This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Svchost.exe runn taking up 25 CPU percentage and lagging the computer

64 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My computer is lagging again, I do not know why the svchost.exe suddenly run at 25 percentage, usually it is almost between 0-5. Can help me solve? Thanks! Henry
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 23:03:04 on 2012-06-28 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.1687 [GMT 8:00] . SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\System32\svchost.exe -k NetworkService C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\ASUS.SYS\config\DVMExportService.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\system32\PnkBstrA.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe C:\Program Files\ASUS\Turbo Key\TurboKey.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Vtune\TBPANEL.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Steam\Steam.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe B:\bit torrent\uTorrent.exe C:\Users\Henry\AppData\Roaming\9 1\rundll32.exe "C:\Users\Henry\AppData\Roaming\9 1\svchost.exe" "crysiss_a:[removed]:8344" "–device=0" "-f" "60" C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Windows\system32\conhost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Funshion Online\Funshion\FunshionService.exe C:\Windows\system32\DllHost.exe C:\Program Files\iTunes\iTunes.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Windows\system32\conhost.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Windows\system32\conhost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\ATH.exe C:\Windows\system32\conhost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Windows\system32\conhost.exe C:\Windows\system32\taskhost.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\rundll32.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\WUDFHost.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Henry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://startsear.ch/?aff=1&cf=30b0a508-49d1-11e1-8800-485b39f40826 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll uURLSearchHooks: SearchHook Class: {bc86e1ab-eda5-4059-938f-ce307b0c6f0a} - c:\program files\devicevm\browser configuration utility\AddressBarSearch.dll BHO: ThunderAtOnce Class: {01443aec-0fd1-40fd-9c87-e93d1494c233} - b:\thunder\comdlls\TDAtOnce_Now.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - No File BHO: VshareComplete: {222f31fb-a14e-4af2-bb14-997f28294370} - c:\users\henry\appdata\roaming\vsharecomplete\VshareComplete.dll BHO: {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - No File BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: IE5BarLauncherBHO Class: {78f3a323-798e-4aea-9a57-88f4b05fd5dd} - c:\program files\startsearch plugin\BarLcher.dll BHO: Thunder Browser Helper: {889d2feb-5411-4565-8998-1dd2c5261283} - b:\thunder\comdlls\xunleiBHO_Now.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - No File BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: {CCAC5586-44D7-4c43-B64A-F042461A97D2} - No File TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: VShareToolBar: {7ac3e13b-3bca-4158-b330-f66dbb03c1b5} - c:\program files\startsearch plugin\BarLcher.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [EPSON K200 Series] c:\windows\system32\spool\drivers\w32x86\3\e_tatig3p.exe /fu "c:\users\henry\appdata\local\temp\E_SFFE7.tmp" /EF "HKCU" uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart uRun: [Google Update] "c:\users\henry\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [ABBYY Screenshot Reader Bonus] "c:\program files\abbyy finereader 9.0 sprint\Bonus.ScreenshotReader.exe" -autorun uRun: [Funshion] c:\program files\funshion online\funshion\Funshion.exe startbywindows tray uRun: [HKCU] c:\program files\adobe\reader.exe uRun: [uTorrent] "b:\bit torrent\uTorrent.exe" /MINIMIZED uRun: [adobeupdate] "c:\users\henry\appdata\roaming\9 1\l3.lnk" uRun: [adobeupdater] "c:\users\henry\appdata\roaming\9 1\rundll32.exe" uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun mRun: [HDAudDeck] c:\program files\via\viaudioi\vdeck\VDeck.exe -r mRun: [BCU] "c:\program files\devicevm\browser configuration utility\BCU.exe" mRun: [Cpu Level Up help] "c:\program files\asus\ai suite\CpuLevelUpHelp.exe" mRun: [Turbo Key] "c:\program files\asus\turbo key\TurboKey.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HKLM] c:\program files\adobe\reader.exe StartupFolder: c:\users\henry\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\henry\appdata\roaming\dropbox\bin\Dropbox.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: use Thunderbolt download - b:\thunder\program\GetUrl.htm IE: use Xunlei download all the links - b:\thunder\program\GetAllUrl.htm IE: {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - b:\thunder\Thunder.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C} : NameServer = 165.21.83.88,165.21.100.88 TCP: Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C} : DhcpNameServer = 192.168.1.254 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL mASetup: {D588YX8G-06R6-235V-4Y5B-4L57WR50OYK2} - c:\program files\adobe\reader.exe . ============= SERVICES / DRIVERS =============== . R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2009-7-6 11448] R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\common files\abbyy\finereadersprint\9.00\licensing\NetworkLicenseServer.exe [2009-5-14 759048] R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2011-12-9 494424] R2 AsSysCtrlService;ASUS System Control Service;c:\program files\asus\assysctrlservice\1.00.02\AsSysCtrlService.exe [2010-9-11 96896] R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648] R2 BCUService;Browser Configuration Utility Service;c:\program files\devicevm\browser configuration utility\BCUService.exe [2010-3-5 235752] R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-16 319488] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-5-5 2348352] R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-6-19 3048136] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-29 382272] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-5-5 148800] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-9-11 1119232] S2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-12 136176] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-5 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-5 250056] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 ConvertTuneAudio;ConvertTuneAudio;c:\windows\system32\drivers\ConvertTuneAudio.sys [2012-3-24 23608] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2012-3-31 23456] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-9-11 54632] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-9-12 136176] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-8-17 137472] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-18 52224] S3 TunRAudio;TunRAudio;c:\windows\system32\drivers\TunRAudio.sys [2012-3-24 23608] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-9-11 1343400] S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2012-3-24 25704] S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2012-3-24 25704] S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2012-3-24 25704] S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2012-3-24 25704] S4 wvchatts;wvchatts; [x] . =============== Created Last 30 ================ . 2012-06-26 04:21:44 ——– d—–w- c:\users\henry\appdata\roaming\9 1 2012-06-26 04:19:30 807 —-a-w- c:\users\henry\appdata\roaming\Henryv1.18.0 - Trial version.vbs 2012-06-22 01:42:03 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-22 01:41:51 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-22 01:41:26 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-22 01:41:26 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-14 16:02:04 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 15:36:39 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 15:29:25 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-14 15:29:25 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 15:29:25 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-11 04:41:30 6737808 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{5525ec81-46b2-4fcc-bdc4-3ea9b16730ea}\mpengine.dll . ==================== Find3M ==================== . 2012-06-23 18:48:23 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-23 18:48:23 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-22 08:34:56 140800 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-06-22 08:34:46 283304 —-a-w- c:\windows\system32\PnkBstrB.xtr 2012-06-22 08:34:46 283304 —-a-w- c:\windows\system32\PnkBstrB.exe 2012-06-22 08:34:18 280904 —-a-w- c:\windows\system32\PnkBstrB.ex0 2012-05-17 22:45:37 1800192 —-a-w- c:\windows\system32\jscript9.dll 2012-05-17 22:35:47 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-05-17 22:35:39 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-05-17 22:29:45 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-05-17 22:24:45 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-05-04 19:49:00 76888 —-a-w- c:\windows\system32\PnkBstrA.exe 2012-05-04 19:40:49 138056 —-a-w- c:\users\henry\appdata\roaming\PnkBstrK.sys 2012-03-31 04:39:37 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-31 04:39:37 3913072 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-30 20:31:10 23456 —-a-w- c:\windows\system32\drivers\DrvAgent32.sys 2012-03-30 20:09:37 472808 —-a-w- c:\windows\system32\deployJava1.dll . ============= FINISH: 23:03:55.20 ===============
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2012-06-28 23:10:01 —————————– 23:10:01.241 OS Version: Windows 6.1.7601 Service Pack 1 23:10:01.241 Number of processors: 4 586 0x403 23:10:01.242 ComputerName: HENRY-PC UserName: Henry 23:10:04.236 Initialize success 23:10:19.862 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000068 23:10:19.882 Disk 0 Vendor: ST350041 CC38 Size: 476940MB BusType: 3 23:10:21.891 Disk 0 MBR read successfully 23:10:21.893 Disk 0 MBR scan 23:10:21.894 Disk 0 Windows 7 default MBR code 23:10:21.897 Disk 0 scanning sectors +976769024 23:10:21.981 Disk 0 scanning C:\Windows\system32\drivers 23:10:29.603 Service scanning 23:10:30.850 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 23:10:31.388 Modules scanning 23:10:38.290 Disk 0 trace - called modules: 23:10:38.321 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x866531f8]<< 23:10:38.324 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a90ac8] 23:10:38.327 3 CLASSPNP.SYS[8bba159e] -> nt!IofCallDriver -> [0x86743940] 23:10:38.334 5 ACPI.sys[8b5553d4] -> nt!IofCallDriver -> \Device\00000068[0x866c3030] 23:10:38.347 \Driver\nvstor32[0x859c0cb0] -> IRP_MJ_CREATE -> 0x866531f8 23:10:38.351 Scan finished successfully 23:10:47.146 Disk 0 MBR has been saved successfully to "C:\Users\Henry\Desktop\MBR.dat" 23:10:47.150 The log file has been saved successfully to "C:\Users\Henry\Desktop\aswMBR.txt"
Hi,

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Attach the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
01:33:34.0826 6108 TDSS rootkit removing tool [removed] Jun 25 2012 21:18:44 01:33:36.0834 6108 ============================================================ 01:33:36.0834 6108 Current date / time: 2012/06/29 01:33:36.0834 01:33:36.0834 6108 SystemInfo: 01:33:36.0834 6108 01:33:36.0834 6108 OS Version: 6.1.7601 ServicePack: 1.0 01:33:36.0834 6108 Product type: Workstation 01:33:36.0834 6108 ComputerName: HENRY-PC 01:33:36.0834 6108 UserName: Henry 01:33:36.0834 6108 Windows directory: C:\Windows 01:33:36.0834 6108 System windows directory: C:\Windows 01:33:36.0834 6108 Processor architecture: Intel x86 01:33:36.0834 6108 Number of processors: 4 01:33:36.0834 6108 Page size: 0x1000 01:33:36.0834 6108 Boot type: Normal boot 01:33:36.0834 6108 ============================================================ 01:33:37.0950 6108 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x38080, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050 01:33:37.0951 6108 ============================================================ 01:33:37.0951 6108 \Device\Harddisk0\DR0: 01:33:37.0951 6108 MBR partitions: 01:33:37.0951 6108 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 01:33:37.0951 6108 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x2047B000 01:33:37.0951 6108 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x204AD800, BlocksNum 0x19ED7800 01:33:37.0951 6108 ============================================================ 01:33:37.0968 6108 C: <-> \Device\Harddisk0\DR0\Partition1 01:33:38.0099 6108 B: <-> \Device\Harddisk0\DR0\Partition2 01:33:38.0099 6108 ============================================================ 01:33:38.0099 6108 Initialize success 01:33:38.0099 6108 ============================================================ 01:33:57.0080 1612 ============================================================ 01:33:57.0080 1612 Scan started 01:33:57.0080 1612 Mode: Manual; TDLFS; 01:33:57.0080 1612 ============================================================ 01:33:58.0313 1612 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 01:33:58.0315 1612 1394ohci - ok 01:33:58.0334 1612 2WIREPCP (6551c1cf190df3e12c435a085987fba0) C:\Windows\system32\DRIVERS\2WirePCP.sys 01:33:58.0335 1612 2WIREPCP - ok 01:33:58.0385 1612 ABBYY.Licensing.FineReader.Sprint.9.0 (b33cf4de909a5b30f526d82053a63c8e) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe 01:33:58.0391 1612 ABBYY.Licensing.FineReader.Sprint.9.0 - ok 01:33:58.0418 1612 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 01:33:58.0420 1612 ACPI - ok 01:33:58.0450 1612 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 01:33:58.0451 1612 AcpiPmi - ok 01:33:58.0508 1612 AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 01:33:58.0511 1612 AdobeFlashPlayerUpdateSvc - ok 01:33:58.0537 1612 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 01:33:58.0541 1612 adp94xx - ok 01:33:58.0558 1612 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 01:33:58.0561 1612 adpahci - ok 01:33:58.0569 1612 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 01:33:58.0571 1612 adpu320 - ok 01:33:58.0662 1612 AdvancedSystemCareService5 (1d8d19a29e695bdc07f1d4e7c90d1cac) C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe 01:33:58.0666 1612 AdvancedSystemCareService5 - ok 01:33:58.0682 1612 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 01:33:58.0683 1612 AeLookupSvc - ok 01:33:58.0719 1612 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 01:33:58.0722 1612 AFD - ok 01:33:58.0744 1612 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 01:33:58.0745 1612 agp440 - ok 01:33:58.0761 1612 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 01:33:58.0762 1612 aic78xx - ok 01:33:58.0771 1612 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 01:33:58.0772 1612 ALG - ok 01:33:58.0800 1612 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 01:33:58.0801 1612 aliide - ok 01:33:58.0823 1612 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 01:33:58.0824 1612 amdagp - ok 01:33:58.0839 1612 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 01:33:58.0840 1612 amdide - ok 01:33:58.0858 1612 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 01:33:58.0859 1612 AmdK8 - ok 01:33:58.0876 1612 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 01:33:58.0876 1612 AmdPPM - ok 01:33:58.0919 1612 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 01:33:58.0920 1612 amdsata - ok 01:33:58.0932 1612 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 01:33:58.0934 1612 amdsbs - ok 01:33:58.0944 1612 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 01:33:58.0945 1612 amdxata - ok 01:33:58.0977 1612 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 01:33:58.0978 1612 AppID - ok 01:33:58.0993 1612 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 01:33:58.0994 1612 AppIDSvc - ok 01:33:59.0033 1612 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll 01:33:59.0034 1612 Appinfo - ok 01:33:59.0082 1612 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 01:33:59.0083 1612 Apple Mobile Device - ok 01:33:59.0099 1612 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 01:33:59.0101 1612 AppMgmt - ok 01:33:59.0109 1612 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 01:33:59.0110 1612 arc - ok 01:33:59.0118 1612 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 01:33:59.0119 1612 arcsas - ok 01:33:59.0140 1612 AsIO (9d8cb58b9a9e177ddd599791a58a654d) C:\Windows\system32\drivers\AsIO.sys 01:33:59.0141 1612 AsIO - ok 01:33:59.0200 1612 aspnet_state (776acefa0ca9df0faa51a5fb2f435705) C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 01:33:59.0222 1612 aspnet_state - ok 01:33:59.0239 1612 AsSysCtrlService (954ffbff05b0b60eb63b52af561436c4) C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe 01:33:59.0240 1612 AsSysCtrlService - ok 01:33:59.0255 1612 AsUpIO (e67493490466b5f04b58c22d2590e8ca) C:\Windows\system32\drivers\AsUpIO.sys 01:33:59.0255 1612 AsUpIO - ok 01:33:59.0275 1612 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 01:33:59.0276 1612 AsyncMac - ok 01:33:59.0314 1612 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 01:33:59.0315 1612 atapi - ok 01:33:59.0346 1612 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 01:33:59.0350 1612 AudioEndpointBuilder - ok 01:33:59.0356 1612 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 01:33:59.0358 1612 Audiosrv - ok 01:33:59.0422 1612 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll 01:33:59.0423 1612 AxInstSV - ok 01:33:59.0451 1612 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 01:33:59.0455 1612 b06bdrv - ok 01:33:59.0466 1612 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 01:33:59.0468 1612 b57nd60x - ok 01:33:59.0520 1612 BBSvc (01a24b415926bb5f772dbe12459d97de) C:\Program Files\Microsoft\BingBar\BBSvc.EXE 01:33:59.0522 1612 BBSvc - ok 01:33:59.0545 1612 BBUpdate (785de7abda13309d6065305542829e76) C:\Program Files\Microsoft\BingBar\SeaPort.EXE 01:33:59.0547 1612 BBUpdate - ok 01:33:59.0581 1612 BCUService (328e794278cc30ca7c06e346a18b1abc) C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe 01:33:59.0583 1612 BCUService - ok 01:33:59.0602 1612 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 01:33:59.0604 1612 BDESVC - ok 01:33:59.0616 1612 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 01:33:59.0616 1612 Beep - ok 01:33:59.0682 1612 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll 01:33:59.0686 1612 BFE - ok 01:33:59.0743 1612 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\system32\qmgr.dll 01:33:59.0749 1612 BITS - ok 01:33:59.0763 1612 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 01:33:59.0764 1612 blbdrive - ok 01:33:59.0829 1612 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 01:33:59.0832 1612 Bonjour Service - ok 01:33:59.0883 1612 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 01:33:59.0892 1612 bowser - ok 01:33:59.0910 1612 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 01:33:59.0911 1612 BrFiltLo - ok 01:33:59.0922 1612 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 01:33:59.0923 1612 BrFiltUp - ok 01:33:59.0947 1612 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll 01:33:59.0948 1612 Browser - ok 01:33:59.0965 1612 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 01:33:59.0967 1612 Brserid - ok 01:33:59.0982 1612 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 01:33:59.0983 1612 BrSerWdm - ok 01:34:00.0019 1612 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 01:34:00.0020 1612 BrUsbMdm - ok 01:34:00.0022 1612 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 01:34:00.0023 1612 BrUsbSer - ok 01:34:00.0059 1612 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 01:34:00.0060 1612 BTHMODEM - ok 01:34:00.0094 1612 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 01:34:00.0095 1612 bthserv - ok 01:34:00.0169 1612 catchme - ok 01:34:00.0179 1612 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 01:34:00.0180 1612 cdfs - ok 01:34:00.0211 1612 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys 01:34:00.0213 1612 cdrom - ok 01:34:00.0241 1612 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 01:34:00.0243 1612 CertPropSvc - ok 01:34:00.0285 1612 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 01:34:00.0286 1612 circlass - ok 01:34:00.0319 1612 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 01:34:00.0321 1612 CLFS - ok 01:34:00.0356 1612 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 01:34:00.0358 1612 clr_optimization_v2.0.50727_32 - ok 01:34:00.0405 1612 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 01:34:00.0505 1612 clr_optimization_v4.0.30319_32 - ok 01:34:00.0515 1612 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 01:34:00.0515 1612 CmBatt - ok 01:34:00.0544 1612 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 01:34:00.0545 1612 cmdide - ok 01:34:00.0590 1612 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys 01:34:00.0594 1612 CNG - ok 01:34:00.0612 1612 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 01:34:00.0612 1612 Compbatt - ok 01:34:00.0620 1612 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 01:34:00.0621 1612 CompositeBus - ok 01:34:00.0658 1612 ConvertTuneAudio (ee87c7a7a0ebedf713a152ca0d0462d6) C:\Windows\system32\drivers\ConvertTuneAudio.sys 01:34:00.0659 1612 ConvertTuneAudio - ok 01:34:00.0662 1612 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 01:34:00.0663 1612 crcdisk - ok 01:34:00.0720 1612 CryptSvc (a585bebf7d054bd9618eda0922d5484a) C:\Windows\system32\cryptsvc.dll 01:34:00.0722 1612 CryptSvc - ok 01:34:00.0752 1612 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 01:34:00.0755 1612 CSC - ok 01:34:00.0773 1612 CscService (15f93b37f6801943360d9eb42485d5d3) C:\Windows\System32\cscsvc.dll 01:34:00.0778 1612 CscService - ok 01:34:00.0897 1612 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 01:34:00.0901 1612 DcomLaunch - ok 01:34:00.0927 1612 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 01:34:00.0930 1612 defragsvc - ok 01:34:00.0969 1612 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 01:34:00.0970 1612 DfsC - ok 01:34:01.0002 1612 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll 01:34:01.0005 1612 Dhcp - ok 01:34:01.0027 1612 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 01:34:01.0028 1612 discache - ok 01:34:01.0036 1612 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 01:34:01.0037 1612 Disk - ok 01:34:01.0064 1612 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll 01:34:01.0066 1612 Dnscache - ok 01:34:01.0127 1612 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll 01:34:01.0130 1612 dot3svc - ok 01:34:01.0144 1612 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll 01:34:01.0146 1612 DPS - ok 01:34:01.0163 1612 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 01:34:01.0164 1612 drmkaud - ok 01:34:01.0202 1612 DrvAgent32 (651554e483712b708ede864d0ca1aa73) C:\Windows\system32\Drivers\DrvAgent32.sys 01:34:01.0202 1612 DrvAgent32 - ok 01:34:01.0247 1612 DvmMDES (e5b95c75557120881076c45cd146d72c) C:\ASUS.SYS\config\DVMExportService.exe 01:34:01.0250 1612 DvmMDES - ok 01:34:01.0294 1612 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 01:34:01.0300 1612 DXGKrnl - ok 01:34:01.0302 1612 EagleNT - ok 01:34:01.0322 1612 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 01:34:01.0324 1612 EapHost - ok 01:34:01.0398 1612 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 01:34:01.0435 1612 ebdrv - ok 01:34:01.0519 1612 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe 01:34:01.0520 1612 EFS - ok 01:34:01.0570 1612 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe 01:34:01.0575 1612 ehRecvr - ok 01:34:01.0598 1612 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 01:34:01.0600 1612 ehSched - ok 01:34:01.0633 1612 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 01:34:01.0637 1612 elxstor - ok 01:34:01.0659 1612 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 01:34:01.0660 1612 ErrDev - ok 01:34:01.0693 1612 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 01:34:01.0696 1612 EventSystem - ok 01:34:01.0720 1612 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 01:34:01.0721 1612 exfat - ok 01:34:01.0748 1612 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 01:34:01.0749 1612 fastfat - ok 01:34:01.0806 1612 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe 01:34:01.0811 1612 Fax - ok 01:34:01.0833 1612 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 01:34:01.0834 1612 fdc - ok 01:34:01.0846 1612 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 01:34:01.0847 1612 fdPHost - ok 01:34:01.0888 1612 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 01:34:01.0889 1612 FDResPub - ok 01:34:01.0915 1612 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 01:34:01.0916 1612 FileInfo - ok 01:34:01.0927 1612 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 01:34:01.0928 1612 Filetrace - ok 01:34:01.0931 1612 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 01:34:01.0932 1612 flpydisk - ok 01:34:01.0961 1612 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 01:34:01.0963 1612 FltMgr - ok 01:34:02.0006 1612 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll 01:34:02.0013 1612 FontCache - ok 01:34:02.0076 1612 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 01:34:02.0078 1612 FontCache3.0.0.0 - ok 01:34:02.0145 1612 ForceWare Intelligent Application Manager (IAM) (c96c52d0d80666af585516ffa97b7c00) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe 01:34:02.0148 1612 ForceWare Intelligent Application Manager (IAM) - ok 01:34:02.0195 1612 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 01:34:02.0196 1612 FsDepends - ok 01:34:02.0227 1612 fssfltr (491e9d9a26a745f6ae7d570849f4bd87) C:\Windows\system32\DRIVERS\fssfltr.sys 01:34:02.0228 1612 fssfltr - ok 01:34:02.0276 1612 fsssvc (45b52394f9624237f33a8a3d73c0b221) C:\Program Files\Windows Live\Family Safety\fsssvc.exe 01:34:02.0282 1612 fsssvc - ok 01:34:02.0307 1612 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys 01:34:02.0308 1612 Fs_Rec - ok 01:34:02.0335 1612 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 01:34:02.0337 1612 fvevol - ok 01:34:02.0354 1612 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 01:34:02.0355 1612 gagp30kx - ok 01:34:02.0380 1612 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 01:34:02.0381 1612 GEARAspiWDM - ok 01:34:02.0426 1612 GGSAFERDriver - ok 01:34:02.0464 1612 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll 01:34:02.0470 1612 gpsvc - ok 01:34:02.0500 1612 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 01:34:02.0502 1612 gupdate - ok 01:34:02.0504 1612 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 01:34:02.0505 1612 gupdatem - ok 01:34:02.0528 1612 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 01:34:02.0530 1612 gusvc - ok 01:34:02.0559 1612 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 01:34:02.0560 1612 hcw85cir - ok 01:34:02.0596 1612 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 01:34:02.0598 1612 HdAudAddService - ok 01:34:02.0609 1612 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 01:34:02.0610 1612 HDAudBus - ok 01:34:02.0635 1612 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 01:34:02.0636 1612 HidBatt - ok 01:34:02.0673 1612 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 01:34:02.0674 1612 HidBth - ok 01:34:02.0690 1612 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 01:34:02.0691 1612 HidIr - ok 01:34:02.0712 1612 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 01:34:02.0714 1612 hidserv - ok 01:34:02.0733 1612 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 01:34:02.0734 1612 HidUsb - ok 01:34:02.0765 1612 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll 01:34:02.0767 1612 hkmsvc - ok 01:34:02.0789 1612 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll 01:34:02.0792 1612 HomeGroupListener - ok 01:34:02.0819 1612 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll 01:34:02.0822 1612 HomeGroupProvider - ok 01:34:02.0829 1612 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 01:34:02.0830 1612 HpSAMD - ok 01:34:02.0876 1612 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 01:34:02.0896 1612 HTTP - ok 01:34:02.0915 1612 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 01:34:02.0916 1612 hwpolicy - ok 01:34:02.0929 1612 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 01:34:02.0930 1612 i8042prt - ok 01:34:03.0023 1612 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 01:34:03.0030 1612 iaStorV - ok 01:34:03.0125 1612 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 01:34:03.0133 1612 idsvc - ok 01:34:03.0184 1612 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 01:34:03.0186 1612 iirsp - ok 01:34:03.0327 1612 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll 01:34:03.0333 1612 IKEEXT - ok 01:34:03.0419 1612 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 01:34:03.0420 1612 intelide - ok 01:34:03.0443 1612 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 01:34:03.0445 1612 intelppm - ok 01:34:03.0462 1612 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 01:34:03.0464 1612 IPBusEnum - ok 01:34:03.0479 1612 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 01:34:03.0480 1612 IpFilterDriver - ok 01:34:03.0517 1612 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll 01:34:03.0522 1612 iphlpsvc - ok 01:34:03.0533 1612 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 01:34:03.0535 1612 IPMIDRV - ok 01:34:03.0543 1612 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 01:34:03.0545 1612 IPNAT - ok 01:34:03.0599 1612 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe 01:34:03.0605 1612 iPod Service - ok 01:34:03.0616 1612 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 01:34:03.0617 1612 IRENUM - ok 01:34:03.0627 1612 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 01:34:03.0629 1612 isapnp - ok 01:34:03.0643 1612 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 01:34:03.0645 1612 iScsiPrt - ok 01:34:03.0670 1612 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys 01:34:03.0670 1612 kbdclass - ok 01:34:03.0691 1612 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys 01:34:03.0692 1612 kbdhid - ok 01:34:03.0732 1612 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 01:34:03.0733 1612 KeyIso - ok 01:34:03.0761 1612 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys 01:34:03.0762 1612 KSecDD - ok 01:34:03.0780 1612 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys 01:34:03.0781 1612 KSecPkg - ok 01:34:03.0804 1612 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 01:34:03.0808 1612 KtmRm - ok 01:34:03.0851 1612 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\System32\srvsvc.dll 01:34:03.0854 1612 LanmanServer - ok 01:34:03.0877 1612 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll 01:34:03.0880 1612 LanmanWorkstation - ok 01:34:03.0895 1612 Lavasoft Kernexplorer - ok 01:34:03.0918 1612 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 01:34:03.0919 1612 lltdio - ok 01:34:03.0948 1612 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 01:34:03.0951 1612 lltdsvc - ok 01:34:03.0960 1612 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 01:34:03.0961 1612 lmhosts - ok 01:34:03.0980 1612 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 01:34:03.0982 1612 LSI_FC - ok 01:34:03.0999 1612 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 01:34:04.0001 1612 LSI_SAS - ok 01:34:04.0020 1612 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 01:34:04.0021 1612 LSI_SAS2 - ok 01:34:04.0063 1612 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 01:34:04.0064 1612 LSI_SCSI - ok 01:34:04.0086 1612 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 01:34:04.0087 1612 luafv - ok 01:34:04.0121 1612 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll 01:34:04.0134 1612 Mcx2Svc - ok 01:34:04.0188 1612 MDM (7cf1b716372b89568ae4c0fe769f5869) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 01:34:04.0191 1612 MDM - ok 01:34:04.0203 1612 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 01:34:04.0204 1612 megasas - ok 01:34:04.0217 1612 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 01:34:04.0220 1612 MegaSR - ok 01:34:04.0233 1612 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 01:34:04.0235 1612 MMCSS - ok 01:34:04.0259 1612 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 01:34:04.0260 1612 Modem - ok 01:34:04.0296 1612 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 01:34:04.0296 1612 monitor - ok 01:34:04.0333 1612 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 01:34:04.0334 1612 mouclass - ok 01:34:04.0358 1612 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 01:34:04.0359 1612 mouhid - ok 01:34:04.0392 1612 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 01:34:04.0394 1612 mountmgr - ok 01:34:04.0407 1612 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 01:34:04.0409 1612 mpio - ok 01:34:04.0424 1612 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 01:34:04.0425 1612 mpsdrv - ok 01:34:04.0468 1612 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll 01:34:04.0474 1612 MpsSvc - ok 01:34:04.0487 1612 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 01:34:04.0489 1612 MRxDAV - ok 01:34:04.0520 1612 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 01:34:04.0521 1612 mrxsmb - ok 01:34:04.0549 1612 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 01:34:04.0551 1612 mrxsmb10 - ok 01:34:04.0563 1612 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 01:34:04.0564 1612 mrxsmb20 - ok 01:34:04.0594 1612 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 01:34:04.0595 1612 msahci - ok 01:34:04.0604 1612 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 01:34:04.0605 1612 msdsm - ok 01:34:04.0636 1612 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 01:34:04.0639 1612 MSDTC - ok 01:34:04.0674 1612 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 01:34:04.0675 1612 Msfs - ok 01:34:04.0705 1612 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 01:34:04.0706 1612 mshidkmdf - ok 01:34:04.0732 1612 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 01:34:04.0733 1612 msisadrv - ok 01:34:04.0776 1612 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 01:34:04.0778 1612 MSiSCSI - ok 01:34:04.0791 1612 msiserver - ok 01:34:04.0797 1612 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 01:34:04.0798 1612 MSKSSRV - ok 01:34:04.0817 1612 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 01:34:04.0818 1612 MSPCLOCK - ok 01:34:04.0825 1612 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 01:34:04.0826 1612 MSPQM - ok 01:34:04.0843 1612 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 01:34:04.0845 1612 MsRPC - ok 01:34:04.0867 1612 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 01:34:04.0868 1612 mssmbios - ok 01:34:04.0892 1612 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 01:34:04.0892 1612 MSTEE - ok 01:34:04.0918 1612 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 01:34:04.0919 1612 MTConfig - ok 01:34:04.0950 1612 MTsensor (cbe71c122434805cb73ffb6619f60598) C:\Windows\system32\DRIVERS\ASACPI.sys 01:34:04.0950 1612 MTsensor - ok 01:34:04.0966 1612 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 01:34:04.0967 1612 Mup - ok 01:34:05.0002 1612 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll 01:34:05.0006 1612 napagent - ok 01:34:05.0019 1612 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 01:34:05.0022 1612 NativeWifiP - ok 01:34:05.0041 1612 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 01:34:05.0047 1612 NDIS - ok 01:34:05.0056 1612 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 01:34:05.0057 1612 NdisCap - ok 01:34:05.0075 1612 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 01:34:05.0076 1612 NdisTapi - ok 01:34:05.0108 1612 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 01:34:05.0110 1612 Ndisuio - ok 01:34:05.0119 1612 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 01:34:05.0120 1612 NdisWan - ok 01:34:05.0154 1612 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 01:34:05.0155 1612 NDProxy - ok 01:34:05.0167 1612 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 01:34:05.0168 1612 NetBIOS - ok 01:34:05.0206 1612 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 01:34:05.0208 1612 NetBT - ok 01:34:05.0247 1612 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 01:34:05.0248 1612 Netlogon - ok 01:34:05.0275 1612 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 01:34:05.0279 1612 Netman - ok 01:34:05.0318 1612 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 01:34:05.0331 1612 NetMsmqActivator - ok 01:34:05.0333 1612 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 01:34:05.0334 1612 NetPipeActivator - ok 01:34:05.0358 1612 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 01:34:05.0362 1612 netprofm - ok 01:34:05.0372 1612 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 01:34:05.0373 1612 NetTcpActivator - ok 01:34:05.0388 1612 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 01:34:05.0389 1612 NetTcpPortSharing - ok 01:34:05.0423 1612 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 01:34:05.0424 1612 nfrd960 - ok 01:34:05.0469 1612 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll 01:34:05.0472 1612 NlaSvc - ok 01:34:05.0492 1612 nmwcdnsu (4f0de685a96dc843ccc8a861b3fac12d) C:\Windows\system32\drivers\nmwcdnsu.sys 01:34:05.0494 1612 nmwcdnsu - ok 01:34:05.0537 1612 npf (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys 01:34:05.0538 1612 npf - ok 01:34:05.0549 1612 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 01:34:05.0550 1612 Npfs - ok 01:34:05.0553 1612 npggsvc - ok 01:34:05.0579 1612 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 01:34:05.0599 1612 nsi - ok 01:34:05.0616 1612 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 01:34:05.0617 1612 nsiproxy - ok 01:34:05.0737 1612 nSvcIp (b6c48d01147ec020de7f1856734127f8) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe 01:34:05.0739 1612 nSvcIp - ok 01:34:05.0792 1612 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 01:34:05.0809 1612 Ntfs - ok 01:34:05.0889 1612 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 01:34:05.0890 1612 Null - ok 01:34:05.0928 1612 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys 01:34:05.0931 1612 NVENETFD - ok 01:34:05.0951 1612 NVHDA (3d7fb57354703809b5f0c23287fac1d6) C:\Windows\system32\drivers\nvhda32v.sys 01:34:05.0953 1612 NVHDA - ok 01:34:06.0276 1612 nvlddmkm (e891b3979f0cf2740c1b073f834221fe) C:\Windows\system32\DRIVERS\nvlddmkm.sys 01:34:06.0403 1612 nvlddmkm - ok 01:34:06.0491 1612 NVNET (1de923088878b495cd4219e47ba34eb8) C:\Windows\system32\DRIVERS\nvmf6232.sys 01:34:06.0494 1612 NVNET - ok 01:34:06.0522 1612 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 01:34:06.0524 1612 nvraid - ok 01:34:06.0532 1612 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 01:34:06.0533 1612 nvstor - ok 01:34:06.0561 1612 nvstor32 (3ff57a9a657c9690ecbc8b1e3b6e3979) C:\Windows\system32\DRIVERS\nvstor32.sys 01:34:06.0562 1612 nvstor32 - ok 01:34:06.0590 1612 nvsvc (ae2de8e165dcb93a66b21748e6f913df) C:\Windows\system32\nvvsvc.exe 01:34:06.0596 1612 nvsvc - ok 01:34:06.0747 1612 nvUpdatusService (c78581c14699c46fe0f0817416383134) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 01:34:06.0781 1612 nvUpdatusService - ok 01:34:06.0851 1612 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 01:34:06.0853 1612 nv_agp - ok 01:34:06.0896 1612 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 01:34:06.0900 1612 odserv - ok 01:34:06.0913 1612 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 01:34:06.0914 1612 ohci1394 - ok 01:34:06.0935 1612 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 01:34:06.0937 1612 ose - ok 01:34:06.0975 1612 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 01:34:06.0978 1612 p2pimsvc - ok 01:34:06.0990 1612 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 01:34:06.0993 1612 p2psvc - ok 01:34:07.0018 1612 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 01:34:07.0019 1612 Parport - ok 01:34:07.0046 1612 partmgr (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys 01:34:07.0047 1612 partmgr - ok 01:34:07.0052 1612 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 01:34:07.0053 1612 Parvdm - ok 01:34:07.0084 1612 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 01:34:07.0086 1612 PcaSvc - ok 01:34:07.0120 1612 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 01:34:07.0122 1612 pci - ok 01:34:07.0130 1612 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 01:34:07.0131 1612 pciide - ok 01:34:07.0148 1612 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 01:34:07.0149 1612 pcmcia - ok 01:34:07.0190 1612 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 01:34:07.0191 1612 pcw - ok 01:34:07.0218 1612 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 01:34:07.0223 1612 PEAUTH - ok 01:34:07.0256 1612 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 01:34:07.0265 1612 PeerDistSvc - ok 01:34:07.0349 1612 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll 01:34:07.0372 1612 pla - ok 01:34:07.0448 1612 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll 01:34:07.0453 1612 PlugPlay - ok 01:34:07.0503 1612 PnkBstrA (205e1b699fd3f2f9b036eea2ec30c620) C:\Windows\system32\PnkBstrA.exe 01:34:07.0506 1612 PnkBstrA - ok 01:34:07.0529 1612 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 01:34:07.0530 1612 PNRPAutoReg - ok 01:34:07.0549 1612 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 01:34:07.0552 1612 PNRPsvc - ok 01:34:07.0590 1612 Point32 (896d916de06f5502d301e8c4dc442ae8) C:\Windows\system32\DRIVERS\point32.sys 01:34:07.0591 1612 Point32 - ok 01:34:07.0627 1612 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll 01:34:07.0631 1612 PolicyAgent - ok 01:34:07.0651 1612 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll 01:34:07.0653 1612 Power - ok 01:34:07.0677 1612 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 01:34:07.0678 1612 PptpMiniport - ok 01:34:07.0688 1612 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 01:34:07.0689 1612 Processor - ok 01:34:07.0706 1612 ProfSvc (43ca4ccc22d52fb58e8988f0198851d0) C:\Windows\system32\profsvc.dll 01:34:07.0709 1612 ProfSvc - ok 01:34:07.0752 1612 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 01:34:07.0753 1612 ProtectedStorage - ok 01:34:07.0765 1612 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 01:34:07.0766 1612 Psched - ok 01:34:07.0800 1612 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 01:34:07.0824 1612 ql2300 - ok 01:34:07.0881 1612 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 01:34:07.0883 1612 ql40xx - ok 01:34:07.0902 1612 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 01:34:07.0905 1612 QWAVE - ok 01:34:07.0920 1612 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 01:34:07.0921 1612 QWAVEdrv - ok 01:34:07.0933 1612 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 01:34:07.0934 1612 RasAcd - ok 01:34:07.0951 1612 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 01:34:07.0952 1612 RasAgileVpn - ok 01:34:07.0985 1612 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 01:34:07.0988 1612 RasAuto - ok 01:34:08.0012 1612 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 01:34:08.0013 1612 Rasl2tp - ok 01:34:08.0049 1612 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll 01:34:08.0053 1612 RasMan - ok 01:34:08.0069 1612 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 01:34:08.0070 1612 RasPppoe - ok 01:34:08.0080 1612 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 01:34:08.0081 1612 RasSstp - ok 01:34:08.0122 1612 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 01:34:08.0124 1612 rdbss - ok 01:34:08.0138 1612 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 01:34:08.0139 1612 rdpbus - ok 01:34:08.0167 1612 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 01:34:08.0168 1612 RDPCDD - ok 01:34:08.0192 1612 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 01:34:08.0194 1612 RDPDR - ok 01:34:08.0220 1612 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 01:34:08.0221 1612 RDPENCDD - ok 01:34:08.0252 1612 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 01:34:08.0253 1612 RDPREFMP - ok 01:34:08.0555 1612 RDPWD (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys 01:34:08.0593 1612 RDPWD - ok 01:34:08.0628 1612 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 01:34:08.0630 1612 rdyboost - ok 01:34:08.0661 1612 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 01:34:08.0663 1612 RemoteAccess - ok 01:34:08.0685 1612 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 01:34:08.0688 1612 RemoteRegistry - ok 01:34:08.0723 1612 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\Windows\system32\Drivers\RimUsb.sys 01:34:08.0724 1612 RimUsb - ok 01:34:08.0736 1612 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 01:34:08.0738 1612 RpcEptMapper - ok 01:34:08.0766 1612 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 01:34:08.0768 1612 RpcLocator - ok 01:34:08.0805 1612 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\System32\rpcss.dll 01:34:08.0808 1612 RpcSs - ok 01:34:08.0847 1612 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 01:34:08.0848 1612 rspndr - ok 01:34:08.0881 1612 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 01:34:08.0882 1612 s3cap - ok 01:34:08.0910 1612 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 01:34:08.0911 1612 SamSs - ok 01:34:08.0919 1612 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 01:34:08.0937 1612 sbp2port - ok 01:34:08.0967 1612 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 01:34:08.0970 1612 SCardSvr - ok 01:34:08.0995 1612 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 01:34:08.0996 1612 scfilter - ok 01:34:09.0054 1612 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll 01:34:09.0062 1612 Schedule - ok 01:34:09.0107 1612 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 01:34:09.0108 1612 SCPolicySvc - ok 01:34:09.0133 1612 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll 01:34:09.0136 1612 SDRSVC - ok 01:34:09.0156 1612 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 01:34:09.0157 1612 secdrv - ok 01:34:09.0165 1612 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 01:34:09.0167 1612 seclogon - ok 01:34:09.0186 1612 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll 01:34:09.0188 1612 SENS - ok 01:34:09.0216 1612 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 01:34:09.0218 1612 SensrSvc - ok 01:34:09.0234 1612 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 01:34:09.0235 1612 Serenum - ok 01:34:09.0256 1612 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 01:34:09.0257 1612 Serial - ok 01:34:09.0284 1612 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 01:34:09.0284 1612 sermouse - ok 01:34:09.0348 1612 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll 01:34:09.0350 1612 SessionEnv - ok 01:34:09.0379 1612 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 01:34:09.0381 1612 sffdisk - ok 01:34:09.0389 1612 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 01:34:09.0390 1612 sffp_mmc - ok 01:34:09.0414 1612 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 01:34:09.0415 1612 sffp_sd - ok 01:34:09.0426 1612 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 01:34:09.0427 1612 sfloppy - ok 01:34:09.0452 1612 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 01:34:09.0455 1612 SharedAccess - ok 01:34:09.0507 1612 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll 01:34:09.0511 1612 ShellHWDetection - ok 01:34:09.0519 1612 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 01:34:09.0520 1612 sisagp - ok 01:34:09.0534 1612 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 01:34:09.0535 1612 SiSRaid2 - ok 01:34:09.0564 1612 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 01:34:09.0566 1612 SiSRaid4 - ok 01:34:09.0685 1612 Skype C2C Service (2a99850c2a6edd6c6602e822c716edaf) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 01:34:09.0722 1612 Skype C2C Service - ok 01:34:09.0776 1612 SkypeUpdate (c70aebd3608ed9fcea2a1bae83567ffc) C:\Program Files\Skype\Updater\Updater.exe 01:34:09.0777 1612 SkypeUpdate - ok 01:34:09.0894 1612 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 01:34:09.0895 1612 Smb - ok 01:34:09.0923 1612 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 01:34:09.0925 1612 SNMPTRAP - ok 01:34:09.0938 1612 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 01:34:09.0939 1612 spldr - ok 01:34:09.0971 1612 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe 01:34:09.0975 1612 Spooler - ok 01:34:10.0081 1612 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe 01:34:10.0128 1612 sppsvc - ok 01:34:10.0216 1612 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll 01:34:10.0218 1612 sppuinotify - ok 01:34:10.0263 1612 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 01:34:10.0263 1612 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 01:34:10.0265 1612 sptd ( LockedFile.Multi.Generic ) - warning 01:34:10.0265 1612 sptd - detected LockedFile.Multi.Generic (1) 01:34:10.0295 1612 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 01:34:10.0298 1612 srv - ok 01:34:10.0315 1612 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 01:34:10.0318 1612 srv2 - ok 01:34:10.0332 1612 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 01:34:10.0333 1612 srvnet - ok 01:34:10.0362 1612 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 01:34:10.0365 1612 SSDPSRV - ok 01:34:10.0379 1612 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 01:34:10.0381 1612 SstpSvc - ok 01:34:10.0410 1612 Steam Client Service - ok 01:34:10.0504 1612 Stereo Service (fc0a58529a02b1eed55ddc58696b7908) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 01:34:10.0507 1612 Stereo Service - ok 01:34:10.0531 1612 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 01:34:10.0532 1612 stexstor - ok 01:34:10.0565 1612 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll 01:34:10.0571 1612 StiSvc - ok 01:34:10.0604 1612 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 01:34:10.0605 1612 storflt - ok 01:34:10.0618 1612 StorSvc (0bf669f0a910beda4a32258d363af2a5) C:\Windows\system32\storsvc.dll 01:34:10.0620 1612 StorSvc - ok 01:34:10.0635 1612 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 01:34:10.0636 1612 storvsc - ok 01:34:10.0661 1612 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 01:34:10.0661 1612 swenum - ok 01:34:10.0741 1612 SwitchBoard (f577910a133a592234ebaad3f3afa258) C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 01:34:10.0745 1612 SwitchBoard - ok 01:34:10.0783 1612 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 01:34:10.0787 1612 swprv - ok 01:34:10.0837 1612 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll 01:34:10.0854 1612 SysMain - ok 01:34:10.0885 1612 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll 01:34:10.0888 1612 TabletInputService - ok 01:34:10.0904 1612 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll 01:34:10.0907 1612 TapiSrv - ok 01:34:10.0940 1612 TBPanel (04e1c782cf14b7282ebc633b0fd3ed16) C:\Windows\system32\drivers\TBPanel.sys 01:34:10.0940 1612 TBPanel - ok 01:34:10.0964 1612 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 01:34:10.0967 1612 TBS - ok 01:34:11.0015 1612 Tcpip (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys 01:34:11.0038 1612 Tcpip - ok 01:34:11.0114 1612 TCPIP6 (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys 01:34:11.0120 1612 TCPIP6 - ok 01:34:11.0202 1612 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 01:34:11.0203 1612 tcpipreg - ok 01:34:11.0237 1612 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 01:34:11.0238 1612 TDPIPE - ok 01:34:11.0268 1612 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys 01:34:11.0268 1612 TDTCP - ok 01:34:11.0303 1612 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 01:34:11.0304 1612 TermDD - ok 01:34:11.0337 1612 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll 01:34:11.0343 1612 TermService - ok 01:34:11.0368 1612 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 01:34:11.0370 1612 Themes - ok 01:34:11.0392 1612 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 01:34:11.0394 1612 THREADORDER - ok 01:34:11.0411 1612 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 01:34:11.0413 1612 TrkWks - ok 01:34:11.0461 1612 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe 01:34:11.0463 1612 TrustedInstaller - ok 01:34:11.0533 1612 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 01:34:11.0534 1612 tssecsrv - ok 01:34:11.0565 1612 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 01:34:11.0566 1612 TsUsbFlt - ok 01:34:11.0599 1612 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 01:34:11.0600 1612 tunnel - ok 01:34:11.0624 1612 TunRAudio (ee87c7a7a0ebedf713a152ca0d0462d6) C:\Windows\system32\drivers\TunRAudio.sys 01:34:11.0625 1612 TunRAudio - ok 01:34:11.0648 1612 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 01:34:11.0649 1612 uagp35 - ok 01:34:11.0685 1612 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 01:34:11.0687 1612 udfs - ok 01:34:11.0716 1612 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 01:34:11.0719 1612 UI0Detect - ok 01:34:11.0751 1612 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 01:34:11.0752 1612 uliagpkx - ok 01:34:11.0762 1612 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 01:34:11.0763 1612 umbus - ok 01:34:11.0770 1612 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 01:34:11.0771 1612 UmPass - ok 01:34:11.0805 1612 UmRdpService (409994a8eaceee4e328749c0353527a0) C:\Windows\System32\umrdp.dll 01:34:11.0808 1612 UmRdpService - ok 01:34:11.0830 1612 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 01:34:11.0834 1612 upnphost - ok 01:34:11.0851 1612 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\Windows\system32\Drivers\usbaapl.sys 01:34:11.0852 1612 USBAAPL - ok 01:34:11.0867 1612 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys 01:34:11.0868 1612 usbccgp - ok 01:34:11.0911 1612 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 01:34:11.0912 1612 usbcir - ok 01:34:11.0943 1612 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys 01:34:11.0945 1612 usbehci - ok 01:34:11.0970 1612 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys 01:34:11.0973 1612 usbhub - ok 01:34:11.0990 1612 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys 01:34:11.0991 1612 usbohci - ok 01:34:12.0008 1612 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 01:34:12.0009 1612 usbprint - ok 01:34:12.0041 1612 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 01:34:12.0042 1612 usbscan - ok 01:34:12.0070 1612 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 01:34:12.0071 1612 USBSTOR - ok 01:34:12.0088 1612 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 01:34:12.0089 1612 usbuhci - ok 01:34:12.0111 1612 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 01:34:12.0113 1612 UxSms - ok 01:34:12.0140 1612 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 01:34:12.0141 1612 VaultSvc - ok 01:34:12.0204 1612 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 01:34:12.0205 1612 vdrvroot - ok 01:34:12.0239 1612 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe 01:34:12.0244 1612 vds - ok 01:34:12.0267 1612 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 01:34:12.0268 1612 vga - ok 01:34:12.0274 1612 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 01:34:12.0274 1612 VgaSave - ok 01:34:12.0325 1612 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 01:34:12.0327 1612 vhdmp - ok 01:34:12.0345 1612 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 01:34:12.0346 1612 viaagp - ok 01:34:12.0366 1612 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 01:34:12.0367 1612 ViaC7 - ok 01:34:12.0417 1612 VIAHdAudAddService (b9ecf6756858c8fed4fe68e966bf2f5f) C:\Windows\system32\drivers\viahduaa.sys 01:34:12.0433 1612 VIAHdAudAddService - ok 01:34:12.0442 1612 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 01:34:12.0443 1612 viaide - ok 01:34:12.0465 1612 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 01:34:12.0467 1612 vmbus - ok 01:34:12.0479 1612 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 01:34:12.0480 1612 VMBusHID - ok 01:34:12.0493 1612 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 01:34:12.0495 1612 volmgr - ok 01:34:12.0508 1612 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 01:34:12.0511 1612 volmgrx - ok 01:34:12.0531 1612 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 01:34:12.0534 1612 volsnap - ok 01:34:12.0544 1612 vpcbus (b26536add1d748cda104d856c979ae79) C:\Windows\system32\DRIVERS\vpchbus.sys 01:34:12.0546 1612 vpcbus - ok 01:34:12.0579 1612 vpcnfltr (a0f7e923a6261760130f22b85df9040e) C:\Windows\system32\DRIVERS\vpcnfltr.sys 01:34:12.0581 1612 vpcnfltr - ok 01:34:12.0596 1612 vpcusb (5f4b55e91ce7e2523c9e1e0ece858869) C:\Windows\system32\DRIVERS\vpcusb.sys 01:34:12.0598 1612 vpcusb - ok 01:34:12.0654 1612 vpcvmm (b487191fe18d6863381a1ac55482469a) C:\Windows\system32\drivers\vpcvmm.sys 01:34:12.0656 1612 vpcvmm - ok 01:34:12.0690 1612 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 01:34:12.0693 1612 vsmraid - ok 01:34:12.0733 1612 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe 01:34:12.0743 1612 VSS - ok 01:34:12.0758 1612 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 01:34:12.0759 1612 vwifibus - ok 01:34:12.0788 1612 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 01:34:12.0792 1612 W32Time - ok 01:34:12.0806 1612 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 01:34:12.0808 1612 WacomPen - ok 01:34:12.0838 1612 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 01:34:12.0839 1612 WANARP - ok 01:34:12.0854 1612 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 01:34:12.0854 1612 Wanarpv6 - ok 01:34:12.0892 1612 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe 01:34:12.0916 1612 WatAdminSvc - ok 01:34:13.0072 1612 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe 01:34:13.0095 1612 wbengine - ok 01:34:13.0115 1612 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 01:34:13.0118 1612 WbioSrvc - ok 01:34:13.0147 1612 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll 01:34:13.0151 1612 wcncsvc - ok 01:34:13.0162 1612 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 01:34:13.0165 1612 WcsPlugInService - ok 01:34:13.0200 1612 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 01:34:13.0201 1612 Wd - ok 01:34:13.0220 1612 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 01:34:13.0224 1612 Wdf01000 - ok 01:34:13.0239 1612 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 01:34:13.0241 1612 WdiServiceHost - ok 01:34:13.0245 1612 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 01:34:13.0247 1612 WdiSystemHost - ok 01:34:13.0304 1612 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll 01:34:13.0308 1612 WebClient - ok 01:34:13.0358 1612 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 01:34:13.0361 1612 Wecsvc - ok 01:34:13.0377 1612 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 01:34:13.0380 1612 wercplsupport - ok 01:34:13.0399 1612 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 01:34:13.0401 1612 WerSvc - ok 01:34:13.0426 1612 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 01:34:13.0426 1612 WfpLwf - ok 01:34:13.0451 1612 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 01:34:13.0452 1612 WIMMount - ok 01:34:13.0528 1612 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 01:34:13.0533 1612 WinDefend - ok 01:34:13.0552 1612 WinHttpAutoProxySvc - ok 01:34:13.0777 1612 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 01:34:13.0778 1612 Winmgmt - ok 01:34:13.0832 1612 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll 01:34:13.0856 1612 WinRM - ok 01:34:13.0905 1612 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys 01:34:13.0906 1612 WinUsb - ok 01:34:13.0938 1612 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 01:34:13.0947 1612 Wlansvc - ok 01:34:14.0110 1612 wlidsvc (5144ae67d60ec653f97ddf3feed29e77) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 01:34:14.0130 1612 wlidsvc - ok 01:34:14.0199 1612 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 01:34:14.0200 1612 WmiAcpi - ok 01:34:14.0237 1612 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 01:34:14.0238 1612 wmiApSrv - ok 01:34:14.0317 1612 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe 01:34:14.0333 1612 WMPNetworkSvc - ok 01:34:14.0383 1612 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 01:34:14.0386 1612 WPCSvc - ok 01:34:14.0397 1612 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll 01:34:14.0400 1612 WPDBusEnum - ok 01:34:14.0434 1612 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 01:34:14.0434 1612 ws2ifsl - ok 01:34:14.0480 1612 WsAudio_DeviceS(2) (4160cbe59d9b5be22e4c3897e8db9d56) C:\Windows\system32\drivers\WsAudio_DeviceS(2).sys 01:34:14.0482 1612 WsAudio_DeviceS(2) - ok 01:34:14.0495 1612 WsAudio_DeviceS(3) (4160cbe59d9b5be22e4c3897e8db9d56) C:\Windows\system32\drivers\WsAudio_DeviceS(3).sys 01:34:14.0497 1612 WsAudio_DeviceS(3) - ok 01:34:14.0519 1612 WsAudio_DeviceS(4) (4160cbe59d9b5be22e4c3897e8db9d56) C:\Windows\system32\drivers\WsAudio_DeviceS(4).sys 01:34:14.0519 1612 WsAudio_DeviceS(4) - ok 01:34:14.0541 1612 WsAudio_DeviceS(5) (4160cbe59d9b5be22e4c3897e8db9d56) C:\Windows\system32\drivers\WsAudio_DeviceS(5).sys 01:34:14.0542 1612 WsAudio_DeviceS(5) - ok 01:34:14.0554 1612 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 01:34:14.0556 1612 wscsvc - ok 01:34:14.0564 1612 WSearch - ok 01:34:14.0633 1612 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll 01:34:14.0662 1612 wuauserv - ok 01:34:14.0762 1612 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 01:34:14.0764 1612 WudfPf - ok 01:34:14.0778 1612 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 01:34:14.0780 1612 WUDFRd - ok 01:34:14.0817 1612 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll 01:34:14.0819 1612 wudfsvc - ok 01:34:14.0847 1612 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 01:34:14.0851 1612 WwanSvc - ok 01:34:14.0870 1612 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 01:34:15.0108 1612 \Device\Harddisk0\DR0 - ok 01:34:15.0112 1612 Boot (0x1200) (16167dc4312cc4a36047c4afc1a7c939) \Device\Harddisk0\DR0\Partition0 01:34:15.0113 1612 \Device\Harddisk0\DR0\Partition0 - ok 01:34:15.0158 1612 Boot (0x1200) (90f9290e04f31f46a971980694e75f51) \Device\Harddisk0\DR0\Partition1 01:34:15.0160 1612 \Device\Harddisk0\DR0\Partition1 - ok 01:34:15.0188 1612 Boot (0x1200) (918544818a1133a2cb50ed618cd63f42) \Device\Harddisk0\DR0\Partition2 01:34:15.0189 1612 \Device\Harddisk0\DR0\Partition2 - ok 01:34:15.0190 1612 ============================================================ 01:34:15.0190 1612 Scan finished 01:34:15.0190 1612 ============================================================ 01:34:15.0217 4500 Detected object count: 1 01:34:15.0217 4500 Actual detected object count: 1 01:34:42.0402 4500 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine 01:34:42.0402 4500 sptd ( LockedFile.Multi.Generic ) - User select action: Quarantine 01:34:59.0131 4664 Deinitialize success
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 12-06-28.03 - Henry 06/30/2012 2:35.2.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.1719 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\StartSearch plugin c:\program files\StartSearch plugin\BarLcher.dll c:\program files\StartSearch plugin\IEhelperActiveX.dll c:\program files\StartSearch plugin\uninst.exe c:\program files\StartSearch plugin\vShareBar.dll c:\program files\StartSearch plugin\vshareplg.crx c:\users\Henry\AppData\Roaming\1 5 c:\users\Henry\AppData\Roaming\1 5\bat.bat c:\users\Henry\AppData\Roaming\1 5\bt.lnk c:\users\Henry\AppData\Roaming\1 5\diablo120328.cl c:\users\Henry\AppData\Roaming\1 5\j.exe c:\users\Henry\AppData\Roaming\1 5\l3.lnk c:\users\Henry\AppData\Roaming\1 5\libcurl.dll c:\users\Henry\AppData\Roaming\1 5\libeay32.dll c:\users\Henry\AppData\Roaming\1 5\libidn-11.dll c:\users\Henry\AppData\Roaming\1 5\libpdcurses.dll c:\users\Henry\AppData\Roaming\1 5\libssl32.dll c:\users\Henry\AppData\Roaming\1 5\phatk120223.cl c:\users\Henry\AppData\Roaming\1 5\poclbm120327.cl c:\users\Henry\AppData\Roaming\1 5\poclbm120327GeForce GT 220v1w256l4.bin c:\users\Henry\AppData\Roaming\1 5\pthreadGC2.dll c:\users\Henry\AppData\Roaming\1 5\README c:\users\Henry\AppData\Roaming\1 5\rundll32.exe c:\users\Henry\AppData\Roaming\1 5\settings.txt c:\users\Henry\AppData\Roaming\1 5\svchost.exe c:\users\Henry\AppData\Roaming\1 5\svchost2.exe c:\users\Henry\AppData\Roaming\9 1 c:\users\Henry\AppData\Roaming\9 1\_ctypes.pyd c:\users\Henry\AppData\Roaming\9 1\_hashlib.pyd c:\users\Henry\AppData\Roaming\9 1\_socket.pyd c:\users\Henry\AppData\Roaming\9 1\_ssl.pyd c:\users\Henry\AppData\Roaming\9 1\bat.bat c:\users\Henry\AppData\Roaming\9 1\boost_python-vc90-mt-1_39.dll c:\users\Henry\AppData\Roaming\9 1\bt.lnk c:\users\Henry\AppData\Roaming\9 1\bz2.pyd c:\users\Henry\AppData\Roaming\9 1\e4a962245539a6c179b3945bca036481.elf c:\users\Henry\AppData\Roaming\9 1\j.exe c:\users\Henry\AppData\Roaming\9 1\l3.lnk c:\users\Henry\AppData\Roaming\9 1\library.zip c:\users\Henry\AppData\Roaming\9 1\msvcp90.dll c:\users\Henry\AppData\Roaming\9 1\numpy.core._dotblas.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.core._sort.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.core.multiarray.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.core.scalarmath.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.core.umath.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.fft.fftpack_lite.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.lib._compiled_base.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.linalg.lapack_lite.pyd c:\users\Henry\AppData\Roaming\9 1\numpy.random.mtrand.pyd c:\users\Henry\AppData\Roaming\9 1\phatk.cl c:\users\Henry\AppData\Roaming\9 1\pyopencl._cl.pyd c:\users\Henry\AppData\Roaming\9 1\python26.dll c:\users\Henry\AppData\Roaming\9 1\rundll32.exe c:\users\Henry\AppData\Roaming\9 1\select.pyd c:\users\Henry\AppData\Roaming\9 1\settings.txt c:\users\Henry\AppData\Roaming\9 1\svchost.exe c:\users\Henry\AppData\Roaming\9 1\svchost2.exe c:\users\Henry\AppData\Roaming\9 1\unicodedata.pyd c:\users\Henry\AppData\Roaming\9 1\w9xpopen.exe . c:\windows\system32\drivers\tdx.sys was missing Restored copy from - c:\windows\winsxs\x86_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.1.7600.16385_none_ea141e6f3d693e28\tdx.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_wvchatts . . ((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-29 ))))))))))))))))))))))))))))))) . . 2012-06-29 18:43 . 2012-06-29 18:43 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-06-29 18:43 . 2012-06-29 18:43 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-06-29 18:43 . 2012-06-29 18:43 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-29 18:43 . 2009-07-13 23:12 74240 —-a-w- c:\windows\system32\drivers\tdx.sys 2012-06-28 17:34 . 2012-06-28 17:34 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-28 15:55 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1DA2E91-E33F-4064-BB65-9C2C50AFB59B}\mpengine.dll 2012-06-26 04:19 . 2012-06-26 04:19 807 —-a-w- c:\users\Henry\AppData\Roaming\Henryv1.18.0 - Trial version.vbs 2012-06-22 01:42 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-22 01:42 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-22 01:42 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-22 01:42 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-22 01:41 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-22 01:41 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-22 01:41 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-22 01:41 . 2012-06-02 07:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-22 01:41 . 2012-06-02 07:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-14 16:02 . 2012-05-15 01:05 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 15:36 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 15:29 . 2012-04-26 04:45 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 15:29 . 2012-04-26 04:45 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-14 15:29 . 2012-04-26 04:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-08 14:33 . 2012-06-08 14:33 ——– d—–w- c:\program files\Common Files\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-23 18:48 . 2012-04-04 16:07 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-23 18:48 . 2011-09-10 13:43 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-22 08:34 . 2012-05-04 19:40 140800 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-06-22 08:34 . 2012-05-04 19:44 283304 —-a-w- c:\windows\system32\PnkBstrB.xtr 2012-06-22 08:34 . 2012-05-04 19:40 283304 —-a-w- c:\windows\system32\PnkBstrB.exe 2012-06-22 08:34 . 2012-05-04 19:40 280904 —-a-w- c:\windows\system32\PnkBstrB.ex0 2012-05-04 19:49 . 2012-05-04 19:40 76888 —-a-w- c:\windows\system32\PnkBstrA.exe 2012-05-04 19:40 . 2012-05-04 19:40 138056 —-a-w- c:\users\Henry\AppData\Roaming\PnkBstrK.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2010-05-26 07:23 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="c:\program files\Vtune\TBPanel.exe" [2009-10-05 2158592] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-11 39408] "Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448] "Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-09 619352] "ABBYY Screenshot Reader Bonus"="c:\program files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" [2009-11-19 939272] "Funshion"="c:\program files\Funshion Online\Funshion\Funshion.exe" [2012-03-06 3265264] "uTorrent"="b:\bit torrent\uTorrent.exe" [2012-05-16 880496] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-06-05 17344176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-02-10 1713152] "BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864] "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-12-28 887936] "Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-11-24 1874432] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736] . c:\users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-25 27112840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 ConvertTuneAudio;ConvertTuneAudio;c:\windows\system32\drivers\ConvertTuneAudio.sys [x] R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [x] R3 GGSAFERDriver;GGSAFER Driver;b:\garena plus\Room\safedrv.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TunRAudio;TunRAudio;c:\windows\system32\drivers\TunRAudio.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [x] R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [x] R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [x] R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [x] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x] S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x] S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x] S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x] S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [x] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [x] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-06-29 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:48] . 2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . 2012-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://startsear.ch/?aff=1&cf=30b0a508-49d1-11e1-8800-485b39f40826 uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: use Thunderbolt download - b:\thunder\Program\GetUrl.htm IE: use Xunlei download all the links - b:\thunder\Program\GetAllUrl.htm IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - b:\thunder\Thunder.exe TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: NameServer = 165.21.83.88,165.21.100.88 . - - - - ORPHANS REMOVED - - - - . AddRemove-vShare plugin - c:\program files\StartSearch plugin\uninst.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(4556) c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll b:\thunder\ComDlls\xunleiBHO_Now.dll b:\thunder\Components\ResWorker\DsBho_01.dll b:\thunder\Components\ResWorker\DataProcessor_01.dll c:\program files\MagicISO\misosh.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\windows\system32\WUDFHost.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\windows\system32\PnkBstrA.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\sppsvc.exe c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\windows\system32\conhost.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Funshion Online\Funshion\FunshionService.exe c:\windows\system32\DllHost.exe . ************************************************************************** . Completion time: 2012-06-30 02:50:23 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-29 18:50 ComboFix2.txt 2011-11-20 13:20 . Pre-Run: 75,101,949,952 bytes free Post-Run: 74,559,315,968 bytes free . - - End Of File - - EFEA2467322FCA576010BA7DC18648A0
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    mStart Page = hxxp://startsear.ch/?aff=1&cf=30b0a508-49d1-11e1-8800-485b39f40826
    uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: VshareComplete: {222f31fb-a14e-4af2-bb14-997f28294370} - c:\users\henry\appdata\roaming\vsharecomplete\VshareComplete.dll
    BHO: IE5BarLauncherBHO Class: {78f3a323-798e-4aea-9a57-88f4b05fd5dd} - c:\program files\startsearch plugin\BarLcher.dll
    BHO: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: Sopcast Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    TB: VShareToolBar: {7ac3e13b-3bca-4158-b330-f66dbb03c1b5} - c:\program files\startsearch plugin\BarLcher.dll
    uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
    mASetup: {D588YX8G-06R6-235V-4Y5B-4L57WR50OYK2} - c:\program files\adobe\reader.exe
    IE: use Xunlei download all the links - b:\thunder\Program\GetAllUrl.htm
    
    File::
    c:\program files\iobit\advanced systemcare 5\ASCService.exe
    c:\program files\Ask.com\GenericAskToolbar.dll
    
    Folder::
    c:\program files\IObit\Advanced SystemCare 5
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    
    Driver::
    AdvancedSystemCareService5
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 12-06-28.03 - Henry 07/01/2012 2:22.3.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2144 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Henry\Desktop\CFScript.txt SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\program files\Ask.com\GenericAskToolbar.dll" "c:\program files\iobit\advanced systemcare 5\ASCService.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Adobe\Reader.exe c:\program files\Ask.com\GenericAskToolbar.dll c:\program files\IObit\Advanced SystemCare 5 c:\program files\IObit\Advanced SystemCare 5\About.dll c:\program files\IObit\Advanced SystemCare 5\ActiveBoost.db c:\program files\IObit\Advanced SystemCare 5\ASC.exe c:\program files\IObit\Advanced SystemCare 5\ASCInit.exe c:\program files\iobit\advanced systemcare 5\ASCService.exe c:\program files\IObit\Advanced SystemCare 5\ASCService_Log.txt c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-16.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-17.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-18.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-19.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-20.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-21.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-22.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-23.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-24.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-25.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-26.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-27.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-28.log c:\program files\IObit\Advanced SystemCare 5\ASCTooltips.exe c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe c:\program files\IObit\Advanced SystemCare 5\ASCUpgrade.exe c:\program files\IObit\Advanced SystemCare 5\ASCv5ComputerMenu.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ComputerMenu_64.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll c:\program files\IObit\Advanced SystemCare 5\AutoCare.exe c:\program files\IObit\Advanced SystemCare 5\AutoSweep.exe c:\program files\IObit\Advanced SystemCare 5\AutoUpdate.exe c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-26 16-35-14 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-26 21-52-03 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-27 11-13-05 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-28 01-34-32 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-28 21-43-54 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-29 00-03-17 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-30 02-13-00 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-30 03-12-37 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-07-01 02-00-03 c:\program files\IObit\Advanced SystemCare 5\Boottime\path.ini c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-17(22-51-46).log c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-08(04-00-59).log c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-02-13(23-10-51).log c:\program files\IObit\Advanced SystemCare 5\checkinfo.txt c:\program files\IObit\Advanced SystemCare 5\Cus.dbd c:\program files\IObit\Advanced SystemCare 5\cxLibraryD12.bpl c:\program files\IObit\Advanced SystemCare 5\datastate.dll c:\program files\IObit\Advanced SystemCare 5\Def.dbd c:\program files\IObit\Advanced SystemCare 5\DelayLoad.exe c:\program files\IObit\Advanced SystemCare 5\diskhelper.dll c:\program files\IObit\Advanced SystemCare 5\DiskMap.dll c:\program files\IObit\Advanced SystemCare 5\DiskScan.exe c:\program files\IObit\Advanced SystemCare 5\DriverData.db c:\program files\IObit\Advanced SystemCare 5\drivers\win7_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\win7_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wlh_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wlh_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wnet_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wnet_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wxp_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wxp_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\dxBarD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxComnD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxCoreD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxDockingD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxGDIPlusD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxhelper.dll c:\program files\IObit\Advanced SystemCare 5\dxSkinOffice2007BlueD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxSkinsCoreD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxThemeD12.bpl c:\program files\IObit\Advanced SystemCare 5\EULA.rtf c:\program files\IObit\Advanced SystemCare 5\Ext.dbd c:\program files\IObit\Advanced SystemCare 5\fav.ico c:\program files\IObit\Advanced SystemCare 5\FfSweep.dll c:\program files\IObit\Advanced SystemCare 5\help.html c:\program files\IObit\Advanced SystemCare 5\Images\dcScreen.png c:\program files\IObit\Advanced SystemCare 5\Images\dcScreen2.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-dc.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-qc.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-tb.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-tbox.png c:\program files\IObit\Advanced SystemCare 5\Images\main.png c:\program files\IObit\Advanced SystemCare 5\Images\mainPro.png c:\program files\IObit\Advanced SystemCare 5\Images\toolboxscreen.png c:\program files\IObit\Advanced SystemCare 5\Images\turboboost.png c:\program files\IObit\Advanced SystemCare 5\IObitCommunities.exe c:\program files\IObit\Advanced SystemCare 5\IObitLogon.dll c:\program files\IObit\Advanced SystemCare 5\Language\ChineseSimp.lng c:\program files\IObit\Advanced SystemCare 5\Language\ChineseTrad.lng c:\program files\IObit\Advanced SystemCare 5\Language\Czech.lng c:\program files\IObit\Advanced SystemCare 5\Language\Danish.lng c:\program files\IObit\Advanced SystemCare 5\Language\English.lng c:\program files\IObit\Advanced SystemCare 5\Language\Finnish.lng c:\program files\IObit\Advanced SystemCare 5\Language\French.lng c:\program files\IObit\Advanced SystemCare 5\Language\German.lng c:\program files\IObit\Advanced SystemCare 5\Language\Greek.lng c:\program files\IObit\Advanced SystemCare 5\Language\Hungarian.lng c:\program files\IObit\Advanced SystemCare 5\Language\Italian.lng c:\program files\IObit\Advanced SystemCare 5\Language\japanese.lng c:\program files\IObit\Advanced SystemCare 5\Language\Nederlands.lng c:\program files\IObit\Advanced SystemCare 5\Language\Portuguese(PT-BR).lng c:\program files\IObit\Advanced SystemCare 5\Language\Russian.lng c:\program files\IObit\Advanced SystemCare 5\Language\Spanish.lng c:\program files\IObit\Advanced SystemCare 5\Language\Swedish.lng c:\program files\IObit\Advanced SystemCare 5\Language\Turkish.lng c:\program files\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg c:\program files\IObit\Advanced SystemCare 5\LatestNews\imagenews.png c:\program files\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini c:\program files\IObit\Advanced SystemCare 5\License.dat c:\program files\IObit\Advanced SystemCare 5\LicenseConverter.exe c:\program files\IObit\Advanced SystemCare 5\madbasic_.bpl c:\program files\IObit\Advanced SystemCare 5\maddisAsm_.bpl c:\program files\IObit\Advanced SystemCare 5\madexcept_.bpl c:\program files\IObit\Advanced SystemCare 5\NtfsData.dll c:\program files\IObit\Advanced SystemCare 5\OFCommon.dll c:\program files\IObit\Advanced SystemCare 5\OFCommon3.dll c:\program files\IObit\Advanced SystemCare 5\Promote.exe c:\program files\IObit\Advanced SystemCare 5\Reg.dbd c:\program files\IObit\Advanced SystemCare 5\Register.exe c:\program files\IObit\Advanced SystemCare 5\Register.log c:\program files\IObit\Advanced SystemCare 5\Report.exe c:\program files\IObit\Advanced SystemCare 5\RescueCenter.exe c:\program files\IObit\Advanced SystemCare 5\Restore.dbd c:\program files\IObit\Advanced SystemCare 5\rtl120.bpl c:\program files\IObit\Advanced SystemCare 5\Scan.dll c:\program files\IObit\Advanced SystemCare 5\SecurityHoleScan.log c:\program files\IObit\Advanced SystemCare 5\skin\black.rcc c:\program files\IObit\Advanced SystemCare 5\skin\cute.rcc c:\program files\IObit\Advanced SystemCare 5\skin\default.rcc c:\program files\IObit\Advanced SystemCare 5\skin\metal.rcc c:\program files\IObit\Advanced SystemCare 5\skin\public.rcc c:\program files\IObit\Advanced SystemCare 5\skin\white.rcc c:\program files\IObit\Advanced SystemCare 5\sqlite3.dll c:\program files\IObit\Advanced SystemCare 5\Suc10_RegistryCleaner.exe c:\program files\IObit\Advanced SystemCare 5\Suc11_PrivacySweeper.exe c:\program files\IObit\Advanced SystemCare 5\Suc12_Uninstal.exe c:\program files\IObit\Advanced SystemCare 5\Suc13_DiskCleaner.exe c:\program files\IObit\Advanced SystemCare 5\Suc14_FileShredder.exe c:\program files\IObit\Advanced SystemCare 5\Sun10_ClonedFilesScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sun11_AutoShutdown.exe c:\program files\IObit\Advanced SystemCare 5\Sun12_DiskExplorer.exe c:\program files\IObit\Advanced SystemCare 5\Sun13_SystemInformation.exe c:\program files\IObit\Advanced SystemCare 5\Sun14_EmptyFolderScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sun15_SystemControl.exe c:\program files\IObit\Advanced SystemCare 5\Suo10_SmartRAM.exe c:\program files\IObit\Advanced SystemCare 5\Suo11_InternetBooster.exe c:\program files\IObit\Advanced SystemCare 5\Suo12_StartupManager.exe c:\program files\IObit\Advanced SystemCare 5\Suo13_RegistryDefrag.exe c:\program files\IObit\Advanced SystemCare 5\Suo14_SmartDefrag.exe c:\program files\IObit\Advanced SystemCare 5\Suo15_GameBooster.exe c:\program files\IObit\Advanced SystemCare 5\Sur10_Undelete.exe c:\program files\IObit\Advanced SystemCare 5\Sur11_ShortcutFixer.exe c:\program files\IObit\Advanced SystemCare 5\Sur12_DiskDoctor.exe c:\program files\IObit\Advanced SystemCare 5\Sur13_WinFix.exe c:\program files\IObit\Advanced SystemCare 5\Sur14_IEHelper.exe c:\program files\IObit\Advanced SystemCare 5\Sus09_BrowserGuard.exe c:\program files\IObit\Advanced SystemCare 5\Sus10_SysExplorer.exe c:\program files\IObit\Advanced SystemCare 5\Sus11_SecurityHolesScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sus12_ProcessManager.exe c:\program files\IObit\Advanced SystemCare 5\Sus13_DriverManager.exe c:\program files\IObit\Advanced SystemCare 5\Sus14_IMF.exe c:\program files\IObit\Advanced SystemCare 5\taskmgr.dll c:\program files\IObit\Advanced SystemCare 5\TbFfSweep.dll c:\program files\IObit\Advanced SystemCare 5\TbFileSweep.dll c:\program files\IObit\Advanced SystemCare 5\toolbar.dbd c:\program files\IObit\Advanced SystemCare 5\ToolBox.exe c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\ChineseSimp.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\ChineseTrad.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Czech.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\English.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\French.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\German.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Greek.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Hungarian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Italian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\japanese.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Russian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Spanish.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Swedish.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Turkish.lng c:\program files\IObit\Advanced SystemCare 5\TurboBoost.exe c:\program files\IObit\Advanced SystemCare 5\TurboBoostGame.dbd c:\program files\IObit\Advanced SystemCare 5\Undelete.dll c:\program files\IObit\Advanced SystemCare 5\unins000.dat c:\program files\IObit\Advanced SystemCare 5\unins000.exe c:\program files\IObit\Advanced SystemCare 5\unins000.msg c:\program files\IObit\Advanced SystemCare 5\Update\Update.Ini c:\program files\IObit\Advanced SystemCare 5\UpdateHistory.txt c:\program files\IObit\Advanced SystemCare 5\vcl120.bpl c:\program files\IObit\Advanced SystemCare 5\vclx120.bpl c:\program files\IObit\Advanced SystemCare 5\WebUI.dll c:\program files\IObit\Advanced SystemCare 5\Wizard.exe c:\program files\IObit\Advanced SystemCare 5\zlibwapi.dll c:\users\henry\appdata\roaming\vsharecomplete\VshareComplete.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_AdvancedSystemCareService5 . . ((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-30 ))))))))))))))))))))))))))))))) . . 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\windows\system32\ASUS OC Profiles 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-30 18:20 . 2012-06-30 18:20 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1DA2E91-E33F-4064-BB65-9C2C50AFB59B}\offreg.dll 2012-06-29 18:43 . 2009-07-13 23:12 74240 —-a-w- c:\windows\system32\drivers\tdx.sys 2012-06-28 17:34 . 2012-06-28 17:34 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-28 15:55 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1DA2E91-E33F-4064-BB65-9C2C50AFB59B}\mpengine.dll 2012-06-26 04:19 . 2012-06-26 04:19 807 —-a-w- c:\users\Henry\AppData\Roaming\Henryv1.18.0 - Trial version.vbs 2012-06-22 01:42 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-22 01:42 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-22 01:42 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-22 01:42 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-22 01:41 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-22 01:41 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-22 01:41 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-22 01:41 . 2012-06-02 07:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-22 01:41 . 2012-06-02 07:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-14 16:02 . 2012-05-15 01:05 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 15:36 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 15:29 . 2012-04-26 04:45 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 15:29 . 2012-04-26 04:45 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-14 15:29 . 2012-04-26 04:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-08 14:33 . 2012-06-08 14:33 ——– d—–w- c:\program files\Common Files\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-23 18:48 . 2012-04-04 16:07 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-23 18:48 . 2011-09-10 13:43 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-22 08:34 . 2012-05-04 19:40 140800 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-06-22 08:34 . 2012-05-04 19:44 283304 —-a-w- c:\windows\system32\PnkBstrB.xtr 2012-06-22 08:34 . 2012-05-04 19:40 283304 —-a-w- c:\windows\system32\PnkBstrB.exe 2012-06-22 08:34 . 2012-05-04 19:40 280904 —-a-w- c:\windows\system32\PnkBstrB.ex0 2012-05-04 19:49 . 2012-05-04 19:40 76888 —-a-w- c:\windows\system32\PnkBstrA.exe 2012-05-04 19:40 . 2012-05-04 19:40 138056 —-a-w- c:\users\Henry\AppData\Roaming\PnkBstrK.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="c:\program files\Vtune\TBPanel.exe" [2009-10-05 2158592] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-11 39408] "Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448] "ABBYY Screenshot Reader Bonus"="c:\program files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" [2009-11-19 939272] "Funshion"="c:\program files\Funshion Online\Funshion\Funshion.exe" [2012-03-06 3265264] "uTorrent"="b:\bit torrent\uTorrent.exe" [2012-05-16 880496] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-06-05 17344176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-02-10 1713152] "BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864] "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-12-28 887936] "Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-11-24 1874432] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736] . c:\users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-25 27112840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 ConvertTuneAudio;ConvertTuneAudio;c:\windows\system32\drivers\ConvertTuneAudio.sys [x] R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [x] R3 GGSAFERDriver;GGSAFER Driver;b:\garena plus\Room\safedrv.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TunRAudio;TunRAudio;c:\windows\system32\drivers\TunRAudio.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [x] R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [x] R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [x] R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [x] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x] S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x] S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x] S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [x] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [x] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-06-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:48] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: use Thunderbolt download - b:\thunder\Program\GetUrl.htm IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - b:\thunder\Thunder.exe TCP: Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: NameServer = 165.21.83.88,165.21.100.88 . - - - - ORPHANS REMOVED - - - - . AddRemove-Advanced SystemCare 5_is1 - c:\program files\IObit\Advanced SystemCare 5\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(604) c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\windows\system32\PnkBstrA.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\sppsvc.exe c:\windows\system32\WUDFHost.exe c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\windows\system32\conhost.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Funshion Online\Funshion\FunshionService.exe c:\windows\system32\DllHost.exe c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe . ************************************************************************** . Completion time: 2012-07-01 02:35:13 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-30 18:35 ComboFix2.txt 2012-06-29 18:50 ComboFix3.txt 2011-11-20 13:20 . Pre-Run: 74,087,518,208 bytes free Post-Run: 73,764,888,576 bytes free . - - End Of File - - 7CF3AD7EB164A74677ED2C630A68BBB3
ComboFix 12-06-28.03 - Henry 07/01/2012 2:22.3.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2144 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Henry\Desktop\CFScript.txt SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\program files\Ask.com\GenericAskToolbar.dll" "c:\program files\iobit\advanced systemcare 5\ASCService.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Adobe\Reader.exe c:\program files\Ask.com\GenericAskToolbar.dll c:\program files\IObit\Advanced SystemCare 5 c:\program files\IObit\Advanced SystemCare 5\About.dll c:\program files\IObit\Advanced SystemCare 5\ActiveBoost.db c:\program files\IObit\Advanced SystemCare 5\ASC.exe c:\program files\IObit\Advanced SystemCare 5\ASCInit.exe c:\program files\iobit\advanced systemcare 5\ASCService.exe c:\program files\IObit\Advanced SystemCare 5\ASCService_Log.txt c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-16.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-17.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-18.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-19.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-20.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-21.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-22.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-23.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-24.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-25.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-26.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-27.log c:\program files\IObit\Advanced SystemCare 5\ASCServiceLog\2012-06-28.log c:\program files\IObit\Advanced SystemCare 5\ASCTooltips.exe c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe c:\program files\IObit\Advanced SystemCare 5\ASCUpgrade.exe c:\program files\IObit\Advanced SystemCare 5\ASCv5ComputerMenu.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ComputerMenu_64.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll c:\program files\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.dll c:\program files\IObit\Advanced SystemCare 5\AutoCare.exe c:\program files\IObit\Advanced SystemCare 5\AutoSweep.exe c:\program files\IObit\Advanced SystemCare 5\AutoUpdate.exe c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-26 16-35-14 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-26 21-52-03 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-27 11-13-05 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-28 01-34-32 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-28 21-43-54 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-29 00-03-17 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-30 02-13-00 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-06-30 03-12-37 c:\program files\IObit\Advanced SystemCare 5\Boottime\BootTimeData\2012-07-01 02-00-03 c:\program files\IObit\Advanced SystemCare 5\Boottime\path.ini c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-17(22-51-46).log c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-08(04-00-59).log c:\program files\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-02-13(23-10-51).log c:\program files\IObit\Advanced SystemCare 5\checkinfo.txt c:\program files\IObit\Advanced SystemCare 5\Cus.dbd c:\program files\IObit\Advanced SystemCare 5\cxLibraryD12.bpl c:\program files\IObit\Advanced SystemCare 5\datastate.dll c:\program files\IObit\Advanced SystemCare 5\Def.dbd c:\program files\IObit\Advanced SystemCare 5\DelayLoad.exe c:\program files\IObit\Advanced SystemCare 5\diskhelper.dll c:\program files\IObit\Advanced SystemCare 5\DiskMap.dll c:\program files\IObit\Advanced SystemCare 5\DiskScan.exe c:\program files\IObit\Advanced SystemCare 5\DriverData.db c:\program files\IObit\Advanced SystemCare 5\drivers\win7_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\win7_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wlh_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wlh_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wnet_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wnet_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wxp_amd64\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\drivers\wxp_x86\RegistryDefragBootTime.exe c:\program files\IObit\Advanced SystemCare 5\dxBarD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxComnD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxCoreD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxDockingD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxGDIPlusD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxhelper.dll c:\program files\IObit\Advanced SystemCare 5\dxSkinOffice2007BlueD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxSkinsCoreD12.bpl c:\program files\IObit\Advanced SystemCare 5\dxThemeD12.bpl c:\program files\IObit\Advanced SystemCare 5\EULA.rtf c:\program files\IObit\Advanced SystemCare 5\Ext.dbd c:\program files\IObit\Advanced SystemCare 5\fav.ico c:\program files\IObit\Advanced SystemCare 5\FfSweep.dll c:\program files\IObit\Advanced SystemCare 5\help.html c:\program files\IObit\Advanced SystemCare 5\Images\dcScreen.png c:\program files\IObit\Advanced SystemCare 5\Images\dcScreen2.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-dc.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-qc.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-tb.png c:\program files\IObit\Advanced SystemCare 5\Images\icon-tbox.png c:\program files\IObit\Advanced SystemCare 5\Images\main.png c:\program files\IObit\Advanced SystemCare 5\Images\mainPro.png c:\program files\IObit\Advanced SystemCare 5\Images\toolboxscreen.png c:\program files\IObit\Advanced SystemCare 5\Images\turboboost.png c:\program files\IObit\Advanced SystemCare 5\IObitCommunities.exe c:\program files\IObit\Advanced SystemCare 5\IObitLogon.dll c:\program files\IObit\Advanced SystemCare 5\Language\ChineseSimp.lng c:\program files\IObit\Advanced SystemCare 5\Language\ChineseTrad.lng c:\program files\IObit\Advanced SystemCare 5\Language\Czech.lng c:\program files\IObit\Advanced SystemCare 5\Language\Danish.lng c:\program files\IObit\Advanced SystemCare 5\Language\English.lng c:\program files\IObit\Advanced SystemCare 5\Language\Finnish.lng c:\program files\IObit\Advanced SystemCare 5\Language\French.lng c:\program files\IObit\Advanced SystemCare 5\Language\German.lng c:\program files\IObit\Advanced SystemCare 5\Language\Greek.lng c:\program files\IObit\Advanced SystemCare 5\Language\Hungarian.lng c:\program files\IObit\Advanced SystemCare 5\Language\Italian.lng c:\program files\IObit\Advanced SystemCare 5\Language\japanese.lng c:\program files\IObit\Advanced SystemCare 5\Language\Nederlands.lng c:\program files\IObit\Advanced SystemCare 5\Language\Portuguese(PT-BR).lng c:\program files\IObit\Advanced SystemCare 5\Language\Russian.lng c:\program files\IObit\Advanced SystemCare 5\Language\Spanish.lng c:\program files\IObit\Advanced SystemCare 5\Language\Swedish.lng c:\program files\IObit\Advanced SystemCare 5\Language\Turkish.lng c:\program files\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg c:\program files\IObit\Advanced SystemCare 5\LatestNews\imagenews.png c:\program files\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini c:\program files\IObit\Advanced SystemCare 5\License.dat c:\program files\IObit\Advanced SystemCare 5\LicenseConverter.exe c:\program files\IObit\Advanced SystemCare 5\madbasic_.bpl c:\program files\IObit\Advanced SystemCare 5\maddisAsm_.bpl c:\program files\IObit\Advanced SystemCare 5\madexcept_.bpl c:\program files\IObit\Advanced SystemCare 5\NtfsData.dll c:\program files\IObit\Advanced SystemCare 5\OFCommon.dll c:\program files\IObit\Advanced SystemCare 5\OFCommon3.dll c:\program files\IObit\Advanced SystemCare 5\Promote.exe c:\program files\IObit\Advanced SystemCare 5\Reg.dbd c:\program files\IObit\Advanced SystemCare 5\Register.exe c:\program files\IObit\Advanced SystemCare 5\Register.log c:\program files\IObit\Advanced SystemCare 5\Report.exe c:\program files\IObit\Advanced SystemCare 5\RescueCenter.exe c:\program files\IObit\Advanced SystemCare 5\Restore.dbd c:\program files\IObit\Advanced SystemCare 5\rtl120.bpl c:\program files\IObit\Advanced SystemCare 5\Scan.dll c:\program files\IObit\Advanced SystemCare 5\SecurityHoleScan.log c:\program files\IObit\Advanced SystemCare 5\skin\black.rcc c:\program files\IObit\Advanced SystemCare 5\skin\cute.rcc c:\program files\IObit\Advanced SystemCare 5\skin\default.rcc c:\program files\IObit\Advanced SystemCare 5\skin\metal.rcc c:\program files\IObit\Advanced SystemCare 5\skin\public.rcc c:\program files\IObit\Advanced SystemCare 5\skin\white.rcc c:\program files\IObit\Advanced SystemCare 5\sqlite3.dll c:\program files\IObit\Advanced SystemCare 5\Suc10_RegistryCleaner.exe c:\program files\IObit\Advanced SystemCare 5\Suc11_PrivacySweeper.exe c:\program files\IObit\Advanced SystemCare 5\Suc12_Uninstal.exe c:\program files\IObit\Advanced SystemCare 5\Suc13_DiskCleaner.exe c:\program files\IObit\Advanced SystemCare 5\Suc14_FileShredder.exe c:\program files\IObit\Advanced SystemCare 5\Sun10_ClonedFilesScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sun11_AutoShutdown.exe c:\program files\IObit\Advanced SystemCare 5\Sun12_DiskExplorer.exe c:\program files\IObit\Advanced SystemCare 5\Sun13_SystemInformation.exe c:\program files\IObit\Advanced SystemCare 5\Sun14_EmptyFolderScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sun15_SystemControl.exe c:\program files\IObit\Advanced SystemCare 5\Suo10_SmartRAM.exe c:\program files\IObit\Advanced SystemCare 5\Suo11_InternetBooster.exe c:\program files\IObit\Advanced SystemCare 5\Suo12_StartupManager.exe c:\program files\IObit\Advanced SystemCare 5\Suo13_RegistryDefrag.exe c:\program files\IObit\Advanced SystemCare 5\Suo14_SmartDefrag.exe c:\program files\IObit\Advanced SystemCare 5\Suo15_GameBooster.exe c:\program files\IObit\Advanced SystemCare 5\Sur10_Undelete.exe c:\program files\IObit\Advanced SystemCare 5\Sur11_ShortcutFixer.exe c:\program files\IObit\Advanced SystemCare 5\Sur12_DiskDoctor.exe c:\program files\IObit\Advanced SystemCare 5\Sur13_WinFix.exe c:\program files\IObit\Advanced SystemCare 5\Sur14_IEHelper.exe c:\program files\IObit\Advanced SystemCare 5\Sus09_BrowserGuard.exe c:\program files\IObit\Advanced SystemCare 5\Sus10_SysExplorer.exe c:\program files\IObit\Advanced SystemCare 5\Sus11_SecurityHolesScanner.exe c:\program files\IObit\Advanced SystemCare 5\Sus12_ProcessManager.exe c:\program files\IObit\Advanced SystemCare 5\Sus13_DriverManager.exe c:\program files\IObit\Advanced SystemCare 5\Sus14_IMF.exe c:\program files\IObit\Advanced SystemCare 5\taskmgr.dll c:\program files\IObit\Advanced SystemCare 5\TbFfSweep.dll c:\program files\IObit\Advanced SystemCare 5\TbFileSweep.dll c:\program files\IObit\Advanced SystemCare 5\toolbar.dbd c:\program files\IObit\Advanced SystemCare 5\ToolBox.exe c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\ChineseSimp.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\ChineseTrad.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Czech.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\English.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\French.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\German.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Greek.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Hungarian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Italian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\japanese.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Russian.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Spanish.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Swedish.lng c:\program files\IObit\Advanced SystemCare 5\Toolbox_Language\Turkish.lng c:\program files\IObit\Advanced SystemCare 5\TurboBoost.exe c:\program files\IObit\Advanced SystemCare 5\TurboBoostGame.dbd c:\program files\IObit\Advanced SystemCare 5\Undelete.dll c:\program files\IObit\Advanced SystemCare 5\unins000.dat c:\program files\IObit\Advanced SystemCare 5\unins000.exe c:\program files\IObit\Advanced SystemCare 5\unins000.msg c:\program files\IObit\Advanced SystemCare 5\Update\Update.Ini c:\program files\IObit\Advanced SystemCare 5\UpdateHistory.txt c:\program files\IObit\Advanced SystemCare 5\vcl120.bpl c:\program files\IObit\Advanced SystemCare 5\vclx120.bpl c:\program files\IObit\Advanced SystemCare 5\WebUI.dll c:\program files\IObit\Advanced SystemCare 5\Wizard.exe c:\program files\IObit\Advanced SystemCare 5\zlibwapi.dll c:\users\henry\appdata\roaming\vsharecomplete\VshareComplete.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_AdvancedSystemCareService5 . . ((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-30 ))))))))))))))))))))))))))))))) . . 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\windows\system32\ASUS OC Profiles 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-06-30 18:28 . 2012-06-30 18:28 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-30 18:20 . 2012-06-30 18:20 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1DA2E91-E33F-4064-BB65-9C2C50AFB59B}\offreg.dll 2012-06-29 18:43 . 2009-07-13 23:12 74240 —-a-w- c:\windows\system32\drivers\tdx.sys 2012-06-28 17:34 . 2012-06-28 17:34 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-28 15:55 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D1DA2E91-E33F-4064-BB65-9C2C50AFB59B}\mpengine.dll 2012-06-26 04:19 . 2012-06-26 04:19 807 —-a-w- c:\users\Henry\AppData\Roaming\Henryv1.18.0 - Trial version.vbs 2012-06-22 01:42 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-22 01:42 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-22 01:42 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-22 01:42 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-22 01:41 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-22 01:41 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-22 01:41 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-22 01:41 . 2012-06-02 07:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-22 01:41 . 2012-06-02 07:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-14 16:02 . 2012-05-15 01:05 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 15:36 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 15:29 . 2012-04-26 04:45 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 15:29 . 2012-04-26 04:45 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-14 15:29 . 2012-04-26 04:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-08 14:33 . 2012-06-08 14:33 ——– d—–w- c:\program files\Common Files\Skype . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-23 18:48 . 2012-04-04 16:07 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-23 18:48 . 2011-09-10 13:43 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-22 08:34 . 2012-05-04 19:40 140800 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-06-22 08:34 . 2012-05-04 19:44 283304 —-a-w- c:\windows\system32\PnkBstrB.xtr 2012-06-22 08:34 . 2012-05-04 19:40 283304 —-a-w- c:\windows\system32\PnkBstrB.exe 2012-06-22 08:34 . 2012-05-04 19:40 280904 —-a-w- c:\windows\system32\PnkBstrB.ex0 2012-05-04 19:49 . 2012-05-04 19:40 76888 —-a-w- c:\windows\system32\PnkBstrA.exe 2012-05-04 19:40 . 2012-05-04 19:40 138056 —-a-w- c:\users\Henry\AppData\Roaming\PnkBstrK.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="c:\program files\Vtune\TBPanel.exe" [2009-10-05 2158592] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-11 39408] "Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448] "ABBYY Screenshot Reader Bonus"="c:\program files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" [2009-11-19 939272] "Funshion"="c:\program files\Funshion Online\Funshion\Funshion.exe" [2012-03-06 3265264] "uTorrent"="b:\bit torrent\uTorrent.exe" [2012-05-16 880496] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-06-05 17344176] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-02-10 1713152] "BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864] "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-12-28 887936] "Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-11-24 1874432] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] "AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736] . c:\users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-25 27112840] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 ConvertTuneAudio;ConvertTuneAudio;c:\windows\system32\drivers\ConvertTuneAudio.sys [x] R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [x] R3 GGSAFERDriver;GGSAFER Driver;b:\garena plus\Room\safedrv.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TunRAudio;TunRAudio;c:\windows\system32\drivers\TunRAudio.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [x] R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [x] R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [x] R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [x] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x] S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x] S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [x] S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [x] S2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [x] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x] S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-06-30 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:48] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . 2012-06-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: use Thunderbolt download - b:\thunder\Program\GetUrl.htm IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - b:\thunder\Thunder.exe TCP: Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: NameServer = 165.21.83.88,165.21.100.88 . - - - - ORPHANS REMOVED - - - - . AddRemove-Advanced SystemCare 5_is1 - c:\program files\IObit\Advanced SystemCare 5\unins000.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(604) c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\windows\system32\PnkBstrA.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\sppsvc.exe c:\windows\system32\WUDFHost.exe c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\windows\system32\conhost.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Funshion Online\Funshion\FunshionService.exe c:\windows\system32\DllHost.exe c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe . ************************************************************************** . Completion time: 2012-07-01 02:35:13 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-30 18:35 ComboFix2.txt 2012-06-29 18:50 ComboFix3.txt 2011-11-20 13:20 . Pre-Run: 74,087,518,208 bytes free Post-Run: 73,764,888,576 bytes free . - - End Of File - - 7CF3AD7EB164A74677ED2C630A68BBB3

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI