This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Zeroaccess [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Norton located Trojan.Zeroaccess.B in the file Windows/System32/consrv.dll. Norton said manual removal was required. I went through the steps that Norton suggested with no success (Norton Power Eraser and Norton Bootable Recovery Tool). I have read on forum that removing consrv.dll will not remove the infection and can cause boot problems, so I stopped there. The computer is not showing any symptoms (that I am aware of). Any assistance would be appreciated.

Here is the hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:48:02 PM, on 7/6/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\JAN2OSD.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\SelectRebates\SelectRebates.exe
C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\Keystatus.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnect.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_257.exe
C:\Users\Lars\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ire&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll
R3 - URLSearchHook: (no name) - {8bc67b0f-a721-45e0-a0b6-db0121b0aade} - C:\Program Files (x86)\RadioPI_4e\bar\1.bin\4eSrcAs.dll (file missing)
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~2\ArcSoft\MEDIAC~1\INTERN~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: ShopAtHomeIEHelper - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coIEPlg.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: ShopAtHome.com Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
O3 - Toolbar: RadioPI - {92926b63-5116-4c6f-a33e-378767b8d15f} - C:\Program Files (x86)\RadioPI_4e\bar\1.bin\4ebar.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [HP KEYBOARDx] "C:\Program Files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE"
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [Buttons & OSDs control application gen3] c:\Program Files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SelectRebates] C:\Program Files (x86)\SelectRebates\SelectRebates.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_257_Plugin.exe -update plugin
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download by GAS - C:\PROGRA~1\GETASF~1\ie_MenuExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Launches HP Network Check that helps you solve connection issues - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: HP Network Check - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://lnmai002.cs-apps.carestreamhealth.com/iNotes6W.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Amazon Download Agent - Amazon.com - C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: CalendarSynchService - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\BurnAware Free\NMSAccess32.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 18383 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Thank you for your assistance. I have backed up personal files, and have run the aswMBR and the TDSSKiller (logs are below). I am starting some long shifts tomorrow, but I will try to respond as quickly as possible. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-09 22:35:09 —————————– 22:35:09.641 OS Version: Windows x64 6.1.7601 Service Pack 1 22:35:09.641 Number of processors: 2 586 0x602 22:35:09.641 ComputerName: LARS-PC UserName: Lars 22:35:11.949 Initialize success 22:36:11.127 AVAST engine defs: 12070901 22:36:28.644 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000063 22:36:28.644 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 11 22:36:28.659 Disk 0 MBR read successfully 22:36:28.659 Disk 0 MBR scan 22:36:28.659 Disk 0 unknown MBR code 22:36:28.675 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 22:36:28.690 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 463784 MB offset 206848 22:36:28.737 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 13054 MB offset 950036480 22:36:28.768 Disk 0 scanning C:\Windows\system32\drivers 22:36:45.014 Service scanning 22:37:10.454 Modules scanning 22:37:10.469 Disk 0 trace - called modules: 22:37:10.485 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 22:37:10.501 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003d82060] 22:37:10.501 3 CLASSPNP.SYS[fffff8800165143f] -> nt!IofCallDriver -> [0xfffffa8003d77b80] 22:37:10.501 5 amdxata.sys[fffff88000c017a8] -> nt!IofCallDriver -> \Device\00000063[0xfffffa8003d738f0] 22:37:12.295 AVAST engine scan C:\Windows 22:37:15.303 AVAST engine scan C:\Windows\system32 22:41:59.812 AVAST engine scan C:\Windows\system32\drivers 22:42:22.928 AVAST engine scan C:\Users\Lars 23:00:16.766 Disk 0 MBR has been saved successfully to "C:\Users\Lars\Desktop\MBR.dat" 23:00:16.766 The log file has been saved successfully to "C:\Users\Lars\Desktop\aswMBR.txt" 23:23:52.058 AVAST engine scan C:\ProgramData 23:41:21.479 Scan finished successfully 23:48:11.922 Disk 0 MBR has been saved successfully to "C:\Users\Lars\Desktop\MBR.dat" 23:48:11.937 The log file has been saved successfully to "C:\Users\Lars\Desktop\aswMBR.txt" 23:04:18.0216 35168 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35 23:04:20.0219 35168 ============================================================ 23:04:20.0219 35168 Current date / time: 2012/07/09 23:04:20.0219 23:04:20.0219 35168 SystemInfo: 23:04:20.0219 35168 23:04:20.0219 35168 OS Version: 6.1.7601 ServicePack: 1.0 23:04:20.0219 35168 Product type: Workstation 23:04:20.0219 35168 ComputerName: LARS-PC 23:04:20.0219 35168 UserName: Lars 23:04:20.0219 35168 Windows directory: C:\Windows 23:04:20.0219 35168 System windows directory: C:\Windows 23:04:20.0219 35168 Running under WOW64 23:04:20.0219 35168 Processor architecture: Intel x64 23:04:20.0219 35168 Number of processors: 2 23:04:20.0219 35168 Page size: 0x1000 23:04:20.0219 35168 Boot type: Normal boot 23:04:20.0219 35168 ============================================================ 23:04:24.0730 35168 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:04:24.0760 35168 ============================================================ 23:04:24.0760 35168 \Device\Harddisk0\DR0: 23:04:24.0770 35168 MBR partitions: 23:04:24.0770 35168 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 23:04:24.0770 35168 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x389D4000 23:04:24.0770 35168 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x38A06800, BlocksNum 0x197F000 23:04:24.0770 35168 ============================================================ 23:04:24.0860 35168 C: <-> \Device\Harddisk0\DR0\Partition1 23:04:25.0060 35168 D: <-> \Device\Harddisk0\DR0\Partition2 23:04:25.0060 35168 ============================================================ 23:04:25.0060 35168 Initialize success 23:04:25.0060 35168 ============================================================ 23:04:48.0851 34028 ============================================================ 23:04:48.0851 34028 Scan started 23:04:48.0851 34028 Mode: Manual; 23:04:48.0851 34028 ============================================================ 23:04:50.0353 34028 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 23:04:50.0383 34028 1394ohci - ok 23:04:50.0633 34028 ACDaemon (adc420616c501b45d26c0fd3ef1e54e4) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 23:04:50.0643 34028 ACDaemon - ok 23:04:50.0763 34028 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 23:04:50.0773 34028 ACPI - ok 23:04:50.0843 34028 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 23:04:50.0853 34028 AcpiPmi - ok 23:04:50.0953 34028 ACPIService (de7e8d852a806be6091983838bf9697f) C:\Windows\system32\DRIVERS\OSDACPI.SYS 23:04:50.0953 34028 ACPIService - ok 23:04:51.0163 34028 ADIHdAudAddService (0fa60a409e1c8ab9a81901311d15393d) C:\Windows\system32\drivers\ADIHdAud.sys 23:04:51.0183 34028 ADIHdAudAddService - ok 23:04:51.0323 34028 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 23:04:51.0333 34028 AdobeARMservice - ok 23:04:51.0734 34028 AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 23:04:51.0744 34028 AdobeFlashPlayerUpdateSvc - ok 23:04:52.0264 34028 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 23:04:52.0264 34028 adp94xx - ok 23:04:52.0434 34028 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 23:04:52.0454 34028 adpahci - ok 23:04:52.0604 34028 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 23:04:52.0624 34028 adpu320 - ok 23:04:52.0684 34028 AEADIFilters (3bdb13c79cc8c06e2f8182595903ed69) C:\Windows\system32\AEADISRV.EXE 23:04:52.0684 34028 AEADIFilters - ok 23:04:52.0714 34028 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 23:04:52.0734 34028 AeLookupSvc - ok 23:04:53.0024 34028 Afc (6ccd1135320109d6b219f1a6e04ad9f6) C:\Windows\syswow64\drivers\Afc.sys 23:04:53.0024 34028 Afc - ok 23:04:53.0314 34028 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys 23:04:53.0324 34028 AFD - ok 23:04:53.0474 34028 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 23:04:53.0474 34028 agp440 - ok 23:04:53.0554 34028 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 23:04:53.0564 34028 ALG - ok 23:04:53.0644 34028 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 23:04:53.0654 34028 aliide - ok 23:04:53.0944 34028 Amazon Download Agent (ff6f0f6a2d72065ae4300426fa414693) C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe 23:04:53.0954 34028 Amazon Download Agent - ok 23:04:54.0114 34028 AMD External Events Utility (c4c88cd854b28fc85495c841a0f6a069) C:\Windows\system32\atiesrxx.exe 23:04:54.0114 34028 AMD External Events Utility - ok 23:04:54.0154 34028 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 23:04:54.0154 34028 amdide - ok 23:04:54.0274 34028 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 23:04:54.0274 34028 AmdK8 - ok 23:04:55.0674 34028 amdkmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atipmdag.sys 23:04:55.0804 34028 amdkmdag - ok 23:04:56.0032 34028 amdkmdap (ebc963d8f5b04c98f5ef597aae79cddd) C:\Windows\system32\DRIVERS\atikmpag.sys 23:04:56.0032 34028 amdkmdap - ok 23:04:56.0110 34028 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 23:04:56.0110 34028 AmdPPM - ok 23:04:56.0173 34028 amdsata (f747497a0ee5498f79b207f215b3d2d8) C:\Windows\system32\DRIVERS\amdsata.sys 23:04:56.0173 34028 amdsata - ok 23:04:56.0313 34028 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 23:04:56.0313 34028 amdsbs - ok 23:04:56.0376 34028 amdxata (2946d695e158615baaa16248e63c7adb) C:\Windows\system32\DRIVERS\amdxata.sys 23:04:56.0391 34028 amdxata - ok 23:04:56.0532 34028 AnyDVD (30682a098e12e2c85fa65518e1618195) C:\Windows\system32\Drivers\AnyDVD.sys 23:04:56.0547 34028 AnyDVD - ok 23:04:56.0656 34028 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 23:04:56.0656 34028 AppID - ok 23:04:56.0703 34028 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 23:04:56.0703 34028 AppIDSvc - ok 23:04:56.0734 34028 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll 23:04:56.0734 34028 Appinfo - ok 23:04:56.0859 34028 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 23:04:56.0859 34028 Apple Mobile Device - ok 23:04:56.0968 34028 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 23:04:56.0968 34028 arc - ok 23:04:57.0015 34028 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 23:04:57.0015 34028 arcsas - ok 23:04:57.0109 34028 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 23:04:57.0109 34028 AsyncMac - ok 23:04:57.0202 34028 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 23:04:57.0202 34028 atapi - ok 23:04:58.0809 34028 atikmdag (1147f8816d4ddc9fc43a40df52f40500) C:\Windows\system32\DRIVERS\atikmdag.sys 23:04:58.0918 34028 atikmdag - ok 23:04:59.0199 34028 AtiPcie (7c5d273e29dcc5505469b299c6f29163) C:\Windows\system32\DRIVERS\AtiPcie.sys 23:04:59.0199 34028 AtiPcie - ok 23:04:59.0402 34028 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 23:04:59.0418 34028 AudioEndpointBuilder - ok 23:04:59.0418 34028 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 23:04:59.0433 34028 AudioSrv - ok 23:04:59.0589 34028 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll 23:04:59.0605 34028 AxInstSV - ok 23:04:59.0886 34028 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 23:04:59.0901 34028 b06bdrv - ok 23:05:00.0026 34028 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 23:05:00.0042 34028 b57nd60a - ok 23:05:00.0135 34028 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 23:05:00.0135 34028 BDESVC - ok 23:05:00.0151 34028 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 23:05:00.0166 34028 Beep - ok 23:05:00.0650 34028 BHDrvx64 (c8ab71a5102d0fc103f6dfc750005137) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\BASHDefs\20120619.001\BHDrvx64.sys 23:05:00.0666 34028 BHDrvx64 - ok 23:05:00.0884 34028 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll 23:05:00.0900 34028 BITS - ok 23:05:01.0024 34028 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 23:05:01.0024 34028 blbdrive - ok 23:05:01.0274 34028 Bonjour Service (f832f1505ad8b83474bd9a5b1b985e01) C:\Program Files (x86)\Bonjour\mDNSResponder.exe 23:05:01.0305 34028 Bonjour Service - ok 23:05:01.0430 34028 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 23:05:01.0430 34028 bowser - ok 23:05:01.0480 34028 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 23:05:01.0480 34028 BrFiltLo - ok 23:05:01.0510 34028 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 23:05:01.0510 34028 BrFiltUp - ok 23:05:01.0610 34028 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll 23:05:01.0630 34028 Browser - ok 23:05:01.0750 34028 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 23:05:01.0750 34028 Brserid - ok 23:05:01.0800 34028 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 23:05:01.0810 34028 BrSerWdm - ok 23:05:01.0840 34028 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 23:05:01.0840 34028 BrUsbMdm - ok 23:05:01.0870 34028 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 23:05:01.0870 34028 BrUsbSer - ok 23:05:01.0900 34028 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 23:05:01.0900 34028 BTHMODEM - ok 23:05:02.0020 34028 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 23:05:02.0020 34028 bthserv - ok 23:05:02.0210 34028 CalendarSynchService (2ae9fca1211ccfdb01b710a25eecf309) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe 23:05:02.0210 34028 CalendarSynchService - ok 23:05:02.0430 34028 ccHP (37f1baec39b505b3b51893a35c8337ea) C:\Windows\system32\drivers\NISx64\1109000.00C\ccHPx64.sys 23:05:02.0450 34028 ccHP - ok 23:05:02.0530 34028 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 23:05:02.0540 34028 cdfs - ok 23:05:02.0610 34028 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys 23:05:02.0610 34028 cdrom - ok 23:05:02.0710 34028 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 23:05:02.0720 34028 CertPropSvc - ok 23:05:02.0800 34028 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 23:05:02.0800 34028 circlass - ok 23:05:02.0960 34028 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 23:05:02.0980 34028 CLFS - ok 23:05:03.0080 34028 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 23:05:03.0160 34028 clr_optimization_v2.0.50727_32 - ok 23:05:03.0270 34028 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 23:05:03.0300 34028 clr_optimization_v2.0.50727_64 - ok 23:05:03.0530 34028 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 23:05:03.0610 34028 clr_optimization_v4.0.30319_32 - ok 23:05:03.0720 34028 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 23:05:03.0780 34028 clr_optimization_v4.0.30319_64 - ok 23:05:03.0870 34028 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 23:05:03.0870 34028 CmBatt - ok 23:05:03.0940 34028 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 23:05:03.0960 34028 cmdide - ok 23:05:04.0127 34028 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys 23:05:04.0142 34028 CNG - ok 23:05:04.0189 34028 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 23:05:04.0189 34028 Compbatt - ok 23:05:04.0283 34028 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 23:05:04.0283 34028 CompositeBus - ok 23:05:04.0314 34028 COMSysApp - ok 23:05:04.0392 34028 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 23:05:04.0392 34028 crcdisk - ok 23:05:04.0469 34028 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll 23:05:04.0489 34028 CryptSvc - ok 23:05:04.0679 34028 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 23:05:04.0699 34028 DcomLaunch - ok 23:05:04.0849 34028 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 23:05:04.0859 34028 defragsvc - ok 23:05:04.0939 34028 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 23:05:04.0949 34028 DfsC - ok 23:05:05.0249 34028 DfSdkS (d51b32ba3897f630d99713b74b40d6a2) C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe 23:05:05.0319 34028 DfSdkS - ok 23:05:05.0539 34028 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll 23:05:05.0549 34028 Dhcp - ok 23:05:05.0599 34028 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 23:05:05.0599 34028 discache - ok 23:05:05.0729 34028 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 23:05:05.0729 34028 Disk - ok 23:05:05.0849 34028 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll 23:05:05.0869 34028 Dnscache - ok 23:05:05.0969 34028 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll 23:05:05.0979 34028 dot3svc - ok 23:05:06.0029 34028 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll 23:05:06.0039 34028 DPS - ok 23:05:06.0089 34028 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 23:05:06.0099 34028 drmkaud - ok 23:05:06.0259 34028 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 23:05:06.0279 34028 DXGKrnl - ok 23:05:06.0389 34028 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 23:05:06.0389 34028 EapHost - ok 23:05:07.0199 34028 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 23:05:07.0259 34028 ebdrv - ok 23:05:07.0509 34028 eeCtrl (ba6420c1f7070ed8f1ba372844f3e1ec) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 23:05:07.0519 34028 eeCtrl - ok 23:05:07.0709 34028 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe 23:05:07.0709 34028 EFS - ok 23:05:07.0849 34028 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe 23:05:07.0939 34028 ehRecvr - ok 23:05:07.0989 34028 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 23:05:08.0029 34028 ehSched - ok 23:05:08.0069 34028 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\Windows\system32\Drivers\ElbyCDIO.sys 23:05:08.0069 34028 ElbyCDIO - ok 23:05:08.0219 34028 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 23:05:08.0229 34028 elxstor - ok 23:05:08.0399 34028 EraserUtilRebootDrv (1343df3451bc0c442dc69837c6fba21b) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 23:05:08.0439 34028 EraserUtilRebootDrv - ok 23:05:08.0469 34028 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 23:05:08.0469 34028 ErrDev - ok 23:05:08.0609 34028 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 23:05:08.0629 34028 EventSystem - ok 23:05:08.0749 34028 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 23:05:08.0759 34028 exfat - ok 23:05:08.0789 34028 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 23:05:08.0789 34028 fastfat - ok 23:05:08.0979 34028 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe 23:05:08.0999 34028 Fax - ok 23:05:09.0049 34028 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 23:05:09.0049 34028 fdc - ok 23:05:09.0079 34028 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 23:05:09.0089 34028 fdPHost - ok 23:05:09.0119 34028 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 23:05:09.0119 34028 FDResPub - ok 23:05:09.0189 34028 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 23:05:09.0189 34028 FileInfo - ok 23:05:09.0229 34028 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 23:05:09.0229 34028 Filetrace - ok 23:05:09.0299 34028 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 23:05:09.0299 34028 flpydisk - ok 23:05:09.0389 34028 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 23:05:09.0399 34028 FltMgr - ok 23:05:09.0759 34028 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll 23:05:09.0779 34028 FontCache - ok 23:05:09.0909 34028 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 23:05:09.0939 34028 FontCache3.0.0.0 - ok 23:05:10.0069 34028 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 23:05:10.0079 34028 FsDepends - ok 23:05:10.0159 34028 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys 23:05:10.0159 34028 fssfltr - ok 23:05:10.0699 34028 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 23:05:10.0799 34028 fsssvc - ok 23:05:11.0019 34028 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys 23:05:11.0035 34028 Fs_Rec - ok 23:05:11.0175 34028 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 23:05:11.0206 34028 fvevol - ok 23:05:11.0316 34028 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 23:05:11.0347 34028 gagp30kx - ok 23:05:11.0550 34028 GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 23:05:11.0565 34028 GamesAppService - ok 23:05:11.0643 34028 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 23:05:11.0643 34028 GEARAspiWDM - ok 23:05:11.0908 34028 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll 23:05:11.0924 34028 gpsvc - ok 23:05:12.0080 34028 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 23:05:12.0106 34028 gupdate - ok 23:05:12.0156 34028 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 23:05:12.0156 34028 gupdatem - ok 23:05:12.0246 34028 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 23:05:12.0306 34028 gusvc - ok 23:05:12.0356 34028 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 23:05:12.0356 34028 hcw85cir - ok 23:05:12.0466 34028 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 23:05:12.0486 34028 HdAudAddService - ok 23:05:12.0536 34028 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 23:05:12.0546 34028 HDAudBus - ok 23:05:12.0586 34028 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 23:05:12.0586 34028 HidBatt - ok 23:05:12.0656 34028 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 23:05:12.0686 34028 HidBth - ok 23:05:12.0746 34028 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 23:05:12.0756 34028 HidIr - ok 23:05:12.0766 34028 hidkmdf (d4bfba2eec009e26854fe61110ef509f) C:\Windows\system32\DRIVERS\hidkmdf.sys 23:05:12.0766 34028 hidkmdf - ok 23:05:12.0796 34028 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll 23:05:12.0806 34028 hidserv - ok 23:05:12.0916 34028 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys 23:05:12.0916 34028 HidUsb - ok 23:05:12.0976 34028 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll 23:05:12.0976 34028 hkmsvc - ok 23:05:13.0076 34028 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll 23:05:13.0076 34028 HomeGroupListener - ok 23:05:13.0276 34028 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll 23:05:13.0286 34028 HomeGroupProvider - ok 23:05:13.0586 34028 HP Support Assistant Service (13bb1114451c63bfb41ba7daa4d70a29) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe 23:05:13.0616 34028 HP Support Assistant Service - ok 23:05:13.0776 34028 HPDrvMntSvc.exe (bcc4a8b2e2e902f52e7f2e7d8e125765) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe 23:05:13.0776 34028 HPDrvMntSvc.exe - ok 23:05:13.0986 34028 hpqwmiex (ec9739a46f1f83c6e52a7a4697f44a65) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe 23:05:14.0046 34028 hpqwmiex - ok 23:05:14.0166 34028 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 23:05:14.0186 34028 HpSAMD - ok 23:05:14.0406 34028 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 23:05:14.0426 34028 HTTP - ok 23:05:14.0466 34028 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 23:05:14.0466 34028 hwpolicy - ok 23:05:14.0526 34028 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 23:05:14.0536 34028 i8042prt - ok 23:05:14.0696 34028 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 23:05:14.0716 34028 iaStorV - ok 23:05:14.0976 34028 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 23:05:15.0036 34028 idsvc - ok 23:05:15.0646 34028 IDSVia64 (ce0bf35c79e03bb89da6b14fac838605) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\IPSDefs\20120707.001\IDSvia64.sys 23:05:15.0666 34028 IDSVia64 - ok 23:05:15.0986 34028 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 23:05:15.0996 34028 iirsp - ok 23:05:16.0226 34028 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll 23:05:16.0256 34028 IKEEXT - ok 23:05:16.0286 34028 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 23:05:16.0296 34028 intelide - ok 23:05:16.0346 34028 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 23:05:16.0356 34028 intelppm - ok 23:05:16.0546 34028 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 23:05:16.0556 34028 IPBusEnum - ok 23:05:16.0616 34028 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 23:05:16.0616 34028 IpFilterDriver - ok 23:05:16.0686 34028 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 23:05:16.0686 34028 IPMIDRV - ok 23:05:16.0776 34028 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 23:05:16.0776 34028 IPNAT - ok 23:05:17.0096 34028 iPod Service (81826a13598a7feaa9e391190e9b539a) C:\Program Files\iPod\bin\iPodService.exe 23:05:17.0126 34028 iPod Service - ok 23:05:17.0166 34028 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 23:05:17.0166 34028 IRENUM - ok 23:05:17.0196 34028 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 23:05:17.0206 34028 isapnp - ok 23:05:17.0356 34028 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 23:05:17.0366 34028 iScsiPrt - ok 23:05:17.0446 34028 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys 23:05:17.0456 34028 kbdclass - ok 23:05:17.0526 34028 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 23:05:17.0526 34028 kbdhid - ok 23:05:17.0586 34028 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 23:05:17.0586 34028 KeyIso - ok 23:05:17.0646 34028 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys 23:05:17.0656 34028 KSecDD - ok 23:05:17.0706 34028 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys 23:05:17.0706 34028 KSecPkg - ok 23:05:17.0746 34028 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 23:05:17.0746 34028 ksthunk - ok 23:05:17.0946 34028 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 23:05:17.0956 34028 KtmRm - ok 23:05:18.0026 34028 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll 23:05:18.0057 34028 LanmanServer - ok 23:05:18.0135 34028 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll 23:05:18.0135 34028 LanmanWorkstation - ok 23:05:18.0874 34028 Lavasoft Ad-Aware Service (4d99fca201b72e0f2ca996e357baa170) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe 23:05:18.0904 34028 Lavasoft Ad-Aware Service - ok 23:05:19.0084 34028 Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys 23:05:19.0084 34028 Lavasoft Kernexplorer - ok 23:05:19.0374 34028 Lbd (c8b3131857931ae76798a741cc52b021) C:\Windows\system32\DRIVERS\Lbd.sys 23:05:19.0374 34028 Lbd - ok 23:05:19.0494 34028 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 23:05:19.0494 34028 lltdio - ok 23:05:19.0654 34028 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 23:05:19.0664 34028 lltdsvc - ok 23:05:19.0674 34028 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 23:05:19.0674 34028 lmhosts - ok 23:05:19.0744 34028 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 23:05:19.0744 34028 LSI_FC - ok 23:05:19.0794 34028 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 23:05:19.0804 34028 LSI_SAS - ok 23:05:19.0844 34028 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 23:05:19.0844 34028 LSI_SAS2 - ok 23:05:19.0934 34028 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 23:05:19.0954 34028 LSI_SCSI - ok 23:05:20.0054 34028 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 23:05:20.0064 34028 luafv - ok 23:05:20.0204 34028 MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys 23:05:20.0214 34028 MBAMProtector - ok 23:05:20.0644 34028 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 23:05:20.0664 34028 MBAMService - ok 23:05:20.0815 34028 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe 23:05:20.0919 34028 McComponentHostService - ok 23:05:20.0981 34028 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll 23:05:20.0981 34028 Mcx2Svc - ok 23:05:21.0028 34028 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 23:05:21.0028 34028 megasas - ok 23:05:21.0169 34028 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 23:05:21.0200 34028 MegaSR - ok 23:05:21.0262 34028 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 23:05:21.0278 34028 MMCSS - ok 23:05:21.0371 34028 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 23:05:21.0371 34028 Modem - ok 23:05:21.0449 34028 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 23:05:21.0449 34028 monitor - ok 23:05:21.0512 34028 motmodem (e90aba3c6f01be2c456c4aa857b28646) C:\Windows\system32\DRIVERS\motmodem.sys 23:05:21.0543 34028 motmodem - ok 23:05:21.0652 34028 MotoConnect Service (bb9de58ac6513da62c005d92e2db4981) C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe 23:05:21.0652 34028 MotoConnect Service - ok 23:05:21.0730 34028 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys 23:05:21.0730 34028 mouclass - ok 23:05:21.0839 34028 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 23:05:21.0839 34028 mouhid - ok 23:05:21.0917 34028 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 23:05:21.0933 34028 mountmgr - ok 23:05:22.0042 34028 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 23:05:22.0105 34028 MozillaMaintenance - ok 23:05:22.0214 34028 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 23:05:22.0229 34028 mpio - ok 23:05:22.0316 34028 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 23:05:22.0316 34028 mpsdrv - ok 23:05:22.0436 34028 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 23:05:22.0446 34028 MRxDAV - ok 23:05:22.0496 34028 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 23:05:22.0506 34028 mrxsmb - ok 23:05:22.0766 34028 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 23:05:22.0796 34028 mrxsmb10 - ok 23:05:22.0846 34028 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 23:05:22.0856 34028 mrxsmb20 - ok 23:05:22.0896 34028 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 23:05:22.0896 34028 msahci - ok 23:05:22.0976 34028 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 23:05:22.0986 34028 msdsm - ok 23:05:23.0176 34028 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 23:05:23.0186 34028 MSDTC - ok 23:05:23.0226 34028 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 23:05:23.0226 34028 Msfs - ok 23:05:23.0246 34028 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 23:05:23.0246 34028 mshidkmdf - ok 23:05:23.0296 34028 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 23:05:23.0306 34028 msisadrv - ok 23:05:23.0466 34028 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 23:05:23.0486 34028 MSiSCSI - ok 23:05:23.0506 34028 msiserver - ok 23:05:23.0556 34028 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 23:05:23.0556 34028 MSKSSRV - ok 23:05:23.0606 34028 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 23:05:23.0606 34028 MSPCLOCK - ok 23:05:23.0636 34028 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 23:05:23.0636 34028 MSPQM - ok 23:05:23.0856 34028 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 23:05:23.0866 34028 MsRPC - ok 23:05:23.0916 34028 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 23:05:23.0916 34028 mssmbios - ok 23:05:23.0956 34028 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 23:05:23.0966 34028 MSTEE - ok 23:05:24.0026 34028 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 23:05:24.0026 34028 MTConfig - ok 23:05:24.0096 34028 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 23:05:24.0096 34028 Mup - ok 23:05:24.0342 34028 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll 23:05:24.0342 34028 napagent - ok 23:05:24.0514 34028 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 23:05:24.0514 34028 NativeWifiP - ok 23:05:24.0872 34028 NAVENG (8043d41f881d6ace40b854ad6e32217f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20120709.021\ENG64.SYS 23:05:24.0872 34028 NAVENG - ok 23:05:25.0403 34028 NAVEX15 (9a9ab2fc45d701daed465d14980f1305) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20120709.021\EX64.SYS 23:05:25.0434 34028 NAVEX15 - ok 23:05:25.0933 34028 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 23:05:25.0949 34028 NDIS - ok 23:05:26.0042 34028 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 23:05:26.0042 34028 NdisCap - ok 23:05:26.0089 34028 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 23:05:26.0105 34028 NdisTapi - ok 23:05:26.0245 34028 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 23:05:26.0261 34028 Ndisuio - ok 23:05:26.0308 34028 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 23:05:26.0323 34028 NdisWan - ok 23:05:26.0386 34028 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 23:05:26.0401 34028 NDProxy - ok 23:05:26.0510 34028 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 23:05:26.0526 34028 NetBIOS - ok 23:05:26.0713 34028 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 23:05:26.0744 34028 NetBT - ok 23:05:26.0807 34028 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 23:05:26.0807 34028 Netlogon - ok 23:05:26.0963 34028 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 23:05:26.0978 34028 Netman - ok 23:05:27.0072 34028 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 23:05:27.0088 34028 netprofm - ok 23:05:27.0384 34028 netr28x (254af6df67eafa8c6e0aa0d316487673) C:\Windows\system32\DRIVERS\netr28x.sys 23:05:27.0400 34028 netr28x - ok 23:05:27.0524 34028 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 23:05:27.0602 34028 NetTcpPortSharing - ok 23:05:27.0665 34028 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 23:05:27.0665 34028 nfrd960 - ok 23:05:27.0883 34028 NIS (b4187346f54e362daffe647b25a58d50) C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe 23:05:27.0883 34028 NIS - ok 23:05:27.0980 34028 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll 23:05:27.0980 34028 NlaSvc - ok 23:05:28.0070 34028 NMSAccess (7aea4df1ca68fd45dd4bbe1f0243ce7f) C:\Program Files (x86)\BurnAware Free\NMSAccess32.exe 23:05:28.0100 34028 NMSAccess - ok 23:05:28.0230 34028 NMSAccessU (fd306fbcce7adb1077b709742e7148e9) C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe 23:05:28.0300 34028 NMSAccessU - ok 23:05:28.0380 34028 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 23:05:28.0380 34028 Npfs - ok 23:05:28.0440 34028 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 23:05:28.0440 34028 nsi - ok 23:05:28.0480 34028 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 23:05:28.0480 34028 nsiproxy - ok 23:05:28.0850 34028 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 23:05:28.0870 34028 Ntfs - ok 23:05:29.0250 34028 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 23:05:29.0250 34028 Null - ok 23:05:29.0340 34028 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 23:05:29.0350 34028 nvraid - ok 23:05:29.0410 34028 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 23:05:29.0410 34028 nvstor - ok 23:05:29.0460 34028 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 23:05:29.0470 34028 nv_agp - ok 23:05:29.0540 34028 NW1950 (1a71763dd0df7ab7b435efa1dde710c6) C:\Windows\system32\DRIVERS\NW1950.sys 23:05:29.0540 34028 NW1950 - ok 23:05:29.0710 34028 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 23:05:29.0800 34028 odserv - ok 23:05:29.0860 34028 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 23:05:29.0860 34028 ohci1394 - ok 23:05:30.0007 34028 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 23:05:30.0054 34028 ose - ok 23:05:30.0116 34028 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 23:05:30.0132 34028 p2pimsvc - ok 23:05:30.0256 34028 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 23:05:30.0288 34028 p2psvc - ok 23:05:30.0350 34028 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 23:05:30.0366 34028 Parport - ok 23:05:30.0412 34028 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys 23:05:30.0428 34028 partmgr - ok 23:05:30.0522 34028 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 23:05:30.0522 34028 PcaSvc - ok 23:05:30.0584 34028 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 23:05:30.0600 34028 pci - ok 23:05:30.0631 34028 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 23:05:30.0631 34028 pciide - ok 23:05:30.0709 34028 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 23:05:30.0724 34028 pcmcia - ok 23:05:30.0771 34028 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 23:05:30.0787 34028 pcw - ok 23:05:30.0943 34028 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 23:05:30.0943 34028 PEAUTH - ok 23:05:31.0302 34028 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 23:05:31.0364 34028 PerfHost - ok 23:05:31.0801 34028 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll 23:05:31.0801 34028 pla - ok 23:05:31.0972 34028 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll 23:05:31.0988 34028 PlugPlay - ok 23:05:32.0035 34028 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 23:05:32.0035 34028 PNRPAutoReg - ok 23:05:32.0175 34028 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 23:05:32.0191 34028 PNRPsvc - ok 23:05:32.0378 34028 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll 23:05:32.0394 34028 PolicyAgent - ok 23:05:32.0503 34028 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 23:05:32.0503 34028 Power - ok 23:05:32.0659 34028 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 23:05:32.0659 34028 PptpMiniport - ok 23:05:32.0741 34028 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 23:05:32.0751 34028 Processor - ok 23:05:32.0931 34028 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll 23:05:32.0941 34028 ProfSvc - ok 23:05:33.0011 34028 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 23:05:33.0021 34028 ProtectedStorage - ok 23:05:33.0121 34028 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 23:05:33.0131 34028 Psched - ok 23:05:33.0641 34028 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 23:05:33.0671 34028 ql2300 - ok 23:05:33.0952 34028 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 23:05:33.0962 34028 ql40xx - ok 23:05:34.0062 34028 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 23:05:34.0072 34028 QWAVE - ok 23:05:34.0122 34028 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 23:05:34.0142 34028 QWAVEdrv - ok 23:05:34.0172 34028 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 23:05:34.0182 34028 RasAcd - ok 23:05:34.0392 34028 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 23:05:34.0392 34028 RasAgileVpn - ok 23:05:34.0542 34028 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 23:05:34.0542 34028 RasAuto - ok 23:05:34.0622 34028 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 23:05:34.0632 34028 Rasl2tp - ok 23:05:34.0782 34028 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll 23:05:34.0802 34028 RasMan - ok 23:05:34.0932 34028 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 23:05:34.0932 34028 RasPppoe - ok 23:05:35.0022 34028 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 23:05:35.0052 34028 RasSstp - ok 23:05:35.0782 34028 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 23:05:35.0812 34028 rdbss - ok 23:05:35.0892 34028 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 23:05:35.0892 34028 rdpbus - ok 23:05:35.0952 34028 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 23:05:35.0972 34028 RDPCDD - ok 23:05:36.0012 34028 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 23:05:36.0012 34028 RDPENCDD - ok 23:05:36.0082 34028 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 23:05:36.0112 34028 RDPREFMP - ok 23:05:36.0512 34028 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys 23:05:36.0542 34028 RDPWD - ok 23:05:37.0002 34028 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 23:05:37.0042 34028 rdyboost - ok 23:05:37.0372 34028 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 23:05:37.0382 34028 RemoteAccess - ok 23:05:37.0482 34028 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 23:05:37.0492 34028 RemoteRegistry - ok 23:05:37.0552 34028 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 23:05:37.0562 34028 RpcEptMapper - ok 23:05:37.0592 34028 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 23:05:37.0612 34028 RpcLocator - ok 23:05:37.0865 34028 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 23:05:37.0881 34028 RpcSs - ok 23:05:37.0943 34028 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 23:05:37.0943 34028 rspndr - ok 23:05:38.0099 34028 RTL8167 (91296f0b2653281b2f11e0fce56aa427) C:\Windows\system32\DRIVERS\Rt64win7.sys 23:05:38.0130 34028 RTL8167 - ok 23:05:38.0193 34028 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 23:05:38.0193 34028 SamSs - ok 23:05:38.0317 34028 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 23:05:38.0317 34028 sbp2port - ok 23:05:38.0910 34028 SBSDWSCService (794d4b48dfb6e999537c7c3947863463) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe 23:05:38.0988 34028 SBSDWSCService - ok 23:05:39.0097 34028 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 23:05:39.0113 34028 SCardSvr - ok 23:05:39.0207 34028 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 23:05:39.0207 34028 scfilter - ok 23:05:39.0581 34028 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll 23:05:39.0612 34028 Schedule - ok 23:05:39.0675 34028 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 23:05:39.0675 34028 SCPolicySvc - ok 23:05:39.0784 34028 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll 23:05:39.0784 34028 SDRSVC - ok 23:05:39.0877 34028 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 23:05:39.0877 34028 secdrv - ok 23:05:39.0940 34028 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll 23:05:39.0940 34028 seclogon - ok 23:05:40.0002 34028 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 23:05:40.0018 34028 SENS - ok 23:05:40.0065 34028 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 23:05:40.0065 34028 SensrSvc - ok 23:05:40.0096 34028 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 23:05:40.0111 34028 Serenum - ok 23:05:40.0174 34028 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 23:05:40.0174 34028 Serial - ok 23:05:40.0221 34028 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 23:05:40.0221 34028 sermouse - ok 23:05:40.0377 34028 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll 23:05:40.0377 34028 SessionEnv - ok 23:05:40.0408 34028 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 23:05:40.0408 34028 sffdisk - ok 23:05:40.0453 34028 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 23:05:40.0453 34028 sffp_mmc - ok 23:05:40.0513 34028 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 23:05:40.0513 34028 sffp_sd - ok 23:05:40.0563 34028 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 23:05:40.0563 34028 sfloppy - ok 23:05:40.0713 34028 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 23:05:40.0723 34028 SharedAccess - ok 23:05:40.0843 34028 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll 23:05:40.0863 34028 ShellHWDetection - ok 23:05:40.0933 34028 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 23:05:40.0933 34028 SiSRaid2 - ok 23:05:41.0013 34028 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 23:05:41.0033 34028 SiSRaid4 - ok 23:05:41.0113 34028 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 23:05:41.0133 34028 Smb - ok 23:05:41.0243 34028 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 23:05:41.0243 34028 SNMPTRAP - ok 23:05:41.0263 34028 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 23:05:41.0263 34028 spldr - ok 23:05:41.0473 34028 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe 23:05:41.0493 34028 Spooler - ok 23:05:42.0893 34028 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe 23:05:42.0953 34028 sppsvc - ok 23:05:43.0293 34028 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 23:05:43.0303 34028 sppuinotify - ok 23:05:43.0788 34028 SRTSP (96babc4906ecdb1c69d1176f8647ad8e) C:\Windows\System32\Drivers\NISx64\1109000.00C\SRTSP64.SYS 23:05:43.0819 34028 SRTSP - ok 23:05:43.0851 34028 SRTSPX (c7f491a290e0e4222f5cdcd50eeb8167) C:\Windows\system32\drivers\NISx64\1109000.00C\SRTSPX64.SYS 23:05:43.0851 34028 SRTSPX - ok 23:05:44.0132 34028 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 23:05:44.0148 34028 srv - ok 23:05:44.0304 34028 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 23:05:44.0320 34028 srv2 - ok 23:05:44.0429 34028 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 23:05:44.0444 34028 srvnet - ok 23:05:44.0647 34028 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 23:05:44.0647 34028 SSDPSRV - ok 23:05:44.0710 34028 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 23:05:44.0725 34028 SstpSvc - ok 23:05:44.0819 34028 StarOpen (e57b778208c783d8debab320c16a1b82) C:\Windows\system32\drivers\StarOpen.sys 23:05:44.0834 34028 StarOpen - ok 23:05:44.0897 34028 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 23:05:44.0897 34028 stexstor - ok 23:05:45.0224 34028 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll 23:05:45.0256 34028 stisvc - ok 23:05:45.0318 34028 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 23:05:45.0318 34028 swenum - ok 23:05:45.0630 34028 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 23:05:45.0646 34028 swprv - ok 23:05:45.0864 34028 SymDS (659b227a72b76115975a6a9491b2fe1f) C:\Windows\system32\drivers\NISx64\1109000.00C\SYMDS64.SYS 23:05:45.0864 34028 SymDS - ok 23:05:46.0036 34028 SymEFA (9f5783a4a03d0091cdbdaa858b566926) C:\Windows\system32\drivers\NISx64\1109000.00C\SYMEFA64.SYS 23:05:46.0051 34028 SymEFA - ok 23:05:46.0176 34028 SymEvent (3f9d5fe52585e2653e59fdbfdf09a94c) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 23:05:46.0176 34028 SymEvent - ok 23:05:46.0254 34028 SYMFW - ok 23:05:46.0379 34028 SymIM (f7f3deb5fdd6cea69a8d1544f7becaf1) C:\Windows\system32\DRIVERS\SymIMv.sys 23:05:46.0394 34028 SymIM - ok 23:05:46.0472 34028 SymIRON (f57588546e738db1583981d8f44e9bc2) C:\Windows\system32\drivers\NISx64\1109000.00C\Ironx64.SYS 23:05:46.0472 34028 SymIRON - ok 23:05:46.0488 34028 SYMNDISV - ok 23:05:46.0706 34028 SYMTDIv (3adfb72f0797ae3832509fe030755e21) C:\Windows\System32\Drivers\NISx64\1109000.00C\SYMTDIV.SYS 23:05:46.0722 34028 SYMTDIv - ok 23:05:47.0486 34028 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll 23:05:47.0549 34028 SysMain - ok 23:05:47.0966 34028 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll 23:05:47.0966 34028 TabletInputService - ok 23:05:48.0106 34028 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll 23:05:48.0116 34028 TapiSrv - ok 23:05:48.0186 34028 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 23:05:48.0196 34028 TBS - ok 23:05:49.0086 34028 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys 23:05:49.0156 34028 Tcpip - ok 23:05:50.0156 34028 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys 23:05:50.0172 34028 TCPIP6 - ok 23:05:50.0562 34028 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 23:05:50.0562 34028 tcpipreg - ok 23:05:50.0628 34028 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 23:05:50.0628 34028 TDPIPE - ok 23:05:50.0718 34028 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys 23:05:50.0718 34028 TDTCP - ok 23:05:50.0828 34028 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 23:05:50.0858 34028 tdx - ok 23:05:50.0918 34028 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 23:05:50.0928 34028 TermDD - ok 23:05:51.0188 34028 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll 23:05:51.0188 34028 TermService - ok 23:05:51.0238 34028 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 23:05:51.0238 34028 Themes - ok 23:05:51.0308 34028 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 23:05:51.0318 34028 THREADORDER - ok 23:05:51.0398 34028 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 23:05:51.0398 34028 TrkWks - ok 23:05:51.0598 34028 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe 23:05:51.0628 34028 TrustedInstaller - ok 23:05:51.0708 34028 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 23:05:51.0708 34028 tssecsrv - ok 23:05:51.0848 34028 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 23:05:51.0858 34028 TsUsbFlt - ok 23:05:52.0018 34028 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 23:05:52.0028 34028 tunnel - ok 23:05:52.0068 34028 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 23:05:52.0068 34028 uagp35 - ok 23:05:52.0198 34028 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 23:05:52.0218 34028 udfs - ok 23:05:52.0298 34028 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 23:05:52.0298 34028 UI0Detect - ok 23:05:52.0348 34028 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 23:05:52.0368 34028 uliagpkx - ok 23:05:52.0458 34028 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 23:05:52.0468 34028 umbus - ok 23:05:52.0508 34028 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 23:05:52.0508 34028 UmPass - ok 23:05:52.0690 34028 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 23:05:52.0705 34028 upnphost - ok 23:05:52.0768 34028 usbbus (c73cb90e6a2ff90fd02451a8dfc6af8a) C:\Windows\system32\DRIVERS\lgx64bus.sys 23:05:52.0768 34028 usbbus - ok 23:05:52.0830 34028 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 23:05:52.0846 34028 usbccgp - ok 23:05:52.0955 34028 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 23:05:52.0970 34028 usbcir - ok 23:05:53.0017 34028 UsbDiag (856ce1f23785369bb5a2de0aedad0aa7) C:\Windows\system32\DRIVERS\lgx64diag.sys 23:05:53.0017 34028 UsbDiag - ok 23:05:53.0080 34028 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys 23:05:53.0080 34028 usbehci - ok 23:05:53.0142 34028 usbfilter (6648c6d7323a2ce0c4776c36cefbcb14) C:\Windows\system32\DRIVERS\usbfilter.sys 23:05:53.0142 34028 usbfilter - ok 23:05:53.0360 34028 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 23:05:53.0360 34028 usbhub - ok 23:05:53.0423 34028 USBModem (f81055629778d33c9317b32e4d2b58db) C:\Windows\system32\DRIVERS\lgx64modem.sys 23:05:53.0423 34028 USBModem - ok 23:05:53.0454 34028 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys 23:05:53.0470 34028 usbohci - ok 23:05:53.0516 34028 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 23:05:53.0516 34028 usbprint - ok 23:05:53.0610 34028 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 23:05:53.0626 34028 USBSTOR - ok 23:05:53.0657 34028 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 23:05:53.0657 34028 usbuhci - ok 23:05:53.0844 34028 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys 23:05:53.0860 34028 usbvideo - ok 23:05:53.0953 34028 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 23:05:53.0969 34028 UxSms - ok 23:05:54.0016 34028 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 23:05:54.0016 34028 VaultSvc - ok 23:05:54.0109 34028 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 23:05:54.0109 34028 vdrvroot - ok 23:05:54.0359 34028 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe 23:05:54.0374 34028 vds - ok 23:05:54.0406 34028 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 23:05:54.0406 34028 vga - ok 23:05:54.0421 34028 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 23:05:54.0421 34028 VgaSave - ok 23:05:54.0468 34028 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 23:05:54.0468 34028 vhdmp - ok 23:05:54.0515 34028 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 23:05:54.0515 34028 viaide - ok 23:05:54.0530 34028 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 23:05:54.0530 34028 volmgr - ok 23:05:54.0577 34028 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 23:05:54.0593 34028 volmgrx - ok 23:05:54.0624 34028 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 23:05:54.0640 34028 volsnap - ok 23:05:54.0702 34028 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 23:05:54.0702 34028 vsmraid - ok 23:05:54.0827 34028 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe 23:05:54.0842 34028 VSS - ok 23:05:54.0952 34028 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 23:05:54.0952 34028 vwifibus - ok 23:05:54.0983 34028 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 23:05:54.0983 34028 vwififlt - ok 23:05:54.0998 34028 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys 23:05:54.0998 34028 vwifimp - ok 23:05:55.0061 34028 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 23:05:55.0061 34028 W32Time - ok 23:05:55.0092 34028 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 23:05:55.0092 34028 WacomPen - ok 23:05:55.0139 34028 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 23:05:55.0139 34028 WANARP - ok 23:05:55.0154 34028 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 23:05:55.0154 34028 Wanarpv6 - ok 23:05:55.0295 34028 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe 23:05:55.0357 34028 WatAdminSvc - ok 23:05:55.0466 34028 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe 23:05:55.0482 34028 wbengine - ok 23:05:55.0591 34028 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 23:05:55.0591 34028 WbioSrvc - ok 23:05:55.0638 34028 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll 23:05:55.0638 34028 wcncsvc - ok 23:05:55.0654 34028 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 23:05:55.0654 34028 WcsPlugInService - ok 23:05:55.0700 34028 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 23:05:55.0700 34028 Wd - ok 23:05:55.0763 34028 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 23:05:55.0763 34028 Wdf01000 - ok 23:05:55.0778 34028 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 23:05:55.0778 34028 WdiServiceHost - ok 23:05:55.0778 34028 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 23:05:55.0794 34028 WdiSystemHost - ok 23:05:55.0825 34028 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll 23:05:55.0825 34028 WebClient - ok 23:05:55.0856 34028 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 23:05:55.0856 34028 Wecsvc - ok 23:05:55.0872 34028 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 23:05:55.0872 34028 wercplsupport - ok 23:05:55.0903 34028 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 23:05:55.0903 34028 WerSvc - ok 23:05:55.0934 34028 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 23:05:55.0934 34028 WfpLwf - ok 23:05:55.0934 34028 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 23:05:55.0934 34028 WIMMount - ok 23:05:55.0950 34028 WinHttpAutoProxySvc - ok 23:05:56.0012 34028 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 23:05:56.0012 34028 Winmgmt - ok 23:05:56.0168 34028 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll 23:05:56.0168 34028 WinRM - ok 23:05:56.0293 34028 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 23:05:56.0293 34028 WinUsb - ok 23:05:56.0371 34028 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 23:05:56.0387 34028 Wlansvc - ok 23:05:56.0480 34028 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 23:05:56.0512 34028 wlcrasvc - ok 23:05:56.0699 34028 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 23:05:56.0730 34028 wlidsvc - ok 23:05:56.0837 34028 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 23:05:56.0837 34028 WmiAcpi - ok 23:05:56.0907 34028 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 23:05:56.0937 34028 wmiApSrv - ok 23:05:56.0967 34028 WMPNetworkSvc - ok 23:05:57.0017 34028 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 23:05:57.0017 34028 WPCSvc - ok 23:05:57.0057 34028 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll 23:05:57.0057 34028 WPDBusEnum - ok 23:05:57.0087 34028 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 23:05:57.0087 34028 ws2ifsl - ok 23:05:57.0107 34028 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys 23:05:57.0107 34028 WSDPrintDevice - ok 23:05:57.0117 34028 WSearch - ok 23:05:57.0277 34028 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll 23:05:57.0317 34028 wuauserv - ok 23:05:57.0447 34028 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 23:05:57.0457 34028 WudfPf - ok 23:05:57.0497 34028 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 23:05:57.0507 34028 WUDFRd - ok 23:05:57.0537 34028 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll 23:05:57.0537 34028 wudfsvc - ok 23:05:57.0567 34028 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 23:05:57.0567 34028 WwanSvc - ok 23:05:57.0617 34028 MBR (0x1B8) (3239ce7842f101b16f173298508f3677) \Device\Harddisk0\DR0 23:05:57.0847 34028 \Device\Harddisk0\DR0 - ok 23:05:57.0847 34028 Boot (0x1200) (8aeb0fbfc5360724668863fc62d62ac1) \Device\Harddisk0\DR0\Partition0 23:05:57.0847 34028 \Device\Harddisk0\DR0\Partition0 - ok 23:05:57.0857 34028 Boot (0x1200) (f90161c21fc2cd300744f052d1520b8d) \Device\Harddisk0\DR0\Partition1 23:05:57.0857 34028 \Device\Harddisk0\DR0\Partition1 - ok 23:05:57.0897 34028 Boot (0x1200) (71eba82ad2563316ff2d4a01618898e4) \Device\Harddisk0\DR0\Partition2 23:05:57.0897 34028 \Device\Harddisk0\DR0\Partition2 - ok 23:05:57.0897 34028 ============================================================ 23:05:57.0897 34028 Scan finished 23:05:57.0897 34028 ============================================================ 23:05:57.0907 36644 Detected object count: 0 23:05:57.0907 36644 Actual detected object count: 0
Hi BigLars,

Thanks for the heads up!

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Hi, NoodleTech– I ran the Combofix and the log is below. That's is for tonight. Thank you. ComboFix 12-07-10.01 - Lars 07/10/2012 0:50.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2251 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\CouponAlert_2pEI c:\program files (x86)\RadioPI_4eEI c:\program files (x86)\SelectRebates c:\program files (x86)\SelectRebates\FFToolbar\chrome.manifest c:\program files (x86)\SelectRebates\FFToolbar\chrome\sahtoolbar.jar c:\program files (x86)\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js c:\program files (x86)\SelectRebates\FFToolbar\install.rdf c:\program files (x86)\SelectRebates\SahImages\alert.png c:\program files (x86)\SelectRebates\SahImages\check.png c:\program files (x86)\SelectRebates\SahImages\close.png c:\program files (x86)\SelectRebates\SelectAlerts.dat c:\program files (x86)\SelectRebates\SelectRebates.exe c:\program files (x86)\SelectRebates\SelectRebates.ini c:\program files (x86)\SelectRebates\SelectRebatesA.dat c:\program files (x86)\SelectRebates\SelectRebatesApi.exe c:\program files (x86)\SelectRebates\SelectRebatesB.dat c:\program files (x86)\SelectRebates\SelectRebatesBT.dat c:\program files (x86)\SelectRebates\SelectRebatesDownload.exe c:\program files (x86)\SelectRebates\SelectRebatesH.dat c:\program files (x86)\SelectRebates\SelectRebatesUninstall.exe c:\program files (x86)\SelectRebates\SRebates.dll c:\program files (x86)\SelectRebates\SRFF3.dll c:\program files (x86)\SelectRebates\Toolbar\AddtoList.bmp c:\program files (x86)\SelectRebates\Toolbar\basis.xml c:\program files (x86)\SelectRebates\Toolbar\Basis.xml.dym c:\program files (x86)\SelectRebates\Toolbar\Blank.bmp c:\program files (x86)\SelectRebates\Toolbar\CashBack.bmp c:\program files (x86)\SelectRebates\Toolbar\Coupons.bmp c:\program files (x86)\SelectRebates\Toolbar\GroceryCoupon.bmp c:\program files (x86)\SelectRebates\Toolbar\i_magnifying.bmp c:\program files (x86)\SelectRebates\Toolbar\icons.bmp c:\program files (x86)\SelectRebates\Toolbar\logo.bmp c:\program files (x86)\SelectRebates\Toolbar\logo_24.bmp c:\program files (x86)\SelectRebates\Toolbar\logo_HotSpots.bmp c:\program files (x86)\SelectRebates\Toolbar\ReviewSite.bmp c:\program files (x86)\SelectRebates\Toolbar\RightControls.dym c:\program files (x86)\SelectRebates\Toolbar\sahtb-alert.bmp c:\program files (x86)\SelectRebates\Toolbar\sahtb-go.bmp c:\program files (x86)\SelectRebates\Toolbar\sahtb-grocerycoupons.bmp c:\program files (x86)\SelectRebates\Toolbar\sahtb-icons.bmp c:\program files (x86)\SelectRebates\Toolbar\sahtb-restaurant.bmp c:\program files (x86)\SelectRebates\Toolbar\sahtb-wishlist.bmp c:\program files (x86)\SelectRebates\Toolbar\Scissors.bmp c:\program files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll c:\users\Lars\AppData\Local\Coupon Alert Installer(04980258).exe c:\users\Lars\AppData\Roaming\.# c:\users\Lars\AppData\Roaming\.#\MBX@102C@C12958.### c:\users\Lars\AppData\Roaming\.#\MBX@102C@C12988.### c:\users\Lars\AppData\Roaming\.#\MBX@102C@C129B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1050@302958.### c:\users\Lars\AppData\Roaming\.#\MBX@1050@302988.### c:\users\Lars\AppData\Roaming\.#\MBX@1050@3029B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1098@2A2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1098@2A2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1098@2A29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@10AC@2362958.### c:\users\Lars\AppData\Roaming\.#\MBX@10AC@2362988.### c:\users\Lars\AppData\Roaming\.#\MBX@10AC@23629B8.### c:\users\Lars\AppData\Roaming\.#\MBX@10B0@262958.### c:\users\Lars\AppData\Roaming\.#\MBX@10B0@262988.### c:\users\Lars\AppData\Roaming\.#\MBX@10B0@2629B8.### c:\users\Lars\AppData\Roaming\.#\MBX@10D4@C82958.### c:\users\Lars\AppData\Roaming\.#\MBX@10D4@C82988.### c:\users\Lars\AppData\Roaming\.#\MBX@10D4@C829B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1154@2122958.### c:\users\Lars\AppData\Roaming\.#\MBX@1154@2122988.### c:\users\Lars\AppData\Roaming\.#\MBX@1154@21229B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1220@2172958.### c:\users\Lars\AppData\Roaming\.#\MBX@1220@2172988.### c:\users\Lars\AppData\Roaming\.#\MBX@1220@21729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1324@1F72958.### c:\users\Lars\AppData\Roaming\.#\MBX@1324@1F72988.### c:\users\Lars\AppData\Roaming\.#\MBX@1324@1F729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1344@23A2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1344@23A2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1344@23A29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1380@3A2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1380@3A2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1380@3A29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@141C@2222958.### c:\users\Lars\AppData\Roaming\.#\MBX@141C@2222988.### c:\users\Lars\AppData\Roaming\.#\MBX@141C@22229B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1480@852958.### c:\users\Lars\AppData\Roaming\.#\MBX@1480@852988.### c:\users\Lars\AppData\Roaming\.#\MBX@1480@8529B8.### c:\users\Lars\AppData\Roaming\.#\MBX@14C0@2E2958.### c:\users\Lars\AppData\Roaming\.#\MBX@14C0@2E2988.### c:\users\Lars\AppData\Roaming\.#\MBX@14C0@2E29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@14F0@A22958.### c:\users\Lars\AppData\Roaming\.#\MBX@14F0@A22988.### c:\users\Lars\AppData\Roaming\.#\MBX@14F0@A229B8.### c:\users\Lars\AppData\Roaming\.#\MBX@152C@6A2958.### c:\users\Lars\AppData\Roaming\.#\MBX@152C@6A2988.### c:\users\Lars\AppData\Roaming\.#\MBX@152C@6A29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1538@B12958.### c:\users\Lars\AppData\Roaming\.#\MBX@1538@B12988.### c:\users\Lars\AppData\Roaming\.#\MBX@1538@B129B8.### c:\users\Lars\AppData\Roaming\.#\MBX@153C@21E2958.### c:\users\Lars\AppData\Roaming\.#\MBX@153C@21E2988.### c:\users\Lars\AppData\Roaming\.#\MBX@153C@21E29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1614@2002958.### c:\users\Lars\AppData\Roaming\.#\MBX@1614@2002988.### c:\users\Lars\AppData\Roaming\.#\MBX@1614@20029B8.### c:\users\Lars\AppData\Roaming\.#\MBX@16AC@2182958.### c:\users\Lars\AppData\Roaming\.#\MBX@16AC@2182988.### c:\users\Lars\AppData\Roaming\.#\MBX@16AC@21829B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1750@2172958.### c:\users\Lars\AppData\Roaming\.#\MBX@1750@2172988.### c:\users\Lars\AppData\Roaming\.#\MBX@1750@21729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@175C@2F2958.### c:\users\Lars\AppData\Roaming\.#\MBX@175C@2F2988.### c:\users\Lars\AppData\Roaming\.#\MBX@175C@2F29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@176C@802958.### c:\users\Lars\AppData\Roaming\.#\MBX@176C@802988.### c:\users\Lars\AppData\Roaming\.#\MBX@176C@8029B8.### c:\users\Lars\AppData\Roaming\.#\MBX@17DC@6B2958.### c:\users\Lars\AppData\Roaming\.#\MBX@17DC@6B2988.### c:\users\Lars\AppData\Roaming\.#\MBX@17DC@6B29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1818@2C2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1818@2C2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1818@2C29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@18F8@1FA2958.### c:\users\Lars\AppData\Roaming\.#\MBX@18F8@1FA2988.### c:\users\Lars\AppData\Roaming\.#\MBX@18F8@1FA29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1990@9B2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1990@9B2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1990@9B29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1A08@C72958.### c:\users\Lars\AppData\Roaming\.#\MBX@1A08@C72988.### c:\users\Lars\AppData\Roaming\.#\MBX@1A08@C729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1A70@1F72958.### c:\users\Lars\AppData\Roaming\.#\MBX@1A70@1F72988.### c:\users\Lars\AppData\Roaming\.#\MBX@1A70@1F729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1A94@9A2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1A94@9A2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1A94@9A29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1B14@20B2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1B14@20B2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1B14@20B29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1BEC@C72958.### c:\users\Lars\AppData\Roaming\.#\MBX@1BEC@C72988.### c:\users\Lars\AppData\Roaming\.#\MBX@1BEC@C729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1CB4@242958.### c:\users\Lars\AppData\Roaming\.#\MBX@1CB4@242988.### c:\users\Lars\AppData\Roaming\.#\MBX@1CB4@2429B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1D38@2042958.### c:\users\Lars\AppData\Roaming\.#\MBX@1D38@2042988.### c:\users\Lars\AppData\Roaming\.#\MBX@1D38@20429B8.### c:\users\Lars\AppData\Roaming\.#\MBX@1E20@1FE2958.### c:\users\Lars\AppData\Roaming\.#\MBX@1E20@1FE2988.### c:\users\Lars\AppData\Roaming\.#\MBX@1E20@1FE29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@2118@2062958.### c:\users\Lars\AppData\Roaming\.#\MBX@2118@2062988.### c:\users\Lars\AppData\Roaming\.#\MBX@2118@20629B8.### c:\users\Lars\AppData\Roaming\.#\MBX@230@20C2958.### c:\users\Lars\AppData\Roaming\.#\MBX@230@20C2988.### c:\users\Lars\AppData\Roaming\.#\MBX@230@20C29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@2450@A72958.### c:\users\Lars\AppData\Roaming\.#\MBX@2450@A72988.### c:\users\Lars\AppData\Roaming\.#\MBX@2450@A729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@348@C52958.### c:\users\Lars\AppData\Roaming\.#\MBX@348@C52988.### c:\users\Lars\AppData\Roaming\.#\MBX@348@C529B8.### c:\users\Lars\AppData\Roaming\.#\MBX@638@2182958.### c:\users\Lars\AppData\Roaming\.#\MBX@638@2182988.### c:\users\Lars\AppData\Roaming\.#\MBX@638@21829B8.### c:\users\Lars\AppData\Roaming\.#\MBX@6E0@2002958.### c:\users\Lars\AppData\Roaming\.#\MBX@6E0@2002988.### c:\users\Lars\AppData\Roaming\.#\MBX@6E0@20029B8.### c:\users\Lars\AppData\Roaming\.#\MBX@734@6F2958.### c:\users\Lars\AppData\Roaming\.#\MBX@734@6F2988.### c:\users\Lars\AppData\Roaming\.#\MBX@734@6F29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@790@292958.### c:\users\Lars\AppData\Roaming\.#\MBX@790@292988.### c:\users\Lars\AppData\Roaming\.#\MBX@790@2929B8.### c:\users\Lars\AppData\Roaming\.#\MBX@820@D02958.### c:\users\Lars\AppData\Roaming\.#\MBX@820@D02988.### c:\users\Lars\AppData\Roaming\.#\MBX@820@D029B8.### c:\users\Lars\AppData\Roaming\.#\MBX@848@B82958.### c:\users\Lars\AppData\Roaming\.#\MBX@848@B82988.### c:\users\Lars\AppData\Roaming\.#\MBX@848@B829B8.### c:\users\Lars\AppData\Roaming\.#\MBX@904@BA2958.### c:\users\Lars\AppData\Roaming\.#\MBX@904@BA2988.### c:\users\Lars\AppData\Roaming\.#\MBX@904@BA29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@96C@1FF2958.### c:\users\Lars\AppData\Roaming\.#\MBX@96C@1FF2988.### c:\users\Lars\AppData\Roaming\.#\MBX@96C@1FF29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@A3C@2082958.### c:\users\Lars\AppData\Roaming\.#\MBX@A3C@2082988.### c:\users\Lars\AppData\Roaming\.#\MBX@A3C@20829B8.### c:\users\Lars\AppData\Roaming\.#\MBX@A4C@2B2958.### c:\users\Lars\AppData\Roaming\.#\MBX@A4C@2B2988.### c:\users\Lars\AppData\Roaming\.#\MBX@A4C@2B29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@AA4@AB2958.### c:\users\Lars\AppData\Roaming\.#\MBX@AA4@AB2988.### c:\users\Lars\AppData\Roaming\.#\MBX@AA4@AB29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@B78@262958.### c:\users\Lars\AppData\Roaming\.#\MBX@B78@262988.### c:\users\Lars\AppData\Roaming\.#\MBX@B78@2629B8.### c:\users\Lars\AppData\Roaming\.#\MBX@C64@9D2958.### c:\users\Lars\AppData\Roaming\.#\MBX@C64@9D2988.### c:\users\Lars\AppData\Roaming\.#\MBX@C64@9D29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@D54@272958.### c:\users\Lars\AppData\Roaming\.#\MBX@D54@272988.### c:\users\Lars\AppData\Roaming\.#\MBX@D54@2729B8.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@2B2958.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@2B2988.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@2B29B8.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@712958.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@712988.### c:\users\Lars\AppData\Roaming\.#\MBX@DC4@7129B8.### c:\users\Lars\AppData\Roaming\.#\MBX@DEC@C32958.### c:\users\Lars\AppData\Roaming\.#\MBX@DEC@C32988.### c:\users\Lars\AppData\Roaming\.#\MBX@DEC@C329B8.### c:\users\Lars\AppData\Roaming\.#\MBX@FB0@692958.### c:\users\Lars\AppData\Roaming\.#\MBX@FB0@692988.### c:\users\Lars\AppData\Roaming\.#\MBX@FB0@6929B8.### c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7} c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7}\chrome.manifest c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7}\chrome\xulcache.jar c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7}\defaults\preferences\xulcache.js c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7}\install.rdf c:\windows\system32\drivers\etc\hosts.ics . . ((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 ))))))))))))))))))))))))))))))) . . 2012-07-07 06:45 . 2012-07-07 06:46 ——– d—–w- c:\users\Lars\AppData\Local\FileTypeAssistant 2012-07-07 06:41 . 2012-07-07 20:17 ——– d—–w- c:\users\Lars\AppData\Roaming\FreeFileViewer 2012-07-07 06:35 . 2012-07-07 06:35 ——– d—–w- c:\program files (x86)\File Type Assistant 2012-07-07 06:35 . 2012-07-07 06:35 ——– d—–w- c:\program files (x86)\FreeFileViewer 2012-07-06 20:58 . 2012-07-06 20:58 ——– d—–w- c:\programdata\Kaspersky Lab 2012-07-06 04:28 . 2012-07-06 04:28 ——– d—–w- C:\NPE 2012-07-06 01:13 . 2009-05-18 07:47 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-07-06 01:12 . 2012-07-06 01:12 ——– d—–w- c:\windows\system32\drivers\NBRTWizardx64 2012-07-06 01:12 . 2012-07-06 01:12 ——– d—–w- c:\program files (x86)\Norton Bootable Recovery Tool Wizard 2012-06-23 04:15 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-23 04:15 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-23 04:15 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-23 04:15 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-23 04:15 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-23 04:15 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-23 04:15 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-23 04:15 . 2012-06-02 22:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-23 04:15 . 2012-06-02 22:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-19 03:16 . 2012-06-19 03:16 ——– d—–w- c:\users\Lars\AppData\Local\Macromedia 2012-06-17 21:50 . 2012-06-17 21:50 770384 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll 2012-06-17 21:50 . 2012-06-17 21:50 421200 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll 2012-06-13 07:12 . 2012-04-26 05:41 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-13 07:12 . 2012-04-26 05:41 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-13 07:12 . 2012-04-26 05:34 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-07 20:20 . 2012-04-08 22:48 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-07 20:20 . 2011-05-22 17:19 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-06-04 13:00 . 2009-08-05 20:45 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2012-06-04 13:00 . 2009-08-05 20:45 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2012-05-04 20:54 . 2012-04-08 22:54 8744608 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192] . [HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-11-29 23:26 3908192 —-a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}] 2010-11-29 23:26 3908192 —-a-w- c:\program files (x86)\MyAshampoo\tbMyAs.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}] 2012-01-18 00:46 174464 —-a-w- c:\program files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192] . [HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "HP KEYBOARDx"="c:\program files (x86)\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE" [2009-07-15 715264] "HP Remote Solution"="c:\program files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe" [2009-05-26 656896] "Buttons & OSDs control application gen3"="c:\program files (x86)\Hewlett-Packard\Buttons & OSDs control application gen3\FastUserSwitching.exe" [2009-07-03 212992] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "NortonOnlineBackupReminder"="c:\program files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-05-13 581480] "UpdatePRCShortCut"="c:\program files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1314816] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-03 98304] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-23 136176] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-07 250056] R3 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [2009-08-25 544768] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-23 136176] R3 hidkmdf;Microsoft HID Class Shim for KMDF;c:\windows\system32\DRIVERS\hidkmdf.sys [2009-07-29 13816] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-13 233472] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\NISx64\1008000.029\SYMNDISV.SYS [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-04 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-08-18 69376] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1109000.00C\SYMDS64.SYS [2010-02-04 433200] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1109000.00C\SYMEFA64.SYS [2011-08-22 221304] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\BASHDefs\20120619.001\BHDrvx64.sys [2012-06-19 1161376] S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NISx64\1109000.00C\ccHPx64.sys [2011-08-04 593544] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\IPSDefs\20120707.001\IDSvia64.sys [2012-06-14 509088] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1109000.00C\Ironx64.SYS [2010-04-29 150064] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NISx64\1109000.00C\SYMTDIV.SYS [2011-08-22 451704] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-02-03 202752] S2 CalendarSynchService;CalendarSynchService;c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2009-08-19 22072] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-10-28 2152152] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408] S2 MotoConnect Service;MotoConnect Service;c:\program files (x86)\Motorola\MotoConnectService\MotoConnectService.exe [2010-01-27 91392] S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe [2011-08-04 126400] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S3 ACPIService;Buttons and OSDs ACPI driver gen2;c:\windows\system32\DRIVERS\OSDACPI.SYS [2009-06-17 17992] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-02-03 6366720] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-02-03 186880] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-05-31 138912] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-10-21 17152] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2009-10-12 763904] S3 NW1950;NextWindow 1950 Touch Screen;c:\windows\system32\DRIVERS\NW1950.sys [2009-07-29 24568] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-04-03 34872] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] . . — Other Services/Drivers In Memory — . *NewlyCreated* - LAVASOFT_KERNEXPLORER *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 20:20] . 2012-07-01 c:\windows\Tasks\EasyShare Registration Task.job - c:\windows\system32\rundll32.exe [2009-07-13 01:14] . 2012-07-10 c:\windows\Tasks\FreeFileViewerUpdateChecker.job - c:\program files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2012-07-07 21:24] . 2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-23 17:43] . 2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-23 17:43] . 2012-07-03 c:\windows\Tasks\HPCeeScheduleForLars.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15] . 2012-06-30 c:\windows\Tasks\PCDRScheduledMaintenance.job - c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2009-06-10 11:04] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAX"="c:\program files (x86)\Analog Devices\SoundMAX\soundmax.exe" [2009-06-22 3866624] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=crossfire&pf=cndt mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download by GAS - c:\progra~1\GETASF~1\ie_MenuExt.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: {{25510184-5A38-4A99-B273-DCA8EEF6CD08} - c:\program files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q= FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . WebBrowser-{A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\17.9.0.12\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-1172577316-3403665654-4273877453-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1172577316-3403665654-4273877453-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\BurnAware Free\NMSAccess32.exe c:\program files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe c:\program files (x86)\Lavasoft\Ad-Aware\AAWTray.exe c:\program files (x86)\Motorola\MotoConnectService\MotoConnect.exe . ************************************************************************** . Completion time: 2012-07-10 01:12:11 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-10 08:12 . Pre-Run: 333,141,848,064 bytes free Post-Run: 333,653,049,344 bytes free . - - End Of File - - 34BF20268BD0514C6B803C2227C61140
Hi BigLars,

Looking good! How is the computer behaving now?

Please run Malwarebytes' Anti-Malware.
  • Click the Update tab, then click Check for Updates.
  • If an update is found, download and install the latest version.
  • Next, click Scanner, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Hi, NoodleTech– The computer seems to be working OK, although reboot was rather slow. I ran the MalwareBytes Anti-Malware and the ESET Online Scanner. The logs are below. Thank you for your assistance so far. Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.07.11.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Lars :: LARS-PC [administrator] Protection: Enabled 7/10/2012 8:15:42 PM mbam-log-2012-07-10 (20-15-42).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 217454 Time elapsed: 5 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Users\Lars\Downloads\FreeFileViewer2011Setup.exe (PUP.BundleOffers.IIQ) -> Quarantined and deleted successfully. C:\Users\Lars\Downloads\SoftonicDownloader_for_kaspersky-tdsskiller.exe (PUP.ToolbarDownloader) -> Quarantined and deleted successfully. (end) C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch134.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch136.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch137.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch142.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch143.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch145.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch148.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch160.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch208.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch323.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch325.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch326.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch331.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch332.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch334.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch337.zip Win32/Bagle.gen.zip worm C:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch349.zip Win32/Bagle.gen.zip worm C:\Qoobox\Quarantine\C\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\9ebbqp1f.default\extensions\{321c4141-beff-4dfd-a920-8bfa7eb28cc7}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch134.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch136.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch137.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch142.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch143.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch145.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch148.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch160.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch208.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch323.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch325.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch326.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch331.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch332.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch334.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch337.zip Win32/Bagle.gen.zip worm C:\Users\All Users\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch349.zip Win32/Bagle.gen.zip worm C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\6f3385d3-3ea5d5e2 Java/Exploit.CVE-2012-0507.CU trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\39995914-22a165cb Java/Exploit.Agent.NBS trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\52b610aa-696cbb3b Java/Exploit.CVE-2012-0507.CU trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\7d191e37-1ef19e50 a variant of Java/Exploit.CVE-2012-0507.BZ trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\3c2d347a-25ebd800 a variant of Java/TrojanDownloader.Agent.NDN trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\54eec2c6-14b39e94 Java/Exploit.CVE-2012-0507.CH trojan C:\Users\Lars\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\1adc57e-2d7dfa64 Java/Exploit.CVE-2011-3544.AU trojan
Hi BigLars,

Everything looks good. We need to clear your Java cache and update Java. Then we will clean up the tools we used and send you on your way.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 5.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Please uninstall HijackThis and delete aswMBR and TDSSKiller

Follow these steps to uninstall Combofix

* Click START
* Now type ComboFix /Uninstall in the searchbox and hit ENTER. Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 

**Please respond one more time to confirm your problem is resolved so I can close this thread.
Hi, NoodleTech– Thank you for the assistance. I have updated Java and cleared Java cache. I have uninstalled the programs used. I have run Secunia and checked Windows updates. I have bookmarked your other suggestions and will soon take a look at those. It seems to be working fine. I will make a donation after I deal with some other transactions. Have a nice night.
Hi BigLars, You are very welcome :). There's one more thing I forgot to mention. You have multiple anti-virus software installed (Norton Internet Security and Lavasoft Ad-Watch Live!). Running multiple AV software can result in sluggish performance as well as conflicts. I suggest you only keep one AV software installed (I recommend uninstalling Ad-Watch Live!) as having more than one AV software on your computer does not improve security. Best, NT

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI