This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ads and music playing in background

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

I've been having this problem where adverts and music would randomly start playing in the background of my laptop, but will only come on if I am connected to the internet. The ads and music will only be their sound and no image, and there is no prediction as to when they will start playing. I can go hours with nothing coming up, but then I get periods of different adverts playing consistently for hours also.

The problem seemed to coincide with when Adobe Flash player was due an update and my McAfee firewall stopped something gaining access to my laptop. I assumed it was Adobe trying to get access and so I didn't block it, but soon afterwards the issues started occurring.

I have tried a few things to rid of the problem myself including installing the free version of AVG and constantly running scans, running CCleaner, and installing the trial of Malwarebytes (which didnt find anything). I've also run TDSSkiller, changed parameters to check box of "Detect TDLFS file system" but it found nothing (unless I did something wrong).

Initially when I started having the problems whenever I attempted to go onto an anti-virus/ anti-malware site or to download these I would be redirected from Google. However I managed to install and AVG and use CCleaner and that problem has gone after running these programs.

The following is my results from HijackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:53:42, on 10/08/2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\PROGRA~2\mcafee\SITEAD~1\saui.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Users\Mitesh\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.search.yahoo.com/search?fr=mcafee&p=%s%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120626012128.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe /hideGUI"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - http://support.euro.dell.com/systemprofile…lSystemLite.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: dlbt_device - Unknown owner - C:\Windows\system32\dlbtcoms.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13546 bytes


Thanks for your help in advance,

mistry91
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi there,

Thanks for your fast reply. Here is the information as requested:

DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 10.4.0
Run by [removed] at 3:10:44 on 2012-08-10
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.4090.1856 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\system32\dlbtcoms.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe
C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe
C:\Windows\splwow64.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\PROGRA~2\mcafee\SITEAD~1\saui.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe
\\.\globalroot\systemroot\Installer\{479469d3-8ccd-754f-0bb2-1225aba89060}\U
C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=%s%s
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120626012128.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe /hideGUI"
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-00104-0001-0004-ABCDEFFEDCBC}
IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{052AEAF6-FFD8-412D-ACFA-B4F5C9BC5DCD} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{1E7ECEFA-15EC-42CA-BA6F-BF4E92731CCB} : DhcpNameServer = [removed] [removed]
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll
BHO-X64: AVG Do Not Track - No File
BHO-X64: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120626012128.dll
BHO-X64: scriptproxy - No File
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe /hideGUI"
mRun-x64: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Mitesh\AppData\Roaming\Mozilla\Firefox\Profiles\gvhso28y.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p;=
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: C:\Users\Mitesh\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\system32\DRIVERS\avgidsha.sys –> C:\Windows\system32\DRIVERS\avgidsha.sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys –> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys –> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys –> C:\Windows\system32\drivers\PCTCore64.sys [?]
R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys –> C:\Windows\system32\drivers\pctDS64.sys [?]
R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\system32\drivers\pctEFA64.sys –> C:\Windows\system32\drivers\pctEFA64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys –> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys –> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys –> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys –> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys –> C:\Windows\system32\drivers\mfewfpk.sys [?]
R1 PCTSD;PC Tools Spyware Doctor Driver;C:\Windows\system32\Drivers\PCTSD64.sys –> C:\Windows\system32\Drivers\PCTSD64.sys [?]
R2 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};{1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7};C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl [2010-2-27 32240]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-26 655944]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-7-8 249936]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-7-8 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-7-8 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2010-7-8 199272]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2010-7-8 210584]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-7-8 162192]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\avgidsdrivera.sys –> C:\Windows\system32\DRIVERS\avgidsdrivera.sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\avgidsfiltera.sys –> C:\Windows\system32\DRIVERS\avgidsfiltera.sys [?]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys –> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys –> C:\Windows\system32\drivers\cfwids.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys –> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys –> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys –> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys –> C:\Windows\system32\drivers\mfefirek.sys [?]
R3 NETw5v64;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys –> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
R3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;C:\Windows\system32\DRIVERS\OA008Ufd.sys –> C:\Windows\system32\DRIVERS\OA008Ufd.sys [?]
R3 OA008Vid;Creative Camera OA008 Function Driver;C:\Windows\system32\DRIVERS\OA008Vid.sys –> C:\Windows\system32\DRIVERS\OA008Vid.sys [?]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-7-4 5160568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-3 250056]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys –> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-10 113120]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-21 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-2-28 93184]
S4 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [2010-2-27 606736]
.
=============== Created Last 30 ================
.
2012-08-07 21:18:47 116016 —-a-w- C:\Windows\System32\drivers\89654959.sys
2012-07-28 17:27:30 35712 —-a-w- C:\Windows\SysWow64\drivers\BlackBox.sys
2012-07-26 20:38:41 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Malwarebytes
2012-07-26 20:38:24 ——– d—–w- C:\ProgramData\Malwarebytes
2012-07-26 20:38:23 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-26 20:38:23 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-26 01:04:14 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\AVG
2012-07-25 23:51:33 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\AVG2012
2012-07-25 23:50:37 ——– d—–w- C:\Windows\SysWow64\drivers\AVG
2012-07-25 23:49:40 ——– d–h–w- C:\$AVG
2012-07-25 23:49:40 ——– d—–w- C:\Windows\System32\drivers\AVG
2012-07-25 23:49:40 ——– d—–w- C:\ProgramData\AVG2012
2012-07-25 23:47:19 ——– d—–w- C:\Program Files (x86)\AVG
2012-07-25 23:40:04 ——– d–h–w- C:\ProgramData\Common Files
2012-07-25 23:40:04 ——– d—–w- C:\ProgramData\MFAData
2012-07-25 21:34:41 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Nico Mak Computing
2012-07-25 21:34:38 18760 —-a-w- C:\Windows\System32\roboot64.exe
2012-07-25 21:34:37 ——– d—–w- C:\Program Files (x86)\WinZip Registry Optimizer
2012-07-25 20:46:31 14808 —-a-w- C:\Windows\System32\drivers\pctBTFix64.sys
2012-07-25 20:46:29 92928 —-a-w- C:\Windows\System32\drivers\pctplsg64.sys
2012-07-25 20:46:24 ——– d—–w- C:\Program Files (x86)\PC Tools
2012-07-25 20:40:59 453896 —-a-w- C:\Windows\System32\drivers\pctDS64.sys
2012-07-25 20:40:59 1096176 —-a-w- C:\Windows\System32\drivers\pctEFA64.sys
2012-07-25 20:40:57 426616 —-a-w- C:\Windows\System32\drivers\PCTCore64.sys
2012-07-25 20:40:56 251560 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys
2012-07-25 20:40:56 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools
2012-07-25 20:40:09 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\TestApp
2012-07-25 20:40:09 ——– d—–w- C:\ProgramData\PC Tools
2012-07-24 21:47:30 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Ridy
2012-07-24 21:47:30 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Qyodza
2012-07-24 21:47:30 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Ewbay
2012-07-24 06:30:55 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Tohevy
2012-07-24 06:30:55 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Sali
2012-07-24 06:30:55 ——– d—–w- C:\Users\Mitesh\AppData\Roaming\Pyomfo
2012-07-20 14:45:03 9133488 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C6598B45-B758-45A8-9D08-9A46E3D8C056}\mpengine.dll
.
==================== Find3M ====================
.
2012-08-02 22:15:22 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-02 22:15:22 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-31 11:25:12 279656 ——w- C:\Windows\System32\MpSigStub.exe
2012-05-23 19:18:12 772552 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-05-23 19:18:12 687560 —-a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 3:11:39.18 ===============

Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 27/02/2010 19:25:43
System Uptime: 09/08/2012 19:45:24 (8 hours ago)
.
Motherboard: Dell Inc. | | 0C234M
Processor: Intel® Core™2 Duo CPU P8600 @ 2.40GHz | U2E1 | 2401/1066mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 451 GiB total, 248.527 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 5.389 GiB free.
E: is CDROM (UDF)
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Base System Device
Device ID: PCI\VEN_1180&DEV;_0592&SUBSYS;_02BE1028&REV;_12\4&31FC8C23&0&0BF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV;_0592&SUBSYS;_02BE1028&REV;_12\4&31FC8C23&0&0BF0
Service:
.
Class GUID:
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV;_2930&SUBSYS;_02BE1028&REV;_03\3&11583659&0&FB;
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV;_2930&SUBSYS;_02BE1028&REV;_03\3&11583659&0&FB;
Service:
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description:
Device ID: ROOT\IMAGE\0000
Manufacturer: Creative Technology Ltd.
Name: Creative Live! Camera
PNP Device ID: ROOT\IMAGE\0000
Service:
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
AVG PC Tuneup
Bejeweled 3
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CCleaner
Dell Dock
Dell Resource CD
Dell Webcam Central
DivX Setup
Facebook Plug-In
Garmin Lifetime Updater
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Java Auto Updater
Java™ 7 Update 4
JavaFX 2.1.0
Live! Cam Avatar Creator
Malwarebytes Anti-Malware version 1.62.0.1300
McAfee Security Scan Plus
McAfee SecurityCenter
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 14.0.1 (x86 en-GB)
Mozilla Maintenance Service
PC Tools Spyware Doctor 9.0
PowerDVD
QuickTime
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
Skins
Skype™ 5.10
Spotify
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195
Visual Studio 2008 x64 Redistributables
.
==== Event Viewer Messages From Past Week ========
.
07/08/2012 22:01:05, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0022FB982A28. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
06/08/2012 13:34:14, Error: Service Control Manager [7022] - The McAfee Network Agent service hung on starting.
06/08/2012 13:33:35, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Skype Updater service to connect.
06/08/2012 13:33:35, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service SkypeUpdate with arguments "/ComService" in order to run the server: {CC957078-B838-47C4-A7CF-626E7A82FC58}
06/08/2012 13:27:51, Error: EventLog [6008] - The previous system shutdown at 13:19:55 on 06/08/2012 was unexpected.
06/08/2012 02:01:59, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the iPod Service service to connect.
06/08/2012 02:01:59, Error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
06/08/2012 02:01:59, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
06/08/2012 01:57:23, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.81 for the Network Card with network address 0022FB982A28 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
03/08/2012 18:59:02, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
03/08/2012 06:26:37, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
03/08/2012 06:26:37, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Security with the following error: Access is denied.
03/08/2012 06:26:37, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
03/08/2012 06:26:37, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
03/08/2012 06:24:57, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
.
==== End Of File ===========================


And here is the aswMBR log:


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-10 03:20:28
—————————–
03:20:28.305 OS Version: Windows x64 6.0.6001 Service Pack 1
03:20:28.305 Number of processors: 2 586 0x170A
03:20:28.306 ComputerName: MITESH-PC UserName: Mitesh
03:20:33.501 Initialize success
03:24:44.543 AVAST engine defs: 12080901
03:26:17.798 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
03:26:17.800 Disk 0 Vendor: SAMSUNG_HM500JI 2AC101C4 Size: 476940MB BusType: 3
03:26:17.828 Disk 0 MBR read successfully
03:26:17.831 Disk 0 MBR scan
03:26:17.837 Disk 0 Windows VISTA default MBR code
03:26:17.840 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
03:26:17.891 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 15000 MB offset 80325
03:26:17.913 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 461899 MB offset 30800325
03:26:17.972 Disk 0 scanning C:\Windows\system32\drivers
03:26:39.993 Service scanning
03:27:11.907 Modules scanning
03:27:11.908 Disk 0 trace - called modules:
03:27:11.937 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore64.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
03:27:11.939 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004ee5300]
03:27:11.940 3 CLASSPNP.SYS[fffffa60012a2b3a] -> nt!IofCallDriver -> [0xfffffa8004ee0250]
03:27:11.940 5 PCTCore64.sys[fffffa6000b85720] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004b813a0]
03:27:16.957 AVAST engine scan C:\Windows
03:27:36.252 AVAST engine scan C:\Windows\system32
03:32:30.909 AVAST engine scan C:\Windows\system32\drivers
03:32:50.405 AVAST engine scan C:\Users\Mitesh
03:41:22.350 AVAST engine scan C:\ProgramData
03:45:38.333 Scan finished successfully
03:49:11.495 Disk 0 MBR has been saved successfully to "C:\Users\Mitesh\Desktop\MBR.dat"
03:49:11.501 The log file has been saved successfully to "C:\Users\Mitesh\Desktop\aswMBR.txt"


Thank you again Jeff :)

Mistry91
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Hi Jeff, That's not good news isn't it :/ I've disabled my antivirus/ antimalware software, downloaded ComboFix, and ran it as administrator, but it runs and then as the progress bar nears completion it just closes and doesnt leave me with a report. I tried downloading it again and running it, but the same thing happened. In addition there wasnt any "prompts" to follow. I just ran as administrator and then it started scanning before closing itself as it neared completion. Thanks for your help btw, mitesh91
Hi,

Delete your copy of ComboFix.

Download Combofix from any of the links below but rename it to Vageta.com before saving it to your desktop.

Link 1
Link 2


==================================

Right-click and Run as Administrator on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Same thing happened again… And after clicking download from the second link, it redirected me to a page with a whole wall of random characters, letters and symbols. The only difference is that while running it came up with the following error message: "Error opening file for writing: C:\32788R22FWJFW\License\iexplore.exe Click Abort to stop the installation, Retry to try again, Ignore to skip this file" I clicked retry but nothing happened, so i clicked ignore but it just did what happened the first time and closed itself before the completion bar reached the end. mistry91
Hi,

Ok thanks for letting me know.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Hi Jeff, This is the report: 16:43:16.0182 6804 TDSS rootkit removing tool [removed] Jul 24 2012 13:16:32 16:43:16.0361 6804 ============================================================ 16:43:16.0361 6804 Current date / time: 2012/08/10 16:43:16.0361 16:43:16.0361 6804 SystemInfo: 16:43:16.0361 6804 16:43:16.0361 6804 OS Version: 6.0.6001 ServicePack: 1.0 16:43:16.0361 6804 Product type: Workstation 16:43:16.0361 6804 ComputerName: MITESH-PC 16:43:16.0361 6804 UserName: Mitesh 16:43:16.0361 6804 Windows directory: C:\Windows 16:43:16.0361 6804 System windows directory: C:\Windows 16:43:16.0361 6804 Running under WOW64 16:43:16.0361 6804 Processor architecture: Intel x64 16:43:16.0361 6804 Number of processors: 2 16:43:16.0361 6804 Page size: 0x1000 16:43:16.0361 6804 Boot type: Normal boot 16:43:16.0362 6804 ============================================================ 16:43:17.0488 6804 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:43:17.0498 6804 ============================================================ 16:43:17.0498 6804 \Device\Harddisk0\DR0: 16:43:17.0498 6804 MBR partitions: 16:43:17.0498 6804 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x1D4C000 16:43:17.0498 6804 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D5F9C5, BlocksNum 0x38625E6B 16:43:17.0498 6804 ============================================================ 16:43:17.0538 6804 C: <-> \Device\Harddisk0\DR0\Partition1 16:43:17.0568 6804 D: <-> \Device\Harddisk0\DR0\Partition0 16:43:17.0568 6804 ============================================================ 16:43:17.0568 6804 Initialize success 16:43:17.0568 6804 ============================================================ 16:43:23.0412 4392 ============================================================ 16:43:23.0412 4392 Scan started 16:43:23.0412 4392 Mode: Manual; TDLFS; 16:43:23.0412 4392 ============================================================ 16:43:24.0672 4392 ACPI (8c99ed256a889d647935a97c543b7b85) C:\Windows\system32\drivers\acpi.sys 16:43:24.0672 4392 ACPI - ok 16:43:24.0812 4392 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 16:43:24.0812 4392 AdobeARMservice - ok 16:43:24.0972 4392 AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 16:43:24.0982 4392 AdobeFlashPlayerUpdateSvc - ok 16:43:25.0052 4392 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys 16:43:25.0062 4392 adp94xx - ok 16:43:25.0142 4392 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys 16:43:25.0152 4392 adpahci - ok 16:43:25.0163 4392 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys 16:43:25.0165 4392 adpu160m - ok 16:43:25.0230 4392 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys 16:43:25.0234 4392 adpu320 - ok 16:43:25.0276 4392 AeLookupSvc (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll 16:43:25.0277 4392 AeLookupSvc - ok 16:43:25.0364 4392 AFD (9bb97042fa331a0fb4bdd98b9280a50a) C:\Windows\system32\drivers\afd.sys 16:43:25.0370 4392 AFD - ok 16:43:25.0426 4392 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys 16:43:25.0428 4392 agp440 - ok 16:43:25.0494 4392 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys 16:43:25.0497 4392 aic78xx - ok 16:43:25.0533 4392 ALG (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe 16:43:25.0535 4392 ALG - ok 16:43:25.0575 4392 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys 16:43:25.0576 4392 aliide - ok 16:43:25.0592 4392 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys 16:43:25.0594 4392 amdide - ok 16:43:25.0646 4392 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys 16:43:25.0648 4392 AmdK8 - ok 16:43:25.0702 4392 Appinfo (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll 16:43:25.0704 4392 Appinfo - ok 16:43:25.0839 4392 Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 16:43:25.0840 4392 Apple Mobile Device - ok 16:43:25.0888 4392 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys 16:43:25.0891 4392 arc - ok 16:43:25.0952 4392 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys 16:43:25.0954 4392 arcsas - ok 16:43:26.0002 4392 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys 16:43:26.0004 4392 AsyncMac - ok 16:43:26.0009 4392 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys 16:43:26.0010 4392 atapi - ok 16:43:26.0134 4392 Ati External Event Utility (00dace1d9a0da60215022c6b1fac1673) C:\Windows\system32\Ati2evxx.exe 16:43:26.0140 4392 Ati External Event Utility - ok 16:43:26.0683 4392 atikmdag (cef278088637401f07a0064b0b900a32) C:\Windows\system32\DRIVERS\atikmdag.sys 16:43:26.0759 4392 atikmdag - ok 16:43:26.0922 4392 AudioEndpointBuilder (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll 16:43:26.0925 4392 AudioEndpointBuilder - ok 16:43:26.0931 4392 AudioSrv (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll 16:43:26.0934 4392 AudioSrv - ok 16:43:27.0463 4392 AVGIDSAgent (d67719bcfde5798f5c30d14efed3bcaf) C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe 16:43:27.0493 4392 AVGIDSAgent - ok 16:43:27.0683 4392 AVGIDSDriver (1b2e9fcdc26dc7c81d4131430e2dc936) C:\Windows\system32\DRIVERS\avgidsdrivera.sys 16:43:27.0683 4392 AVGIDSDriver - ok 16:43:27.0693 4392 AVGIDSFilter (0f293406f64b48d5d2f0d3a1117f3a83) C:\Windows\system32\DRIVERS\avgidsfiltera.sys 16:43:27.0693 4392 AVGIDSFilter - ok 16:43:27.0713 4392 AVGIDSHA (cffc3a4a638f462e0561cb368b9a7a3a) C:\Windows\system32\DRIVERS\avgidsha.sys 16:43:27.0713 4392 AVGIDSHA - ok 16:43:27.0813 4392 Avgldx64 (59955b4c288dd2a8b9fd2cd5158355c5) C:\Windows\system32\DRIVERS\avgldx64.sys 16:43:27.0823 4392 Avgldx64 - ok 16:43:27.0883 4392 Avgmfx64 (a6aec362aae5e2dda7445e7690cb0f33) C:\Windows\system32\DRIVERS\avgmfx64.sys 16:43:27.0883 4392 Avgmfx64 - ok 16:43:27.0963 4392 Avgrkx64 (645c7f0a0e39758a0024a9b1748273c0) C:\Windows\system32\DRIVERS\avgrkx64.sys 16:43:27.0963 4392 Avgrkx64 - ok 16:43:28.0073 4392 Avgtdia (1bee674ad792b1c63bb0dac5fa724b23) C:\Windows\system32\DRIVERS\avgtdia.sys 16:43:28.0073 4392 Avgtdia - ok 16:43:28.0243 4392 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe 16:43:28.0243 4392 avgwd - ok 16:43:28.0323 4392 BFE (bc4737aaffa5964e4f8827c9b8c0eb8e) C:\Windows\System32\bfe.dll 16:43:28.0323 4392 BFE - ok 16:43:28.0333 4392 BlackBox - ok 16:43:28.0373 4392 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys 16:43:28.0373 4392 blbdrive - ok 16:43:28.0493 4392 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe 16:43:28.0493 4392 Bonjour Service - ok 16:43:28.0573 4392 bowser (f0f035fcec3554cc1b70c5611bd87951) C:\Windows\system32\DRIVERS\bowser.sys 16:43:28.0573 4392 bowser - ok 16:43:28.0623 4392 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys 16:43:28.0633 4392 BrFiltLo - ok 16:43:28.0653 4392 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys 16:43:28.0653 4392 BrFiltUp - ok 16:43:28.0713 4392 Browser (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll 16:43:28.0713 4392 Browser - ok 16:43:28.0743 4392 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys 16:43:28.0753 4392 Brserid - ok 16:43:28.0763 4392 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys 16:43:28.0773 4392 BrSerWdm - ok 16:43:28.0793 4392 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys 16:43:28.0793 4392 BrUsbMdm - ok 16:43:28.0803 4392 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys 16:43:28.0813 4392 BrUsbSer - ok 16:43:28.0863 4392 BthEnum (86f46c41f773da5a4a1d221c9201e3b8) C:\Windows\system32\DRIVERS\BthEnum.sys 16:43:28.0863 4392 BthEnum - ok 16:43:28.0913 4392 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys 16:43:28.0913 4392 BTHMODEM - ok 16:43:28.0943 4392 BthPan (befc5311736b475ac5b60c14ff7c775a) C:\Windows\system32\DRIVERS\bthpan.sys 16:43:28.0953 4392 BthPan - ok 16:43:29.0003 4392 BthPort (e76f40c8dffd33b6f142de90d3cabb73) C:\Windows\system32\Drivers\BTHport.sys 16:43:29.0013 4392 BthPort - ok 16:43:29.0073 4392 BthServ (e53aa49695b7bd95808b7c6da170a40e) C:\Windows\System32\bthserv.dll 16:43:29.0073 4392 BthServ - ok 16:43:29.0113 4392 BTHUSB (cd52602d1884c6867269babcb67849c5) C:\Windows\system32\Drivers\BTHUSB.sys 16:43:29.0113 4392 BTHUSB - ok 16:43:29.0163 4392 btwaudio (319c67f7d157eaac519dcc5f29e929d0) C:\Windows\system32\drivers\btwaudio.sys 16:43:29.0163 4392 btwaudio - ok 16:43:29.0171 4392 btwavdt (0b79273c8c2846d28aab936e7a2dbaad) C:\Windows\system32\drivers\btwavdt.sys 16:43:29.0174 4392 btwavdt - ok 16:43:29.0309 4392 btwdins (6c32a638ee80fd832418ce78e516ffa1) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 16:43:29.0314 4392 btwdins - ok 16:43:29.0364 4392 btwl2cap (fda1b5124e07003c3d0d279e5050485e) C:\Windows\system32\DRIVERS\btwl2cap.sys 16:43:29.0366 4392 btwl2cap - ok 16:43:29.0396 4392 btwrchid (47216d8b5f4042e6d0736bfa2e57b5df) C:\Windows\system32\DRIVERS\btwrchid.sys 16:43:29.0397 4392 btwrchid - ok 16:43:29.0436 4392 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys 16:43:29.0439 4392 cdfs - ok 16:43:29.0482 4392 cdrom (3b2fb35363423ed60c8fbf15fc8680bd) C:\Windows\system32\DRIVERS\cdrom.sys 16:43:29.0484 4392 cdrom - ok 16:43:29.0533 4392 CertPropSvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll 16:43:29.0534 4392 CertPropSvc - ok 16:43:29.0586 4392 cfwids (274ce03459896006f7a5069266e0469e) C:\Windows\system32\drivers\cfwids.sys 16:43:29.0588 4392 cfwids - ok 16:43:29.0624 4392 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys 16:43:29.0626 4392 circlass - ok 16:43:29.0676 4392 CLFS (caeda2572b7042b11062f327f099251d) C:\Windows\system32\CLFS.sys 16:43:29.0682 4392 CLFS - ok 16:43:29.0810 4392 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 16:43:29.0812 4392 clr_optimization_v2.0.50727_32 - ok 16:43:29.0880 4392 clr_optimization_v2.0.50727_64 (fa58b51ed71c9133e141164eaa7c54eb) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 16:43:29.0883 4392 clr_optimization_v2.0.50727_64 - ok 16:43:29.0969 4392 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 16:43:29.0971 4392 clr_optimization_v4.0.30319_32 - ok 16:43:30.0031 4392 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 16:43:30.0034 4392 clr_optimization_v4.0.30319_64 - ok 16:43:30.0083 4392 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys 16:43:30.0085 4392 CmBatt - ok 16:43:30.0124 4392 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys 16:43:30.0126 4392 cmdide - ok 16:43:30.0155 4392 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys 16:43:30.0156 4392 Compbatt - ok 16:43:30.0170 4392 COMSysApp - ok 16:43:30.0178 4392 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys 16:43:30.0180 4392 crcdisk - ok 16:43:30.0228 4392 CryptSvc (4374f784121d8b3bb466b03f5e5ebd33) C:\Windows\system32\cryptsvc.dll 16:43:30.0231 4392 CryptSvc - ok 16:43:30.0293 4392 CtClsFlt (11f13042577705093612c6a123caf12f) C:\Windows\system32\DRIVERS\CtClsFlt.sys 16:43:30.0297 4392 CtClsFlt - ok 16:43:30.0387 4392 DcomLaunch (52cdade8289ff21f1f2215ff51a5f36c) C:\Windows\system32\rpcss.dll 16:43:30.0392 4392 DcomLaunch - ok 16:43:30.0455 4392 DfsC (3725c43c9e90731eca651d506cc599a3) C:\Windows\system32\Drivers\dfsc.sys 16:43:30.0456 4392 DfsC - ok 16:43:30.0718 4392 DFSR (1781f99840979ee7b126c9073c377fd0) C:\Windows\system32\DFSR.exe 16:43:30.0760 4392 DFSR - ok 16:43:30.0914 4392 Dhcp (fdaa0edfcfb70cd529589ad654651b40) C:\Windows\System32\dhcpcsvc.dll 16:43:30.0916 4392 Dhcp - ok 16:43:30.0966 4392 disk (2dc415fc05fb8a079f896cbbacb19324) C:\Windows\system32\drivers\disk.sys 16:43:30.0969 4392 disk - ok 16:43:30.0978 4392 dlbt_device - ok 16:43:31.0048 4392 Dnscache (daf05293c1264e251d3a25e7e24b2ddf) C:\Windows\System32\dnsrslvr.dll 16:43:31.0051 4392 Dnscache - ok 16:43:31.0165 4392 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe 16:43:31.0166 4392 DockLoginService - ok 16:43:31.0205 4392 dot3svc (cc661867677627f2911c2a4970dee0f1) C:\Windows\System32\dot3svc.dll 16:43:31.0224 4392 dot3svc - ok 16:43:31.0270 4392 DPS (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll 16:43:31.0270 4392 DPS - ok 16:43:31.0327 4392 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys 16:43:31.0327 4392 drmkaud - ok 16:43:31.0457 4392 DXGKrnl (412964040ce920ff83aff6b5b551bf99) C:\Windows\System32\drivers\dxgkrnl.sys 16:43:31.0467 4392 DXGKrnl - ok 16:43:31.0517 4392 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys 16:43:31.0517 4392 E1G60 - ok 16:43:31.0567 4392 EapHost (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll 16:43:31.0567 4392 EapHost - ok 16:43:31.0607 4392 Ecache (7343d950a34a95dcb7441642e3e6beef) C:\Windows\system32\drivers\ecache.sys 16:43:31.0607 4392 Ecache - ok 16:43:31.0687 4392 ehRecvr (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe 16:43:31.0687 4392 ehRecvr - ok 16:43:31.0707 4392 ehSched (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe 16:43:31.0707 4392 ehSched - ok 16:43:31.0727 4392 ehstart (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll 16:43:31.0727 4392 ehstart - ok 16:43:31.0797 4392 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys 16:43:31.0797 4392 elxstor - ok 16:43:31.0887 4392 EMDMgmt (e4eb76d0a8fc43db7f36302e1f33791f) C:\Windows\system32\emdmgmt.dll 16:43:31.0887 4392 EMDMgmt - ok 16:43:31.0937 4392 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys 16:43:31.0937 4392 ErrDev - ok 16:43:32.0007 4392 EventSystem (6b1a97bf9fefbdc83f3c7c7d0f826c66) C:\Windows\system32\es.dll 16:43:32.0007 4392 EventSystem - ok 16:43:32.0047 4392 exfat (2a546b9a84658b0554b1ec35cd9adaf5) C:\Windows\system32\drivers\exfat.sys 16:43:32.0057 4392 exfat - ok 16:43:32.0097 4392 fastfat (fe731d345ed9eeabbc72a59b35941834) C:\Windows\system32\drivers\fastfat.sys 16:43:32.0097 4392 fastfat - ok 16:43:32.0137 4392 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys 16:43:32.0137 4392 fdc - ok 16:43:32.0187 4392 fdPHost (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll 16:43:32.0187 4392 fdPHost - ok 16:43:32.0197 4392 FDResPub (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll 16:43:32.0197 4392 FDResPub - ok 16:43:32.0217 4392 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys 16:43:32.0217 4392 FileInfo - ok 16:43:32.0247 4392 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys 16:43:32.0247 4392 Filetrace - ok 16:43:32.0287 4392 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 16:43:32.0287 4392 flpydisk - ok 16:43:32.0327 4392 FltMgr (7dacf1a3a4219575070c6dc7c957428a) C:\Windows\system32\drivers\fltmgr.sys 16:43:32.0327 4392 FltMgr - ok 16:43:32.0397 4392 FontCache3.0.0.0 (73d0f1d32edae3dcc4e84468bf910add) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 16:43:32.0397 4392 FontCache3.0.0.0 - ok 16:43:32.0427 4392 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys 16:43:32.0427 4392 Fs_Rec - ok 16:43:32.0467 4392 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys 16:43:32.0467 4392 gagp30kx - ok 16:43:32.0537 4392 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 16:43:32.0537 4392 GEARAspiWDM - ok 16:43:32.0617 4392 gpsvc (9e5b254d58232ec8921ec3c5a94c81ed) C:\Windows\System32\gpsvc.dll 16:43:32.0627 4392 gpsvc - ok 16:43:32.0677 4392 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys 16:43:32.0677 4392 HdAudAddService - ok 16:43:32.0707 4392 HDAudBus (0c0d0f8a3ff09ecc81963d09ec6a0a84) C:\Windows\system32\DRIVERS\HDAudBus.sys 16:43:32.0707 4392 HDAudBus - ok 16:43:32.0727 4392 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys 16:43:32.0727 4392 HidBth - ok 16:43:32.0737 4392 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys 16:43:32.0737 4392 HidIr - ok 16:43:32.0787 4392 hidserv (0aa154538544e988429da2d5aa803a6c) C:\Windows\System32\hidserv.dll 16:43:32.0787 4392 hidserv - ok 16:43:32.0797 4392 HidUsb (128e2da8483fdd4dd0c7b3f9abd6f323) C:\Windows\system32\DRIVERS\hidusb.sys 16:43:32.0797 4392 HidUsb - ok 16:43:32.0827 4392 hkmsvc (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll 16:43:32.0837 4392 hkmsvc - ok 16:43:32.0867 4392 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys 16:43:32.0867 4392 HpCISSs - ok 16:43:32.0947 4392 HTTP (e690736da6c543f5d99c8fa27bea31db) C:\Windows\system32\drivers\HTTP.sys 16:43:32.0947 4392 HTTP - ok 16:43:32.0987 4392 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys 16:43:32.0987 4392 i2omp - ok 16:43:33.0007 4392 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys 16:43:33.0007 4392 i8042prt - ok 16:43:33.0057 4392 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys 16:43:33.0067 4392 iaStorV - ok 16:43:33.0233 4392 idsvc (76ea63cdb2d88dae7209691d089bef1d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 16:43:33.0246 4392 idsvc - ok 16:43:33.0268 4392 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys 16:43:33.0270 4392 iirsp - ok 16:43:33.0354 4392 IKEEXT (3a3b232140c33376e134e7b61a0eaa44) C:\Windows\System32\ikeext.dll 16:43:33.0362 4392 IKEEXT - ok 16:43:33.0391 4392 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys 16:43:33.0392 4392 intelide - ok 16:43:33.0410 4392 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys 16:43:33.0411 4392 intelppm - ok 16:43:33.0449 4392 IPBusEnum (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll 16:43:33.0452 4392 IPBusEnum - ok 16:43:33.0506 4392 IpFilterDriver (99b821f5bebd6a3cc3fe564f802ae0fd) C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:43:33.0508 4392 IpFilterDriver - ok 16:43:33.0581 4392 iphlpsvc (3a0427f35e7f8c16bbc5b1be32b8de76) C:\Windows\System32\iphlpsvc.dll 16:43:33.0586 4392 iphlpsvc - ok 16:43:33.0590 4392 IpInIp - ok 16:43:33.0632 4392 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys 16:43:33.0634 4392 IPMIDRV - ok 16:43:33.0660 4392 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys 16:43:33.0662 4392 IPNAT - ok 16:43:33.0829 4392 iPod Service (a9ab99ee7d39725eafec82732d2b3271) C:\Program Files\iPod\bin\iPodService.exe 16:43:33.0834 4392 iPod Service - ok 16:43:33.0879 4392 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys 16:43:33.0881 4392 IRENUM - ok 16:43:33.0932 4392 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys 16:43:33.0934 4392 isapnp - ok 16:43:33.0994 4392 iScsiPrt (49e4ccbf74783fce5d2cc1ff6480e1f4) C:\Windows\system32\DRIVERS\msiscsi.sys 16:43:33.0998 4392 iScsiPrt - ok 16:43:34.0023 4392 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys 16:43:34.0025 4392 iteatapi - ok 16:43:34.0056 4392 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys 16:43:34.0058 4392 iteraid - ok 16:43:34.0102 4392 k57nd60a (eb5c7891b9e6e4a1a4428f2160b12b53) C:\Windows\system32\DRIVERS\k57nd60a.sys 16:43:34.0107 4392 k57nd60a - ok 16:43:34.0117 4392 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys 16:43:34.0119 4392 kbdclass - ok 16:43:34.0128 4392 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys 16:43:34.0130 4392 kbdhid - ok 16:43:34.0168 4392 KeyIso (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe 16:43:34.0170 4392 KeyIso - ok 16:43:34.0218 4392 KSecDD (ccdcce6224e1e207e953af826b98a9d9) C:\Windows\system32\Drivers\ksecdd.sys 16:43:34.0226 4392 KSecDD - ok 16:43:34.0253 4392 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys 16:43:34.0255 4392 ksthunk - ok 16:43:34.0319 4392 KtmRm (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll 16:43:34.0326 4392 KtmRm - ok 16:43:34.0367 4392 LanmanServer (3f27c9cdae606d74431e3ab39571a7f3) C:\Windows\System32\srvsvc.dll 16:43:34.0371 4392 LanmanServer - ok 16:43:34.0420 4392 LanmanWorkstation (6e25ffc6fead6544c6e9f1d23329570c) C:\Windows\System32\wkssvc.dll 16:43:34.0423 4392 LanmanWorkstation - ok 16:43:34.0472 4392 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys 16:43:34.0474 4392 lltdio - ok 16:43:34.0517 4392 lltdsvc (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll 16:43:34.0523 4392 lltdsvc - ok 16:43:34.0537 4392 lmhosts (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll 16:43:34.0539 4392 lmhosts - ok 16:43:34.0582 4392 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys 16:43:34.0584 4392 LSI_FC - ok 16:43:34.0607 4392 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys 16:43:34.0610 4392 LSI_SAS - ok 16:43:34.0629 4392 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys 16:43:34.0632 4392 LSI_SCSI - ok 16:43:34.0668 4392 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys 16:43:34.0670 4392 luafv - ok 16:43:34.0735 4392 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys 16:43:34.0736 4392 MBAMProtector - ok 16:43:34.0857 4392 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 16:43:34.0861 4392 MBAMService - ok 16:43:35.0001 4392 McAfee SiteAdvisor Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:35.0004 4392 McAfee SiteAdvisor Service - ok 16:43:35.0058 4392 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe 16:43:35.0062 4392 McComponentHostService - ok 16:43:35.0080 4392 McMPFSvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:35.0082 4392 McMPFSvc - ok 16:43:35.0087 4392 mcmscsvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:35.0089 4392 mcmscsvc - ok 16:43:35.0117 4392 McNASvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:35.0119 4392 McNASvc - ok 16:43:35.0261 4392 McODS (504c0af387549fab2f3e867e5043851d) C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe 16:43:35.0271 4392 McODS - ok 16:43:35.0271 4392 McProxy (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:35.0281 4392 McProxy - ok 16:43:35.0361 4392 McShield (e998e3b12101288d716558466cbf6ae1) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 16:43:35.0361 4392 McShield - ok 16:43:35.0481 4392 McSysmon (f2a433e0ea959028e349fb1d5bae01e7) C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe 16:43:35.0491 4392 McSysmon - ok 16:43:35.0611 4392 Mcx2Svc (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll 16:43:35.0611 4392 Mcx2Svc - ok 16:43:35.0701 4392 MDM (11f714f85530a2bd134074dc30e99fca) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 16:43:35.0701 4392 MDM - ok 16:43:35.0771 4392 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys 16:43:35.0771 4392 megasas - ok 16:43:35.0811 4392 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys 16:43:35.0821 4392 MegaSR - ok 16:43:35.0881 4392 mfeapfk (01884cb7655c8908b43ff5e364fe6fd2) C:\Windows\system32\drivers\mfeapfk.sys 16:43:35.0881 4392 mfeapfk - ok 16:43:35.0921 4392 mfeavfk (dab9a9cdfb04e4d68924492aa043019d) C:\Windows\system32\drivers\mfeavfk.sys 16:43:35.0921 4392 mfeavfk - ok 16:43:36.0051 4392 mfefire (b26782c3d6045b4464017d7926877560) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 16:43:36.0051 4392 mfefire - ok 16:43:36.0121 4392 mfefirek (ce9a3680675c0907ade16404ca967b49) C:\Windows\system32\drivers\mfefirek.sys 16:43:36.0131 4392 mfefirek - ok 16:43:36.0201 4392 mfehidk (60cf67458dd29cd17e77f2327b1a9a54) C:\Windows\system32\drivers\mfehidk.sys 16:43:36.0211 4392 mfehidk - ok 16:43:36.0261 4392 mfenlfk (a8129cfb919347f8533c934b365e9202) C:\Windows\system32\DRIVERS\mfenlfk.sys 16:43:36.0261 4392 mfenlfk - ok 16:43:36.0301 4392 mferkdet (5041fa2bd2b3a2693b015771bfbf6dca) C:\Windows\system32\drivers\mferkdet.sys 16:43:36.0301 4392 mferkdet - ok 16:43:36.0431 4392 mfevtp (723a5eb6cef7f408c3d0f15a82a6bff8) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe 16:43:36.0431 4392 mfevtp - ok 16:43:36.0481 4392 mfewfpk (919c56db14a0e1e2ab6da5d2821dc26e) C:\Windows\system32\drivers\mfewfpk.sys 16:43:36.0481 4392 mfewfpk - ok 16:43:36.0521 4392 MMCSS (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll 16:43:36.0521 4392 MMCSS - ok 16:43:36.0551 4392 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys 16:43:36.0551 4392 Modem - ok 16:43:36.0581 4392 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys 16:43:36.0581 4392 monitor - ok 16:43:36.0591 4392 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys 16:43:36.0591 4392 mouclass - ok 16:43:36.0641 4392 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys 16:43:36.0641 4392 mouhid - ok 16:43:36.0661 4392 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys 16:43:36.0661 4392 MountMgr - ok 16:43:36.0811 4392 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 16:43:36.0821 4392 MozillaMaintenance - ok 16:43:36.0871 4392 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys 16:43:36.0881 4392 mpio - ok 16:43:36.0911 4392 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys 16:43:36.0911 4392 mpsdrv - ok 16:43:36.0941 4392 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys 16:43:36.0941 4392 Mraid35x - ok 16:43:36.0971 4392 MRxDAV (fe2706c15f8345c342820e4e4583fea0) C:\Windows\system32\drivers\mrxdav.sys 16:43:36.0981 4392 MRxDAV - ok 16:43:37.0051 4392 mrxsmb (b698eb9acc7ecd4927d99d268918f912) C:\Windows\system32\DRIVERS\mrxsmb.sys 16:43:37.0051 4392 mrxsmb - ok 16:43:37.0101 4392 mrxsmb10 (9a797e27fd28500ee13d43000c931435) C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:43:37.0111 4392 mrxsmb10 - ok 16:43:37.0121 4392 mrxsmb20 (f9425d610712533107a264e2d5b2154b) C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:43:37.0121 4392 mrxsmb20 - ok 16:43:37.0161 4392 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys 16:43:37.0161 4392 msahci - ok 16:43:37.0201 4392 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys 16:43:37.0211 4392 msdsm - ok 16:43:37.0261 4392 MSDTC (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe 16:43:37.0271 4392 MSDTC - ok 16:43:37.0301 4392 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys 16:43:37.0301 4392 Msfs - ok 16:43:37.0321 4392 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys 16:43:37.0321 4392 msisadrv - ok 16:43:37.0381 4392 MSiSCSI (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll 16:43:37.0381 4392 MSiSCSI - ok 16:43:37.0381 4392 msiserver - ok 16:43:37.0501 4392 MSK80Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 16:43:37.0501 4392 MSK80Service - ok 16:43:37.0531 4392 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys 16:43:37.0531 4392 MSKSSRV - ok 16:43:37.0561 4392 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys 16:43:37.0561 4392 MSPCLOCK - ok 16:43:37.0591 4392 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys 16:43:37.0591 4392 MSPQM - ok 16:43:37.0641 4392 MsRPC (b8e32e6103fbba9fbb1d0c11ff0d13b5) C:\Windows\system32\drivers\MsRPC.sys 16:43:37.0651 4392 MsRPC - ok 16:43:37.0681 4392 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys 16:43:37.0681 4392 mssmbios - ok 16:43:37.0711 4392 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys 16:43:37.0711 4392 MSTEE - ok 16:43:37.0731 4392 Mup (ddf133501f68d6988a0f55dfa88637b4) C:\Windows\system32\Drivers\mup.sys 16:43:37.0731 4392 Mup - ok 16:43:37.0791 4392 napagent (c25022cdd18980846973b598900915f8) C:\Windows\system32\qagentRT.dll 16:43:37.0791 4392 napagent - ok 16:43:37.0831 4392 NativeWifiP (73b99c98fa3a2ed1566e02d6fe1913a5) C:\Windows\system32\DRIVERS\nwifi.sys 16:43:37.0831 4392 NativeWifiP - ok 16:43:37.0921 4392 NDIS (2a2ee457af36c5c9a6808c768bd3a12b) C:\Windows\system32\drivers\ndis.sys 16:43:37.0931 4392 NDIS - ok 16:43:37.0931 4392 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys 16:43:37.0931 4392 NdisTapi - ok 16:43:37.0941 4392 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys 16:43:37.0951 4392 Ndisuio - ok 16:43:37.0971 4392 NdisWan (52e3e8e35101399be9b2938c992aa087) C:\Windows\system32\DRIVERS\ndiswan.sys 16:43:37.0971 4392 NdisWan - ok 16:43:37.0981 4392 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys 16:43:37.0981 4392 NDProxy - ok 16:43:38.0011 4392 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys 16:43:38.0011 4392 NetBIOS - ok 16:43:38.0041 4392 netbt (7a29ca243a629230799754162d80120f) C:\Windows\system32\DRIVERS\netbt.sys 16:43:38.0051 4392 netbt - ok 16:43:38.0071 4392 Netlogon (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe 16:43:38.0071 4392 Netlogon - ok 16:43:38.0121 4392 Netman (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll 16:43:38.0131 4392 Netman - ok 16:43:38.0171 4392 netprofm (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll 16:43:38.0172 4392 netprofm - ok 16:43:38.0255 4392 NetTcpPortSharing (b84613b469b98e09f50a748c1d02e132) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 16:43:38.0256 4392 NetTcpPortSharing - ok 16:43:38.0606 4392 NETw5v64 (6d27b976934afc67f09a9553c2ce1309) C:\Windows\system32\DRIVERS\NETw5v64.sys 16:43:38.0665 4392 NETw5v64 - ok 16:43:38.0822 4392 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys 16:43:38.0824 4392 nfrd960 - ok 16:43:38.0869 4392 NlaSvc (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll 16:43:38.0874 4392 NlaSvc - ok 16:43:38.0885 4392 Npfs (b06154e2a2c91e9be5599fca53bc4cd0) C:\Windows\system32\drivers\Npfs.sys 16:43:38.0887 4392 Npfs - ok 16:43:38.0915 4392 nsi (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll 16:43:38.0917 4392 nsi - ok 16:43:38.0933 4392 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys 16:43:38.0935 4392 nsiproxy - ok 16:43:39.0092 4392 Ntfs (fe86ba5ac3b50e2ca911e9c60c07b638) C:\Windows\system32\drivers\Ntfs.sys 16:43:39.0112 4392 Ntfs - ok 16:43:39.0259 4392 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys 16:43:39.0260 4392 Null - ok 16:43:39.0301 4392 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys 16:43:39.0303 4392 nvraid - ok 16:43:39.0334 4392 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys 16:43:39.0335 4392 nvstor - ok 16:43:39.0370 4392 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys 16:43:39.0373 4392 nv_agp - ok 16:43:39.0377 4392 NwlnkFlt - ok 16:43:39.0382 4392 NwlnkFwd - ok 16:43:39.0435 4392 OA008Ufd (404b0121ae1a75d9a63b6934eb07c258) C:\Windows\system32\DRIVERS\OA008Ufd.sys 16:43:39.0438 4392 OA008Ufd - ok 16:43:39.0468 4392 OA008Vid (126885007e8f601861165fc77c93f1be) C:\Windows\system32\DRIVERS\OA008Vid.sys 16:43:39.0474 4392 OA008Vid - ok 16:43:39.0649 4392 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 16:43:39.0655 4392 odserv - ok 16:43:39.0708 4392 ohci1394 (1b30103fde512915a9214b108b6e7a9c) C:\Windows\system32\DRIVERS\ohci1394.sys 16:43:39.0710 4392 ohci1394 - ok 16:43:39.0753 4392 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:43:39.0756 4392 ose - ok 16:43:39.0840 4392 p2pimsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll 16:43:39.0852 4392 p2pimsvc - ok 16:43:39.0860 4392 p2psvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll 16:43:39.0865 4392 p2psvc - ok 16:43:39.0936 4392 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys 16:43:39.0938 4392 Parport - ok 16:43:39.0980 4392 partmgr (5ab40c36894f4c06bdab0c9a2fba282d) C:\Windows\system32\drivers\partmgr.sys 16:43:39.0982 4392 partmgr - ok 16:43:40.0024 4392 PcaSvc (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll 16:43:40.0026 4392 PcaSvc - ok 16:43:40.0054 4392 pci (2a5b2a51559066ea84742909b5b2cd69) C:\Windows\system32\drivers\pci.sys 16:43:40.0058 4392 pci - ok 16:43:40.0080 4392 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys 16:43:40.0082 4392 pciide - ok 16:43:40.0114 4392 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys 16:43:40.0118 4392 pcmcia - ok 16:43:40.0189 4392 PCTCore (876fd95b7a3b7fe6179fbd16e7a6486c) C:\Windows\system32\drivers\PCTCore64.sys 16:43:40.0196 4392 PCTCore - ok 16:43:40.0246 4392 pctDS (ba1f42a42f405f62ceff6b69a2797f7c) C:\Windows\system32\drivers\pctDS64.sys 16:43:40.0253 4392 pctDS - ok 16:43:40.0345 4392 pctEFA (146cc91c93ced13e7fe40e8d8615be39) C:\Windows\system32\drivers\pctEFA64.sys 16:43:40.0359 4392 pctEFA - ok 16:43:40.0417 4392 PCTSD (c4775e7f54f3cc6307b73462b1b802c6) C:\Windows\system32\Drivers\PCTSD64.sys 16:43:40.0421 4392 PCTSD - ok 16:43:40.0502 4392 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys 16:43:40.0513 4392 PEAUTH - ok 16:43:40.0606 4392 PerfHost (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe 16:43:40.0608 4392 PerfHost - ok 16:43:40.0748 4392 pla (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll 16:43:40.0766 4392 pla - ok 16:43:40.0833 4392 PlugPlay (5aaa0c5534b05ed49919fcd9dbd11a5b) C:\Windows\system32\umpnpmgr.dll 16:43:40.0839 4392 PlugPlay - ok 16:43:40.0929 4392 PNRPAutoReg (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll 16:43:40.0935 4392 PNRPAutoReg - ok 16:43:40.0943 4392 PNRPsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll 16:43:40.0949 4392 PNRPsvc - ok 16:43:41.0023 4392 PolicyAgent (eef3688d5e9592cbbbed00de71dda1ef) C:\Windows\System32\ipsecsvc.dll 16:43:41.0032 4392 PolicyAgent - ok 16:43:41.0111 4392 PptpMiniport (f5739f2c6db2534c384ad5150808e8f5) C:\Windows\system32\DRIVERS\raspptp.sys 16:43:41.0114 4392 PptpMiniport - ok 16:43:41.0147 4392 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys 16:43:41.0149 4392 Processor - ok 16:43:41.0192 4392 ProfSvc (b21fe10dad3ab59e78df7aa3fbf41e70) C:\Windows\system32\profsvc.dll 16:43:41.0196 4392 ProfSvc - ok 16:43:41.0223 4392 ProtectedStorage (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe 16:43:41.0224 4392 ProtectedStorage - ok 16:43:41.0257 4392 PSched (0e0e205a296095fe4c631e6a4775ad6c) C:\Windows\system32\DRIVERS\pacer.sys 16:43:41.0259 4392 PSched - ok 16:43:41.0378 4392 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys 16:43:41.0395 4392 ql2300 - ok 16:43:41.0428 4392 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys 16:43:41.0431 4392 ql40xx - ok 16:43:41.0489 4392 QWAVE (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll 16:43:41.0495 4392 QWAVE - ok 16:43:41.0512 4392 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys 16:43:41.0514 4392 QWAVEdrv - ok 16:43:41.0547 4392 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys 16:43:41.0548 4392 RasAcd - ok 16:43:41.0571 4392 RasAuto (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll 16:43:41.0574 4392 RasAuto - ok 16:43:41.0589 4392 Rasl2tp (3b9085f91ef00abd15a6f36570e90e12) C:\Windows\system32\DRIVERS\rasl2tp.sys 16:43:41.0592 4392 Rasl2tp - ok 16:43:41.0644 4392 RasMan (2a63d46b01685fd4be9778ca3c231c2d) C:\Windows\System32\rasmans.dll 16:43:41.0649 4392 RasMan - ok 16:43:41.0679 4392 RasPppoe (2ce1703c27196094fb6e4c6e439f2c21) C:\Windows\system32\DRIVERS\raspppoe.sys 16:43:41.0681 4392 RasPppoe - ok 16:43:41.0690 4392 RasSstp (fcd04fa67e8b40fa0ad361dd38593942) C:\Windows\system32\DRIVERS\rassstp.sys 16:43:41.0692 4392 RasSstp - ok 16:43:41.0752 4392 rdbss (33fa5b6136d92ee0f53f021c79091300) C:\Windows\system32\DRIVERS\rdbss.sys 16:43:41.0757 4392 rdbss - ok 16:43:41.0762 4392 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys 16:43:41.0763 4392 RDPCDD - ok 16:43:41.0813 4392 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys 16:43:41.0819 4392 rdpdr - ok 16:43:41.0825 4392 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys 16:43:41.0826 4392 RDPENCDD - ok 16:43:41.0857 4392 RDPWD (7747082f672aa2846235c9cea42e2e72) C:\Windows\system32\drivers\RDPWD.sys 16:43:41.0861 4392 RDPWD - ok 16:43:41.0903 4392 RemoteAccess (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll 16:43:41.0906 4392 RemoteAccess - ok 16:43:41.0959 4392 RemoteRegistry (416c611369cbe49074b89cee2f83abef) C:\Windows\system32\regsvc.dll 16:43:41.0964 4392 RemoteRegistry - ok 16:43:41.0992 4392 RFCOMM (f228ce2f778503cecb2b27097b5b3139) C:\Windows\system32\DRIVERS\rfcomm.sys 16:43:41.0994 4392 RFCOMM - ok 16:43:42.0018 4392 rimmptsk (9c23519fc1fd331aaaedc145ab947293) C:\Windows\system32\DRIVERS\rimmpx64.sys 16:43:42.0020 4392 rimmptsk - ok 16:43:42.0028 4392 rismxdp (2a43f9e6dbde12bc0c104785c3b3f5df) C:\Windows\system32\DRIVERS\rixdpx64.sys 16:43:42.0031 4392 rismxdp - ok 16:43:42.0060 4392 RpcLocator (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe 16:43:42.0062 4392 RpcLocator - ok 16:43:42.0151 4392 RpcSs (52cdade8289ff21f1f2215ff51a5f36c) C:\Windows\system32\rpcss.dll 16:43:42.0156 4392 RpcSs - ok 16:43:42.0192 4392 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys 16:43:42.0194 4392 rspndr - ok 16:43:42.0223 4392 SamSs (80f4593e92ff960e4763380d3168e498) C:\Windows\system32\lsass.exe 16:43:42.0224 4392 SamSs - ok 16:43:42.0264 4392 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys 16:43:42.0266 4392 sbp2port - ok 16:43:42.0318 4392 SCardSvr (f024d560fea06f8b56d673849eb89ae6) C:\Windows\System32\SCardSvr.dll 16:43:42.0322 4392 SCardSvr - ok 16:43:42.0416 4392 Schedule (ce75d26e0a1106129f4d156851e298ed) C:\Windows\system32\schedsvc.dll 16:43:42.0422 4392 Schedule - ok 16:43:42.0453 4392 SCPolicySvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll 16:43:42.0454 4392 SCPolicySvc - ok 16:43:42.0497 4392 sdbus (b42ee50f7d24f837f925332eb349eca5) C:\Windows\system32\DRIVERS\sdbus.sys 16:43:42.0500 4392 sdbus - ok 16:43:42.0537 4392 SDRSVC (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll 16:43:42.0540 4392 SDRSVC - ok 16:43:42.0574 4392 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 16:43:42.0575 4392 secdrv - ok 16:43:42.0589 4392 seclogon (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll 16:43:42.0592 4392 seclogon - ok 16:43:42.0614 4392 SENS (90973a64b96cd647ff81c79443618eed) C:\Windows\System32\sens.dll 16:43:42.0617 4392 SENS - ok 16:43:42.0639 4392 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys 16:43:42.0641 4392 Serenum - ok 16:43:42.0670 4392 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys 16:43:42.0673 4392 Serial - ok 16:43:42.0705 4392 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys 16:43:42.0707 4392 sermouse - ok 16:43:42.0778 4392 SessionEnv (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll 16:43:42.0781 4392 SessionEnv - ok 16:43:42.0795 4392 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\DRIVERS\sffdisk.sys 16:43:42.0797 4392 sffdisk - ok 16:43:42.0826 4392 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys 16:43:42.0828 4392 sffp_mmc - ok 16:43:42.0838 4392 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\DRIVERS\sffp_sd.sys 16:43:42.0840 4392 sffp_sd - ok 16:43:42.0861 4392 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys 16:43:42.0863 4392 sfloppy - ok 16:43:42.0914 4392 ShellHWDetection (9235ec680d3db17464b39c7c7decb4dd) C:\Windows\System32\shsvcs.dll 16:43:42.0920 4392 ShellHWDetection - ok 16:43:42.0952 4392 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys 16:43:42.0954 4392 SiSRaid2 - ok 16:43:42.0979 4392 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys 16:43:42.0982 4392 SiSRaid4 - ok 16:43:43.0119 4392 SkypeUpdate (ddaa5f4a6b958fc313ebd02dd925752f) C:\Program Files (x86)\Skype\Updater\Updater.exe 16:43:43.0121 4392 SkypeUpdate - ok 16:43:43.0299 4392 slsvc (a301d2cefb4747dfe0c24425dcbe0b78) C:\Windows\system32\SLsvc.exe 16:43:43.0312 4392 slsvc - ok 16:43:43.0435 4392 SLUINotify (f5ddf7c0af85eb72cb295171f8c3cb35) C:\Windows\system32\SLUINotify.dll 16:43:43.0438 4392 SLUINotify - ok 16:43:43.0510 4392 Smb (41eb2e8e005feedcafce301983eff932) C:\Windows\system32\DRIVERS\smb.sys 16:43:43.0512 4392 Smb - ok 16:43:43.0526 4392 SNMPTRAP (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe 16:43:43.0528 4392 SNMPTRAP - ok 16:43:43.0537 4392 spldr (f9cb0672162f7f04248e2b82c1ff4617) C:\Windows\system32\drivers\spldr.sys 16:43:43.0539 4392 spldr - ok 16:43:43.0613 4392 Spooler (92e6738d25c2123be9515c0eac0776cd) C:\Windows\System32\spoolsv.exe 16:43:43.0616 4392 Spooler - ok 16:43:43.0712 4392 srv (a8abd7d0d907b45cf3831f4dd8644349) C:\Windows\system32\DRIVERS\srv.sys 16:43:43.0720 4392 srv - ok 16:43:43.0787 4392 srv2 (6c72eea39e1c37b436a6d1532999f9ec) C:\Windows\system32\DRIVERS\srv2.sys 16:43:43.0803 4392 srv2 - ok 16:43:43.0850 4392 srvnet (7f69bcf9e6fa3d93c82ee6b87812666d) C:\Windows\system32\DRIVERS\srvnet.sys 16:43:43.0850 4392 srvnet - ok 16:43:43.0880 4392 SSDPSRV (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll 16:43:43.0880 4392 SSDPSRV - ok 16:43:43.0920 4392 SstpSvc (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll 16:43:43.0920 4392 SstpSvc - ok 16:43:43.0990 4392 stisvc (f14f7d7d68a66777fb999d5d0f21138d) C:\Windows\System32\wiaservc.dll 16:43:44.0000 4392 stisvc - ok 16:43:44.0050 4392 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys 16:43:44.0050 4392 swenum - ok 16:43:44.0110 4392 swprv (da34d6eb4a3154c0bebaeb0a2483ef3e) C:\Windows\System32\swprv.dll 16:43:44.0110 4392 swprv - ok 16:43:44.0140 4392 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys 16:43:44.0140 4392 Symc8xx - ok 16:43:44.0190 4392 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys 16:43:44.0190 4392 Sym_hi - ok 16:43:44.0220 4392 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys 16:43:44.0220 4392 Sym_u3 - ok 16:43:44.0310 4392 SysMain (bea0d5521ed21df8f6ffeed86daede7b) C:\Windows\system32\sysmain.dll 16:43:44.0310 4392 SysMain - ok 16:43:44.0350 4392 TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll 16:43:44.0350 4392 TabletInputService - ok 16:43:44.0390 4392 TapiSrv (52091001caf20ae84cf47023ee21b4bb) C:\Windows\System32\tapisrv.dll 16:43:44.0390 4392 TapiSrv - ok 16:43:44.0420 4392 TBS (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll 16:43:44.0420 4392 TBS - ok 16:43:44.0550 4392 Tcpip (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\drivers\tcpip.sys 16:43:44.0680 4392 Tcpip - ok 16:43:44.0700 4392 Tcpip6 (7d86275fb640011b372fd566c0eafa8d) C:\Windows\system32\DRIVERS\tcpip.sys 16:43:44.0700 4392 Tcpip6 - ok 16:43:44.0770 4392 tcpipreg (c29d4b3b08ad0b7e8564814e4ff6a57b) C:\Windows\system32\drivers\tcpipreg.sys 16:43:44.0770 4392 tcpipreg - ok 16:43:44.0780 4392 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys 16:43:44.0780 4392 TDPIPE - ok 16:43:44.0800 4392 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys 16:43:44.0800 4392 TDTCP - ok 16:43:44.0820 4392 tdx (8c39c72e0e853de04748c0337d9b9216) C:\Windows\system32\DRIVERS\tdx.sys 16:43:44.0830 4392 tdx - ok 16:43:44.0840 4392 TermDD (3f0ebf6ee609f2a276c0d5faf244ec90) C:\Windows\system32\DRIVERS\termdd.sys 16:43:44.0840 4392 TermDD - ok 16:43:44.0910 4392 TermService (f870a5589d6a94b426efb13689023946) C:\Windows\System32\termsrv.dll 16:43:44.0920 4392 TermService - ok 16:43:44.0970 4392 Themes (9235ec680d3db17464b39c7c7decb4dd) C:\Windows\system32\shsvcs.dll 16:43:44.0970 4392 Themes - ok 16:43:45.0000 4392 THREADORDER (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll 16:43:45.0010 4392 THREADORDER - ok 16:43:45.0050 4392 TrkWks (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll 16:43:45.0050 4392 TrkWks - ok 16:43:45.0110 4392 TrustedInstaller (ac6ff1df22ed90bad6417ee5a4c6e2f0) C:\Windows\servicing\TrustedInstaller.exe 16:43:45.0110 4392 TrustedInstaller - ok 16:43:45.0120 4392 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys 16:43:45.0120 4392 tssecsrv - ok 16:43:45.0160 4392 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys 16:43:45.0160 4392 tunmp - ok 16:43:45.0181 4392 tunnel (2dc2c423572946e9a3131425bda73cb6) C:\Windows\system32\DRIVERS\tunnel.sys 16:43:45.0181 4392 tunnel - ok 16:43:45.0209 4392 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys 16:43:45.0212 4392 uagp35 - ok 16:43:45.0263 4392 udfs (eca6629e33f122afff18a2ab7c3eb033) C:\Windows\system32\DRIVERS\udfs.sys 16:43:45.0268 4392 udfs - ok 16:43:45.0303 4392 UI0Detect (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe 16:43:45.0305 4392 UI0Detect - ok 16:43:45.0371 4392 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys 16:43:45.0373 4392 uliagpkx - ok 16:43:45.0444 4392 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys 16:43:45.0449 4392 uliahci - ok 16:43:45.0480 4392 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys 16:43:45.0483 4392 UlSata - ok 16:43:45.0500 4392 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys 16:43:45.0503 4392 ulsata2 - ok 16:43:45.0536 4392 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys 16:43:45.0538 4392 umbus - ok 16:43:45.0589 4392 upnphost (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll 16:43:45.0596 4392 upnphost - ok 16:43:45.0652 4392 USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys 16:43:45.0654 4392 USBAAPL64 - ok 16:43:45.0710 4392 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys 16:43:45.0713 4392 usbccgp - ok 16:43:45.0758 4392 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys 16:43:45.0761 4392 usbcir - ok 16:43:45.0799 4392 usbehci (da6d8d8ed0a53c63ac6f4bd40fe83fbe) C:\Windows\system32\DRIVERS\usbehci.sys 16:43:45.0801 4392 usbehci - ok 16:43:45.0833 4392 usbhub (99045369ae3216216573d0775fd7ed56) C:\Windows\system32\DRIVERS\usbhub.sys 16:43:45.0838 4392 usbhub - ok 16:43:45.0862 4392 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys 16:43:45.0864 4392 usbohci - ok 16:43:45.0908 4392 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys 16:43:45.0910 4392 usbprint - ok 16:43:45.0962 4392 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys 16:43:45.0965 4392 usbscan - ok 16:43:46.0025 4392 USBSTOR (586d9876a4945779c8eea926c0d16889) C:\Windows\system32\DRIVERS\USBSTOR.SYS 16:43:46.0027 4392 USBSTOR - ok 16:43:46.0070 4392 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys 16:43:46.0071 4392 usbuhci - ok 16:43:46.0135 4392 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys 16:43:46.0138 4392 usbvideo - ok 16:43:46.0177 4392 UxSms (9190f03c82547afa87367f1ceca88f3b) C:\Windows\System32\uxsms.dll 16:43:46.0180 4392 UxSms - ok 16:43:46.0233 4392 vds (c15a4a550cba7b9f1f68b72528e04ce1) C:\Windows\System32\vds.exe 16:43:46.0241 4392 vds - ok 16:43:46.0270 4392 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys 16:43:46.0272 4392 vga - ok 16:43:46.0287 4392 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys 16:43:46.0289 4392 VgaSave - ok 16:43:46.0303 4392 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys 16:43:46.0305 4392 viaide - ok 16:43:46.0325 4392 volmgr (793d9b32a1c462c91f6f70358283ac97) C:\Windows\system32\drivers\volmgr.sys 16:43:46.0328 4392 volmgr - ok 16:43:46.0368 4392 volmgrx (5aa217da5dc4ff5b9ac9ab86563b3223) C:\Windows\system32\drivers\volmgrx.sys 16:43:46.0375 4392 volmgrx - ok 16:43:46.0403 4392 volsnap (de4307412d98050239026e56a7dff3c0) C:\Windows\system32\drivers\volsnap.sys 16:43:46.0408 4392 volsnap - ok 16:43:46.0449 4392 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys 16:43:46.0452 4392 vsmraid - ok 16:43:46.0591 4392 VSS (186bd53f8a408ad20f5a056c05678629) C:\Windows\system32\vssvc.exe 16:43:46.0612 4392 VSS - ok 16:43:46.0650 4392 W32Time (ba29f34a61cb55c0dee29e787542edf4) C:\Windows\system32\w32time.dll 16:43:46.0657 4392 W32Time - ok 16:43:46.0710 4392 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys 16:43:46.0712 4392 WacomPen - ok 16:43:46.0735 4392 Wanarp (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys 16:43:46.0737 4392 Wanarp - ok 16:43:46.0741 4392 Wanarpv6 (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys 16:43:46.0742 4392 Wanarpv6 - ok 16:43:46.0813 4392 wcncsvc (055449247c490e24b968b44fe8a969eb) C:\Windows\System32\wcncsvc.dll 16:43:46.0823 4392 wcncsvc - ok 16:43:46.0830 4392 WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll 16:43:46.0833 4392 WcsPlugInService - ok 16:43:46.0895 4392 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys 16:43:46.0896 4392 Wd - ok 16:43:46.0990 4392 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys 16:43:47.0002 4392 Wdf01000 - ok 16:43:47.0034 4392 WdiServiceHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll 16:43:47.0037 4392 WdiServiceHost - ok 16:43:47.0041 4392 WdiSystemHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll 16:43:47.0044 4392 WdiSystemHost - ok 16:43:47.0077 4392 WebClient (3d4ab55f8178fd0cd3ca45cd0ec9cf5b) C:\Windows\System32\webclnt.dll 16:43:47.0082 4392 WebClient - ok 16:43:47.0126 4392 Wecsvc (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll 16:43:47.0129 4392 Wecsvc - ok 16:43:47.0164 4392 wercplsupport (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll 16:43:47.0168 4392 wercplsupport - ok 16:43:47.0208 4392 WerSvc (fc25242b3bcaf7e84d9184082274ae08) C:\Windows\System32\WerSvc.dll 16:43:47.0225 4392 WerSvc - ok 16:43:47.0319 4392 WinDefend - ok 16:43:47.0319 4392 WinHttpAutoProxySvc - ok 16:43:47.0370 4392 Winmgmt (ac98f38feab066a8f983d54ff3f4fd4c) C:\Windows\system32\wbem\WMIsvc.dll 16:43:47.0380 4392 Winmgmt - ok 16:43:47.0560 4392 WinRM (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll 16:43:47.0600 4392 WinRM - ok 16:43:47.0760 4392 Wlansvc (0a69955261c1b54206adc9beb89517de) C:\Windows\System32\wlansvc.dll 16:43:47.0770 4392 Wlansvc - ok 16:43:47.0860 4392 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys 16:43:47.0860 4392 WmiAcpi - ok 16:43:47.0930 4392 wmiApSrv (d303322dd577c3deda1251ed2e7a496c) C:\Windows\system32\wbem\WmiApSrv.exe 16:43:47.0930 4392 wmiApSrv - ok 16:43:48.0000 4392 WMPNetworkSvc - ok 16:43:48.0040 4392 WPCSvc (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll 16:43:48.0050 4392 WPCSvc - ok 16:43:48.0060 4392 WPDBusEnum (a27c8f92d84e2ddc151978e4692c978e) C:\Windows\system32\wpdbusenum.dll 16:43:48.0060 4392 WPDBusEnum - ok 16:43:48.0110 4392 WpdUsb (6329d1990db931073b86ab5946d8e317) C:\Windows\system32\DRIVERS\wpdusb.sys 16:43:48.0110 4392 WpdUsb - ok 16:43:48.0304 4392 WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe 16:43:48.0310 4392 WPFFontCache_v0400 - ok 16:43:48.0347 4392 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys 16:43:48.0349 4392 ws2ifsl - ok 16:43:48.0395 4392 wscsvc (cb8ea6d95949384925ccfca21cc6dfd8) C:\Windows\system32\wscsvc.dll 16:43:48.0397 4392 wscsvc - ok 16:43:48.0401 4392 WSearch - ok 16:43:48.0598 4392 wuauserv (fb3796754fe00f0bdc87a36f164a5f4d) C:\Windows\system32\wuaueng.dll 16:43:48.0632 4392 wuauserv - ok 16:43:48.0766 4392 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys 16:43:48.0769 4392 WUDFRd - ok 16:43:48.0808 4392 wudfsvc (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll 16:43:48.0811 4392 wudfsvc - ok 16:43:48.0908 4392 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7} (177590b0d2f8be513626bb8c8d6e6a08) C:\Program Files (x86)\CyberLink\PowerDVD DX\000.fcl 16:43:48.0909 4392 {1E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7} - ok 16:43:48.0978 4392 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 16:43:49.0408 4392 \Device\Harddisk0\DR0 - ok 16:43:49.0442 4392 Boot (0x1200) (32d5282cd5927289d76caad389f8cde5) \Device\Harddisk0\DR0\Partition0 16:43:49.0444 4392 \Device\Harddisk0\DR0\Partition0 - ok 16:43:49.0464 4392 Boot (0x1200) (4f9b9f7bcdda53c3399fef66037bd13d) \Device\Harddisk0\DR0\Partition1 16:43:49.0466 4392 \Device\Harddisk0\DR0\Partition1 - ok 16:43:49.0467 4392 ============================================================ 16:43:49.0467 4392 Scan finished 16:43:49.0467 4392 ============================================================ 16:43:49.0478 2640 Detected object count: 0 16:43:49.0478 2640 Actual detected object count: 0 Thank you, mistry91
Hi,

We are going to have to go about this another way.

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Hi Jeff, Sorry I haven't had long enough periods are my laptop this weekend. I'll try the flashdrive - system recovery method now.
Hi Jeff, I'm sorry, but looks like I dont have the "repair your computer" option on my Advanced Boot Options, so I will need to use the installation discs. However these are probably at my home which I won't be going back to for a few weeks most likely. I know the rules of the forum say that no reply in 3 days means you close the topic, but is it possible to keep this one open for now? Or shall I start a new topic when I can get this information? Thanks, mistry91
Hi,

I can leave it open for your of course. :)

Try this in the mean-time….

Click the Windows Start button > in the Start Search bar type Run >> Select 'Run' - then copy/paste this into the run box & click OK: (assuming ComboFix.exe is on the desktop as was instructed)

"%userprofile%\desktop\combofix.exe"

If ComboFix creates a log please post that.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI