This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Sorry I had to start a new topic, I was unable to get to my computer for a few days.
I uninstalled AVG so that combofix would run and here are the results:


ComboFix 12-07-12.02 - Cazzimodo 14/07/2012 17:05:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.927 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Cazzimodo\AppData\Local\.#
c:\users\Cazzimodo\AppData\Local\eikwevuk.log
c:\users\Cazzimodo\AppData\Local\gebtquyn.log
c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
c:\users\Cazzimodo\AppData\Local\kstjseyl.log
c:\users\Cazzimodo\AppData\Local\sjqjddqt.log
c:\users\Cazzimodo\AppData\Local\tjgybktk.log
c:\users\Cazzimodo\AppData\Local\wceqmydo.log
c:\users\Cazzimodo\AppData\Roaming\.#
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2938.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2968.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2998.###
.
.
((((((((((((((((((((((((( Files Created from 2012-06-14 to 2012-07-14 )))))))))))))))))))))))))))))))
.
.
2012-07-14 16:19 . 2012-07-14 16:24 ——– d—–w- c:\users\Cazzimodo\AppData\Local\temp
2012-07-14 16:19 . 2012-07-14 16:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-13 14:39 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{706ED08E-829F-43C8-91C9-16331763E815}\mpengine.dll
2012-07-12 02:10 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 15:36 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 15:36 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 15:36 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 15:35 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 15:35 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 15:35 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-06-30 10:33 . 2012-06-30 10:33 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-06-30 10:33 . 2012-07-04 20:48 829920 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-06-30 10:33 . 2012-07-04 20:48 2042848 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-06-22 18:44 . 2012-07-04 20:48 16864 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2012-06-22 08:49 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-22 08:49 . 2012-03-01 14:46 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-06-22 08:49 . 2012-03-01 14:46 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-06-22 08:49 . 2012-02-29 14:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-06-22 08:49 . 2012-02-29 13:44 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-06-22 08:49 . 2012-02-29 13:41 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-06-22 03:39 . 2012-06-22 03:39 ——– d—–w- c:\program files\Windows Portable Devices
2012-06-22 03:07 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-06-22 03:07 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-06-22 03:07 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-06-22 02:56 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-22 02:56 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-22 02:56 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-22 02:56 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-22 02:55 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-22 02:55 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-22 02:55 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-22 02:54 . 2012-06-02 14:19 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-22 02:54 . 2012-06-02 14:12 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-22 02:51 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-22 02:51 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-06-22 02:51 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-22 02:51 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-22 02:38 . 2012-06-22 02:38 307200 —-a-w- c:\program files\Internet Explorer\iediagcmd.exe
2012-06-22 02:38 . 2012-06-22 02:38 161792 —-a-w- c:\windows\system32\msls31.dll
2012-06-22 02:38 . 2012-06-22 02:38 107008 —-a-w- c:\program files\Internet Explorer\iecleanup.exe
2012-06-22 02:36 . 2012-06-22 02:36 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2012-06-22 02:36 . 2012-06-22 02:36 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2012-06-22 02:36 . 2012-06-22 02:36 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2012-06-22 02:36 . 2012-06-22 02:36 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2012-06-22 02:36 . 2012-06-22 02:36 98816 —-a-w- c:\windows\system32\mfps.dll
2012-06-22 02:36 . 2012-06-22 02:36 2873344 —-a-w- c:\windows\system32\mf.dll
2012-06-22 02:34 . 2012-06-22 02:34 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-06-22 02:34 . 2012-06-22 02:34 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-06-22 02:34 . 2012-06-22 02:34 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-06-22 02:34 . 2012-06-22 02:34 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-06-22 02:34 . 2012-06-22 02:34 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-06-22 02:34 . 2012-06-22 02:34 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-06-22 02:34 . 2012-06-22 02:34 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-21 07:58 . 2012-04-23 16:00 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-21 07:58 . 2012-04-23 16:00 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-21 07:58 . 2012-04-23 16:00 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-21 07:58 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2012-06-21 07:58 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2012-06-21 07:58 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2012-06-21 07:58 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2012-06-21 07:58 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-06-21 07:58 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-06-21 07:57 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-06-21 07:57 . 2012-02-01 15:11 1218048 —-a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-21 07:57 . 2012-02-01 15:10 964608 —-a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-21 07:57 . 2012-02-01 15:10 1404928 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2012-06-21 07:57 . 2012-02-01 15:10 983040 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-21 07:57 . 2012-02-01 15:10 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-21 07:57 . 2012-02-01 13:58 47104 —-a-w- c:\program files\Windows Journal\PDIALOG.exe
2012-06-21 07:57 . 2012-03-30 12:39 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-21 07:57 . 2012-03-20 23:28 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-21 07:57 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-06-21 07:57 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-06-21 07:56 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-06-21 07:56 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-06-21 07:56 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-06-21 07:56 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-06-21 07:56 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-06-21 07:56 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
2012-06-21 07:56 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2012-06-21 07:56 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-06-21 07:56 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2012-06-21 07:56 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-06-21 07:56 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2012-06-21 07:56 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2012-06-21 07:55 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-06-21 07:55 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-06-21 07:55 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-06-21 07:55 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-06-21 07:55 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-21 07:55 . 2012-05-01 14:03 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-21 07:55 . 2012-04-03 08:16 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-06-21 07:55 . 2012-04-03 08:16 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-21 07:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2012-06-21 07:41 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-06-21 07:32 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\ca-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\eu-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\vi-VN
2012-06-20 10:18 . 2012-07-02 17:02 ——– d—–w- c:\users\Cazzimodo\AppData\Local\ilrryeuh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-22 02:34 . 2012-06-22 02:34 4096 —-a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-03-27 04:09 . 2012-03-27 04:09 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll
2012-03-27 04:09 . 2012-03-27 04:09 421736 —-a-w- c:\program files\iTunesHelper.exe
2012-03-27 04:09 . 2012-03-27 04:09 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll
2012-03-27 04:09 . 2012-03-27 04:09 156520 —-a-w- c:\program files\iTunesHelper.dll
2012-03-27 04:09 . 2012-03-27 04:09 402792 —-a-w- c:\program files\iTunesAdmin.dll
2012-03-27 04:09 . 2012-03-27 04:09 9777000 —-a-w- c:\program files\iTunes.exe
2012-03-27 04:09 . 2012-03-27 04:09 21006696 —-a-w- c:\program files\iTunes.dll
2012-03-27 04:09 . 2012-03-27 04:09 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll
2012-03-27 04:09 . 2012-03-27 04:09 649576 —-a-w- c:\program files\iPodUpdaterExt.dll
2012-03-27 04:09 . 2012-03-27 04:09 3029528 —-a-w- c:\program files\gnsdk_dsp.dll
2012-03-27 04:09 . 2012-03-27 04:09 281112 —-a-w- c:\program files\gnsdk_submit.dll
2012-03-27 04:09 . 2012-03-27 04:09 240152 —-a-w- c:\program files\gnsdk_musicid.dll
2012-03-06 19:44 . 2012-03-06 19:44 112488 —-a-w- c:\program files\ITDetector.ocx
2012-07-04 20:48 . 2012-06-30 10:33 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Spotify Web Helper"="c:\users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe" [2012-05-08 932528]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-08-25 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunesHelper.exe" [2012-03-27 421736]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
.
c:\users\Cazzimodo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-13 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-18 17:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 17:38]
.
2012-07-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 18:56]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000Core.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000UA.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Cazzimodo\AppData\Roaming\Mozilla\Firefox\Profiles\mujlpshm.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D&mid=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds=AVG&v=10.0.0.7&lang=us&pr=fr&d=2011-12-10%2014%3A33%3A45&sap=ku&q=
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-Exetender - c:\program files\Free Ride Games\GPlayer.exe
HKCU-Run-Facebook Update - c:\users\Cazzimodo\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKCU-Run-QrjEjeex - c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
HKCU-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
AddRemove-Spotify - c:\users\Cazzimodo\Desktop\uninstall.exe
AddRemove-{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06} - c:\users\Cazzimodo\Documents\Chikeeto's\EAUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-14 17:23
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2012-07-14 17:31:11 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-14 16:30
.
Pre-Run: 15,890,980,864 bytes free
Post-Run: 18,242,781,184 bytes free
.
- - End Of File - - 5C0A0035F72AEC471A89929056ACD025
Hello again, now that Combofix has removed some infections see if TDSSKiller can be downloaded and ran.If not just continue with Malwarebytes and ESET.



Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)









Please download Malwarebytes Free from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
The TDSSKiller is now working this time! My computer also seems to be running normally too, it now lets me use the desktop short cuts and access Google Chrome again. Here are the TDSSKiller results: 19:13:37.0858 5580 TDSS rootkit removing tool [removed] Jul 9 2012 12:46:35 19:13:38.0107 5580 ============================================================ 19:13:38.0107 5580 Current date / time: 2012/07/15 19:13:38.0107 19:13:38.0107 5580 SystemInfo: 19:13:38.0107 5580 19:13:38.0108 5580 OS Version: 6.0.6002 ServicePack: 2.0 19:13:38.0108 5580 Product type: Workstation 19:13:38.0108 5580 ComputerName: CHIKEETO-PC 19:13:38.0109 5580 UserName: Cazzimodo 19:13:38.0109 5580 Windows directory: C:\Windows 19:13:38.0109 5580 System windows directory: C:\Windows 19:13:38.0109 5580 Processor architecture: Intel x86 19:13:38.0109 5580 Number of processors: 2 19:13:38.0109 5580 Page size: 0x1000 19:13:38.0109 5580 Boot type: Normal boot 19:13:38.0109 5580 ============================================================ 19:13:40.0615 5580 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 19:13:40.0647 5580 ============================================================ 19:13:40.0647 5580 \Device\Harddisk0\DR0: 19:13:40.0647 5580 MBR partitions: 19:13:40.0647 5580 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x6A000, BlocksNum 0x1400000 19:13:40.0647 5580 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x146A000, BlocksNum 0x115AF000 19:13:40.0647 5580 ============================================================ 19:13:40.0690 5580 C: <-> \Device\Harddisk0\DR0\Partition1 19:13:40.0730 5580 D: <-> \Device\Harddisk0\DR0\Partition0 19:13:40.0731 5580 ============================================================ 19:13:40.0731 5580 Initialize success 19:13:40.0731 5580 ============================================================ 19:14:00.0080 4780 ============================================================ 19:14:00.0080 4780 Scan started 19:14:00.0080 4780 Mode: Manual; 19:14:00.0080 4780 ============================================================ 19:14:03.0200 4780 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 19:14:03.0209 4780 ACPI - ok 19:14:03.0310 4780 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 19:14:03.0321 4780 AdobeFlashPlayerUpdateSvc - ok 19:14:03.0425 4780 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 19:14:03.0445 4780 adp94xx - ok 19:14:03.0525 4780 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 19:14:03.0541 4780 adpahci - ok 19:14:03.0577 4780 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 19:14:03.0581 4780 adpu160m - ok 19:14:03.0627 4780 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 19:14:03.0637 4780 adpu320 - ok 19:14:03.0695 4780 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll 19:14:03.0697 4780 AeLookupSvc - ok 19:14:03.0805 4780 AESTFilters (ef1142512bec12f1c2c87735da1755be) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe 19:14:03.0808 4780 AESTFilters - ok 19:14:03.0893 4780 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 19:14:03.0910 4780 AFD - ok 19:14:03.0950 4780 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 19:14:03.0953 4780 agp440 - ok 19:14:04.0011 4780 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 19:14:04.0014 4780 aic78xx - ok 19:14:04.0044 4780 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe 19:14:04.0049 4780 ALG - ok 19:14:04.0090 4780 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 19:14:04.0103 4780 aliide - ok 19:14:04.0135 4780 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 19:14:04.0139 4780 amdagp - ok 19:14:04.0172 4780 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 19:14:04.0173 4780 amdide - ok 19:14:04.0303 4780 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 19:14:04.0360 4780 AmdK7 - ok 19:14:04.0400 4780 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 19:14:04.0403 4780 AmdK8 - ok 19:14:04.0461 4780 ApfiltrService (b83f9da84f7079451c1c6a4a2f140920) C:\Windows\system32\DRIVERS\Apfiltr.sys 19:14:04.0468 4780 ApfiltrService - ok 19:14:04.0496 4780 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll 19:14:04.0497 4780 Appinfo - ok 19:14:04.0605 4780 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 19:14:04.0622 4780 Apple Mobile Device - ok 19:14:04.0691 4780 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 19:14:04.0706 4780 arc - ok 19:14:04.0764 4780 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 19:14:04.0768 4780 arcsas - ok 19:14:04.0912 4780 aspnet_state (40c145f12ff461a0220303bda134f598) C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 19:14:04.0916 4780 aspnet_state - ok 19:14:04.0961 4780 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 19:14:04.0963 4780 AsyncMac - ok 19:14:05.0013 4780 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 19:14:05.0013 4780 atapi - ok 19:14:05.0084 4780 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 19:14:05.0093 4780 AudioEndpointBuilder - ok 19:14:05.0105 4780 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 19:14:05.0110 4780 Audiosrv - ok 19:14:05.0172 4780 BCM42RLY (7bd70aeed0d975285a1b20bd012ebf4e) C:\Windows\system32\drivers\BCM42RLY.sys 19:14:05.0174 4780 BCM42RLY - ok 19:14:05.0352 4780 BCM43XX (fa6707a346cd122407f3b0bad1c47639) C:\Windows\system32\DRIVERS\bcmwl6.sys 19:14:05.0394 4780 BCM43XX - ok 19:14:05.0463 4780 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 19:14:05.0466 4780 Beep - ok 19:14:05.0553 4780 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll 19:14:05.0561 4780 BFE - ok 19:14:05.0716 4780 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\system32\qmgr.dll 19:14:05.0752 4780 BITS - ok 19:14:05.0784 4780 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 19:14:05.0786 4780 blbdrive - ok 19:14:05.0939 4780 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 19:14:05.0952 4780 Bonjour Service - ok 19:14:06.0001 4780 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 19:14:06.0017 4780 bowser - ok 19:14:06.0064 4780 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 19:14:06.0066 4780 BrFiltLo - ok 19:14:06.0101 4780 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 19:14:06.0102 4780 BrFiltUp - ok 19:14:06.0149 4780 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll 19:14:06.0152 4780 Browser - ok 19:14:06.0199 4780 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 19:14:06.0203 4780 Brserid - ok 19:14:06.0277 4780 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 19:14:06.0279 4780 BrSerWdm - ok 19:14:06.0300 4780 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 19:14:06.0303 4780 BrUsbMdm - ok 19:14:06.0325 4780 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 19:14:06.0327 4780 BrUsbSer - ok 19:14:06.0389 4780 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 19:14:06.0392 4780 BTHMODEM - ok 19:14:06.0513 4780 catchme - ok 19:14:06.0581 4780 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 19:14:06.0584 4780 cdfs - ok 19:14:06.0651 4780 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 19:14:06.0654 4780 cdrom - ok 19:14:06.0714 4780 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 19:14:06.0717 4780 CertPropSvc - ok 19:14:06.0750 4780 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys 19:14:06.0753 4780 circlass - ok 19:14:06.0818 4780 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 19:14:06.0830 4780 CLFS - ok 19:14:06.0938 4780 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:14:06.0944 4780 clr_optimization_v2.0.50727_32 - ok 19:14:07.0071 4780 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 19:14:07.0104 4780 clr_optimization_v4.0.30319_32 - ok 19:14:07.0141 4780 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 19:14:07.0143 4780 CmBatt - ok 19:14:07.0195 4780 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 19:14:07.0197 4780 cmdide - ok 19:14:07.0229 4780 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 19:14:07.0232 4780 Compbatt - ok 19:14:07.0239 4780 COMSysApp - ok 19:14:07.0286 4780 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 19:14:07.0288 4780 crcdisk - ok 19:14:07.0322 4780 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 19:14:07.0324 4780 Crusoe - ok 19:14:07.0429 4780 CryptSvc (75c6a297e364014840b48eccd7525e30) C:\Windows\system32\cryptsvc.dll 19:14:07.0440 4780 CryptSvc - ok 19:14:07.0555 4780 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 19:14:07.0591 4780 DcomLaunch - ok 19:14:07.0625 4780 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 19:14:07.0629 4780 DfsC - ok 19:14:07.0935 4780 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe 19:14:08.0009 4780 DFSR - ok 19:14:08.0197 4780 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll 19:14:08.0214 4780 Dhcp - ok 19:14:08.0311 4780 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 19:14:08.0314 4780 disk - ok 19:14:08.0366 4780 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll 19:14:08.0380 4780 Dnscache - ok 19:14:08.0511 4780 DockLoginService (db29915209770d8b59654345ec2d943a) C:\Program Files\Dell\DellDock\DockLogin.exe 19:14:08.0515 4780 DockLoginService - ok 19:14:08.0583 4780 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll 19:14:08.0602 4780 dot3svc - ok 19:14:08.0657 4780 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll 19:14:08.0667 4780 DPS - ok 19:14:08.0714 4780 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 19:14:08.0716 4780 drmkaud - ok 19:14:08.0838 4780 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 19:14:08.0863 4780 DXGKrnl - ok 19:14:08.0938 4780 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys 19:14:08.0954 4780 e1express - ok 19:14:09.0019 4780 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 19:14:09.0032 4780 E1G60 - ok 19:14:09.0063 4780 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll 19:14:09.0065 4780 EapHost - ok 19:14:09.0133 4780 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 19:14:09.0165 4780 Ecache - ok 19:14:09.0258 4780 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe 19:14:09.0275 4780 ehRecvr - ok 19:14:09.0304 4780 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe 19:14:09.0313 4780 ehSched - ok 19:14:09.0333 4780 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll 19:14:09.0335 4780 ehstart - ok 19:14:09.0479 4780 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 19:14:09.0501 4780 elxstor - ok 19:14:09.0613 4780 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll 19:14:09.0632 4780 EMDMgmt - ok 19:14:09.0671 4780 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 19:14:09.0673 4780 ErrDev - ok 19:14:09.0738 4780 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll 19:14:09.0758 4780 EventSystem - ok 19:14:09.0819 4780 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 19:14:09.0828 4780 exfat - ok 19:14:09.0884 4780 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 19:14:09.0891 4780 fastfat - ok 19:14:09.0916 4780 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 19:14:09.0918 4780 fdc - ok 19:14:09.0969 4780 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll 19:14:09.0972 4780 fdPHost - ok 19:14:09.0989 4780 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll 19:14:09.0992 4780 FDResPub - ok 19:14:10.0025 4780 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 19:14:10.0027 4780 FileInfo - ok 19:14:10.0053 4780 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 19:14:10.0056 4780 Filetrace - ok 19:14:10.0099 4780 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 19:14:10.0102 4780 flpydisk - ok 19:14:10.0192 4780 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 19:14:10.0207 4780 FltMgr - ok 19:14:10.0383 4780 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll 19:14:10.0413 4780 FontCache - ok 19:14:10.0491 4780 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 19:14:10.0495 4780 FontCache3.0.0.0 - ok 19:14:10.0548 4780 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys 19:14:10.0550 4780 Fs_Rec - ok 19:14:10.0595 4780 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 19:14:10.0598 4780 gagp30kx - ok 19:14:10.0632 4780 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:14:10.0634 4780 GEARAspiWDM - ok 19:14:10.0731 4780 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe 19:14:10.0734 4780 GoToAssist - ok 19:14:10.0823 4780 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll 19:14:10.0851 4780 gpsvc - ok 19:14:10.0951 4780 gupdate1c9969b94668854 (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe 19:14:10.0962 4780 gupdate1c9969b94668854 - ok 19:14:10.0985 4780 gupdatem (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe 19:14:10.0987 4780 gupdatem - ok 19:14:11.0100 4780 gusvc (408ddd80eede47175f6844817b90213e) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 19:14:11.0138 4780 gusvc - ok 19:14:11.0296 4780 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 19:14:11.0314 4780 HDAudBus - ok 19:14:11.0363 4780 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 19:14:11.0366 4780 HidBth - ok 19:14:11.0414 4780 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys 19:14:11.0416 4780 HidIr - ok 19:14:11.0452 4780 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\System32\hidserv.dll 19:14:11.0455 4780 hidserv - ok 19:14:11.0506 4780 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 19:14:11.0508 4780 HidUsb - ok 19:14:11.0550 4780 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll 19:14:11.0554 4780 hkmsvc - ok 19:14:11.0593 4780 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 19:14:11.0596 4780 HpCISSs - ok 19:14:11.0682 4780 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 19:14:11.0705 4780 HTTP - ok 19:14:11.0733 4780 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 19:14:11.0737 4780 i2omp - ok 19:14:11.0782 4780 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 19:14:11.0786 4780 i8042prt - ok 19:14:11.0847 4780 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 19:14:11.0862 4780 iaStorV - ok 19:14:12.0074 4780 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 19:14:12.0106 4780 idsvc - ok 19:14:13.0193 4780 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 19:14:13.0468 4780 igfx - ok 19:14:13.0662 4780 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 19:14:13.0664 4780 iirsp - ok 19:14:13.0749 4780 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll 19:14:13.0765 4780 IKEEXT - ok 19:14:13.0817 4780 IntcHdmiAddService (8dab99684cfe8b4ddd5d6d0c5d55fdac) C:\Windows\system32\drivers\IntcHdmi.sys 19:14:13.0829 4780 IntcHdmiAddService - ok 19:14:13.0865 4780 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 19:14:13.0868 4780 intelide - ok 19:14:13.0911 4780 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 19:14:13.0914 4780 intelppm - ok 19:14:13.0975 4780 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll 19:14:13.0980 4780 IPBusEnum - ok 19:14:14.0004 4780 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:14:14.0017 4780 IpFilterDriver - ok 19:14:14.0077 4780 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll 19:14:14.0097 4780 iphlpsvc - ok 19:14:14.0105 4780 IpInIp - ok 19:14:14.0151 4780 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 19:14:14.0154 4780 IPMIDRV - ok 19:14:14.0196 4780 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 19:14:14.0200 4780 IPNAT - ok 19:14:14.0381 4780 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe 19:14:14.0402 4780 iPod Service - ok 19:14:14.0438 4780 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 19:14:14.0492 4780 IRENUM - ok 19:14:14.0704 4780 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 19:14:14.0707 4780 isapnp - ok 19:14:14.0822 4780 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 19:14:14.0838 4780 iScsiPrt - ok 19:14:14.0885 4780 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 19:14:14.0887 4780 iteatapi - ok 19:14:14.0934 4780 itecir (8bcd857c7932ad005d5f9c89329da2e1) C:\Windows\system32\DRIVERS\itecir.sys 19:14:14.0936 4780 itecir - ok 19:14:14.0997 4780 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 19:14:15.0000 4780 iteraid - ok 19:14:15.0064 4780 k57nd60x (2fbf424e4e8d5f320d2f69d9a726de30) C:\Windows\system32\DRIVERS\k57nd60x.sys 19:14:15.0070 4780 k57nd60x - ok 19:14:15.0100 4780 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 19:14:15.0103 4780 kbdclass - ok 19:14:15.0182 4780 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 19:14:15.0185 4780 kbdhid - ok 19:14:15.0245 4780 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 19:14:15.0249 4780 KeyIso - ok 19:14:15.0340 4780 KSecDD (4a1445efa932a3baf5bdb02d7131ee20) C:\Windows\system32\Drivers\ksecdd.sys 19:14:15.0379 4780 KSecDD - ok 19:14:15.0459 4780 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll 19:14:15.0476 4780 KtmRm - ok 19:14:15.0523 4780 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\System32\srvsvc.dll 19:14:15.0554 4780 LanmanServer - ok 19:14:15.0618 4780 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll 19:14:15.0637 4780 LanmanWorkstation - ok 19:14:15.0687 4780 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 19:14:15.0689 4780 lltdio - ok 19:14:15.0755 4780 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll 19:14:15.0772 4780 lltdsvc - ok 19:14:15.0803 4780 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll 19:14:15.0807 4780 lmhosts - ok 19:14:15.0864 4780 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 19:14:15.0867 4780 LSI_FC - ok 19:14:15.0899 4780 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 19:14:15.0913 4780 LSI_SAS - ok 19:14:15.0968 4780 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 19:14:15.0972 4780 LSI_SCSI - ok 19:14:16.0010 4780 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 19:14:16.0025 4780 luafv - ok 19:14:16.0210 4780 McComponentHostService (22a7776c5d8eb5930edf9c8dd0884259) C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe 19:14:16.0217 4780 McComponentHostService - ok 19:14:16.0290 4780 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll 19:14:16.0295 4780 Mcx2Svc - ok 19:14:16.0352 4780 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 19:14:16.0354 4780 megasas - ok 19:14:16.0445 4780 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 19:14:16.0457 4780 MegaSR - ok 19:14:16.0486 4780 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 19:14:16.0490 4780 MMCSS - ok 19:14:16.0532 4780 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 19:14:16.0534 4780 Modem - ok 19:14:16.0578 4780 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 19:14:16.0579 4780 monitor - ok 19:14:16.0595 4780 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 19:14:16.0598 4780 mouclass - ok 19:14:16.0619 4780 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 19:14:16.0621 4780 mouhid - ok 19:14:16.0640 4780 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 19:14:16.0643 4780 MountMgr - ok 19:14:16.0729 4780 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 19:14:16.0741 4780 MozillaMaintenance - ok 19:14:16.0789 4780 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 19:14:16.0793 4780 mpio - ok 19:14:16.0821 4780 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 19:14:16.0824 4780 mpsdrv - ok 19:14:16.0919 4780 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll 19:14:16.0958 4780 MpsSvc - ok 19:14:16.0982 4780 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 19:14:16.0984 4780 Mraid35x - ok 19:14:17.0041 4780 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 19:14:17.0054 4780 MRxDAV - ok 19:14:17.0125 4780 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 19:14:17.0160 4780 mrxsmb - ok 19:14:17.0252 4780 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:14:17.0265 4780 mrxsmb10 - ok 19:14:17.0303 4780 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:14:17.0319 4780 mrxsmb20 - ok 19:14:17.0383 4780 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 19:14:17.0385 4780 msahci - ok 19:14:17.0437 4780 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 19:14:17.0451 4780 msdsm - ok 19:14:17.0511 4780 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe 19:14:17.0522 4780 MSDTC - ok 19:14:17.0566 4780 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 19:14:17.0569 4780 Msfs - ok 19:14:17.0594 4780 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 19:14:17.0596 4780 msisadrv - ok 19:14:17.0660 4780 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll 19:14:17.0666 4780 MSiSCSI - ok 19:14:17.0679 4780 msiserver - ok 19:14:17.0723 4780 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 19:14:17.0725 4780 MSKSSRV - ok 19:14:17.0767 4780 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 19:14:17.0769 4780 MSPCLOCK - ok 19:14:17.0798 4780 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 19:14:17.0799 4780 MSPQM - ok 19:14:17.0853 4780 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 19:14:17.0858 4780 MsRPC - ok 19:14:17.0879 4780 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 19:14:17.0881 4780 mssmbios - ok 19:14:17.0911 4780 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 19:14:17.0913 4780 MSTEE - ok 19:14:17.0963 4780 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 19:14:17.0966 4780 Mup - ok 19:14:18.0033 4780 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll 19:14:18.0053 4780 napagent - ok 19:14:18.0128 4780 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 19:14:18.0133 4780 NativeWifiP - ok 19:14:18.0225 4780 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 19:14:18.0257 4780 NDIS - ok 19:14:18.0284 4780 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 19:14:18.0286 4780 NdisTapi - ok 19:14:18.0309 4780 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 19:14:18.0312 4780 Ndisuio - ok 19:14:18.0372 4780 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 19:14:18.0393 4780 NdisWan - ok 19:14:18.0428 4780 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 19:14:18.0431 4780 NDProxy - ok 19:14:18.0457 4780 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 19:14:18.0459 4780 NetBIOS - ok 19:14:18.0533 4780 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 19:14:18.0539 4780 netbt - ok 19:14:18.0587 4780 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 19:14:18.0590 4780 Netlogon - ok 19:14:18.0659 4780 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll 19:14:18.0692 4780 Netman - ok 19:14:18.0737 4780 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll 19:14:18.0742 4780 netprofm - ok 19:14:18.0864 4780 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 19:14:18.0868 4780 NetTcpPortSharing - ok 19:14:18.0896 4780 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 19:14:18.0899 4780 nfrd960 - ok 19:14:18.0945 4780 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll 19:14:18.0986 4780 NlaSvc - ok 19:14:19.0029 4780 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 19:14:19.0031 4780 Npfs - ok 19:14:19.0048 4780 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll 19:14:19.0052 4780 nsi - ok 19:14:19.0089 4780 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 19:14:19.0091 4780 nsiproxy - ok 19:14:19.0272 4780 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 19:14:19.0315 4780 Ntfs - ok 19:14:19.0358 4780 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 19:14:19.0360 4780 ntrigdigi - ok 19:14:19.0392 4780 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 19:14:19.0394 4780 Null - ok 19:14:19.0455 4780 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 19:14:19.0513 4780 nvraid - ok 19:14:19.0553 4780 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 19:14:19.0556 4780 nvstor - ok 19:14:19.0590 4780 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 19:14:19.0602 4780 nv_agp - ok 19:14:19.0608 4780 NwlnkFlt - ok 19:14:19.0624 4780 NwlnkFwd - ok 19:14:19.0669 4780 OA001Ufd (a015dd2ba6009c8bdd00a6c431302d06) C:\Windows\system32\DRIVERS\OA001Ufd.sys 19:14:19.0678 4780 OA001Ufd - ok 19:14:19.0740 4780 OA001Vid (2c9410571660dfd607c863c66ca56d60) C:\Windows\system32\DRIVERS\OA001Vid.sys 19:14:19.0771 4780 OA001Vid - ok 19:14:19.0843 4780 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 19:14:19.0846 4780 ohci1394 - ok 19:14:19.0954 4780 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 19:14:19.0986 4780 p2pimsvc - ok 19:14:20.0002 4780 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 19:14:20.0015 4780 p2psvc - ok 19:14:20.0055 4780 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 19:14:20.0070 4780 Parport - ok 19:14:20.0127 4780 partmgr (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys 19:14:20.0130 4780 partmgr - ok 19:14:20.0170 4780 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 19:14:20.0173 4780 Parvdm - ok 19:14:20.0209 4780 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll 19:14:20.0215 4780 PcaSvc - ok 19:14:20.0305 4780 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 19:14:20.0325 4780 pci - ok 19:14:20.0348 4780 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 19:14:20.0351 4780 pciide - ok 19:14:20.0440 4780 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 19:14:20.0490 4780 pcmcia - ok 19:14:20.0757 4780 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 19:14:20.0807 4780 PEAUTH - ok 19:14:21.0145 4780 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll 19:14:21.0267 4780 pla - ok 19:14:21.0706 4780 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll 19:14:21.0747 4780 PlugPlay - ok 19:14:21.0964 4780 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 19:14:21.0978 4780 PNRPAutoReg - ok 19:14:21.0999 4780 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 19:14:22.0011 4780 PNRPsvc - ok 19:14:22.0169 4780 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll 19:14:22.0192 4780 PolicyAgent - ok 19:14:22.0276 4780 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 19:14:22.0281 4780 PptpMiniport - ok 19:14:22.0331 4780 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 19:14:22.0333 4780 Processor - ok 19:14:22.0378 4780 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll 19:14:22.0421 4780 ProfSvc - ok 19:14:22.0478 4780 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 19:14:22.0481 4780 ProtectedStorage - ok 19:14:22.0544 4780 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 19:14:22.0547 4780 PSched - ok 19:14:22.0599 4780 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys 19:14:22.0602 4780 PxHelp20 - ok 19:14:22.0822 4780 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 19:14:22.0881 4780 ql2300 - ok 19:14:22.0939 4780 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 19:14:22.0943 4780 ql40xx - ok 19:14:23.0025 4780 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll 19:14:23.0035 4780 QWAVE - ok 19:14:23.0108 4780 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 19:14:23.0110 4780 QWAVEdrv - ok 19:14:23.0404 4780 R300 (e642b131fb74caf4bb8a014f31113142) C:\Windows\system32\DRIVERS\atikmdag.sys 19:14:23.0482 4780 R300 - ok 19:14:23.0664 4780 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 19:14:23.0667 4780 RasAcd - ok 19:14:23.0716 4780 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll 19:14:23.0731 4780 RasAuto - ok 19:14:23.0760 4780 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 19:14:23.0763 4780 Rasl2tp - ok 19:14:23.0835 4780 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll 19:14:23.0845 4780 RasMan - ok 19:14:23.0875 4780 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 19:14:23.0878 4780 RasPppoe - ok 19:14:23.0934 4780 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 19:14:23.0951 4780 RasSstp - ok 19:14:23.0991 4780 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 19:14:24.0004 4780 rdbss - ok 19:14:24.0027 4780 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 19:14:24.0029 4780 RDPCDD - ok 19:14:24.0093 4780 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 19:14:24.0138 4780 rdpdr - ok 19:14:24.0146 4780 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 19:14:24.0149 4780 RDPENCDD - ok 19:14:24.0226 4780 RDPWD (c127ebd5afab31524662c48dfceb773a) C:\Windows\system32\drivers\RDPWD.sys 19:14:24.0262 4780 RDPWD - ok 19:14:24.0307 4780 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll 19:14:24.0324 4780 RemoteAccess - ok 19:14:24.0373 4780 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll 19:14:24.0407 4780 RemoteRegistry - ok 19:14:24.0446 4780 rimmptsk (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys 19:14:24.0460 4780 rimmptsk - ok 19:14:24.0485 4780 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys 19:14:24.0488 4780 rimsptsk - ok 19:14:24.0530 4780 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys 19:14:24.0532 4780 rismxdp - ok 19:14:24.0567 4780 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe 19:14:24.0571 4780 RpcLocator - ok 19:14:24.0836 4780 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 19:14:24.0849 4780 RpcSs - ok 19:14:24.0897 4780 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 19:14:24.0900 4780 rspndr - ok 19:14:24.0928 4780 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 19:14:24.0931 4780 SamSs - ok 19:14:24.0979 4780 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 19:14:24.0994 4780 sbp2port - ok 19:14:25.0051 4780 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll 19:14:25.0066 4780 SCardSvr - ok 19:14:25.0174 4780 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll 19:14:25.0201 4780 Schedule - ok 19:14:25.0251 4780 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 19:14:25.0253 4780 SCPolicySvc - ok 19:14:25.0337 4780 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 19:14:25.0352 4780 sdbus - ok 19:14:25.0403 4780 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll 19:14:25.0415 4780 SDRSVC - ok 19:14:25.0438 4780 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 19:14:25.0440 4780 secdrv - ok 19:14:25.0462 4780 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll 19:14:25.0467 4780 seclogon - ok 19:14:25.0508 4780 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\system32\sens.dll 19:14:25.0513 4780 SENS - ok 19:14:25.0542 4780 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 19:14:25.0545 4780 Serenum - ok 19:14:25.0579 4780 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 19:14:25.0583 4780 Serial - ok 19:14:25.0635 4780 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 19:14:25.0637 4780 sermouse - ok 19:14:25.0692 4780 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll 19:14:25.0707 4780 SessionEnv - ok 19:14:25.0729 4780 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 19:14:25.0732 4780 sffdisk - ok 19:14:25.0751 4780 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 19:14:25.0754 4780 sffp_mmc - ok 19:14:25.0810 4780 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 19:14:25.0812 4780 sffp_sd - ok 19:14:25.0839 4780 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 19:14:25.0842 4780 sfloppy - ok 19:14:25.0912 4780 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll 19:14:25.0933 4780 SharedAccess - ok 19:14:25.0983 4780 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll 19:14:25.0992 4780 ShellHWDetection - ok 19:14:26.0022 4780 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 19:14:26.0026 4780 sisagp - ok 19:14:26.0058 4780 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 19:14:26.0061 4780 SiSRaid2 - ok 19:14:26.0087 4780 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 19:14:26.0091 4780 SiSRaid4 - ok 19:14:26.0573 4780 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe 19:14:26.0684 4780 slsvc - ok 19:14:26.0848 4780 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll 19:14:26.0865 4780 SLUINotify - ok 19:14:26.0941 4780 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 19:14:26.0960 4780 Smb - ok 19:14:27.0019 4780 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe 19:14:27.0024 4780 SNMPTRAP - ok 19:14:27.0060 4780 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 19:14:27.0063 4780 spldr - ok 19:14:27.0125 4780 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe 19:14:27.0158 4780 Spooler - ok 19:14:27.0249 4780 sprtsvc_DellSupportCenter (777115c9cc675bd98127660712d2f784) C:\Program Files\Dell Support Center\bin\sprtsvc.exe 19:14:27.0297 4780 sprtsvc_DellSupportCenter - ok 19:14:27.0367 4780 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 19:14:27.0386 4780 srv - ok 19:14:27.0428 4780 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 19:14:27.0434 4780 srv2 - ok 19:14:27.0476 4780 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 19:14:27.0489 4780 srvnet - ok 19:14:27.0524 4780 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll 19:14:27.0532 4780 SSDPSRV - ok 19:14:27.0582 4780 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll 19:14:27.0595 4780 SstpSvc - ok 19:14:27.0721 4780 STacSV (19c539ffa23f7db20d6ac6e2905adc21) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe 19:14:27.0726 4780 STacSV - ok 19:14:27.0812 4780 STHDA (d4ae2486c4290054b8d6f1adc4bad7fd) C:\Windows\system32\DRIVERS\stwrt.sys 19:14:27.0835 4780 STHDA - ok 19:14:27.0921 4780 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll 19:14:27.0940 4780 stisvc - ok 19:14:28.0029 4780 stllssvr (1d0063597c3666404fcf97698abeb019) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe 19:14:28.0045 4780 stllssvr - ok 19:14:28.0083 4780 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 19:14:28.0085 4780 swenum - ok 19:14:28.0192 4780 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll 19:14:28.0215 4780 swprv - ok 19:14:28.0291 4780 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 19:14:28.0294 4780 Symc8xx - ok 19:14:28.0320 4780 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 19:14:28.0322 4780 Sym_hi - ok 19:14:28.0364 4780 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 19:14:28.0367 4780 Sym_u3 - ok 19:14:28.0481 4780 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll 19:14:28.0512 4780 SysMain - ok 19:14:28.0554 4780 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll 19:14:28.0570 4780 TabletInputService - ok 19:14:28.0784 4780 TabletServicePen (dad1a4d96291139c0f834b138320e475) C:\Windows\system32\Pen_Tablet.exe 19:14:28.0833 4780 TabletServicePen - ok 19:14:29.0425 4780 TabletServiceWacom (43a2b78a3235c3aeace2d6ea70cef2a8) C:\Windows\system32\Wacom_Tablet.exe 19:14:29.0555 4780 TabletServiceWacom - ok 19:14:29.0740 4780 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll 19:14:29.0756 4780 TapiSrv - ok 19:14:29.0802 4780 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll 19:14:29.0819 4780 TBS - ok 19:14:30.0020 4780 Tcpip (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys 19:14:30.0053 4780 Tcpip - ok 19:14:30.0081 4780 Tcpip6 (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys 19:14:30.0095 4780 Tcpip6 - ok 19:14:30.0134 4780 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 19:14:30.0136 4780 tcpipreg - ok 19:14:30.0185 4780 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 19:14:30.0187 4780 TDPIPE - ok 19:14:30.0217 4780 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 19:14:30.0220 4780 TDTCP - ok 19:14:30.0275 4780 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 19:14:30.0291 4780 tdx - ok 19:14:30.0354 4780 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 19:14:30.0357 4780 TermDD - ok 19:14:30.0444 4780 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll 19:14:30.0482 4780 TermService - ok 19:14:30.0556 4780 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll 19:14:30.0563 4780 Themes - ok 19:14:30.0604 4780 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 19:14:30.0608 4780 THREADORDER - ok 19:14:30.0655 4780 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll 19:14:30.0670 4780 TrkWks - ok 19:14:30.0740 4780 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe 19:14:30.0742 4780 TrustedInstaller - ok 19:14:30.0778 4780 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 19:14:30.0781 4780 tssecsrv - ok 19:14:30.0798 4780 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 19:14:30.0800 4780 tunmp - ok 19:14:30.0844 4780 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 19:14:30.0846 4780 tunnel - ok 19:14:30.0883 4780 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 19:14:30.0886 4780 uagp35 - ok 19:14:30.0950 4780 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 19:14:30.0962 4780 udfs - ok 19:14:30.0993 4780 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe 19:14:30.0999 4780 UI0Detect - ok 19:14:31.0035 4780 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 19:14:31.0038 4780 uliagpkx - ok 19:14:31.0080 4780 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 19:14:31.0115 4780 uliahci - ok 19:14:31.0163 4780 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 19:14:31.0176 4780 UlSata - ok 19:14:31.0239 4780 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 19:14:31.0243 4780 ulsata2 - ok 19:14:31.0291 4780 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 19:14:31.0294 4780 umbus - ok 19:14:31.0337 4780 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll 19:14:31.0359 4780 upnphost - ok 19:14:31.0402 4780 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\Windows\system32\Drivers\usbaapl.sys 19:14:31.0405 4780 USBAAPL - ok 19:14:31.0486 4780 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 19:14:31.0490 4780 usbaudio - ok 19:14:31.0574 4780 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 19:14:31.0590 4780 usbccgp - ok 19:14:31.0623 4780 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 19:14:31.0626 4780 usbcir - ok 19:14:31.0675 4780 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 19:14:31.0678 4780 usbehci - ok 19:14:31.0714 4780 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 19:14:31.0731 4780 usbhub - ok 19:14:31.0758 4780 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 19:14:31.0760 4780 usbohci - ok 19:14:31.0786 4780 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 19:14:31.0788 4780 usbprint - ok 19:14:31.0841 4780 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:14:31.0844 4780 USBSTOR - ok 19:14:31.0870 4780 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 19:14:31.0873 4780 usbuhci - ok 19:14:31.0920 4780 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll 19:14:31.0925 4780 UxSms - ok 19:14:32.0043 4780 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe 19:14:32.0067 4780 vds - ok 19:14:32.0099 4780 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 19:14:32.0101 4780 vga - ok 19:14:32.0112 4780 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 19:14:32.0115 4780 VgaSave - ok 19:14:32.0156 4780 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 19:14:32.0159 4780 viaagp - ok 19:14:32.0190 4780 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 19:14:32.0193 4780 ViaC7 - ok 19:14:32.0222 4780 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 19:14:32.0233 4780 viaide - ok 19:14:32.0280 4780 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 19:14:32.0283 4780 volmgr - ok 19:14:32.0353 4780 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 19:14:32.0373 4780 volmgrx - ok 19:14:32.0459 4780 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 19:14:32.0473 4780 volsnap - ok 19:14:32.0516 4780 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 19:14:32.0534 4780 vsmraid - ok 19:14:32.0711 4780 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe 19:14:32.0756 4780 VSS - ok 19:14:32.0828 4780 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll 19:14:32.0849 4780 W32Time - ok 19:14:32.0935 4780 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\Windows\system32\DRIVERS\wacommousefilter.sys 19:14:32.0938 4780 wacommousefilter - ok 19:14:32.0985 4780 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 19:14:32.0988 4780 WacomPen - ok 19:14:33.0003 4780 wacomvhid - ok 19:14:33.0077 4780 WacomVKHid (889459833432b161cb99cfdf84a1a9bb) C:\Windows\system32\DRIVERS\WacomVKHid.sys 19:14:33.0079 4780 WacomVKHid - ok 19:14:33.0131 4780 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 19:14:33.0134 4780 Wanarp - ok 19:14:33.0146 4780 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 19:14:33.0147 4780 Wanarpv6 - ok 19:14:33.0205 4780 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll 19:14:33.0221 4780 wcncsvc - ok 19:14:33.0295 4780 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll 19:14:33.0301 4780 WcsPlugInService - ok 19:14:33.0330 4780 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 19:14:33.0333 4780 Wd - ok 19:14:33.0412 4780 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 19:14:33.0438 4780 Wdf01000 - ok 19:14:33.0470 4780 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 19:14:33.0485 4780 WdiServiceHost - ok 19:14:33.0491 4780 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 19:14:33.0503 4780 WdiSystemHost - ok 19:14:33.0568 4780 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll 19:14:33.0584 4780 WebClient - ok 19:14:33.0639 4780 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll 19:14:33.0714 4780 Wecsvc - ok 19:14:33.0738 4780 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll 19:14:33.0755 4780 wercplsupport - ok 19:14:33.0801 4780 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll 19:14:33.0811 4780 WerSvc - ok 19:14:33.0928 4780 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll 19:14:33.0939 4780 WinDefend - ok 19:14:33.0950 4780 WinHttpAutoProxySvc - ok 19:14:34.0037 4780 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll 19:14:34.0045 4780 Winmgmt - ok 19:14:34.0232 4780 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll 19:14:34.0322 4780 WinRM - ok 19:14:34.0435 4780 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll 19:14:34.0453 4780 Wlansvc - ok 19:14:34.0460 4780 wltrysvc - ok 19:14:34.0531 4780 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 19:14:34.0533 4780 WmiAcpi - ok 19:14:34.0601 4780 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe 19:14:34.0611 4780 wmiApSrv - ok 19:14:34.0976 4780 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe 19:14:35.0008 4780 WMPNetworkSvc - ok 19:14:35.0039 4780 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll 19:14:35.0048 4780 WPCSvc - ok 19:14:35.0110 4780 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll 19:14:35.0125 4780 WPDBusEnum - ok 19:14:35.0221 4780 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 19:14:35.0224 4780 WpdUsb - ok 19:14:35.0475 4780 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 19:14:35.0499 4780 WPFFontCache_v0400 - ok 19:14:35.0541 4780 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 19:14:35.0543 4780 ws2ifsl - ok 19:14:35.0585 4780 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\system32\wscsvc.dll 19:14:35.0602 4780 wscsvc - ok 19:14:35.0609 4780 WSearch - ok 19:14:35.0902 4780 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll 19:14:35.0958 4780 wuauserv - ok 19:14:36.0138 4780 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 19:14:36.0142 4780 WUDFRd - ok 19:14:36.0186 4780 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll 19:14:36.0203 4780 wudfsvc - ok 19:14:36.0246 4780 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 19:14:36.0671 4780 \Device\Harddisk0\DR0 - ok 19:14:36.0697 4780 Boot (0x1200) (6f7539ea63a14f7c512e56519b2fbaef) \Device\Harddisk0\DR0\Partition0 19:14:36.0699 4780 \Device\Harddisk0\DR0\Partition0 - ok 19:14:36.0705 4780 Boot (0x1200) (a3ba0951f4de49168eadd53c1dd2aa2b) \Device\Harddisk0\DR0\Partition1 19:14:36.0709 4780 \Device\Harddisk0\DR0\Partition1 - ok 19:14:36.0711 4780 ============================================================ 19:14:36.0711 4780 Scan finished 19:14:36.0711 4780 ============================================================ 19:14:36.0831 0472 Detected object count: 0 19:14:36.0831 0472 Actual detected object count: 0
Okay,
This is my Malwarebytes report:


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.15.10

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Cazzimodo :: CHIKEETO-PC [administrator]

16/07/2012 00:30:34
mbam-log-2012-07-16 (00-30-34).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206832
Time elapsed: 7 minute(s), 43 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



and this is the ESET scan report:


C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5ed43550-3c0b0867 probably a variant of Java/Exploit.Agent.NBU trojan
C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\41e8aee3-3d06b624 a variant of Java/Exploit.CVE-2009-2843.B trojan
C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\63dde168-773bd572 a variant of Java/Rowindal.A trojan
C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4084a7b0-7d4640e6 multiple threats
C:\Users\Cazzimodo\Downloads\MsgPlusLive-470.exe a variant of Win32/Adware.CiDHelp application
C:\Users\Cazzimodo\Downloads\snapshot13.exe a variant of MSIL/Injector.JB trojan
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :files
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5ed43550-3c0b0867 
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\41e8aee3-3d06b624 
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\63dde168-773bd572 
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4084a7b0-7d4640e6 
    C:\Users\Cazzimodo\Downloads\MsgPlusLive-470.exe 
    C:\Users\Cazzimodo\Downloads\snapshot13.exe
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )



Any more problems?
Sorry, ignore that, thought we used OTL in previous thread.Do this instead.


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5ed43550-3c0b0867
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\41e8aee3-3d06b624
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\63dde168-773bd572
    C:\Users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4084a7b0-7d4640e6
    C:\Users\Cazzimodo\Downloads\MsgPlusLive-470.exe
    C:\Users\Cazzimodo\Downloads\snapshot13.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Combofix results:

ComboFix 12-07-12.02 - Cazzimodo 16/07/2012 20:22:46.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.1129 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Cazzimodo\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5ed43550-3c0b0867"
"c:\users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\41e8aee3-3d06b624"
"c:\users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\63dde168-773bd572"
"c:\users\Cazzimodo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\4084a7b0-7d4640e6"
"c:\users\Cazzimodo\Downloads\MsgPlusLive-470.exe"
"c:\users\Cazzimodo\Downloads\snapshot13.exe"
.
.
((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 )))))))))))))))))))))))))))))))
.
.
2012-07-16 19:34 . 2012-07-16 19:34 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-15 23:41 . 2012-07-15 23:41 ——– d—–w- c:\program files\ESET
2012-07-15 23:26 . 2012-07-15 23:26 ——– d—–w- c:\users\Cazzimodo\AppData\Roaming\Malwarebytes
2012-07-15 23:25 . 2012-07-15 23:25 ——– d—–w- c:\programdata\Malwarebytes
2012-07-15 23:25 . 2012-07-15 23:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-07-15 23:25 . 2012-07-03 12:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-14 16:31 . 2012-07-16 19:34 ——– d—–w- c:\users\Cazzimodo\AppData\Local\temp
2012-07-13 14:39 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{706ED08E-829F-43C8-91C9-16331763E815}\mpengine.dll
2012-07-12 02:10 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 15:36 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 15:36 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 15:36 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 15:35 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 15:35 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 15:35 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-06-30 10:33 . 2012-06-30 10:33 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-06-30 10:33 . 2012-07-04 20:48 829920 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-06-30 10:33 . 2012-07-04 20:48 2042848 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-06-22 18:44 . 2012-07-04 20:48 16864 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2012-06-22 08:49 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-22 08:49 . 2012-03-01 14:46 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-06-22 08:49 . 2012-03-01 14:46 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-06-22 08:49 . 2012-02-29 14:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-06-22 08:49 . 2012-02-29 13:44 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-06-22 08:49 . 2012-02-29 13:41 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-06-22 03:39 . 2012-06-22 03:39 ——– d—–w- c:\program files\Windows Portable Devices
2012-06-22 03:07 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-06-22 03:07 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-06-22 03:07 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-06-22 02:56 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-22 02:56 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-22 02:56 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-22 02:56 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-22 02:55 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-22 02:55 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-22 02:55 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-22 02:54 . 2012-06-02 14:19 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-22 02:54 . 2012-06-02 14:12 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-22 02:51 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-22 02:51 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-06-22 02:51 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-22 02:51 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-22 02:38 . 2012-06-22 02:38 307200 —-a-w- c:\program files\Internet Explorer\iediagcmd.exe
2012-06-22 02:38 . 2012-06-22 02:38 161792 —-a-w- c:\windows\system32\msls31.dll
2012-06-22 02:38 . 2012-06-22 02:38 107008 —-a-w- c:\program files\Internet Explorer\iecleanup.exe
2012-06-22 02:36 . 2012-06-22 02:36 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2012-06-22 02:36 . 2012-06-22 02:36 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2012-06-22 02:36 . 2012-06-22 02:36 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2012-06-22 02:36 . 2012-06-22 02:36 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2012-06-22 02:36 . 2012-06-22 02:36 98816 —-a-w- c:\windows\system32\mfps.dll
2012-06-22 02:36 . 2012-06-22 02:36 2873344 —-a-w- c:\windows\system32\mf.dll
2012-06-22 02:34 . 2012-06-22 02:34 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-06-22 02:34 . 2012-06-22 02:34 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-06-22 02:34 . 2012-06-22 02:34 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-06-22 02:34 . 2012-06-22 02:34 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-06-22 02:34 . 2012-06-22 02:34 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-06-22 02:34 . 2012-06-22 02:34 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-06-22 02:34 . 2012-06-22 02:34 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-21 07:58 . 2012-04-23 16:00 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-21 07:58 . 2012-04-23 16:00 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-21 07:58 . 2012-04-23 16:00 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-21 07:58 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2012-06-21 07:58 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2012-06-21 07:58 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2012-06-21 07:58 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2012-06-21 07:58 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-06-21 07:58 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-06-21 07:57 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-06-21 07:57 . 2012-02-01 15:11 1218048 —-a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-21 07:57 . 2012-02-01 15:10 964608 —-a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-21 07:57 . 2012-02-01 15:10 1404928 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2012-06-21 07:57 . 2012-02-01 15:10 983040 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-21 07:57 . 2012-02-01 15:10 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-21 07:57 . 2012-02-01 13:58 47104 —-a-w- c:\program files\Windows Journal\PDIALOG.exe
2012-06-21 07:57 . 2012-03-30 12:39 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-21 07:57 . 2012-03-20 23:28 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-21 07:57 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-06-21 07:57 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-06-21 07:56 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-06-21 07:56 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-06-21 07:56 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-06-21 07:56 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-06-21 07:56 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-06-21 07:56 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
2012-06-21 07:56 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2012-06-21 07:56 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-06-21 07:56 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2012-06-21 07:56 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-06-21 07:56 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2012-06-21 07:56 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2012-06-21 07:55 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-06-21 07:55 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-06-21 07:55 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-06-21 07:55 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-06-21 07:55 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-21 07:55 . 2012-05-01 14:03 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-21 07:55 . 2012-04-03 08:16 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-06-21 07:55 . 2012-04-03 08:16 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-21 07:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2012-06-21 07:41 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-06-21 07:32 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\ca-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\eu-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\vi-VN
2012-06-20 10:18 . 2012-07-02 17:02 ——– d—–w- c:\users\Cazzimodo\AppData\Local\ilrryeuh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-22 02:34 . 2012-06-22 02:34 4096 —-a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-03-27 04:09 . 2012-03-27 04:09 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll
2012-03-27 04:09 . 2012-03-27 04:09 421736 —-a-w- c:\program files\iTunesHelper.exe
2012-03-27 04:09 . 2012-03-27 04:09 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll
2012-03-27 04:09 . 2012-03-27 04:09 156520 —-a-w- c:\program files\iTunesHelper.dll
2012-03-27 04:09 . 2012-03-27 04:09 402792 —-a-w- c:\program files\iTunesAdmin.dll
2012-03-27 04:09 . 2012-03-27 04:09 9777000 —-a-w- c:\program files\iTunes.exe
2012-03-27 04:09 . 2012-03-27 04:09 21006696 —-a-w- c:\program files\iTunes.dll
2012-03-27 04:09 . 2012-03-27 04:09 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll
2012-03-27 04:09 . 2012-03-27 04:09 649576 —-a-w- c:\program files\iPodUpdaterExt.dll
2012-03-27 04:09 . 2012-03-27 04:09 3029528 —-a-w- c:\program files\gnsdk_dsp.dll
2012-03-27 04:09 . 2012-03-27 04:09 281112 —-a-w- c:\program files\gnsdk_submit.dll
2012-03-27 04:09 . 2012-03-27 04:09 240152 —-a-w- c:\program files\gnsdk_musicid.dll
2012-03-06 19:44 . 2012-03-06 19:44 112488 —-a-w- c:\program files\ITDetector.ocx
2012-07-04 20:48 . 2012-06-30 10:33 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Spotify Web Helper"="c:\users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe" [2012-05-08 932528]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-08-25 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunesHelper.exe" [2012-03-27 421736]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Cazzimodo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-13 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-18 17:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 15772727
*Deregistered* - 15772727
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 17:38]
.
2012-07-16 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 18:56]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000Core.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
2012-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000UA.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Cazzimodo\AppData\Roaming\Mozilla\Firefox\Profiles\mujlpshm.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D&mid=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds=AVG&v=10.0.0.7&lang=us&pr=fr&d=2011-12-10%2014%3A33%3A45&sap=ku&q=
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-16 20:34
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\CAZZIM~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
Completion time: 2012-07-16 20:39:08
ComboFix-quarantined-files.txt 2012-07-16 19:38
ComboFix2.txt 2012-07-14 16:31
.
Pre-Run: 16,089,182,208 bytes free
Post-Run: 15,958,528,000 bytes free
.
- - End Of File - - BF1B70CB209D66A26B82B9E0E1B02632
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean











Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI