This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possibly infected [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

XP computer won't stay connected in normal mode. I'm running in Safe Mode now. . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 12:45:22 on 2012-08-30 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.203 [GMT -5:00] . AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\mfevtps.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\WINDOWS\system32\rundll32.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\ctfmon.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\2Wire\2PortalMon.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\VTTimer.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\HP\KBD\KBD.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\ALCXMNTR.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe c:\PROGRA~1\mcafee\SITEAD~1\saui.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\McAfee\VirusScan\mcods.exe C:\WINDOWS\system32\ipconfig.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://att.yahoo.com uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uSearch Bar = hxxp://www.yahoo.com/search/ie.html uSEARCH PAGE = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com mDefault_Page_URL = hxxp://att.yahoo.com mSearch Page = mStart Page = hxxp://att.yahoo.com mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop uInternet Settings,ProxyOverride = 127.0.0.1 uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20120829220454.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [2wSysTray] c:\program files\2wire\2PortalMon.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Zone Labs Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe mRun: [VTTimer] VTTimer.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [MsgCenterExe] "c:\program files\common files\real\update_ob\RealOneMessageCenter.exe" -osboot mRun: [Motive SmartBridge] c:\progra~1\sbcsel~1\smartb~1\MotiveSB.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [iTunesHelper] c:\program files\itunes\iTunesHelper.exe mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [AlcxMonitor] ALCXMNTR.EXE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\at&tse~1.lnk - c:\program files\sbc self support tool\bin\matcli.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1346272295078 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164406261484 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{BEC2432F-43EB-49BD-A650-9A91D963025D} : DhcpNameServer = [removed] [removed] Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\mrook2ld.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/ FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll FF - plugin: c:\program files\mcafee\supportability\mvt\NPMVTPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\openoffice.org 3\program\npsoplugin.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_271.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-20 64288] R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-2-28 464304] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-2-28 89792] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-29 655944] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-1-22 95200] R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-28 214904] R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-28 214904] R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-28 214904] R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-2-28 166288] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-2-28 161632] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-2-28 151880] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-2-28 57600] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-29 22344] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-2-28 180848] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-2-28 59456] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-2-28 340920] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-2-28 83856] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-2-28 87656] S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\admini~1\locals~1\temp\001542~1.exe -cleanup -nolog –> c:\docume~1\admini~1\locals~1\temp\001542~1.EXE -cleanup -nolog [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-7-15 250056] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-2-28 83856] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-8 113120] . =============== Created Last 30 ================ . 2012-08-29 22:41:53 ——– d—–w- c:\documents and settings\compaq_owner\application data\Malwarebytes 2012-08-29 21:20:32 ——– d—–w- c:\documents and settings\compaq_owner\application data\McAfee 2012-08-29 19:49:03 ——– d—–w- c:\program files\SUPERAntiSpyware 2012-08-29 19:49:03 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com 2012-08-29 18:58:50 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2012-08-29 18:58:49 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-29 18:58:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-08-28 00:29:35 ——– d—–w- c:\program files\AVAST Software 2012-08-28 00:29:35 ——– d—–w- c:\documents and settings\all users\application data\AVAST Software 2012-08-27 15:23:47 ——– d—–w- c:\documents and settings\compaq_owner\DoctorWeb 2012-08-17 20:43:15 9826504 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe . ==================== Find3M ==================== . 2012-08-17 20:43:36 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-17 20:43:35 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-06 13:58:51 78336 —-a-w- c:\windows\system32\browser.dll 2012-07-04 14:05:18 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-07-03 15:07:44 832512 —-a-w- c:\windows\system32\wininet.dll 2012-07-03 15:07:43 1830912 —-a-w- c:\windows\system32\inetcpl.cpl 2012-07-03 15:07:42 78336 —-a-w- c:\windows\system32\ieencode.dll 2012-07-03 15:07:42 17408 ——w- c:\windows\system32\corpol.dll 2012-07-03 13:40:15 1866112 —-a-w- c:\windows\system32\win32k.sys 2012-06-05 15:50:25 1372672 —-a-w- c:\windows\system32\msxml6.dll 2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll 2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 20:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 20:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 20:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 20:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 20:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui 2012-06-02 20:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll 2012-06-02 20:18:58 214256 —-a-w- c:\windows\system32\muweb.dll 2012-06-02 20:18:58 17136 —-a-w- c:\windows\system32\mucltui.dll.mui 2005-02-16 17:06:00 218112 -c–a-w- c:\program files\HijackThis.exe . ============= FINISH: 12:46:40.90 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-


Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-30 14:08:55 —————————– 14:08:55.906 OS Version: Windows 5.1.2600 Service Pack 3 14:08:55.906 Number of processors: 1 586 0xA00 14:08:55.906 ComputerName: YOUR-22CA86D5C4 UserName: Administrator 14:08:56.421 Initialize success 14:10:02.203 AVAST engine defs: 12083000 14:10:12.656 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12 14:10:12.656 Disk 0 Vendor: SAMSUNG_SP1203N TL100-24 Size: 114498MB BusType: 3 14:10:12.687 Disk 0 MBR read successfully 14:10:12.687 Disk 0 MBR scan 14:10:12.718 Disk 0 unknown MBR code 14:10:12.734 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 114492 MB offset 63 14:10:12.734 Disk 0 scanning sectors +234480960 14:10:12.859 Disk 0 scanning C:\WINDOWS\system32\drivers 14:10:27.218 Service scanning 14:11:09.078 Modules scanning 14:11:26.187 Disk 0 trace - called modules: 14:11:26.234 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS 14:11:26.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8574bab8] 14:11:27.015 3 CLASSPNP.SYS[f75cffd7] -> nt!IofCallDriver -> \Device\0000006e[0x857439e8] 14:11:27.031 5 ACPI.sys[f7526620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-12[0x8574ed98] 14:11:27.328 AVAST engine scan C:\WINDOWS 14:11:45.203 AVAST engine scan C:\WINDOWS\system32 14:14:29.828 AVAST engine scan C:\WINDOWS\system32\drivers 14:14:51.921 AVAST engine scan C:\Documents and Settings\Administrator 14:15:17.750 AVAST engine scan C:\Documents and Settings\All Users 14:16:11.843 Scan finished successfully 14:16:33.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat" 14:16:33.812 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"
Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.
———-
ComboFix 12-08-30.04 - Administrator 08/30/2012 14:40:53.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.600 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Compaq_Owner\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\windows\patch.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\FlashPlayerInstaller.exe
c:\windows\system32\ps2.bat
c:\windows\system32\SETE8.tmp
c:\windows\system32\SETE9.tmp
c:\windows\system32\SETED.tmp
c:\windows\system32\SETEE.tmp
c:\windows\system32\SETF5.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\unicows.1
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-30 )))))))))))))))))))))))))))))))
.
.
2012-08-29 19:49 . 2012-08-29 19:49 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-08-29 19:49 . 2012-08-29 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-29 18:58 . 2012-07-03 18:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 00:29 . 2012-08-29 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-08-28 00:29 . 2012-08-28 00:29 ——– d—–w- c:\program files\AVAST Software
2012-08-27 15:23 . 2012-08-27 15:23 ——– d—–w- c:\documents and settings\Compaq_Owner\DoctorWeb
2012-08-21 21:30 . 2012-08-30 19:45 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-17 20:43 . 2012-07-15 12:33 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 20:43 . 2012-02-15 21:16 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2004-08-09 05:41 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 15:07 . 2004-08-09 04:28 832512 —-a-w- c:\windows\system32\wininet.dll
2012-07-03 15:07 . 2004-08-09 04:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-07-03 15:07 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-07-03 15:07 . 2004-08-09 04:28 17408 ——w- c:\windows\system32\corpol.dll
2012-07-03 13:40 . 2004-08-09 04:28 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-08-22 22:48 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-09 04:28 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 22:35 . 2004-08-09 05:43 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-04 04:32 . 2004-08-09 04:28 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2007-06-21 22:34 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2007-06-21 22:34 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2004-08-09 05:43 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2004-08-09 05:43 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2007-06-21 22:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2005-05-26 09:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2005-01-29 10:45 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2004-08-09 05:43 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2004-08-09 04:28 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2007-06-21 22:34 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2004-08-09 05:43 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2004-08-09 05:43 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 20:18 . 2007-06-22 16:20 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 20:18 . 2006-11-28 19:26 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18 . 2005-05-26 10:19 214256 —-a-w- c:\windows\system32\muweb.dll
2005-02-16 17:06 . 2006-11-25 03:30 218112 -c–a-w- c:\program files\HijackThis.exe
2012-07-19 00:00 . 2012-03-24 01:43 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-02-28 22:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 4777856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"2wSysTray"="c:\program files\2Wire\2PortalMon.exe" [2004-09-15 393216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1318816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"VTTimer"="VTTimer.exe" [2004-01-16 49152]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2007-6-17 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 19:30 98304 -c–a-w- c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-01 03:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/20/2009 7:31 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/28/2011 5:21 PM 89792]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [2/28/2011 5:21 PM 161632]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2/28/2011 5:21 PM 151880]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/28/2011 5:21 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/29/2012 1:58 PM 655944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/22/2009 12:51 PM 95200]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/15/2012 7:33 AM 250056]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/28/2011 5:21 PM 57600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/29/2012 1:58 PM 22344]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/28/2011 5:21 PM 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/8/2012 11:38 AM 113120]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 20:43]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://att.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://att.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jda7ze27.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/?fr=yfp-t-403
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
HKLM-Run-Zone Labs Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
HKLM-Run-YBrowser - c:\progra~1\Yahoo!\browser\ybrwicon.exe
HKLM-Run-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
HKLM-Run-MsgCenterExe - c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
AddRemove-HijackThis - c:\docume~1\COMPAQ~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
AddRemove-SBC Yahoo! UMUninstaller - c:\program files\SBC Yahoo!\umuninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-30 14:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(876)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2012-08-30 14:48:10
ComboFix-quarantined-files.txt 2012-08-30 19:48
.
Pre-Run: 96,935,829,504 bytes free
Post-Run: 97,036,156,928 bytes free
.
- - End Of File - - C61D8ABDF6A35319FE608E43A333FE66
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    ClearJavaCache::

    DDS::
    uSEARCH PAGE = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    mRun: [AlcxMonitor] ALCXMNTR.EXE

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Jeff, I have a dentist appt. and will have to be gone for about an hour or so. I will continue your instructions when I return. Thanks for your help!
ComboFix 12-08-30.05 - Administrator 08/30/2012 16:43:09.2.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.553 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-30 )))))))))))))))))))))))))))))))
.
.
2012-08-29 19:49 . 2012-08-29 19:49 ——– d—–w- c:\program files\SUPERAntiSpyware
2012-08-29 19:49 . 2012-08-29 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-29 18:58 . 2012-07-03 18:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 00:29 . 2012-08-29 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-08-28 00:29 . 2012-08-28 00:29 ——– d—–w- c:\program files\AVAST Software
2012-08-27 15:23 . 2012-08-27 15:23 ——– d—–w- c:\documents and settings\Compaq_Owner\DoctorWeb
2012-08-21 21:30 . 2012-08-30 19:45 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-17 20:43 . 2012-07-15 12:33 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 20:43 . 2012-02-15 21:16 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2004-08-09 05:41 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 15:07 . 2004-08-09 04:28 832512 —-a-w- c:\windows\system32\wininet.dll
2012-07-03 15:07 . 2004-08-09 04:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-07-03 15:07 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-07-03 15:07 . 2004-08-09 04:28 17408 ——w- c:\windows\system32\corpol.dll
2012-07-03 13:40 . 2004-08-09 04:28 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-08-22 22:48 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-09 04:28 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 22:35 . 2004-08-09 05:43 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-04 04:32 . 2004-08-09 04:28 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2007-06-21 22:34 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2007-06-21 22:34 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2004-08-09 05:43 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2004-08-09 05:43 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2007-06-21 22:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2005-05-26 09:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2005-01-29 10:45 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2004-08-09 05:43 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2004-08-09 04:28 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2007-06-21 22:34 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2004-08-09 05:43 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2004-08-09 05:43 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 20:18 . 2007-06-22 16:20 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 20:18 . 2006-11-28 19:26 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18 . 2005-05-26 10:19 214256 —-a-w- c:\windows\system32\muweb.dll
2005-02-16 17:06 . 2006-11-25 03:30 218112 -c–a-w- c:\program files\HijackThis.exe
2012-07-19 00:00 . 2012-03-24 01:43 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-02-28 22:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 4777856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"2wSysTray"="c:\program files\2Wire\2PortalMon.exe" [2004-09-15 393216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1318816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"VTTimer"="VTTimer.exe" [2004-01-16 49152]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2007-6-17 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 19:30 98304 -c–a-w- c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-01 03:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/20/2009 7:31 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/28/2011 5:21 PM 89792]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [2/28/2011 5:21 PM 161632]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2/28/2011 5:21 PM 151880]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/28/2011 5:21 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/29/2012 1:58 PM 655944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/22/2009 12:51 PM 95200]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/15/2012 7:33 AM 250056]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/28/2011 5:21 PM 57600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/29/2012 1:58 PM 22344]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/28/2011 5:21 PM 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/8/2012 11:38 AM 113120]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 20:43]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://att.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://att.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jda7ze27.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/?fr=yfp-t-403
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-30 16:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(876)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1660)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2012-08-30 16:50:57
ComboFix-quarantined-files.txt 2012-08-30 21:50
ComboFix2.txt 2012-08-30 19:48
.
Pre-Run: 97,046,233,088 bytes free
Post-Run: 97,026,973,696 bytes free
.
- - End Of File - - D1943377EA07254211D5BC9FD69232FB
Hi,

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-


I see that your Java software is out of date. Please go to Start >> Control Panel >> Add/Remove Programs >> delete all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-
Here is the Malwarebytes scan results. I will run the ESET scan next. Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.31.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 7.0.5730.11 Compaq_Owner :: YOUR-22CA86D5C4 [administrator] Protection: Enabled 8/31/2012 9:17:02 AM mbam-log-2012-08-31 (09-17-02).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 220039 Time elapsed: 19 minute(s), 32 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
I downloaded and ran TDS SKiller.EXE and no threats were found. 14:06:48.0187 1724 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 14:06:49.0187 1724 ============================================================ 14:06:49.0187 1724 Current date / time: 2012/08/31 14:06:49.0187 14:06:49.0187 1724 SystemInfo: 14:06:49.0187 1724 14:06:49.0187 1724 OS Version: 5.1.2600 ServicePack: 3.0 14:06:49.0187 1724 Product type: Workstation 14:06:49.0203 1724 ComputerName: YOUR-22CA86D5C4 14:06:49.0203 1724 UserName: Compaq_Owner 14:06:49.0203 1724 Windows directory: C:\WINDOWS 14:06:49.0203 1724 System windows directory: C:\WINDOWS 14:06:49.0203 1724 Processor architecture: Intel x86 14:06:49.0203 1724 Number of processors: 1 14:06:49.0203 1724 Page size: 0x1000 14:06:49.0203 1724 Boot type: Safe boot with network 14:06:49.0203 1724 ============================================================ 14:06:50.0828 1724 Drive \Device\Harddisk0\DR0 - Size: 0x1BF4290000 (111.82 Gb), SectorSize: 0x200, Cylinders: 0x3C94, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054 14:06:51.0000 1724 ============================================================ 14:06:51.0000 1724 \Device\Harddisk0\DR0: 14:06:51.0000 1724 MBR partitions: 14:06:51.0000 1724 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xDF9E501 14:06:51.0000 1724 ============================================================ 14:06:51.0031 1724 C: <-> \Device\Harddisk0\DR0\Partition1 14:06:51.0031 1724 ============================================================ 14:06:51.0031 1724 Initialize success 14:06:51.0031 1724 ============================================================ 14:06:54.0578 1096 ============================================================ 14:06:54.0578 1096 Scan started 14:06:54.0578 1096 Mode: Manual; 14:06:54.0578 1096 ============================================================ 14:06:56.0609 1096 ================ Scan system memory ======================== 14:06:56.0609 1096 System memory - ok 14:06:56.0625 1096 ================ Scan services ============================= 14:06:56.0734 1096 [ C0393EB99A6C72C6BEF9BFC4A72B33A6 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE 14:06:56.0750 1096 !SASCORE - ok 14:06:57.0031 1096 0015421346290574mcinstcleanup - ok 14:06:57.0218 1096 [ 6551C1CF190DF3E12C435A085987FBA0 ] 2WIREPCP C:\WINDOWS\system32\DRIVERS\2WirePCP.sys 14:06:57.0234 1096 2WIREPCP - ok 14:06:57.0265 1096 Abiosdsk - ok 14:06:57.0296 1096 abp480n5 - ok 14:06:57.0375 1096 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 14:06:57.0375 1096 ACPI - ok 14:06:57.0437 1096 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 14:06:57.0437 1096 ACPIEC - ok 14:06:57.0546 1096 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 14:06:57.0546 1096 AdobeFlashPlayerUpdateSvc - ok 14:06:57.0578 1096 adpu160m - ok 14:06:57.0656 1096 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 14:06:57.0656 1096 aec - ok 14:06:57.0718 1096 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 14:06:57.0718 1096 AFD - ok 14:06:57.0843 1096 [ 029E01CB2938BEC5AF31BF47B6AF0159 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys 14:06:57.0859 1096 AgereSoftModem - ok 14:06:57.0890 1096 Aha154x - ok 14:06:57.0921 1096 aic78u2 - ok 14:06:57.0984 1096 aic78xx - ok 14:06:58.0046 1096 [ FBBCB95F677CBAA924140B6EA2D9A97B ] ALCXSENS C:\WINDOWS\system32\drivers\ALCXSENS.SYS 14:06:58.0062 1096 ALCXSENS - ok 14:06:58.0203 1096 [ 8D6C30E515717248E0E52B85FD7AC466 ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS 14:06:58.0234 1096 ALCXWDM - ok 14:06:58.0281 1096 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 14:06:58.0296 1096 Alerter - ok 14:06:58.0343 1096 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 14:06:58.0343 1096 ALG - ok 14:06:58.0390 1096 AliIde - ok 14:06:58.0484 1096 [ 8FCE268CDBDD83B23419D1F35F42C7B1 ] AmdK7 C:\WINDOWS\system32\DRIVERS\amdk7.sys 14:06:58.0484 1096 AmdK7 - ok 14:06:58.0531 1096 amsint - ok 14:06:58.0562 1096 AppMgmt - ok 14:06:58.0625 1096 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys 14:06:58.0625 1096 Arp1394 - ok 14:06:58.0656 1096 asc - ok 14:06:58.0703 1096 asc3350p - ok 14:06:58.0734 1096 asc3550 - ok 14:06:58.0937 1096 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe 14:06:58.0937 1096 aspnet_state - ok 14:06:59.0000 1096 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 14:06:59.0000 1096 AsyncMac - ok 14:06:59.0046 1096 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 14:06:59.0046 1096 atapi - ok 14:06:59.0078 1096 Atdisk - ok 14:06:59.0125 1096 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 14:06:59.0125 1096 Atmarpc - ok 14:06:59.0187 1096 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 14:06:59.0187 1096 AudioSrv - ok 14:06:59.0250 1096 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 14:06:59.0250 1096 audstub - ok 14:06:59.0359 1096 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 14:06:59.0359 1096 Beep - ok 14:06:59.0453 1096 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 14:06:59.0546 1096 BITS - ok 14:06:59.0609 1096 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 14:06:59.0609 1096 Browser - ok 14:06:59.0640 1096 catchme - ok 14:06:59.0703 1096 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 14:06:59.0703 1096 cbidf2k - ok 14:06:59.0734 1096 cd20xrnt - ok 14:06:59.0796 1096 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 14:06:59.0796 1096 Cdaudio - ok 14:06:59.0859 1096 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 14:06:59.0859 1096 Cdfs - ok 14:06:59.0906 1096 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 14:06:59.0906 1096 Cdrom - ok 14:06:59.0968 1096 [ 1C7B1E36F3CED9E4B0B13385E627FE8B ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys 14:06:59.0968 1096 cfwids - ok 14:07:00.0000 1096 Changer - ok 14:07:00.0062 1096 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 14:07:00.0062 1096 CiSvc - ok 14:07:00.0109 1096 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 14:07:00.0109 1096 ClipSrv - ok 14:07:00.0156 1096 CmdIde - ok 14:07:00.0187 1096 COMSysApp - ok 14:07:00.0296 1096 [ 6BE1D6403727BDD8A2B2568DBE6BFB8B ] CO_Mon C:\WINDOWS\system32\Drivers\CO_Mon.sys 14:07:00.0296 1096 CO_Mon - ok 14:07:00.0328 1096 Cpqarray - ok 14:07:00.0390 1096 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 14:07:00.0390 1096 CryptSvc - ok 14:07:00.0421 1096 dac2w2k - ok 14:07:00.0468 1096 dac960nt - ok 14:07:00.0562 1096 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 14:07:00.0578 1096 DcomLaunch - ok 14:07:00.0656 1096 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 14:07:00.0671 1096 Dhcp - ok 14:07:00.0734 1096 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 14:07:00.0734 1096 Disk - ok 14:07:00.0750 1096 dmadmin - ok 14:07:00.0828 1096 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 14:07:00.0859 1096 dmboot - ok 14:07:00.0906 1096 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 14:07:00.0906 1096 dmio - ok 14:07:00.0953 1096 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 14:07:00.0953 1096 dmload - ok 14:07:01.0015 1096 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 14:07:01.0015 1096 dmserver - ok 14:07:01.0078 1096 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 14:07:01.0078 1096 DMusic - ok 14:07:01.0140 1096 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 14:07:01.0140 1096 Dnscache - ok 14:07:01.0187 1096 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 14:07:01.0187 1096 Dot3svc - ok 14:07:01.0218 1096 dpti2o - ok 14:07:01.0265 1096 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 14:07:01.0265 1096 drmkaud - ok 14:07:01.0312 1096 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 14:07:01.0312 1096 EapHost - ok 14:07:01.0359 1096 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 14:07:01.0359 1096 ERSvc - ok 14:07:01.0421 1096 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 14:07:01.0421 1096 Eventlog - ok 14:07:01.0500 1096 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 14:07:01.0515 1096 EventSystem - ok 14:07:01.0578 1096 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 14:07:01.0578 1096 Fastfat - ok 14:07:01.0640 1096 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 14:07:01.0640 1096 FastUserSwitchingCompatibility - ok 14:07:01.0734 1096 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe 14:07:01.0765 1096 Fax - ok 14:07:01.0828 1096 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 14:07:01.0828 1096 Fdc - ok 14:07:01.0921 1096 [ CFC4CC73C903152A23E1DB28EABA1F03 ] FETND5BV C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys 14:07:01.0921 1096 FETND5BV - ok 14:07:01.0984 1096 [ E9648254056BCE81A85380C0C3647DC4 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5.sys 14:07:01.0984 1096 FETNDIS - ok 14:07:02.0031 1096 [ B7186B33B6CF3A23841015531E6E7D68 ] FETNDISB C:\WINDOWS\system32\DRIVERS\fetnd5b.sys 14:07:02.0031 1096 FETNDISB - ok 14:07:02.0078 1096 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 14:07:02.0078 1096 Fips - ok 14:07:02.0140 1096 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 14:07:02.0140 1096 Flpydisk - ok 14:07:02.0218 1096 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 14:07:02.0218 1096 FltMgr - ok 14:07:02.0281 1096 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 14:07:02.0281 1096 Fs_Rec - ok 14:07:02.0343 1096 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 14:07:02.0343 1096 Ftdisk - ok 14:07:02.0406 1096 [ 2FB04DB459C71F416EE8B05448CA4AC3 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 14:07:02.0406 1096 GEARAspiWDM - ok 14:07:02.0468 1096 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 14:07:02.0468 1096 Gpc - ok 14:07:02.0578 1096 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 14:07:02.0593 1096 gupdate - ok 14:07:02.0625 1096 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 14:07:02.0625 1096 gupdatem - ok 14:07:02.0703 1096 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 14:07:02.0750 1096 gusvc - ok 14:07:02.0890 1096 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 14:07:02.0890 1096 helpsvc - ok 14:07:02.0953 1096 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 14:07:02.0953 1096 HidServ - ok 14:07:03.0031 1096 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 14:07:03.0031 1096 HidUsb - ok 14:07:03.0078 1096 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 14:07:03.0078 1096 hkmsvc - ok 14:07:03.0109 1096 hpn - ok 14:07:03.0140 1096 [ 5FABA4775D4C61E55EC669D643FFC71F ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys 14:07:03.0140 1096 HPZid412 - ok 14:07:03.0171 1096 [ A3C43980EE1F1BEAC778B44EA65DBDD4 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 14:07:03.0171 1096 HPZipr12 - ok 14:07:03.0234 1096 [ 2906949BD4E206F2BB0DD1896CE9F66F ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys 14:07:03.0234 1096 HPZius12 - ok 14:07:03.0312 1096 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 14:07:03.0328 1096 HTTP - ok 14:07:03.0390 1096 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 14:07:03.0390 1096 HTTPFilter - ok 14:07:03.0421 1096 i2omgmt - ok 14:07:03.0453 1096 i2omp - ok 14:07:03.0515 1096 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 14:07:03.0515 1096 i8042prt - ok 14:07:03.0593 1096 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 14:07:03.0593 1096 Imapi - ok 14:07:03.0671 1096 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 14:07:03.0671 1096 ImapiService - ok 14:07:03.0734 1096 ini910u - ok 14:07:03.0796 1096 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 14:07:03.0796 1096 IntelIde - ok 14:07:03.0843 1096 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 14:07:03.0843 1096 intelppm - ok 14:07:03.0890 1096 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 14:07:03.0890 1096 Ip6Fw - ok 14:07:03.0921 1096 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 14:07:03.0921 1096 IpFilterDriver - ok 14:07:03.0968 1096 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 14:07:03.0968 1096 IpInIp - ok 14:07:04.0031 1096 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 14:07:04.0031 1096 IpNat - ok 14:07:04.0109 1096 [ 3AC9F355ECCE7D6BB8FF184E9B2229A9 ] iPodService C:\Program Files\iPod\bin\iPodService.exe 14:07:04.0140 1096 iPodService - ok 14:07:04.0187 1096 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 14:07:04.0187 1096 IPSec - ok 14:07:04.0218 1096 IPVNMon - ok 14:07:04.0281 1096 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 14:07:04.0281 1096 IRENUM - ok 14:07:04.0343 1096 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 14:07:04.0359 1096 isapnp - ok 14:07:04.0531 1096 [ 80F08F50D248EEEEB9256F6522891D40 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 14:07:04.0531 1096 JavaQuickStarterService - ok 14:07:04.0593 1096 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 14:07:04.0593 1096 Kbdclass - ok 14:07:04.0656 1096 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 14:07:04.0656 1096 kmixer - ok 14:07:04.0750 1096 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 14:07:04.0750 1096 KSecDD - ok 14:07:04.0812 1096 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 14:07:04.0828 1096 lanmanserver - ok 14:07:04.0890 1096 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 14:07:04.0906 1096 lanmanworkstation - ok 14:07:04.0937 1096 Lavasoft Kernexplorer - ok 14:07:05.0000 1096 [ B7C19EC8B0DD7EFA58AD41FFEB8B8CDA ] Lbd C:\WINDOWS\system32\DRIVERS\Lbd.sys 14:07:05.0000 1096 Lbd - ok 14:07:05.0046 1096 lbrtfdc - ok 14:07:05.0156 1096 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 14:07:05.0156 1096 LmHosts - ok 14:07:05.0218 1096 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 14:07:05.0218 1096 MBAMProtector - ok 14:07:05.0312 1096 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 14:07:05.0328 1096 MBAMService - ok 14:07:05.0484 1096 [ 6C3D154FFF0A97A6C3D9F78D60C41655 ] McAfee SiteAdvisor Service C:\Program Files\McAfee\SiteAdvisor\McSACore.exe 14:07:05.0484 1096 McAfee SiteAdvisor Service - ok 14:07:05.0609 1096 [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 14:07:05.0640 1096 McComponentHostService - ok 14:07:05.0828 1096 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McMPFSvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 14:07:05.0828 1096 McMPFSvc - ok 14:07:05.0875 1096 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] mcmscsvc C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:07:05.0875 1096 mcmscsvc - ok 14:07:05.0906 1096 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McNaiAnn C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:07:05.0921 1096 McNaiAnn - ok 14:07:05.0953 1096 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McNASvc C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:07:05.0953 1096 McNASvc - ok 14:07:06.0078 1096 [ B3CD9ADE1C2665124CA34125B331B0B4 ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe 14:07:06.0093 1096 McODS - ok 14:07:06.0125 1096 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McProxy C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:07:06.0140 1096 McProxy - ok 14:07:06.0265 1096 [ 593FA4C378818ECE76BA64A11AD56CF2 ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 14:07:06.0281 1096 McShield - ok 14:07:06.0359 1096 [ D7010580BF4E45D5E793A1FE75758C69 ] MDC8021X C:\WINDOWS\system32\DRIVERS\mdc8021x.sys 14:07:06.0359 1096 MDC8021X - ok 14:07:06.0515 1096 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 14:07:06.0562 1096 MDM - ok 14:07:06.0609 1096 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 14:07:06.0609 1096 Messenger - ok 14:07:06.0671 1096 [ 43C31BDF404A6D7A7AC1BFD5EAD2A566 ] mfeapfk C:\WINDOWS\system32\drivers\mfeapfk.sys 14:07:06.0671 1096 mfeapfk - ok 14:07:06.0750 1096 [ C1DC5F42D3367F33B6451BE78B38BD46 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys 14:07:06.0765 1096 mfeavfk - ok 14:07:06.0828 1096 [ 0435C43F4C2BE01B84868AD2A906397B ] mfebopk C:\WINDOWS\system32\drivers\mfebopk.sys 14:07:06.0828 1096 mfebopk - ok 14:07:06.0890 1096 [ 7E1F8B1BDC8240F08BD358B3A466C005 ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 14:07:06.0906 1096 mfefire - ok 14:07:06.0984 1096 [ 4EA6FF90015424517843E931448E00F1 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys 14:07:06.0984 1096 mfefirek - ok 14:07:07.0078 1096 [ D1E998748BA24A731106611D535C6BBF ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys 14:07:07.0078 1096 mfehidk - ok 14:07:07.0171 1096 [ 26C76D10ED650E6492800D6F081ECFBA ] mfendisk C:\WINDOWS\system32\DRIVERS\mfendisk.sys 14:07:07.0171 1096 mfendisk - ok 14:07:07.0203 1096 [ 26C76D10ED650E6492800D6F081ECFBA ] mfendiskmp C:\WINDOWS\system32\DRIVERS\mfendisk.sys 14:07:07.0203 1096 mfendiskmp - ok 14:07:07.0265 1096 [ F454A13377F0A006D20A8C14A753C432 ] mferkdet C:\WINDOWS\system32\drivers\mferkdet.sys 14:07:07.0265 1096 mferkdet - ok 14:07:07.0343 1096 [ 070D3FAF2EAC417C59D8674A8752F7A6 ] mfetdi2k C:\WINDOWS\system32\drivers\mfetdi2k.sys 14:07:07.0343 1096 mfetdi2k - ok 14:07:07.0421 1096 [ B10C4EFD40810C08F4B44DF2EFCB54F7 ] mfevtp C:\WINDOWS\system32\mfevtps.exe 14:07:07.0421 1096 mfevtp - ok 14:07:07.0484 1096 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 14:07:07.0484 1096 mnmdd - ok 14:07:07.0531 1096 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 14:07:07.0546 1096 mnmsrvc - ok 14:07:07.0625 1096 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 14:07:07.0625 1096 Modem - ok 14:07:07.0671 1096 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 14:07:07.0671 1096 Mouclass - ok 14:07:07.0734 1096 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 14:07:07.0734 1096 mouhid - ok 14:07:07.0812 1096 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 14:07:07.0812 1096 MountMgr - ok 14:07:07.0906 1096 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 14:07:07.0906 1096 MozillaMaintenance - ok 14:07:07.0953 1096 mraid35x - ok 14:07:08.0000 1096 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 14:07:08.0000 1096 MRxDAV - ok 14:07:08.0093 1096 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 14:07:08.0125 1096 MRxSmb - ok 14:07:08.0187 1096 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 14:07:08.0187 1096 MSDTC - ok 14:07:08.0234 1096 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 14:07:08.0234 1096 Msfs - ok 14:07:08.0265 1096 MSIServer - ok 14:07:08.0343 1096 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 14:07:08.0343 1096 MSKSSRV - ok 14:07:08.0375 1096 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 14:07:08.0375 1096 MSPCLOCK - ok 14:07:08.0406 1096 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 14:07:08.0406 1096 MSPQM - ok 14:07:08.0484 1096 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 14:07:08.0484 1096 mssmbios - ok 14:07:08.0546 1096 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 14:07:08.0546 1096 Mup - ok 14:07:08.0640 1096 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 14:07:08.0656 1096 napagent - ok 14:07:08.0734 1096 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 14:07:08.0734 1096 NDIS - ok 14:07:08.0781 1096 [ B797EE2EF919C95561DEE78B72B33E5B ] ndiscm C:\WINDOWS\system32\DRIVERS\NetMotCM.sys 14:07:08.0796 1096 ndiscm - ok 14:07:08.0875 1096 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 14:07:08.0875 1096 NdisTapi - ok 14:07:08.0921 1096 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 14:07:08.0921 1096 Ndisuio - ok 14:07:08.0968 1096 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 14:07:08.0968 1096 NdisWan - ok 14:07:09.0046 1096 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 14:07:09.0046 1096 NDProxy - ok 14:07:09.0125 1096 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 14:07:09.0125 1096 NetBIOS - ok 14:07:09.0171 1096 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 14:07:09.0171 1096 NetBT - ok 14:07:09.0250 1096 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 14:07:09.0250 1096 NetDDE - ok 14:07:09.0281 1096 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 14:07:09.0281 1096 NetDDEdsdm - ok 14:07:09.0343 1096 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 14:07:09.0343 1096 Netlogon - ok 14:07:09.0437 1096 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 14:07:09.0453 1096 Netman - ok 14:07:09.0515 1096 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys 14:07:09.0515 1096 NIC1394 - ok 14:07:09.0593 1096 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 14:07:09.0625 1096 Nla - ok 14:07:09.0703 1096 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 14:07:09.0703 1096 Npfs - ok 14:07:09.0765 1096 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 14:07:09.0796 1096 Ntfs - ok 14:07:09.0843 1096 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 14:07:09.0843 1096 NtLmSsp - ok 14:07:09.0921 1096 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 14:07:09.0953 1096 NtmsSvc - ok 14:07:10.0015 1096 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 14:07:10.0015 1096 Null - ok 14:07:10.0062 1096 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 14:07:10.0078 1096 NwlnkFlt - ok 14:07:10.0109 1096 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 14:07:10.0109 1096 NwlnkFwd - ok 14:07:10.0187 1096 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys 14:07:10.0187 1096 ohci1394 - ok 14:07:10.0265 1096 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:07:10.0265 1096 ose - ok 14:07:10.0343 1096 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 14:07:10.0343 1096 Parport - ok 14:07:10.0406 1096 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 14:07:10.0406 1096 PartMgr - ok 14:07:10.0453 1096 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 14:07:10.0453 1096 ParVdm - ok 14:07:10.0515 1096 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 14:07:10.0515 1096 PCI - ok 14:07:10.0546 1096 PCIDump - ok 14:07:10.0578 1096 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 14:07:10.0593 1096 PCIIde - ok 14:07:10.0640 1096 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 14:07:10.0656 1096 Pcmcia - ok 14:07:10.0687 1096 PDCOMP - ok 14:07:10.0718 1096 PDFRAME - ok 14:07:10.0750 1096 PDRELI - ok 14:07:10.0796 1096 PDRFRAME - ok 14:07:10.0828 1096 perc2 - ok 14:07:10.0859 1096 perc2hib - ok 14:07:10.0968 1096 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 14:07:10.0968 1096 PlugPlay - ok 14:07:11.0046 1096 [ 2D091A99624FB9E7EEF0A86D872EC0C3 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe 14:07:11.0046 1096 Pml Driver HPZ12 - ok 14:07:11.0078 1096 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 14:07:11.0093 1096 PolicyAgent - ok 14:07:11.0156 1096 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 14:07:11.0156 1096 PptpMiniport - ok 14:07:11.0187 1096 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 14:07:11.0187 1096 ProtectedStorage - ok 14:07:11.0250 1096 [ 390C204CED3785609AB24E9C52054A84 ] Ps2 C:\WINDOWS\system32\DRIVERS\PS2.sys 14:07:11.0250 1096 Ps2 - ok 14:07:11.0281 1096 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 14:07:11.0281 1096 PSched - ok 14:07:11.0312 1096 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 14:07:11.0312 1096 Ptilink - ok 14:07:11.0375 1096 [ D6AB98DCF05EFE76431414EFB49ED66A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 14:07:11.0375 1096 PxHelp20 - ok 14:07:11.0406 1096 ql1080 - ok 14:07:11.0468 1096 Ql10wnt - ok 14:07:11.0500 1096 ql12160 - ok 14:07:11.0531 1096 ql1240 - ok 14:07:11.0578 1096 ql1280 - ok 14:07:11.0625 1096 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 14:07:11.0625 1096 RasAcd - ok 14:07:11.0687 1096 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 14:07:11.0687 1096 RasAuto - ok 14:07:11.0765 1096 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 14:07:11.0765 1096 Rasl2tp - ok 14:07:11.0843 1096 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 14:07:11.0843 1096 RasMan - ok 14:07:11.0890 1096 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 14:07:11.0890 1096 RasPppoe - ok 14:07:11.0921 1096 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 14:07:11.0921 1096 Raspti - ok 14:07:12.0000 1096 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 14:07:12.0000 1096 Rdbss - ok 14:07:12.0046 1096 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 14:07:12.0046 1096 RDPCDD - ok 14:07:12.0140 1096 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 14:07:12.0140 1096 RDPWD - ok 14:07:12.0234 1096 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 14:07:12.0250 1096 RDSessMgr - ok 14:07:12.0312 1096 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 14:07:12.0312 1096 redbook - ok 14:07:12.0375 1096 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 14:07:12.0375 1096 RemoteAccess - ok 14:07:12.0453 1096 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 14:07:12.0453 1096 RpcLocator - ok 14:07:12.0531 1096 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll 14:07:12.0531 1096 RpcSs - ok 14:07:12.0609 1096 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 14:07:12.0625 1096 RSVP - ok 14:07:12.0671 1096 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 14:07:12.0671 1096 rtl8139 - ok 14:07:12.0734 1096 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 14:07:12.0734 1096 SamSs - ok 14:07:12.0781 1096 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 14:07:12.0781 1096 SASDIFSV - ok 14:07:12.0828 1096 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 14:07:12.0828 1096 SASKUTIL - ok 14:07:12.0890 1096 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 14:07:12.0906 1096 SCardSvr - ok 14:07:12.0968 1096 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 14:07:13.0015 1096 Schedule - ok 14:07:13.0109 1096 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 14:07:13.0109 1096 Secdrv - ok 14:07:13.0156 1096 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 14:07:13.0156 1096 seclogon - ok 14:07:13.0218 1096 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 14:07:13.0218 1096 SENS - ok 14:07:13.0296 1096 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 14:07:13.0296 1096 serenum - ok 14:07:13.0328 1096 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 14:07:13.0328 1096 Serial - ok 14:07:13.0390 1096 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 14:07:13.0390 1096 Sfloppy - ok 14:07:13.0453 1096 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 14:07:13.0500 1096 SharedAccess - ok 14:07:13.0562 1096 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 14:07:13.0562 1096 ShellHWDetection - ok 14:07:13.0609 1096 Simbad - ok 14:07:13.0640 1096 Sparrow - ok 14:07:13.0687 1096 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 14:07:13.0687 1096 splitter - ok 14:07:13.0765 1096 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 14:07:13.0781 1096 Spooler - ok 14:07:13.0843 1096 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 14:07:13.0843 1096 sr - ok 14:07:13.0921 1096 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 14:07:13.0937 1096 srservice - ok 14:07:14.0000 1096 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 14:07:14.0031 1096 Srv - ok 14:07:14.0109 1096 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 14:07:14.0109 1096 SSDPSRV - ok 14:07:14.0187 1096 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 14:07:14.0218 1096 stisvc - ok 14:07:14.0281 1096 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 14:07:14.0296 1096 swenum - ok 14:07:14.0343 1096 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 14:07:14.0359 1096 swmidi - ok 14:07:14.0406 1096 SwPrv - ok 14:07:14.0468 1096 symc810 - ok 14:07:14.0500 1096 symc8xx - ok 14:07:14.0531 1096 sym_hi - ok 14:07:14.0578 1096 sym_u3 - ok 14:07:14.0609 1096 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 14:07:14.0609 1096 sysaudio - ok 14:07:14.0671 1096 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 14:07:14.0687 1096 SysmonLog - ok 14:07:14.0750 1096 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 14:07:14.0765 1096 TapiSrv - ok 14:07:14.0859 1096 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 14:07:14.0875 1096 Tcpip - ok 14:07:14.0937 1096 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 14:07:14.0937 1096 TDPIPE - ok 14:07:14.0984 1096 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 14:07:14.0984 1096 TDTCP - ok 14:07:15.0031 1096 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 14:07:15.0031 1096 TermDD - ok 14:07:15.0125 1096 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 14:07:15.0140 1096 TermService - ok 14:07:15.0187 1096 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 14:07:15.0187 1096 Themes - ok 14:07:15.0234 1096 TosIde - ok 14:07:15.0312 1096 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 14:07:15.0312 1096 TrkWks - ok 14:07:15.0421 1096 [ D85938F272D1BCF3DB3A31FC0A048928 ] uagp35 C:\WINDOWS\system32\DRIVERS\uagp35.sys 14:07:15.0421 1096 uagp35 - ok 14:07:15.0468 1096 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 14:07:15.0468 1096 Udfs - ok 14:07:15.0500 1096 ultra - ok 14:07:15.0578 1096 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 14:07:15.0593 1096 Update - ok 14:07:15.0671 1096 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 14:07:15.0687 1096 upnphost - ok 14:07:15.0750 1096 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 14:07:15.0750 1096 UPS - ok 14:07:15.0859 1096 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 14:07:15.0859 1096 usbccgp - ok 14:07:15.0906 1096 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 14:07:15.0906 1096 usbehci - ok 14:07:15.0968 1096 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 14:07:15.0968 1096 usbhub - ok 14:07:16.0046 1096 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 14:07:16.0046 1096 usbprint - ok 14:07:16.0093 1096 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 14:07:16.0093 1096 usbscan - ok 14:07:16.0171 1096 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 14:07:16.0171 1096 USBSTOR - ok 14:07:16.0250 1096 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 14:07:16.0250 1096 usbuhci - ok 14:07:16.0296 1096 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 14:07:16.0296 1096 VgaSave - ok 14:07:16.0375 1096 [ 4B039BBD037B01F5DB5A144C837F283A ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys 14:07:16.0375 1096 viaagp1 - ok 14:07:16.0453 1096 [ 45489356501EC6CBB789DECE991D393F ] viagfx C:\WINDOWS\system32\DRIVERS\vtmini.sys 14:07:16.0453 1096 viagfx - ok 14:07:16.0500 1096 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 14:07:16.0500 1096 ViaIde - ok 14:07:16.0562 1096 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 14:07:16.0562 1096 VolSnap - ok 14:07:16.0656 1096 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 14:07:16.0671 1096 VSS - ok 14:07:16.0765 1096 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 14:07:16.0765 1096 W32Time - ok 14:07:16.0828 1096 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 14:07:16.0843 1096 Wanarp - ok 14:07:16.0875 1096 WDICA - ok 14:07:16.0921 1096 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 14:07:16.0921 1096 wdmaud - ok 14:07:17.0000 1096 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 14:07:17.0000 1096 WebClient - ok 14:07:17.0109 1096 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 14:07:17.0125 1096 winmgmt - ok 14:07:17.0234 1096 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 14:07:17.0234 1096 WmdmPmSN - ok 14:07:17.0328 1096 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 14:07:17.0328 1096 WmiApSrv - ok 14:07:17.0468 1096 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 14:07:17.0500 1096 WMPNetworkSvc - ok 14:07:17.0546 1096 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys 14:07:17.0562 1096 WS2IFSL - ok 14:07:17.0625 1096 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 14:07:17.0625 1096 wscsvc - ok 14:07:17.0687 1096 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 14:07:17.0703 1096 wuauserv - ok 14:07:17.0750 1096 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 14:07:17.0750 1096 WudfPf - ok 14:07:17.0828 1096 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 14:07:17.0828 1096 WudfRd - ok 14:07:17.0906 1096 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 14:07:17.0906 1096 WudfSvc - ok 14:07:18.0000 1096 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 14:07:18.0015 1096 WZCSVC - ok 14:07:18.0093 1096 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 14:07:18.0109 1096 xmlprov - ok 14:07:18.0203 1096 ================ Scan global =============================== 14:07:18.0250 1096 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 14:07:18.0296 1096 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 14:07:18.0343 1096 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 14:07:18.0375 1096 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 14:07:18.0375 1096 [Global] - ok 14:07:18.0390 1096 ================ Scan MBR ================================== 14:07:18.0421 1096 [ 027F40A2F09E5F236787ED07466CE5A8 ] \Device\Harddisk0\DR0 14:07:18.0593 1096 \Device\Harddisk0\DR0 - ok 14:07:18.0609 1096 ================ Scan VBR ================================== 14:07:18.0625 1096 [ 21A10111F955DE25FA255135FB3C9251 ] \Device\Harddisk0\DR0\Partition1 14:07:18.0625 1096 \Device\Harddisk0\DR0\Partition1 - ok 14:07:18.0625 1096 ============================================================ 14:07:18.0625 1096 Scan finished 14:07:18.0625 1096 ============================================================ 14:07:18.0687 2044 Detected object count: 0 14:07:18.0687 2044 Actual detected object count: 0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI