This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.zbot [Closed]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

All processes killed ========== OTL ========== C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\FireFox\Profiles\qjys52r7.default\user.js moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.PETE-05CK9PEMS6 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Temp folder emptied: 41689508 bytes ->Temporary Internet Files folder emptied: 310887297 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 64832513 bytes ->Flash cache emptied: 737 bytes User: Owner.PETE-OZKKR0BYRK ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 89364 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 398.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 10242012_211736 Files\Folders moved on Reboot… C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\X85IWU9J\ads[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\X85IWU9J\iframe[11].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\X85IWU9J\index[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\X85IWU9J\si[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\VKBD0ZWW\iframe[6].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\HDFUJV9Y\ads[2].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\HDFUJV9Y\si[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\6SYJ2A5M\ads[1].htm moved successfully. C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Temporary Internet Files\Content.IE5\6SYJ2A5M\si[1].htm moved successfully. C:\WINDOWS\temp\Perflib_Perfdata_78c.dat moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… ——————————————————————————- Had to go to sleep while gmer was running and just now am sending you the info requested. for my limited time on the computer this am, seems to working ok.

Attachments:

Hi pfilighera,

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Next

  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • TDSSKiller log
  • OTL.txt
i need to clarify what to do with that tdsskiller. i see the zip file on my desktop but when i open it , the box just says start scan and there is an option to change parameters, but your directions don't seem to gel with what i am doing. please clarify. thanks
Hi pfilighera;

i need to clarify what to do with that tdsskiller. i see the zip file on my desktop but when i open it , the box just says start scan and there is an option to change parameters, but your directions don't seem to gel with what i am doing. please clarify. thanks

You are doing fine. All you should need to do is follow the steps as outlined in the post. If no threats are found please just continue with the steps and run the OTL scan as well. I will still need the TDSSKiller log (regardless of whether any threats are found or not) and the OTL log.

Please download TDSSKiller.zip
  • Extract (unzip) it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan You do not need to change any parameters.
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • If no threats are found just continue
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
OTL logfile created on: 10/28/2012 9:13:24 AM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 263.26 Mb Available Physical Memory | 41.26% Memory free
1.52 Gb Paging File | 1.21 Gb Available in Paging File | 79.62% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 21.29 Gb Free Space | 57.22% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20121005.002\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121027.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121027.007\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121027.001\IDSXpx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\0604000.009\ccsetx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0604000.009\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0604000.009\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0604000.009\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0604000.009\symds.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver;=6
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 2
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.7.2
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/06/06 15:10:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/10/28 09:02:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/13 09:31:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/13 09:28:18 | 000,000,000 | —D | M]

[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 14:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2012/10/22 20:19:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/16 11:33:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/10/13 09:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/10/13 09:31:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/10/28 09:02:22 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
[2012/06/06 15:10:41 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN
[2012/10/10 21:06:18 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 21:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 21:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/10/22 21:59:45 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 15:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/25 20:35:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller
[2012/10/24 21:20:04 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/10/22 20:39:55 | 000,000,000 | —D | C] – C:\ComboFix
[2012/10/22 20:37:36 | 004,987,615 | R— | C] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2012/10/20 08:53:25 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2012/10/18 19:51:10 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/10/18 19:51:10 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/10/18 19:51:10 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/10/18 19:51:10 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/10/18 19:50:20 | 000,000,000 | —D | C] – C:\Qoobox
[2012/10/18 19:50:03 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Start Menu\Programs\Administrative Tools
[2012/10/14 08:44:41 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/10/14 08:39:40 | 000,696,760 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 08:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2012/10/13 16:20:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Sun
[2012/10/13 09:28:18 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 09:28:18 | 000,246,760 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/13 09:27:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/13 09:27:27 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/13 09:27:27 | 000,093,672 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/13 09:24:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\My Documents\Downloads
[2012/10/13 09:22:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla
[2012/10/13 09:22:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/10/13 09:19:13 | 018,494,856 | —- | C] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 20:48:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 20:42:47 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/12 17:27:22 | 002,213,464 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\TDSSKiller.exe
[2012/10/08 20:07:20 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/10/28 09:02:46 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/28 08:59:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/28 08:54:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/28 04:58:44 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2012/10/25 20:29:48 | 002,194,704 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller.zip
[2012/10/25 17:01:02 | 000,002,608 | —- | M] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
[2012/10/24 21:34:39 | 000,294,216 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\gmer.zip
[2012/10/22 21:59:45 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/10/22 20:37:39 | 004,987,615 | R— | M] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2012/10/22 20:18:41 | 000,002,608 | —- | M] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
[2012/10/19 15:02:13 | 000,031,704 | —- | M] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
[2012/10/19 14:04:38 | 000,031,696 | —- | M] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}
[2012/10/15 20:39:25 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\VT20121008.022
[2012/10/14 08:57:55 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 08:57:54 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/13 09:31:45 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/10/13 09:31:45 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 09:26:50 | 000,093,672 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/13 09:26:47 | 000,246,760 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2012/10/13 09:26:47 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/10/13 09:26:47 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/13 09:26:47 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2012/10/13 09:26:46 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 09:26:46 | 000,746,984 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2012/10/13 09:19:20 | 018,494,856 | —- | M] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 20:51:09 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 20:48:29 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 20:28:12 | 000,538,327 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/12 17:27:22 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\TDSSKiller.exe
[2012/10/10 23:45:13 | 000,031,776 | —- | M] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 03:57:51 | 000,001,920 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 03:57:20 | 000,693,941 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\Cat.DB
[2012/10/10 03:08:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/08 20:07:20 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/10/08 18:06:46 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/01 15:45:02 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\isolate.ini

========== Files Created - No Company Name ==========

[2012/10/25 20:34:05 | 002,194,704 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller.zip
[2012/10/25 17:01:02 | 000,002,608 | —- | C] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
[2012/10/24 21:34:38 | 000,294,216 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\gmer.zip
[2012/10/22 20:18:41 | 000,002,608 | —- | C] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
[2012/10/19 15:02:13 | 000,031,704 | —- | C] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
[2012/10/19 14:04:38 | 000,031,696 | —- | C] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}
[2012/10/18 19:51:10 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/10/18 19:51:10 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/10/18 19:51:10 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/10/18 19:51:10 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/10/18 19:51:10 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/10/14 08:39:43 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/13 09:22:23 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 09:22:22 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2012/10/12 20:51:09 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 20:28:12 | 000,538,327 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/10 23:45:13 | 000,031,776 | —- | C] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 03:57:51 | 000,001,920 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 03:06:59 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/10/08 18:06:46 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/15 07:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/02/06 19:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 14:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
—————————————————————–
09:06:22.0813 3644 TDSS rootkit removing tool [removed] Oct 12 2012 17:26:47
09:06:23.0220 3644 ============================================================
09:06:23.0220 3644 Current date / time: 2012/10/28 09:06:23.0220
09:06:23.0220 3644 SystemInfo:
09:06:23.0220 3644
09:06:23.0220 3644 OS Version: 5.1.2600 ServicePack: 3.0
09:06:23.0220 3644 Product type: Workstation
09:06:23.0220 3644 ComputerName: PETE-05CK9PEMS6
09:06:23.0220 3644 UserName: Owner
09:06:23.0220 3644 Windows directory: C:\WINDOWS
09:06:23.0220 3644 System windows directory: C:\WINDOWS
09:06:23.0220 3644 Processor architecture: Intel x86
09:06:23.0220 3644 Number of processors: 1
09:06:23.0220 3644 Page size: 0x1000
09:06:23.0220 3644 Boot type: Normal boot
09:06:23.0220 3644 ============================================================
09:06:56.0579 3644 Drive \Device\Harddisk0\DR0 - Size: 0x9502F9000 (37.25 Gb), SectorSize: 0x200, Cylinders: 0x12FF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
09:06:56.0641 3644 ============================================================
09:06:56.0641 3644 \Device\Harddisk0\DR0:
09:06:56.0657 3644 MBR partitions:
09:06:56.0657 3644 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x4A69BB9
09:06:56.0657 3644 ============================================================
09:06:57.0141 3644 C: <-> \Device\Harddisk0\DR0\Partition1
09:06:57.0141 3644 ============================================================
09:06:57.0141 3644 Initialize success
09:06:57.0141 3644 ============================================================
09:07:01.0829 3940 ============================================================
09:07:01.0829 3940 Scan started
09:07:01.0829 3940 Mode: Manual;
09:07:01.0829 3940 ============================================================
09:07:17.0548 3940 ================ Scan system memory ========================
09:07:17.0563 3940 System memory - ok
09:07:17.0563 3940 ================ Scan services =============================
09:07:19.0423 3940 Abiosdsk - ok
09:07:19.0454 3940 abp480n5 - ok
09:07:19.0579 3940 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
09:07:19.0735 3940 ACPI - ok
09:07:19.0782 3940 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
09:07:19.0860 3940 ACPIEC - ok
09:07:20.0391 3940 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
09:07:20.0735 3940 AdobeFlashPlayerUpdateSvc - ok
09:07:20.0751 3940 adpu160m - ok
09:07:21.0563 3940 [ 96D6CDD0B32846E8CFBE592F4F32E608 ] AdvancedSystemCareService5 C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
09:07:22.0220 3940 AdvancedSystemCareService5 - ok
09:07:22.0360 3940 [ 11C04B17ED2ABBB4833694BCD644AC90 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
09:07:22.0407 3940 aeaudio - ok
09:07:22.0563 3940 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
09:07:22.0673 3940 aec - ok
09:07:22.0829 3940 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
09:07:22.0891 3940 AFD - ok
09:07:22.0938 3940 Aha154x - ok
09:07:23.0032 3940 aic78u2 - ok
09:07:23.0048 3940 aic78xx - ok
09:07:23.0110 3940 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
09:07:23.0126 3940 Alerter - ok
09:07:23.0173 3940 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
09:07:23.0220 3940 ALG - ok
09:07:23.0235 3940 AliIde - ok
09:07:23.0251 3940 amsint - ok
09:07:23.0266 3940 AppMgmt - ok
09:07:23.0282 3940 asc - ok
09:07:23.0298 3940 asc3350p - ok
09:07:23.0313 3940 asc3550 - ok
09:07:23.0720 3940 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
09:07:24.0720 3940 aspnet_state - ok
09:07:24.0845 3940 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
09:07:24.0954 3940 AsyncMac - ok
09:07:25.0204 3940 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
09:07:25.0204 3940 atapi - ok
09:07:25.0235 3940 Atdisk - ok
09:07:25.0298 3940 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
09:07:25.0407 3940 Atmarpc - ok
09:07:25.0548 3940 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
09:07:25.0579 3940 AudioSrv - ok
09:07:25.0720 3940 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
09:07:25.0860 3940 audstub - ok
09:07:26.0204 3940 [ B60F57B4D9CDBC663CC03EB8AF7EC34E ] bcm4sbxp C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
09:07:26.0438 3940 bcm4sbxp - ok
09:07:26.0641 3940 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
09:07:26.0782 3940 Beep - ok
09:07:28.0485 3940 [ 684B12018A54ADC1F856372EC5762B48 ] BHDrvx86 C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20121005.002\BHDrvx86.sys
09:07:29.0204 3940 BHDrvx86 - ok
09:07:29.0438 3940 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
09:07:29.0907 3940 BITS - ok
09:07:30.0313 3940 [ 727C5C2727CF824FBA2A0C1AACF74473 ] Bjmcmng C:\Program Files\Canon\BJCard\Bjmcmng.exe
09:07:30.0423 3940 Bjmcmng - ok
09:07:30.0657 3940 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
09:07:30.0876 3940 Browser - ok
09:07:30.0923 3940 catchme - ok
09:07:31.0204 3940 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
09:07:31.0391 3940 cbidf2k - ok
09:07:31.0860 3940 [ ACE85AF1C31F68BDFEE9333F6592917E ] ccSet_N360 C:\WINDOWS\system32\drivers\N360\0604000.009\ccSetx86.sys
09:07:32.0391 3940 ccSet_N360 - ok
09:07:32.0438 3940 cd20xrnt - ok
09:07:32.0516 3940 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
09:07:32.0641 3940 Cdaudio - ok
09:07:32.0735 3940 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
09:07:32.0860 3940 Cdfs - ok
09:07:33.0110 3940 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
09:07:33.0204 3940 Cdrom - ok
09:07:33.0235 3940 Changer - ok
09:07:33.0345 3940 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
09:07:33.0610 3940 CiSvc - ok
09:07:34.0266 3940 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
09:07:34.0407 3940 ClipSrv - ok
09:07:34.0923 3940 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
09:07:36.0579 3940 clr_optimization_v2.0.50727_32 - ok
09:07:36.0595 3940 CmdIde - ok
09:07:36.0610 3940 COMSysApp - ok
09:07:36.0641 3940 Cpqarray - ok
09:07:36.0735 3940 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
09:07:36.0766 3940 CryptSvc - ok
09:07:36.0782 3940 dac2w2k - ok
09:07:36.0798 3940 dac960nt - ok
09:07:37.0141 3940 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
09:07:37.0329 3940 DcomLaunch - ok
09:07:37.0423 3940 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
09:07:37.0516 3940 Dhcp - ok
09:07:37.0657 3940 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
09:07:37.0688 3940 Disk - ok
09:07:37.0704 3940 dmadmin - ok
09:07:38.0329 3940 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
09:07:39.0173 3940 dmboot - ok
09:07:39.0329 3940 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
09:07:39.0485 3940 dmio - ok
09:07:39.0610 3940 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
09:07:39.0657 3940 dmload - ok
09:07:39.0845 3940 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
09:07:39.0891 3940 dmserver - ok
09:07:40.0266 3940 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
09:07:40.0360 3940 DMusic - ok
09:07:40.0501 3940 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
09:07:40.0516 3940 Dnscache - ok
09:07:40.0751 3940 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
09:07:40.0876 3940 Dot3svc - ok
09:07:40.0891 3940 dpti2o - ok
09:07:41.0188 3940 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
09:07:41.0298 3940 drmkaud - ok
09:07:41.0454 3940 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
09:07:41.0610 3940 EapHost - ok
09:07:42.0704 3940 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
09:07:43.0360 3940 eeCtrl - ok
09:07:43.0501 3940 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
09:07:43.0704 3940 EraserUtilRebootDrv - ok
09:07:43.0829 3940 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
09:07:43.0860 3940 ERSvc - ok
09:07:43.0970 3940 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
09:07:44.0157 3940 Eventlog - ok
09:07:44.0579 3940 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\System32\es.dll
09:07:45.0016 3940 EventSystem - ok
09:07:45.0298 3940 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
09:07:45.0720 3940 Fastfat - ok
09:07:46.0188 3940 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
09:07:46.0501 3940 FastUserSwitchingCompatibility - ok
09:07:46.0563 3940 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
09:07:46.0704 3940 Fdc - ok
09:07:47.0360 3940 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
09:07:47.0438 3940 Fips - ok
09:07:47.0641 3940 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
09:07:47.0766 3940 Flpydisk - ok
09:07:47.0954 3940 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
09:07:48.0188 3940 FltMgr - ok
09:07:48.0891 3940 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
09:07:49.0376 3940 FontCache3.0.0.0 - ok
09:07:49.0657 3940 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
09:07:49.0876 3940 Fs_Rec - ok
09:07:50.0298 3940 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
09:07:50.0470 3940 Ftdisk - ok
09:07:50.0673 3940 [ 20F6C49E2C410FCD32D781F521579BF5 ] GIDv2 C:\WINDOWS\system32\drivers\GIDv2.sys
09:07:51.0345 3940 GIDv2 - ok
09:07:51.0470 3940 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
09:07:51.0532 3940 Gpc - ok
09:07:51.0860 3940 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
09:07:52.0157 3940 helpsvc - ok
09:07:52.0188 3940 HidServ - ok
09:07:52.0751 3940 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
09:07:52.0876 3940 hkmsvc - ok
09:07:52.0891 3940 hpn - ok
09:07:53.0423 3940 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
09:07:53.0626 3940 HTTP - ok
09:07:53.0735 3940 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
09:07:53.0766 3940 HTTPFilter - ok
09:07:53.0782 3940 i2omgmt - ok
09:07:53.0813 3940 i2omp - ok
09:07:53.0985 3940 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
09:07:54.0266 3940 i8042prt - ok
09:07:54.0782 3940 [ 44B7D5A4F2BD9FE21AEA0BB0BACE38C4 ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
09:07:55.0813 3940 ialm - ok
09:07:56.0688 3940 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
09:07:58.0157 3940 idsvc - ok
09:07:58.0860 3940 [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86 C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121027.001\IDSxpx86.sys
09:07:59.0704 3940 IDSxpx86 - ok
09:07:59.0860 3940 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
09:07:59.0985 3940 Imapi - ok
09:08:00.0313 3940 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
09:08:00.0563 3940 ImapiService - ok
09:08:00.0595 3940 ini910u - ok
09:08:00.0641 3940 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
09:08:00.0735 3940 IntelIde - ok
09:08:00.0876 3940 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
09:08:00.0907 3940 intelppm - ok
09:08:01.0188 3940 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
09:08:01.0407 3940 ip6fw - ok
09:08:01.0595 3940 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
09:08:01.0766 3940 IpFilterDriver - ok
09:08:01.0970 3940 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
09:08:02.0204 3940 IpInIp - ok
09:08:02.0423 3940 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
09:08:02.0548 3940 IpNat - ok
09:08:02.0626 3940 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
09:08:03.0063 3940 IPSec - ok
09:08:03.0266 3940 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
09:08:03.0720 3940 IRENUM - ok
09:08:03.0829 3940 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
09:08:03.0907 3940 isapnp - ok
09:08:04.0579 3940 [ A12175F063302CD68F8FC6D572D7E5FD ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
09:08:05.0001 3940 JavaQuickStarterService - ok
09:08:05.0173 3940 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
09:08:05.0735 3940 Kbdclass - ok
09:08:05.0845 3940 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
09:08:06.0204 3940 kmixer - ok
09:08:06.0360 3940 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
09:08:06.0626 3940 KSecDD - ok
09:08:06.0704 3940 [ CBE185162D867D9335629E1E4528258B ] L8042pr2 C:\WINDOWS\system32\DRIVERS\L8042pr2.Sys
09:08:07.0173 3940 L8042pr2 - ok
09:08:07.0282 3940 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
09:08:07.0391 3940 lanmanserver - ok
09:08:07.0516 3940 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
09:08:07.0860 3940 lanmanworkstation - ok
09:08:07.0907 3940 Lavasoft Ad-Aware Service - ok
09:08:07.0985 3940 [ 419590EBE7855215BB157EA0CF0D0531 ] Lbd C:\WINDOWS\system32\DRIVERS\Lbd.sys
09:08:08.0282 3940 Lbd - ok
09:08:08.0345 3940 lbrtfdc - ok
09:08:08.0438 3940 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
09:08:08.0641 3940 LmHosts - ok
09:08:09.0220 3940 [ B6291087D44920D87448FBCFF77B13E5 ] LMouFlt2 C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys
09:08:15.0438 3940 LMouFlt2 - ok
09:08:16.0157 3940 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
09:08:16.0313 3940 Messenger - ok
09:08:16.0407 3940 [ BAFDD5E28BAEA99D7F4772AF2F5EC7EE ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys
09:08:16.0610 3940 mfeavfk - ok
09:08:16.0782 3940 [ 1D003E3056A43D881597D6763E83B943 ] mfebopk C:\WINDOWS\system32\drivers\mfebopk.sys
09:08:16.0860 3940 mfebopk - ok
09:08:17.0048 3940 [ 3F138A1C8A0659F329F242D1E389B2CF ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys
09:08:17.0423 3940 mfehidk - ok
09:08:17.0563 3940 [ 41FE2F288E05A6C8AB85DD56770FFBAD ] mferkdk C:\WINDOWS\system32\drivers\mferkdk.sys
09:08:17.0688 3940 mferkdk - ok
09:08:17.0735 3940 [ 096B52EA918AA909BA5903D79E129005 ] mfesmfk C:\WINDOWS\system32\drivers\mfesmfk.sys
09:08:17.0813 3940 mfesmfk - ok
09:08:17.0970 3940 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
09:08:18.0032 3940 mnmdd - ok
09:08:18.0532 3940 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
09:08:18.0673 3940 mnmsrvc - ok
09:08:19.0610 3940 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
09:08:19.0782 3940 Modem - ok
09:08:19.0938 3940 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
09:08:19.0954 3940 Mouclass - ok
09:08:20.0079 3940 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
09:08:20.0204 3940 MountMgr - ok
09:08:20.0501 3940 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
09:08:21.0501 3940 MozillaMaintenance - ok
09:08:21.0516 3940 mraid35x - ok
09:08:21.0673 3940 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
09:08:21.0954 3940 MRxDAV - ok
09:08:22.0360 3940 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
09:08:22.0766 3940 MRxSmb - ok
09:08:22.0907 3940 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
09:08:22.0970 3940 MSDTC - ok
09:08:23.0032 3940 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
09:08:23.0095 3940 Msfs - ok
09:08:23.0110 3940 MSIServer - ok
09:08:23.0313 3940 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
09:08:23.0376 3940 MSKSSRV - ok
09:08:23.0407 3940 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
09:08:23.0485 3940 MSPCLOCK - ok
09:08:23.0626 3940 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
09:08:23.0688 3940 MSPQM - ok
09:08:23.0782 3940 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
09:08:23.0798 3940 mssmbios - ok
09:08:23.0938 3940 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
09:08:24.0063 3940 Mup - ok
09:08:24.0563 3940 [ F2840DBFE9322F35557219AE82CC4597 ] N360 C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe
09:08:24.0595 3940 N360 - ok
09:08:24.0845 3940 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
09:08:25.0001 3940 napagent - ok
09:08:25.0282 3940 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121027.007\NAVENG.SYS
09:08:25.0329 3940 NAVENG - ok
09:08:26.0204 3940 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121027.007\NAVEX15.SYS
09:08:27.0220 3940 NAVEX15 - ok
09:08:27.0391 3940 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
09:08:27.0595 3940 NDIS - ok
09:08:28.0220 3940 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
09:08:28.0298 3940 NdisTapi - ok
09:08:28.0360 3940 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
09:08:28.0626 3940 Ndisuio - ok
09:08:28.0860 3940 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
09:08:29.0251 3940 NdisWan - ok
09:08:29.0391 3940 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
09:08:29.0813 3940 NDProxy - ok
09:08:29.0970 3940 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
09:08:30.0548 3940 NetBIOS - ok
09:08:30.0876 3940 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
09:08:31.0173 3940 NetBT - ok
09:08:31.0438 3940 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
09:08:31.0891 3940 NetDDE - ok
09:08:31.0923 3940 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
09:08:31.0970 3940 NetDDEdsdm - ok
09:08:32.0063 3940 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
09:08:32.0126 3940 Netlogon - ok
09:08:32.0438 3940 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
09:08:32.0532 3940 Netman - ok
09:08:32.0673 3940 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
09:08:33.0016 3940 NetTcpPortSharing - ok
09:08:33.0204 3940 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
09:08:33.0391 3940 Nla - ok
09:08:33.0501 3940 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
09:08:33.0985 3940 Npfs - ok
09:08:34.0188 3940 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
09:08:34.0673 3940 Ntfs - ok
09:08:34.0704 3940 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
09:08:34.0720 3940 NtLmSsp - ok
09:08:35.0095 3940 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
09:08:35.0501 3940 NtmsSvc - ok
09:08:35.0548 3940 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
09:08:35.0563 3940 Null - ok
09:08:35.0641 3940 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
09:08:35.0673 3940 NwlnkFlt - ok
09:08:35.0735 3940 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
09:08:35.0845 3940 NwlnkFwd - ok
09:08:35.0954 3940 [ CEC7E2C6C1FA00C7AB2F5434F848AE51 ] OMCI C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
09:08:35.0970 3940 OMCI - ok
09:08:36.0079 3940 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
09:08:36.0110 3940 Parport - ok
09:08:36.0173 3940 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
09:08:36.0173 3940 PartMgr - ok
09:08:36.0266 3940 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
09:08:36.0282 3940 ParVdm - ok
09:08:36.0407 3940 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
09:08:36.0438 3940 PCI - ok
09:08:36.0454 3940 PCIDump - ok
09:08:36.0501 3940 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
09:08:36.0516 3940 PCIIde - ok
09:08:36.0673 3940 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
09:08:36.0766 3940 Pcmcia - ok
09:08:36.0782 3940 PDCOMP - ok
09:08:36.0798 3940 PDFRAME - ok
09:08:36.0813 3940 PDRELI - ok
09:08:36.0860 3940 PDRFRAME - ok
09:08:36.0985 3940 perc2 - ok
09:08:37.0016 3940 perc2hib - ok
09:08:37.0126 3940 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
09:08:37.0141 3940 PlugPlay - ok
09:08:37.0173 3940 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
09:08:37.0173 3940 PolicyAgent - ok
09:08:37.0282 3940 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
09:08:37.0345 3940 PptpMiniport - ok
09:08:37.0626 3940 [ 3102F13AFDCDFBFE1467BF03BF027CB1 ] PRISM_A02 C:\WINDOWS\system32\DRIVERS\PRISMA02.sys
09:08:37.0829 3940 PRISM_A02 - ok
09:08:37.0970 3940 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
09:08:38.0016 3940 Processor - ok
09:08:38.0079 3940 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
09:08:38.0079 3940 ProtectedStorage - ok
09:08:38.0188 3940 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
09:08:38.0220 3940 PSched - ok
09:08:38.0313 3940 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
09:08:38.0329 3940 Ptilink - ok
09:08:38.0391 3940 [ DB3B30C3A4CDCF07E164C14584D9D0F2 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
09:08:38.0423 3940 PxHelp20 - ok
09:08:38.0438 3940 ql1080 - ok
09:08:38.0454 3940 Ql10wnt - ok
09:08:38.0485 3940 ql12160 - ok
09:08:38.0516 3940 ql1240 - ok
09:08:38.0532 3940 ql1280 - ok
09:08:38.0579 3940 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
09:08:38.0626 3940 RasAcd - ok
09:08:38.0751 3940 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
09:08:38.0813 3940 RasAuto - ok
09:08:38.0938 3940 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
09:08:39.0016 3940 Rasl2tp - ok
09:08:39.0173 3940 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
09:08:39.0235 3940 RasMan - ok
09:08:39.0266 3940 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
09:08:39.0298 3940 RasPppoe - ok
09:08:39.0329 3940 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
09:08:39.0345 3940 Raspti - ok
09:08:39.0438 3940 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
09:08:39.0532 3940 Rdbss - ok
09:08:39.0563 3940 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
09:08:39.0579 3940 RDPCDD - ok
09:08:39.0782 3940 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
09:08:39.0829 3940 RDPWD - ok
09:08:40.0079 3940 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
09:08:40.0157 3940 RDSessMgr - ok
09:08:40.0313 3940 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
09:08:40.0345 3940 redbook - ok
09:08:40.0470 3940 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
09:08:40.0704 3940 RemoteAccess - ok
09:08:40.0813 3940 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\System32\locator.exe
09:08:41.0001 3940 RpcLocator - ok
09:08:41.0204 3940 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
09:08:41.0204 3940 RpcSs - ok
09:08:41.0376 3940 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\System32\rsvp.exe
09:08:41.0673 3940 RSVP - ok
09:08:41.0704 3940 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
09:08:41.0720 3940 SamSs - ok
09:08:41.0860 3940 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
09:08:41.0970 3940 SCardSvr - ok
09:08:42.0141 3940 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
09:08:42.0329 3940 Schedule - ok
09:08:42.0438 3940 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
09:08:42.0516 3940 Secdrv - ok
09:08:42.0579 3940 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
09:08:42.0595 3940 seclogon - ok
09:08:42.0720 3940 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
09:08:42.0751 3940 SENS - ok
09:08:42.0829 3940 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
09:08:42.0891 3940 serenum - ok
09:08:43.0110 3940 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
09:08:43.0157 3940 Sfloppy - ok
09:08:43.0423 3940 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
09:08:43.0563 3940 SharedAccess - ok
09:08:43.0626 3940 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
09:08:43.0626 3940 ShellHWDetection - ok
09:08:43.0641 3940 Simbad - ok
09:08:44.0298 3940 [ 99A9E1EF62F955C82A5001AC94B4B77B ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
09:08:44.0610 3940 smwdm - ok
09:08:44.0626 3940 Sparrow - ok
09:08:44.0673 3940 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
09:08:44.0704 3940 splitter - ok
09:08:44.0813 3940 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
09:08:44.0845 3940 Spooler - ok
09:08:44.0954 3940 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
09:08:45.0016 3940 sr - ok
09:08:45.0141 3940 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
09:08:45.0204 3940 srservice - ok
09:08:45.0548 3940 [ 7BB297CADA42903328E92425D9761DA6 ] SRTSP C:\WINDOWS\System32\Drivers\N360\0604000.009\SRTSP.SYS
09:08:46.0048 3940 SRTSP - ok
09:08:46.0126 3940 [ 475FCF0F28D845BF1C8ABAC27F19003E ] SRTSPX C:\WINDOWS\system32\drivers\N360\0604000.009\SRTSPX.SYS
09:08:46.0173 3940 SRTSPX - ok
09:08:46.0407 3940 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
09:08:46.0595 3940 Srv - ok
09:08:46.0704 3940 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
09:08:46.0735 3940 SSDPSRV - ok
09:08:46.0938 3940 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
09:08:47.0079 3940 stisvc - ok
09:08:47.0157 3940 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
09:08:47.0173 3940 swenum - ok
09:08:47.0266 3940 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
09:08:47.0298 3940 swmidi - ok
09:08:47.0313 3940 SwPrv - ok
09:08:47.0360 3940 symc810 - ok
09:08:47.0391 3940 symc8xx - ok
09:08:47.0579 3940 [ 690FA0E61B90084C4D9A721BD4F3D779 ] SymDS C:\WINDOWS\system32\drivers\N360\0604000.009\SYMDS.SYS
09:08:47.0704 3940 SymDS - ok
09:08:48.0079 3940 [ 8F88EDB211B12537D2DC2A6D73D6067C ] SymEFA C:\WINDOWS\system32\drivers\N360\0604000.009\SYMEFA.SYS
09:08:48.0391 3940 SymEFA - ok
09:08:48.0485 3940 [ 74E2521E96176A4449570E50BE91954D ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
09:08:48.0532 3940 SymEvent - ok
09:08:48.0657 3940 [ 2C356CCA706505CF63CBE39D532B9236 ] SymIRON C:\WINDOWS\system32\drivers\N360\0604000.009\Ironx86.SYS
09:08:48.0720 3940 SymIRON - ok
09:08:48.0876 3940 [ 508BD882040F9CB12319E3A4FC78EDB9 ] SYMTDI C:\WINDOWS\System32\Drivers\N360\0604000.009\SYMTDI.SYS
09:08:49.0063 3940 SYMTDI - ok
09:08:49.0095 3940 sym_hi - ok
09:08:49.0110 3940 sym_u3 - ok
09:08:49.0188 3940 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
09:08:49.0204 3940 sysaudio - ok
09:08:49.0298 3940 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
09:08:49.0329 3940 SysmonLog - ok
09:08:49.0470 3940 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
09:08:49.0563 3940 TapiSrv - ok
09:08:49.0751 3940 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
09:08:49.0876 3940 Tcpip - ok
09:08:49.0954 3940 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
09:08:49.0954 3940 TDPIPE - ok
09:08:49.0985 3940 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
09:08:50.0001 3940 TDTCP - ok
09:08:50.0110 3940 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
09:08:50.0141 3940 TermDD - ok
09:08:50.0313 3940 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
09:08:50.0407 3940 TermService - ok
09:08:50.0501 3940 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
09:08:50.0501 3940 Themes - ok
09:08:50.0610 3940 TosIde - ok
09:08:50.0704 3940 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
09:08:50.0751 3940 TrkWks - ok
09:08:50.0891 3940 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
09:08:51.0110 3940 Udfs - ok
09:08:51.0126 3940 ultra - ok
09:08:51.0313 3940 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
09:08:51.0673 3940 Update - ok
09:08:51.0813 3940 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
09:08:51.0923 3940 upnphost - ok
09:08:51.0985 3940 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
09:08:52.0032 3940 UPS - ok
09:08:52.0110 3940 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
09:08:52.0126 3940 usbehci - ok
09:08:52.0220 3940 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
09:08:52.0251 3940 usbhub - ok
09:08:52.0313 3940 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
09:08:52.0313 3940 usbprint - ok
09:08:52.0360 3940 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:08:52.0360 3940 USBSTOR - ok
09:08:52.0423 3940 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
09:08:52.0438 3940 usbuhci - ok
09:08:52.0470 3940 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
09:08:52.0485 3940 VgaSave - ok
09:08:52.0501 3940 ViaIde - ok
09:08:52.0579 3940 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
09:08:52.0595 3940 VolSnap - ok
09:08:52.0751 3940 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
09:08:52.0907 3940 VSS - ok
09:08:53.0016 3940 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
09:08:53.0079 3940 W32Time - ok
09:08:53.0126 3940 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
09:08:53.0141 3940 Wanarp - ok
09:08:53.0157 3940 WDICA - ok
09:08:53.0251 3940 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
09:08:53.0282 3940 wdmaud - ok
09:08:53.0329 3940 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
09:08:53.0360 3940 WebClient - ok
09:08:53.0548 3940 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
09:08:53.0595 3940 winmgmt - ok
09:08:53.0657 3940 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
09:08:53.0673 3940 WmdmPmSN - ok
09:08:53.0751 3940 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
09:08:53.0829 3940 WmiApSrv - ok
09:08:54.0235 3940 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
09:08:54.0595 3940 WMPNetworkSvc - ok
09:08:54.0641 3940 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
09:08:54.0657 3940 WS2IFSL - ok
09:08:54.0751 3940 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
09:08:54.0782 3940 wscsvc - ok
09:08:54.0829 3940 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
09:08:54.0829 3940 wuauserv - ok
09:08:54.0907 3940 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
09:08:54.0938 3940 WudfPf - ok
09:08:55.0001 3940 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
09:08:55.0032 3940 WudfRd - ok
09:08:55.0110 3940 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
09:08:55.0157 3940 WudfSvc - ok
09:08:55.0407 3940 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
09:08:55.0595 3940 WZCSVC - ok
09:08:55.0688 3940 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
09:08:55.0735 3940 xmlprov - ok
09:08:55.0845 3940 [ 61002DB7B6EFB5711685B9D79B8E8CE6 ] {6080A529-897E-4629-A488-ABA0C29B635E} C:\WINDOWS\system32\drivers\ialmsbw.sys
09:08:55.0891 3940 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
09:08:55.0938 3940 [ 35CE2BAA708EA038AB72359DE87BAB87 ] {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} C:\WINDOWS\system32\drivers\ialmkchw.sys
09:08:56.0001 3940 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
09:08:56.0001 3940 ================ Scan global ===============================
09:08:56.0079 3940 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
09:08:56.0266 3940 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
09:08:56.0485 3940 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
09:08:56.0548 3940 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
09:08:56.0548 3940 [Global] - ok
09:08:56.0548 3940 ================ Scan MBR ==================================
09:08:56.0595 3940 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
09:08:56.0923 3940 \Device\Harddisk0\DR0 - ok
09:08:56.0923 3940 ================ Scan VBR ==================================
09:08:56.0954 3940 [ 28AF12765B15B0AFFBB1E62B0D210318 ] \Device\Harddisk0\DR0\Partition1
09:08:56.0954 3940 \Device\Harddisk0\DR0\Partition1 - ok
09:08:56.0954 3940 ============================================================
09:08:56.0954 3940 Scan finished
09:08:56.0954 3940 ============================================================
09:08:56.0985 3784 Detected object count: 0
09:08:56.0985 3784 Actual detected object count: 0
09:09:36.0845 3628 Deinitialize success
—————————————————————————————————-

When i tried again to download tss in ie, i got nonsense (as if i was trying to open an application with the wrong program). i had copied and pasted a bit of it to post and show you, but the internet immediately stalled. then i just went to the desktop and ran it from when i downloaded it the other day and have posted that. i feel like it's running slow but maybe that's due to what i am trying to do on this computer. let me know what my step should be. it looks like i may have a few days off here if Sandy comes visiting to NJ.
Hi pfilighera,

You stated that your system continues to feel a bit slow. Unfortunately, due to your limited system resources that is most likely a sign of the age of your computer. You have a rather small amount of RAM based on today's machines. One way to maybe help correct this is to consider adding additional RAM. Although adding more RAM alone would probably not make your system that much faster because you will still have an older processor.
Upgrading to a new machine would probably be your best approach, but that is a financial decision only you can make.

= = = = = = = = = =

Disk Defragmenter for XP
  • Open My Computer.
  • Right-click the local disk volume that you want to defragment, and then click Properties.
  • On the Tools tab, click Defragment Now.
  • Click Defragment.
Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=6
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next post please provide the following:
  • OTL.txt
All processes killed ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Administrator.PETE-05CK9PEMS6 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner.PETE-05CK9PEMS6 ->Temp folder emptied: 22608 bytes ->Temporary Internet Files folder emptied: 141562156 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 85946154 bytes ->Flash cache emptied: 834 bytes User: Owner.PETE-OZKKR0BYRK ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 23828 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 217.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 11042012_132259 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_198.dat not found! PendingFileRenameOperations files… Registry entries deleted on Reboot… —————————————————————- Delayed here in nj by storm sandy. back on track now. please advise.
Hi pfilighera,

Welcome back. Glad to see you are doing better after the storm. I would just like to get this scan to make sure nothing has slipped by.

  • Re-run OTL (it should be located on your desktop).
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • OTL.txt
  • How is your computer running, any remaining issues?
OTL logfile created on: 11/7/2012 4:49:40 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

638.00 Mb Total Physical Memory | 337.01 Mb Available Physical Memory | 52.82% Memory free
1.52 Gb Paging File | 1.18 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): C:\pagefile.sys 960 1920 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 21.01 Gb Free Space | 56.47% Space Free | Partition Type: NTFS

Computer Name: PETE-05CK9PEMS6 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (AdvancedSystemCareService5) – C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20121030.002\BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121106.032\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20121106.032\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20121106.001\IDSXpx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0604000.009\srtspx.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\WINDOWS\system32\drivers\N360\0604000.009\ccsetx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0604000.009\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0604000.009\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0604000.009\ironx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0604000.009\symds.sys (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (PRISM_A02) – C:\WINDOWS\system32\drivers\PRISMA02.sys (GlobespanVirata, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "http://yahoo.com/"
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 2
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.7.2
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPlgn\ [2012/06/06 14:10:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ [2012/11/06 18:24:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/13 08:31:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/13 08:28:18 | 000,000,000 | —D | M]

[2010/07/11 13:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions
[2010/07/11 13:16:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Extensions\[removed]
[2012/10/22 19:19:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions
[2012/10/16 10:33:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/10/13 08:27:40 | 000,020,591 | —- | M] () (No name found) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Mozilla\Firefox\Profiles\qjys52r7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2012/10/13 08:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/10/13 08:31:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2012/10/13 08:31:40 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/11/06 18:24:53 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\COFFPLGN
[2012/06/06 14:10:41 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFFPLGN
[2012/10/10 20:06:18 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 20:05:38 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 20:05:38 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/10/22 20:59:45 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.comcastsupport.com/oneclickfix/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1136593632451 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{45D6A31F-96C2-4D92-B3F2-4ADBAE67D96B}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5479463A-91E8-4138-B3CE-765B64CB7D71}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/31 14:30:52 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/11/04 13:40:19 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2012/11/04 13:40:19 | 000,093,672 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/11/04 13:40:18 | 000,174,056 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2012/10/28 20:05:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Foxit Reader
[2012/10/28 20:05:16 | 000,000,000 | —D | C] – C:\Program Files\Foxit Software
[2012/10/25 19:35:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller
[2012/10/24 20:20:04 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/10/22 19:39:55 | 000,000,000 | —D | C] – C:\ComboFix
[2012/10/22 19:37:36 | 004,987,615 | R— | C] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2012/10/20 07:53:25 | 000,000,000 | —D | C] – C:\N360_BACKUP
[2012/10/18 18:51:10 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/10/18 18:51:10 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/10/18 18:51:10 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/10/18 18:51:10 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/10/18 18:50:20 | 000,000,000 | —D | C] – C:\Qoobox
[2012/10/18 18:50:03 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Start Menu\Programs\Administrative Tools
[2012/10/14 07:44:41 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/10/14 07:39:40 | 000,696,760 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 07:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2012/10/13 15:20:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\Sun
[2012/10/13 08:28:18 | 000,821,736 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 08:24:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\My Documents\Downloads
[2012/10/13 08:22:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla
[2012/10/13 08:22:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/10/13 08:19:13 | 018,494,856 | —- | C] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 19:48:29 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 19:42:47 | 000,000,000 | —D | C] – C:\_OTL
[2012/10/12 16:27:22 | 002,213,464 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\TDSSKiller.exe
[2012/10/08 19:07:20 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/11/07 16:54:01 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/07 11:48:10 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{96E858C2-BB80-4CA6-A945-5D7F401AA939}.job
[2012/11/06 18:23:32 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/11/06 18:22:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/11/06 16:06:55 | 000,031,816 | —- | M] () – C:\{0F965B62-B635-4ABE-A5E1-8777DD9208D6}
[2012/11/04 23:41:02 | 000,032,080 | —- | M] () – C:\{CF641E0E-D774-46A2-9D74-15C385994FF4}
[2012/11/04 13:28:57 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/11/04 13:28:57 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/11/03 04:06:37 | 000,032,256 | —- | M] () – C:\{5EDAF753-B854-4D94-A952-35C6EA497E53}
[2012/11/03 03:38:13 | 000,032,096 | —- | M] () – C:\{104EF115-17E4-42F3-A4A8-073F1BB5854B}
[2012/10/31 16:43:17 | 000,032,144 | —- | M] () – C:\{2EF32154-D389-4EE7-888C-72CE6353A6B7}
[2012/10/31 09:40:58 | 000,032,408 | —- | M] () – C:\{BB64D130-35BB-4983-8332-C15F15D0DD78}
[2012/10/28 20:05:41 | 000,000,809 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2012/10/28 20:05:41 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Foxit Reader.lnk
[2012/10/25 19:29:48 | 002,194,704 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller.zip
[2012/10/25 16:01:02 | 000,002,608 | —- | M] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
[2012/10/24 20:34:39 | 000,294,216 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\gmer.zip
[2012/10/22 20:59:45 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/10/22 19:37:39 | 004,987,615 | R— | M] (Swearware) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\ComboFix.exe
[2012/10/22 19:18:41 | 000,002,608 | —- | M] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
[2012/10/19 14:02:13 | 000,031,704 | —- | M] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
[2012/10/19 13:04:38 | 000,031,696 | —- | M] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}
[2012/10/15 19:39:25 | 000,010,074 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\VT20121008.022
[2012/10/14 07:57:55 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/10/14 07:57:54 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/10/13 08:31:45 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/10/13 08:31:45 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 08:26:46 | 000,821,736 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/13 08:26:46 | 000,746,984 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2012/10/13 08:19:20 | 018,494,856 | —- | M] (Mozilla) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\Firefox Setup 16.0.1.exe
[2012/10/12 19:51:09 | 000,000,512 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 19:48:29 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\aswMBR.exe
[2012/10/12 19:28:12 | 000,538,327 | —- | M] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/12 16:27:22 | 002,213,464 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\TDSSKiller.exe
[2012/10/10 22:45:13 | 000,031,776 | —- | M] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 02:57:51 | 000,001,920 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 02:57:20 | 000,693,941 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0604000.009\Cat.DB
[2012/10/10 02:08:34 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/10/08 19:07:20 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\OTL.exe
[2012/10/08 17:06:46 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2012/11/06 16:06:55 | 000,031,816 | —- | C] () – C:\{0F965B62-B635-4ABE-A5E1-8777DD9208D6}
[2012/11/04 23:41:02 | 000,032,080 | —- | C] () – C:\{CF641E0E-D774-46A2-9D74-15C385994FF4}
[2012/11/03 04:06:37 | 000,032,256 | —- | C] () – C:\{5EDAF753-B854-4D94-A952-35C6EA497E53}
[2012/11/03 03:38:13 | 000,032,096 | —- | C] () – C:\{104EF115-17E4-42F3-A4A8-073F1BB5854B}
[2012/10/31 16:43:17 | 000,032,144 | —- | C] () – C:\{2EF32154-D389-4EE7-888C-72CE6353A6B7}
[2012/10/31 09:40:58 | 000,032,408 | —- | C] () – C:\{BB64D130-35BB-4983-8332-C15F15D0DD78}
[2012/10/28 20:05:41 | 000,000,809 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2012/10/28 20:05:40 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Foxit Reader.lnk
[2012/10/25 19:34:05 | 002,194,704 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\tdsskiller.zip
[2012/10/25 16:01:02 | 000,002,608 | —- | C] () – C:\{C6D62A8E-7509-4558-81FB-F118214A5C0F}
[2012/10/24 20:34:38 | 000,294,216 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\gmer.zip
[2012/10/22 19:18:41 | 000,002,608 | —- | C] () – C:\{C14588FA-2D5F-401D-B9FF-FBD3B8BDFB0C}
[2012/10/19 14:02:13 | 000,031,704 | —- | C] () – C:\{D1179989-863E-4374-ABF6-3EACA2F2FD20}
[2012/10/19 13:04:38 | 000,031,696 | —- | C] () – C:\{F765599A-AF2E-4919-8ECD-E0D9E979E54F}
[2012/10/18 18:51:10 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/10/18 18:51:10 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/10/18 18:51:10 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/10/18 18:51:10 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/10/18 18:51:10 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/10/14 07:39:43 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/13 08:22:23 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2012/10/13 08:22:22 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2012/10/12 19:51:09 | 000,000,512 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\MBR.dat
[2012/10/12 19:28:12 | 000,538,327 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Desktop\AdwCleaner.exe
[2012/10/10 22:45:13 | 000,031,776 | —- | C] () – C:\{3CAB558C-0424-4399-AC7E-182613966719}
[2012/10/10 02:57:51 | 000,001,920 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Norton Security Suite.LNK
[2012/10/10 02:06:59 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/10/08 17:06:46 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/15 06:24:01 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2009/02/06 18:55:45 | 000,076,288 | —- | C] () – C:\Documents and Settings\Owner.PETE-05CK9PEMS6\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/07/04 13:15:49 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 19:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 19:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
——————————————
Hello, here is the results of the scan. No news from husband on how machine is working, so that would mean all is ok.
Hi pfilighera,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
    IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next post please provide the following:
  • OTL.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI