This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My comp may be infected, requesting help

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think that my comp may be infected. The Hijack this report as shown.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:29 AM, on 5/21/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\NetWorx\networx.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\Downloads\HiJackThis.exe
C:\Windows\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1060933
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O2 - BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Neel\AppData\Roaming\Complitly\Complitly.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKCU\..\Run: [Google Update] "C:\Users\Neel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Neel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{983C7EA8-54AD-4AB7-8ED4-849D2436A231}: NameServer = 218.248.255.147 218.248.255.146
O17 - HKLM\System\CS1\Services\Tcpip\..\{983C7EA8-54AD-4AB7-8ED4-849D2436A231}: NameServer = 218.248.255.147 218.248.255.146
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: vToolbarUpdater11.0.2 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe

–
End of file - 10287 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, neel385

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Can you please describe your problem in further detail?

—————————————————————————————————
By browsing speed is very slow and even when no applications seem to be running,there is unaccounted for net activity. I have carried out various virus scans which have failed to show up anything and on trying a root-kit remover, I got partial success when, it was unable to clear all root-kits. I'm attaching the report: +—————————————————- | Trend Micro RootkitBuster | Module version: 5.0.0.1061 | Computer Name: NEEL-PC | OS version: 6.1-7600 | User Name: Neel +—————————————————- –== Dump Hidden MBR, Hidden Files and Alternate Data Streams on C:\ ==– MBR unsupported disk type [FILE_STREAM]: FullPath : C:\ProgramData\TEMP:0B4227B4:$DATA FullPathLength: 27 DesiredAccess : 0x0 Options : 0x0 Attributes : 0x2030 ShareAccess : 0x0 Type : 0x0 [FILE_STREAM]: FullPath : C:\Users\All Users\TEMP:0B4227B4:$DATA FullPathLength: 31 DesiredAccess : 0x0 Options : 0x0 Attributes : 0x2030 ShareAccess : 0x0 Type : 0x0 [FILE_STREAM]: FullPath : C:\Users\Neel\Downloads\drweb-cureit.exe:Zone.Identifier:$DATA FullPathLength: 40 DesiredAccess : 0x0 Options : 0x0 Attributes : 0x20 ShareAccess : 0x0 Type : 0x0 [FILE_STREAM]: FullPath : C:\Users\Neel\Downloads\RootkitBuster_v5_1061.exe:Zone.Identifier:$DATA FullPathLength: 49 DesiredAccess : 0x0 Options : 0x0 Attributes : 0x20 ShareAccess : 0x0 Type : 0x0 4 hidden files found. –== Dump Hidden Registry Value on HKLM ==– [HIDDEN_REGISTRY][Hidden Reg Key]: KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\523 SubKey : 523 FullLength: 90 [HIDDEN_REGISTRY][Hidden Reg Value]: KeyPath : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Root : 70fbf94 SubKey : Parameters ValueName : DhcpDomain Data : home ValueType : 1 AccessType: 0 FullLength: 69 DataSize : 10 [HIDDEN_REGISTRY][Hidden Reg Value]: KeyPath : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Root : 70fbf94 SubKey : Parameters ValueName : DhcpNameServer Data : 192.168.0.1 ValueType : 1 AccessType: 0 FullLength: 69 DataSize : 24 3 hidden registry entries found. –== Dump Hidden Process ==– No hidden processes found. –== Dump Hidden Driver ==– No hidden drivers found. –== Service Win32 API Hook List ==– [HOOKED_SERVICE_API]: Service API : ZwAdjustPrivilegesToken Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c19875 CurrentHandler : 0x8fc4cf26 ServiceNumber : 0xc ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwAlpcConnectPort Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c5f821 CurrentHandler : 0x8fc4d112 ServiceNumber : 0x16 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwConnectPort Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c84894 CurrentHandler : 0x8fc4c286 ServiceNumber : 0x3b ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwCreateFile Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c56e82 CurrentHandler : 0x8fc4cb8c ServiceNumber : 0x42 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwCreateSection Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c3cce3 CurrentHandler : 0x8fc4c940 ServiceNumber : 0x54 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwCreateSymbolicLinkObject Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c1b059 CurrentHandler : 0x8fc4dc8a ServiceNumber : 0x56 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwCreateThread Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82ce6c0e CurrentHandler : 0x8fc4bc72 ServiceNumber : 0x57 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwCreateThreadEx Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c44d51 CurrentHandler : 0x8fc4d340 ServiceNumber : 0x58 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwLoadDriver Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82bad279 CurrentHandler : 0x8fc4d6bc ServiceNumber : 0x9b ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwMakeTemporaryObject Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c13363 CurrentHandler : 0x8fc4c54e ServiceNumber : 0xa4 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwNotifyChangeKey Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c05ce5 CurrentHandler : 0x92421004 ServiceNumber : 0xac ModuleName : avgidsshimx.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwNotifyChangeMultipleKeys Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c0508f CurrentHandler : 0x924210d4 ServiceNumber : 0xad ModuleName : avgidsshimx.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwOpenFile Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c865c4 CurrentHandler : 0x8fc4cd68 ServiceNumber : 0xb3 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwOpenProcess Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c8d531 CurrentHandler : 0x92420d76 ServiceNumber : 0xbe ModuleName : avgidsshimx.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwOpenSection Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c8b1ba CurrentHandler : 0x8fc4c7e8 ServiceNumber : 0xc2 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwSetSystemInformation Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c96df5 CurrentHandler : 0x8fc4d9a8 ServiceNumber : 0x15e ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwShutdownSystem Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82d0d64b CurrentHandler : 0x8fc4c4b8 ServiceNumber : 0x168 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwSystemDebugControl Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys OriginalHandler : 0x82c152fc CurrentHandler : 0x8fc4c6d4 ServiceNumber : 0x170 ModuleName : cmdguard.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwTerminateProcess Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c6db3d CurrentHandler : 0x92420e1e ServiceNumber : 0x172 ModuleName : avgidsshimx.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwTerminateThread Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c808e4 CurrentHandler : 0x92420eba ServiceNumber : 0x173 ModuleName : avgidsshimx.sys SDTType : 0x0 [HOOKED_SERVICE_API]: Service API : ZwWriteVirtualMemory Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys OriginalHandler : 0x82c935b5 CurrentHandler : 0x92420f56 ServiceNumber : 0x18f ModuleName : avgidsshimx.sys SDTType : 0x0 No hidden operating system service hooks found. –== Dump Hidden Port ==– No hidden ports found. –== Dump Kernel Code Patching ==– No kernel code patching detected. –== Dump Hidden Services ==– No hidden services found. I am in a bit of a hurry as I am re-locating and I will not be able to access the internet from the 25th of this month till about the 20th of next month. Thanks.. Neel.
Hi Neel, I'm sorry but due to the difference in timezone, I don't think I can go through it for you as quick as I could have hoped for. This is because it usually takes more than 3 days or more depending on the nature of infection to successfully eradicate malware.

We can still carry on as much as we can. It's up to you.

Hello there,

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi,

I would like to ask, did you perform an uninstall procedure for AVG 2011?

Also how did you install Comodo? Did you just click next all the way or specified only firewall to be installed?

I'm asking this is because I think the Comodo AV and AVG may have clashed together, so I just want to be clear that you only have Comodo act as your firewall and AVG as AV.


===================================================

You have ( µTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================
Thanks for the prompt reply… No I did not perform an uninstall procedure for AVG 2011…a pop up asked me to update to 2012 and I did after verifying that i was downloading the real stuff. I do not remember as to how I installed Comodo, but my intention was to only install the Firewall. So yes, my intention is for Comodo to act as Firewall and AVG as AV. Point about P2P is well taken. I generally keep it OFF and put it on only when I want to, but I get your point about the content. Will not use it as for now. Thank You.
Ok, thanks. Go to your right-hand corner, click on the Taskbar, right click on Comodo icon, go to Configurations, then see if you have Internet Security selected or Firewall Security. Just wanted to make sure that the configuration is correct.
O.K. Got it! The report is pasted below. It did not find anything. 22:56:22.0579 5672 TDSS rootkit removing tool [removed] May 23 2012 08:15:30 22:56:23.0467 5672 ============================================================ 22:56:23.0467 5672 Current date / time: 2012/05/23 22:56:23.0467 22:56:23.0467 5672 SystemInfo: 22:56:23.0467 5672 22:56:23.0467 5672 OS Version: 6.1.7600 ServicePack: 0.0 22:56:23.0468 5672 Product type: Workstation 22:56:23.0468 5672 ComputerName: NEEL-PC 22:56:23.0468 5672 UserName: Neel 22:56:23.0469 5672 Windows directory: C:\Windows 22:56:23.0469 5672 System windows directory: C:\Windows 22:56:23.0469 5672 Processor architecture: Intel x86 22:56:23.0469 5672 Number of processors: 1 22:56:23.0469 5672 Page size: 0x1000 22:56:23.0469 5672 Boot type: Normal boot 22:56:23.0469 5672 ============================================================ 22:56:24.0617 5672 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 22:56:24.0754 5672 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1D92650, SectorsPerTrack: 0x3F, TracksPerCylinder: 0x1, Type 'W' 22:56:30.0803 5672 ============================================================ 22:56:30.0803 5672 \Device\Harddisk0\DR0: 22:56:30.0814 5672 MBR partitions: 22:56:30.0814 5672 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4E1EDEC 22:56:30.0834 5672 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x4E1EE6A, BlocksNum 0x23293F8 22:56:30.0849 5672 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x71482A1, BlocksNum 0x23C235F 22:56:30.0849 5672 \Device\Harddisk1\DR1: 22:56:30.0850 5672 MBR partitions: 22:56:30.0850 5672 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x747059C1 22:56:30.0850 5672 ============================================================ 22:56:30.0891 5672 C: <-> \Device\Harddisk0\DR0\Partition0 22:56:30.0932 5672 D: <-> \Device\Harddisk0\DR0\Partition1 22:56:30.0969 5672 E: <-> \Device\Harddisk0\DR0\Partition2 22:56:30.0979 5672 G: <-> \Device\Harddisk1\DR1\Partition0 22:56:30.0980 5672 ============================================================ 22:56:30.0980 5672 Initialize success 22:56:30.0980 5672 ============================================================ 22:56:32.0978 4280 ============================================================ 22:56:32.0978 4280 Scan started 22:56:32.0978 4280 Mode: Manual; 22:56:32.0978 4280 ============================================================ 22:56:33.0967 4280 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 22:56:33.0982 4280 1394ohci - ok 22:56:34.0037 4280 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 22:56:34.0040 4280 ACPI - ok 22:56:34.0108 4280 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 22:56:34.0110 4280 AcpiPmi - ok 22:56:34.0249 4280 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 22:56:34.0252 4280 AdobeARMservice - ok 22:56:34.0354 4280 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 22:56:34.0357 4280 AdobeFlashPlayerUpdateSvc - ok 22:56:34.0446 4280 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 22:56:34.0457 4280 adp94xx - ok 22:56:34.0501 4280 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 22:56:34.0514 4280 adpahci - ok 22:56:34.0578 4280 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 22:56:34.0584 4280 adpu320 - ok 22:56:34.0639 4280 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 22:56:34.0641 4280 AeLookupSvc - ok 22:56:34.0769 4280 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 22:56:34.0773 4280 AFD - ok 22:56:34.0824 4280 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 22:56:34.0827 4280 agp440 - ok 22:56:34.0888 4280 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 22:56:34.0891 4280 aic78xx - ok 22:56:34.0954 4280 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 22:56:34.0957 4280 ALG - ok 22:56:34.0978 4280 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 22:56:34.0980 4280 aliide - ok 22:56:35.0033 4280 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 22:56:35.0036 4280 amdagp - ok 22:56:35.0059 4280 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 22:56:35.0061 4280 amdide - ok 22:56:35.0122 4280 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 22:56:35.0125 4280 AmdK8 - ok 22:56:35.0161 4280 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 22:56:35.0165 4280 AmdPPM - ok 22:56:35.0219 4280 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\drivers\amdsata.sys 22:56:35.0222 4280 amdsata - ok 22:56:35.0351 4280 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 22:56:35.0366 4280 amdsbs - ok 22:56:35.0397 4280 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\drivers\amdxata.sys 22:56:35.0399 4280 amdxata - ok 22:56:35.0506 4280 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 22:56:35.0509 4280 AppID - ok 22:56:35.0561 4280 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 22:56:35.0577 4280 AppIDSvc - ok 22:56:35.0613 4280 Appinfo (7dead9e3f65dcb2794f2711003bbf650) C:\Windows\System32\appinfo.dll 22:56:35.0615 4280 Appinfo - ok 22:56:35.0678 4280 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 22:56:35.0685 4280 AppMgmt - ok 22:56:35.0741 4280 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 22:56:35.0744 4280 arc - ok 22:56:35.0782 4280 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 22:56:35.0789 4280 arcsas - ok 22:56:35.0832 4280 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 22:56:35.0834 4280 AsyncMac - ok 22:56:35.0889 4280 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 22:56:35.0890 4280 atapi - ok 22:56:36.0065 4280 AudioEndpointBuilder (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 22:56:36.0090 4280 AudioEndpointBuilder - ok 22:56:36.0108 4280 Audiosrv (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 22:56:36.0114 4280 Audiosrv - ok 22:56:36.0565 4280 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe 22:56:36.0602 4280 AVGIDSAgent - ok 22:56:36.0785 4280 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\Windows\system32\DRIVERS\avgidsdriverx.sys 22:56:36.0788 4280 AVGIDSDriver - ok 22:56:36.0829 4280 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\Windows\system32\DRIVERS\avgidsfilterx.sys 22:56:36.0832 4280 AVGIDSFilter - ok 22:56:36.0960 4280 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\Windows\system32\DRIVERS\avgidshx.sys 22:56:36.0962 4280 AVGIDSHX - ok 22:56:36.0994 4280 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\Windows\system32\DRIVERS\avgidsshimx.sys 22:56:36.0996 4280 AVGIDSShim - ok 22:56:37.0036 4280 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\Windows\system32\DRIVERS\avgldx86.sys 22:56:37.0039 4280 Avgldx86 - ok 22:56:37.0075 4280 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\Windows\system32\DRIVERS\avgmfx86.sys 22:56:37.0076 4280 Avgmfx86 - ok 22:56:37.0117 4280 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\Windows\system32\DRIVERS\avgrkx86.sys 22:56:37.0185 4280 Avgrkx86 - ok 22:56:37.0224 4280 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\Windows\system32\DRIVERS\avgtdix.sys 22:56:37.0275 4280 Avgtdix - ok 22:56:37.0388 4280 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe 22:56:37.0391 4280 avgwd - ok 22:56:37.0458 4280 AxInstSV (dd6a431b43e34b91a767d1ce33728175) C:\Windows\System32\AxInstSV.dll 22:56:37.0471 4280 AxInstSV - ok 22:56:37.0557 4280 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 22:56:37.0571 4280 b06bdrv - ok 22:56:37.0630 4280 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 22:56:37.0645 4280 b57nd60x - ok 22:56:37.0707 4280 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 22:56:37.0710 4280 BDESVC - ok 22:56:37.0767 4280 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 22:56:37.0769 4280 Beep - ok 22:56:37.0851 4280 BFE (85ac71c045ceb054ed48a7841aae0c11) C:\Windows\System32\bfe.dll 22:56:37.0873 4280 BFE - ok 22:56:37.0957 4280 BITS (53f476476f55a27f580661bde09c4ec4) C:\Windows\System32\qmgr.dll 22:56:37.0983 4280 BITS - ok 22:56:38.0036 4280 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 22:56:38.0038 4280 blbdrive - ok 22:56:38.0063 4280 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 22:56:38.0065 4280 bowser - ok 22:56:38.0089 4280 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 22:56:38.0093 4280 BrFiltLo - ok 22:56:38.0150 4280 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 22:56:38.0154 4280 BrFiltUp - ok 22:56:38.0209 4280 Browser (598e1280e7ff3744f4b8329366cc5635) C:\Windows\System32\browser.dll 22:56:38.0223 4280 Browser - ok 22:56:38.0275 4280 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 22:56:38.0285 4280 Brserid - ok 22:56:38.0326 4280 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 22:56:38.0330 4280 BrSerWdm - ok 22:56:38.0391 4280 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 22:56:38.0394 4280 BrUsbMdm - ok 22:56:38.0414 4280 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 22:56:38.0417 4280 BrUsbSer - ok 22:56:38.0455 4280 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 22:56:38.0458 4280 BTHMODEM - ok 22:56:38.0534 4280 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 22:56:38.0537 4280 bthserv - ok 22:56:38.0597 4280 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 22:56:38.0600 4280 cdfs - ok 22:56:38.0641 4280 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 22:56:38.0643 4280 cdrom - ok 22:56:38.0717 4280 CertPropSvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 22:56:38.0720 4280 CertPropSvc - ok 22:56:38.0766 4280 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 22:56:38.0768 4280 circlass - ok 22:56:38.0831 4280 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 22:56:38.0834 4280 CLFS - ok 22:56:38.0998 4280 CLPSLS (be465a17fda2e79ed49053cbec7e9335) C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe 22:56:39.0006 4280 CLPSLS - ok 22:56:39.0100 4280 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:56:39.0104 4280 clr_optimization_v2.0.50727_32 - ok 22:56:39.0225 4280 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 22:56:39.0227 4280 CmBatt - ok 22:56:39.0337 4280 cmdAgent (907324001ae25ac5959c91eaa34cabae) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe 22:56:39.0352 4280 cmdAgent - ok 22:56:39.0507 4280 cmdGuard (ed042da80d9d6a087e83df395ceefd65) C:\Windows\system32\DRIVERS\cmdguard.sys 22:56:39.0512 4280 cmdGuard - ok 22:56:39.0525 4280 cmdHlp (ed6b6a222cb9adf6751e02ad478a89fb) C:\Windows\system32\DRIVERS\cmdhlp.sys 22:56:39.0527 4280 cmdHlp - ok 22:56:39.0557 4280 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 22:56:39.0560 4280 cmdide - ok 22:56:39.0590 4280 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 22:56:39.0594 4280 CNG - ok 22:56:39.0631 4280 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 22:56:39.0634 4280 Compbatt - ok 22:56:39.0677 4280 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 22:56:39.0678 4280 CompositeBus - ok 22:56:39.0705 4280 COMSysApp - ok 22:56:39.0751 4280 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 22:56:39.0754 4280 crcdisk - ok 22:56:39.0831 4280 CryptSvc (9c231178ce4fb385f4b54b0a9080b8a4) C:\Windows\system32\cryptsvc.dll 22:56:39.0847 4280 CryptSvc - ok 22:56:39.0889 4280 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys 22:56:39.0898 4280 CSC - ok 22:56:39.0981 4280 CscService (56fb5f222ea30d3d3fc459879772cb73) C:\Windows\System32\cscsvc.dll 22:56:39.0999 4280 CscService - ok 22:56:40.0071 4280 DcomLaunch (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 22:56:40.0086 4280 DcomLaunch - ok 22:56:40.0144 4280 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 22:56:40.0161 4280 defragsvc - ok 22:56:40.0248 4280 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 22:56:40.0250 4280 DfsC - ok 22:56:40.0332 4280 Dhcp (c56495fbd770712367cad35e5de72da6) C:\Windows\system32\dhcpcore.dll 22:56:40.0348 4280 Dhcp - ok 22:56:40.0388 4280 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 22:56:40.0390 4280 discache - ok 22:56:40.0472 4280 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 22:56:40.0475 4280 Disk - ok 22:56:40.0561 4280 Dnscache (d0722e963d3c6145446874241401b209) C:\Windows\System32\dnsrslvr.dll 22:56:40.0568 4280 Dnscache - ok 22:56:40.0636 4280 dot3svc (4408c85c21eea48eb0ce486baeef0502) C:\Windows\System32\dot3svc.dll 22:56:40.0670 4280 dot3svc - ok 22:56:40.0732 4280 DPS (7fa81c6e11caa594adb52084da73a1e5) C:\Windows\system32\dps.dll 22:56:40.0746 4280 DPS - ok 22:56:40.0818 4280 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 22:56:40.0820 4280 drmkaud - ok 22:56:40.0917 4280 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys 22:56:40.0923 4280 DXGKrnl - ok 22:56:41.0007 4280 E100B (20de769b84960606d8dbb2aec123021a) C:\Windows\system32\DRIVERS\e100b325.sys 22:56:41.0010 4280 E100B - ok 22:56:41.0069 4280 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 22:56:41.0077 4280 EapHost - ok 22:56:41.0237 4280 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 22:56:41.0316 4280 ebdrv - ok 22:56:41.0603 4280 EFS (f42309c4191c506b71db5d1126d26318) C:\Windows\System32\lsass.exe 22:56:41.0607 4280 EFS - ok 22:56:41.0706 4280 ehRecvr (3a74a6e33685662b125a3269b1f2114f) C:\Windows\ehome\ehRecvr.exe 22:56:41.0734 4280 ehRecvr - ok 22:56:41.0806 4280 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 22:56:41.0819 4280 ehSched - ok 22:56:41.0960 4280 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 22:56:41.0983 4280 elxstor - ok 22:56:42.0013 4280 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 22:56:42.0018 4280 ErrDev - ok 22:56:42.0107 4280 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 22:56:42.0123 4280 EventSystem - ok 22:56:42.0180 4280 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 22:56:42.0185 4280 exfat - ok 22:56:42.0217 4280 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 22:56:42.0223 4280 fastfat - ok 22:56:42.0308 4280 Fax (f7ea23cc5e6bf2181f3f399d54f6efc1) C:\Windows\system32\fxssvc.exe 22:56:42.0333 4280 Fax - ok 22:56:42.0391 4280 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 22:56:42.0394 4280 fdc - ok 22:56:42.0452 4280 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 22:56:42.0455 4280 fdPHost - ok 22:56:42.0484 4280 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 22:56:42.0487 4280 FDResPub - ok 22:56:42.0520 4280 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 22:56:42.0522 4280 FileInfo - ok 22:56:42.0572 4280 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 22:56:42.0574 4280 Filetrace - ok 22:56:42.0596 4280 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 22:56:42.0598 4280 flpydisk - ok 22:56:42.0645 4280 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 22:56:42.0647 4280 FltMgr - ok 22:56:42.0743 4280 FontCache (b6512a85815fdc3d560c3705f5bdb93d) C:\Windows\system32\FntCache.dll 22:56:42.0808 4280 FontCache - ok 22:56:43.0019 4280 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 22:56:43.0035 4280 FontCache3.0.0.0 - ok 22:56:43.0080 4280 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 22:56:43.0088 4280 FsDepends - ok 22:56:43.0132 4280 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 22:56:43.0133 4280 Fs_Rec - ok 22:56:43.0176 4280 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys 22:56:43.0179 4280 fvevol - ok 22:56:43.0243 4280 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 22:56:43.0246 4280 gagp30kx - ok 22:56:43.0320 4280 gpsvc (8ba3c04702bf8f927ab36ae8313ca4ee) C:\Windows\System32\gpsvc.dll 22:56:43.0340 4280 gpsvc - ok 22:56:43.0522 4280 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 22:56:43.0524 4280 gupdate - ok 22:56:43.0567 4280 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 22:56:43.0569 4280 gupdatem - ok 22:56:43.0623 4280 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 22:56:43.0635 4280 gusvc - ok 22:56:43.0683 4280 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 22:56:43.0686 4280 hcw85cir - ok 22:56:43.0765 4280 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 22:56:43.0768 4280 HdAudAddService - ok 22:56:43.0836 4280 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 22:56:43.0838 4280 HDAudBus - ok 22:56:43.0865 4280 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 22:56:43.0868 4280 HidBatt - ok 22:56:43.0918 4280 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 22:56:43.0925 4280 HidBth - ok 22:56:43.0971 4280 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 22:56:43.0974 4280 HidIr - ok 22:56:44.0024 4280 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll 22:56:44.0028 4280 hidserv - ok 22:56:44.0099 4280 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 22:56:44.0101 4280 HidUsb - ok 22:56:44.0155 4280 hkmsvc (741c2a45ca8407e374aaba3e330b7872) C:\Windows\system32\kmsvc.dll 22:56:44.0159 4280 hkmsvc - ok 22:56:44.0216 4280 HomeGroupListener (a768ca158bb06782a2835b907f4873c3) C:\Windows\system32\ListSvc.dll 22:56:44.0229 4280 HomeGroupListener - ok 22:56:44.0284 4280 HomeGroupProvider (fb08dec5ef43d0c66d83b8e9694e7549) C:\Windows\system32\provsvc.dll 22:56:44.0297 4280 HomeGroupProvider - ok 22:56:44.0363 4280 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 22:56:44.0366 4280 HpSAMD - ok 22:56:44.0418 4280 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 22:56:44.0423 4280 HTTP - ok 22:56:44.0463 4280 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 22:56:44.0465 4280 hwpolicy - ok 22:56:44.0522 4280 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 22:56:44.0524 4280 i8042prt - ok 22:56:44.0588 4280 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\drivers\iaStorV.sys 22:56:44.0608 4280 iaStorV - ok 22:56:44.0730 4280 idsvc (5af815eb5bc9802e5a064e2ba62bfc0c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 22:56:44.0753 4280 idsvc - ok 22:56:45.0003 4280 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 22:56:45.0043 4280 igfx - ok 22:56:45.0202 4280 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 22:56:45.0204 4280 iirsp - ok 22:56:45.0332 4280 IJPLMSVC (ad5df6f4fbbc798636edc66bfec7d0de) C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 22:56:45.0334 4280 IJPLMSVC - ok 22:56:45.0406 4280 IKEEXT (fac0ee6562b121b1399d6e855583f7a5) C:\Windows\System32\ikeext.dll 22:56:45.0429 4280 IKEEXT - ok 22:56:45.0475 4280 inspect (2ee3db2c1760171c6f72f2f1792a47b5) C:\Windows\system32\DRIVERS\inspect.sys 22:56:45.0477 4280 inspect - ok 22:56:45.0527 4280 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 22:56:45.0529 4280 intelide - ok 22:56:45.0562 4280 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 22:56:45.0564 4280 intelppm - ok 22:56:45.0611 4280 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 22:56:45.0626 4280 IPBusEnum - ok 22:56:45.0653 4280 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:56:45.0656 4280 IpFilterDriver - ok 22:56:45.0725 4280 iphlpsvc (477397b432a256a50ee7e4339eb9ea14) C:\Windows\System32\iphlpsvc.dll 22:56:45.0745 4280 iphlpsvc - ok 22:56:45.0792 4280 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 22:56:45.0795 4280 IPMIDRV - ok 22:56:45.0824 4280 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 22:56:45.0831 4280 IPNAT - ok 22:56:45.0898 4280 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 22:56:45.0900 4280 IRENUM - ok 22:56:45.0933 4280 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 22:56:45.0936 4280 isapnp - ok 22:56:45.0982 4280 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 22:56:45.0997 4280 iScsiPrt - ok 22:56:46.0067 4280 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 22:56:46.0070 4280 kbdclass - ok 22:56:46.0113 4280 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 22:56:46.0115 4280 kbdhid - ok 22:56:46.0159 4280 KeyIso (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 22:56:46.0162 4280 KeyIso - ok 22:56:46.0212 4280 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 22:56:46.0214 4280 KSecDD - ok 22:56:46.0268 4280 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 22:56:46.0271 4280 KSecPkg - ok 22:56:46.0338 4280 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 22:56:46.0362 4280 KtmRm - ok 22:56:46.0440 4280 LanmanServer (bca92cb047a4326925ecef759dbaa233) C:\Windows\system32\srvsvc.dll 22:56:46.0457 4280 LanmanServer - ok 22:56:46.0509 4280 LanmanWorkstation (b9891f885dcf1f0513a51cb58493cb1f) C:\Windows\System32\wkssvc.dll 22:56:46.0525 4280 LanmanWorkstation - ok 22:56:46.0779 4280 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 22:56:46.0781 4280 lltdio - ok 22:56:46.0841 4280 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 22:56:46.0858 4280 lltdsvc - ok 22:56:46.0894 4280 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 22:56:46.0898 4280 lmhosts - ok 22:56:46.0963 4280 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 22:56:46.0971 4280 LSI_FC - ok 22:56:47.0019 4280 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 22:56:47.0027 4280 LSI_SAS - ok 22:56:47.0087 4280 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 22:56:47.0090 4280 LSI_SAS2 - ok 22:56:47.0126 4280 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 22:56:47.0139 4280 LSI_SCSI - ok 22:56:47.0241 4280 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 22:56:47.0243 4280 luafv - ok 22:56:47.0299 4280 LVRS (ed643e777ba3f7151ef3f0fb6be4f7f0) C:\Windows\system32\DRIVERS\lvrs.sys 22:56:47.0303 4280 LVRS - ok 22:56:47.0513 4280 LVUVC (5bc80451109a8dd7f2ddd35bce2929a3) C:\Windows\system32\DRIVERS\lvuvc.sys 22:56:47.0545 4280 LVUVC - ok 22:56:47.0676 4280 Mcx2Svc (e2b0887816ed336685954e3d8fdaa51d) C:\Windows\system32\Mcx2Svc.dll 22:56:47.0692 4280 Mcx2Svc - ok 22:56:47.0761 4280 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 22:56:47.0764 4280 megasas - ok 22:56:47.0825 4280 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 22:56:47.0839 4280 MegaSR - ok 22:56:47.0893 4280 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 22:56:47.0897 4280 MMCSS - ok 22:56:47.0923 4280 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 22:56:47.0926 4280 Modem - ok 22:56:47.0986 4280 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 22:56:47.0987 4280 monitor - ok 22:56:48.0025 4280 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 22:56:48.0027 4280 mouclass - ok 22:56:48.0112 4280 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 22:56:48.0115 4280 mouhid - ok 22:56:48.0144 4280 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 22:56:48.0146 4280 mountmgr - ok 22:56:48.0205 4280 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 22:56:48.0213 4280 mpio - ok 22:56:48.0249 4280 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 22:56:48.0251 4280 mpsdrv - ok 22:56:48.0424 4280 MpsSvc (5cd996cecf45cbc3e8d109c86b82d69e) C:\Windows\system32\mpssvc.dll 22:56:48.0454 4280 MpsSvc - ok 22:56:48.0551 4280 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 22:56:48.0623 4280 MRxDAV - ok 22:56:48.0649 4280 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys 22:56:48.0651 4280 mrxsmb - ok 22:56:48.0718 4280 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:56:48.0722 4280 mrxsmb10 - ok 22:56:48.0753 4280 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:56:48.0755 4280 mrxsmb20 - ok 22:56:48.0790 4280 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 22:56:48.0792 4280 msahci - ok 22:56:48.0848 4280 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 22:56:48.0854 4280 msdsm - ok 22:56:48.0929 4280 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 22:56:48.0945 4280 MSDTC - ok 22:56:48.0979 4280 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 22:56:48.0981 4280 Msfs - ok 22:56:49.0032 4280 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 22:56:49.0034 4280 mshidkmdf - ok 22:56:49.0052 4280 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 22:56:49.0055 4280 msisadrv - ok 22:56:49.0127 4280 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 22:56:49.0155 4280 MSiSCSI - ok 22:56:49.0169 4280 msiserver - ok 22:56:49.0229 4280 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 22:56:49.0234 4280 MSKSSRV - ok 22:56:49.0291 4280 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 22:56:49.0293 4280 MSPCLOCK - ok 22:56:49.0312 4280 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 22:56:49.0314 4280 MSPQM - ok 22:56:49.0359 4280 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 22:56:49.0362 4280 MsRPC - ok 22:56:49.0395 4280 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 22:56:49.0397 4280 mssmbios - ok 22:56:49.0452 4280 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 22:56:49.0454 4280 MSTEE - ok 22:56:49.0477 4280 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 22:56:49.0494 4280 MTConfig - ok 22:56:49.0540 4280 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 22:56:49.0542 4280 Mup - ok 22:56:49.0606 4280 napagent (80284f1985c70c86f0b5f86da2dfe1df) C:\Windows\system32\qagentRT.dll 22:56:49.0621 4280 napagent - ok 22:56:49.0705 4280 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 22:56:49.0722 4280 NativeWifiP - ok 22:56:49.0781 4280 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 22:56:49.0787 4280 NDIS - ok 22:56:49.0847 4280 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 22:56:49.0849 4280 NdisCap - ok 22:56:49.0883 4280 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 22:56:49.0885 4280 NdisTapi - ok 22:56:49.0924 4280 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 22:56:49.0926 4280 Ndisuio - ok 22:56:49.0979 4280 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 22:56:49.0982 4280 NdisWan - ok 22:56:50.0005 4280 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 22:56:50.0008 4280 NDProxy - ok 22:56:50.0071 4280 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 22:56:50.0073 4280 NetBIOS - ok 22:56:50.0104 4280 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 22:56:50.0107 4280 NetBT - ok 22:56:50.0158 4280 Netlogon (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 22:56:50.0161 4280 Netlogon - ok 22:56:50.0245 4280 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 22:56:50.0265 4280 Netman - ok 22:56:50.0304 4280 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 22:56:50.0324 4280 netprofm - ok 22:56:50.0447 4280 NetTcpPortSharing (fe2aa5a684b0dd9b1fae57b7817c198b) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 22:56:50.0459 4280 NetTcpPortSharing - ok 22:56:50.0543 4280 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 22:56:50.0545 4280 nfrd960 - ok 22:56:50.0608 4280 NlaSvc (2226496e34bd40734946a054b1cd657f) C:\Windows\System32\nlasvc.dll 22:56:50.0620 4280 NlaSvc - ok 22:56:50.0742 4280 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys 22:56:50.0744 4280 NPF - ok 22:56:50.0783 4280 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 22:56:50.0785 4280 Npfs - ok 22:56:50.0839 4280 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 22:56:50.0847 4280 nsi - ok 22:56:50.0882 4280 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 22:56:50.0883 4280 nsiproxy - ok 22:56:50.0987 4280 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 22:56:50.0997 4280 Ntfs - ok 22:56:51.0021 4280 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 22:56:51.0022 4280 Null - ok 22:56:51.0068 4280 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\drivers\nvraid.sys 22:56:51.0080 4280 nvraid - ok 22:56:51.0128 4280 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\drivers\nvstor.sys 22:56:51.0140 4280 nvstor - ok 22:56:51.0185 4280 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 22:56:51.0198 4280 nv_agp - ok 22:56:51.0241 4280 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 22:56:51.0244 4280 ohci1394 - ok 22:56:51.0300 4280 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 22:56:51.0316 4280 p2pimsvc - ok 22:56:51.0374 4280 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 22:56:51.0387 4280 p2psvc - ok 22:56:51.0457 4280 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 22:56:51.0459 4280 Parport - ok 22:56:51.0480 4280 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 22:56:51.0482 4280 partmgr - ok 22:56:51.0535 4280 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 22:56:51.0537 4280 Parvdm - ok 22:56:51.0588 4280 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 22:56:51.0603 4280 PcaSvc - ok 22:56:51.0685 4280 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 22:56:51.0687 4280 pccsmcfd - ok 22:56:51.0744 4280 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 22:56:51.0747 4280 pci - ok 22:56:51.0774 4280 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 22:56:51.0776 4280 pciide - ok 22:56:51.0870 4280 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 22:56:51.0884 4280 pcmcia - ok 22:56:51.0946 4280 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 22:56:51.0948 4280 pcw - ok 22:56:52.0015 4280 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 22:56:52.0021 4280 PEAUTH - ok 22:56:52.0127 4280 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 22:56:52.0155 4280 PeerDistSvc - ok 22:56:52.0303 4280 pla (9c1bff7910c89a1d12e57343475840cb) C:\Windows\system32\pla.dll 22:56:52.0357 4280 pla - ok 22:56:52.0517 4280 PlugPlay (2cc2008f1296968fba162ed9f9afe328) C:\Windows\system32\umpnpmgr.dll 22:56:52.0546 4280 PlugPlay - ok 22:56:52.0607 4280 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 22:56:52.0611 4280 PNRPAutoReg - ok 22:56:52.0668 4280 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 22:56:52.0673 4280 PNRPsvc - ok 22:56:52.0725 4280 PolicyAgent (48e1b75c6dc0232fd92baae4bd344721) C:\Windows\System32\ipsecsvc.dll 22:56:52.0742 4280 PolicyAgent - ok 22:56:52.0780 4280 Power (dbff83f709a91049621c1d35dd45c92c) C:\Windows\system32\umpo.dll 22:56:52.0795 4280 Power - ok 22:56:52.0883 4280 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 22:56:52.0885 4280 PptpMiniport - ok 22:56:52.0927 4280 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 22:56:52.0930 4280 Processor - ok 22:56:52.0995 4280 ProfSvc (630cf26f0227498b7d5a92b12548960f) C:\Windows\system32\profsvc.dll 22:56:53.0008 4280 ProfSvc - ok 22:56:53.0056 4280 ProtectedStorage (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 22:56:53.0060 4280 ProtectedStorage - ok 22:56:53.0136 4280 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 22:56:53.0141 4280 Psched - ok 22:56:53.0188 4280 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\Windows\system32\Drivers\pssdk42.sys 22:56:53.0190 4280 PSSDK42 - ok 22:56:53.0286 4280 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 22:56:53.0322 4280 ql2300 - ok 22:56:53.0473 4280 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 22:56:53.0484 4280 ql40xx - ok 22:56:53.0543 4280 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 22:56:53.0560 4280 QWAVE - ok 22:56:53.0609 4280 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 22:56:53.0611 4280 QWAVEdrv - ok 22:56:53.0640 4280 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 22:56:53.0643 4280 RasAcd - ok 22:56:53.0698 4280 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 22:56:53.0700 4280 RasAgileVpn - ok 22:56:53.0751 4280 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 22:56:53.0771 4280 RasAuto - ok 22:56:53.0817 4280 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 22:56:53.0820 4280 Rasl2tp - ok 22:56:53.0906 4280 RasMan (0ce66ec736b7fc526d78f7624c7d2a94) C:\Windows\System32\rasmans.dll 22:56:53.0919 4280 RasMan - ok 22:56:53.0980 4280 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 22:56:53.0982 4280 RasPppoe - ok 22:56:54.0039 4280 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 22:56:54.0041 4280 RasSstp - ok 22:56:54.0069 4280 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 22:56:54.0073 4280 rdbss - ok 22:56:54.0128 4280 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 22:56:54.0129 4280 rdpbus - ok 22:56:54.0154 4280 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 22:56:54.0158 4280 RDPCDD - ok 22:56:54.0202 4280 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys 22:56:54.0215 4280 RDPDR - ok 22:56:54.0271 4280 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 22:56:54.0273 4280 RDPENCDD - ok 22:56:54.0309 4280 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 22:56:54.0311 4280 RDPREFMP - ok 22:56:54.0341 4280 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 22:56:54.0355 4280 RDPWD - ok 22:56:54.0419 4280 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 22:56:54.0422 4280 rdyboost - ok 22:56:54.0483 4280 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 22:56:54.0491 4280 RemoteAccess - ok 22:56:54.0548 4280 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 22:56:54.0560 4280 RemoteRegistry - ok 22:56:54.0641 4280 rpcapd (b60f58f175de20a6739194e85b035178) C:\Program Files\WinPcap\rpcapd.exe 22:56:54.0652 4280 rpcapd - ok 22:56:54.0719 4280 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 22:56:54.0725 4280 RpcEptMapper - ok 22:56:54.0774 4280 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 22:56:54.0782 4280 RpcLocator - ok 22:56:54.0848 4280 RpcSs (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 22:56:54.0856 4280 RpcSs - ok 22:56:54.0914 4280 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 22:56:54.0916 4280 rspndr - ok 22:56:54.0968 4280 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys 22:56:54.0970 4280 s3cap - ok 22:56:55.0022 4280 SamSs (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 22:56:55.0025 4280 SamSs - ok 22:56:55.0067 4280 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 22:56:55.0075 4280 sbp2port - ok 22:56:55.0128 4280 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 22:56:55.0149 4280 SCardSvr - ok 22:56:55.0201 4280 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 22:56:55.0204 4280 scfilter - ok 22:56:55.0299 4280 Schedule (3e8b0c453e25613a1f59762a5c42aa75) C:\Windows\system32\schedsvc.dll 22:56:55.0326 4280 Schedule - ok 22:56:55.0384 4280 SCPolicySvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 22:56:55.0386 4280 SCPolicySvc - ok 22:56:55.0437 4280 SDRSVC (5fd90abdbfaee85986802622cbb03446) C:\Windows\System32\SDRSVC.dll 22:56:55.0452 4280 SDRSVC - ok 22:56:55.0509 4280 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 22:56:55.0510 4280 secdrv - ok 22:56:55.0555 4280 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 22:56:55.0563 4280 seclogon - ok 22:56:55.0621 4280 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll 22:56:55.0629 4280 SENS - ok 22:56:55.0650 4280 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 22:56:55.0666 4280 SensrSvc - ok 22:56:55.0694 4280 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 22:56:55.0696 4280 Serenum - ok 22:56:55.0757 4280 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 22:56:55.0759 4280 Serial - ok 22:56:55.0789 4280 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 22:56:55.0791 4280 sermouse - ok 22:56:55.0903 4280 SessionEnv (8f55ce568c543d5adf45c409d16718fc) C:\Windows\system32\sessenv.dll 22:56:55.0919 4280 SessionEnv - ok 22:56:55.0965 4280 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 22:56:55.0967 4280 sffdisk - ok 22:56:55.0992 4280 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 22:56:55.0995 4280 sffp_mmc - ok 22:56:56.0035 4280 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys 22:56:56.0037 4280 sffp_sd - ok 22:56:56.0064 4280 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 22:56:56.0068 4280 sfloppy - ok 22:56:56.0132 4280 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 22:56:56.0149 4280 SharedAccess - ok 22:56:56.0218 4280 ShellHWDetection (cd2e48fa5b29ee2b3b5858056d246ef2) C:\Windows\System32\shsvcs.dll 22:56:56.0233 4280 ShellHWDetection - ok 22:56:56.0293 4280 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 22:56:56.0295 4280 sisagp - ok 22:56:56.0354 4280 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 22:56:56.0356 4280 SiSRaid2 - ok 22:56:56.0411 4280 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 22:56:56.0415 4280 SiSRaid4 - ok 22:56:56.0482 4280 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 22:56:56.0485 4280 Smb - ok 22:56:56.0560 4280 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 22:56:56.0567 4280 SNMPTRAP - ok 22:56:56.0611 4280 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 22:56:56.0613 4280 spldr - ok 22:56:56.0687 4280 Spooler (49b6dd6ab3715b7a67965f17194e98a9) C:\Windows\System32\spoolsv.exe 22:56:56.0693 4280 Spooler - ok 22:56:56.0862 4280 sppsvc (4c287f9069fedbd791178876ee9de536) C:\Windows\system32\sppsvc.exe 22:56:56.0946 4280 sppsvc - ok 22:56:57.0063 4280 sppuinotify (d8e3e19eebdab49dd4a8d3062ead4ec7) C:\Windows\system32\sppuinotify.dll 22:56:57.0069 4280 sppuinotify - ok 22:56:57.0158 4280 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys 22:56:57.0162 4280 srv - ok 22:56:57.0203 4280 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys 22:56:57.0206 4280 srv2 - ok 22:56:57.0234 4280 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys 22:56:57.0237 4280 srvnet - ok 22:56:57.0301 4280 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 22:56:57.0316 4280 SSDPSRV - ok 22:56:57.0374 4280 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 22:56:57.0386 4280 SstpSvc - ok 22:56:57.0441 4280 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 22:56:57.0444 4280 stexstor - ok 22:56:57.0501 4280 StiSvc (a22825e7bb7018e8af3e229a5af17221) C:\Windows\System32\wiaservc.dll 22:56:57.0520 4280 StiSvc - ok 22:56:57.0572 4280 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys 22:56:57.0574 4280 storflt - ok 22:56:57.0632 4280 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys 22:56:57.0634 4280 storvsc - ok 22:56:57.0680 4280 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 22:56:57.0682 4280 swenum - ok 22:56:57.0746 4280 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 22:56:57.0763 4280 swprv - ok 22:56:57.0863 4280 SysMain (04105c8da62353589c29bdaeb8d88bd8) C:\Windows\system32\sysmain.dll 22:56:57.0896 4280 SysMain - ok 22:56:57.0953 4280 TabletInputService (fcfb6c552fbc0da299799cbd50ad9fd4) C:\Windows\System32\TabSvc.dll 22:56:57.0961 4280 TabletInputService - ok 22:56:58.0014 4280 TapiSrv (2f46b0c70a4adc8c90cf825da3b4feaf) C:\Windows\System32\tapisrv.dll 22:56:58.0028 4280 TapiSrv - ok 22:56:58.0096 4280 tapoas (827c8058c284ff0013e4462efe2591a3) C:\Windows\system32\DRIVERS\tapoas.sys 22:56:58.0098 4280 tapoas - ok 22:56:58.0163 4280 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 22:56:58.0169 4280 TBS - ok 22:56:58.0287 4280 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys 22:56:58.0298 4280 Tcpip - ok 22:56:58.0346 4280 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys 22:56:58.0356 4280 TCPIP6 - ok 22:56:58.0410 4280 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 22:56:58.0414 4280 tcpipreg - ok 22:56:58.0473 4280 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 22:56:58.0475 4280 TDPIPE - ok 22:56:58.0492 4280 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 22:56:58.0495 4280 TDTCP - ok 22:56:58.0526 4280 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 22:56:58.0528 4280 tdx - ok 22:56:58.0587 4280 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 22:56:58.0589 4280 TermDD - ok 22:56:58.0662 4280 TermService (a01e50a04d7b1960b33e92b9080e6a94) C:\Windows\System32\termsrv.dll 22:56:58.0684 4280 TermService - ok 22:56:58.0735 4280 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 22:56:58.0743 4280 Themes - ok 22:56:58.0797 4280 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 22:56:58.0800 4280 THREADORDER - ok 22:56:58.0858 4280 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 22:56:58.0865 4280 TrkWks - ok 22:56:58.0943 4280 TrustedInstaller (41a4c781d2286208d397d72099304133) C:\Windows\servicing\TrustedInstaller.exe 22:56:58.0982 4280 TrustedInstaller - ok 22:56:59.0026 4280 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 22:56:59.0034 4280 tssecsrv - ok 22:56:59.0070 4280 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 22:56:59.0073 4280 tunnel - ok 22:56:59.0119 4280 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 22:56:59.0122 4280 uagp35 - ok 22:56:59.0153 4280 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 22:56:59.0167 4280 udfs - ok 22:56:59.0233 4280 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 22:56:59.0282 4280 UI0Detect - ok 22:56:59.0335 4280 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 22:56:59.0338 4280 uliagpkx - ok 22:56:59.0386 4280 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 22:56:59.0394 4280 umbus - ok 22:56:59.0417 4280 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 22:56:59.0419 4280 UmPass - ok 22:56:59.0487 4280 UmRdpService (8ecaca5454844f66386f7be4ae0d7cd1) C:\Windows\System32\umrdp.dll 22:56:59.0498 4280 UmRdpService - ok 22:56:59.0618 4280 UMVPFSrv (67a95b9d129ed5399e7965cd09cf30e7) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 22:56:59.0623 4280 UMVPFSrv - ok 22:56:59.0673 4280 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 22:56:59.0686 4280 upnphost - ok 22:56:59.0744 4280 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 22:56:59.0747 4280 usbaudio - ok 22:56:59.0795 4280 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 22:56:59.0798 4280 usbccgp - ok 22:56:59.0848 4280 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 22:56:59.0860 4280 usbcir - ok 22:56:59.0916 4280 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 22:56:59.0918 4280 usbehci - ok 22:56:59.0964 4280 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 22:56:59.0968 4280 usbhub - ok 22:57:00.0021 4280 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 22:57:00.0023 4280 usbohci - ok 22:57:00.0076 4280 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 22:57:00.0078 4280 usbprint - ok 22:57:00.0123 4280 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 22:57:00.0126 4280 usbscan - ok 22:57:00.0182 4280 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys 22:57:00.0184 4280 usbser - ok 22:57:00.0219 4280 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:57:00.0221 4280 USBSTOR - ok 22:57:00.0273 4280 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 22:57:00.0275 4280 usbuhci - ok 22:57:00.0350 4280 usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\Windows\system32\Drivers\usbvideo.sys 22:57:00.0361 4280 usbvideo - ok 22:57:00.0416 4280 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 22:57:00.0422 4280 UxSms - ok 22:57:00.0478 4280 VaultSvc (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 22:57:00.0481 4280 VaultSvc - ok 22:57:00.0550 4280 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 22:57:00.0553 4280 vdrvroot - ok 22:57:00.0632 4280 vds (8c4e7c49d3641bc9e299e466a7f8867d) C:\Windows\System32\vds.exe 22:57:00.0653 4280 vds - ok 22:57:00.0717 4280 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 22:57:00.0720 4280 vga - ok 22:57:00.0752 4280 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 22:57:00.0754 4280 VgaSave - ok 22:57:00.0789 4280 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 22:57:00.0796 4280 vhdmp - ok 22:57:00.0851 4280 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 22:57:00.0859 4280 viaagp - ok 22:57:00.0884 4280 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 22:57:00.0887 4280 ViaC7 - ok 22:57:00.0935 4280 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 22:57:00.0937 4280 viaide - ok 22:57:00.0978 4280 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys 22:57:00.0991 4280 vmbus - ok 22:57:01.0035 4280 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys 22:57:01.0038 4280 VMBusHID - ok 22:57:01.0092 4280 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 22:57:01.0100 4280 volmgr - ok 22:57:01.0131 4280 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 22:57:01.0135 4280 volmgrx - ok 22:57:01.0207 4280 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 22:57:01.0211 4280 volsnap - ok 22:57:01.0261 4280 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 22:57:01.0274 4280 vsmraid - ok 22:57:01.0366 4280 VSS (7ea2bcd94d9cfaf4c556f5cc94532a6c) C:\Windows\system32\vssvc.exe 22:57:01.0399 4280 VSS - ok 22:57:01.0575 4280 vToolbarUpdater11.0.2 (56e1e4442e4613fb2039a6b7421f4e58) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe 22:57:01.0582 4280 vToolbarUpdater11.0.2 - ok 22:57:01.0742 4280 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 22:57:01.0744 4280 vwifibus - ok 22:57:01.0810 4280 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 22:57:01.0826 4280 W32Time - ok 22:57:01.0882 4280 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 22:57:01.0884 4280 WacomPen - ok 22:57:01.0926 4280 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 22:57:01.0928 4280 WANARP - ok 22:57:01.0942 4280 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 22:57:01.0944 4280 Wanarpv6 - ok 22:57:02.0043 4280 wbengine (7790b77fe1e5ee47dcc66247095bb4c9) C:\Windows\system32\wbengine.exe 22:57:02.0079 4280 wbengine - ok 22:57:02.0110 4280 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 22:57:02.0125 4280 WbioSrvc - ok 22:57:02.0181 4280 wcncsvc (d0f88aa11ee1a62bcc6d6a8a7783ca11) C:\Windows\System32\wcncsvc.dll 22:57:02.0194 4280 wcncsvc - ok 22:57:02.0242 4280 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 22:57:02.0251 4280 WcsPlugInService - ok 22:57:02.0337 4280 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 22:57:02.0339 4280 Wd - ok 22:57:02.0425 4280 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 22:57:02.0435 4280 Wdf01000 - ok 22:57:02.0460 4280 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 22:57:02.0475 4280 WdiServiceHost - ok 22:57:02.0489 4280 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 22:57:02.0495 4280 WdiSystemHost - ok 22:57:02.0552 4280 WebClient (d87c7d2c517f82a5ab7a73e203063d9e) C:\Windows\System32\webclnt.dll 22:57:02.0566 4280 WebClient - ok 22:57:02.0621 4280 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 22:57:02.0637 4280 Wecsvc - ok 22:57:02.0683 4280 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 22:57:02.0691 4280 wercplsupport - ok 22:57:02.0751 4280 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 22:57:02.0763 4280 WerSvc - ok 22:57:02.0817 4280 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 22:57:02.0819 4280 WfpLwf - ok 22:57:02.0850 4280 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 22:57:02.0854 4280 WIMMount - ok 22:57:02.0995 4280 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 22:57:03.0020 4280 WinDefend - ok 22:57:03.0043 4280 WinHttpAutoProxySvc - ok 22:57:03.0134 4280 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 22:57:03.0148 4280 Winmgmt - ok 22:57:03.0244 4280 WinRM (c4f5d3901d1b41d602ddc196e0b95b51) C:\Windows\system32\WsmSvc.dll 22:57:03.0282 4280 WinRM - ok 22:57:03.0381 4280 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 22:57:03.0384 4280 WinUsb - ok 22:57:03.0470 4280 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 22:57:03.0495 4280 Wlansvc - ok 22:57:03.0546 4280 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 22:57:03.0548 4280 WmiAcpi - ok 22:57:03.0636 4280 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 22:57:03.0658 4280 wmiApSrv - ok 22:57:03.0794 4280 WMPNetworkSvc (77fbd400984cf72ba0fc4b3489d65f74) C:\Program Files\Windows Media Player\wmpnetwk.exe 22:57:03.0803 4280 WMPNetworkSvc - ok 22:57:03.0857 4280 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 22:57:03.0862 4280 WPCSvc - ok 22:57:03.0888 4280 WPDBusEnum (b7f658a2ebc07129538ad9ab35212637) C:\Windows\system32\wpdbusenum.dll 22:57:03.0902 4280 WPDBusEnum - ok 22:57:03.0983 4280 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 22:57:03.0985 4280 ws2ifsl - ok 22:57:04.0063 4280 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\System32\wscsvc.dll 22:57:04.0078 4280 wscsvc - ok 22:57:04.0093 4280 WSearch - ok 22:57:04.0226 4280 wuauserv (a33408cc036f9c08142b11be5e93f0a1) C:\Windows\system32\wuaueng.dll 22:57:04.0314 4280 wuauserv - ok 22:57:04.0459 4280 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 22:57:04.0462 4280 WudfPf - ok 22:57:04.0520 4280 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 22:57:04.0527 4280 WUDFRd - ok 22:57:04.0601 4280 wudfsvc (ddee3682fe97037c45f4d7ab467cb8b6) C:\Windows\System32\WUDFSvc.dll 22:57:04.0607 4280 wudfsvc - ok 22:57:04.0649 4280 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 22:57:04.0687 4280 WwanSvc - ok 22:57:04.0773 4280 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 22:57:04.0961 4280 \Device\Harddisk0\DR0 - ok 22:57:04.0975 4280 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR1 22:57:05.0358 4280 \Device\Harddisk1\DR1 - ok 22:57:05.0381 4280 Boot (0x1200) (4ccd8149d97cf7a43e7aa6254f81579d) \Device\Harddisk0\DR0\Partition0 22:57:05.0383 4280 \Device\Harddisk0\DR0\Partition0 - ok 22:57:05.0417 4280 Boot (0x1200) (29d1b16527f5fadb56e554830ee808b3) \Device\Harddisk0\DR0\Partition1 22:57:05.0419 4280 \Device\Harddisk0\DR0\Partition1 - ok 22:57:05.0452 4280 Boot (0x1200) (d87a060e29b41e4d06bd82134904f589) \Device\Harddisk0\DR0\Partition2 22:57:05.0454 4280 \Device\Harddisk0\DR0\Partition2 - ok 22:57:05.0466 4280 Boot (0x1200) (47dc14d1c3f4e315b209e4f9fecdac00) \Device\Harddisk1\DR1\Partition0 22:57:05.0469 4280 \Device\Harddisk1\DR1\Partition0 - ok 22:57:05.0475 4280 ============================================================ 22:57:05.0475 4280 Scan finished 22:57:05.0475 4280 ============================================================ 22:57:05.0498 2716 Detected object count: 0 22:57:05.0498 2716 Actual detected object count: 0
Nothing significant or alarming I can see from your log. As far as I can tell it is clean. Do you carry out regular maintenance on your computer like clearing temporary files, defragmentation, anti-malware scan?

I think the unaccounted network activity is due to the automatic update of your software, because I see some of your programs are out of date like Firefox, Java, and also your Windows update.

That said, please run these for me. Thanks.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Carried out the scans as asked. The logs are placed below: ESET Log: C:\WGASetup.exe probably a variant of Win32/Agent.JUBXKMB trojan C:\Users\Neel\DoctorWeb\Quarantine\WGA_v1.9.40.0_crack.exe probably a variant of Win32/Agent.NARLUUV trojan D:\programme files\Setup_FreeConverter.exe Win32/Toolbar.Widgi application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpgefbvs Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpko4_hv Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmplrrwhw Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpsbb58u Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpvrzp_u Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpyja8an Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\rbia.exe Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\Launcher.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rbmonitor.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rbnotifier.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_decryptor.exe Win32/RegistryBooster application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_move_serial.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_track_install.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\registrybooster.exe Win32/Packed.RBCrypt.A.Gen application G:\Windows.old\Program Files\Secret Crush Revealer\Zugo.exe Win32/Toolbar.Zugo application MBAM Log: Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.24.01 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 Neel :: NEEL-PC [administrator] 5/24/2012 10:37:50 AM mbam-log-2012-05-24 (10-37-50).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 191851 Time elapsed: 7 minute(s), 6 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\WGASetup.exe (Hacktool.WPA) -> Quarantined and deleted successfully. (end) Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI