This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

All manner of viruses on PC (XP service pack 3) [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All,

I'm trying to assist a friend who is having lots of strange behavior and virus problems on thier computer.

Upon restaring a warning message pops up "tsassist.exe - abnormal program termination". She is unable to stay on the internet and gets lots of warning messages. Also she informed me that saved files are missing from the computer. Not sure about that yet.

Any help would be much appreciated. For now, here is the highjack this log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:17:21 PM, on 8/21/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\SmarThru Office\BackUpSvr.exe
C:\Program Files\SmarThru Office\LegacyLauncher.exe
C:\WINDOWS\Dell\PanelMgr\SSMMgr.exe
C:\WINDOWS\twain_32\DELL\DELL1235\Scan2Pc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Office\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dell.msn.com/?pc=MDDS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USSMB/1
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Free TV Bar c3 - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files\Free_TV_Bar_c3\prxtbFre2.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Special Savings - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files\Superfish\Special Savings\SpecialSavings.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MI1933~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Free TV Bar c3 Toolbar - {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - C:\Program Files\Free_TV_Bar_c3\prxtbFre2.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe /hw
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [STO Backup Service] C:\Program Files\SmarThru Office\BackUpSvr.exe
O4 - HKLM\..\Run: [STO Launcher Service] C:\Program Files\SmarThru Office\LegacyLauncher.exe /run
O4 - HKLM\..\Run: [Dell PanelMgr] C:\WINDOWS\Dell\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [1235cn Scan2PC] "C:\WINDOWS\twain_32\DELL\DELL1235\Scan2Pc.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [lwGuXDuVJdJAFej.exe] C:\Documents and Settings\All Users\Application Data\lwGuXDuVJdJAFej.exe
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\WINDOWS\is-2QMNS.exe" /REG /REGSVRMODE
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [NjvPDQr7hmWWRQ] C:\Documents and Settings\All Users\Application Data\NjvPDQr7hmWWRQ.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Capture Selection - C:\Program Files\SmarThru Office\WebCapture.dll2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Save as HTML - C:\Program Files\SmarThru Office\WebCapture.dll1.htm
O8 - Extra context menu item: Save Selected Text - C:\Program Files\SmarThru Office\WebCapture.dll.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MI1933~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Web Capture - C:\Program Files\SmarThru Office\WebCapture.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Special Savings - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files\Superfish\Special Savings\SpecialSavings.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Web Capture - {7BDBFB9E-FD6E-43c2-937A-5C9F33FEBE5F} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: Web Capture - {7BDBFB9E-FD6E-43c2-937A-5C9F33FEBE5F} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra button: Capture Selection - {A36A58CC-70D5-4462-9C90-C0E9D244B230} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: Capture Selection - {A36A58CC-70D5-4462-9C90-C0E9D244B230} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra button: Save Selected Text - {A5183750-A927-4ec3-B027-C633A2D5418C} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: Save Selected Text - {A5183750-A927-4ec3-B027-C633A2D5418C} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra button: Save as HTML - {BDC4DF0E-D605-48d6-B4AF-CA5927A463EE} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O9 - Extra 'Tools' menuitem: Save as HTML - {BDC4DF0E-D605-48d6-B4AF-CA5927A463EE} - C:\Program Files\SmarThru Office\WebCapture.dll (HKCU)
O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://hudson.fnismls.com/Paragon/Codebase…rintControl.cab
O16 - DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} (Cacher Class) - http://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CAB
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\pev.3XE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 14929 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Jeff, Thanks much for getting back to me so soon. I will have access to this computer again tomorrow morning and will begin proceeding with the steps that you've outlined above. I really appreciate your taking the time to help me. Danny
Morning Jeff, I ran into some difficulty right off the bat unfortunetly. I'm able to download DDS from both links (first I tried one and then the other). I disabled the real time protection on Microsoft Security Essentials which is the only anti-virus that I'm aware of on this computer. I disabled the firewall, though I'm not sure if that was necessary. All attempts at running DDS resulted in the process hanging up. It seems to start working and gets about a minute or so into the procedure then it hangs up. I tried to let it run for quite a while each time. I'll be off this computer until tomorrow am but I'm looking forward to troubleshooting it then when I'll have more time. Thanks again for taking the time to help us out. Danny
Okay, he we go….. . DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 13:25:47 on 2012-08-23 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3037.2708 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\userinit.exe C:\WINDOWS\Explorer.EXE . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\bh\BabylonToolbar.dll BHO: Free TV Bar c3 Toolbar: {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - c:\program files\free_tv_bar_c3\prxtbFre2.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Special Savings: {74f475fa-6c75-43bd-aab9-ecda6184f600} - c:\program files\superfish\special savings\SpecialSavings.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Free TV Bar c3 Toolbar: {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - c:\program files\free_tv_bar_c3\prxtbFre2.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\BabylonToolbarTlbr.dll uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [NjvPDQr7hmWWRQ] c:\documents and settings\all users\application data\NjvPDQr7hmWWRQ.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [8169Diag] c:\program files\realtek\diagnostics utility\8169Diag.exe /hw mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [STO Backup Service] c:\program files\smarthru office\BackUpSvr.exe mRun: [STO Launcher Service] c:\program files\smarthru office\LegacyLauncher.exe /run mRun: [Dell PanelMgr] c:\windows\dell\panelmgr\SSMMgr.exe /autorun mRun: [1235cn Scan2PC] "c:\windows\twain_32\dell\dell1235\Scan2Pc.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [lwGuXDuVJdJAFej.exe] c:\documents and settings\all users\application data\lwGuXDuVJdJAFej.exe StartupFolder: c:\docume~1\office\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: Capture Selection - c:\program files\smarthru office\WebCapture.dll2.htm IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000 IE: Save as HTML - c:\program files\smarthru office\WebCapture.dll1.htm IE: Save Selected Text - c:\program files\smarthru office\WebCapture.dll.htm IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105 IE: Web Capture - c:\program files\smarthru office\WebCapture.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\superfish\special savings\SpecialSavings.dll DPF: {0854D220-A90A-466D-BC02-6683183802B7} - hxxp://hudson.fnismls.com/Paragon/Codebase/FNISPrintControl.cab DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} - hxxp://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CAB DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://zone.msn.com/bingame/chnz/default/mjolauncher.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{FC3111F6-7862-44D5-993B-AA31578D340F} : DhcpNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\office\application data\mozilla\firefox\profiles\9r7ejmvu.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109935&babsrc=KW_ss&mntrId=5ec20cca0000000000000024e80fcfe9&q= FF - component: c:\documents and settings\office\application data\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\FFTextLinks.dll FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\livingplay\nplplaypop.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll . —- FIREFOX POLICIES —- FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109935 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - 5ec20cca0000000000000024e80fcfe9 FF - user.js: extensions.BabylonToolbar_i.hardId - 5ec20cca0000000000000024e80fcfe9 FF - user.js: extensions.BabylonToolbar_i.instlDay - 15482 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1711:30:55 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9 FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . ============= SERVICES / DRIVERS =============== . R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-5-11 239168] R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-5-11 338880] S0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 171064] S0 vkquwexg;vkquwexg;c:\windows\system32\drivers\combo-fix.sys –> c:\windows\system32\drivers\Combo-Fix.sys [?] S1 nmvowknv;nmvowknv;\??\c:\windows\system32\drivers\nmvowknv.sys –> c:\windows\system32\drivers\nmvowknv.sys [?] S2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-1 135664] S2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [2009-6-29 8960] S2 PEVSystemStart;PEVSystemStart;c:\combofix\pev.3XE [2011-6-26 256000] S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys –> c:\windows\system32\drivers\SSPORT.sys [?] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-9 250056] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336] S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [2009-6-29 11264] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-9-1 135664] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-6-29 110080] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-1-3 40776] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-9 113120] S3 NAVENG;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\naveng.sys –> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\NAVENG.SYS [?] S3 NAVEX15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\navex15.sys –> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090507.003\NAVEX15.SYS [?] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [2009-6-29 16640] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-5-11 366840] S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-5-11 1150936] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336] . =============== Created Last 30 ================ . 2012-08-23 15:34:55 7023536 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5b29baa6-e6df-4b83-b8b5-d1f92171b19d}\mpengine.dll 2012-08-22 15:21:06 7023536 ——w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-08-21 18:06:03 ——– d—–w- c:\documents and settings\office\application data\PriceGong 2012-08-17 17:58:17 559128 —-a-w- c:\windows\system32\PerfStringBackup.TMP 2012-08-17 17:57:36 ——– d-s—w- C:\ComboFix 2012-08-16 21:23:28 98816 —-a-w- c:\windows\sed.exe 2012-08-16 21:23:28 518144 —-a-w- c:\windows\SWREG.exe 2012-08-16 21:23:28 256000 —-a-w- c:\windows\PEV.exe 2012-08-16 21:23:28 208896 —-a-w- c:\windows\MBR.exe 2012-08-15 17:07:03 9232584 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe 2012-07-27 20:51:30 184248 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2012-07-27 00:10:45 ——– d–h–w- c:\documents and settings\office\local settings\application data\Apple Computer 2012-07-27 00:10:30 26600 —ha-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-07-27 00:10:30 107368 —ha-w- c:\windows\system32\GEARAspi.dll 2012-07-27 00:09:28 ——– d–h–w- c:\program files\iPod 2012-07-27 00:09:24 ——– d–h–w- c:\program files\iTunes 2012-07-27 00:09:24 ——– d–h–w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2012-07-27 00:09:11 ——– d–h–w- c:\documents and settings\office\local settings\application data\Apple 2012-07-27 00:09:04 4547944 —ha-w- c:\windows\system32\usbaaplrc.dll 2012-07-27 00:09:04 43520 —ha-w- c:\windows\system32\drivers\usbaapl.sys 2012-07-27 00:08:51 ——– d–h–w- c:\program files\Bonjour . ==================== Find3M ==================== . 2012-08-02 18:07:08 70344 —ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-08-02 18:07:08 426184 —ha-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-03 17:46:44 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-13 13:29:09 1875072 —ha-w- c:\windows\system32\win32k.sys 2012-06-05 15:50:25 1372672 —ha-w- c:\windows\system32\msxml6.dll 2012-06-05 15:50:25 1172480 —ha-w- c:\windows\system32\msxml3.dll 2012-06-04 04:32:08 152576 —ha-w- c:\windows\system32\schannel.dll 2012-06-02 19:19:44 22040 —ha-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 19:19:38 219160 —ha-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 19:19:38 15384 —ha-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 19:19:34 15384 —ha-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 19:19:30 17944 —ha-w- c:\windows\system32\wuaueng.dll.mui 2012-06-02 19:18:58 275696 —ha-w- c:\windows\system32\mucltui.dll 2012-06-02 19:18:58 214256 —ha-w- c:\windows\system32\muweb.dll 2012-06-02 19:18:58 17136 —ha-w- c:\windows\system32\mucltui.dll.mui 2012-05-31 13:22:09 599040 —ha-w- c:\windows\system32\crypt32.dll . ============= FINISH: 13:27:02.15 =============== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-23 13:32:02 —————————– 13:32:02.875 OS Version: Windows 5.1.2600 Service Pack 3 13:32:02.875 Number of processors: 2 586 0x170A 13:32:02.875 ComputerName: NEWFRONT UserName: Office 13:32:03.890 Initialize success 13:33:24.906 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:33:24.906 Disk 0 Vendor: WDC_WD25 01.0 Size: 238418MB BusType: 3 13:33:24.921 Disk 0 MBR read successfully 13:33:24.921 Disk 0 MBR scan 13:33:24.921 Disk 0 Windows VISTA default MBR code 13:33:24.921 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63 13:33:24.937 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 238355 MB offset 112455 13:33:24.968 Disk 0 Partition 3 80 (A) 17 Hidd HPFS/NTFS NTFS 8 MB offset 488263545 13:33:24.968 Disk 0 Partition 3 **SUSPICIOUS** 13:33:24.968 Disk 0 scanning sectors +488281234 13:33:25.296 Disk 0 scanning C:\WINDOWS\system32\drivers 13:33:36.328 Service scanning 13:33:42.593 Service MpKsl294948d4 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5B29BAA6-E6DF-4B83-B8B5-D1F92171B19D}\MpKsl294948d4.sys **LOCKED** 32 13:33:48.843 Modules scanning 13:34:04.078 Disk 0 trace - called modules: 13:34:04.109 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys iaStor.sys hal.dll 13:34:04.109 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ace1570] 13:34:04.109 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> [0x8ace1d58] 13:34:04.109 5 PCTCore.sys[b9dec099] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8a6bd028] 13:34:04.109 Scan finished successfully 13:34:13.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Office\Desktop\MBR.dat" 13:34:13.968 The log file has been saved successfully to "C:\Documents and Settings\Office\Desktop\aswMBR.txt"

Attachments:

Hi,

Good job!

I see that you have run ComboFix? Could you please post the log that was created….it should be located at C:\ComboFix.txt
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • click OK
  • Press Start Scan
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Thanks Jeff, It found one thing, I selected cure and was instructed to reboot. here's the log: 15:10:13.0859 0684 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 15:10:14.0093 0684 ============================================================ 15:10:14.0093 0684 Current date / time: 2012/08/23 15:10:14.0093 15:10:14.0093 0684 SystemInfo: 15:10:14.0093 0684 15:10:14.0093 0684 OS Version: 5.1.2600 ServicePack: 3.0 15:10:14.0093 0684 Product type: Workstation 15:10:14.0093 0684 ComputerName: NEWFRONT 15:10:14.0093 0684 UserName: Office 15:10:14.0093 0684 Windows directory: C:\WINDOWS 15:10:14.0093 0684 System windows directory: C:\WINDOWS 15:10:14.0093 0684 Processor architecture: Intel x86 15:10:14.0093 0684 Number of processors: 2 15:10:14.0093 0684 Page size: 0x1000 15:10:14.0093 0684 Boot type: Normal boot 15:10:14.0093 0684 ============================================================ 15:10:16.0890 0684 Drive \Device\Harddisk0\DR0 - Size: 0x3A35294400 (232.83 Gb), SectorSize: 0x200, Cylinders: 0x76BA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 15:10:16.0937 0684 ============================================================ 15:10:16.0937 0684 \Device\Harddisk0\DR0: 15:10:16.0937 0684 MBR partitions: 15:10:16.0937 0684 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x1D189832 15:10:16.0937 0684 ============================================================ 15:10:17.0031 0684 C: <-> \Device\Harddisk0\DR0\Partition1 15:10:17.0031 0684 ============================================================ 15:10:17.0031 0684 Initialize success 15:10:17.0031 0684 ============================================================
Yup sorry: 15:10:13.0859 0684 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 15:10:14.0093 0684 ============================================================ 15:10:14.0093 0684 Current date / time: 2012/08/23 15:10:14.0093 15:10:14.0093 0684 SystemInfo: 15:10:14.0093 0684 15:10:14.0093 0684 OS Version: 5.1.2600 ServicePack: 3.0 15:10:14.0093 0684 Product type: Workstation 15:10:14.0093 0684 ComputerName: NEWFRONT 15:10:14.0093 0684 UserName: Office 15:10:14.0093 0684 Windows directory: C:\WINDOWS 15:10:14.0093 0684 System windows directory: C:\WINDOWS 15:10:14.0093 0684 Processor architecture: Intel x86 15:10:14.0093 0684 Number of processors: 2 15:10:14.0093 0684 Page size: 0x1000 15:10:14.0093 0684 Boot type: Normal boot 15:10:14.0093 0684 ============================================================ 15:10:16.0890 0684 Drive \Device\Harddisk0\DR0 - Size: 0x3A35294400 (232.83 Gb), SectorSize: 0x200, Cylinders: 0x76BA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 15:10:16.0937 0684 ============================================================ 15:10:16.0937 0684 \Device\Harddisk0\DR0: 15:10:16.0937 0684 MBR partitions: 15:10:16.0937 0684 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x1D189832 15:10:16.0937 0684 ============================================================ 15:10:17.0031 0684 C: <-> \Device\Harddisk0\DR0\Partition1 15:10:17.0031 0684 ============================================================ 15:10:17.0031 0684 Initialize success 15:10:17.0031 0684 ============================================================ 15:11:12.0203 2536 ============================================================ 15:11:12.0203 2536 Scan started 15:11:12.0203 2536 Mode: Manual; 15:11:12.0203 2536 ============================================================ 15:11:12.0312 2536 ================ Scan system memory ======================== 15:11:12.0312 2536 System memory - ok 15:11:12.0312 2536 ================ Scan services ============================= 15:11:12.0578 2536 43405483 - ok 15:11:12.0593 2536 Abiosdsk - ok 15:11:12.0640 2536 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 15:11:12.0640 2536 abp480n5 - ok 15:11:12.0687 2536 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:11:12.0750 2536 ACPI - ok 15:11:12.0765 2536 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 15:11:12.0765 2536 ACPIEC - ok 15:11:13.0031 2536 [ F19C98AD81D2C0E1BBFD8153D2C80EE8 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 15:11:13.0031 2536 AdobeFlashPlayerUpdateSvc - ok 15:11:13.0078 2536 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys 15:11:13.0078 2536 adpu160m - ok 15:11:13.0187 2536 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 15:11:13.0281 2536 aec - ok 15:11:13.0328 2536 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 15:11:13.0343 2536 AFD - ok 15:11:13.0421 2536 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys 15:11:13.0421 2536 agp440 - ok 15:11:13.0421 2536 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 15:11:13.0421 2536 agpCPQ - ok 15:11:13.0421 2536 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys 15:11:13.0421 2536 Aha154x - ok 15:11:13.0437 2536 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys 15:11:13.0437 2536 aic78u2 - ok 15:11:13.0453 2536 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys 15:11:13.0468 2536 aic78xx - ok 15:11:13.0546 2536 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 15:11:13.0546 2536 Alerter - ok 15:11:13.0593 2536 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 15:11:13.0593 2536 ALG - ok 15:11:13.0656 2536 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys 15:11:13.0656 2536 AliIde - ok 15:11:13.0671 2536 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys 15:11:13.0671 2536 alim1541 - ok 15:11:13.0703 2536 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys 15:11:13.0703 2536 amdagp - ok 15:11:13.0796 2536 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys 15:11:13.0812 2536 amsint - ok 15:11:13.0984 2536 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 15:11:13.0984 2536 Apple Mobile Device - ok 15:11:14.0031 2536 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 15:11:14.0031 2536 AppMgmt - ok 15:11:14.0140 2536 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys 15:11:14.0140 2536 asc - ok 15:11:14.0156 2536 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys 15:11:14.0156 2536 asc3350p - ok 15:11:14.0171 2536 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys 15:11:14.0171 2536 asc3550 - ok 15:11:14.0453 2536 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 15:11:16.0640 2536 aspnet_state - ok 15:11:16.0656 2536 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:11:16.0656 2536 AsyncMac - ok 15:11:16.0703 2536 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 15:11:16.0703 2536 atapi - ok 15:11:16.0703 2536 Atdisk - ok 15:11:16.0718 2536 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:11:16.0718 2536 Atmarpc - ok 15:11:16.0765 2536 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 15:11:16.0781 2536 AudioSrv - ok 15:11:16.0828 2536 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 15:11:16.0828 2536 audstub - ok 15:11:16.0937 2536 [ 2ED050291BC1D7F9E322E328DB3AAECF ] BBSvc C:\Program Files\Microsoft\BingBar\BBSvc.EXE 15:11:16.0953 2536 BBSvc - ok 15:11:17.0000 2536 [ 785DE7ABDA13309D6065305542829E76 ] BBUpdate C:\Program Files\Microsoft\BingBar\SeaPort.EXE 15:11:17.0000 2536 BBUpdate - ok 15:11:17.0015 2536 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 15:11:17.0015 2536 Beep - ok 15:11:17.0078 2536 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 15:11:17.0109 2536 BITS - ok 15:11:17.0218 2536 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 15:11:17.0218 2536 Bonjour Service - ok 15:11:17.0281 2536 [ A06CE3399D16DB864F55FAEB1F1927A9 ] Browser C:\WINDOWS\System32\browser.dll 15:11:17.0281 2536 Browser - ok 15:11:17.0468 2536 catchme - ok 15:11:17.0484 2536 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 15:11:17.0484 2536 cbidf - ok 15:11:17.0500 2536 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 15:11:17.0500 2536 cbidf2k - ok 15:11:17.0500 2536 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 15:11:17.0500 2536 cd20xrnt - ok 15:11:17.0531 2536 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 15:11:17.0546 2536 Cdaudio - ok 15:11:17.0546 2536 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 15:11:17.0546 2536 Cdfs - ok 15:11:17.0609 2536 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:11:17.0609 2536 Cdrom - ok 15:11:17.0609 2536 Changer - ok 15:11:17.0656 2536 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 15:11:17.0656 2536 CiSvc - ok 15:11:17.0656 2536 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 15:11:17.0656 2536 ClipSrv - ok 15:11:17.0703 2536 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:11:17.0890 2536 clr_optimization_v2.0.50727_32 - ok 15:11:17.0921 2536 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys 15:11:17.0921 2536 CmdIde - ok 15:11:17.0921 2536 COMSysApp - ok 15:11:17.0937 2536 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys 15:11:17.0937 2536 Cpqarray - ok 15:11:17.0968 2536 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 15:11:17.0968 2536 CryptSvc - ok 15:11:18.0000 2536 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 15:11:18.0000 2536 dac2w2k - ok 15:11:18.0031 2536 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys 15:11:18.0031 2536 dac960nt - ok 15:11:18.0078 2536 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 15:11:18.0078 2536 DcomLaunch - ok 15:11:18.0140 2536 [ 7F19DBA1A467B838CCB23124A2C55568 ] DgiVecp C:\WINDOWS\system32\Drivers\DgiVecp.sys 15:11:18.0140 2536 DgiVecp - ok 15:11:18.0203 2536 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 15:11:18.0203 2536 Dhcp - ok 15:11:18.0203 2536 [ A22D5A027F397E412CBB2D97E8661BFF ] Diag69xp C:\WINDOWS\system32\Drivers\Diag69xp.sys 15:11:18.0203 2536 Diag69xp - ok 15:11:18.0265 2536 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 15:11:18.0265 2536 Disk - ok 15:11:18.0296 2536 [ A0500678A33802D8954153839301D539 ] DLABMFSM C:\WINDOWS\system32\Drivers\DLABMFSM.SYS 15:11:18.0296 2536 DLABMFSM - ok 15:11:18.0328 2536 [ B8D2F68CAC54D46281399F9092644794 ] DLABOIOM C:\WINDOWS\system32\Drivers\DLABOIOM.SYS 15:11:18.0328 2536 DLABOIOM - ok 15:11:18.0343 2536 [ 0EE93AB799D1CB4EC90B36F3612FE907 ] DLACDBHM C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 15:11:18.0343 2536 DLACDBHM - ok 15:11:18.0343 2536 [ 87413B94AE1FABC117C4E8AE6725134E ] DLADResM C:\WINDOWS\system32\Drivers\DLADResM.SYS 15:11:18.0343 2536 DLADResM - ok 15:11:18.0343 2536 [ 766A148235BE1C0039C974446E4C0EDC ] DLAIFS_M C:\WINDOWS\system32\Drivers\DLAIFS_M.SYS 15:11:18.0343 2536 DLAIFS_M - ok 15:11:18.0359 2536 [ 38267CCA177354F1C64450A43A4F7627 ] DLAOPIOM C:\WINDOWS\system32\Drivers\DLAOPIOM.SYS 15:11:18.0359 2536 DLAOPIOM - ok 15:11:18.0359 2536 [ FD363369FD313B46B5AEAB1A688B52E9 ] DLAPoolM C:\WINDOWS\system32\Drivers\DLAPoolM.SYS 15:11:18.0359 2536 DLAPoolM - ok 15:11:18.0375 2536 [ 336AE18F0912EF4FBE5518849E004D74 ] DLARTL_M C:\WINDOWS\system32\Drivers\DLARTL_M.SYS 15:11:18.0375 2536 DLARTL_M - ok 15:11:18.0375 2536 [ FD85F682C1CC2A7CA878C7A448E6D87E ] DLAUDFAM C:\WINDOWS\system32\Drivers\DLAUDFAM.SYS 15:11:18.0375 2536 DLAUDFAM - ok 15:11:18.0390 2536 [ AF389CE587B6BF5BBDCD6F6ABE5EABC0 ] DLAUDF_M C:\WINDOWS\system32\Drivers\DLAUDF_M.SYS 15:11:18.0390 2536 DLAUDF_M - ok 15:11:18.0390 2536 dmadmin - ok 15:11:18.0437 2536 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 15:11:18.0453 2536 dmboot - ok 15:11:18.0453 2536 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 15:11:18.0453 2536 dmio - ok 15:11:18.0468 2536 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 15:11:18.0468 2536 dmload - ok 15:11:18.0500 2536 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 15:11:18.0500 2536 dmserver - ok 15:11:18.0515 2536 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 15:11:18.0515 2536 DMusic - ok 15:11:18.0562 2536 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 15:11:18.0562 2536 Dnscache - ok 15:11:18.0625 2536 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 15:11:18.0625 2536 Dot3svc - ok 15:11:18.0640 2536 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys 15:11:18.0640 2536 dpti2o - ok 15:11:18.0656 2536 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 15:11:18.0656 2536 drmkaud - ok 15:11:18.0687 2536 [ 5D3B71BB2BB0009D65D290E2EF374BD3 ] DRVMCDB C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 15:11:18.0687 2536 DRVMCDB - ok 15:11:18.0703 2536 [ C591BA9F96F40A1FD6494DAFDCD17185 ] DRVNDDM C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 15:11:18.0703 2536 DRVNDDM - ok 15:11:18.0750 2536 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 15:11:18.0750 2536 EapHost - ok 15:11:18.0765 2536 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 15:11:18.0765 2536 ERSvc - ok 15:11:18.0828 2536 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 15:11:18.0828 2536 Eventlog - ok 15:11:18.0859 2536 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 15:11:18.0875 2536 EventSystem - ok 15:11:18.0906 2536 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 15:11:18.0906 2536 Fastfat - ok 15:11:18.0953 2536 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 15:11:18.0953 2536 FastUserSwitchingCompatibility - ok 15:11:19.0015 2536 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe 15:11:19.0015 2536 Fax - ok 15:11:19.0031 2536 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 15:11:19.0031 2536 Fdc - ok 15:11:19.0046 2536 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 15:11:19.0046 2536 Fips - ok 15:11:19.0078 2536 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 15:11:19.0078 2536 Flpydisk - ok 15:11:19.0109 2536 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 15:11:19.0125 2536 FltMgr - ok 15:11:19.0234 2536 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 15:11:19.0234 2536 FontCache3.0.0.0 - ok 15:11:19.0234 2536 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:11:19.0250 2536 Fs_Rec - ok 15:11:19.0281 2536 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:11:19.0281 2536 Ftdisk - ok 15:11:19.0312 2536 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 15:11:19.0312 2536 GEARAspiWDM - ok 15:11:19.0359 2536 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:11:19.0375 2536 Gpc - ok 15:11:19.0531 2536 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 15:11:19.0531 2536 gupdate - ok 15:11:19.0546 2536 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 15:11:19.0546 2536 gupdatem - ok 15:11:19.0562 2536 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 15:11:19.0562 2536 gusvc - ok 15:11:19.0609 2536 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:11:19.0625 2536 HDAudBus - ok 15:11:19.0734 2536 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 15:11:19.0734 2536 helpsvc - ok 15:11:19.0781 2536 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 15:11:19.0796 2536 HidServ - ok 15:11:19.0812 2536 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:11:19.0812 2536 hidusb - ok 15:11:19.0859 2536 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 15:11:19.0859 2536 hkmsvc - ok 15:11:19.0859 2536 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys 15:11:19.0859 2536 hpn - ok 15:11:19.0890 2536 [ 9F1D80908658EB7F1BF70809E0B51470 ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys 15:11:19.0890 2536 HPZid412 - ok 15:11:19.0921 2536 [ F7E3E9D50F9CD3DE28085A8FDAA0A1C3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 15:11:19.0921 2536 HPZipr12 - ok 15:11:19.0937 2536 [ CF1B7951B4EC8D13F3C93B74BB2B461B ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys 15:11:19.0937 2536 HPZius12 - ok 15:11:19.0984 2536 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 15:11:19.0984 2536 HTTP - ok 15:11:20.0031 2536 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 15:11:20.0046 2536 HTTPFilter - ok 15:11:20.0046 2536 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys 15:11:20.0062 2536 i2omgmt - ok 15:11:20.0093 2536 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys 15:11:20.0093 2536 i2omp - ok 15:11:20.0203 2536 [ F79525634B192F5A18DE503568F94EF3 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 15:11:20.0203 2536 IAANTMON - ok 15:11:20.0421 2536 [ 2DA364EE62D4949620B6FAE4FFEA16A7 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 15:11:20.0593 2536 ialm - ok 15:11:20.0640 2536 [ 707C1692214B1C290271067197F075F6 ] iaStor C:\WINDOWS\system32\drivers\iaStor.sys 15:11:20.0640 2536 iaStor - ok 15:11:20.0718 2536 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 15:11:20.0734 2536 idsvc - ok 15:11:20.0781 2536 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 15:11:20.0781 2536 Imapi - ok 15:11:20.0843 2536 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 15:11:20.0843 2536 ImapiService - ok 15:11:20.0875 2536 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys 15:11:20.0875 2536 ini910u - ok 15:11:21.0031 2536 [ 5C8F36CDCB489111B24003AF4DFE1FDC ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 15:11:21.0062 2536 IntcAzAudAddService - ok 15:11:21.0093 2536 [ C9EF68BEE3B1A62F34125A9FBBAAC10C ] IntcHdmiAddService C:\WINDOWS\system32\drivers\IntcHdmi.sys 15:11:21.0093 2536 IntcHdmiAddService - ok 15:11:21.0109 2536 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 15:11:21.0109 2536 IntelIde - ok 15:11:21.0140 2536 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:11:21.0140 2536 intelppm - ok 15:11:21.0171 2536 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 15:11:21.0171 2536 Ip6Fw - ok 15:11:21.0171 2536 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:11:21.0171 2536 IpFilterDriver - ok 15:11:21.0234 2536 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:11:21.0250 2536 IpInIp - ok 15:11:21.0421 2536 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:11:21.0437 2536 IpNat - ok 15:11:21.0562 2536 [ E6BE7A41A28D8F2DB174957454D32448 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 15:11:21.0578 2536 iPod Service - ok 15:11:21.0625 2536 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:11:21.0625 2536 IPSec - ok 15:11:21.0656 2536 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 15:11:21.0656 2536 IRENUM - ok 15:11:21.0703 2536 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:11:21.0703 2536 isapnp - ok 15:11:21.0812 2536 [ 9DBA73C2F1E76EC4CB837E67C5743596 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 15:11:21.0812 2536 JavaQuickStarterService - ok 15:11:21.0875 2536 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:11:21.0875 2536 Kbdclass - ok 15:11:21.0937 2536 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:11:21.0937 2536 kbdhid - ok 15:11:21.0953 2536 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 15:11:21.0953 2536 kmixer - ok 15:11:22.0000 2536 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 15:11:22.0015 2536 KSecDD - ok 15:11:22.0031 2536 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 15:11:22.0046 2536 LanmanServer - ok 15:11:22.0093 2536 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 15:11:22.0109 2536 lanmanworkstation - ok 15:11:22.0156 2536 [ 8F5795B166CBB50966E29982F8CDB310 ] LANPkt C:\WINDOWS\system32\DRIVERS\LANPkt.sys 15:11:22.0156 2536 LANPkt - ok 15:11:22.0156 2536 lbrtfdc - ok 15:11:22.0218 2536 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 15:11:22.0218 2536 LmHosts - ok 15:11:22.0250 2536 [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy C:\WINDOWS\system32\drivers\mbamswissarmy.sys 15:11:22.0265 2536 MBAMSwissArmy - ok 15:11:22.0328 2536 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 15:11:22.0328 2536 MDM - ok 15:11:22.0343 2536 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 15:11:22.0359 2536 Messenger - ok 15:11:22.0390 2536 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 15:11:22.0390 2536 mnmdd - ok 15:11:22.0421 2536 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 15:11:22.0421 2536 mnmsrvc - ok 15:11:22.0437 2536 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 15:11:22.0437 2536 Modem - ok 15:11:22.0468 2536 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:11:22.0468 2536 Mouclass - ok 15:11:22.0484 2536 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:11:22.0484 2536 mouhid - ok 15:11:22.0500 2536 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 15:11:22.0500 2536 MountMgr - ok 15:11:22.0562 2536 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 15:11:22.0562 2536 MozillaMaintenance - ok 15:11:22.0578 2536 [ D993BEA500E7382DC4E760BF4F35EFCB ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys 15:11:22.0578 2536 MpFilter - ok 15:11:22.0625 2536 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys 15:11:22.0625 2536 mraid35x - ok 15:11:22.0671 2536 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:11:22.0671 2536 MRxDAV - ok 15:11:22.0734 2536 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:11:22.0750 2536 MRxSmb - ok 15:11:22.0796 2536 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 15:11:22.0796 2536 MSDTC - ok 15:11:22.0796 2536 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 15:11:22.0796 2536 Msfs - ok 15:11:22.0796 2536 MSIServer - ok 15:11:22.0812 2536 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:11:22.0828 2536 MSKSSRV - ok 15:11:22.0890 2536 [ 24516BF4E12A46CB67302E2CDCB8CDDF ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 15:11:22.0906 2536 MsMpSvc - ok 15:11:22.0937 2536 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:11:22.0937 2536 MSPCLOCK - ok 15:11:22.0937 2536 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 15:11:22.0953 2536 MSPQM - ok 15:11:22.0984 2536 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:11:22.0984 2536 mssmbios - ok 15:11:23.0031 2536 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 15:11:23.0046 2536 Mup - ok 15:11:23.0078 2536 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 15:11:23.0093 2536 napagent - ok 15:11:23.0156 2536 NAVENG - ok 15:11:23.0156 2536 NAVEX15 - ok 15:11:23.0187 2536 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 15:11:23.0187 2536 NDIS - ok 15:11:23.0250 2536 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:11:23.0250 2536 NdisTapi - ok 15:11:23.0312 2536 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:11:23.0312 2536 Ndisuio - ok 15:11:23.0312 2536 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:11:23.0312 2536 NdisWan - ok 15:11:23.0343 2536 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 15:11:23.0343 2536 NDProxy - ok 15:11:23.0359 2536 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 15:11:23.0359 2536 NetBIOS - ok 15:11:23.0390 2536 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 15:11:23.0390 2536 NetBT - ok 15:11:23.0437 2536 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 15:11:23.0437 2536 NetDDE - ok 15:11:23.0437 2536 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 15:11:23.0437 2536 NetDDEdsdm - ok 15:11:23.0484 2536 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 15:11:23.0484 2536 Netlogon - ok 15:11:23.0500 2536 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 15:11:23.0515 2536 Netman - ok 15:11:23.0546 2536 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 15:11:23.0562 2536 NetTcpPortSharing - ok 15:11:23.0593 2536 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 15:11:23.0593 2536 Nla - ok 15:11:23.0593 2536 nmvowknv - ok 15:11:23.0609 2536 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 15:11:23.0609 2536 Npfs - ok 15:11:23.0671 2536 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 15:11:23.0671 2536 Ntfs - ok 15:11:23.0687 2536 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 15:11:23.0687 2536 NtLmSsp - ok 15:11:23.0734 2536 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 15:11:23.0750 2536 NtmsSvc - ok 15:11:23.0781 2536 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 15:11:23.0796 2536 Null - ok 15:11:23.0828 2536 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:11:23.0828 2536 NwlnkFlt - ok 15:11:23.0828 2536 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:11:23.0828 2536 NwlnkFwd - ok 15:11:23.0859 2536 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 15:11:23.0859 2536 ose - ok 15:11:24.0015 2536 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 15:11:24.0125 2536 osppsvc - ok 15:11:24.0156 2536 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys 15:11:24.0156 2536 Parport - ok 15:11:24.0187 2536 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 15:11:24.0187 2536 PartMgr - ok 15:11:24.0218 2536 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 15:11:24.0218 2536 ParVdm - ok 15:11:24.0234 2536 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 15:11:24.0234 2536 PCI - ok 15:11:24.0234 2536 PCIDump - ok 15:11:24.0265 2536 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 15:11:24.0265 2536 PCIIde - ok 15:11:24.0265 2536 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 15:11:24.0281 2536 Pcmcia - ok 15:11:24.0312 2536 [ 6EF125721A9F1F7DBF3229786F7DECD0 ] PCTCore C:\WINDOWS\system32\drivers\PCTCore.sys 15:11:24.0328 2536 PCTCore - ok 15:11:24.0328 2536 [ F820B4C61D1E591325B679D479D4EEA4 ] pctDS C:\WINDOWS\system32\drivers\pctDS.sys 15:11:24.0343 2536 pctDS - ok 15:11:24.0343 2536 PDCOMP - ok 15:11:24.0343 2536 PDFRAME - ok 15:11:24.0343 2536 PDRELI - ok 15:11:24.0359 2536 PDRFRAME - ok 15:11:24.0359 2536 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys 15:11:24.0359 2536 perc2 - ok 15:11:24.0359 2536 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys 15:11:24.0359 2536 perc2hib - ok 15:11:24.0484 2536 [ F042EE4C8D66248D9B86DCF52ABAE416 ] PEVSystemStart C:\ComboFix\pev.3XE 15:11:24.0484 2536 PEVSystemStart - ok 15:11:24.0515 2536 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 15:11:24.0531 2536 PlugPlay - ok 15:11:24.0593 2536 [ 9D84376931440F3679BEEF2A414FA493 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe 15:11:24.0593 2536 Pml Driver HPZ12 - ok 15:11:24.0609 2536 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 15:11:24.0609 2536 PolicyAgent - ok 15:11:24.0671 2536 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:11:24.0671 2536 PptpMiniport - ok 15:11:24.0671 2536 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 15:11:24.0671 2536 ProtectedStorage - ok 15:11:24.0671 2536 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 15:11:24.0671 2536 PSched - ok 15:11:24.0718 2536 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:11:24.0718 2536 Ptilink - ok 15:11:24.0765 2536 [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 15:11:24.0765 2536 PxHelp20 - ok 15:11:24.0781 2536 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys 15:11:24.0781 2536 ql1080 - ok 15:11:24.0796 2536 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 15:11:24.0796 2536 Ql10wnt - ok 15:11:24.0796 2536 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys 15:11:24.0796 2536 ql12160 - ok 15:11:24.0796 2536 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys 15:11:24.0812 2536 ql1240 - ok 15:11:24.0828 2536 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys 15:11:24.0828 2536 ql1280 - ok 15:11:24.0859 2536 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:11:24.0859 2536 RasAcd - ok 15:11:24.0906 2536 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 15:11:24.0906 2536 RasAuto - ok 15:11:24.0937 2536 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:11:24.0937 2536 Rasl2tp - ok 15:11:24.0968 2536 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 15:11:24.0984 2536 RasMan - ok 15:11:24.0984 2536 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:11:24.0984 2536 RasPppoe - ok 15:11:24.0984 2536 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 15:11:24.0984 2536 Raspti - ok 15:11:25.0031 2536 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:11:25.0031 2536 Rdbss - ok 15:11:25.0046 2536 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:11:25.0046 2536 RDPCDD - ok 15:11:25.0046 2536 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 15:11:25.0046 2536 rdpdr - ok 15:11:25.0109 2536 [ 6589DB6E5969F8EEE594CF71171C5028 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 15:11:25.0109 2536 RDPWD - ok 15:11:25.0125 2536 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 15:11:25.0140 2536 RDSessMgr - ok 15:11:25.0171 2536 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 15:11:25.0171 2536 redbook - ok 15:11:25.0203 2536 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 15:11:25.0203 2536 RemoteAccess - ok 15:11:25.0234 2536 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 15:11:25.0234 2536 RemoteRegistry - ok 15:11:25.0281 2536 [ F17713D108ACA124A139FDE877EEF68A ] RimUsb C:\WINDOWS\system32\Drivers\RimUsb.sys 15:11:25.0281 2536 RimUsb - ok 15:11:25.0312 2536 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 15:11:25.0312 2536 RpcLocator - ok 15:11:25.0343 2536 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll 15:11:25.0359 2536 RpcSs - ok 15:11:25.0390 2536 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 15:11:25.0390 2536 RSVP - ok 15:11:25.0437 2536 [ 00FD6811350E175585ABCF7D4A61DD90 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 15:11:25.0437 2536 RTLE8023xp - ok 15:11:25.0484 2536 [ B9CA69921379EA2931C4450FE975BCE7 ] RTLVLAN C:\WINDOWS\system32\DRIVERS\RTLVLAN.SYS 15:11:25.0484 2536 RTLVLAN - ok 15:11:25.0500 2536 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 15:11:25.0515 2536 SamSs - ok 15:11:25.0531 2536 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 15:11:25.0531 2536 SCardSvr - ok 15:11:25.0578 2536 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 15:11:25.0578 2536 Schedule - ok 15:11:25.0640 2536 [ A1089AC7683826E6C7C9FAB9723DD80F ] sdAuxService C:\Program Files\PC Tools Security\pctsAuxs.exe 15:11:25.0656 2536 sdAuxService - ok 15:11:25.0734 2536 [ ED6C2EFEB47524BFF4D5E5109FB1A2BB ] sdCoreService C:\Program Files\PC Tools Security\pctsSvc.exe 15:11:25.0765 2536 sdCoreService - ok 15:11:25.0796 2536 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:11:25.0796 2536 Secdrv - ok 15:11:25.0843 2536 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 15:11:25.0843 2536 seclogon - ok 15:11:25.0859 2536 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 15:11:25.0859 2536 SENS - ok 15:11:25.0875 2536 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] Serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 15:11:25.0875 2536 Serenum - ok 15:11:25.0875 2536 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 15:11:25.0875 2536 Serial - ok 15:11:25.0937 2536 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 15:11:25.0937 2536 Sfloppy - ok 15:11:26.0000 2536 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 15:11:26.0000 2536 SharedAccess - ok 15:11:26.0046 2536 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 15:11:26.0062 2536 ShellHWDetection - ok 15:11:26.0062 2536 Simbad - ok 15:11:26.0062 2536 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys 15:11:26.0062 2536 sisagp - ok 15:11:26.0109 2536 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys 15:11:26.0109 2536 Sparrow - ok 15:11:26.0140 2536 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 15:11:26.0140 2536 splitter - ok 15:11:26.0187 2536 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 15:11:26.0187 2536 Spooler - ok 15:11:26.0250 2536 sprtsvc_dellsupportcenter - ok 15:11:26.0265 2536 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 15:11:26.0265 2536 sr - ok 15:11:26.0328 2536 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 15:11:26.0328 2536 srservice - ok 15:11:26.0328 2536 SRTSP - ok 15:11:26.0328 2536 SRTSPX - ok 15:11:26.0390 2536 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 15:11:26.0406 2536 Srv - ok 15:11:26.0437 2536 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 15:11:26.0437 2536 SSDPSRV - ok 15:11:26.0437 2536 SSPORT - ok 15:11:26.0453 2536 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 15:11:26.0468 2536 stisvc - ok 15:11:26.0500 2536 [ DE3E7A2345EBAA3CE8E6957DFB55FB15 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe 15:11:26.0500 2536 stllssvr - ok 15:11:26.0531 2536 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 15:11:26.0531 2536 swenum - ok 15:11:26.0531 2536 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 15:11:26.0531 2536 swmidi - ok 15:11:26.0546 2536 SwPrv - ok 15:11:26.0578 2536 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys 15:11:26.0593 2536 symc810 - ok 15:11:26.0609 2536 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys 15:11:26.0609 2536 symc8xx - ok 15:11:26.0609 2536 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys 15:11:26.0609 2536 sym_hi - ok 15:11:26.0625 2536 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys 15:11:26.0625 2536 sym_u3 - ok 15:11:26.0656 2536 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 15:11:26.0656 2536 sysaudio - ok 15:11:26.0687 2536 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 15:11:26.0703 2536 SysmonLog - ok 15:11:26.0734 2536 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 15:11:26.0734 2536 TapiSrv - ok 15:11:26.0812 2536 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:11:26.0812 2536 Tcpip - ok 15:11:26.0843 2536 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 15:11:26.0843 2536 TDPIPE - ok 15:11:26.0859 2536 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 15:11:26.0859 2536 TDTCP - ok 15:11:26.0890 2536 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 15:11:26.0890 2536 TermDD - ok 15:11:26.0890 2536 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 15:11:26.0906 2536 TermService - ok 15:11:26.0968 2536 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 15:11:26.0968 2536 Themes - ok 15:11:27.0000 2536 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 15:11:27.0000 2536 TlntSvr - ok 15:11:27.0015 2536 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys 15:11:27.0015 2536 TosIde - ok 15:11:27.0015 2536 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 15:11:27.0015 2536 TrkWks - ok 15:11:27.0031 2536 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 15:11:27.0031 2536 Udfs - ok 15:11:27.0062 2536 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys 15:11:27.0062 2536 ultra - ok 15:11:27.0078 2536 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 15:11:27.0078 2536 Update - ok 15:11:27.0109 2536 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 15:11:27.0109 2536 upnphost - ok 15:11:27.0140 2536 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 15:11:27.0140 2536 UPS - ok 15:11:27.0156 2536 [ EAFE1E00739AFE6C51487A050E772E17 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys 15:11:27.0156 2536 USBAAPL - ok 15:11:27.0187 2536 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:11:27.0187 2536 usbccgp - ok 15:11:27.0203 2536 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:11:27.0203 2536 usbehci - ok 15:11:27.0234 2536 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:11:27.0234 2536 usbhub - ok 15:11:27.0265 2536 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 15:11:27.0265 2536 usbprint - ok 15:11:27.0343 2536 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:11:27.0343 2536 usbscan - ok 15:11:27.0375 2536 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:11:27.0390 2536 USBSTOR - ok 15:11:27.0406 2536 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 15:11:27.0406 2536 usbuhci - ok 15:11:27.0421 2536 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 15:11:27.0421 2536 VgaSave - ok 15:11:27.0453 2536 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys 15:11:27.0453 2536 viaagp - ok 15:11:27.0468 2536 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 15:11:27.0468 2536 ViaIde - ok 15:11:27.0468 2536 vkquwexg - ok 15:11:27.0500 2536 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 15:11:27.0500 2536 VolSnap - ok 15:11:27.0546 2536 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 15:11:27.0546 2536 VSS - ok 15:11:27.0593 2536 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll 15:11:27.0593 2536 w32time - ok 15:11:27.0609 2536 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:11:27.0609 2536 Wanarp - ok 15:11:27.0609 2536 WDICA - ok 15:11:27.0625 2536 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 15:11:27.0625 2536 wdmaud - ok 15:11:27.0625 2536 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 15:11:27.0640 2536 WebClient - ok 15:11:27.0750 2536 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 15:11:27.0765 2536 winmgmt - ok 15:11:27.0812 2536 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll 15:11:27.0843 2536 WinRM - ok 15:11:27.0906 2536 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 15:11:27.0906 2536 WmdmPmSN - ok 15:11:27.0953 2536 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 15:11:27.0968 2536 Wmi - ok 15:11:28.0046 2536 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 15:11:28.0046 2536 WmiApSrv - ok 15:11:28.0140 2536 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 15:11:28.0156 2536 WMPNetworkSvc - ok 15:11:28.0187 2536 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 15:11:28.0187 2536 WpdUsb - ok 15:11:28.0234 2536 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys 15:11:28.0234 2536 WS2IFSL - ok 15:11:28.0296 2536 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 15:11:28.0296 2536 wscsvc - ok 15:11:28.0296 2536 WSearch - ok 15:11:28.0312 2536 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 15:11:28.0343 2536 wuauserv - ok 15:11:28.0375 2536 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 15:11:28.0375 2536 WudfPf - ok 15:11:28.0406 2536 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 15:11:28.0406 2536 WudfRd - ok 15:11:28.0437 2536 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 15:11:28.0437 2536 WudfSvc - ok 15:11:28.0453 2536 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 15:11:28.0468 2536 WZCSVC - ok 15:11:28.0500 2536 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 15:11:28.0515 2536 xmlprov - ok 15:11:28.0562 2536 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 15:11:28.0578 2536 YahooAUService - ok 15:11:28.0578 2536 ================ Scan global =============================== 15:11:28.0640 2536 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 15:11:28.0687 2536 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:11:28.0718 2536 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:11:28.0765 2536 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 15:11:28.0765 2536 [Global] - ok 15:11:28.0765 2536 ================ Scan MBR ================================== 15:11:28.0796 2536 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 15:11:28.0984 2536 \Device\Harddisk0\DR0 - ok 15:11:28.0984 2536 ================ Scan VBR ================================== 15:11:28.0984 2536 [ A94E45297EFAE204796C18230BFD3841 ] \Device\Harddisk0\DR0\Partition1 15:11:29.0000 2536 \Device\Harddisk0\DR0\Partition1 - ok 15:11:29.0000 2536 ============================================================ 15:11:29.0000 2536 Scan finished 15:11:29.0000 2536 ============================================================ 15:11:29.0000 2520 Detected object count: 0 15:11:29.0000 2520 Actual detected object count: 0 15:11:33.0031 0232 Deinitialize success
:thumbup: We go rid of a nasty one there.

Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.

Disable your AntiVirus and AntiSpyware applications.

Right-click and Run as Administrator on the Combofix.exe and follow the prombts on your display. When finish, it will create a C:\Combofix.txt. Please post this log for further review.
———
Thanks again Jeff. I'll be off the computer til tomorrow, but I followed your instructions from the last post. Here's the log:


ComboFix 12-08-22.03 - Administrator 08/23/2012 15:39:04.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3037.2446 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Office\Application Data\PriceGong
c:\documents and settings\Office\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\j.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\z.xml
c:\windows\system32\FlashPlayerInstaller.exe
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\lwGuXDuVJdJAFej.exe
c:\documents and settings\All Users\Application Data\NjvPDQr7hmWWRQ
c:\documents and settings\All Users\Application Data\NjvPDQr7hmWWRQ.exe
c:\documents and settings\All Users\Application Data\SEC323.tmp
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome.manifest
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\bar.xul
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\buttons.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\constants.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\events.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\globals.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\hosts.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\init.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_images.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_maps.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_news.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_videos.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\engine_web.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_amazon.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_ebay.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_facebook.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_games.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_msn.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_shopping.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_travel.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\icon_twitter.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\images\startnow_logo.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\installer.xml
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\chevron_button.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_button_hover.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_button_normal.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_dropdown_button_normal.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_background.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_left.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\searchbox_input_middle.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\separator.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\splitter.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ff_hover_c.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_c.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_l.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_hover_r.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_c.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_l.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\skin\toolbarbutton_ie_normal_r.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\content\resources\toolbar.xml
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\locale\en-US\{5911488E-9D1E-40ec-8CBB-06B231CC153F}.dtd
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\chrome\skin\overlay.css
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\components\tellSvc.dll
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}\install.rdf
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\searchplugins\bing-zugo.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Office\g2ax_customer_downloadhelper_win32_x86.exe
c:\documents and settings\Office\Local Settings\Application Data\I Want This\Chrome\I Want This.crx
c:\program files\I Want This\I Want This.dll
c:\program files\I Want This\I Want This.exe
c:\program files\I Want This\I Want This.ico
c:\program files\I Want This\I Want This.ini
c:\program files\I Want This\I Want ThisGui.exe
c:\program files\I Want This\I Want ThisInstaller.log
c:\program files\I Want This\Uninstall.exe
c:\program files\StartNow Toolbar\ReactivateFF.exe
c:\program files\StartNow Toolbar\ReactivateIE.exe
c:\program files\StartNow Toolbar\Resources\images\engine_images.png
c:\program files\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files\StartNow Toolbar\Resources\images\engine_news.png
c:\program files\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files\StartNow Toolbar\Resources\images\engine_web.png
c:\program files\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files\StartNow Toolbar\Resources\images\icon_games.png
c:\program files\StartNow Toolbar\Resources\images\icon_msn.png
c:\program files\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files\StartNow Toolbar\Resources\installer.xml
c:\program files\StartNow Toolbar\Resources\skin\chevron_button.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_hover.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_dropdown_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_background.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_left.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_middle.png
c:\program files\StartNow Toolbar\Resources\skin\separator.png
c:\program files\StartNow Toolbar\Resources\skin\splitter.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ff_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_r.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_r.png
c:\program files\StartNow Toolbar\Resources\toolbar.xml
c:\program files\StartNow Toolbar\Resources\update.xml
c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files\StartNow Toolbar\Toolbar32.dll
c:\program files\StartNow Toolbar\ToolbarBroker.exe
c:\program files\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files\StartNow Toolbar\uninstall.dat
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
– Previous Run –
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
——–
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Service_Updater Service for StartNow Toolbar
——-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2012-07-23 to 2012-08-23 )))))))))))))))))))))))))))))))
.
.
2012-08-23 19:05 . 2012-08-23 19:05 ——– d—–w- C:\TDSSKiller_Quarantine
2012-08-23 15:34 . 2012-08-01 22:51 7023536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5B29BAA6-E6DF-4B83-B8B5-D1F92171B19D}\mpengine.dll
2012-08-22 15:21 . 2012-08-01 22:51 7023536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-17 17:58 . 2012-08-23 18:00 559128 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2012-07-27 20:51 . 2012-07-27 20:51 184248 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-07-27 00:10 . 2012-07-31 20:32 ——– d–h–w- c:\documents and settings\Office\Application Data\Apple Computer
2012-07-27 00:10 . 2012-07-27 00:10 ——– d–h–w- c:\documents and settings\Office\Local Settings\Application Data\Apple Computer
2012-07-27 00:10 . 2009-05-18 17:17 26600 —ha-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-07-27 00:10 . 2008-04-17 16:12 107368 —ha-w- c:\windows\system32\GEARAspi.dll
2012-07-27 00:09 . 2012-07-27 00:09 ——– d–h–w- c:\program files\iPod
2012-07-27 00:09 . 2012-07-27 00:10 ——– d–h–w- c:\program files\iTunes
2012-07-27 00:09 . 2012-07-27 00:10 ——– d–h–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-07-27 00:09 . 2012-07-27 00:09 ——– d–h–w- c:\documents and settings\All Users\Application Data\Apple Computer
2012-07-27 00:09 . 2012-07-27 00:09 ——– d–h–w- c:\documents and settings\Office\Local Settings\Application Data\Apple
2012-07-27 00:09 . 2012-07-27 00:09 ——– d–h–w- c:\program files\Apple Software Update
2012-07-27 00:09 . 2012-07-27 00:09 ——– d–h–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2012-07-27 00:09 . 2012-04-25 16:11 4547944 —ha-w- c:\windows\system32\usbaaplrc.dll
2012-07-27 00:09 . 2012-04-25 16:11 43520 —ha-w- c:\windows\system32\drivers\usbaapl.sys
2012-07-27 00:08 . 2012-07-27 00:08 ——– d–h–w- c:\program files\Bonjour
2012-07-27 00:08 . 2012-07-27 00:09 ——– d–h–w- c:\program files\Common Files\Apple
2012-07-27 00:08 . 2012-07-27 00:09 ——– d–h–w- c:\documents and settings\All Users\Application Data\Apple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 18:07 . 2012-05-09 18:29 426184 —ha-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-02 18:07 . 2011-05-16 14:10 70344 —ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 17:46 . 2011-12-30 17:48 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-06-13 13:29 . 2008-04-25 16:16 1875072 —ha-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-04-25 16:16 1372672 —ha-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-25 16:16 1172480 —ha-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-25 16:16 152576 —ha-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2008-10-16 18:09 22040 —ha-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2008-10-16 18:07 15384 —ha-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2008-04-25 21:27 329240 —ha-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2008-04-25 21:27 219160 —ha-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2008-04-25 21:27 210968 —ha-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2008-10-16 18:09 45080 -c-ha-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2008-10-16 18:07 15384 —ha-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 53784 —ha-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2008-04-25 21:27 35864 —ha-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-25 16:16 97304 —ha-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2008-10-16 18:07 17944 —ha-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 577048 —ha-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2008-04-25 21:27 1933848 —ha-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-03-19 17:09 275696 —ha-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-03-19 17:09 214256 —ha-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-03-19 17:09 17136 —ha-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2008-04-25 16:16 599040 —ha-w- c:\windows\system32\crypt32.dll
2012-07-23 19:13 . 2011-06-18 17:09 136672 —ha-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}]
2011-05-09 09:49 176936 —ha-w- c:\program files\Free_TV_Bar_c3\prxtbFre2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}"= "c:\program files\Free_TV_Bar_c3\prxtbFre2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 150040]
"8169Diag"="c:\program files\Realtek\Diagnostics Utility\8169Diag.exe" [2008-02-26 909312]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-09 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"STO Backup Service"="c:\program files\SmarThru Office\BackUpSvr.exe" [2009-07-01 184320]
"STO Launcher Service"="c:\program files\SmarThru Office\LegacyLauncher.exe" [2009-07-01 331776]
"Dell PanelMgr"="c:\windows\Dell\PanelMgr\SSMMgr.exe" [2009-05-18 541936]
"1235cn Scan2PC"="c:\windows\twain_32\DELL\DELL1235\Scan2Pc.exe" [2008-09-26 495616]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\documents and settings\Office\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-08-18 22:19 57344 —ha-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-08-18 22:20 16806912 —ha-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Sscan2io.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\ScanMgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/11/2011 2:22 PM 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/11/2011 2:22 PM 338880]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [6/15/2011 6:33 PM 249648]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [6/29/2009 7:26 PM 110080]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S0 43405483;43405483;c:\windows\system32\drivers\34552256.sys –> c:\windows\system32\drivers\34552256.sys [?]
S1 nmvowknv;nmvowknv;\??\c:\windows\system32\drivers\nmvowknv.sys –> c:\windows\system32\drivers\nmvowknv.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [6/29/2009 3:39 PM 8960]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/9/2012 2:29 PM 250056]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [7/7/2011 8:31 PM 195336]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [6/29/2009 3:39 PM 11264]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/3/2012 12:35 AM 40776]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/9/2012 2:25 PM 113120]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [6/29/2009 3:39 PM 16640]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [5/11/2011 2:22 PM 366840]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 31522952
*Deregistered* - 31522952
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 18:07]
.
2012-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-23 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-08-23 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
.
2012-07-25 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-10-27 16:39]
.
2012-08-23 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-05-22 02:19]
.
2012-08-23 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-10-27 16:40]
.
.
——- Supplementary Scan ——-
.
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\Superfish\Special Savings\SpecialSavings.dll
TCP: DhcpNameServer = 192.168.1.1
DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} - hxxp://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CAB
FF - ProfilePath - c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109935&babsrc=KW_ss&mntrId=5ec20cca0000000000000024e80fcfe9&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109935
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 5ec20cca0000000000000024e80fcfe9
FF - user.js: extensions.BabylonToolbar_i.hardId - 5ec20cca0000000000000024e80fcfe9
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15482
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1711:30
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-lwGuXDuVJdJAFej.exe - c:\documents and settings\All Users\Application Data\lwGuXDuVJdJAFej.exe
SafeBoot-43405483.sys
MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
AddRemove-I Want This - c:\program files\I Want This\Uninstall.exe
AddRemove-StartNow Toolbar - c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-23 15:44
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-08-23 15:47:30
ComboFix-quarantined-files.txt 2012-08-23 19:47
.
Pre-Run: 213,909,901,312 bytes free
Post-Run: 213,936,861,184 bytes free
.
- - End Of File - - 8F3F522CDD1DE024665DCE015C8466CC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI