:35.0242 3992 HpqKbFiltr - ok
20:17:35.0273 3992 hpqwmiex (fdf273a845f1ffcceadf363aaf47582f) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
20:17:35.0398 3992 hpqwmiex - ok
20:17:35.0445 3992 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
20:17:35.0445 3992 HpSAMD - ok
20:17:35.0476 3992 hpsrv (d1f817e61d52816996b8f1eba9a38276) C:\Windows\system32\Hpservice.exe
20:17:35.0569 3992 hpsrv - ok
20:17:35.0632 3992 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
20:17:35.0647 3992 HTTP - ok
20:17:35.0663 3992 huawei_enumerator - ok
20:17:35.0725 3992 hwdatacard - ok
20:17:35.0772 3992 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
20:17:35.0772 3992 hwpolicy - ok
20:17:35.0819 3992 hwusbdev - ok
20:17:35.0897 3992 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
20:17:35.0897 3992 i8042prt - ok
20:17:35.0928 3992 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
20:17:35.0928 3992 iaStorV - ok
20:17:35.0975 3992 icepack - ok
20:17:36.0069 3992 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:17:36.0256 3992 idsvc - ok
20:17:36.0287 3992 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
20:17:36.0287 3992 iirsp - ok
20:17:36.0365 3992 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll
20:17:36.0381 3992 IKEEXT - ok
20:17:36.0396 3992 iksysflt - ok
20:17:36.0459 3992 IntelC53 - ok
20:17:36.0490 3992 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
20:17:36.0490 3992 intelide - ok
20:17:36.0521 3992 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
20:17:36.0537 3992 intelppm - ok
20:17:36.0568 3992 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll
20:17:36.0568 3992 IPBusEnum - ok
20:17:36.0599 3992 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:17:36.0599 3992 IpFilterDriver - ok
20:17:36.0661 3992 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll
20:17:36.0677 3992 iphlpsvc - ok
20:17:36.0708 3992 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
20:17:36.0708 3992 IPMIDRV - ok
20:17:36.0724 3992 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
20:17:36.0739 3992 IPNAT - ok
20:17:36.0817 3992 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
20:17:36.0817 3992 iPod Service - ok
20:17:36.0880 3992 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
20:17:36.0880 3992 IRENUM - ok
20:17:36.0911 3992 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
20:17:36.0911 3992 isapnp - ok
20:17:36.0942 3992 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
20:17:36.0942 3992 iScsiPrt - ok
20:17:36.0973 3992 itchfltr - ok
20:17:37.0036 3992 JMCR (65da9fa42c0972fe5b9b7d6047f06f4c) C:\Windows\system32\DRIVERS\jmcr.sys
20:17:37.0051 3992 JMCR - ok
20:17:37.0098 3992 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
20:17:37.0098 3992 kbdclass - ok
20:17:37.0129 3992 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
20:17:37.0129 3992 kbdhid - ok
20:17:37.0176 3992 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
20:17:37.0176 3992 KeyIso - ok
20:17:37.0223 3992 klblmain - ok
20:17:37.0270 3992 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys
20:17:37.0285 3992 KSecDD - ok
20:17:37.0317 3992 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys
20:17:37.0317 3992 KSecPkg - ok
20:17:37.0363 3992 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll
20:17:37.0410 3992 KtmRm - ok
20:17:37.0473 3992 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\System32\srvsvc.dll
20:17:37.0473 3992 LanmanServer - ok
20:17:37.0519 3992 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll
20:17:37.0519 3992 LanmanWorkstation - ok
20:17:37.0644 3992 LightScribeService (83d8be94e1cbcbe2ea8372db1a95a159) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
20:17:37.0644 3992 LightScribeService - ok
20:17:37.0675 3992 lkclassads - ok
20:17:37.0785 3992 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
20:17:37.0800 3992 lltdio - ok
20:17:37.0831 3992 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll
20:17:37.0863 3992 lltdsvc - ok
20:17:37.0894 3992 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll
20:17:37.0894 3992 lmhosts - ok
20:17:37.0909 3992 lp6nds35 - ok
20:17:37.0972 3992 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
20:17:37.0972 3992 LSI_FC - ok
20:17:38.0003 3992 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
20:17:38.0003 3992 LSI_SAS - ok
20:17:38.0019 3992 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:17:38.0034 3992 LSI_SAS2 - ok
20:17:38.0065 3992 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:17:38.0065 3992 LSI_SCSI - ok
20:17:38.0112 3992 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
20:17:38.0112 3992 luafv - ok
20:17:38.0128 3992 lusbaudio - ok
20:17:38.0159 3992 LUsbKbd - ok
20:17:38.0221 3992 LVBulk - ok
20:17:38.0284 3992 ManyCam (c6d085c7045200143528136a43a65fde) C:\Windows\system32\DRIVERS\ManyCam.sys
20:17:38.0284 3992 ManyCam - ok
20:17:38.0315 3992 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys
20:17:38.0315 3992 MBAMProtector - ok
20:17:38.0424 3992 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
20:17:38.0424 3992 MBAMService - ok
20:17:38.0502 3992 McAfee SiteAdvisor Service (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:38.0518 3992 McAfee SiteAdvisor Service - ok
20:17:38.0643 3992 McComponentHostService (485405de203e88b3fe4294a2ea48d7ee) C:\Program Files\McAfee Security Scan\3.0.271\McCHSvc.exe
20:17:38.0643 3992 McComponentHostService - ok
20:17:38.0674 3992 McMPFSvc (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:38.0674 3992 McMPFSvc - ok
20:17:38.0689 3992 mcmscsvc (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:38.0705 3992 mcmscsvc - ok
20:17:38.0721 3992 McNaiAnn (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:38.0721 3992 McNaiAnn - ok
20:17:38.0799 3992 McNASvc (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:38.0799 3992 McNASvc - ok
20:17:38.0861 3992 McODS (5379a996f953da65f40cc4e848dc7590) C:\Program Files\McAfee\VirusScan\mcods.exe
20:17:38.0970 3992 McODS - ok
20:17:38.0986 3992 McProxy (7e6932eeda54c8eaf7dc6c2225261b85) C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
20:17:39.0001 3992 McProxy - ok
20:17:39.0064 3992 McShield (16767b4cb7ae8f388e091717db34ff6c) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
20:17:39.0064 3992 McShield - ok
20:17:39.0173 3992 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll
20:17:39.0251 3992 Mcx2Svc - ok
20:17:39.0298 3992 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
20:17:39.0298 3992 megasas - ok
20:17:39.0345 3992 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
20:17:39.0345 3992 MegaSR - ok
20:17:39.0423 3992 mfeapfk (36b47b1e9c537f8f2b4481084b8f7d22) C:\Windows\system32\drivers\mfeapfk.sys
20:17:39.0423 3992 mfeapfk - ok
20:17:39.0501 3992 mfeavfk (cde41293db871a75cd99eb0ce781356b) C:\Windows\system32\drivers\mfeavfk.sys
20:17:39.0516 3992 mfeavfk - ok
20:17:39.0547 3992 mfeavfk01 - ok
20:17:39.0594 3992 mfebopk (e22385f64bdf0ad81157479496e33c4a) C:\Windows\system32\drivers\mfebopk.sys
20:17:39.0594 3992 mfebopk - ok
20:17:39.0703 3992 mfefire (3f17534b8867854113df2b45fff3acf5) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
20:17:39.0703 3992 mfefire - ok
20:17:39.0750 3992 mfefirek (215666a8a85023ef019b510cbb67f678) C:\Windows\system32\drivers\mfefirek.sys
20:17:39.0750 3992 mfefirek - ok
20:17:39.0813 3992 mfehidk (37800fbb68d88e3c3e49bb9c97233e87) C:\Windows\system32\drivers\mfehidk.sys
20:17:39.0828 3992 mfehidk - ok
20:17:39.0859 3992 mfenlfk (b41bacc049cdb916a52b1448bf30d6ab) C:\Windows\system32\DRIVERS\mfenlfk.sys
20:17:39.0859 3992 mfenlfk - ok
20:17:39.0875 3992 mferkdet (47c91e229b129047f0138011ddf9f92f) C:\Windows\system32\drivers\mferkdet.sys
20:17:39.0891 3992 mferkdet - ok
20:17:39.0984 3992 mfevtp (9f09caa8dc12fc1626f82a5c212f6f9c) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
20:17:39.0984 3992 mfevtp - ok
20:17:40.0015 3992 mfewfpk (c2ff7473a60c0fb2df145ab686889653) C:\Windows\system32\drivers\mfewfpk.sys
20:17:40.0031 3992 mfewfpk - ok
20:17:40.0062 3992 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
20:17:40.0062 3992 MMCSS - ok
20:17:40.0093 3992 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
20:17:40.0093 3992 Modem - ok
20:17:40.0140 3992 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
20:17:40.0156 3992 monitor - ok
20:17:40.0218 3992 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
20:17:40.0218 3992 mouclass - ok
20:17:40.0281 3992 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
20:17:40.0281 3992 mouhid - ok
20:17:40.0359 3992 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
20:17:40.0359 3992 mountmgr - ok
20:17:40.0405 3992 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
20:17:40.0405 3992 mpio - ok
20:17:40.0437 3992 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
20:17:40.0437 3992 mpsdrv - ok
20:17:40.0530 3992 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll
20:17:40.0624 3992 MpsSvc - ok
20:17:40.0686 3992 mqdmbus - ok
20:17:40.0749 3992 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
20:17:40.0749 3992 MRxDAV - ok
20:17:40.0827 3992 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:17:40.0827 3992 mrxsmb - ok
20:17:40.0889 3992 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:17:40.0905 3992 mrxsmb10 - ok
20:17:40.0936 3992 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:17:40.0936 3992 mrxsmb20 - ok
20:17:41.0014 3992 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
20:17:41.0014 3992 msahci - ok
20:17:41.0061 3992 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
20:17:41.0076 3992 msdsm - ok
20:17:41.0107 3992 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe
20:17:41.0139 3992 MSDTC - ok
20:17:41.0217 3992 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
20:17:41.0232 3992 Msfs - ok
20:17:41.0263 3992 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
20:17:41.0263 3992 mshidkmdf - ok
20:17:41.0326 3992 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
20:17:41.0326 3992 msisadrv - ok
20:17:41.0404 3992 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll
20:17:41.0419 3992 MSiSCSI - ok
20:17:41.0451 3992 msiserver - ok
20:17:41.0529 3992 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
20:17:41.0529 3992 MSKSSRV - ok
20:17:41.0560 3992 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
20:17:41.0560 3992 MSPCLOCK - ok
20:17:41.0607 3992 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
20:17:41.0622 3992 MSPQM - ok
20:17:41.0653 3992 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
20:17:41.0653 3992 MsRPC - ok
20:17:41.0716 3992 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
20:17:41.0716 3992 mssmbios - ok
20:17:41.0763 3992 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
20:17:41.0763 3992 MSTEE - ok
20:17:41.0809 3992 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
20:17:41.0809 3992 MTConfig - ok
20:17:41.0856 3992 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
20:17:41.0856 3992 Mup - ok
20:17:41.0903 3992 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll
20:17:41.0919 3992 napagent - ok
20:17:41.0997 3992 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
20:17:41.0997 3992 NativeWifiP - ok
20:17:42.0075 3992 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
20:17:42.0090 3992 NDIS - ok
20:17:42.0137 3992 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
20:17:42.0137 3992 NdisCap - ok
20:17:42.0199 3992 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
20:17:42.0199 3992 NdisTapi - ok
20:17:42.0246 3992 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
20:17:42.0246 3992 Ndisuio - ok
20:17:42.0277 3992 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
20:17:42.0293 3992 NdisWan - ok
20:17:42.0324 3992 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
20:17:42.0324 3992 NDProxy - ok
20:17:42.0355 3992 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
20:17:42.0355 3992 NetBIOS - ok
20:17:42.0402 3992 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
20:17:42.0402 3992 NetBT - ok
20:17:42.0449 3992 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
20:17:42.0449 3992 Netlogon - ok
20:17:42.0527 3992 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll
20:17:42.0527 3992 Netman - ok
20:17:42.0558 3992 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll
20:17:42.0574 3992 netprofm - ok
20:17:42.0621 3992 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:17:42.0699 3992 NetTcpPortSharing - ok
20:17:42.0745 3992 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
20:17:42.0745 3992 nfrd960 - ok
20:17:42.0792 3992 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll
20:17:42.0792 3992 NlaSvc - ok
20:17:42.0823 3992 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
20:17:42.0823 3992 Npfs - ok
20:17:42.0855 3992 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll
20:17:42.0855 3992 nsi - ok
20:17:42.0870 3992 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
20:17:42.0870 3992 nsiproxy - ok
20:17:42.0933 3992 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
20:17:42.0964 3992 Ntfs - ok
20:17:42.0979 3992 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
20:17:42.0979 3992 Null - ok
20:17:43.0042 3992 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys
20:17:43.0042 3992 NVENETFD - ok
20:17:43.0104 3992 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
20:17:43.0104 3992 nvraid - ok
20:17:43.0151 3992 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
20:17:43.0151 3992 nvstor - ok
20:17:43.0198 3992 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
20:17:43.0213 3992 nv_agp - ok
20:17:43.0291 3992 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
20:17:43.0401 3992 odserv - ok
20:17:43.0416 3992 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
20:17:43.0416 3992 ohci1394 - ok
20:17:43.0432 3992 ood2000 - ok
20:17:43.0479 3992 oracleorahomepagingserver - ok
20:17:43.0510 3992 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:17:43.0588 3992 ose - ok
20:17:43.0635 3992 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
20:17:43.0635 3992 p2pimsvc - ok
20:17:43.0650 3992 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll
20:17:43.0650 3992 p2psvc - ok
20:17:43.0681 3992 PAR1284 - ok
20:17:43.0728 3992 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
20:17:43.0728 3992 Parport - ok
20:17:43.0775 3992 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
20:17:43.0775 3992 partmgr - ok
20:17:43.0806 3992 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
20:17:43.0806 3992 Parvdm - ok
20:17:43.0837 3992 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll
20:17:43.0837 3992 PcaSvc - ok
20:17:43.0884 3992 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
20:17:43.0900 3992 pci - ok
20:17:43.0931 3992 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
20:17:43.0931 3992 pciide - ok
20:17:43.0962 3992 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
20:17:43.0962 3992 pcmcia - ok
20:17:43.0993 3992 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
20:17:44.0009 3992 pcw - ok
20:17:44.0056 3992 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
20:17:44.0056 3992 PEAUTH - ok
20:17:44.0087 3992 pilogsrv - ok
20:17:44.0149 3992 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll
20:17:44.0165 3992 pla - ok
20:17:44.0212 3992 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll
20:17:44.0212 3992 PlugPlay - ok
20:17:44.0290 3992 PnkBstrA (831883b107684301f48ace752c963984) C:\Windows\system32\PnkBstrA.exe
20:17:44.0290 3992 PnkBstrA - ok
20:17:44.0321 3992 PnkBstrB (e24106a5eaecddff00b25497049dd65f) C:\Windows\system32\PnkBstrB.exe
20:17:44.0321 3992 PnkBstrB - ok
20:17:44.0352 3992 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll
20:17:44.0368 3992 PNRPAutoReg - ok
20:17:44.0383 3992 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
20:17:44.0399 3992 PNRPsvc - ok
20:17:44.0446 3992 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll
20:17:44.0508 3992 PolicyAgent - ok
20:17:44.0524 3992 portmapper - ok
20:17:44.0539 3992 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll
20:17:44.0539 3992 Power - ok
20:17:44.0633 3992 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
20:17:44.0633 3992 PptpMiniport - ok
20:17:44.0664 3992 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
20:17:44.0680 3992 Processor - ok
20:17:44.0758 3992 ProfSvc (43ca4ccc22d52fb58e8988f0198851d0) C:\Windows\system32\profsvc.dll
20:17:44.0758 3992 ProfSvc - ok
20:17:44.0805 3992 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
20:17:44.0805 3992 ProtectedStorage - ok
20:17:44.0836 3992 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
20:17:44.0851 3992 Psched - ok
20:17:44.0914 3992 PxHelp20 (40fedd328f98245ad201cf5f9f311724) C:\Windows\system32\Drivers\PxHelp20.sys
20:17:44.0914 3992 PxHelp20 - ok
20:17:44.0992 3992 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
20:17:45.0007 3992 ql2300 - ok
20:17:45.0039 3992 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
20:17:45.0039 3992 ql40xx - ok
20:17:45.0085 3992 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll
20:17:45.0085 3992 QWAVE - ok
20:17:45.0117 3992 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
20:17:45.0117 3992 QWAVEdrv - ok
20:17:45.0148 3992 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
20:17:45.0148 3992 RasAcd - ok
20:17:45.0163 3992 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:17:45.0163 3992 RasAgileVpn - ok
20:17:45.0179 3992 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll
20:17:45.0195 3992 RasAuto - ok
20:17:45.0257 3992 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:17:45.0257 3992 Rasl2tp - ok
20:17:45.0335 3992 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll
20:17:45.0335 3992 RasMan - ok
20:17:45.0366 3992 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
20:17:45.0366 3992 RasPppoe - ok
20:17:45.0413 3992 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
20:17:45.0413 3992 RasSstp - ok
20:17:45.0475 3992 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
20:17:45.0475 3992 rdbss - ok
20:17:45.0507 3992 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
20:17:45.0507 3992 rdpbus - ok
20:17:45.0553 3992 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:17:45.0553 3992 RDPCDD - ok
20:17:45.0616 3992 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
20:17:45.0616 3992 RDPENCDD - ok
20:17:45.0647 3992 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
20:17:45.0663 3992 RDPREFMP - ok
20:17:45.0694 3992 RDPWD (244c83332f44589ae98fc347f11b2693) C:\Windows\system32\drivers\RDPWD.sys
20:17:45.0709 3992 RDPWD - ok
20:17:45.0741 3992 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
20:17:45.0756 3992 rdyboost - ok
20:17:45.0787 3992 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll
20:17:45.0787 3992 RemoteAccess - ok
20:17:45.0819 3992 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll
20:17:45.0834 3992 RemoteRegistry - ok
20:17:45.0881 3992 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
20:17:45.0881 3992 RFCOMM - ok
20:17:45.0959 3992 RichVideo (498eb62a160674e793fa40fd65390625) C:\Program Files\CyberLink\Shared files\RichVideo.exe
20:17:45.0975 3992 RichVideo - ok
20:17:46.0006 3992 ROB_A - ok
20:17:46.0053 3992 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll
20:17:46.0068 3992 RpcEptMapper - ok
20:17:46.0099 3992 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe
20:17:46.0099 3992 RpcLocator - ok
20:17:46.0131 3992 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
20:17:46.0146 3992 RpcSs - ok
20:17:46.0193 3992 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
20:17:46.0209 3992 rspndr - ok
20:17:46.0240 3992 RTL8023xp - ok
20:17:46.0302 3992 RTL8167 (26a9d6227d12b9d9da5a81bb9b55d810) C:\Windows\system32\DRIVERS\Rt86win7.sys
20:17:46.0302 3992 RTL8167 - ok
20:17:46.0333 3992 SaiNtBus - ok
20:17:46.0365 3992 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
20:17:46.0365 3992 SamSs - ok
20:17:46.0427 3992 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
20:17:46.0427 3992 sbp2port - ok
20:17:46.0489 3992 SBSDWSCService (794d4b48dfb6e999537c7c3947863463) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
20:17:46.0521 3992 SBSDWSCService - ok
20:17:46.0536 3992 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll
20:17:46.0552 3992 SCardSvr - ok
20:17:46.0630 3992 SCDEmu (20b2751cd4c8f3fd989739ca661b9f30) C:\Windows\system32\drivers\SCDEmu.sys
20:17:46.0630 3992 SCDEmu - ok
20:17:46.0677 3992 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
20:17:46.0677 3992 scfilter - ok
20:17:46.0723 3992 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll
20:17:46.0739 3992 Schedule - ok
20:17:46.0755 3992 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
20:17:46.0755 3992 SCPolicySvc - ok
20:17:46.0817 3992 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys
20:17:46.0817 3992 sdbus - ok
20:17:46.0864 3992 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll
20:17:46.0879 3992 SDRSVC - ok
20:17:46.0895 3992 se44nd5 - ok
20:17:46.0942 3992 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
20:17:46.0942 3992 secdrv - ok
20:17:46.0973 3992 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll
20:17:46.0973 3992 seclogon - ok
20:17:47.0035 3992 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll
20:17:47.0035 3992 SENS - ok
20:17:47.0098 3992 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll
20:17:47.0113 3992 SensrSvc - ok
20:17:47.0145 3992 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
20:17:47.0145 3992 Serenum - ok
20:17:47.0160 3992 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
20:17:47.0160 3992 Serial - ok
20:17:47.0207 3992 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
20:17:47.0207 3992 sermouse - ok
20:17:47.0238 3992 servicemgr - ok
20:17:47.0285 3992 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll
20:17:47.0285 3992 SessionEnv - ok
20:17:47.0316 3992 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
20:17:47.0332 3992 sffdisk - ok
20:17:47.0347 3992 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
20:17:47.0347 3992 sffp_mmc - ok
20:17:47.0363 3992 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
20:17:47.0363 3992 sffp_sd - ok
20:17:47.0379 3992 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
20:17:47.0379 3992 sfloppy - ok
20:17:47.0394 3992 sfrem01 - ok
20:17:47.0457 3992 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll
20:17:47.0472 3992 SharedAccess - ok
20:17:47.0519 3992 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll
20:17:47.0535 3992 ShellHWDetection - ok
20:17:47.0566 3992 Si3114r5 - ok
20:17:47.0628 3992 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
20:17:47.0628 3992 sisagp - ok
20:17:47.0644 3992 sisperf - ok
20:17:47.0691 3992 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:17:47.0691 3992 SiSRaid2 - ok
20:17:47.0722 3992 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
20:17:47.0737 3992 SiSRaid4 - ok
20:17:47.0800 3992 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
20:17:47.0800 3992 Smb - ok
20:17:47.0862 3992 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe
20:17:47.0862 3992 SNMPTRAP - ok
20:17:47.0893 3992 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
20:17:47.0893 3992 spldr - ok
20:17:47.0971 3992 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe
20:17:47.0987 3992 Spooler - ok
20:17:48.0096 3992 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe
20:17:48.0127 3992 sppsvc - ok
20:17:48.0159 3992 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll
20:17:48.0159 3992 sppuinotify - ok
20:17:48.0205 3992 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
20:17:48.0221 3992 srv - ok
20:17:48.0237 3992 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
20:17:48.0252 3992 srv2 - ok
20:17:48.0299 3992 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS
20:17:48.0299 3992 SrvHsfHDA - ok
20:17:48.0346 3992 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
20:17:48.0361 3992 SrvHsfV92 - ok
20:17:48.0393 3992 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
20:17:48.0408 3992 SrvHsfWinac - ok
20:17:48.0424 3992 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
20:17:48.0424 3992 srvnet - ok
20:17:48.0471 3992 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll
20:17:48.0486 3992 SSDPSRV - ok
20:17:48.0517 3992 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll
20:17:48.0517 3992 SstpSvc - ok
20:17:48.0627 3992 STacSV (05ae358cd777bf8857f512a18e1de7aa) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe
20:17:48.0627 3992 STacSV - ok
20:17:48.0705 3992 Steam Client Service - ok
20:17:48.0767 3992 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
20:17:48.0767 3992 stexstor - ok
20:17:48.0829 3992 STHDA (e69a606872650b46de54ec15dcc93529) C:\Windows\system32\DRIVERS\stwrt.sys
20:17:48.0845 3992 STHDA - ok
20:17:48.0907 3992 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll
20:17:48.0923 3992 StiSvc - ok
20:17:48.0954 3992 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
20:17:48.0954 3992 swenum - ok
20:17:49.0001 3992 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll
20:17:49.0001 3992 swprv - ok
20:17:49.0079 3992 SynTP (067cb9d745407a8c1b26e89a6a2ce152) C:\Windows\system32\DRIVERS\SynTP.sys
20:17:49.0079 3992 SynTP - ok
20:17:49.0141 3992 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll
20:17:49.0157 3992 SysMain - ok
20:17:49.0188 3992 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll
20:17:49.0188 3992 TabletInputService - ok
20:17:49.0219 3992 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll
20:17:49.0235 3992 TapiSrv - ok
20:17:49.0251 3992 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll
20:17:49.0266 3992 TBS - ok
20:17:49.0344 3992 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys
20:17:49.0344 3992 Tcpip - ok
20:17:49.0391 3992 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys
20:17:49.0391 3992 TCPIP6 - ok
20:17:49.0453 3992 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
20:17:49.0469 3992 tcpipreg - ok
20:17:49.0500 3992 TdmService - ok
20:17:49.0563 3992 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
20:17:49.0563 3992 TDPIPE - ok
20:17:49.0594 3992 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys
20:17:49.0594 3992 TDTCP - ok
20:17:49.0641 3992 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
20:17:49.0641 3992 tdx - ok
20:17:49.0672 3992 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
20:17:49.0687 3992 TermDD - ok
20:17:49.0734 3992 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll
20:17:49.0750 3992 TermService - ok
20:17:49.0765 3992 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll
20:17:49.0781 3992 Themes - ok
20:17:49.0797 3992 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
20:17:49.0812 3992 THREADORDER - ok
20:17:49.0828 3992 tifm21 - ok
20:17:49.0890 3992 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll
20:17:49.0890 3992 TrkWks - ok
20:17:49.0937 3992 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe
20:17:49.0953 3992 TrustedInstaller - ok
20:17:49.0984 3992 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:17:49.0984 3992 tssecsrv - ok
20:17:50.0046 3992 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
20:17:50.0062 3992 TsUsbFlt - ok
20:17:50.0109 3992 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
20:17:50.0109 3992 tunnel - ok
20:17:50.0171 3992 tvtfilter - ok
20:17:50.0202 3992 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
20:17:50.0218 3992 uagp35 - ok
20:17:50.0265 3992 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
20:17:50.0265 3992 udfs - ok
20:17:50.0311 3992 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe
20:17:50.0311 3992 UI0Detect - ok
20:17:50.0374 3992 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
20:17:50.0374 3992 uliagpkx - ok
20:17:50.0436 3992 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
20:17:50.0436 3992 umbus - ok
20:17:50.0499 3992 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
20:17:50.0499 3992 UmPass - ok
20:17:50.0545 3992 UNDPX2A - ok
20:17:50.0592 3992 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll
20:17:50.0592 3992 upnphost - ok
20:17:50.0670 3992 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
20:17:50.0670 3992 USBAAPL - ok
20:17:50.0701 3992 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
20:17:50.0701 3992 usbccgp - ok
20:17:50.0733 3992 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
20:17:50.0733 3992 usbcir - ok
20:17:50.0764 3992 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
20:17:50.0764 3992 usbehci - ok
20:17:50.0826 3992 usbfilter (64b43327dda15af730ce22b052a5efd4) C:\Windows\system32\DRIVERS\usbfilter.sys
20:17:50.0826 3992 usbfilter - ok
20:17:50.0904 3992 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
20:17:50.0904 3992 usbhub - ok
20:17:50.0935 3992 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
20:17:50.0935 3992 usbohci - ok
20:17:50.0967 3992 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
20:17:50.0967 3992 usbprint - ok
20:17:50.0998 3992 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:17:50.0998 3992 USBSTOR - ok
20:17:51.0029 3992 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
20:17:51.0029 3992 usbuhci - ok
20:17:51.0091 3992 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
20:17:51.0091 3992 usbvideo - ok
20:17:51.0123 3992 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll
20:17:51.0138 3992 UxSms - ok
20:17:51.0185 3992 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
20:17:51.0185 3992 VaultSvc - ok
20:17:51.0216 3992 VC4CB104 - ok
20:17:51.0232 3992 vclone - ok
20:17:51.0279 3992 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
20:17:51.0279 3992 vdrvroot - ok
20:17:51.0325 3992 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe
20:17:51.0341 3992 vds - ok
20:17:51.0372 3992 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
20:17:51.0372 3992 vga - ok
20:17:51.0403 3992 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
20:17:51.0403 3992 VgaSave - ok
20:17:51.0419 3992 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
20:17:51.0435 3992 vhdmp - ok
20:17:51.0481 3992 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
20:17:51.0481 3992 viaagp - ok
20:17:51.0497 3992 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
20:17:51.0513 3992 ViaC7 - ok
20:17:51.0544 3992 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
20:17:51.0544 3992 viaide - ok
20:17:51.0591 3992 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
20:17:51.0591 3992 volmgr - ok
20:17:51.0622 3992 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
20:17:51.0637 3992 volmgrx - ok
20:17:51.0669 3992 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
20:17:51.0684 3992 volsnap - ok
20:17:51.0715 3992 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
20:17:51.0715 3992 vsmraid - ok
20:17:51.0778 3992 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe
20:17:51.0809 3992 VSS - ok
20:17:51.0809 3992 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
20:17:51.0825 3992 vwifibus - ok
20:17:51.0871 3992 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
20:17:51.0871 3992 vwififlt - ok
20:17:51.0903 3992 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
20:17:51.0903 3992 vwifimp - ok
20:17:51.0949 3992 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll
20:17:51.0965 3992 W32Time - ok
20:17:51.0996 3992 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
20:17:51.0996 3992 WacomPen - ok
20:17:52.0059 3992 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
20:17:52.0059 3992 WANARP - ok
20:17:52.0074 3992 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
20:17:52.0090 3992 Wanarpv6 - ok
20:17:52.0183 3992 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe
20:17:52.0339 3992 WatAdminSvc - ok
20:17:52.0417 3992 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe
20:17:52.0433 3992 wbengine - ok
20:17:52.0464 3992 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll
20:17:52.0480 3992 WbioSrvc - ok
20:17:52.0527 3992 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll
20:17:52.0542 3992 wcncsvc - ok
20:17:52.0558 3992 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll
20:17:52.0558 3992 WcsPlugInService - ok
20:17:52.0605 3992 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
20:17:52.0605 3992 Wd - ok
20:17:52.0636 3992 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
20:17:52.0651 3992 Wdf01000 - ok
20:17:52.0667 3992 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
20:17:52.0683 3992 WdiServiceHost - ok
20:17:52.0683 3992 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
20:17:52.0683 3992 WdiSystemHost - ok
20:17:52.0745 3992 wdmaud - ok
20:17:52.0807 3992 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll
20:17:52.0823 3992 WebClient - ok
20:17:52.0839 3992 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll
20:17:52.0854 3992 Wecsvc - ok
20:17:52.0885 3992 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll
20:17:52.0885 3992 wercplsupport - ok
20:17:52.0948 3992 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll
20:17:52.0948 3992 WerSvc - ok
20:17:53.0010 3992 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
20:17:53.0010 3992 WfpLwf - ok
20:17:53.0041 3992 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
20:17:53.0041 3992 WIMMount - ok
20:17:53.0151 3992 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll
20:17:53.0197 3992 WinDefend - ok
20:17:53.0213 3992 WinHttpAutoProxySvc - ok
20:17:53.0260 3992 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll
20:17:53.0275 3992 Winmgmt - ok
20:17:53.0338 3992 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll
20:17:53.0353 3992 WinRM - ok
20:17:53.0447 3992 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
20:17:53.0447 3992 WinUsb - ok
20:17:53.0494 3992 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll
20:17:53.0525 3992 Wlansvc - ok
20:17:53.0665 3992 wlidsvc (fb01d4ae207b9efdbabfc55dc95c7e31) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:17:53.0681 3992 wlidsvc - ok
20:17:53.0743 3992 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
20:17:53.0759 3992 WmiAcpi - ok
20:17:53.0821 3992 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe
20:17:53.0821 3992 wmiApSrv - ok
20:17:53.0853 3992 wmp54gssvc - ok
20:17:53.0931 3992 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe
20:17:53.0946 3992 WMPNetworkSvc - ok
20:17:53.0977 3992 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll
20:17:53.0977 3992 WPCSvc - ok
20:17:54.0024 3992 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll
20:17:54.0024 3992 WPDBusEnum - ok
20:17:54.0055 3992 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
20:17:54.0055 3992 ws2ifsl - ok
20:17:54.0055 3992 WscNetDr - ok
20:17:54.0118 3992 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll
20:17:54.0133 3992 wscsvc - ok
20:17:54.0133 3992 WSearch - ok
20:17:54.0243 3992 wuauserv (3026418a50c5b4761befa632cedb7406) C:\Windows\system32\wuaueng.dll
20:17:54.0258 3992 wuauserv - ok
20:17:54.0305 3992 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
20:17:54.0305 3992 WudfPf - ok
20:17:54.0367 3992 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:17:54.0383 3992 WUDFRd - ok
20:17:54.0445 3992 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll
20:17:54.0461 3992 wudfsvc - ok
20:17:54.0492 3992 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll
20:17:54.0492 3992 WwanSvc - ok
20:17:54.0570 3992 MBR (0x1B8) (9e916435c55f606e17f4b87708c22000) \Device\Harddisk0\DR0
20:17:54.0601 3992 \Device\Harddisk0\DR0 - ok
20:17:54.0633 3992 Boot (0x1200) (11f597453d1a6040ba1c2563273c5021) \Device\Harddisk0\DR0\Partition0
20:17:54.0633 3992 \Device\Harddisk0\DR0\Partition0 - ok
20:17:54.0664 3992 Boot (0x1200) (2ee1e6b654086f43d3c35611a31e7e8e) \Device\Harddisk0\DR0\Partition1
20:17:54.0664 3992 \Device\Harddisk0\DR0\Partition1 - ok
20:17:54.0695 3992 Boot (0x1200) (d2f6ae8f6d154ea01c373ef713e3da31) \Device\Harddisk0\DR0\Partition2
20:17:54.0711 3992 \Device\Harddisk0\DR0\Partition2 - ok
20:17:54.0711 3992 Boot (0x1200) (880f72f47b20415fc59526216f4e3168) \Device\Harddisk0\DR0\Partition3
20:17:54.0726 3992 \Device\Harddisk0\DR0\Partition3 - ok
20:17:54.0726 3992 ============================================================
20:17:54.0726 3992 Scan finished
20:17:54.0726 3992 ============================================================
20:17:54.0757 5396 Detected object count: 0
20:17:54.0757 5396 Actual detected object count: 0
This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
I haven't been redirected since my last post and everything out of place seems to have stopped, I have run the scan and it said that it found 8 infected files, found the log file and this is all it says: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK Thanks Angus
Please work your way through the following steps
  • Hold down the Windows key (has the Windows symbol on it) and press the "R" key. A Run box will open. Type in Notepad and press Enter.
  • Copy the text provided in the code box below and paste it into Notepad (make sure you include Windows Registry Editor Version 5.00.
Windows Registry Editor Version 5.00

"netsvcs"=hex(7):41,00,65,00,4c,00,6f,00,6f,00,6b,00,75,00,70,00,53,00,76,00,\
  63,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,6f,00,70,00,53,00,76,00,63,\
  00,00,00,53,00,43,00,50,00,6f,00,6c,00,69,00,63,00,79,00,53,00,76,00,63,00,\
  00,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,73,00,65,00,72,00,76,00,65,00,72,\
  00,00,00,67,00,70,00,73,00,76,00,63,00,00,00,49,00,4b,00,45,00,45,00,58,00,\
  54,00,00,00,41,00,75,00,64,00,69,00,6f,00,53,00,72,00,76,00,00,00,46,00,61,\
  00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,\
  69,00,6e,00,67,00,43,00,6f,00,6d,00,70,00,61,00,74,00,69,00,62,00,69,00,6c,\
  00,69,00,74,00,79,00,00,00,49,00,61,00,73,00,00,00,49,00,72,00,6d,00,6f,00,\
  6e,00,00,00,4e,00,6c,00,61,00,00,00,4e,00,74,00,6d,00,73,00,73,00,76,00,63,\
  00,00,00,4e,00,57,00,43,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,\
  69,00,6f,00,6e,00,00,00,4e,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6e,\
  00,74,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6f,00,00,00,52,00,61,00,\
  73,00,6d,00,61,00,6e,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,61,00,63,\
  00,63,00,65,00,73,00,73,00,00,00,53,00,45,00,4e,00,53,00,00,00,53,00,68,00,\
  61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,52,\
  00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,\
  73,00,72,00,76,00,00,00,57,00,6d,00,69,00,00,00,57,00,6d,00,64,00,6d,00,50,\
  00,6d,00,53,00,70,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,\
  69,00,63,00,65,00,00,00,77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,\
  00,42,00,49,00,54,00,53,00,00,00,53,00,68,00,65,00,6c,00,6c,00,48,00,57,00,\
  44,00,65,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,6f,00,67,\
  00,6f,00,6e,00,48,00,6f,00,75,00,72,00,73,00,00,00,50,00,43,00,41,00,75,00,\
  64,00,69,00,74,00,00,00,68,00,65,00,6c,00,70,00,73,00,76,00,63,00,00,00,75,\
  00,70,00,6c,00,6f,00,61,00,64,00,6d,00,67,00,72,00,00,00,69,00,70,00,68,00,\
  6c,00,70,00,73,00,76,00,63,00,00,00,73,00,65,00,63,00,6c,00,6f,00,67,00,6f,\
  00,6e,00,00,00,41,00,70,00,70,00,49,00,6e,00,66,00,6f,00,00,00,6d,00,73,00,\
  69,00,73,00,63,00,73,00,69,00,00,00,4d,00,4d,00,43,00,53,00,53,00,00,00,77,\
  00,65,00,72,00,63,00,70,00,6c,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,\
  00,00,45,00,61,00,70,00,48,00,6f,00,73,00,74,00,00,00,50,00,72,00,6f,00,66,\
  00,53,00,76,00,63,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,\
  00,00,68,00,6b,00,6d,00,73,00,76,00,63,00,00,00,53,00,65,00,73,00,73,00,69,\
  00,6f,00,6e,00,45,00,6e,00,76,00,00,00,77,00,69,00,6e,00,6d,00,67,00,6d,00,\
  74,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,54,00,68,00,65,\
  00,6d,00,65,00,73,00,00,00,42,00,44,00,45,00,53,00,56,00,43,00,00,00,41,00,\
  70,00,70,00,4d,00,67,00,6d,00,74,00,00,00,00,00
  • Save the text in Notepad as fix.reg, change the "Save as Type" to "All Files" and select your desktop as the save location.
  • An icon will appear on your desktop called "fix.reg".
  • Double click on the "fix.reg" icon.
  • You will be asked if you wish to merge the contents of the file to the registry. Click "Yes" or "OK".
  • You should then receive a message informing you that the merge was successful.
  • Next, please reboot your machine.
  • Once you have rebooted, you may delete the fix.reg file.
Once you have completed the steps above, please disable your security programs and run ComboFix again. If it asks you to allow it to update please do so.

Please post the log that is created in your next reply.
ComboFix 12-04-14.01 - angus 17/04/2012 11:30:41.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3580.2594 [GMT 10:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-03-17 to 2012-04-17 )))))))))))))))))))))))))))))))
.
.
2012-04-17 01:37 . 2012-04-17 01:37 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-16 06:29 . 2012-04-16 06:29 ——– d—–w- c:\program files\ESET
2012-04-14 09:35 . 2012-04-17 01:37 ——– d—–w- c:\users\angus\AppData\Local\temp
2012-04-14 09:13 . 2011-04-25 02:18 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2012-04-14 08:08 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-14 08:08 . 2012-03-01 05:37 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-04-14 08:08 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-14 08:08 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-14 08:08 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-14 08:08 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-13 06:13 . 2012-04-13 06:13 ——– d—–w- c:\windows\en
2012-04-13 06:10 . 2012-04-13 06:10 537432 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DXSETUP.exe
2012-04-13 06:10 . 2012-04-13 06:10 1801048 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\dsetup32.dll
2012-04-13 06:10 . 2012-04-13 06:10 89944 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DSETUP.dll
2012-04-13 05:25 . 2012-04-13 05:25 ——– d—–w- c:\program files\iPod
2012-04-13 05:25 . 2012-04-13 05:26 ——– d—–w- c:\program files\iTunes
2012-04-13 04:44 . 2012-04-13 04:44 ——– d—–w- c:\program files\Synaptics
2012-04-02 05:42 . 2012-04-11 07:33 14664 —-a-w- c:\windows\stinger.sys
2012-04-02 05:41 . 2012-04-13 03:33 ——– d—–w- c:\program files\stinger
2012-04-01 02:50 . 2012-04-01 02:50 ——– d—–w- c:\programdata\Recovery
2012-03-31 14:33 . 2012-04-11 08:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2012-03-31 14:33 . 2012-03-31 14:33 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-03-31 10:22 . 2012-03-31 10:22 ——– d—–w- c:\users\angus\AppData\Roaming\Malwarebytes
2012-03-31 10:21 . 2012-03-31 10:21 ——– d—–w- c:\programdata\Malwarebytes
2012-03-31 10:21 . 2012-04-04 05:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-03-31 10:21 . 2012-04-13 01:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-03-31 09:51 . 2012-03-31 09:51 ——– d—–w- c:\program files\CCleaner
2012-03-29 16:01 . 2012-04-13 04:39 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-13 04:39 . 2011-08-07 07:25 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-02 05:41 . 2010-04-19 07:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2012-04-02 05:41 . 2010-01-05 08:04 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2012-03-08 08:50 . 2012-03-08 08:50 49016 —-a-w- c:\windows\system32\sirenacm.dll
2012-03-08 08:37 . 2012-03-08 08:37 302448 —-a-w- c:\windows\WLXPGSS.SCR
2012-02-17 05:34 . 2012-03-17 03:01 826880 —-a-w- c:\windows\system32\rdpcore.dll
2012-02-17 04:14 . 2012-03-17 03:01 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:13 . 2012-03-17 03:01 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 05:38 . 2012-03-17 03:01 1077248 —-a-w- c:\windows\system32\DWrite.dll
2012-02-07 01:02 . 2012-02-07 01:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 03:54 . 2012-03-17 03:01 2343424 —-a-w- c:\windows\system32\win32k.sys
2012-01-25 05:32 . 2012-03-17 03:01 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-01-25 05:32 . 2012-03-17 03:01 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-01-25 05:27 . 2012-03-17 03:01 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2011-11-21 04:04 . 2011-12-09 09:59 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.271\SSScheduler.exe [2012-3-14 274328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"WallpaperStyle"= 2
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^angus^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\angus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-01-04 06:51 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 02:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-20 11:28 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 21:50 54576 —-a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-07-16 00:51 1668664 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2010-07-21 06:52 1797008 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-26 19:09 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2009-06-17 19:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 05:56 462408 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
2011-11-22 07:18 1318816 —-a-w- c:\program files\McAfee.com\Agent\mcagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 04:28 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2009-07-02 19:32 98304 —-a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-11-04 05:34 1242448 —-a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 03:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2010-05-27 05:31 1721640 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2009-07-22 01:33 458844 —-a-w- c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut]
2009-05-20 05:16 222504 ——w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2009-07-23 18:04 498744 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253600]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 116136]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.271\McCHSvc.exe [2012-03-13 237272]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-04-02 87656]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-09 1343400]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 165680]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 64880]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 160608]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2012-04-02 159608]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-07-17 29472]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 57600]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 59904]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 338176]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-23 167936]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 28344]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
NETSVCS REQUIRES REPAIRS - current entries shown
AeLookupSvc
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Ias
Irmon
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
SENS
Sharedaccess
SRService
Tapisrv
Wmi
WmdmPmSp
CBN
portmapper
TdmService
vclone
sfrem01
cpntsrv
SaiNtBus
servicemgr
lp6nds35
ATIBTCAP
klblmain
asuskeyboardservice
tifm21
caboagp
se44nd5
pilogsrv
VC4CB104
atiavpci
itchfltr
lusbaudio
freebsd
pdlnemsg
hpwirelessmgr
mgabg
osaio
messenger
ISAMSvc
ood2000
IntelC53
bobo
PAR1284
puscsrvc
wdmaud
icepack
ROB_A
ftsata2
dirms_defragmentation
tvtfilter
TIEHDUSB
proxyhostdriver
usbser
db2ntsecserver
teefer
hdthermal
LVBulk
dbmang
FireTDI
e1express
oracleorahomepagingserver
RTL8023xp
arrayssl_vpn_service3,0,1,9
sisperf
wmp54gssvc
Si3114r5
mqdmbus
bt
AR5416
lkclassads
WscNetDr
UNDPX2A
LUsbKbd
flashpnt
DELL_A02
dns4meclient
iksysflt
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
wercplsupport
EapHost
ProfSvc
schedule
hkmsvc
SessionEnv
winmgmt
browser
Themes
BDESVC
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 04:39]
.
2012-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44]
.
2012-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44]
.
2012-04-16 c:\windows\Tasks\vtscheduletask.job
- c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-02-21 04:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_AU&c=94&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = ;*.local
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\angus\AppData\Roaming\Mozilla\Firefox\Profiles\wxjv5vxp.default\
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109985
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 049b126b00000000000006037f8ee659
FF - user.js: extensions.BabylonToolbar_i.hardId - 049b126b00000000000006037f8ee659
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15379
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1712:30
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2291357997-1775983430-1860472803-1000\Software\SecuROM\License information*]
"datasecu"=hex:bf,e9,a2,e9,f9,ff,a5,4e,bb,f3,9f,04,74,61,28,be,87,f9,59,76,1e,
02,26,26,30,99,33,5c,8a,89,b5,6a,35,6c,eb,0d,c8,dc,32,03,63,3a,9f,a6,64,99,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-04-17 11:38:33
ComboFix-quarantined-files.txt 2012-04-17 01:38
ComboFix2.txt 2012-04-14 09:58
.
Pre-Run: 341,962,104,832 bytes free
Post-Run: 341,918,445,568 bytes free
.
- - End Of File - - 7832243D3993D8EC0DC7784FF680B121
My deepest apologies, I missed an important line in that code box, so it didn't actually do the registry merge it was supposed to. Let's try that one more time with the corrected code below:



Please work your way through the following steps
  • Hold down the Windows key (has the Windows symbol on it) and press the "R" key. A Run box will open. Type in Notepad and press Enter.
  • Copy the text provided in the code box below and paste it into Notepad (make sure you include Windows Registry Editor Version 5.00.
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
"netsvcs"=hex(7):41,00,65,00,4c,00,6f,00,6f,00,6b,00,75,00,70,00,53,00,76,00,\
  63,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,6f,00,70,00,53,00,76,00,63,\
  00,00,00,53,00,43,00,50,00,6f,00,6c,00,69,00,63,00,79,00,53,00,76,00,63,00,\
  00,00,6c,00,61,00,6e,00,6d,00,61,00,6e,00,73,00,65,00,72,00,76,00,65,00,72,\
  00,00,00,67,00,70,00,73,00,76,00,63,00,00,00,49,00,4b,00,45,00,45,00,58,00,\
  54,00,00,00,41,00,75,00,64,00,69,00,6f,00,53,00,72,00,76,00,00,00,46,00,61,\
  00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,\
  69,00,6e,00,67,00,43,00,6f,00,6d,00,70,00,61,00,74,00,69,00,62,00,69,00,6c,\
  00,69,00,74,00,79,00,00,00,49,00,61,00,73,00,00,00,49,00,72,00,6d,00,6f,00,\
  6e,00,00,00,4e,00,6c,00,61,00,00,00,4e,00,74,00,6d,00,73,00,73,00,76,00,63,\
  00,00,00,4e,00,57,00,43,00,57,00,6f,00,72,00,6b,00,73,00,74,00,61,00,74,00,\
  69,00,6f,00,6e,00,00,00,4e,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6e,\
  00,74,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6f,00,00,00,52,00,61,00,\
  73,00,6d,00,61,00,6e,00,00,00,52,00,65,00,6d,00,6f,00,74,00,65,00,61,00,63,\
  00,63,00,65,00,73,00,73,00,00,00,53,00,45,00,4e,00,53,00,00,00,53,00,68,00,\
  61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,52,\
  00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,\
  73,00,72,00,76,00,00,00,57,00,6d,00,69,00,00,00,57,00,6d,00,64,00,6d,00,50,\
  00,6d,00,53,00,70,00,00,00,54,00,65,00,72,00,6d,00,53,00,65,00,72,00,76,00,\
  69,00,63,00,65,00,00,00,77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,\
  00,42,00,49,00,54,00,53,00,00,00,53,00,68,00,65,00,6c,00,6c,00,48,00,57,00,\
  44,00,65,00,74,00,65,00,63,00,74,00,69,00,6f,00,6e,00,00,00,4c,00,6f,00,67,\
  00,6f,00,6e,00,48,00,6f,00,75,00,72,00,73,00,00,00,50,00,43,00,41,00,75,00,\
  64,00,69,00,74,00,00,00,68,00,65,00,6c,00,70,00,73,00,76,00,63,00,00,00,75,\
  00,70,00,6c,00,6f,00,61,00,64,00,6d,00,67,00,72,00,00,00,69,00,70,00,68,00,\
  6c,00,70,00,73,00,76,00,63,00,00,00,73,00,65,00,63,00,6c,00,6f,00,67,00,6f,\
  00,6e,00,00,00,41,00,70,00,70,00,49,00,6e,00,66,00,6f,00,00,00,6d,00,73,00,\
  69,00,73,00,63,00,73,00,69,00,00,00,4d,00,4d,00,43,00,53,00,53,00,00,00,77,\
  00,65,00,72,00,63,00,70,00,6c,00,73,00,75,00,70,00,70,00,6f,00,72,00,74,00,\
  00,00,45,00,61,00,70,00,48,00,6f,00,73,00,74,00,00,00,50,00,72,00,6f,00,66,\
  00,53,00,76,00,63,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6c,00,65,00,\
  00,00,68,00,6b,00,6d,00,73,00,76,00,63,00,00,00,53,00,65,00,73,00,73,00,69,\
  00,6f,00,6e,00,45,00,6e,00,76,00,00,00,77,00,69,00,6e,00,6d,00,67,00,6d,00,\
  74,00,00,00,62,00,72,00,6f,00,77,00,73,00,65,00,72,00,00,00,54,00,68,00,65,\
  00,6d,00,65,00,73,00,00,00,42,00,44,00,45,00,53,00,56,00,43,00,00,00,41,00,\
  70,00,70,00,4d,00,67,00,6d,00,74,00,00,00,00,00
  • Save the text in Notepad as fix.reg, change the "Save as Type" to "All Files" and select your desktop as the save location.
  • An icon will appear on your desktop called "fix.reg".
  • Double click on the "fix.reg" icon.
  • You will be asked if you wish to merge the contents of the file to the registry. Click "Yes" or "OK".
  • You should then receive a message informing you that the merge was successful.
  • Next, please reboot your machine.
  • Once you have rebooted, you may delete the fix.reg file.
Once you have completed the steps above, please disable your security programs and run ComboFix again. If it asks you to allow it to update please do so.

Please post the log that is created in your next reply.
ComboFix 12-04-14.01 - angus 18/04/2012 20:29:53.3.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3580.2314 [GMT 10:00] Running from: c:\users\[removed]\Desktop\Interesting things\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2012-03-18 to 2012-04-18 ))))))))))))))))))))))))))))))) . . 2012-04-18 10:37 . 2012-04-18 10:37 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-16 06:29 . 2012-04-16 06:29 ——– d—–w- c:\program files\ESET 2012-04-14 09:35 . 2012-04-18 10:37 ——– d—–w- c:\users\angus\AppData\Local\temp 2012-04-14 09:13 . 2011-04-25 02:18 338944 —-a-w- c:\windows\system32\drivers\afd.sys 2012-04-14 08:08 . 2012-03-01 05:46 19824 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-14 08:08 . 2012-03-01 05:37 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-04-14 08:08 . 2012-03-01 05:33 159232 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-14 08:08 . 2012-03-01 05:29 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-14 08:08 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-14 08:08 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-13 06:13 . 2012-04-13 06:13 ——– d—–w- c:\windows\en 2012-04-13 06:10 . 2012-04-13 06:10 537432 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DXSETUP.exe 2012-04-13 06:10 . 2012-04-13 06:10 1801048 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\dsetup32.dll 2012-04-13 06:10 . 2012-04-13 06:10 89944 —-a-w- c:\program files\Common Files\Windows Live\.cache\28eae1191cd193c01\DSETUP.dll 2012-04-13 05:25 . 2012-04-13 05:25 ——– d—–w- c:\program files\iPod 2012-04-13 05:25 . 2012-04-13 05:26 ——– d—–w- c:\program files\iTunes 2012-04-13 04:44 . 2012-04-13 04:44 ——– d—–w- c:\program files\Synaptics 2012-04-02 05:42 . 2012-04-11 07:33 14664 —-a-w- c:\windows\stinger.sys 2012-04-02 05:41 . 2012-04-13 03:33 ——– d—–w- c:\program files\stinger 2012-04-01 02:50 . 2012-04-01 02:50 ——– d—–w- c:\programdata\Recovery 2012-03-31 14:33 . 2012-04-11 08:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2012-03-31 14:33 . 2012-03-31 14:33 ——– d—–w- c:\program files\Spybot - Search & Destroy 2012-03-31 10:22 . 2012-03-31 10:22 ——– d—–w- c:\users\angus\AppData\Roaming\Malwarebytes 2012-03-31 10:21 . 2012-03-31 10:21 ——– d—–w- c:\programdata\Malwarebytes 2012-03-31 10:21 . 2012-04-04 05:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-31 10:21 . 2012-04-13 01:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-03-31 09:51 . 2012-03-31 09:51 ——– d—–w- c:\program files\CCleaner 2012-03-29 16:01 . 2012-04-13 04:39 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-13 04:39 . 2011-08-07 07:25 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-02 05:41 . 2010-04-19 07:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-04-02 05:41 . 2010-01-05 08:04 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-03-08 08:50 . 2012-03-08 08:50 49016 —-a-w- c:\windows\system32\sirenacm.dll 2012-03-08 08:37 . 2012-03-08 08:37 302448 —-a-w- c:\windows\WLXPGSS.SCR 2012-02-17 05:34 . 2012-03-17 03:01 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-17 04:14 . 2012-03-17 03:01 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-17 04:13 . 2012-03-17 03:01 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-10 05:38 . 2012-03-17 03:01 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-02-07 01:02 . 2012-02-07 01:02 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-03 03:54 . 2012-03-17 03:01 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-01-25 05:32 . 2012-03-17 03:01 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-01-25 05:32 . 2012-03-17 03:01 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-01-25 05:27 . 2012-03-17 03:01 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2011-11-21 04:04 . 2011-12-09 09:59 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-05-27 1721640] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.271\SSScheduler.exe [2012-3-14 274328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system] "WallpaperStyle"= 2 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^angus^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\angus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-01-04 06:51 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier] 2011-04-20 02:48 58656 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2012-02-20 11:28 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2008-12-08 21:50 54576 —-a-w- c:\program files\Hp\HP Software Update\hpwuschd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR] 2009-07-16 00:51 1668664 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint] 2010-07-21 06:52 1797008 —-a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2012-03-26 19:09 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel] 2009-06-17 19:13 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware] 2012-04-04 05:56 462408 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe] 2011-11-22 07:18 1318816 —-a-w- c:\program files\McAfee.com\Agent\mcagent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE] 2010-04-12 08:40 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 04:28 421888 —-a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2009-07-02 19:32 98304 —-a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] 2011-11-04 05:34 1242448 —-a-w- c:\program files\Steam\Steam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2011-06-09 03:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2010-05-27 05:31 1721640 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp] 2009-07-22 01:33 458844 —-a-w- c:\program files\IDT\WDM\sttray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut] 2009-05-20 05:16 222504 ——w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant] 2009-07-23 18:04 498744 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 253600] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 135664] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 116136] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.271\McCHSvc.exe [2012-03-13 237272] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-04-02 87656] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-09 1343400] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 165680] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 64880] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-02 176128] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 160608] S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2012-04-02 159608] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-07-17 29472] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 57600] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 59904] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 338176] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-23 167936] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 28344] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-04-18 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 04:39] . 2012-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44] . 2012-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-23 07:44] . 2012-04-18 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-02-21 04:25] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com.au/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_AU&c=94&bd=Pavilion&pf=cnnb uInternet Settings,ProxyOverride = ;*.local Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\angus\AppData\Roaming\Mozilla\Firefox\Profiles\wxjv5vxp.default\ FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p= FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109985 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - 049b126b00000000000006037f8ee659 FF - user.js: extensions.BabylonToolbar_i.hardId - 049b126b00000000000006037f8ee659 FF - user.js: extensions.BabylonToolbar_i.instlDay - 15379 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1712:30 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9 FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2291357997-1775983430-1860472803-1000\Software\SecuROM\License information*] "datasecu"=hex:bf,e9,a2,e9,f9,ff,a5,4e,bb,f3,9f,04,74,61,28,be,87,f9,59,76,1e, 02,26,26,30,99,33,5c,8a,89,b5,6a,35,6c,eb,0d,c8,dc,32,03,63,3a,9f,a6,64,99,\ "rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-18 20:39:15 ComboFix-quarantined-files.txt 2012-04-18 10:39 ComboFix2.txt 2012-04-17 01:38 ComboFix3.txt 2012-04-14 09:58 . Pre-Run: 341,959,639,040 bytes free Post-Run: 341,919,162,368 bytes free . - - End Of File - - A343A1F3509F53ED26BE7ED7C467FC41
Fantastic! Things look much better now.

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click the Windows Key + R to open the Run box.
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.



Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI